Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The Department of Commerce's International Trade Administration published a Federal Register notice on 10 April 2026 (91 FR 18412, doc 2026-06952) opening the inaugural Call for Proposals for the American AI Exports Program established under Executive Order 14320. Proposals are accepted from 1 April 2026 through 5:00 pm EDT on 30 June 2026 from US industry-led "pre-set" consortia offering full-stack American AI export packages — AI-optimised hardware, data pipelines, AI models and systems, security and cybersecurity measures, and sector-specific applications — for presentation by the US government to foreign public- and private-sector buyers. Designated consortia receive priority US-government advocacy, priority consideration for export-control licence engagement, interagency coordination, and federal-financing referrals (EXIM, DFC), with a 14-business-day completeness review and 60-calendar-day designation decision once a proposal is deemed complete.
On 31 March 2026 the Government of Vietnam issued Decree 96/2026/ND-CP, the principal implementing decree for the Law on Investment 2025 (Law 143/2025/QH15). It takes effect on its signing date and replaces Decree 31/2021/ND-CP, Decree 19/2025/ND-CP and Decree 239/2025/ND-CP — the first comprehensive overhaul of Vietnam's general FDI-licensing framework since 2021. The decree operationalises the new Special Investment Procedure (a registration-and-commitment fast-track in industrial parks, export-processing zones, hi-tech parks, concentrated digital- technology zones, free-trade zones, international financial centres and economic-zone functional areas) and details the list of 16 specially-incentivised sectors covering semiconductor and chip manufacturing, AI, big data, digital technology and high-tech R&D. It also rewrites foreign-investor market-access conditions, document procedures and dispute / grievance mechanisms.
Presidential Decision No. 10767, published in the Official Gazette (Resmî Gazete, Issue No. 33118) on 25 December 2025, re-sets the Digital Services Tax (Dijital Hizmet Vergisi, DHV) rate under Article 5(3) of Law No. 7194. The rate, set at 7.5% since the tax's 2020 introduction, is reduced to 5% for revenue generated from 1 January 2026 and to 2.5% for revenue generated from 1 January 2027. The tax applies to gross Turkish-sourced revenue of digital-service providers (online advertising, content sales, social-media/intermediary platforms) exceeding statutory turnover thresholds, and falls predominantly on large non-resident platform operators (Google, Meta, Amazon and comparable multinationals).
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
On 18 September 2025 Brazil's federal government published Medida Provisória (Provisional Measure) 1318/2025, creating REDATA — the Special Taxation Regime for Datacenter Services — alongside a parallel IT-export regime (REPES). REDATA zeroes federal taxes on servers, storage, networking, cooling and other datacenter capital equipment for qualifying operators from 1 January 2026, conditioned on 100% renewable/zero-carbon energy sourcing, a 2% of investment R&D-in-Brazil commitment, and preferential use of Brazilian- manufactured components. The Finance Ministry projects R$5.2 billion in forgone-tax incentives in 2026 alone, with potential to unlock up to R$2 trillion in private datacenter investment over ten years. REDATA is framed as implementing the National Datacenter Policy (PNDC) under the Nova Indústria Brasil industrial-policy umbrella.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Canada announced on 29 June 2025 that it would rescind the Digital Services Tax Act (originally enacted 20 June 2024) to revive US-Canada trade negotiations after President Trump suspended talks on 27 June, citing the 3% DST on large digital-services revenues as a discriminatory measure against US technology firms. The Canada Revenue Agency halted collection effective 30 June 2025, and legislation to retroactively repeal the Act back to its June 2024 enactment date is to follow, with refunds — plus interest at the standard corporate tax refund rate — to be paid to affected taxpayers including US technology majors.
On 26 June 2025 President Bola Ahmed Tinubu signed four acts constituting Nigeria's most comprehensive fiscal overhaul in decades: the Nigeria Tax Act 2025 (NTA), Nigeria Tax Administration Act 2025 (NTAA), Nigeria Revenue Service (Establishment) Act 2025, and Joint Revenue Board (Establishment) Act 2025. The NTA consolidates and repeals six core statutes — CITA, PITA, PPTA, VAT Act, CGT Act, and Stamp Duties Act — into a single unified code effective 1 January 2026, while the NTAA standardises assessment, filing, and enforcement procedures across all federal taxes. The two establishment acts restructure the Federal Inland Revenue Service (FIRS) into the Nigeria Revenue Service (NRS) with a broadened mandate and create an empowered Joint Revenue Board to coordinate federal-state fiscal relations.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 13 May 2025, two days before the AI Diffusion Rule's primary 15 May 2025 compliance date, the Trump administration's BIS announced it would rescind the Biden-era Framework for AI Diffusion (90 FR 4544) and simultaneously issued three guidance documents that re-routed US AI export policy through existing EAR authorities. The package comprises (1) GP10 guidance asserting that all ECCN 3A090 ICs designed by PRC-headquartered firms are presumptively EAR-violative, with Huawei Ascend 910B/910C/910D processors named explicitly — making US- and non-US-person use, transfer, financing, or servicing of those chips anywhere in the world a presumptive General Prohibition 10 violation; (2) a policy statement warning industry that supplying US advanced computing ICs for training or inference of Chinese AI models risks EAR enforcement; and (3) industry guidance on diversion-prevention diligence. BIS stated a formal Federal Register rescission and replacement rule would follow.
On 9 April 2025 the European Commission adopted Communication COM(2025)165, the AI Continent Action Plan, setting out a five-pillar strategy to make the EU a global AI leader. The pillars are (1) computing infrastructure, (2) data for AI, (3) strategic AI innovation and adoption, (4) AI skills and talent, and (5) regulatory simplification. Headline commitments include mobilising approximately €200bn of public+private investment via the InvestAI initiative announced at the AI Action Summit in Paris (11 February 2025), deploying 13 AI Factories (HPC-anchored shared compute facilities) plus regional antennas, building 5 AI Gigafactories powered by >100,000 advanced AI processors with €20bn earmarked from InvestAI, launching the Apply AI Strategy and Data Union Strategy, and proposing a Cloud and AI Development Act with a public consultation closing 4 June 2025. The one-year progress report (9 April 2026) confirmed 19 AI Factories deployed across EU supercomputers with 13 Antennas providing regional access, and €1bn in Apply AI funding calls earmarked.
Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025 and published in the Official Journal on 2 July 2025, supplements DORA (Regulation (EU) 2022/2554) with binding Regulatory Technical Standards governing ICT subcontracting of critical or important functions. It requires all EU-regulated financial entities to establish a subcontracting policy, conduct due-diligence and concentration-risk assessments at each tier of the ICT supply chain (including nth-party providers), impose equivalent resilience standards on sub-ICT-providers, and maintain enforceable termination and information-access rights. The RTS entered into force on 22 July 2025, completing the second-batch DORA implementing acts on outsourcing chains.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Indonesia's Ministry of Communications and Digital Affairs (Kemkomdigi) promulgated Permenkomdigi No. 5/2025 on 25 March 2025 as the implementing regulation under Government Regulation PP 71/2019 governing Public-Scope Electronic System Operators (PSE Lingkup Publik), defined as operators running electronic systems for government institutions or critical public services. The regulation mandates registration, data classification by risk level (low/medium/ high/strategic) with corresponding domestic storage and processing requirements, content- moderation governance, and access-blocking mechanisms for prohibited electronic information. All public-scope PSEs must achieve compliance by 25 March 2026, with non-compliant operators subject to progressive administrative sanctions under Articles 100-series ranging from written warnings to access disconnection (pemutusan akses) and removal from official registries.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
President Trump signed Executive Order 14179 on 23 January 2025 (published in the Federal Register on 31 January 2025 as 90 FR 8741, doc 2025-02172). The order revokes Biden-era Executive Order 14110 of 30 October 2023 ("Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence") and directs federal agencies to identify and rescind, revise, or suspend any policies, regulations, memoranda, or guidance documents adopted pursuant to the revoked Biden order. It mandates that the Assistant to the President for Science and Technology, the Assistant to the President for National Security Affairs, the Special Advisor for AI and Crypto, and the Assistant to the President for Economic Policy develop an AI Action Plan within 180 days to "sustain and enhance America's global AI dominance." The plan was released on 23 July 2025. EO 14179 reframes US AI industrial-policy posture from safety-first regulation to deregulation, infrastructure investment, and export-competitiveness.
The UK government published the AI Opportunities Action Plan (CP 1241) on 13 January 2025, authored by Matt Clifford CBE (Chair, ARIA), and simultaneously accepted all 50 recommendations via the government response (CP 1242). The plan establishes binding cross-government commitments including a 20× expansion of UK sovereign AI compute capacity by 2030, designation of AI Growth Zones (Culham, Oxfordshire named first), a National Data Library, and energy-grid prioritisation for AI datacentres. It positions AI compute as critical national infrastructure and represents the most comprehensive national AI industrial-policy roadmap published in the UK to date.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
India's Finance (No. 2) Act, 2024 (Act No. 15 of 2024) repeals the 2% Equalisation Levy on e-commerce supplies and services by non-resident operators (§165A of the Finance Act 2016, introduced 2020), with effect from 1 August 2024. The repeal removes a long-standing US trade irritant — the USTR had found the 2% levy unreasonable under a Section 301 investigation, and India agreed in October 2021 to remove it as part of a multilateral OECD Pillar 1 commitment, formally implemented here three years later. The residual 6% Equalisation Levy on digital advertising under §165 (in force since 2016) was not touched by this Act and remained in force until its own repeal effective 1 April 2025 via a subsequent Finance Act.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
The Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA), enacted as Division H of P.L. 118-50 (21st Century Peace through Strength Act), prohibits app stores and internet hosting services from distributing, maintaining, or updating "foreign adversary controlled applications" — defined explicitly to include ByteDance Ltd and its subsidiaries (TikTok). ByteDance was given 270 days from enactment (until January 19, 2025) to execute a "qualified divestiture" — selling TikTok to an owner with no operational relationship with a foreign adversary — or face a nationwide distribution ban. The Supreme Court unanimously upheld the law's constitutionality in TikTok, Inc. v. Garland (January 17, 2025), rejecting First Amendment challenges and affirming the national-security rationale grounded in data-collection concerns.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
Ireland's Screening of Third Country Transactions Act 2023 (Act No. 28 of 2023), signed into law on 31 October 2023 and commenced on 6 January 2025 via S.I. No. 651 of 2024, establishes Ireland's first-ever mandatory inbound FDI screening regime. The Act empowers the Minister for Enterprise, Tourism and Employment to assess, condition, or prohibit transactions by third-country investors (non-EU/EEA/Switzerland) exceeding a EUR 2 million cumulative threshold in targets operating across critical infrastructure, critical technologies, dual-use items, supply of critical inputs, sensitive personal data, and media freedom. A 90-day standstill period applies during Ministerial determination, with criminal sanctions and transaction-voiding powers available for non-compliance.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.