Upcoming Deadlines

Privacy, AI, accessibility and analytics deadlines for organisations with a website, soonest first, each one checked against the regulator or vendor that set it.

I last checked every date on 28 September 2026, from Hobart, where deadlines arrive most of a day before they reach California and still somehow feel late.

This page used to have countdown clocks. One of them counted down to Chrome removing third-party cookies, and then Google decided not to remove them, so for a while it counted down to nothing in particular, very precisely. The clocks are gone. Each date below links to its source instead, because a deadline without a source is a rumour with a calendar. None of this is legal advice. It is a map, and you still need someone to walk the ground.

Coming Up

2 December 2026: The EU AI Act's Second Wave

Two things start on the same day. A new ban applies to AI systems that generate non-consensual sexual deepfakes or child sexual abuse material. And generative AI systems that were already on the market before 2 August 2026 must now mark what they make in a machine-readable way, so software can tell it was machine-made. Both dates come from the Digital Omnibus on AI and are on the Commission's own AI Act timeline. I took the whole timetable apart, clock by clock, in The AI Act Blinks.

10 December 2026: Australian Privacy Policies Must Name Their Robots

From this date, if your organisation uses personal information in a computer program that makes, or substantially helps make, decisions that could significantly affect people, your privacy policy must say what kinds of information go in and what kinds of decisions come out. The legal term is automated decision-making, or ADM. The OAIC confirms the date. "Computer program" is read broadly. The OAIC's own issues paper uses an Excel formula as an example, so your robot may be a formula in cell F12. My checklist is in Privacy Policies: Somebody Is Finally Reading the Fine Print.

The same day is the deadline for the OAIC to register the Children's Online Privacy Code. As of its 5 August 2026 update, the OAIC had finished consulting and said the code will be in place by 10 December 2026, but had not published the final text. If your service is likely to be used by children, watch this one closely.

1 January 2027: California, Twice

California's new CCPA regulations switch on their rules for automated decisionmaking technology (ADMT: software that replaces, or mostly replaces, a human decision about a job, a loan or a home). A business already using ADMT for a significant decision must comply by 1 January 2027 (section 7200). The same date starts the first audit year for businesses with revenue over US$100 million. Details, and a toll bridge, in CCPA Grows Up.

Also on 1 January, the California Opt Me Out Act (AB 566) makes browser makers include a setting that sends an opt-out preference signal. So more of your visitors will arrive already saying no, politely, in a header. Global Privacy Control explains how to hear it.

26 April 2027: ADA Title II, Larger US Governments

US state and local governments serving 50,000 people or more must make their websites and apps meet WCAG 2.1 Level AA, the international accessibility standard. The US Department of Justice set this date for 26 April 2027. Smaller governments and special district governments now have until 26 April 2028.

2 December 2027: EU AI Act, High-Risk Systems

The rules for high-risk AI in the Annex III list start. That list covers AI used in areas such as hiring, credit and education. High-risk AI built into regulated products (the Annex I list: machinery, toys, lifts) follows on 2 August 2028.

31 December 2027 to 2030: California Risk Assessments and Audits

Processing that started before 2026 and counts as high risk under the CCPA needs a documented risk assessment by 31 December 2027. The first submissions to the regulator are due by 1 April 2028. Cybersecurity audit reports follow in three waves by revenue: 1 April 2028, 1 April 2029 and 1 April 2030. All of these dates are in the approved regulation text.

On the Radar, No Date Yet

  • Australia's Privacy Act, tranche 2. The Attorney-General released an exposure draft on 31 August 2026, and submissions closed on 18 September. It includes a "fair and reasonable" test for how organisations collect and use personal information. There is no start date until a bill passes. My notes are in Tranche 2.
  • Google Analytics and ad personalisation. Google says that the ad_personalization consent setting will become the only control for ads personalisation, later in 2026. It has not given a date.

Already Happened

Kept here for the record, and for anyone who finds an old bookmark. Each one is done; the job now is to check that your setup caught up.

If a date here has moved since I last checked, tell me. I would rather fix this page than let it become another countdown to nothing.