Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
On June 8, 2026, the US Department of Defense published its annual update to the Section 1260H Chinese Military Companies (CMIC) list, adding 65 entities (17 new parent companies and 48 subsidiaries), bringing the total to approximately 188–200 designated entities. Major additions span EV and battery manufacturing (BYD, NIO, CATL), consumer internet (Alibaba, Baidu, Tencent), semiconductors (SMIC, YMTC, CXMT), solar (JA Solar, Trina Solar), biotech (BGI Genomics, WuXi AppTec), drones/robotics (DJI, Unitree, RoboSense), and telecoms (TP-Link). Effective June 30, 2026, DoD is prohibited from procuring goods, services, or technology directly from listed entities; effective June 30, 2027, the ban extends to indirect supply-chain procurement through prime contractors and all sub-tiers.
Presidential Decree No. 10813 (Resmî Gazete, 7 January 2026, issue 33130) amends Article 62 of Türkiye's Customs Law implementation decree (Decision 2009/15481) to abolish the simplified customs declaration regime for individual low-value imports arriving by post or express courier. Previously, shipments up to EUR 30 (inclusive of freight) qualified for a flat-rate, simplified declaration; from 6 February 2026 all such imports — regardless of value — must clear through standard customs procedures and the ordinary tariff schedule. Prescription medicines and medical supplements remain under the simplified regime up to EUR 1,500.
Decree 353/2025/NĐ-CP is the principal implementing instrument of Vietnam's Law on Digital Technology Industry (Law No. 71/2025/QH15), effective 1 January 2026 — the same date as the parent statute. The decree's five chapters and 36 articles operationalise three pillars: (i) a comprehensive State-support and preferential-incentive framework for products, services, and infrastructure across the semiconductor, AI, cloud, fintech, and e-commerce sectors; (ii) a high-quality-human-resources development framework covering training funds, scholarship schemes, and foreign-expert visa fast-tracks; and (iii) Vietnam's first statutory innovation sandbox, allowing organisations to deploy new digital products and business models under time- and scope-limited regulatory carve-outs where current law has not kept pace with practice.
Presidential Decision No. 10767, published in the Official Gazette (Resmî Gazete, Issue No. 33118) on 25 December 2025, re-sets the Digital Services Tax (Dijital Hizmet Vergisi, DHV) rate under Article 5(3) of Law No. 7194. The rate, set at 7.5% since the tax's 2020 introduction, is reduced to 5% for revenue generated from 1 January 2026 and to 2.5% for revenue generated from 1 January 2027. The tax applies to gross Turkish-sourced revenue of digital-service providers (online advertising, content sales, social-media/intermediary platforms) exceeding statutory turnover thresholds, and falls predominantly on large non-resident platform operators (Google, Meta, Amazon and comparable multinationals).
Vietnam's National Assembly passed Law on Cybersecurity No. 116/2025/QH15 on 10 December 2025 (434 of 443 deputies in favour), effective 1 July 2026. The law supersedes both the 2018 Cybersecurity Law (Law 24/2018/QH14) and the 2015 Law on Cyber Information Security, consolidating cybersecurity, cyber-information-security, and network-information-security into a unified Ministry of Public Security-led framework. It retains data-localization obligations for foreign digital-service providers handling personal data, user-generated content, and relationship graphs of Vietnamese users (minimum 24-month retention), introduces 6-hour urgent / 24-hour standard content take-down windows on MPS request, expressly prohibits AI/deepfake forgery of images, voices, and videos for illegal purposes, and mandates child-safety platform measures.
President Trump signed Executive Order 14324, "Suspending Duty-Free De Minimis Treatment for All Countries," on 30 July 2025 (published in the Federal Register on 5 August 2025 as FR doc 2025-14897, 90 FR 37775). The order eliminated the Section 321(a)(2)(C) administrative exemption that had allowed shipments valued at $800 or less to enter the United States duty-free, applying the suspension to all countries of origin rather than the China/Hong Kong-only carve-out imposed earlier in 2025. DHS/CBP published a Notice of Implementation on 2 September 2025 (FR doc 2025-16802) modifying the Harmonized Tariff Schedule so that covered low-value goods must be entered via formal or informal ACE entry types and pay applicable duties; goods shipped through the international postal network were instead made subject to a new flat ad valorem or specific per-item duty rate set by HTSUS annex. The suspension took effect for entries on or after 12:01 a.m. EDT on 29 August 2025. A DHS/CBP rule published 24 June 2026 (FR doc 2026-12670) converted the non-postal suspension from time-limited to indefinite and closed the remaining international-postal-network exemption to formal/ informal entry procedures as well.
Mexico's tax authority (SAT), acting under SHCP, published the Cuarta Resolución de Modificaciones a las Reglas Generales de Comercio Exterior para 2025 in the Diario Oficial de la Federación on 28 July 2025, raising the flat tax rate applied under the simplified customs regime for low-value courier and parcel shipments (goods valued at USD 2,500 or less) from 19% to 33.5%, effective 15 August 2025. The increase applies to shipments from countries without a free trade agreement with Mexico — in practice overwhelmingly China-origin goods — and is aimed at cross-border e-commerce platforms (Shein, Temu, AliExpress) as well as triangulated goods routed through courier channels by other importers including large retailers. The measure is framed by SHCP as combating under-invoicing and non-tariff-preference triangulation via the courier de minimis channel.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
The Nigeria Data Protection Commission issued the General Application and Implementation Directive (GAID) 2025 on 20 March 2025, the principal implementing directive of the Nigeria Data Protection Act 2023 (NDPA). The GAID came fully into force on 19 September 2025, replacing the Nigeria Data Protection Regulation (NDPR) 2019 as the operative enforcement instrument. It applies extraterritorially to any data controller or processor established outside Nigeria that processes personal data of Nigerian data subjects, imposes a tripartite cross-border transfer framework (adequacy decisions, Transfer Instruments, and statutory exceptions), mandates Data Protection Impact Assessments for AI and high-risk technologies, and carries a civil-penalty ceiling of 2% of annual gross revenue or NGN 10 million for designated data controllers and processors of major importance (DCPMIs), whichever is greater.
Malaysia's Personal Data Protection (Amendment) Act 2024 (Act A1727), gazetted 17 October 2024, enters its third and final commencement phase on 1 June 2025 per commencement order P.U.(B) 522/2024. Phase 3 activates sections 6 and 9 of the amending Act, which impose mandatory Data Protection Officer (DPO) appointment thresholds, a 72-hour breach-notification duty to the Commissioner, and a statutory data-portability right, bringing Malaysia's PDPA broadly into alignment with GDPR and the ASEAN Model AI Governance Framework.
Regulation (EU) 2025/40, published in the Official Journal on 22 January 2025 and entering into force on 11 February 2025, replaces the 1994 Packaging and Packaging Waste Directive 94/62/EC with a directly-applicable Regulation. It mandates binding recycled-content targets for plastic packaging (by polymer and format, reaching 30–65% by 2030 with higher targets by 2040), minimum reusable-packaging shares for beverages and transport, recyclability standards for all packaging placed on the EU market from 2030, deposit-return-scheme obligations for beverage containers from 2029, and bans on specified single-use plastic packaging formats. General application begins 12 August 2026, with staggered compliance windows extending to 2030 and beyond, affecting all non-EU exporters shipping consumer goods, beverages, or e-commerce fulfilment into the EU single market.
India's Finance (No. 2) Act, 2024 (Act No. 15 of 2024) repeals the 2% Equalisation Levy on e-commerce supplies and services by non-resident operators (§165A of the Finance Act 2016, introduced 2020), with effect from 1 August 2024. The repeal removes a long-standing US trade irritant — the USTR had found the 2% levy unreasonable under a Section 301 investigation, and India agreed in October 2021 to remove it as part of a multilateral OECD Pillar 1 commitment, formally implemented here three years later. The residual 6% Equalisation Levy on digital advertising under §165 (in force since 2016) was not touched by this Act and remained in force until its own repeal effective 1 April 2025 via a subsequent Finance Act.
The Cyberspace Administration of China (CAC) issued the Provisions on Promoting and Regulating Cross-Border Data Flows (《促进和规范数据跨境流动规定》) on 22 March 2024, effective immediately. The rules substantially raise the thresholds at which CAC security assessment, Standard Contractual Clauses (SCC), or Personal Information Protection Certification are required for outbound data transfers, and create categorical exemptions for contract performance, HR management, intra-group transfers below a volume threshold, and transit data processed in China with no domestic personal information introduced. A Free Trade Zone pilot mechanism allows designated FTZs (Shanghai Lingang, Tianjin, Beijing) to publish their own negative lists defining which data categories still require prior approval, easing conditions for multinationals with operations in those zones.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
The Personal Information Protection Law of the People's Republic of China (中华人民共和国个人信息保护法 — PIPL) was adopted at the 30th meeting of the 13th NPC Standing Committee on 20 August 2021 and entered into force on 1 November 2021, constituting the third and final pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Data Security Law (2021). The PIPL is China's comprehensive personal-information statute establishing consent-based and necessity-based legal bases for PI processing, a tiered cross-border personal-data transfer regime (CAC security assessment / PI protection certification / Standard Contractual Clauses), extraterritorial application (Art. 3) to non-Chinese controllers offering services to or analysing the behaviour of PRC residents, and a heightened protection regime for sensitive personal information and data of minors under 14. It mandates data-protection impact assessments, personal-information-protection-officer obligations at designated handlers, breach notification, and a full suite of data-subject rights including access, rectification, deletion, portability, objection, and automated- decision-making opt-out. Article 53 requires overseas controllers to establish a domestic representative or designated entity in China, providing a domestic enforcement counterparty.