Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed Executive Order "Ending Certain Tariff Actions" on 20 February 2026 (Federal Register doc 2026-03832, published 25 February 2026), terminating the additional ad-valorem duties imposed under nine prior IEEPA-based executive orders. The order followed within hours of the US Supreme Court's 6-3 decision the same day in Learning Resources, Inc. v. Trump, 607 U.S. ___ (2026), holding that the International Emergency Economic Powers Act does not authorize the President to impose tariffs and vacating the Trump 2.0 IEEPA tariff regime. The EO directs CBP to cease collection "as soon as practicable"; CSMS guidance set the collection-end date at 12:00 a.m. eastern on 24 February 2026. The order explicitly preserves all underlying national-emergency declarations and all non-IEEPA trade actions — Section 232 of the Trade Expansion Act, Section 301 of the Trade Act, Section 122 of the Trade Act, and Section 201 — so the Section 232 cascade and the paired Section 122 10% temporary surcharge (effective 24 Feb 2026) remain in force. This is the first SCOTUS-driven repeal of a presidential tariff regime in the modern era and recalibrates the entire post-2024 US tariff architecture by removing IEEPA as a legal pillar.
Presidential Decision No. 10767, published in the Official Gazette (Resmî Gazete, Issue No. 33118) on 25 December 2025, re-sets the Digital Services Tax (Dijital Hizmet Vergisi, DHV) rate under Article 5(3) of Law No. 7194. The rate, set at 7.5% since the tax's 2020 introduction, is reduced to 5% for revenue generated from 1 January 2026 and to 2.5% for revenue generated from 1 January 2027. The tax applies to gross Turkish-sourced revenue of digital-service providers (online advertising, content sales, social-media/intermediary platforms) exceeding statutory turnover thresholds, and falls predominantly on large non-resident platform operators (Google, Meta, Amazon and comparable multinationals).
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Canada announced on 29 June 2025 that it would rescind the Digital Services Tax Act (originally enacted 20 June 2024) to revive US-Canada trade negotiations after President Trump suspended talks on 27 June, citing the 3% DST on large digital-services revenues as a discriminatory measure against US technology firms. The Canada Revenue Agency halted collection effective 30 June 2025, and legislation to retroactively repeal the Act back to its June 2024 enactment date is to follow, with refunds — plus interest at the standard corporate tax refund rate — to be paid to affected taxpayers including US technology majors.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
Regulation (EU) 2025/40, published in the Official Journal on 22 January 2025 and entering into force on 11 February 2025, replaces the 1994 Packaging and Packaging Waste Directive 94/62/EC with a directly-applicable Regulation. It mandates binding recycled-content targets for plastic packaging (by polymer and format, reaching 30–65% by 2030 with higher targets by 2040), minimum reusable-packaging shares for beverages and transport, recyclability standards for all packaging placed on the EU market from 2030, deposit-return-scheme obligations for beverage containers from 2029, and bans on specified single-use plastic packaging formats. General application begins 12 August 2026, with staggered compliance windows extending to 2030 and beyond, affecting all non-EU exporters shipping consumer goods, beverages, or e-commerce fulfilment into the EU single market.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
India's Finance (No. 2) Act, 2024 (Act No. 15 of 2024) repeals the 2% Equalisation Levy on e-commerce supplies and services by non-resident operators (§165A of the Finance Act 2016, introduced 2020), with effect from 1 August 2024. The repeal removes a long-standing US trade irritant — the USTR had found the 2% levy unreasonable under a Section 301 investigation, and India agreed in October 2021 to remove it as part of a multilateral OECD Pillar 1 commitment, formally implemented here three years later. The residual 6% Equalisation Levy on digital advertising under §165 (in force since 2016) was not touched by this Act and remained in force until its own repeal effective 1 April 2025 via a subsequent Finance Act.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.