Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On March 11, 2025 FinCEN issued a Geographic Targeting Order (GTO) under 31 USC 5326 — published in the Federal Register on March 14, 2025 (FR Doc. 2025-04099) and effective April 14, 2025 — requiring every money services business (MSB) located in 30 designated ZIP codes across seven counties in California (Imperial, San Diego) and Texas (Cameron, El Paso, Hidalgo, Maverick, Webb) to file a Currency Transaction Report (CTR) on cash transactions of more than $200 but not more than $10,000, far below the Bank Secrecy Act's standard $10,000 CTR floor. The order also imposed customer-identification recordkeeping and, per the FinCEN order text, gave covered MSBs thirty (30) days to file CTRs (vs. the standard fifteen). It was framed by Treasury as part of the post-January-2025 cartel-targeting policy stack (Trump Executive Order 14157 designating Mexican drug cartels as Foreign Terrorist Organizations / SDGTs) and was intended to surface low-value cash flows used by Mexico-based cartels and related criminal actors. The GTO was a 180-day order set to expire September 9, 2025; it was subsequently superseded on September 10, 2025 by a modified GTO that raised the threshold to $1,000 in response to MSB-industry feedback on burden, expanded geography to Arizona, and was itself replaced/expanded again on March 10, 2026.
Indonesia issued Government Regulation (Peraturan Pemerintah) No. 8 of 2025 on Foreign-Exchange Proceeds from Natural-Resource Exports (DHE SDA), amending PP No. 36/2023. President Prabowo Subianto announced the policy at Merdeka Palace on 17–18 February 2025 and the regulation takes effect on 1 March 2025. It mandates that exporters of non-oil- and-gas mining, plantation, forestry, and fisheries products with export-proceeds value of USD 250,000 or more per shipment retain 100 percent of those foreign-exchange proceeds inside Indonesia's financial system for 12 months — sharply up from the prior 30 percent for 3 months under PP 36/2023. Oil-and-gas exporters remain on the earlier 30 percent / 3-month regime. Permitted in-period uses include rupiah conversion at the holding bank, payment of state obligations in foreign currency, dividend distribution, payment for imported raw materials and capital goods unavailable domestically, and servicing of foreign-currency capital-expenditure loans. Non-compliance carries administrative sanctions including suspension of export services. The government has projected the measure could lift retained foreign- exchange proceeds by USD 80 billion in 2025 and over USD 100 billion on a full 12-month basis.
El Salvador's Legislative Assembly adopted Decreto Legislativo No. 199 on 29 January 2025 with 55 of 60 votes, reforming six articles and repealing three articles of the original Ley Bitcoin (Decreto 57, June 2021). The reform downgrades Bitcoin from compulsory legal tender to voluntary acceptance only — private parties are no longer obliged to accept BTC payments, and Bitcoin can no longer be used to pay taxes or settle public-sector debts. The State also withdraws from operational involvement in the Chivo Wallet platform. The reform is an explicit prior action under the IMF's US$1.4 billion Extended Fund Facility (EFF) programme (IMF Country Report 25/58), published in the Diario Oficial on 30 January 2025 and entering into force 90 days later on 30 April 2025.
BIS (acting through its Office of Information and Communications Technology and Services, OICTS) published a final rule under Executive Order 13873's ICTS authority prohibiting certain connected-vehicle (CV) transactions involving hardware and software designed, developed, manufactured, or supplied by persons owned by, controlled by, or subject to the jurisdiction of the People's Republic of China or the Russian Federation. The rule reaches the Vehicle Connectivity System (VCS — hardware/software enabling external RF connectivity above 450 MHz) and the Automated Driving System (ADS) software stack. Effective 17 March 2025, with phased prohibitions: import/sale of CVs incorporating covered software prohibited from model year 2027; import of covered VCS hardware prohibited from model year 2030 (or 1 January 2029 for hardware not associated with a model year). Importers and connected-vehicle manufacturers must file annual Declarations of Conformity.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
The Republic of Korea's National Assembly passed the Framework Act on the Development of Artificial Intelligence and the Establishment of a Foundation for Trustworthiness ("AI Basic Act") in plenary session on 26 December 2024, consolidating 19 separate AI bills tabled in the 22nd National Assembly. The statute was promulgated on 21 January 2025 and takes effect on 22 January 2026 after a one-year preparation period. Korea becomes the second jurisdiction worldwide — after the EU AI Act — to enact a comprehensive horizontal AI law, and the first in the Asia-Pacific. The Act establishes a risk-tiered regime targeting "high-impact" AI in healthcare, energy, public services, employment decisions, and generative-AI labelling, with extraterritorial reach over foreign providers whose systems affect the Korean market or users (mandatory local representative). It creates an AI Safety Institute, a national AI policy "control tower," and R&D / standardisation programmes under MSIT. Penalties are modest by international comparison — fines up to KRW 30 million plus a one-year grace period before full enforcement.
Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727), gazetted 17 October 2024, enters its third and final commencement phase on 1 June 2025 per commencement order P.U.(B) 522/2024. Phase 3 activates sections 6 and 9 of the amending Act, which impose mandatory Data Protection Officer (DPO) appointment thresholds, a 72-hour breach-notification duty to the Commissioner, and a statutory data-portability right, bringing Malaysia's PDPA broadly into alignment with GDPR and the ASEAN Model AI Governance Framework.
The Office of Foreign Assets Control (OFAC) issued a final rule on 19 December 2024 amending 32 parts of 31 CFR chapter V to modernize the general licenses authorizing payments for legal services from funds originating outside the United States. The rule replaces the annual reporting requirement that had applied to such payments with a 10-year recordkeeping requirement, aligning the legal-services general licenses with the new 10-year statute of limitations for IEEPA/TWEA violations and OFAC's parallel 5→10-year recordkeeping extension (31 CFR 501). The rule also standardises legal-services general-license language across programs — removing legacy letter-of-engagement prerequisites in certain parts (e.g., 31 CFR 594, 597), updating 31 CFR 549 (Lebanon) and 31 CFR 576 (Iraq Stabilization and Insurgency) to remove the requirement that payments for authorised legal services be separately specifically licensed, and harmonising the 31 CFR 591 (Venezuela-related) authorisation language. The rule was effective 19 December 2024 with an applicability date of 12 March 2025.
UAE Cabinet Decision No. 142 of 2024, announced 9 December 2024 and formally gazetted 11 February 2025, introduces a Domestic Minimum Top-Up Tax (DMTT) on UAE constituent entities of Multinational Enterprise (MNE) groups with consolidated annual revenues ≥ EUR 750 million in at least two of the four preceding fiscal years. The DMTT ensures a 15% minimum effective tax rate (ETR) on UAE-source profits, functioning as a Qualified Domestic Minimum Top-up Tax (QDMTT) under the OECD/G20 Pillar Two GloBE framework, thereby giving the UAE first-priority taxing right before any IIR top-up by a parent-jurisdiction authority. The measure applies to fiscal years beginning on or after 1 January 2025. The UAE deliberately excluded the Income Inclusion Rule (IIR) and Under-Taxed Profits Rule (UTPR) from this primary instrument, deferring those to subsequent Cabinet Decisions; the QDMTT-only architecture mirrors Singapore's MEMTA and Switzerland's MindStV as the first-mover design choice for established low-tax financial hubs.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published in the Federal Register (89 FR 84472–84474, FR Doc 2024-24524) three general licenses issued under the Western Balkans Stabilization Regulations (31 CFR Part 588): GL 3A, GL 4, and GL 5. All three were originally issued on 18 June 2024 concurrent with OFAC's expansion of Republika Srpska / Dodik-network designations; the 23 October 2024 Federal Register notice formalises them per the Administrative Procedure Act notice requirements. GL 3A (which superseded GL 3 of 16 November 2023) authorises transactions involving certain WBSR-blocked entities that are ordinarily incident and necessary to the exportation or re-exportation of agricultural commodities, medicine, medical devices, replacement parts and components, software updates, or activities involving medical prevention, diagnosis, treatment, or clinical trials. GL 4 authorises wind-down transactions with entities blocked on 18 June 2024 through a defined cutoff. GL 5 authorises transactions ordinarily incident and necessary to the manufacture, distribution, operation, installation, or maintenance/repair of drinking-water pumps manufactured or distributed by the WBSR-blocked Bosnian Serb entity Kaldera Company EL PGP d.o.o. (and 50%-or-more-owned subsidiaries), preserving municipal water supply continuity.
FinCEN published a final rule (FR Doc 2024-23920, 89 FR 83782, effective on publication October 18, 2024) clarifying the public-utility exemption to the Corporate Transparency Act's beneficial ownership information (BOI) reporting rule. The amendment to 31 CFR 1010.380(c)(2)(xv) corrects a drafting cross-reference so the exemption explicitly covers any regulated public utility under 26 U.S.C. 7701(a)(33)(A) *or* (D) that provides telecommunications services, electrical power, natural gas, or water and sewer services within the United States. The change codifies FinCEN's June 10, 2024 telecommunications-provider guidance and is effective immediately upon publication; it neither expands nor restricts the underlying universe of reporting companies beyond aligning the rule text with the CTA statute.
Regulation (EU) 2024/2747, adopted on 9 October 2024 and published in the Official Journal on 8 November 2024, establishes the EU's first dedicated framework to anticipate, prepare for and respond to crises affecting the internal market. IMERA creates a two-tier "vigilance" / "emergency" mode architecture, sets up the Internal Market Emergency and Resilience Board (IMERB) to coordinate Member States and advise the Commission, and equips the Commission with last-resort powers including mandatory information requests to economic operators, priority-rated orders for crisis-relevant goods, fast-track conformity-assessment procedures, and rules to safeguard free movement of goods, services and persons. The regulation amends Council Regulation (EC) No 2679/98 (the "Strawberries Regulation") and becomes applicable on 29 May 2026.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Office of Foreign Assets Control (OFAC) issued a final rule on 8 October 2024 amending the Reporting, Procedures and Penalties Regulations (RPPR) at 31 CFR Part 501. The rule finalises portions of OFAC's 10 May 2024 interim final rule and adds three exceptions to the requirement to file a report with OFAC concerning blocked property that is unblocked or transferred. It also implements other technical clarifications to OFAC's reporting framework. The rule takes effect on 7 November 2024.
On 6 September 2024 China's National Development and Reform Commission (NDRC) and Ministry of Commerce (MOFCOM) jointly issued Order No. 23, the Special Administrative Measures (Negative List) for Foreign Investment Access (2024 Edition), effective 1 November 2024. The 2024 list reduces nationwide restrictions from 31 to 29 entries, removing the last two manufacturing- sector restrictions (publication printing must be Chinese-controlled; investment in TCM-decoction steaming/roasting/calcination processes and confidential-formula proprietary Chinese-medicine production prohibited). Restrictions remain in services (telecommunications value-added, healthcare, education) and in 21 prohibited categories (news publishing, postal monopoly, fishing, gene therapy, tobacco). The 2021 edition is repealed on the same date.
FinCEN issued a final rule (89 FR 70258, FR Doc 2024-19198) requiring certain real-estate-closing and settlement professionals to file a new "Real Estate Report" and maintain records on non-financed (i.e., all-cash) transfers of U.S. residential real property to specified legal entities and trusts, on a nationwide basis. The rule uses a "reporting cascade" to designate one filer per transaction (settlement agent, title-insurance underwriter, escrow agent, or attorney, depending on which is present), replacing the long-running geographic-targeting-order (GTO) regime with a permanent nationwide framework. The original effective date of December 1, 2025 was subsequently postponed to March 1, 2026 via a FinCEN exemptive-relief order issued September 30, 2025.
FinCEN issued a final rule (published September 4, 2024 at 89 FR 72156; FR Doc 2024-19260) including most SEC-registered investment advisers (RIAs) and Exempt Reporting Advisers (ERAs) within the Bank Secrecy Act definition of "financial institution." Covered firms must implement a risk-based AML/CFT compliance program, appoint a compliance officer, train staff, obtain independent testing, file Suspicious Activity Reports (SARs) and Currency Transaction Reports (CTRs), and participate in §314(a)/(b) information sharing. The original compliance date was January 1, 2026; FinCEN subsequently delayed the effective date to January 1, 2028 by final rule published 2026-01-02 (FR Doc 2025-24184).
India's Finance (No. 2) Act, 2024 (Act No. 15 of 2024) repeals the 2% Equalisation Levy on e-commerce supplies and services by non-resident operators (§165A of the Finance Act 2016, introduced 2020), with effect from 1 August 2024. The repeal removes a long-standing US trade irritant — the USTR had found the 2% levy unreasonable under a Section 301 investigation, and India agreed in October 2021 to remove it as part of a multilateral OECD Pillar 1 commitment, formally implemented here three years later. The residual 6% Equalisation Levy on digital advertising under §165 (in force since 2016) was not touched by this Act and remained in force until its own repeal effective 1 April 2025 via a subsequent Finance Act.
The Department of Commerce published a final rule redesignating the regulations implementing Executive Order 13873 (Securing the Information and Communications Technology and Services Supply Chain) from 15 CFR subtitle A, part 7 (Office of the Secretary of Commerce) to 15 CFR subtitle B, chapter VII, part 791, under the Bureau of Industry and Security (BIS). The redesignation reflects the formal transfer of ICTS-transaction review authority from the Secretary of Commerce to BIS's new Office of Information and Communications Technology and Services (OICTS). The rule is non-substantive — it relocates the existing regulatory text without altering the scope of covered ICTS transactions, the foreign-adversary list, the review procedures, or any substantive obligations on parties. Effective on publication (18 July 2024) without notice and comment because it is an internal agency reorganization.
The Ethiopian Capital Market Authority (ECMA) issued Directive No. 1009/2024 on 16 July 2024, establishing the comprehensive licensing, operational, and supervisory framework for securities exchanges, derivatives exchanges, and the over-the-counter (OTC) market under the authority of Article 108 of the Capital Market Proclamation No. 1248/2021. The directive consolidates Ethiopia's previously fragmented securities-trading architecture into a single, licensed, and regulated market structure and provided the statutory pathway for the Ethiopian Securities Exchange (ESX) to receive the country's first securities-exchange licence. This is the first capital-markets architecture filing for Ethiopia on the IPTM register, forming the operating- licence layer alongside the banking-sector liberalisation enacted under Proclamation 1360/2025.
The European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689, was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024. It establishes the world's first horizontal, risk-tiered legal framework for the development, market placement, and use of AI systems — covering prohibited practices, high-risk systems, general-purpose AI models, and minimal-risk applications — with extraterritorial reach over any provider placing an AI system on the EU market or whose output is used in the EU. Penalties reach up to EUR 35 million or 7% of global annual turnover. Application is staged: prohibitions from 2 February 2025, GPAI and governance from 2 August 2025, the bulk of high-risk obligations from 2 August 2026, and product-safety-embedded high-risk systems from 2 August 2027.
FinCEN issued a final rule under Section 311 of the USA PATRIOT Act (31 U.S.C. § 5318A) prohibiting US covered financial institutions from opening or maintaining a correspondent account for, or on behalf of, Iraq-based Al-Huda Bank, a foreign financial institution found to be of primary money-laundering concern. Treasury determined that Al-Huda Bank exploited its access to US dollars to support designated Foreign Terrorist Organizations including Iran's Islamic Revolutionary Guard Corps (IRGC) and IRGC-Quds Force, as well as Iran-aligned Iraqi militias Kata'ib Hizballah and Asa'ib Ahl al-Haq. The rule also imposes a special-due-diligence requirement on US covered institutions to guard against indirect access via foreign correspondent accounts. Published in the Federal Register on July 3, 2024; effective August 2, 2024.
The Office of Foreign Assets Control (OFAC) issued an interim final rule (IFR) on 10 May 2024 (FR Doc 2024-10033, 89 FR) amending the Reporting, Procedures and Penalties Regulations (RPPR) at 31 CFR Part 501. The IFR overhauls OFAC's reporting framework by requiring electronic submission of certain reports through the OFAC Reporting System (ORS), expanding the rejected-transaction reporting obligation to all U.S. persons (not only U.S. financial institutions), modifying blocked-property reporting procedures, updating procedures for petitions for administrative reconsideration and property-blocked-in-error requests, and revising FOIA-availability provisions. The IFR took effect on 8 August 2024 and was subsequently finalised — with three new exceptions to the blocked-property reporting requirement — by the 8 October 2024 final rule (FR Doc 2024-23217, effective 7 November 2024).
Loi n° 2024-449 of 21 May 2024, known as the SREN law (Sécuriser et Réguler l'Espace Numérique), was definitively adopted by the French Parliament on 10 April 2024, validated in part by the Conseil Constitutionnel on 17 May 2024 (Decision n° 2024-866 DC), promulgated by the President on 21 May 2024, and published in the Journal Officiel on 22 May 2024. SREN is France's digital-sovereignty omnibus statute: it transposes parts of the EU Digital Services Act (Regulation 2022/2065), Digital Markets Act (Regulation 2022/1925), and Data Governance Act (Regulation 2022/868) into French law and layers national-level instruments on top — most consequentially a data-localisation hook for sensitive public-sector data tied to the ANSSI SecNumCloud sovereign-cloud certification scheme, an ARCOM-enforced age-verification regime for adult-content sites (with €250k or 2%-of-turnover fines and account-closure powers), an "anti-scam" cybersecurity filter requiring browsers and DNS resolvers to block ANSSI-designated fraudulent domains, a jeux-en-ligne (JONUM) regime for cryptoasset-adjacent gaming, and a coordination framework between CSA, CNIL, ARCOM, and the Autorité de la concurrence. SREN is one of the first EU member-state digital omnibus statutes anchoring national public-sector data-hosting rules to a sovereign-cloud certification scheme.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
OFAC amended and reissued the Global Magnitsky Sanctions Regulations (31 CFR Part 583) in their entirety on 12 March 2024, to implement the Global Magnitsky Human Rights Accountability Act and EO 13818 (20 December 2017) more fully. The reissuance adds expanded interpretive guidance, new definitions (agricultural commodities, medicines, medical devices), new statutory authority (Uyghur Human Rights Policy Act of 2020), and several new general licenses covering blocked-account management, legal services, personal-use medical/food transactions, and emergency services. No new SDN designations or country-level targeting; the action is a compliance-architecture update that clarifies permissible conduct and tightens procedural standards across the global human-rights-and-corruption sanctions program.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published in the Federal Register (89 FR 16400, FR Doc 2024-04856) two general licenses issued under the Western Balkans Stabilization Regulations (31 CFR Part 588): GL 2 and GL 3. Both were originally issued on 16 November 2023 concurrent with OFAC's initial round of Republika Srpska / Dodik-network designations; the 7 March 2024 Federal Register notice formalises them per the Administrative Procedure Act notice requirements. GL 2 authorises wind-down transactions with newly blocked WBSR entities through 15 March 2024. GL 3 authorises exports and re-exports of agricultural commodities, medicine, medical devices, replacement parts, and services for medical prevention and treatment to WBSR-blocked persons; GL 3 was subsequently superseded by GL 3A on 18 June 2024.
The U.S. Treasury's Office of Foreign Assets Control (OFAC) published a final rule in the Federal Register (89 FR 15769, FR Doc 2024-04500) renaming the Darfur Sanctions Regulations (31 CFR Part 546) to the Sudan Stabilization Sanctions Regulations and amending them to implement Executive Order 14098 of May 4, 2023. E.O. 14098 broadened US sanctions authority beyond the Darfur-specific frame to cover all persons destabilising Sudan and undermining democratic transition, responding to the SAF–RSF armed conflict that erupted in April 2023. The rule adds new general licenses covering legal-service payments (§ 546.508), African Union transactions (§ 546.511), and agricultural/medical exports (§ 546.513), and introduces an interpretative provision clarifying that entities are not automatically blocked solely because a blocked individual holds a leadership position.
A joint advisory issued January 26, 2024 by six US agencies (USTR, State, Treasury, Commerce, DHS, and Labor) updating businesses on supply-chain risks associated with Burma's post-coup military regime (SAC). The advisory warns of reputational, economic, and legal exposure for entities operating in or sourcing from Burma and specifically flags heightened due-diligence requirements for metal importers, the SAC's opaque network of corporate affiliates in Thailand, Singapore, India, and the UAE that complicate traceability, and cross-border reporting gaps for goods and funds transfers. Targeted sectors include rare earths (dysprosium, terbium), base metals and gold mining, timber, aviation services and jet fuel, computer chips and ICT equipment, and small arms components.
FinCEN published a final rule on January 25, 2024 adjusting the maximum civil monetary penalties (CMPs) for Bank Secrecy Act (BSA) violations as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990, as amended by the 2015 Improvements Act. Adjustments are calculated using the CPI-U percent change between October 2022 and October 2023 and are codified in 31 CFR § 1010.821. The update covers 12 BSA statutory penalty provisions, ranging from per-day recordkeeping violations to wilful correspondent-account and special-measures infractions, with the largest single-penalty ceiling rising to $1,731,383.
OFAC published a final rule on January 12, 2024 adjusting the maximum civil monetary penalty (CMP) ceiling amounts across five statutory authorities as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the 2015 Improvements Act). The 2024 adjustment multiplier is 1.03241 (reflecting the October 2022–October 2023 CPI-U change). Penalties under IEEPA rise from $356,579 to $368,136; TWEA penalties from $105,083 to $108,489; and the Narcotics Kingpin Act maximum from $1,771,754 to $1,829,177. The rule is issued as a final rule effective on publication without prior notice and comment under the non-discretionary "good cause" exemption.
FinCEN published the Beneficial Ownership Information Access and Safeguards Final Rule (FR Doc 2023-27973, 88 FR 88732, December 22, 2023; effective February 20, 2024), implementing the access and disclosure provisions of Section 6403(c) of the Corporate Transparency Act (CTA) enacted as part of the Anti-Money Laundering Act of 2020. The rule defines six categories of authorized recipients permitted to access the FinCEN BOI database — US federal agencies engaged in national security/intelligence/law enforcement, state/local/tribal law enforcement, foreign law enforcement and competent authorities (via intermediary federal agency), financial institutions using BOI for customer due diligence (CDD), federal functional regulators assessing financial-institution CDD compliance, and Treasury officers/employees. Access is to be phased in, beginning with a 2024 pilot for key federal agencies before extending to financial institutions and their supervisors. The rule establishes data-security standards, re-disclosure prohibitions, and oversight mechanisms governing each recipient category.
Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data — the "Data Act" — was published in the Official Journal on 22 December 2023, entered into force on 11 January 2024, and applies generally from 12 September 2025 (with longer transitional periods for IoT product-design obligations under Article 3(1), which apply to products placed on the market after 12 September 2026, and for the data-portability standardisation framework, applicable from 12 September 2027). The Data Act is the third pillar of the EU data-economy framework alongside the GDPR (personal data) and the Data Governance Act 2022/868 (data-intermediation services), and is the world's first horizontal statutory regime governing access to and portability of industrial / IoT / non-personal data — covering by-design data-availability obligations on connected-product manufacturers, a mandatory cloud- switching framework with progressive elimination of switching charges, B2G emergency data-sharing in exceptional needs, unfair-contract-terms protection for SMEs, and safeguards against unlawful international government access to non-personal data held in EU cloud.
FinCEN published a final rule (FR Doc 2023-26399, 88 FR 83499, November 30, 2023; effective January 1, 2024) extending the initial beneficial ownership information (BOI) reporting deadline under the Corporate Transparency Act (CTA) for reporting companies created or registered in calendar year 2024. Rather than the default 30-day window, these companies receive 90 calendar days from the date of receiving actual or public notice of creation or registration becoming effective to file their initial BOI reports with FinCEN. Companies created before January 1, 2024 retain their original deadline of January 1, 2025; companies created on or after January 1, 2025 revert to the standard 30-day window.
Regulation (EU) 2023/2675 — the Anti-Coercion Instrument (ACI) — is the EU's first horizontal trade-defence framework explicitly empowering the Union to respond to economic coercion by third countries. Adopted by the European Parliament and Council on 22 November 2023, published in the Official Journal on 7 December 2023, and in force from 27 December 2023, it lets the European Commission (i) determine that a third country is applying economic coercion against the Union or a Member State, (ii) seek dialogue, cessation, and reparation, and (iii) impose Union response measures — including tariffs, services-trade restrictions, IP-rights restrictions, public-procurement restrictions, and FDI restrictions targeting nationals or controlled entities of the coercing state. It complements but does not duplicate the Foreign Subsidies Regulation (which addresses subsidies, not coercion).
FinCEN published a final rule (FR Doc 2023-24559, 88 FR 76995, November 8, 2023; effective January 1, 2024) specifying when and how entities required to report beneficial ownership information (BOI) under the Corporate Transparency Act (CTA) may use another entity's FinCEN identifier in lieu of disclosing the underlying individual beneficial owners. A reporting company may substitute a related entity's FinCEN ID when: (1) that entity has obtained a FinCEN identifier and provided it to the reporting company, (2) the individual is a beneficial owner solely through an ownership interest in the other entity, and (3) the beneficial owners of both entities are the same. Any change to beneficial ownership of the other entity requires an updated BOI report, after which the entity FinCEN identifier may no longer be used until recertified.
Saudi Arabia's Personal Data Protection Law (PDPL), issued under Royal Decree M/19 (16 September 2021) and substantively amended by Royal Decree M/148 (27 March 2023), entered into force on 14 September 2023 with a one-year transition period that ended on 14 September 2024 — at which point the Saudi Data & Artificial Intelligence Authority (SDAIA) became the binding regulator with full enforcement powers. Alongside the Implementing Regulations and the Regulations on the Transfer of Personal Data Outside the Kingdom (both issued 7 September 2023), SDAIA published in 2024 a set of four pre-approved Standard Contractual Clauses templates (C2C, C2P, P2P, P2C) governing cross-border transfers. The regime establishes consent requirements, DPO appointment, a 72-hour breach notification duty, and prior-clearance / SCC-or-BCR-style conditions on personal-data exports out of Saudi Arabia.
Canada's Fighting Against Forced Labour and Child Labour in Supply Chains Act (S.C. 2023, c. 9; "Bill S-211") received Royal Assent on 11 May 2023 and entered into force on 1 January 2024. It imposes a binding annual supply-chain disclosure obligation on government institutions and in-scope private-sector entities (any two of: ≥CAD 20m assets, ≥CAD 40m revenue, ≥250 employees) requiring a public report by 31 May each year detailing steps taken to prevent and reduce the risk of forced or child labour in their supply chains. The Act also amends the Canadian Customs Tariff (Schedule 9898.00.00) to extend the existing import prohibition on goods produced with forced labour to also cover goods produced with child labour, enforced at the border by the Canada Border Services Agency (CBSA). Criminal penalties of up to CAD 250,000 apply for non-compliance, false reporting, or obstruction.
FinCEN published a final rule on January 19, 2023 (88 FR 3312) adjusting the maximum civil monetary penalties for Bank Secrecy Act (BSA) violations under 31 CFR § 1010.821, as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the 2015 Improvements Act). The 2023 multiplier is 1.07745, reflecting the October 2021 → October 2022 CPI-U change per OMB Memorandum M-23-05. A correction notice (88 FR 7357, Feb. 3, 2023) revised certain table entries; the corrected amounts are authoritative and are reflected in this filing. The table covers 10 BSA statutory penalty provisions, with the largest single-penalty ceiling rising to $1,677,030.
OFAC published a final rule on January 13, 2023 adjusting the maximum civil monetary penalty (CMP) ceiling amounts across multiple statutory sanctions authorities as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015). The adjustment covers IEEPA, TWEA, and the Narcotics Kingpin Act authorities, resetting the penalty ceilings that apply to violations adjudicated through 2023. A correction notice (C1-2023-00593, April 17, 2023) fixed a purely typographical error in Appendix A to 31 CFR Part 501 — paragraph numbering "v" corrected to "vi" — with no change to any penalty amount.
On 21 December 2022 OFAC published final rule FR Doc 2022-27564, amending 30 CFR parts (31 CFR Parts 510, 525, 536, 539, 541, 542, 544, 546, 547, 548, 549, 551, 552, 555, 558, 560, 561, 562, 569, 576, 579, 582, 583, 584, 585, 591, 594, 596, 597, 598) to add or update general licenses authorising (1) official business of the US government and (2) official business of designated international organisations and entities across the full OFAC program library. The rule also updates the 50 Percent Rule interpretive provision, clarifying that an entity's property is blocked when one or more blocked persons own an aggregate interest of 50 percent or more — directly or indirectly — and corrects CFR citations to meet current Federal Register formatting requirements. Published as companion to FR Doc 2022-27639 (NGO and humanitarian GLs), both rules effective 21 December 2022.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
FinCEN issued a final rule (87 FR 59498, September 30, 2022) implementing the Corporate Transparency Act (CTA) by requiring most corporations, limited liability companies, and similar entities created in or registered to do business in the United States to file beneficial ownership information (BOI) reports with FinCEN. Reporting companies must identify two categories of individuals: beneficial owners (persons exercising substantial control or owning ≥25% of the entity) and company applicants (persons who filed the formation documents). Entities formed before January 1, 2024 had until January 1, 2025 to file; entities formed on or after that date had 30 days. Non-compliance carries civil penalties of up to $500/day and criminal penalties of up to $10,000 and two years imprisonment.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).