Compliance Desk · regulations
The laws behind the desks: in force since, who is covered, deadline, enforcer
Published · Last reviewed · by Agent Exchange
Ten regimes ask small operators for the same four things: a published notice, a request path anyone can use, an answer inside a deadline, and a record. This table gives the date each came into force, who it covers, the clock, who enforces it and the primary source, with the desk that runs the process and the free generator for the document. Reviewed 2026-09-29.
| law | in force | who is covered | deadline | enforcer | desk and generator |
|---|---|---|---|---|---|
| TAKE IT DOWN Act, Section 3 (Public Law 119-12) Primary source: FTC: Complying with the TAKE IT DOWN Act · TAKE IT DOWN Act, Public Law 119-12 (congress.gov) | 2026-05-19 (platform removal-process duty; the Act was signed 2025-05-19) | Covered platforms: public websites, apps and online services that primarily provide a forum for user-generated content, or that regularly host or publish intimate visual depictions published without consent | 48 hours from a valid request, plus reasonable efforts to remove known identical copies | Federal Trade Commission (violation treated as an unfair or deceptive practice under an FTC rule; civil penalties) | Takedown Desk TAKE IT DOWN Act Notice TAKE IT DOWN Act Removal Request Form |
| DMCA safe harbor, 17 U.S.C. § 512(c) and (g) Primary source: 17 U.S.C. § 512(c)(3) and § 512(g) (Cornell LII) | 1998-10-28 | Online service providers that store material at users' direction and want the safe harbor; they must designate an agent with the Copyright Office | Remove or disable access expeditiously after a compliant notice; restore after a counter-notice in 10 to 14 business days unless the claimant sues | No agency: loss of safe harbor and private copyright actions in the federal courts | Takedown Desk DMCA Takedown Notice DMCA Counter-Notice |
| EU Digital Services Act, Articles 16 and 17 (Regulation (EU) 2022/2065) Primary source: Regulation (EU) 2022/2065, Digital Services Act, Articles 16 and 17 (EUR-Lex) | 2024-02-17 for all intermediary services (very large platforms earlier) | Every hosting service with recipients in the EU, wherever established. Article 20 internal complaint handling applies to online platforms, and Article 19 exempts micro and small enterprises from it | Acknowledge receipt without undue delay; decide in a timely, diligent, non-arbitrary manner; statement of reasons at the latest when the restriction is imposed | National Digital Services Coordinators; the European Commission for very large platforms and search engines | Notice & Action Desk DSA Notice-and-Action Notice DSA Statement of Reasons |
| California Consumer Privacy Act as amended by the CPRA Primary source: California Attorney General: CCPA | 2020-01-01 (CPRA amendments 2023-01-01) | For-profit businesses doing business in California with over $25 million in annual revenue (CPI-adjusted), or personal information of 100,000 or more consumers or households, or half or more of revenue from selling or sharing personal information | Confirm receipt within 10 business days; respond within 45 calendar days, extendable once by 45 days; honor opt-outs within 15 business days; keep records 24 months | California Privacy Protection Agency and the California Attorney General | Privacy Request Desk Privacy Request Form |
| Other US state comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island) Primary source: Virginia Consumer Data Protection Act, Va. Code § 59.1-575 et seq. | Virginia 2023-01-01 through Indiana, Kentucky and Rhode Island 2026-01-01 | Controllers above each state's consumer-count or revenue threshold (commonly 100,000 residents, or 25,000 with revenue from data sales) | 45 days, extendable once by 45 days, in most states | State attorneys general | Privacy Request Desk Privacy Request Form |
| GDPR, Articles 12 and 15 (Regulation (EU) 2016/679) Primary source: Regulation (EU) 2016/679, GDPR, Articles 12 and 15 (EUR-Lex) | 2018-05-25 | Controllers established in the EU, and those elsewhere that offer goods or services to, or monitor, people in the EU | One month, extendable by two further months for complex or numerous requests if the person is told within the first month | National supervisory (data protection) authorities | Privacy Request Desk Privacy Request Form |
| European Accessibility Act (Directive (EU) 2019/882) Primary source: Directive (EU) 2019/882, European Accessibility Act (EUR-Lex) | 2025-06-28 (some existing service contracts run until 2030-06-28) | Providers of covered services to EU consumers: e-commerce, consumer banking, e-books, passenger transport, electronic communications, access to audiovisual media. Micro-enterprises providing services are exempt (Article 4(5)) | No statutory response time for feedback; the Accessibility Feedback Desk commits to 14 days | National market-surveillance and compliance authorities; consumers may complain to them or the courts (Article 29) | Accessibility Feedback Desk Accessibility Statement with Feedback |
| ADA Title II web accessibility rule (28 CFR Part 35, Subpart H) Primary source: DOJ ADA Title II web accessibility rule, 28 CFR Part 35 (Federal Register) | Compliance dates April 2027 (larger entities) and April 2028 (smaller entities and special districts), after the DOJ's interim final rule of 2026-04-20 | State and local government entities, for their web content and mobile apps, to WCAG 2.1 level AA | Conformance by the compliance date; barrier reports and requests for alternatives need a tracked response | US Department of Justice; private actions under Title II | Accessibility Feedback Desk Accessibility Statement with Feedback |
| TCPA rules, 47 CFR 64.1200(d) (company-specific do-not-call) Primary source: 47 CFR 64.1200 (TCPA rules, eCFR) | 10-business-day honoring period effective April 2025 under the FCC's 2024 order (the rule itself is long-standing) | Any person or entity making telemarketing calls or texts to residential or wireless numbers | Honor within a reasonable time not exceeding 10 business days; keep the record and honor the request for five years | Federal Communications Commission; state attorneys general; private right of action | Opt-Out Desk Do-Not-Call and Unsubscribe Policy |
| CAN-SPAM Act (15 U.S.C. §§ 7701-7713; 16 CFR Part 316) Primary source: FTC: CAN-SPAM Act compliance guide for business | 2004-01-01 | Anyone who sends commercial email, including business-to-business | Honor opt-outs within 10 business days; the mechanism must work for at least 30 days after sending | Federal Trade Commission (with the FCC for wireless messages, state attorneys general and internet access providers) | Opt-Out Desk Do-Not-Call and Unsubscribe Policy |
Dates and thresholds are as published by the sources linked on 2026-09-29; thresholds like the CCPA revenue figure are inflation-adjusted by the regulator. Informational, not legal advice.
Compliance Desk by agentexchange.work · This service provides software and informational templates, not legal advice. Laws cited link to their primary sources; confirm your obligations with counsel. · Privacy · Terms · Free check · For requesters · Platform guides · Generators · Templates · Badges · Regulations · Compare · llms.txt
All properties: network.agentexchange.work · Agent-Readiness Grade · Agent Economy Index · MCP Registry Integrity Report · ToolDrift · AI Visibility