Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 19 March 2026 the UK Office of Financial Sanctions Implementation (OFSI), part of HM Treasury, imposed a £390,000 monetary penalty on Apple Distribution International Limited (ADI), the Ireland-incorporated subsidiary of Apple Inc. The penalty relates to two payments totalling approximately £635,000 made in 2022 to Okko LLC, a sanctioned Russian app developer, for App Store revenue. ADI's failure to cancel the payments amounted to conduct in the UK that breached regulation 12 of the Russia (Sanctions) (EU Exit) Regulations 2019, which prohibits making funds available to a person owned or controlled by a designated person. The enforcement is notable as the **first use of OFSI's new settlement mechanism** (introduced February 2026), which allows OFSI and a subject of an enforcement action to resolve a civil monetary penalty case via time-bound negotiation. OFSI applied a 35% discount to the £600,000 baseline penalty to reach the £390,000 final figure, reflecting ADI's voluntary self-disclosure (made 4 October 2022) and cooperation.
President Trump signed Executive Order "Ending Certain Tariff Actions" on 20 February 2026 (Federal Register doc 2026-03832, published 25 February 2026), terminating the additional ad-valorem duties imposed under nine prior IEEPA-based executive orders. The order followed within hours of the US Supreme Court's 6-3 decision the same day in Learning Resources, Inc. v. Trump, 607 U.S. ___ (2026), holding that the International Emergency Economic Powers Act does not authorize the President to impose tariffs and vacating the Trump 2.0 IEEPA tariff regime. The EO directs CBP to cease collection "as soon as practicable"; CSMS guidance set the collection-end date at 12:00 a.m. eastern on 24 February 2026. The order explicitly preserves all underlying national-emergency declarations and all non-IEEPA trade actions — Section 232 of the Trade Expansion Act, Section 301 of the Trade Act, Section 122 of the Trade Act, and Section 201 — so the Section 232 cascade and the paired Section 122 10% temporary surcharge (effective 24 Feb 2026) remain in force. This is the first SCOTUS-driven repeal of a presidential tariff regime in the modern era and recalibrates the entire post-2024 US tariff architecture by removing IEEPA as a legal pillar.
President Trump signed a Presidential Proclamation on 20 February 2026 invoking Section 122 of the Trade Act of 1974 (19 U.S.C. § 2132) to impose a temporary 10% ad-valorem import surcharge on articles imported into the United States, effective 12:01 a.m. EST on 24 February 2026. The proclamation was issued within hours of the US Supreme Court's 20 February 2026 ruling in Learning Resources, Inc. v. Trump, which held that the International Emergency Economic Powers Act (IEEPA) does not authorize the president to set tariffs and vacated the IEEPA-based reciprocal-tariff regime previously in effect. The Section 122 surcharge is statutorily limited to 150 days (terminates 24 July 2026 absent Congressional extension) and the statute caps any such surcharge at 15% ad valorem. Goods qualifying as USMCA originating from Canada or Mexico are exempt; CAFTA-DR textile/apparel articles meeting specified rules of origin are exempt; and a substantial product-exception list excludes critical minerals, energy products, certain pharmaceuticals, electronics, vehicles, aerospace products, specified agricultural goods, and goods already subject to Section 232 duties (the Section 122 duty does not stack on Section 232).
On 9 February 2026 the UK Office of Financial Sanctions Implementation (OFSI) published a comprehensively revised enforcement and monetary-penalties guidance following its July–October 2025 public consultation. The update introduces a Settlement Scheme (20% penalty discount for subjects who agree not to contest OFSI's findings within 30 business days), an Early Account Scheme (up to 20% discount for legal persons providing a timely senior-attested factual account), a revised voluntary-disclosure framework (maximum discount cut from 50% to 30% and renamed to cover both prompt self-reporting and full cooperation), a four-level case-assessment seriousness matrix (severity × conduct), and fixed monetary penalties of £5,000 and £10,000 for information, reporting, and licensing offences. A planned legislative amendment (requiring primary legislation) will subsequently double the statutory civil monetary-penalty cap from £1m / 50%-of-breach to £2m / 100%-of-breach; in the interim the Policing and Crime Act 2017 caps remain in force. The revised guidance is the foundational enforcement architecture for all UK financial-sanctions programs (Russia, Iran, DPRK, Syria, Belarus, Myanmar, and 10+ additional regimes).
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
Canada announced on 29 June 2025 that it would rescind the Digital Services Tax Act (originally enacted 20 June 2024) to revive US-Canada trade negotiations after President Trump suspended talks on 27 June, citing the 3% DST on large digital-services revenues as a discriminatory measure against US technology firms. The Canada Revenue Agency halted collection effective 30 June 2025, and legislation to retroactively repeal the Act back to its June 2024 enactment date is to follow, with refunds — plus interest at the standard corporate tax refund rate — to be paid to affected taxpayers including US technology majors.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 10–11 May 2025 in Geneva, US Treasury Secretary Scott Bessent and USTR Jamieson Greer met with PRC Vice Premier He Lifeng and on 12 May 2025 issued the "Joint Statement on US-China Economic and Trade Meeting in Geneva," producing the first bilateral de-escalation of the post-2 April 2025 reciprocal-tariff stand-off. The agreement was implemented on the US side via Executive Order 14298 of 12 May 2025 ("Modifying Reciprocal Tariff Rates To Reflect Discussions With the People's Republic of China," published in the Federal Register 21 May 2025 as 90 FR 21831 / 2025-09297) and on the Chinese side via State Council Tariff Commission Announcement No. 4 of 2025. Effective 12:01 a.m. EDT on 14 May 2025, both sides suspended for 90 days (through 12 August 2025) the 24 percentage points of additional ad valorem duty layered on top of the prior 10% reciprocal rate, while the 10% reciprocal rate itself was retained. On the US side this reduced the headline reciprocal-tariff burden on PRC-origin goods from a 125% scheduled rate (under EOs 14259 and 14266) to 10%; combined with the still-in-force 20% IEEPA-fentanyl tariff under Executive Order 14195 (separately filed: `2025-02-01-us-trump-fentanyl-tariffs-canada-mexico-china`), the effective additional rate on most Chinese imports came down to ~30%. China made a parallel 24pp suspension on US-origin goods (from a 125% retaliatory rate to 10%) and additionally suspended non-tariff countermeasures imposed since 2 April 2025 (export controls, unreliable-entity designations, MOFCOM probes). The truce is structurally a calibrated freeze of the reciprocal-tariff ladder under the April 2025 regime, not a repeal: the underlying EO 14257 / IEEPA framework remains intact and was scheduled to re-engage at the 24pp escalated rate on 12 August 2025 absent further extension. The Geneva agreement is the precursor to the August 2025 Stockholm extension and the October 2025 Busan Economic and Trade Arrangement (separately filed: `2025-10-30-us-china-busan-economic-trade-arrangement`).
President Trump signed Executive Order 14257 on 2 April 2025 declaring a national emergency over US trade deficits and imposing a baseline 10% ad-valorem tariff on imports from nearly all trading partners effective 5 April, with higher country-specific "reciprocal" rates effective 9 April. The rate schedule was constructed from a formula tied to bilateral goods-trade deficits and ranged from 10% (UK, Singapore, Brazil, Australia, others) through 20% (EU), 24% (Japan), 25% (Korea), 32% (Taiwan, Indonesia, Switzerland), 34% (China, later raised to 84% then 125% during the April escalation), 46% (Vietnam), 49% (Cambodia). Multiple subsequent EOs paused the country-specific rates for 90 days for non-China destinations on 9 April while keeping the 10% baseline, pending bilateral negotiations.
President Trump signed three Executive Orders on 1 February 2025 (EO 14193, 14194, 14195) declaring national emergencies under IEEPA over the cross-border flow of fentanyl + illegal migration, and using that authority to impose new tariffs: 25% on imports from Canada (with a reduced 10% rate on Canadian energy products), 25% on imports from Mexico, and an additional 10% on imports from China (separate from pre-existing Section 301 + Section 232 tariffs). The tariffs took effect 4 February 2025. On 3 February 2025 the administration announced a 30-day pause for both Canada and Mexico following bilateral border-enforcement commitments; the China tariff was not paused. China responded 4 February with retaliatory tariffs of 15% on US LNG/coal/farm equipment and additional measures. The package set the precedent for the broader 2 April 2025 "Liberation Day" reciprocal-tariff regime (filed: 2025-04-02-us-trump-reciprocal-tariff-regime).
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Regulation (EU) 2024/1781, the Ecodesign for Sustainable Products Regulation (ESPR), replaces the 2009 Ecodesign Directive with a cross-cutting product-sustainability framework covering nearly all physical goods placed on the EU single market. It empowers the Commission to adopt binding delegated acts setting ecodesign requirements (durability, reparability, recyclability, recycled content, chemical restrictions, energy and resource efficiency) by product category, establishes a mandatory Digital Product Passport (DPP) for supply-chain traceability, and bans the destruction of unsold consumer products. The regulation entered into force on 18 July 2024; the Commission's first ESPR and Energy Labelling Working Plan (2025–2030, COM(2025) 187) was adopted in April 2025, prioritising textiles, furniture, tyres, electronics, and iron/steel/aluminium.
The Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA), enacted as Division H of P.L. 118-50 (21st Century Peace through Strength Act), prohibits app stores and internet hosting services from distributing, maintaining, or updating "foreign adversary controlled applications" — defined explicitly to include ByteDance Ltd and its subsidiaries (TikTok). ByteDance was given 270 days from enactment (until January 19, 2025) to execute a "qualified divestiture" — selling TikTok to an owner with no operational relationship with a foreign adversary — or face a nationwide distribution ban. The Supreme Court unanimously upheld the law's constitutionality in TikTok, Inc. v. Garland (January 17, 2025), rejecting First Amendment challenges and affirming the national-security rationale grounded in data-collection concerns.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Regulation (EU) 2023/1542 establishes a comprehensive EU statutory framework for all battery categories (portable, SLI, LMT, EV, industrial), imposing supply-chain due-diligence obligations for cobalt, lithium, nickel, and natural graphite; mandatory recycled-content thresholds; carbon-footprint declarations; a digital battery passport; and ambitious collection and recycling-efficiency targets, with rolling application dates running from February 2024 through August 2036. It repeals Battery Directive 2006/66/EC and applies to every economic operator placing batteries on the EU market, binding every EV, consumer-electronics, and stationary-storage supply chain that relies on DRC cobalt, Australian/Chilean lithium, Indonesian/Philippine nickel, and Chinese/Mozambican graphite.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
The Bureau of Industry and Security (BIS) added 31 Chinese entities — including Yangtze Memory Technologies Co., Ltd. (YMTC), China's largest NAND flash manufacturer — to the Unverified List (UVL), suspending license exceptions and requiring end-user statements for all EAR-controlled items destined to these parties. BIS simultaneously removed nine Chinese entities previously on the UVL after successfully completing end-use checks. The rule also established a new 60-day UVL-to-Entity-List escalation clock and clarified that sustained host-government obstruction of end-use checks constitutes independent grounds for Entity List designation — a structural enforcement change aimed at closing China's pattern of blocking BIS post-shipment verification visits.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.