Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On June 8, 2026, the US Department of Defense published its annual update to the Section 1260H Chinese Military Companies (CMIC) list, adding 65 entities (17 new parent companies and 48 subsidiaries), bringing the total to approximately 188–200 designated entities. Major additions span EV and battery manufacturing (BYD, NIO, CATL), consumer internet (Alibaba, Baidu, Tencent), semiconductors (SMIC, YMTC, CXMT), solar (JA Solar, Trina Solar), biotech (BGI Genomics, WuXi AppTec), drones/robotics (DJI, Unitree, RoboSense), and telecoms (TP-Link). Effective June 30, 2026, DoD is prohibited from procuring goods, services, or technology directly from listed entities; effective June 30, 2027, the ban extends to indirect supply-chain procurement through prime contractors and all sub-tiers.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
President Trump signed Executive Order 14324, "Suspending Duty-Free De Minimis Treatment for All Countries," on 30 July 2025 (published in the Federal Register on 5 August 2025 as FR doc 2025-14897, 90 FR 37775). The order eliminated the Section 321(a)(2)(C) administrative exemption that had allowed shipments valued at $800 or less to enter the United States duty-free, applying the suspension to all countries of origin rather than the China/Hong Kong-only carve-out imposed earlier in 2025. DHS/CBP published a Notice of Implementation on 2 September 2025 (FR doc 2025-16802) modifying the Harmonized Tariff Schedule so that covered low-value goods must be entered via formal or informal ACE entry types and pay applicable duties; goods shipped through the international postal network were instead made subject to a new flat ad valorem or specific per-item duty rate set by HTSUS annex. The suspension took effect for entries on or after 12:01 a.m. EDT on 29 August 2025. A DHS/CBP rule published 24 June 2026 (FR doc 2026-12670) converted the non-postal suspension from time-limited to indefinite and closed the remaining international-postal-network exemption to formal/ informal entry procedures as well.
Mexico's tax authority (SAT), acting under SHCP, published the Cuarta Resolución de Modificaciones a las Reglas Generales de Comercio Exterior para 2025 in the Diario Oficial de la Federación on 28 July 2025, raising the flat tax rate applied under the simplified customs regime for low-value courier and parcel shipments (goods valued at USD 2,500 or less) from 19% to 33.5%, effective 15 August 2025. The increase applies to shipments from countries without a free trade agreement with Mexico — in practice overwhelmingly China-origin goods — and is aimed at cross-border e-commerce platforms (Shein, Temu, AliExpress) as well as triangulated goods routed through courier channels by other importers including large retailers. The measure is framed by SHCP as combating under-invoicing and non-tariff-preference triangulation via the courier de minimis channel.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.