BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Compliance Colleague//Deadline Calendar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:Compliance deadlines (Compliance Colleague)
X-WR-CALDESC:Upcoming security\, privacy and AI governance compliance dates
 . Not legal advice.
REFRESH-INTERVAL;VALUE=DURATION:P1D
X-PUBLISHED-TTL:P1D
BEGIN:VEVENT
UID:in-dpdp-consent-managers-2026-11-13@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20261113
DTEND;VALUE=DATE:20261114
SUMMARY:India DPDP: Consent Manager provisions commence
DESCRIPTION:Consent Manager registration and obligations under the Digital 
 Personal Data Protection Rules\, 2025 come into force. Core obligations fo
 llow on 13 May 2027.\n\nSource: DPDP Rules\, 2025\, Rule 1 and Rule 4\; DP
 DP Act\, 2023 ss. 6(9)\, 27(1)(d)\n\nMore: https://compliancecolleague.ai/
 answers/dpdpa-foreign-saas-and-paper-records?ref=ics\n\nAsk the standard\,
  not the internet: https://compliancecolleague.ai/?ref=ics\nNot legal advi
 ce.
URL:https://compliancecolleague.ai/answers/dpdpa-foreign-saas-and-paper-rec
 ords?ref=ics
CATEGORIES:India
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:us-nist-sp800-82r4-comments-2026-11-30@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20261130
DTEND;VALUE=DATE:20261201
SUMMARY:NIST SP 800-82 Rev. 4 (OT security) draft: comments close
DESCRIPTION:Last day to comment on the initial public draft of NIST SP 800-
 82 Rev. 4\, Guide to Operational Technology Security\, rebuilt around CSF 
 2.0.\n\nSource: NIST CSRC\, SP 800-82 Rev. 4 initial public draft (21 Sep 
 2026)\n\nMore: https://compliancecolleague.ai/answers?ref=ics\n\nAsk the s
 tandard\, not the internet: https://compliancecolleague.ai/?ref=ics\nNot l
 egal advice.
URL:https://compliancecolleague.ai/answers?ref=ics
CATEGORIES:United States
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:eu-ai-act-art5-art50-2026-12-02@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20261202
DTEND;VALUE=DATE:20261203
SUMMARY:EU AI Act: new Art. 5 prohibitions and Art. 50(2) marking for older
  generative systems
DESCRIPTION:The intimate-imagery and child sexual abuse material prohibitio
 ns (Art. 5(1)(ba)\, (bb)) apply\, and generative AI systems placed on the 
 market before 2 Aug 2026 must meet the Art. 50(2) machine-readable marking
  duty.\n\nSource: Regulation (EU) 2024/1689 Art. 5\, Art. 111(4) and Art. 
 113\, as amended by Regulation (EU) 2026/1744\n\nMore: https://compliancec
 olleague.ai/answers/eu-ai-act-high-risk-application-dates?ref=ics\n\nAsk t
 he standard\, not the internet: https://compliancecolleague.ai/?ref=ics\nN
 ot legal advice.
URL:https://compliancecolleague.ai/answers/eu-ai-act-high-risk-application-
 dates?ref=ics
CATEGORIES:European Union
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:au-app-1-7-automated-decisions-2026-12-10@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20261210
DTEND;VALUE=DATE:20261211
SUMMARY:Australia: automated-decision transparency (APP 1.7-1.9) in force
DESCRIPTION:APP entities must say in their privacy policy when computer pro
 grams make\, or substantially help make\, decisions that could significant
 ly affect individuals. Applies to decisions made after this date.\n\nSourc
 e: Privacy and Other Legislation Amendment Act 2024\, s. 2 (item 7) and Sc
 hedule 1 Part 15\n\nMore: https://compliancecolleague.ai/answers?ref=ics\n
 \nAsk the standard\, not the internet: https://compliancecolleague.ai/?ref
 =ics\nNot legal advice.
URL:https://compliancecolleague.ai/answers?ref=ics
CATEGORIES:Australia
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:us-ca-ccpa-admt-2027-01-01@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20270101
DTEND;VALUE=DATE:20270102
SUMMARY:California CCPA: ADMT compliance date
DESCRIPTION:Businesses that use automated decision-making technology for si
 gnificant decisions before this date (including tools first deployed durin
 g 2026) must comply with the ADMT rules by 1 January 2027. Use that starts
  later must comply from the start.\n\nSource: CCPA Regulations\, 11 CCR §
  7200(b)\n\nMore: https://compliancecolleague.ai/answers?ref=ics\n\nAsk th
 e standard\, not the internet: https://compliancecolleague.ai/?ref=ics\nNo
 t legal advice.
URL:https://compliancecolleague.ai/answers?ref=ics
CATEGORIES:California\, United States
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:in-dpdp-full-compliance-2027-05-13@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20270513
DTEND;VALUE=DATE:20270514
SUMMARY:India DPDP: full compliance deadline
DESCRIPTION:The core obligations of the Digital Personal Data Protection Ac
 t and Rules apply: notice\, consent\, security safeguards\, breach notific
 ation\, data principal rights and retention.\n\nSource: DPDP Rules\, 2025\
 , Rule 1 (18 months from notification)\n\nMore: https://compliancecolleagu
 e.ai/answers/dpdpa-foreign-saas-and-paper-records?ref=ics\n\nAsk the stand
 ard\, not the internet: https://compliancecolleague.ai/?ref=ics\nNot legal
  advice.
URL:https://compliancecolleague.ai/answers/dpdpa-foreign-saas-and-paper-rec
 ords?ref=ics
CATEGORIES:India
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:eu-ai-act-annex-iii-2027-12-02@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20271202
DTEND;VALUE=DATE:20271203
SUMMARY:EU AI Act: high-risk obligations for Annex III systems apply
DESCRIPTION:Provider and deployer obligations for high-risk AI systems list
 ed in Annex III (employment\, credit\, education\, essential services and 
 others) apply\, deferred from August 2026 by the Digital Omnibus.\n\nSourc
 e: Regulation (EU) 2024/1689 Art. 113\, as amended by Regulation (EU) 2026
 /1744\n\nMore: https://compliancecolleague.ai/answers/eu-ai-act-high-risk-
 application-dates?ref=ics\n\nAsk the standard\, not the internet: https://
 compliancecolleague.ai/?ref=ics\nNot legal advice.
URL:https://compliancecolleague.ai/answers/eu-ai-act-high-risk-application-
 dates?ref=ics
CATEGORIES:European Union
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:eu-cra-full-application-2027-12-11@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20271211
DTEND;VALUE=DATE:20271212
SUMMARY:EU Cyber Resilience Act applies in full
DESCRIPTION:All remaining Cyber Resilience Act obligations apply to product
 s with digital elements\, including the essential cybersecurity requiremen
 ts and conformity assessment. Vulnerability and incident reporting already
  applies.\n\nSource: Regulation (EU) 2024/2847 Art. 71(2)\n\nMore: https:/
 /compliancecolleague.ai/answers?ref=ics\n\nAsk the standard\, not the inte
 rnet: https://compliancecolleague.ai/?ref=ics\nNot legal advice.
URL:https://compliancecolleague.ai/answers?ref=ics
CATEGORIES:European Union
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:us-ca-ccpa-risk-assessments-2027-12-31@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20271231
DTEND;VALUE=DATE:20280101
SUMMARY:California CCPA: risk assessments due for processing begun before 2
 026
DESCRIPTION:Risk assessments must be completed for processing activities th
 at began before 1 January 2026 and are still continuing.\n\nSource: CCPA R
 egulations\, 11 CCR § 7155(b)\n\nMore: https://compliancecolleague.ai/ans
 wers?ref=ics\n\nAsk the standard\, not the internet: https://compliancecol
 league.ai/?ref=ics\nNot legal advice.
URL:https://compliancecolleague.ai/answers?ref=ics
CATEGORIES:California\, United States
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:us-ca-ccpa-audit-attestation-2028-04-01@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20280401
DTEND;VALUE=DATE:20280402
SUMMARY:California CCPA: first cybersecurity audit certifications and risk-
 assessment submissions
DESCRIPTION:Businesses with 2026 revenue over $100 million submit their fir
 st cybersecurity audit certification (audit period 2027). Risk-assessment 
 information and an executive attestation for assessments conducted in 2026
 -2027 are also due.\n\nSource: CCPA Regulations\, 11 CCR §§ 7121 and 715
 7(a)\n\nMore: https://compliancecolleague.ai/answers?ref=ics\n\nAsk the st
 andard\, not the internet: https://compliancecolleague.ai/?ref=ics\nNot le
 gal advice.
URL:https://compliancecolleague.ai/answers?ref=ics
CATEGORIES:California\, United States
TRANSP:TRANSPARENT
END:VEVENT
BEGIN:VEVENT
UID:eu-ai-act-annex-i-2028-08-02@compliancecolleague.ai
DTSTAMP:20261003T000000Z
DTSTART;VALUE=DATE:20280802
DTEND;VALUE=DATE:20280803
SUMMARY:EU AI Act: high-risk obligations for Annex I products apply
DESCRIPTION:High-risk obligations apply to AI systems that are safety compo
 nents of products covered by the EU harmonisation legislation in Annex I (
 machinery\, medical devices\, toys and others).\n\nSource: Regulation (EU)
  2024/1689 Art. 113\, as amended by Regulation (EU) 2026/1744\n\nMore: htt
 ps://compliancecolleague.ai/answers/eu-ai-act-high-risk-application-dates?
 ref=ics\n\nAsk the standard\, not the internet: https://compliancecolleagu
 e.ai/?ref=ics\nNot legal advice.
URL:https://compliancecolleague.ai/answers/eu-ai-act-high-risk-application-
 dates?ref=ics
CATEGORIES:European Union
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
