Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) issued a final rule amending 31 CFR § 560.540 of the Iranian Transactions and Sanctions Regulations (ITSR) to incorporate, with amendments, General License (GL) D-2 — originally issued on OFAC's website on September 23, 2022 — which authorizes the export, reexport, and provision of certain services, software, and hardware incident to communications over the internet to persons in Iran. The codification preserves the GL D-2 expansion (cloud-based services; third-country importation of hardware/software previously exported to Iran; ex-Iran installation, repair and replacement services; case-by-case licensing for internet-freedom activities) and updates the § 560.540 List of Services, Software, and Hardware Incident to Communications. Effective June 17, 2024, the List is amended to exclude laptops, tablets, and personal computing devices with an Adjusted Peak Performance (APP) exceeding 1 Weighted TeraFLOP (WT) — narrowing the consumer-electronics authorization to lower-performance devices and aligning the carve-out with broader BIS-style compute thresholds. The rule does not relax primary ITSR prohibitions; it codifies a humanitarian / internet-freedom exception while inserting a narrow high-performance-compute carve-out.
The Indiana Economic Development Corporation approved up to USD 18.3 million in EDGE (Economic Development for a Growing Economy) payroll-based tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. The credit was one component of a larger state incentive package announced by Governor Eric Holcomb on 2024-04-25, which also included up to USD 55 million in Hoosier Business Investment tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01. The project committed to creating at least 1,000 new jobs.
The Indiana Economic Development Corporation approved up to USD 55 million in Hoosier Business Investment (HBI) tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the largest single instrument in the five-part state incentive package Governor Eric Holcomb announced on 2024-04-25, which also included up to USD 18.3 million in EDGE payroll tax credits, up to USD 20 million in redevelopment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC describes all incentives as performance-based, claimable only once the underlying investment and job-creation commitments are verified. IEDC records cite an incentive-agreement effective date of 2023-09-01.
The Indiana Economic Development Corporation approved up to USD 20 million in redevelopment tax credits for Amazon Data Services Inc., tied to Amazon Web Services' USD 11 billion data center campus at the Indiana Enterprise Center in New Carlisle, St. Joseph County. This is the third of five distinct incentive instruments in the state package Governor Eric Holcomb announced on 2024-04-25, alongside up to USD 18.3 million in EDGE payroll tax credits, up to USD 55 million in Hoosier Business Investment tax credits, up to USD 5 million in training grants, a USD 7 million road-infrastructure contribution, and a 50-year state sales-tax exemption on data center equipment. IEDC records cite an incentive-agreement effective date of 2023-09-01.
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
On April 4, 2024, the Bureau of Industry and Security published an interim final rule (89 FR 23876) providing corrections, clarifications, and targeted revisions to the October 2023 advanced-computing and semiconductor manufacturing equipment rules. The most substantive change splits the former License Exception NAC (Notified Advanced Computing) into two separate exceptions: NAC (retaining the 25-day prior notification requirement) and a new ACA (Advanced Computing Authorized) exception that permits certain shipments without advance notification. The rule also adds ECCN 4A090.b covering computers and assemblies containing advanced ICs, restores national-security controls to several ECCNs, and addresses various technical drafting errors from the October 2023 rules.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
On 25 October 2023 the Bureau of Industry and Security published an interim final rule (88 FR 73424; FR Doc 2023-23055) making substantive revisions to the October 7 2022 advanced-computing IFR, incorporating 43 public comments covering 78 topics. The rule replaced the prior TOPS-based performance metric with a new "Total Processing Performance" (TPP) / performance-density dual-threshold structure for ECCN 3A090, splitting the control into tiers 3A090.a (full licence requirement for highest-capability datacenter AI chips) and 3A090.b (new License Exception NAC with 25-day prior notification for the intermediate tier). Geographic scope was expanded from China-and-Macau to Country Groups D:1/D:4/D:5 to block diversion via third-country intermediaries and offshore datacenters.
The US Bureau of Industry and Security issued an interim final rule on 17 October 2023 that substantially expanded the advanced-computing and semiconductor manufacturing controls first imposed in October 2022. The rule closed the performance-threshold workaround that NVIDIA had used to ship China-specific A800/H800 GPUs, replacing it with a "performance density" metric and adding a new "Notified Advanced Computing" licence category. It expanded controls on chipmaking equipment (additional ECCNs covering deposition, etch, metrology), pulled 21 additional countries (mostly Middle East / Central Asia) into a regional licensing scheme to prevent transshipment, and added 13 Chinese entities to the Entity List including AI-chip designers.
BIS amended §§ 734.15 and 734.19 of the Export Administration Regulations (EAR) to clarify that a "release of software" for purposes of the transfer-of-access-information provision includes both source code and object code. A cross-reference was also added from § 734.15 to § 734.19. The practical effect is that providing a decryption key, password, or other access credential to a foreign person to unlock controlled software requires an export licence to the same degree as exporting the software itself would.
Saudi Arabia's Personal Data Protection Law (PDPL), issued under Royal Decree M/19 (16 September 2021) and substantively amended by Royal Decree M/148 (27 March 2023), entered into force on 14 September 2023 with a one-year transition period that ended on 14 September 2024 — at which point the Saudi Data & Artificial Intelligence Authority (SDAIA) became the binding regulator with full enforcement powers. Alongside the Implementing Regulations and the Regulations on the Transfer of Personal Data Outside the Kingdom (both issued 7 September 2023), SDAIA published in 2024 a set of four pre-approved Standard Contractual Clauses templates (C2C, C2P, P2P, P2C) governing cross-border transfers. The regime establishes consent requirements, DPO appointment, a 72-hour breach notification duty, and prior-clearance / SCC-or-BCR-style conditions on personal-data exports out of Saudi Arabia.
The Bureau of Industry and Security (BIS) added 37 entities under 38 entries to the Entity List, effective March 2, 2023, spanning six destinations: China (28), Pakistan (4), Burma (3), Russia (1), Belarus (1), and Taiwan (1). The China tranche — the largest — targets entities supporting the People's Liberation Army's military modernization, including BGI Research and Forensic Genomics International (genomic surveillance/data risk), Inspur Group Co. Ltd. (cloud servers supplied to Chinese military), and Loongson Technology (domestic CPU developer). Three Burmese entities, including the Ministry of Transport and Communications, are designated for providing surveillance equipment enabling the military junta's tracking and targeting of civilians. Pakistani entities Abdul Razaq Asim, Add-On Technology, and Dynamic Engineers are added for contributing to Pakistan's ballistic missile programs; Russian DMT Electronics and Belarusian DMT Trading LLC for export-control evasion. All listed entities are subject to a license requirement for all items subject to the EAR, with the review policy being presumption of denial for the majority of Chinese entries.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).
The Act on the Promotion of Ensuring National Security through Integrated Implementation of Economic Measures (Law No. 43 of 2022), enacted 18 May 2022, establishes a four-pillar framework: (1) supply-chain resilience for "specified critical products," (2) security of critical infrastructure, (3) state-backed development of "specified critical technologies," and (4) non-disclosure of nationally sensitive patents. A December 2022 Cabinet Order designated 11 product categories as specified critical products, including semiconductors, storage batteries, permanent magnets, cloud programs, LNG, critical minerals, machine tools, and aircraft parts. Competent ministries must publish stable-supply plans, can fund private-sector surveys, and may provide subsidies to qualifying firms.
BIS published a technical correction to the Entity List (15 CFR Part 744, Supplement No. 4) fixing three errors in the February 14, 2022 final rule (87 FR 8180; FR Doc. 2022-03029) that added and revised Huawei entities. Two entries — Huawei Cloud Brazil (São Paulo) and Huawei Technologies Co., Ltd. (China, with 22+ affiliated addresses) — incorrectly cited §736.2(b)(3)(vi) as the Foreign Direct Product rule trigger instead of the correct §734.9(e) (the Huawei-specific FDP rule); a third error was a typographical fix to the footnote reference ("except for" → "EXCEPT\2\ for"). No new restrictions were created; the substantive export control status of all listed Huawei entities is unchanged, but exporters relying on the CFR text now have the correct regulatory citation for license requirement determinations.
The Bureau of Industry and Security (BIS) extended for a second time the temporary unilateral export control on software classified as ECCN 0D521 — "software specially designed for training a Deep Convolutional Neural Network to automate the analysis of geospatial imagery and point clouds" — adding a third year of control through January 6, 2023. The extension was required because COVID-19 prevented the Wassenaar Arrangement from formally convening in 2020 or holding sufficient deliberations in 2021 to consider the US multilateral control proposal submitted in 2020. Only License Exception GOV (§ 740.11(b)(2)(ii)) is available; all other exports require a specific license from BIS.
France 2030 is a €54 billion public investment plan unveiled by President Emmanuel Macron on 12 October 2021 to fund breakthrough innovation and reindustrialisation across ten strategic priorities — small modular nuclear reactors, green hydrogen, low-carbon transport (incl. two million EVs/year), food/agritech, twenty drug therapies for cancer and chronic disease, cultural industries, space, deep-sea exploration, semiconductors and electronic components, and robotics/digital (AI/cloud). Two cross-cutting rules require 50% of investment to flow to decarbonisation and 50% to emerging innovative players. Operationalised from the 2022 budget law, the plan is coordinated by the Secrétariat général pour l'investissement (SGPI) under the Prime Minister and delivered by ANR, ADEME, Bpifrance and Caisse des Dépôts / Banque des Territoires.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Bureau of Industry and Security (BIS) extended for one year the temporary unilateral export control on software classified as ECCN 0D521 — "software specially designed for training a Deep Convolutional Neural Network to automate the analysis of geospatial imagery and point clouds" — adding a second year of control through January 6, 2022. The extension was required because COVID-19 prevented the Wassenaar Arrangement from formally convening in 2020 to consider the US multilateral control proposal submitted that year. Only License Exception GOV (§ 740.11(b)(2)(ii)) is available; all other exports require a specific licence from BIS.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Decreto-Legge 15 marzo 2012 n. 21 (GU n. 63 of 15 March 2012), converted with amendments into Legge 11 maggio 2012 n. 56 (GU n. 111 of 14 May 2012), establishes Italy's "Golden Power" special-powers regime — the foundational statute authorising the Italian Government to impose conditions on, veto, or prescribe remedies for corporate transactions in strategic sectors. The decree marked Italy's transition from a golden-share model (applicable only to privatised companies) to a sector-wide golden-power model applicable to any company carrying out activities of strategic relevance. Administered by the Presidenza del Consiglio dei Ministri (DICA), the regime has been progressively extended from its original defence + national-security + energy/transport/ communications scope to cover 5G, cloud, critical-raw-materials, financial-credit-insurance, agri-food, healthcare, media, space, and AI through a series of amending decrees from 2019 to 2026.
Japan's Foreign Exchange and Foreign Trade Act (FEFTA, Act No. 228 of 1 December 1949; 外国為替及び外国貿易法) is the foundational umbrella statute governing the entire modern Japanese economic-statecraft toolkit. Originally a restrictive positive-list regime for foreign-exchange transactions, FEFTA was fundamentally liberalised by the 1980 revision (positive-list to negative-list shift) and again overhauled in 1998 to establish the modern regulatory architecture. Three principal enforcement arms operate under FEFTA: (i) security export controls administered by METI via the Export Trade Control Order and the Foreign Exchange Order (covering the Wassenaar Arrangement, Australia Group, MTCR, NSG, and CWC controlled-items lists plus Japan-specific catch-all controls); (ii) inward FDI screening administered jointly by the Ministry of Finance and sector ministries (prior notification and pre-notification regime, substantially expanded 2019–2020 with Core Business Sectors covering semiconductors, critical minerals, advanced materials, cloud computing, and aerospace added 2021); and (iii) autonomous economic sanctions (asset- freeze and payment-restriction designations against Russia, Iran, DPRK, Myanmar, Belarus, and others via Cabinet Orders made under FEFTA authority). Structurally peer-foundational to the US Trade Expansion Act 1962, US Trade Act 1974, UK SAMLA 2018, CN Export Control Law 2020, and CN Anti-Foreign Sanctions Law 2021 as the G7+CN foundational economic- statecraft statute cluster.