Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Brazil's Foreign Trade Chamber Executive Committee (GECEX/CAMEX, under the Ministry of Development, Industry, Trade and Services) approved Resolução Gecex nº 824, dated 4 December 2025, rebalancing the country's ex-tarifário IT- and telecommunications-goods (BIT) duty-relief regime. The resolution excludes a batch of expired or superseded ex-tarifário codes from Annex I of the base Resolução Gecex nº 323/2022 — reverting those products to Brazil's standard import tariff — and adds a new batch of exemptions to the Anexo Único of Resolução Gecex nº 781/2025, extending duty relief on a different set of IT/telecom products (printing equipment, data-processing machines, telecom apparatus, network/fibre-optic components, mobile-phone components) through late 2027. Global Trade Alert's analysis counts 301 IT/telecommunications products as affected by the net exclusion/inclusion changes. Published in the Diário Oficial da União on 5 December 2025, the resolution entered into force seven days after publication (12 December 2025).
President Trump signed Executive Order "Saving TikTok While Protecting National Security" on September 25, 2025, certifying a restructuring plan as a "qualified divestiture" under the 2024 PAFACA law and directing the Attorney General not to enforce the Act for 120 days while the transaction closes. The plan creates TikTok USDS Joint Venture LLC, valued at roughly $14 billion, with a new US-investor consortium (Oracle, Silver Lake and MGX at 15% each, plus other investors, totaling 50%), affiliates of existing ByteDance investors holding 30.1%, and ByteDance itself retaining 19.9%. Oracle will run US data storage and algorithm retraining/oversight; the deal closed January 22, 2026.
Brazil's Foreign Trade Chamber executive committee (GECEX) issued Resolution No. 732, dated 20 May 2025 and published in the Diário Oficial da União on 21 May 2025, amending Annexes II and VI of Resolução Gecex nº 272/2021 — the instrument that adapted Brazil's Common Mercosur Nomenclature (NCM) and Common External Tariff (TEC) to the 2022 Harmonized System revision. The amendment recomposes the TEC toward its full bound level for products on the IT/telecom (LEBIT) and capital-goods (BK) special-tariff exception lists, while carving out roughly 925 NCM codes across some 585 six-digit HS subheadings from the recomposition; secondary reporting describes the net effect as duty cuts on select data-processing and telephone equipment paired with duty increases across the broader excepted product set. Global Trade Alert classifies the measure as a "Red" (trade-restrictive) import-tariff intervention.
On 27 February 2025, the Parliament of the Republic of Moldova adopted Law No. 33/2025 amending Law No. 174/2021 on the mechanism for examining investments of importance for state security. The law entered into force on 20 April 2025 after publication in Monitorul Oficial Nr. 144-147 of 20 March 2025 (promulgated by Presidential Decree No. 118-X of 17 March 2025). Key operative changes expand the protected-sector perimeter to explicitly enumerate 17 categories covering data processing and storage, AI, robotics, cybersecurity, semiconductors, quantum, nanotechnology and biotechnology alongside the pre-existing energy, transport, communications, defence and aerospace pillars; add new grounds for refusal (money-laundering suspicion, corruption convictions, foreign-government control, cybersecurity risk, access to personal data of citizens); introduce enhanced Council powers including retroactive review of previously approved investments and fines of up to 5% of annual turnover (capped at MDL 5 million); and carve out intra-group transactions, asset sales below EUR 1 million, and state-owned-enterprise dealings. The Screening Council became operational in July 2025.
Nepal's Federal Parliament ratified an omnibus statute on 20–31 March 2025 converting the 13 January 2025 Presidential Ordinance into permanent law, comprehensively amending 11 Acts including the Foreign Investment and Technology Transfer Act 2019 (FITTA), the Industrial Enterprises Act 2020, and the Special Economic Zone Act 2016. The statute expands the scope of permissible foreign investment (replacing the positive-list "any industry" with the broader "any industry other than those in the Schedule"), broadens the "technology transfer" definition to include management/technical services, IT, marketing, finance, engineering, and digital-data-processing, mandates prior Department of Industry approval for foreign investor equity transfers to domestic parties, and for the first time authorises Nepali companies to invest abroad using income earned from technology exports. Repatriation approval windows are compressed to 7 days (15 days for appeals), and foreign investment in Specialised Investment Fund (SIF) units is enabled via SEBON approval.
The Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA), enacted as Division H of P.L. 118-50 (21st Century Peace through Strength Act), prohibits app stores and internet hosting services from distributing, maintaining, or updating "foreign adversary controlled applications" — defined explicitly to include ByteDance Ltd and its subsidiaries (TikTok). ByteDance was given 270 days from enactment (until January 19, 2025) to execute a "qualified divestiture" — selling TikTok to an owner with no operational relationship with a foreign adversary — or face a nationwide distribution ban. The Supreme Court unanimously upheld the law's constitutionality in TikTok, Inc. v. Garland (January 17, 2025), rejecting First Amendment challenges and affirming the national-security rationale grounded in data-collection concerns.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Canada made SOR/2024-32, Regulations Amending the Special Economic Measures (Russia) Regulations, registered and effective 2024-02-21 on the second anniversary of Russia's invasion of Ukraine. The regulations add 163 persons to Schedule 1 — 10 individuals and 153 entities, predominantly Russian organizations tied to military-industrial production, logistics, insurance and oil-sector support — triggering Canadian dealing/asset bans. A parallel amendment to Schedule 7 adds five new goods categories under the Harmonized System (explosives and pyrotechnics; data-processing units and components; ball and roller bearings; semiconductor manufacturing equipment; optical and navigational instruments), banning their export to Russia or Russian persons.
Luxembourg's Chambre des Députés adopted the first-ever national FDI-screening statute on 14 July 2023 (promulgated by the Grand Duke and published in Mémorial A n° 411 on 18 July 2023), entering into force 1 September 2023. The law requires non-EU investors to notify the Ministre de l'Économie before completing direct or indirect acquisitions of ≥25% voting rights / equity in Luxembourg entities engaged in "critical activities" across twelve sectors. The Minister can approve, conditionally approve, or prohibit transactions within a two-month initial screening window, with a further 60-day deep-review phase available; an inter-ministerial Comité de filtrage (Economy + Foreign Affairs + Finance + SREL intelligence service) advises on security and public-order grounds consistent with EU Regulation 2019/452.
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.