Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On 18 September 2026 the President signed a proclamation extending Proclamation 10973 (originally issued 19 September 2025), which conditions issuance/entry on new H-1B specialty-occupation petitions on a $100,000 payment by the sponsoring employer, for a further 12 months through 21 September 2027 (exceptions remain at DHS Secretary discretion for national-interest cases). Alongside it the President signed a companion executive order, "Enhancing Program Integrity and Interagency Coordination in the Administration of the H-1B Nonimmigrant Visa Program," directing DHS, State and Labor to coordinate review of H-1B petitions and consult Commerce, Education and SBA on employment data, with heightened scrutiny for employers with recent or planned US-worker layoffs. The accompanying fact sheet cites a 92% drop in H-1B registrations by the largest IT-outsourcing firms (24,946 to 2,055) and a ~97% decrease in consular H-1B processing requests since the original 2025 proclamation. ## Severity basis Quant anchor from the primary source: $100,000 flat fee per covered H-1B petition, extended for a further 12-month term (through 2027-09-21); a measured 92% reduction in H-1B registrations by the largest IT-outsourcing filers (24,946 → 2,055) and a ~97% drop in consular H-1B processing requests attributed to the fee regime since its 2025 introduction. Severity 4/5: a binding, renewed cost barrier with a demonstrated order-of-magnitude effect on offshore-staffing-dependent filers, not a one-off or symbolic measure.
The Office of the United States Trade Representative released the 2026 Special 301 Report on 30 April 2026, designating Vietnam as a Priority Foreign Country (PFC) — the most severe category under Section 182 of the Trade Act of 1974 (19 U.S.C. § 2242). This is the first PFC designation since Ukraine held the status from 2013 through 2015, a gap of approximately 11 years. The PFC designation triggers a statutory 30-day window (expiring ~30 May 2026) within which USTR must decide whether to initiate a Section 301 investigation under 19 U.S.C. § 2412(b)(2)(A), which could lead to tariffs, withdrawal of trade benefits, or other Section 301 enforcement remedies against Vietnam. Separately, the EU was added to the Watch List for the first time, citing AI training-data, geographical-indications, and customs-enforcement concerns.
Premier Li Qiang signed State Council Order No. 835 on 13 April 2026 promulgating the "Regulations of the People's Republic of China on Countering Foreign States' Unlawful Extraterritorial Jurisdiction" (20 articles), effective on the date of publication. The Regulations are the first State Council–level administrative regulation to operationalise the PRC's framework for identifying and countering foreign extraterritorial measures on a horizontal basis, complementing the 2021 Anti-Foreign Sanctions Law and the March 2025 AFSL implementation regulations. Article 5 establishes a State Council–led inter-agency coordination mechanism; Article 6 vests the State Council legal affairs department (the Ministry of Justice in practice) with authority to identify "improper" foreign extraterritorial measures and to grant exemptions; Article 8 authorises a new Malicious Entity List targeting foreign organisations and individuals that "promote or participate in implementing" such measures, with nine countermeasure categories spanning visa denial, asset freezing, trade restrictions and fines; Article 11 codifies an exemption-application channel under which Chinese persons facing conflicting legal demands may request approval to comply with foreign measures within a defined scope; Article 14 authorises a private right of action for harmed Chinese citizens and organisations to sue parties enforcing such measures; and Article 18 elevates enforcement beyond administrative penalties by referencing potential criminal liability.
On 3 February 2026 the European Commission opened an in-depth Phase II investigation under the Foreign Subsidies Regulation (FSR) — the second FSR ex officio case and the first targeting the renewable-energy wind-OEM sector — into whether Xinjiang Goldwind Science & Technology Co., Ltd. and its EU affiliates received Chinese foreign subsidies (grants, preferential tax treatment, and state-bank preferential financing) that distort competition for wind-turbine supply and services in the EU internal market. The case (FS.100143) follows the April 2024 preliminary-review opening and subjects Goldwind to an 18-month Phase II investigation with potential redressive-measures decision. The action structurally extends the FSR enforcement perimeter from security equipment (Nuctech, FS.100068) into the green-transition energy-equipment supply chain.
On 9 February 2026 the UK Office of Financial Sanctions Implementation (OFSI) published a comprehensively revised enforcement and monetary-penalties guidance following its July–October 2025 public consultation. The update introduces a Settlement Scheme (20% penalty discount for subjects who agree not to contest OFSI's findings within 30 business days), an Early Account Scheme (up to 20% discount for legal persons providing a timely senior-attested factual account), a revised voluntary-disclosure framework (maximum discount cut from 50% to 30% and renamed to cover both prompt self-reporting and full cooperation), a four-level case-assessment seriousness matrix (severity × conduct), and fixed monetary penalties of £5,000 and £10,000 for information, reporting, and licensing offences. A planned legislative amendment (requiring primary legislation) will subsequently double the statutory civil monetary-penalty cap from £1m / 50%-of-breach to £2m / 100%-of-breach; in the interim the Policing and Crime Act 2017 caps remain in force. The revised guidance is the foundational enforcement architecture for all UK financial-sanctions programs (Russia, Iran, DPRK, Syria, Belarus, Myanmar, and 10+ additional regimes).
Germany's first cross-sector federal statute establishing minimum requirements for the physical protection and resilience of critical infrastructure operators (KRITIS) — sectors covered include energy, transport, water, food, ICT, financial services, health, and federal government infrastructure. Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities). Identifies operators of critical facilities with Europe-wide significance, mandates national risk analyses for critical services, requires operator risk-management measures and creates a federal incident-reporting regime. Passed by the Bundestag on 29 January 2026, confirmed by the Bundesrat on 6 March 2026, published in BGBl. 2026 I Nr. 66 on 16 March 2026, in force from 17 March 2026.
Taiwan's Legislative Yuan passed the Artificial Intelligence Basic Act (人工智慧基本法) on third reading on 23 December 2025, and President Lai Ching-te promulgated the 20-article statute on 14 January 2026, bringing it into force immediately. The Act designates the National Science and Technology Council (NSTC) as the central AI-policy competent authority and codifies seven governance principles — sustainability and well-being, human autonomy, privacy protection and data governance, cybersecurity and safety, transparency and explainability, fairness and non-discrimination, and accountability — that apply to all public-sector AI procurement and high-risk sectoral applications. The statute establishes a statutory foundation for the Taiwan AI Action Plan 2.0, mandates an Executive Yuan National AI Strategy Committee, and provides authority for sector-specific implementing regulations by FSC, NCC, MOHW, and MOTC across finance, telecoms, medical, and autonomous-vehicle AI within a two-year window. As the first national AI governance statute in the Greater China region and the third globally after the EU AI Act and South Korea's AI Basic Act, it frames regulatory expectations for the companies at the heart of the global AI hardware supply chain — TSMC, NVIDIA ODM partners, and advanced-packaging incumbents — that are headquartered or operate substantially in Taiwan.
On 22 December 2025 the FCC's Public Safety and Homeland Security Bureau released Public Notice DA-25-1086, adding to the Covered List (under section 1709 of the FY2025 NDAA) all unmanned aircraft systems (UAS) and UAS critical components produced in a foreign country, plus communications and video-surveillance equipment/services produced by DJI Technologies and Autel Robotics (and their subsidiaries, affiliates, and licensing/JV partners). The designation is comprehensive by scope — every foreign-made drone from consumer quadcopters to large uncrewed systems, with no size/performance carve-out — and blocks the FCC from granting any new equipment authorization to covered UAS/components going forward. Previously authorized models already in the US market are not revoked. A follow-on Public Notice (DA-26-22, 7 January 2026) narrowed the scope with a temporary exemption (see amendments).
Section 851 of the FY 2026 National Defense Authorization Act (P.L. 119-60), signed December 18, 2025, prohibits US federal agencies from procuring biotechnology equipment or services from designated "biotechnology companies of concern" (BCCs), and bars federal contractors from using such equipment/services in work performed under federal contracts, grants, or loans. The final enacted text ties initial BCC designations to DoD's existing §1260H Chinese-military-company list (which currently includes BGI and MGI, but not WuXi AppTec or WuXi Biologics) and directs OMB to designate additional BCCs within one year of enactment; operational prohibitions activate 60-90 days after FAR revision, with a five-year grandfather period for pre-existing contracts — enforcement is expected to begin in 2027-28. The legislation is the successor to H.R.8333 (118th Congress, House-passed September 2024 but stalled in the Senate before adjournment) and represents the first enacted US federal-procurement biotech-supply-chain-resilience statute.
On 10 December 2025 the National Assembly of Vietnam adopted Law No. 134/2025/QH15 on Artificial Intelligence (8 chapters, 35 articles), Vietnam's first dedicated AI statutory framework and one of the first comprehensive horizontal AI laws in Southeast Asia. The law establishes a three-tier risk-based regulatory architecture (high / medium / low) for the research, development, provision, deployment, and use of AI systems; defines the rights and obligations of providers, deployers, importers, distributors, and users; and mandates state oversight via the Ministry of Information & Communications and Ministry of Science & Technology. Prohibited acts include systematic deception, manipulation of human perception, generation of fake content endangering national security, exploitation of vulnerable populations, and obstruction of human-supervision mechanisms. The law applies to Vietnamese agencies, organizations, and individuals as well as foreign organizations and individuals involved in AI-related activities in Vietnam, taking effect 1 March 2026 with 12-18 month transition windows for existing systems depending on sector.
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
India's Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 via Gazette notification G.S.R. 846(E) on 13 November 2025, operationalising the 2023 DPDP Act. The Rules introduce a "negative list" cross-border personal-data transfer regime under Rule 14, verifiable parental consent, breach-notification windows, and tiered penalties up to INR 250 crore. Implementation is phased: Data Protection Board provisions in force on notification, Consent Manager rules from 13 Nov 2026, and core data-fiduciary / cross-border-transfer obligations from 13 May 2027.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Cambodia-based Huione Group, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Huione Group and its subsidiaries — including Haowang Guarantee, Huione Pay PLC, and Huione Crypto — laundered at least $4 billion of illicit proceeds between August 2021 and January 2025, including funds tied to North Korean cyber-heist actors and Southeast Asian "pig-butchering" investment-scam compounds. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Effective November 17, 2025.
Italy enacted Legge 23 settembre 2025, n. 132 — "Disposizioni e deleghe al Governo in materia di intelligenza artificiale" — published in Gazzetta Ufficiale Serie Generale n. 223 of 25 September 2025 (atto 25G00143) and entered into force on 10 October 2025. The statute makes Italy the first EU member state to enact a comprehensive national AI law complementing Regulation (EU) 2024/1689 (EU AI Act), designating AgID (Agency for Digital Italy) and ACN (National Cybersecurity Agency) as national oversight authorities under Presidency-of-the-Council-of-Ministers coordination. It sets sectoral rules for healthcare, labour, intellectual professions, public administration and the judiciary; authorises up to €1 billion in state-backed venture capital (via CDP Venture Capital) for AI, cybersecurity and telecoms; creates criminal penalties of up to five years' imprisonment for harmful deepfakes; mandates parental consent for under-14 users; and delegates secondary legislation to the Government across multiple domains.
Czech Republic's first standalone federal statute on the resilience of critical-infrastructure entities — Act No. 266/2025 Sb., "Zákon o odolnosti subjektů kritické infrastruktury a o změně souvisejících zákonů" (Critical Infrastructure Act). Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities) into Czech law and removes critical-infrastructure regulation from the earlier crisis-management law (Zákon č. 240/2000 Sb.) into a dedicated statute. Covers the 11 CER-Directive sectors (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food production-processing-distribution) and obligates designated operators of essential services to conduct risk analyses, implement technical/organisational resilience measures, report incidents to sector-competent authorities, and submit to inspection. Published in the Sbírka zákonů on 4 August 2025; in force 19 August 2025; operator information-obligation deadline 1 March 2026.
Canada announced on 29 June 2025 that it would rescind the Digital Services Tax Act (originally enacted 20 June 2024) to revive US-Canada trade negotiations after President Trump suspended talks on 27 June, citing the 3% DST on large digital-services revenues as a discriminatory measure against US technology firms. The Canada Revenue Agency halted collection effective 30 June 2025, and legislation to retroactively repeal the Act back to its June 2024 enactment date is to follow, with refunds — plus interest at the standard corporate tax refund rate — to be paid to affected taxpayers including US technology majors.
On 26 June 2025 President Bola Ahmed Tinubu signed four acts constituting Nigeria's most comprehensive fiscal overhaul in decades: the Nigeria Tax Act 2025 (NTA), Nigeria Tax Administration Act 2025 (NTAA), Nigeria Revenue Service (Establishment) Act 2025, and Joint Revenue Board (Establishment) Act 2025. The NTA consolidates and repeals six core statutes — CITA, PITA, PPTA, VAT Act, CGT Act, and Stamp Duties Act — into a single unified code effective 1 January 2026, while the NTAA standardises assessment, filing, and enforcement procedures across all federal taxes. The two establishment acts restructure the Federal Inland Revenue Service (FIRS) into the Nigeria Revenue Service (NRS) with a broadened mandate and create an empowered Joint Revenue Board to coordinate federal-state fiscal relations.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
Indonesia issued Government Regulation (Peraturan Pemerintah) No. 8 of 2025 on Foreign-Exchange Proceeds from Natural-Resource Exports (DHE SDA), amending PP No. 36/2023. President Prabowo Subianto announced the policy at Merdeka Palace on 17–18 February 2025 and the regulation takes effect on 1 March 2025. It mandates that exporters of non-oil- and-gas mining, plantation, forestry, and fisheries products with export-proceeds value of USD 250,000 or more per shipment retain 100 percent of those foreign-exchange proceeds inside Indonesia's financial system for 12 months — sharply up from the prior 30 percent for 3 months under PP 36/2023. Oil-and-gas exporters remain on the earlier 30 percent / 3-month regime. Permitted in-period uses include rupiah conversion at the holding bank, payment of state obligations in foreign currency, dividend distribution, payment for imported raw materials and capital goods unavailable domestically, and servicing of foreign-currency capital-expenditure loans. Non-compliance carries administrative sanctions including suspension of export services. The government has projected the measure could lift retained foreign- exchange proceeds by USD 80 billion in 2025 and over USD 100 billion on a full 12-month basis.
BIS (acting through its Office of Information and Communications Technology and Services, OICTS) published a final rule under Executive Order 13873's ICTS authority prohibiting certain connected-vehicle (CV) transactions involving hardware and software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction of the People's Republic of China or the Russian Federation. The rule reaches the Vehicle Connectivity System (VCS — hardware/software enabling external RF connectivity above 450 MHz) and the Automated Driving System (ADS) software stack. Effective 17 March 2025, with phased prohibitions: import/sale of CVs incorporating covered software prohibited from model year 2027; import of covered VCS hardware prohibited from model year 2030 (or 1 January 2029 for hardware not associated with a model year). Importers and connected-vehicle manufacturers must file annual Declarations of Conformity.
UAE Cabinet Decision No. 142 of 2024, announced 9 December 2024 and formally gazetted 11 February 2025, introduces a Domestic Minimum Top-Up Tax (DMTT) on UAE constituent entities of Multinational Enterprise (MNE) groups with consolidated annual revenues ≥ EUR 750 million in at least two of the four preceding fiscal years. The DMTT ensures a 15% minimum effective tax rate (ETR) on UAE-source profits, functioning as a Qualified Domestic Minimum Top-up Tax (QDMTT) under the OECD/G20 Pillar Two GloBE framework, thereby giving the UAE first-priority taxing right before any IIR top-up by a parent-jurisdiction authority. The measure applies to fiscal years beginning on or after 1 January 2025. The UAE deliberately excluded the Income Inclusion Rule (IIR) and Under-Taxed Profits Rule (UTPR) from this primary instrument, deferring those to subsequent Cabinet Decisions; the QDMTT-only architecture mirrors Singapore's MEMTA and Switzerland's MindStV as the first-mover design choice for established low-tax financial hubs.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
Regulation (EU) 2024/2747, adopted on 9 October 2024 and published in the Official Journal on 8 November 2024, establishes the EU's first dedicated framework to anticipate, prepare for and respond to crises affecting the internal market. IMERA creates a two-tier "vigilance" / "emergency" mode architecture, sets up the Internal Market Emergency and Resilience Board (IMERB) to coordinate Member States and advise the Commission, and equips the Commission with last-resort powers including mandatory information requests to economic operators, priority-rated orders for crisis-relevant goods, fast-track conformity-assessment procedures, and rules to safeguard free movement of goods, services and persons. The regulation amends Council Regulation (EC) No 2679/98 (the "Strawberries Regulation") and becomes applicable on 29 May 2026.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
Regulation (EU) 2023/2675 — the Anti-Coercion Instrument (ACI) — is the EU's first horizontal trade-defence framework explicitly empowering the Union to respond to economic coercion by third countries. Adopted by the European Parliament and Council on 22 November 2023, published in the Official Journal on 7 December 2023, and in force from 27 December 2023, it lets the European Commission (i) determine that a third country is applying economic coercion against the Union or a Member State, (ii) seek dialogue, cessation, and reparation, and (iii) impose Union response measures — including tariffs, services-trade restrictions, IP-rights restrictions, public-procurement restrictions, and FDI restrictions targeting nationals or controlled entities of the coercing state. It complements but does not duplicate the Foreign Subsidies Regulation (which addresses subsidies, not coercion).
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
The Federal Act of 22 March 2002 on the Implementation of International Sanctions (Embargogesetz / EmbG, SR 946.231), in force 1 January 2003, is Switzerland's foundational enabling statute authorising the Federal Council to issue coercive-measure ordinances implementing UN Security Council mandatory sanctions (under UN Charter Art. 25 obligations accepted upon Switzerland's 2002 UN accession), OSCE sanctions decisions, and — via the progressive EU-tracking clause — the sanctions of Switzerland's most important trading partners, primarily the EU. The State Secretariat for Economic Affairs (SECO) administers all resulting ordinances; FINMA supervises financial-sector compliance and FOEN supervises trade-in-goods compliance. The EmbG is the parent authority for Switzerland's entire portfolio of approximately 25 country-specific sanctions ordinances, including the Ukraine/Russia ordinance (SR 946.231.176.72 implementing EU Russia packages 1-19+), the Iran ordinance (SR 946.231.143.6), the DPRK ordinance (SR 946.231.127.6), the Myanmar ordinance (SR 946.231.157.5), and the Belarus ordinance (SR 946.231.116.9).