<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GRCIDE — Regulatory radar</title>
    <link>https://grcide.com/radar</link>
    <description>Changes to the instruments that land in scope: what moved, who it affects, and what it asks of a program.</description>
    <language>en</language>
    <atom:link href="https://grcide.com/radar.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Sun, 06 Sep 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>EU post-quantum roadmap: consultation feedback, 2 September 2026</title>
      <link>https://grcide.com/radar#eu-pqc-roadmap-faq</link>
      <guid isPermaLink="false">https://grcide.com/radar#eu-pqc-roadmap-faq</guid>
      <pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate>
      <description>The Commission published the roadmap consultation feedback on 2 September 2026; the FAQ of 15 April 2026 answers the milestone and inventory questions.</description>
    </item>
    <item>
      <title>China: simplified personal information duties for small processors, in force 1 September 2026</title>
      <link>https://grcide.com/radar#china-small-pi-processors</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-small-pi-processors</guid>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <description>Order No. 25 gives a processor under one hundred thousand people a five-year audit cycle, form-based impact assessments and six export exemptions.</description>
    </item>
    <item>
      <title>NIST finalised the CSF 2.0 informative references guide on 25 August 2026</title>
      <link>https://grcide.com/radar#nist-csf-informative-references</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-csf-informative-references</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 +0000</pubDate>
      <description>NIST SP 1347 reached final status on 25 August 2026, covering what a CSF 2.0 informative reference is and which NIST tools serve the reference data.</description>
    </item>
    <item>
      <title>China: annual network data risk assessments from 20 August 2026</title>
      <link>https://grcide.com/radar#china-network-data-risk-assessment</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-network-data-risk-assessment</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <description>Order No. 24 makes an annual risk assessment compulsory for important data processors, with the report filed within twenty working days.</description>
    </item>
    <item>
      <title>Netherlands: the NIS2 and CER acts took effect on 15 August 2026</title>
      <link>https://grcide.com/radar#nl-cyberbeveiligingswet</link>
      <guid isPermaLink="false">https://grcide.com/radar#nl-cyberbeveiligingswet</guid>
      <pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate>
      <description>The Cyberbeveiligingswet and the Wet weerbaarheid kritieke entiteiten entered into force on 15 August 2026, and the decree carries no transitional law.</description>
    </item>
    <item>
      <title>HIPAA Security Rule: the rewrite moved to long-term actions on 14 August 2026</title>
      <link>https://grcide.com/radar#hipaa-security-rule-long-term-actions</link>
      <guid isPermaLink="false">https://grcide.com/radar#hipaa-security-rule-long-term-actions</guid>
      <pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
      <description>The 2026 Unified Agenda moved the HIPAA Security Rule rewrite out of the final rule stage and projected final action in July 2027, with no day set.</description>
    </item>
    <item>
      <title>China: police cyberspace security inspections apply from 1 October 2026</title>
      <link>https://grcide.com/radar#china-police-cyberspace-inspection</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-police-cyberspace-inspection</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <description>Order No. 176 replaces the 2018 internet inspection rules, holds routine on-site checks to one a year, and reuses another regulator's inspection result.</description>
    </item>
    <item>
      <title>EU AI Act: high-risk dates deferred, two prohibitions added</title>
      <link>https://grcide.com/radar#ai-act-high-risk-deferral</link>
      <guid isPermaLink="false">https://grcide.com/radar#ai-act-high-risk-deferral</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Digital Omnibus on AI moves the high-risk obligations to December 2027 and August 2028, and adds two prohibited practices from December 2026.</description>
    </item>
    <item>
      <title>Cyber Resilience Act: the Commission's application guidance, 27 July 2026</title>
      <link>https://grcide.com/radar#cra-commission-guidance</link>
      <guid isPermaLink="false">https://grcide.com/radar#cra-commission-guidance</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <description>C(2026) 5252 and its annex set out how the Commission reads scope, substantial modification, support periods and the reporting duties.</description>
    </item>
    <item>
      <title>EU AI Act: the transparency code and guidelines arrived before 2 August 2026</title>
      <link>https://grcide.com/radar#ai-act-transparency-code</link>
      <guid isPermaLink="false">https://grcide.com/radar#ai-act-transparency-code</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <description>The Code of Practice on Transparency of AI-generated Content closed on 10 June 2026, and the Commission's Article 50 guidelines followed on 20 July 2026.</description>
    </item>
    <item>
      <title>Japan: the 2026 amendment to the personal information act adds a surcharge</title>
      <link>https://grcide.com/radar#japan-appi-2026-amendment</link>
      <guid isPermaLink="false">https://grcide.com/radar#japan-appi-2026-amendment</guid>
      <pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate>
      <description>Promulgated 17 July 2026, the amending act adds a surcharge regime; one tranche is in force from 17 January 2027 and the rest await a Cabinet Order.</description>
    </item>
    <item>
      <title>China: rules for anthropomorphic AI interaction services, in force 15 July 2026</title>
      <link>https://grcide.com/radar#china-anthropomorphic-ai-services</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-anthropomorphic-ai-services</guid>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <description>Order No. 21 reaches AI that sustains emotional interaction, with a security assessment at a million registered users and algorithm filing verified each year.</description>
    </item>
    <item>
      <title>CER Directive: Swedish bill proposes entry into force on 1 January 2027</title>
      <link>https://grcide.com/radar#cer-directive-swedish-bill</link>
      <guid isPermaLink="false">https://grcide.com/radar#cer-directive-swedish-bill</guid>
      <pubDate>Tue, 14 Jul 2026 00:00:00 +0000</pubDate>
      <description>Sweden's bill implementing the critical entities resilience directive was laid before the Riksdag on 14 July 2026, proposing effect from 1 January 2027.</description>
    </item>
    <item>
      <title>ISO replaced the ISMS overview standard and the auditing guidelines in 2026</title>
      <link>https://grcide.com/radar#iso-27000-19011-2026</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-27000-19011-2026</guid>
      <pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate>
      <description>ISO/IEC 27000:2026 was published on 3 July 2026 and ISO 19011:2026 in May 2026, withdrawing the editions an older audit file cites.</description>
    </item>
    <item>
      <title>China: the cybersecurity label scheme took effect on 1 July 2026</title>
      <link>https://grcide.com/radar#china-cybersecurity-label</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-cybersecurity-label</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>A voluntary three-star label rates a connected product's security, filed with a designated body and scannable to the test report and conformity declaration.</description>
    </item>
    <item>
      <title>China: the personal information audit standard applies from 1 July 2026</title>
      <link>https://grcide.com/radar#china-pi-audit-standard</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-pi-audit-standard</guid>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate>
      <description>GB/T 46903-2025 took effect on 1 July 2026, giving the compliance audit already required of large processors a published national method.</description>
    </item>
    <item>
      <title>China: guidance on AI in banking and insurance, issued 18 June 2026</title>
      <link>https://grcide.com/radar#china-nfra-ai-banking-insurance-guidance</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-nfra-ai-banking-insurance-guidance</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate>
      <description>Thirty-two items put AI in banks and insurers under a board committee, a graded application inventory, and risk committee approval for high-risk uses.</description>
    </item>
    <item>
      <title>Cyber Resilience Act: manufacturer reporting starts on 11 September 2026</title>
      <link>https://grcide.com/radar#cra-reporting-obligations</link>
      <guid isPermaLink="false">https://grcide.com/radar#cra-reporting-obligations</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>Article 14 applies from 11 September 2026, ahead of full application on 11 December 2027, and it reaches products already placed on the market.</description>
    </item>
    <item>
      <title>NIST reissued the ransomware profile against CSF 2.0</title>
      <link>https://grcide.com/radar#nist-ransomware-profile</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-ransomware-profile</guid>
      <pubDate>Thu, 11 Jun 2026 00:00:00 +0000</pubDate>
      <description>NIST IR 8374 Revision 1 was published in June 2026 and supersedes the 2022 ransomware profile, which predates the six-Function Core.</description>
    </item>
    <item>
      <title>UN Regulation No 156: amendments binding on applying Contracting Parties from 4 June 2026</title>
      <link>https://grcide.com/radar#un-r156-amendments-2026</link>
      <guid isPermaLink="false">https://grcide.com/radar#un-r156-amendments-2026</guid>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <description>In force since 22 January 2021; amended by ECE/TRANS/WP.29/2025/142, binding on applying Contracting Parties from 4 June 2026 per the UN depositary record.</description>
    </item>
    <item>
      <title>China: implementation opinion on AI agents, issued 8 May 2026</title>
      <link>https://grcide.com/radar#china-ai-agents-implementation-opinion</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-ai-agents-implementation-opinion</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate>
      <description>Thirty-eight tasks for AI agents: a registration platform carrying digital identity, a permission boundary, anomaly tooling and graded sector treatment.</description>
    </item>
    <item>
      <title>EDPB: the Board approved a Chapter V transfer certification on 15 April 2026</title>
      <link>https://grcide.com/radar#edpb-europrivacy-transfer-seal</link>
      <guid isPermaLink="false">https://grcide.com/radar#edpb-europrivacy-transfer-seal</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
      <description>Two opinions adopted on 15 April 2026 approve an updated European Data Protection Seal and, separately, one usable as an Article 46(2)(f) transfer tool.</description>
    </item>
    <item>
      <title>Korea: the PIPA amendment adds a ten per cent surcharge tier from 11 September 2026</title>
      <link>https://grcide.com/radar#korea-pipa-2026-amendment</link>
      <guid isPermaLink="false">https://grcide.com/radar#korea-pipa-2026-amendment</guid>
      <pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate>
      <description>Act No. 21445, promulgated 10 March 2026, is in force from 11 September 2026, with a ten per cent turnover tier and a board resolution for the privacy officer.</description>
    </item>
    <item>
      <title>China: the 2026 automotive data export guidance, issued 30 January 2026</title>
      <link>https://grcide.com/radar#china-automotive-data-export-guidance</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-automotive-data-export-guidance</guid>
      <pubDate>Fri, 30 Jan 2026 00:00:00 +0000</pubDate>
      <description>Eight departments set nine export exemptions for automotive data, scenario rules for judging important data, and three-year tamper-proof log retention.</description>
    </item>
    <item>
      <title>NIS2: Sweden's Cybersecurity Act took effect on 15 January 2026</title>
      <link>https://grcide.com/radar#nis2-swedish-cybersecurity-act</link>
      <guid isPermaLink="false">https://grcide.com/radar#nis2-swedish-cybersecurity-act</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 +0000</pubDate>
      <description>Cybersäkerhetslag (2025:1506) entered into force on 15 January 2026, fifteen months after the directive's transposition date of 17 October 2024.</description>
    </item>
    <item>
      <title>China: the amended Cybersecurity Law took effect on 1 January 2026</title>
      <link>https://grcide.com/radar#china-cybersecurity-law-amendment</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-cybersecurity-law-amendment</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate>
      <description>Presidential Order No. 61 adds an artificial intelligence article to the Cybersecurity Law and sets the top penalty on an operator at ten million yuan.</description>
    </item>
    <item>
      <title>GB 44495-2024 and GB 44496-2024 took effect in China on 1 January 2026</title>
      <link>https://grcide.com/radar#gb-44495-44496-in-force</link>
      <guid isPermaLink="false">https://grcide.com/radar#gb-44495-44496-in-force</guid>
      <pubDate>Thu, 01 Jan 2026 00:00:00 +0000</pubDate>
      <description>China's mandatory vehicle cybersecurity and software-update standards moved from issued to in force on 1 January 2026, seventeen months after publication.</description>
    </item>
    <item>
      <title>Vietnam: Decree 356/2025 replaced the 2023 data protection decree on 1 January 2026</title>
      <link>https://grcide.com/radar#vietnam-pdpl-decree-356</link>
      <guid isPermaLink="false">https://grcide.com/radar#vietnam-pdpl-decree-356</guid>
      <pubDate>Wed, 31 Dec 2025 00:00:00 +0000</pubDate>
      <description>Issued on 31 December 2025 and in force the next day, the decree sets the dossier forms, widens the transfer exemptions and repeals Decree 13/2023.</description>
    </item>
    <item>
      <title>India: the DPDP Rules stage their own commencement from 13 November 2025</title>
      <link>https://grcide.com/radar#india-dpdp-rules-2025</link>
      <guid isPermaLink="false">https://grcide.com/radar#india-dpdp-rules-2025</guid>
      <pubDate>Thu, 13 Nov 2025 00:00:00 +0000</pubDate>
      <description>G.S.R. 846(E) splits commencement three ways: part on publication, consent managers a year on, and the working obligations eighteen months on.</description>
    </item>
    <item>
      <title>ISO/IEC 27001:2013 certificates stopped being valid after 31 October 2025</title>
      <link>https://grcide.com/radar#iso-27001-2022-transition-closed</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-27001-2022-transition-closed</guid>
      <pubDate>Fri, 31 Oct 2025 00:00:00 +0000</pubDate>
      <description>The accredited transition period set by IAF MD 26 ended on 31 October 2025; certificates naming the 2013 edition expire or are withdrawn.</description>
    </item>
    <item>
      <title>China: the personal information export certification measures, in force 1 January 2026</title>
      <link>https://grcide.com/radar#china-pi-export-certification</link>
      <guid isPermaLink="false">https://grcide.com/radar#china-pi-export-certification</guid>
      <pubDate>Tue, 14 Oct 2025 00:00:00 +0000</pubDate>
      <description>Order No. 20 gives the certification route its own rules: who may use it, a three-year certificate, and a bar on splitting volumes to dodge the assessment.</description>
    </item>
    <item>
      <title>California: the CCPA regulations put dates on audits, risk assessments and ADMT</title>
      <link>https://grcide.com/radar#california-ccpa-audit-admt-regulations</link>
      <guid isPermaLink="false">https://grcide.com/radar#california-ccpa-audit-admt-regulations</guid>
      <pubDate>Mon, 22 Sep 2025 00:00:00 +0000</pubDate>
      <description>Approved on 22 September 2025 and effective 1 January 2026, the package dates ADMT compliance at 2027, first audit reports at 2028 and later.</description>
    </item>
    <item>
      <title>ISO/IEC 42006:2025 completes the certification route for AI management systems</title>
      <link>https://grcide.com/radar#iso-42006-certification-route</link>
      <guid isPermaLink="false">https://grcide.com/radar#iso-42006-certification-route</guid>
      <pubDate>Mon, 07 Jul 2025 00:00:00 +0000</pubDate>
      <description>The requirements standard for bodies auditing AI management systems was published on 7 July 2025, alongside the impact-assessment standard of May 2025.</description>
    </item>
    <item>
      <title>DORA: the subcontracting technical standard was published on 2 July 2025</title>
      <link>https://grcide.com/radar#dora-subcontracting-rts</link>
      <guid isPermaLink="false">https://grcide.com/radar#dora-subcontracting-rts</guid>
      <pubDate>Wed, 02 Jul 2025 00:00:00 +0000</pubDate>
      <description>Delegated Regulation (EU) 2025/532 sets what a financial entity must determine before ICT services supporting critical or important functions are subcontracted.</description>
    </item>
    <item>
      <title>Vietnam: the personal data protection law has been in force since 1 January 2026</title>
      <link>https://grcide.com/radar#vietnam-personal-data-protection-law</link>
      <guid isPermaLink="false">https://grcide.com/radar#vietnam-personal-data-protection-law</guid>
      <pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate>
      <description>Law No. 91/2025/QH15, passed on 26 June 2025, took effect on 1 January 2026 and caps cross-border transfer fines at five per cent of turnover.</description>
    </item>
    <item>
      <title>UN Regulation No 155: Supplement 3 entered into force on 10 January 2025</title>
      <link>https://grcide.com/radar#un-r155-supplement-3</link>
      <guid isPermaLink="false">https://grcide.com/radar#un-r155-supplement-3</guid>
      <pubDate>Fri, 10 Jan 2025 00:00:00 +0000</pubDate>
      <description>The consolidated R155 text republished in the Official Journal as 2025/5 incorporates all valid text up to Supplement 3 to the original version.</description>
    </item>
    <item>
      <title>Chile: Ley N° 21.719 is in force from 1 December 2026</title>
      <link>https://grcide.com/radar#chile-ley-21719</link>
      <guid isPermaLink="false">https://grcide.com/radar#chile-ley-21719</guid>
      <pubDate>Fri, 13 Dec 2024 00:00:00 +0000</pubDate>
      <description>Published on 13 December 2024, the law rewrites Chile's data protection regime and creates a supervisory agency, in force from 1 December 2026.</description>
    </item>
    <item>
      <title>NIST CSF 2.0 restructured the Core around six Functions</title>
      <link>https://grcide.com/radar#nist-csf-2-0</link>
      <guid isPermaLink="false">https://grcide.com/radar#nist-csf-2-0</guid>
      <pubDate>Mon, 26 Feb 2024 00:00:00 +0000</pubDate>
      <description>The Cybersecurity Framework 2.0 was published on 26 February 2024 as NIST CSWP 29, with Govern at the centre of a six-Function Core.</description>
    </item>
    <item>
      <title>EU Data Act: switching charges end on 12 January 2027</title>
      <link>https://grcide.com/radar#eu-data-act-switching-charges</link>
      <guid isPermaLink="false">https://grcide.com/radar#eu-data-act-switching-charges</guid>
      <pubDate>Wed, 13 Dec 2023 00:00:00 +0000</pubDate>
      <description>Article 29 bars any switching charge for cloud and other data processing services from 12 January 2027, and already caps the reduced charges allowed until then.</description>
    </item>
  </channel>
</rss>
