Upcoming Deadlines
Privacy, AI, accessibility and analytics deadlines for organisations with a website, soonest first, each one checked against the regulator or vendor that set it.
I last checked every date on 28 September 2026, from Hobart, where deadlines arrive most of a day before they reach California and still somehow feel late.
This page used to have countdown clocks. One of them counted down to Chrome removing third-party cookies, and then Google decided not to remove them, so for a while it counted down to nothing in particular, very precisely. The clocks are gone. Each date below links to its source instead, because a deadline without a source is a rumour with a calendar. None of this is legal advice. It is a map, and you still need someone to walk the ground.
Coming Up
2 December 2026: The EU AI Act's Second Wave
Two things start on the same day. A new ban applies to AI systems that generate non-consensual sexual deepfakes or child sexual abuse material. And generative AI systems that were already on the market before 2 August 2026 must now mark what they make in a machine-readable way, so software can tell it was machine-made. Both dates come from the Digital Omnibus on AI and are on the Commission's own AI Act timeline. I took the whole timetable apart, clock by clock, in The AI Act Blinks.
10 December 2026: Australian Privacy Policies Must Name Their Robots
From this date, if your organisation uses personal information in a computer program that makes, or substantially helps make, decisions that could significantly affect people, your privacy policy must say what kinds of information go in and what kinds of decisions come out. The legal term is automated decision-making, or ADM. The OAIC confirms the date. "Computer program" is read broadly. The OAIC's own issues paper uses an Excel formula as an example, so your robot may be a formula in cell F12. My checklist is in Privacy Policies: Somebody Is Finally Reading the Fine Print.
The same day is the deadline for the OAIC to register the Children's Online Privacy Code. As of its 5 August 2026 update, the OAIC had finished consulting and said the code will be in place by 10 December 2026, but had not published the final text. If your service is likely to be used by children, watch this one closely.
1 January 2027: California, Twice
California's new CCPA regulations switch on their rules for automated decisionmaking technology (ADMT: software that replaces, or mostly replaces, a human decision about a job, a loan or a home). A business already using ADMT for a significant decision must comply by 1 January 2027 (section 7200). The same date starts the first audit year for businesses with revenue over US$100 million. Details, and a toll bridge, in CCPA Grows Up.
Also on 1 January, the California Opt Me Out Act (AB 566) makes browser makers include a setting that sends an opt-out preference signal. So more of your visitors will arrive already saying no, politely, in a header. Global Privacy Control explains how to hear it.
26 April 2027: ADA Title II, Larger US Governments
US state and local governments serving 50,000 people or more must make their websites and apps meet WCAG 2.1 Level AA, the international accessibility standard. The US Department of Justice set this date for 26 April 2027. Smaller governments and special district governments now have until 26 April 2028.
2 December 2027: EU AI Act, High-Risk Systems
The rules for high-risk AI in the Annex III list start. That list covers AI used in areas such as hiring, credit and education. High-risk AI built into regulated products (the Annex I list: machinery, toys, lifts) follows on 2 August 2028.
31 December 2027 to 2030: California Risk Assessments and Audits
Processing that started before 2026 and counts as high risk under the CCPA needs a documented risk assessment by 31 December 2027. The first submissions to the regulator are due by 1 April 2028. Cybersecurity audit reports follow in three waves by revenue: 1 April 2028, 1 April 2029 and 1 April 2030. All of these dates are in the approved regulation text.
On the Radar, No Date Yet
- Australia's Privacy Act, tranche 2. The Attorney-General released an exposure draft on 31 August 2026, and submissions closed on 18 September. It includes a "fair and reasonable" test for how organisations collect and use personal information. There is no start date until a bill passes. My notes are in Tranche 2.
- Google Analytics and ad personalisation. Google says that the
ad_personalizationconsent setting will become the only control for ads personalisation, later in 2026. It has not given a date.
Already Happened
Kept here for the record, and for anyone who finds an old bookmark. Each one is done; the job now is to check that your setup caught up.
- 1 July 2023 and 1 July 2024: Universal Analytics. Standard properties stopped processing data in 2023. In the week of 1 July 2024, Google removed access to every property and the API, and deleted the data. If nobody exported it, it is gone.
- July 2024 and 22 April 2025: Chrome keeps third-party cookies. Google first dropped its plan to remove them, then dropped the choice prompt it planned instead, and kept the current approach. Safari has blocked them by default since 2020, so the cookie is gone for some of your visitors anyway. The whole saga, with sandcastles, is in Privacy Sandbox: The Sandcastle the Tide Took Back.
- 28 June 2025: the European Accessibility Act. Many products and services sold in the EU, including online shops and banking (more in my post), must now be accessible.
- 10 December 2025: Australia's social media minimum age. Age-restricted platforms must take reasonable steps to keep under-16s from holding accounts. More in Age Assurance.
- 1 January 2026: the CCPA regulations take effect. Approved in September 2025, with new high-risk processing needing a risk assessment before it starts.
- 5 February 2026: the UK analytics cookie exception. The Data (Use and Access) Act's changes to the cookie rules came into force, including a new exception for some analytics. Counting Heads Without Asking covers what it allows.
- 15 June 2026: Google Signals steps back. Consent mode became the single control for whether the Google Analytics tag collects Google Ads cookies and identifiers. Google Signals Goes Quiet has the detail.
- 2 August 2026: the EU AI Act's main date. Article 50 transparency duties started (tell people when they are talking to AI; label deep fakes), and so did enforcement at national and EU level.
If a date here has moved since I last checked, tell me. I would rather fix this page than let it become another countdown to nothing.