Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Premier Li Qiang signed State Council Order No. 835 on 13 April 2026 promulgating the "Regulations of the People's Republic of China on Countering Foreign States' Unlawful Extraterritorial Jurisdiction" (20 articles), effective on the date of publication. The Regulations are the first State Council–level administrative regulation to operationalise the PRC's framework for identifying and countering foreign extraterritorial measures on a horizontal basis, complementing the 2021 Anti-Foreign Sanctions Law and the March 2025 AFSL implementation regulations. Article 5 establishes a State Council–led inter-agency coordination mechanism; Article 6 vests the State Council legal affairs department (the Ministry of Justice in practice) with authority to identify "improper" foreign extraterritorial measures and to grant exemptions; Article 8 authorises a new Malicious Entity List targeting foreign organisations and individuals that "promote or participate in implementing" such measures, with nine countermeasure categories spanning visa denial, asset freezing, trade restrictions and fines; Article 11 codifies an exemption-application channel under which Chinese persons facing conflicting legal demands may request approval to comply with foreign measures within a defined scope; Article 14 authorises a private right of action for harmed Chinese citizens and organisations to sue parties enforcing such measures; and Article 18 elevates enforcement beyond administrative penalties by referencing potential criminal liability.
Directive (EU) 2026/470 of 24 February 2026, published in the EU Official Journal on 26 February 2026 and entered into force on 18 March 2026, amends the Corporate Sustainability Reporting Directive (CSRD, Directive (EU) 2022/2464) and the Corporate Sustainability Due Diligence Directive (CSDDD, Directive (EU) 2024/1760). It raises CSRD scope thresholds to undertakings with more than 1,000 employees and more than EUR 450 million net turnover, raises CSDDD scope thresholds to entities with more than 5,000 employees and EUR 1.5 billion turnover (and non-EU entities with EUR 1.5 billion EU turnover), drops the requirement to adopt or put into effect a climate transition plan under CSDDD, and replaces reasonable-assurance with limited-assurance for CSRD reports. CSRD-related provisions must be transposed by 19 March 2027; CSDDD-related provisions by 26 July 2028.
On 9 February 2026 the UK Office of Financial Sanctions Implementation (OFSI) published a comprehensively revised enforcement and monetary-penalties guidance following its July–October 2025 public consultation. The update introduces a Settlement Scheme (20% penalty discount for subjects who agree not to contest OFSI's findings within 30 business days), an Early Account Scheme (up to 20% discount for legal persons providing a timely senior-attested factual account), a revised voluntary-disclosure framework (maximum discount cut from 50% to 30% and renamed to cover both prompt self-reporting and full cooperation), a four-level case-assessment seriousness matrix (severity × conduct), and fixed monetary penalties of £5,000 and £10,000 for information, reporting, and licensing offences. A planned legislative amendment (requiring primary legislation) will subsequently double the statutory civil monetary-penalty cap from £1m / 50%-of-breach to £2m / 100%-of-breach; in the interim the Policing and Crime Act 2017 caps remain in force. The revised guidance is the foundational enforcement architecture for all UK financial-sanctions programs (Russia, Iran, DPRK, Syria, Belarus, Myanmar, and 10+ additional regimes).
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
Morocco's Loi de Finances n° 50-25 for fiscal year 2026, promulgated by Dahir n° 1-25-67 of 10 December 2025 and published in Bulletin Officiel n° 7465 bis of 16 December 2025, sets the FY2026 customs-tariff schedule (continuing the EU Common External Tariff alignment process at 2.5%/17.5%/40% tiers with sector-specific input reductions), amends the fiscal regimes for Zones d'Accélération Industrielle and Casablanca Finance City, and delivers the 2026 tranche of the multi-year IS (corporate-tax) rate-convergence schedule under Framework Law n° 69-19. The law also extends green-investment fiscal accelerators aligned with the EU's Carbon Border Adjustment Mechanism and the EU-Morocco Strategic Partnership on Sustainable Raw Materials Value Chains, and contains phosphate-sector fiscal provisions affecting OCP Group's DAP/MAP/TSP export treatment. Entry into force: 1 January 2026.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
The Mauritius Finance Act 2025 (Act No. 18 of 2025), assented to by Acting President Dharambeer Gokhool G.C.S.K. and gazetted in August 2025, is an omnibus financial-sector statute amending the Companies Act, Financial Services Act 2007, Income Tax Act, Bank of Mauritius Act, and FIAMLA. Its headline provisions are: (i) introduction of a Qualified Domestic Minimum Top-Up Tax (QDMTT) aligned with the OECD GloBE Pillar Two rules, imposing a 15% effective minimum tax on Mauritius profits of MNE groups with consolidated revenue ≥ EUR 750 million; (ii) new fiscal incentives for investments in AI infrastructure and Virtual Asset Service Provider (VASP) licensees; (iii) enhanced beneficial-ownership (UBO) identification and record-keeping requirements under the Companies Act, aligned with FATF Recommendation 24; (iv) tightened substance and economic-presence requirements for Global Business Companies (GBCs); and (v) an expanded AML/CFT administrative- penalty framework under FIAMLA.
On 26 June 2025, the Governing Board of Mexico's National Banking and Securities Commission (CNBV), invoking Article 129 of the Ley de Instituciones de Crédito, decreed the temporary managerial intervention of CI Banco, S.A. and Intercam Banco, S.A., replacing their administrative bodies and legal representatives. The measure came one day after the US Treasury's FinCEN designated both institutions (along with Vector Casa de Bolsa) as foreign financial institutions of primary money-laundering concern tied to opioid-trafficking networks, and prohibited certain US fund transmittals to them. CNBV/SHCP framed the intervention as a depositor- and creditor-protection measure to safeguard the two banks' operations against the fallout of the US action; Vector Casa de Bolsa was not included in the CNBV intervention.
On 26 June 2025 President Bola Ahmed Tinubu signed four acts constituting Nigeria's most comprehensive fiscal overhaul in decades: the Nigeria Tax Act 2025 (NTA), Nigeria Tax Administration Act 2025 (NTAA), Nigeria Revenue Service (Establishment) Act 2025, and Joint Revenue Board (Establishment) Act 2025. The NTA consolidates and repeals six core statutes — CITA, PITA, PPTA, VAT Act, CGT Act, and Stamp Duties Act — into a single unified code effective 1 January 2026, while the NTAA standardises assessment, filing, and enforcement procedures across all federal taxes. The two establishment acts restructure the Federal Inland Revenue Service (FIRS) into the Nigeria Revenue Service (NRS) with a broadened mandate and create an empowered Joint Revenue Board to coordinate federal-state fiscal relations.
The Hong Kong Legislative Council passed the Stablecoins Ordinance (Cap. 656) on 21 May 2025 (third reading), brought into operation by the Secretary for Financial Services and the Treasury on 1 August 2025. The Ordinance introduces a mandatory licensing regime administered by the Hong Kong Monetary Authority (HKMA) for any person who issues a fiat-referenced stablecoin (FRS) in Hong Kong, issues an HKD-pegged stablecoin anywhere in the world, or actively markets such issuance to the Hong Kong public. Key requirements include minimum HK$25 million paid-up capital, segregated pools of high-quality liquid reserve assets fully backing circulating supply, mandatory redemption-at-par rights for holders, AML/CFT controls, and broad HKMA enforcement powers including licence suspension, revocation, and financial penalties. A six-month transitional period for existing operators expires 31 January 2026.
FinCEN issued an interim final rule (FR Doc 2025-05199, 90 FR 13688, published March 26, 2025) revising the definition of "reporting company" under the Corporate Transparency Act to mean only entities formed under the law of a foreign country that have registered to do business in a U.S. State or tribal jurisdiction. All entities created in the United States — previously known as "domestic reporting companies" — and U.S. persons are exempted from BOI reporting. Foreign reporting companies registered before March 26, 2025 must file by April 25, 2025; those registered on or after that date have 30 days from registration. Foreign reporting companies are not required to report any U.S. persons as beneficial owners. The IFR is effective immediately; FinCEN is accepting comments and intends to finalize the rule.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
El Salvador's Legislative Assembly adopted Decreto Legislativo No. 199 on 29 January 2025 with 55 of 60 votes, reforming six articles and repealing three articles of the original Ley Bitcoin (Decreto 57, June 2021). The reform downgrades Bitcoin from compulsory legal tender to voluntary acceptance only — private parties are no longer obliged to accept BTC payments, and Bitcoin can no longer be used to pay taxes or settle public-sector debts. The State also withdraws from operational involvement in the Chivo Wallet platform. The reform is an explicit prior action under the IMF's US$1.4 billion Extended Fund Facility (EFF) programme (IMF Country Report 25/58), published in the Diario Oficial on 30 January 2025 and entering into force 90 days later on 30 April 2025.
Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727), gazetted 17 October 2024, enters its third and final commencement phase on 1 June 2025 per commencement order P.U.(B) 522/2024. Phase 3 activates sections 6 and 9 of the amending Act, which impose mandatory Data Protection Officer (DPO) appointment thresholds, a 72-hour breach-notification duty to the Commissioner, and a statutory data-portability right, bringing Malaysia's PDPA broadly into alignment with GDPR and the ASEAN Model AI Governance Framework.
UAE Cabinet Decision No. 142 of 2024, announced 9 December 2024 and formally gazetted 11 February 2025, introduces a Domestic Minimum Top-Up Tax (DMTT) on UAE constituent entities of Multinational Enterprise (MNE) groups with consolidated annual revenues ≥ EUR 750 million in at least two of the four preceding fiscal years. The DMTT ensures a 15% minimum effective tax rate (ETR) on UAE-source profits, functioning as a Qualified Domestic Minimum Top-up Tax (QDMTT) under the OECD/G20 Pillar Two GloBE framework, thereby giving the UAE first-priority taxing right before any IIR top-up by a parent-jurisdiction authority. The measure applies to fiscal years beginning on or after 1 January 2025. The UAE deliberately excluded the Income Inclusion Rule (IIR) and Under-Taxed Profits Rule (UTPR) from this primary instrument, deferring those to subsequent Cabinet Decisions; the QDMTT-only architecture mirrors Singapore's MEMTA and Switzerland's MindStV as the first-mover design choice for established low-tax financial hubs.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
FinCEN issued a final rule (89 FR 70258, FR Doc 2024-19198) requiring certain real-estate-closing and settlement professionals to file a new "Real Estate Report" and maintain records on non-financed (i.e., all-cash) transfers of U.S. residential real property to specified legal entities and trusts, on a nationwide basis. The rule uses a "reporting cascade" to designate one filer per transaction (settlement agent, title-insurance underwriter, escrow agent, or attorney, depending on which is present), replacing the long-running geographic-targeting-order (GTO) regime with a permanent nationwide framework. The original effective date of December 1, 2025 was subsequently postponed to March 1, 2026 via a FinCEN exemptive-relief order issued September 30, 2025.
FinCEN issued a final rule (published September 4, 2024 at 89 FR 72156; FR Doc 2024-19260) including most SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) within the Bank Secrecy Act definition of "financial institution." Covered firms must implement a risk-based AML/CFT compliance program, appoint a compliance officer, train staff, obtain independent testing, file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs), and participate in §314(a)/(b) information sharing. The original compliance date was January 1, 2026; FinCEN subsequently delayed the effective date to January 1, 2028 by final rule published 2026-01-02 (FR Doc 2025-24184).
The Ethiopian Capital Market Authority (ECMA) issued Directive No. 1009/2024 on 16 July 2024, establishing the comprehensive licensing, operational, and supervisory framework for securities exchanges, derivatives exchanges, and the over-the-counter (OTC) market under the authority of Article 108 of the Capital Market Proclamation No. 1248/2021. The directive consolidates Ethiopia's previously fragmented securities-trading architecture into a single, licensed, and regulated market structure and provided the statutory pathway for the Ethiopian Securities Exchange (ESX) to receive the country's first securities-exchange licence. This is the first capital-markets architecture filing for Ethiopia on the IPTM register, forming the operating- licence layer alongside the banking-sector liberalisation enacted under Proclamation 1360/2025.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
FinCEN published the Beneficial Ownership Information Access and Safeguards Final Rule (FR Doc 2023-27973, 88 FR 88732, December 22, 2023; effective February 20, 2024), implementing the access and disclosure provisions of Section 6403(c) of the Corporate Transparency Act (CTA) enacted as part of the Anti-Money Laundering Act of 2020. The rule defines six categories of authorized recipients permitted to access the FinCEN BOI database — US federal agencies engaged in national security/intelligence/law enforcement, state/local/tribal law enforcement, foreign law enforcement and competent authorities (via intermediary federal agency), financial institutions using BOI for customer due diligence (CDD), federal functional regulators assessing financial-institution CDD compliance, and Treasury officers/employees. Access is to be phased in, beginning with a 2024 pilot for key federal agencies before extending to financial institutions and their supervisors. The rule establishes data-security standards, re-disclosure prohibitions, and oversight mechanisms governing each recipient category.
Saudi Arabia's Personal Data Protection Law (PDPL), issued under Royal Decree M/19 (16 September 2021) and substantively amended by Royal Decree M/148 (27 March 2023), entered into force on 14 September 2023 with a one-year transition period that ended on 14 September 2024 — at which point the Saudi Data & Artificial Intelligence Authority (SDAIA) became the binding regulator with full enforcement powers. Alongside the Implementing Regulations and the Regulations on the Transfer of Personal Data Outside the Kingdom (both issued 7 September 2023), SDAIA published in 2024 a set of four pre-approved Standard Contractual Clauses templates (C2C, C2P, P2P, P2C) governing cross-border transfers. The regime establishes consent requirements, DPO appointment, a 72-hour breach notification duty, and prior-clearance / SCC-or-BCR-style conditions on personal-data exports out of Saudi Arabia.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
The Federal Act of 22 March 2002 on the Implementation of International Sanctions (Embargogesetz / EmbG, SR 946.231), in force 1 January 2003, is Switzerland's foundational enabling statute authorising the Federal Council to issue coercive-measure ordinances implementing UN Security Council mandatory sanctions (under UN Charter Art. 25 obligations accepted upon Switzerland's 2002 UN accession), OSCE sanctions decisions, and — via the progressive EU-tracking clause — the sanctions of Switzerland's most important trading partners, primarily the EU. The State Secretariat for Economic Affairs (SECO) administers all resulting ordinances; FINMA supervises financial-sector compliance and FOEN supervises trade-in-goods compliance. The EmbG is the parent authority for Switzerland's entire portfolio of approximately 25 country-specific sanctions ordinances, including the Ukraine/Russia ordinance (SR 946.231.176.72 implementing EU Russia packages 1-19+), the Iran ordinance (SR 946.231.143.6), the DPRK ordinance (SR 946.231.127.6), the Myanmar ordinance (SR 946.231.157.5), and the Belarus ordinance (SR 946.231.116.9).