Dates on which privacy obligations take effect, compiled from our reporting and linked to the statute, rule or order that sets each one. This page is generated from tagged coverage, so it reflects what we have reported rather than every deadline in force. It describes what the law says takes effect and when; whether a given obligation reaches a particular organization is a question for an attorney.

DateWhat takes effectApplies toCoverage
March 31, 2024My Health My Data Act obligations take effect for most regulated entitiesEntities doing business in Washington that collect consumer health data (small businesses: June 30, 2024)Washington's My Health My Data Act Covers Health Data HIPAA Does Not
April 22, 2026Compliance date for the amended COPPA Rule, except 16 CFR 312.11(d)(1), (d)(4) and (g), which carried earlier datesOperators covered by 16 CFR Part 312The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound
August 1, 2026Registered data brokers must access DROP at least once every 45 days and process deletion requests within 45 days, under Civ. Code § 1798.99.86(c) and Cal. Code Regs. tit. 11, § 7612Businesses registered as data brokers with the California Privacy Protection AgencyThe California Delete Act: Registration, DROP, and the Deadlines Written Into SB 362
January 1, 2027Vermont Age-Appropriate Design Code Act (9 V.S.A. §§ 2449a to 2449j) takes effectCovered businesses as defined in 9 V.S.A. § 2449a(10)Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027
January 1, 2027Part 17 of article 1 of title 6, as repealed and reenacted by SB 26-189, takes effect and applies to consequential decisions made on or after this dateDevelopers and deployers of covered automated decision-making technology doing business in ColoradoColorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says
January 1, 2027Article 11 compliance deadline for businesses using ADMT to make a significant decision, under Cal. Code Regs. tit. 11, § 7200(b)Businesses using automated decisionmaking technology to make a significant decision concerning a consumerCalifornia's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says
January 31, 2027Waived effective date of 47 CFR 64.1200(a)(10), to the extent it requires a revocation made in response to one type of message to apply to all future robocalls and robotexts from that caller on unrelated mattersCallers and text senders subject to 47 CFR 64.1200Revoking TCPA Consent: The 2024 FCC Rule, and the Part of It Still Waived