Dated obligations drawn from our coverage, each linked to the source
Dates on which privacy obligations take effect, compiled from our reporting and linked to the statute, rule or order that sets each one. This page is generated from tagged coverage, so it reflects what we have reported rather than every deadline in force. It describes what the law says takes effect and when; whether a given obligation reaches a particular organization is a question for an attorney.
| Date | What takes effect | Applies to | Coverage |
|---|---|---|---|
| March 31, 2024 | My Health My Data Act obligations take effect for most regulated entities | Entities doing business in Washington that collect consumer health data (small businesses: June 30, 2024) | Washington's My Health My Data Act Covers Health Data HIPAA Does Not |
| April 22, 2026 | Compliance date for the amended COPPA Rule, except 16 CFR 312.11(d)(1), (d)(4) and (g), which carried earlier dates | Operators covered by 16 CFR Part 312 | The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound |
| August 1, 2026 | Registered data brokers must access DROP at least once every 45 days and process deletion requests within 45 days, under Civ. Code § 1798.99.86(c) and Cal. Code Regs. tit. 11, § 7612 | Businesses registered as data brokers with the California Privacy Protection Agency | The California Delete Act: Registration, DROP, and the Deadlines Written Into SB 362 |
| January 1, 2027 | Vermont Age-Appropriate Design Code Act (9 V.S.A. §§ 2449a to 2449j) takes effect | Covered businesses as defined in 9 V.S.A. § 2449a(10) | Vermont's Age-Appropriate Design Code: What Act 63 Requires of Online Services From January 1, 2027 |
| January 1, 2027 | Part 17 of article 1 of title 6, as repealed and reenacted by SB 26-189, takes effect and applies to consequential decisions made on or after this date | Developers and deployers of covered automated decision-making technology doing business in Colorado | Colorado's AI Act and the Consequential Decision: What the Reenacted Part 17 Says |
| January 1, 2027 | Article 11 compliance deadline for businesses using ADMT to make a significant decision, under Cal. Code Regs. tit. 11, § 7200(b) | Businesses using automated decisionmaking technology to make a significant decision concerning a consumer | California's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says |
| January 31, 2027 | Waived effective date of 47 CFR 64.1200(a)(10), to the extent it requires a revocation made in response to one type of message to apply to all future robocalls and robotexts from that caller on unrelated matters | Callers and text senders subject to 47 CFR 64.1200 | Revoking TCPA Consent: The 2024 FCC Rule, and the Part of It Still Waived |