Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On June 8, 2026, the US Department of Defense published its annual update to the Section 1260H Chinese Military Companies (CMIC) list, adding 65 entities (17 new parent companies and 48 subsidiaries), bringing the total to approximately 188–200 designated entities. Major additions span EV and battery manufacturing (BYD, NIO, CATL), consumer internet (Alibaba, Baidu, Tencent), semiconductors (SMIC, YMTC, CXMT), solar (JA Solar, Trina Solar), biotech (BGI Genomics, WuXi AppTec), drones/robotics (DJI, Unitree, RoboSense), and telecoms (TP-Link). Effective June 30, 2026, DoD is prohibited from procuring goods, services, or technology directly from listed entities; effective June 30, 2027, the ban extends to indirect supply-chain procurement through prime contractors and all sub-tiers.
President Trump signed Executive Order "Saving TikTok While Protecting National Security" on September 25, 2025, certifying a restructuring plan as a "qualified divestiture" under the 2024 PAFACA law and directing the Attorney General not to enforce the Act for 120 days while the transaction closes. The plan creates TikTok USDS Joint Venture LLC, valued at roughly $14 billion, with a new US-investor consortium (Oracle, Silver Lake and MGX at 15% each, plus other investors, totaling 50%), affiliates of existing ByteDance investors holding 30.1%, and ByteDance itself retaining 19.9%. Oracle will run US data storage and algorithm retraining/oversight; the deal closed January 22, 2026.
The Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA), enacted as Division H of P.L. 118-50 (21st Century Peace through Strength Act), prohibits app stores and internet hosting services from distributing, maintaining, or updating "foreign adversary controlled applications" — defined explicitly to include ByteDance Ltd and its subsidiaries (TikTok). ByteDance was given 270 days from enactment (until January 19, 2025) to execute a "qualified divestiture" — selling TikTok to an owner with no operational relationship with a foreign adversary — or face a nationwide distribution ban. The Supreme Court unanimously upheld the law's constitutionality in TikTok, Inc. v. Garland (January 17, 2025), rejecting First Amendment challenges and affirming the national-security rationale grounded in data-collection concerns.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
The Bureau of Industry and Security (BIS) added 37 entities under 38 entries to the Entity List, effective March 2, 2023, spanning six destinations: China (28), Pakistan (4), Burma (3), Russia (1), Belarus (1), and Taiwan (1). The China tranche — the largest — targets entities supporting the People's Liberation Army's military modernization, including BGI Research and Forensic Genomics International (genomic surveillance/data risk), Inspur Group Co. Ltd. (cloud servers supplied to Chinese military), and Loongson Technology (domestic CPU developer). Three Burmese entities, including the Ministry of Transport and Communications, are designated for providing surveillance equipment enabling the military junta's tracking and targeting of civilians. Pakistani entities Abdul Razaq Asim, Add-On Technology, and Dynamic Engineers are added for contributing to Pakistan's ballistic missile programs; Russian DMT Electronics and Belarusian DMT Trading LLC for export-control evasion. All listed entities are subject to a license requirement for all items subject to the EAR, with the review policy being presumption of denial for the majority of Chinese entries.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.