Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Latvia's Saeima adopted on 27 March 2024 amendments to the National Security Law (Nacionālās drošības likums), entering into force on 24 April 2024, that widen the perimeter of foreign-investment and ownership transactions subject to Cabinet of Ministers pre-clearance over "companies of significance to national security." The amendments expand the universe of regulated subjects beyond registered companies to include foundations and associations, tighten the rules on beneficial-ownership disclosure, and bring additional sensitive activities — energy security including LNG-terminal acquisitions, electronic communications, cybersecurity, and critical-raw-materials processing — under the regime, while clarifying Cabinet authority to impose conditions or unwind transactions retroactively. The law functions as Latvia's horizontal FDI-screening instrument under the EU-wide cooperation framework of Regulation 2019/452.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Bulgaria's National Assembly adopted on 22 February 2024 amendments to the Investment Promotion Act establishing the country's first horizontal foreign direct investment screening mechanism, published in State Gazette No. 20 on 8 March 2024 and entering into force on 12 March 2024. The regime implements EU Regulation 2019/452 by creating an Interdepartmental Screening Council with a 45-day decision window over non-EU investments meeting a 10 % equity stake or €2 million threshold in critical-infrastructure, dual-use, advanced-technology, media, and financial-infrastructure sectors, with no threshold for investments by Russian or Belarusian persons or in oil and petroleum activities. Non-compliance and false declarations carry fines of 5 % of investment value, with a minimum BGN 50,000.
Ireland's Screening of Third Country Transactions Act 2023 (Act No. 28 of 2023), signed into law on 31 October 2023 and commenced on 6 January 2025 via S.I. No. 651 of 2024, establishes Ireland's first-ever mandatory inbound FDI screening regime. The Act empowers the Minister for Enterprise, Tourism and Employment to assess, condition, or prohibit transactions by third-country investors (non-EU/EEA/Switzerland) exceeding a EUR 2 million cumulative threshold in targets operating across critical infrastructure, critical technologies, dual-use items, supply of critical inputs, sensitive personal data, and media freedom. A 90-day standstill period applies during Ministerial determination, with criminal sanctions and transaction-voiding powers available for non-compliance.
Decree-Law No. 104 of 10 August 2023 ("Decreto Asset" / Omnibus Decree, GU n.186 of 10 Aug 2023, in force 11 Aug 2023) was converted with amendments into Law No. 136 of 9 October 2023 (GU n.236 of 9 Oct 2023). The conversion law materially expanded Italy's "Golden Power" foreign-direct-investment screening regime (DL 21/2012). Two key extensions: (i) intra-group transactions involving entities outside the EU are no longer exempt from the exercise of special powers — only the prior notification carve-out was preserved; (ii) acts, resolutions and operations concerning intellectual-property rights in artificial intelligence, semiconductor production, cybersecurity, aerospace, energy storage, quantum and nuclear technologies, and food production technologies fall within scope when one or more counter-parties sit outside the EU. The Prime Minister also obtained an explicit veto power over transactions creating "exceptional situations" not already covered by sectoral or EU prudential / merger rules, including those touching qualifying holdings in the financial sector.
Bureau of Industry and Security final rule (88 FR 46071, Doc 2023-15343) adding four entities to the Entity List effective July 18, 2023. Intellexa S.A. (Greece) and Intellexa Limited (Ireland) — the corporate architecture behind the "Predator" commercial spyware platform — and Cytrox Holdings Zrt. (Hungary) and Cytrox AD (North Macedonia) — the developer of the underlying spyware technology — were listed for "trafficking in cyber exploits used to gain access to information systems, thereby threatening the privacy and security of individuals and organizations worldwide." All items subject to the EAR require a license with a presumption-of-denial review policy for all four entities, effectively cutting off access to US-origin hardware, software, and technology.
Luxembourg's Chambre des Députés adopted the first-ever national FDI-screening statute on 14 July 2023 (promulgated by the Grand Duke and published in Mémorial A n° 411 on 18 July 2023), entering into force 1 September 2023. The law requires non-EU investors to notify the Ministre de l'Économie before completing direct or indirect acquisitions of ≥25% voting rights / equity in Luxembourg entities engaged in "critical activities" across twelve sectors. The Minister can approve, conditionally approve, or prohibit transactions within a two-month initial screening window, with a further 60-day deep-review phase available; an inter-ministerial Comité de filtrage (Economy + Foreign Affairs + Finance + SREL intelligence service) advises on security and public-order grounds consistent with EU Regulation 2019/452.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
Belgium's first horizontal foreign-direct-investment screening regime, established by a Cooperation Agreement signed on 30 November 2022 between the Federal State and the Flemish, Walloon, Brussels-Capital and German-Community governments, and in force from 1 July 2023. The agreement creates a centralised Interfederal Screening Commission (ISC), chaired by the FPS Economy, to receive and process mandatory ex-ante notifications of foreign acquisitions of 10%, 25% or higher voting-rights / control thresholds (sector-dependent) in Belgian undertakings active in eleven strategic sectors. ISC decisions are binding; sanctions for failure to notify or for non-compliance with conditions imposed include unwinding of the transaction and administrative fines.
OFAC reissued the Cyber-Related Sanctions Regulations (31 CFR Part 578) in their entirety on 6 September 2022, replacing the abbreviated placeholder framework first published on 31 December 2015. The reissuance implements Executive Order 13694 (1 April 2015, blocking property of persons engaging in significant malicious cyber-enabled activities) and Executive Order 13757 (28 December 2016, expanding that authority to include election interference). The full-form regulations add interpretive definitions, general licences, and civil-penalties provisions — providing compliance clarity for US financial institutions and technology companies without expanding the underlying sanctions perimeter.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
BIS finalized changes to the Export Administration Regulations (EAR) governing controls on cybersecurity items — primarily intrusion software, command-and-control platforms, and surveillance tools capable of disrupting or monitoring information systems without authorization. The final rule, effective May 26 2022, revises License Exception ACE (Authorized Cybersecurity Exports) originally established by an October 2021 interim rule and narrows end-user carve-outs for government end users in Country Group D:5 and A:6 destinations. Exports of affected ECCNs (4A005, 4D001, 4D004, 4E001, 5A001.j, 5B001, 5D001, 5E001) to Country Groups E:1 and E:2 remain prohibited; D:1 through D:5 government-end-user transactions require a license.
BIS published an interim rule on January 12, 2022 delaying the effective date of its October 21, 2021 cybersecurity items interim final rule by 45 days, from January 19, 2022 to March 7, 2022. The underlying October 2021 rule establishes new Export Control Classification Numbers (ECCNs) for cybersecurity items — including intrusion software, command-and-control platforms, and surveillance tools — and introduces License Exception ACE (Authorized Cybersecurity Exports) for national security and anti-terrorism purposes. The delay was granted after twelve public comments highlighted significant compliance challenges, with BIS acknowledging the need for additional time for industry to update procedures and for BIS to issue supplemental guidance before the controls took effect.
On November 4, 2021, BIS added four entities to the Entity List under a policy of denial: NSO Group and Candiru (Israel), Positive Technologies (Russia), and Computer Security Initiative Consultancy PTE (Singapore). NSO Group and Candiru were designated for supplying commercial spyware to foreign governments used to maliciously surveil government officials, journalists, activists, and academics; Positive Technologies and CSIC for trafficking cyber tools enabling unauthorized access to information systems. All four entities now require BIS licenses for any export, re-export, or in-country transfer of EAR-controlled items, with a presumption of denial.
BIS published an interim final rule on October 21, 2021 establishing new Export Control Classification Numbers (ECCNs 4A005, 4D004, 4E001.c, and 5A001.j) for intrusion software systems, command-and-control platforms, and IP network surveillance tools, implementing the Wassenaar Arrangement 2017 cybersecurity decisions into the Export Administration Regulations (EAR). The rule simultaneously created License Exception ACE (Authorized Cybersecurity Exports), codified at § 740.22, to authorize exports to most destinations while imposing licence requirements — or outright prohibitions — for sales to Country Groups E:1/E:2 governments and certain D-group government end-users. Carve-outs for vulnerability disclosure and cyber-incident-response activities were included to protect legitimate security research. The effective date was subsequently delayed from January 19, 2022 to March 7, 2022 by a separate interim rule (FR 2022-00448), and the rule was finalized with revisions on May 26, 2022 (FR 2022-11282).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Bureau of Industry and Security amended the Export Administration Regulations by adding six Russian technology entities to the Entity List, all designated consistent with Executive Order 14024 on blocking property associated with harmful foreign activities of the Russian government. The designated entities operate in Russia's technology sector and have been determined to support Russian intelligence services, including notable cybersecurity firms and defense-innovation institutions. All items subject to the EAR require a BIS licence for export, reexport, or transfer to these parties, subject to a presumption-of-denial review policy with no licence exceptions available. The rule also corrects an existing FSB entry to reference updated General Licence No. 1B.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
Regulation (EU) 2021/821, adopted 20 May 2021 and applied from 9 September 2021, establishes the Union regime for controlling exports, brokering, technical assistance, transit, and transfer of dual-use items, repealing Regulation (EC) No 428/2009. Annex I lists controlled items implementing internationally agreed dual-use controls under the Wassenaar Arrangement, MTCR, Australia Group, NSG, and Chemical Weapons Convention. The regulation introduces a new catch-all control on cyber-surveillance technologies that could facilitate human-rights violations (Art. 5 and Annex IV), and strengthens cooperation between Member States and the European Commission, placing specific obligations on exporters. It serves as the statutory anchor for all EU export licences, every multilateral-regime transposition into EU law, and coordination mechanisms with US BIS, UK ECJU, JP METI, and KR MOTIE export-control regimes.
The German Federal Government adopted the 17th amendment to the Außenwirtschaftsverordnung (AWV, Foreign Trade and Payments Ordinance), published 30 April 2021 and entering into force 1 May 2021, aligning Germany's FDI screening regime with EU Regulation 2019/452. The amendment adds 16 further sectors to the sector-specific mandatory-notification regime, on top of the 11 already covered, bringing the total to 27 -- including AI, robotics, autonomous vehicles/drones, semiconductors, quantum technology, satellite systems, cybersecurity, and critical raw materials. Filing thresholds are voting-rights acquisitions of 10% or more by a non-EU/EFTA investor in the newly added sectors, with subsequent review triggers at 20%, 25%, 40%, 50% and 75%.
BIS published an interim final rule on 5 October 2020 implementing multilateral export controls on six emerging technology categories agreed at the December 2019 Wassenaar Arrangement Plenary meeting, revising Commerce Control List ECCNs 2B001, 3D003, 3E004, 5A004, 5D001, and 9A004. The six technologies are: hybrid additive-manufacturing/CNC machine tools; computational lithography software for extreme-ultraviolet (EUV) mask fabrication; wafer-finishing technology for 5 nm-node production; digital forensics tools that circumvent device authentication to extract raw data; software for monitoring and analysis of communications acquired from a handover interface; and sub-orbital craft. As the first of two US implementing actions for the 2019 Wassenaar Plenary, this rule elevated nascent commercial technologies into permanent CCL classifications enforceable against all non-EAR99 destinations.
The Investitionskontrollgesetz (InvKG, "Investment Control Act") is Austria's horizontal, statutory FDI screening regime. Published as Article 1 of the Federal Law BGBl. I Nr. 87/2020 on 24 July 2020 and entering into force on 25 July 2020, the Act replaced the previous narrow §§25a–25e Außenwirtschaftsgesetz 2011 (Foreign Trade Act) regime — under which fewer than 10 permits were issued from 2013 to mid-2020 — and transposes EU Regulation 2019/452 establishing a framework for the screening of foreign direct investments into the Union. The InvKG introduces mandatory ex-ante notification and approval of non-EU / non-EEA / non-Swiss acquisitions where the acquirer crosses any of the 10% / 25% / 50% voting-rights thresholds in an Austrian target operating in the critical sectors listed in Annex Part 1 (especially sensitive: defence, energy / water / telecoms critical infrastructure, dual-use technology, cybersecurity, AI, quantum technology, robotics, semiconductors, biotech, health, vaccines) and 25% / 50% in the sectors listed in Annex Part 2 (broader, including media, food-security, electronic communications infrastructure, financial infrastructure). Administered by the Bundesministerium für Arbeit und Wirtschaft (BMAW), with case decisions taken in coordination with the Komitee für Investitionskontrolle (inter-ministerial Investment Control Committee) and, where the case is escalated to the EU cooperation mechanism, the Commission and EU peer Member States. The InvKG is Austria's functional peer of US CFIUS / FIRRMA, UK NSI Act 2021, Germany AWG §§55–62, France Décret 2014-479 / R. 151-1 et seq., Italy Golden Power Decree, Netherlands Wet Vifo, Denmark investeringsscreeningsloven, and Belgium ISC. Sunset clause: originally limited to 30 June 2022 under §17(2) InvKG; permanently extended by BGBl. I Nr. 80/2022 of 14 July 2022.
The modern French FDI-screening regime is codified in Code monétaire et financier (CMF) Art. L151-1 to L151-7, substantially restructured by Loi PACTE n° 2019-486 du 22 mai 2019 (Art. 152-158) and operationalised by Décret n° 2019-1590 du 31 décembre 2019 (in force 1 April 2020) with implementing Arrêté du 31 décembre 2019. The regime requires prior authorisation from DG Trésor for non-EU/EEA acquisitions reaching ≥25% of a French target's voting rights across 17 sensitive sectors enumerated in CMF Art. R151-3, and for ≥10% acquisitions in listed-company targets (threshold made permanent by Décret 2023-1293 from 1 January 2024, having been originally introduced during COVID-19 by Décret 2020-892). Approximately 310 notifications are received annually; the regime closes the last major G7 EU-member-state FDI-screening parent-statute gap after DE AWG §§55-62, IT Golden Power DL 21/2012, NL Wet Vifo, UK NSI Act 2021, US CFIUS, JP FEFTA, AU FATA, and CH IPG.
The Sanctions and Anti-Money Laundering Act 2018 (SAMLA, Chapter 13) received Royal Assent on 23 May 2018 and established the UK's autonomous post-Brexit sanctions legal framework. Part 1 empowers Ministers (FCDO, HM Treasury) to impose financial, trade, immigration, aircraft, and shipping sanctions by statutory instrument for purposes including UN compliance, national security, foreign-policy objectives, and promotion of human rights and democracy. Part 2 grants Ministers authority to make AML and counter-terrorist-financing regulations aligned with FATF standards, previously derived from EU Anti-Money-Laundering Directives. SAMLA is the parent enabling statute for every UK sanctions regime in force post-Brexit, including 30+ thematic and geographic regulations covering Russia (SI 2019/855), Iran, DPRK, Belarus, Myanmar, Syria, Venezuela, cyber, chemical weapons, global anti-corruption, and global human rights; under SAMLA, OFSI (HM Treasury) holds civil monetary-penalty and criminal-referral enforcement powers. Structurally peer to US IEEPA, EU Council Regulation framework, CN AFSL 2021, and JP FEFTA as the G7+CN foundational sanctions-statute cluster.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
The International Emergency Economic Powers Act of 1977 (IEEPA, Title II of Pub. L. 95-223, 91 Stat. 1626, codified at 50 U.S.C. §§ 1701–1708) was signed by President Carter on 28 December 1977 and grants the President sweeping authority to declare a national emergency with respect to "any unusual and extraordinary threat, which has its source in whole or substantial part outside the United States, to the national security, foreign policy, or economy of the United States" — and then to investigate, regulate, direct, compel, nullify, void, prevent, or prohibit any transaction in, or involving, foreign exchange, banking transfers, importing, exporting, or dealings in property by persons subject to US jurisdiction. IEEPA is the parent enabling statute for every OFAC-administered autonomous sanctions program (Russia, Iran, DPRK, Venezuela, Cuba, Syria, Belarus, Myanmar, cyber, Global Magnitsky, Hong Kong, ICC, and others) as well as the legal basis for the entire Trump-era IEEPA-tariff regime (EO 14193–14195 fentanyl tariffs, Canada/Mexico/China; EO 14257 reciprocal-tariff framework; EO 14323 Brazil; EO 14380 Cuba; EO 14382 Iran; and the US-India interim tariff agreement). Between 1977 and 2025 Presidents invoked IEEPA in 77 national-emergency declarations; of these, 7+ directly parent IPTM-filed implementing actions, with ~dozens of OFAC SDN designation actions tracing their legal root to this statute.