Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
President Trump signed Executive Order 14420 on 26 August 2026, declaring a national emergency under IEEPA and the National Emergencies Act over foreign threats to the US bulk-power system. The order generally prohibits the acquisition, import, transfer, or installation of foreign-produced bulk-power system electric equipment — transformers, inverters, battery storage, generators, circuit breakers, turbines, and industrial control systems, including associated software and remote-access capabilities — where a transaction involves a "Covered Foreign Entity" and poses a risk of sabotage, unauthorized access, or catastrophic disruption to critical infrastructure. Local electric distribution facilities are excluded. No countries or companies are named in the order itself; DOE must publish implementing rules within 120 days (by 24 December 2026) identifying covered equipment and entities, and submit recommended Federal Acquisition Regulation revisions within 180 days.
Peru's Mining Council (Consejo de Minería) issued Resolution No. 236-2026-MINEM/CM on 19 March 2026, declaring null and void Directoral Resolution No. 0692-2025-MINEM/DGM of 13 October 2025, which had authorised Southern Peru Copper Corporation (SPCC, NYSE: SCCO; subsidiary of Grupo México) to begin exploitation activities at the Tía María copper project in Islay province, Arequipa. The council found the original DGM authorisation lacked adequate legal motivation and failed to address two technical observations relating to waste-dump infrastructure design and construction-sequencing plans, as required under the Regulation of Mining Procedures and the consolidated text of the Administrative Procedures Act (Law 27444). The resolution returned the file to the General Directorate of Mining (DGM) for technical re-evaluation, without terminating the project's administrative procedure; MINEM subsequently re-authorised the project's first-stage La Tapada open-pit operations on approximately 20 April 2026 after a revised technical assessment.
The DRC government's APCSC formally launched a technical and financial audit of the Sicomines Sino-Congolese mining project on March 5, 2026, signing consortium contracts with ATF-PCSC/Mayer Brown (legal), Rothschild & Cie (financial valuation), EY (accounting and tax), and SRK Consulting (resource certification). The audit covers 16 years of project implementation (2008–2024), examining revenue flows, infrastructure delivery commitments, and compliance with the collaboration convention and its five amendments. The initiative signals DRC's intention to renegotiate or enforce Amendment 5 (2024) terms, which conditioned any further project expansion on audit outcomes and a certified feasibility study.
Germany's first cross-sector federal statute establishing minimum requirements for the physical protection and resilience of critical infrastructure operators (KRITIS) — sectors covered include energy, transport, water, food, ICT, financial services, health, and federal government infrastructure. Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities). Identifies operators of critical facilities with Europe-wide significance, mandates national risk analyses for critical services, requires operator risk-management measures and creates a federal incident-reporting regime. Passed by the Bundestag on 29 January 2026, confirmed by the Bundesrat on 6 March 2026, published in BGBl. 2026 I Nr. 66 on 16 March 2026, in force from 17 March 2026.
President Claudia Sheinbaum signed a comprehensive reform to Mexico's Customs Law (Ley Aduanera) published in the Diario Oficial de la Federación on 19 November 2025, entering into force 1 January 2026. The decree formally recognises the Agencia Nacional de Aduanas de México (ANAM) as the autonomous customs authority with expanded inspection and fiscalisation powers, creates a new inter-secretarial Consejo Aduanero with binding decisional authority over customs-agent licensing, and mandates real-time electronic traceability and video-surveillance at all recintos fiscales. The reform is Mexico's most comprehensive statutory overhaul of its customs-administration architecture in over a decade, directly conditioning USMCA-origin compliance infrastructure for approximately US$800 billion in annual MX-US trade and over 3,200 IMMEX-registered nearshoring operators.
On 18 November 2025, the European Supervisory Authorities (EBA, ESMA, and EIOPA) jointly designated 19 Critical ICT Third-Party Providers (CTPPs) under DORA Article 31, with immediate effect — the first-ever exercise of direct EU financial-regulator supervision over hyperscale cloud and infrastructure providers. The designated entities include Amazon Web Services, Microsoft Azure, Google Cloud, Deutsche Telekom, Oracle, SAP, IBM, Bloomberg LP, London Stock Exchange Group (LSEG), Tata Consultancy Services, and Orange, among others. Designation triggers direct oversight by a lead ESA (EBA for banking-critical, ESMA for capital-markets-critical, EIOPA for insurance-critical) via Joint Examination Teams (JETs), with powers to conduct investigations, carry out on-site inspections, and impose fines of up to 1% of average daily worldwide turnover per day for non-compliance.
Germany's transposition of EU Directive 2022/2555 (NIS2), enacted as the "Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung." Bundestag passage 13 November 2025; Bundesrat approval 21 November 2025; published as BGBl. I 2025 Nr. 301 on 5 December 2025; entered into force 6 December 2025. The statute designates the Bundesamt für Sicherheit in der Informationstechnik (BSI) as the central national supervisory authority over an estimated 29,500 covered entities across 18 critical and important sectors, introduces a mandatory 24h initial / 72h detailed / 1-month final cyber-incident reporting cascade, establishes board-level personal liability for senior management, and applies to SME critical- infrastructure suppliers — with no transitional grace period from entry into force.
The Bank of Zambia formally accepted Chinese renminbi (RMB/CNY) for copper and cobalt mining royalty and tax payments starting October 2025, making Zambia the first African country to establish an official RMB settlement channel for mining fiscal flows. In December 2025 the BoZ began publishing an official RMB-kwacha exchange rate to enable precise royalty and corporate tax calculations. The central bank cited efficiency grounds: Chinese mining companies operating Zambia's largest copper producers already receive export revenues in yuan from Chinese off-takers, making yuan-denominated tax settlement a natural extension that also reduces Zambia's Chinese-debt servicing friction. The policy embeds Chinese currency infrastructure into the sovereign fiscal architecture governing Zambia's copper and cobalt supply chain, deepening structural alignment between Zambia's resource sector and China's commodity-import ecosystem.
The Mauritius Finance Act 2025 (Act No. 18 of 2025), assented to by Acting President Dharambeer Gokhool G.C.S.K. and gazetted in August 2025, is an omnibus financial-sector statute amending the Companies Act, Financial Services Act 2007, Income Tax Act, Bank of Mauritius Act, and FIAMLA. Its headline provisions are: (i) introduction of a Qualified Domestic Minimum Top-Up Tax (QDMTT) aligned with the OECD GloBE Pillar Two rules, imposing a 15% effective minimum tax on Mauritius profits of MNE groups with consolidated revenue ≥ EUR 750 million; (ii) new fiscal incentives for investments in AI infrastructure and Virtual Asset Service Provider (VASP) licensees; (iii) enhanced beneficial-ownership (UBO) identification and record-keeping requirements under the Companies Act, aligned with FATF Recommendation 24; (iv) tightened substance and economic-presence requirements for Global Business Companies (GBCs); and (v) an expanded AML/CFT administrative- penalty framework under FIAMLA.
The FCC adopted a Report and Order (FCC 25-49) on 7 August 2025 — the first comprehensive overhaul of submarine cable landing license rules since 2001 — effective 26 November 2025. The order prohibits Indefeasible Right of Use (IRU) agreements that would give entities from designated foreign adversary countries (China including Hong Kong and Macau, Cuba, Iran, DPRK, Russia, and Venezuela) control over Submarine Line Terminal Equipment (SLTE) on US cable landings, and mandates new annual reporting plus certification/disclosure requirements covering ownership, cybersecurity and physical security plans, and FCC Covered List compliance. The order operationalises the FCC's bifurcated policy package: accelerating legitimate commercial cable buildout while hardening national-security review for foreign-adversary-connected infrastructure.
Czech Republic's first standalone federal statute on the resilience of critical-infrastructure entities — Act No. 266/2025 Sb., "Zákon o odolnosti subjektů kritické infrastruktury a o změně souvisejících zákonů" (Critical Infrastructure Act). Transposes EU Directive 2022/2557 (CER Directive on the resilience of critical entities) into Czech law and removes critical-infrastructure regulation from the earlier crisis-management law (Zákon č. 240/2000 Sb.) into a dedicated statute. Covers the 11 CER-Directive sectors (energy, transport, banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, space, food production-processing-distribution) and obligates designated operators of essential services to conduct risk analyses, implement technical/organisational resilience measures, report incidents to sector-competent authorities, and submit to inspection. Published in the Sbírka zákonů on 4 August 2025; in force 19 August 2025; operator information-obligation deadline 1 March 2026.
The Joint Committee of the European Supervisory Authorities (EBA, EIOPA, ESMA) published the Guide on DORA Oversight Activities (JC 2025 29) on 15 July 2025, the definitive operational description of how the ESAs will supervise Critical ICT Third-Party Providers (CTPPs) designated under DORA Art. 31. The guide establishes the governance of Joint Examination Teams (JETs), the oversight examination lifecycle (planning, risk assessment, binding recommendations, follow-up), penalty processes of up to 1% of average daily worldwide turnover per day of breach (DORA Art. 35(6)), and lead-overseer assignments (EBA for banking, ESMA for capital markets, EIOPA for insurance). It is authoritative ESA interpretive guidance, not legally binding per se, but constitutes the supervisory playbook CTPPs and their dependent financial entities must plan against.
The National Assembly of Vietnam passed the Personal Data Protection Law (Luật Bảo vệ dữ liệu cá nhân), Law No. 91/2025/QH15, on 26 June 2025; it enters into force on 1 January 2026. The PDPL is Vietnam's first statutory (rather than decree-level) personal-data-protection framework, elevating the prior Decree 13/2023/ND-CP (PDPD) regime into a 5-chapter, 39-article primary statute and adding revenue-based administrative penalties of up to 5% of prior-year annual revenue for cross-border data-transfer violations and up to 10x illegal gains for unlawful data trading. The law is implemented by Decree 356/2025/ND-CP (issued 31 December 2025, effective 1 January 2026) and applies extraterritorially to foreign organisations offering services to or processing the personal data of Vietnam residents.
On 11 April 2025 President Javier Milei signed Decreto de Necesidad y Urgencia 269/2025, published in the Boletín Oficial on 14 April 2025 (edición Nº 35.647). The decree repealed Decreto 28/2023, formally lifting the cepo cambiario — the foreign-exchange restrictions that had been in continuous operation in some form since November 2011. Operative provisions include elimination of the 80/20 export-proceeds-channelling mandate, removal of individual USD purchase and wire-transfer caps, permission for companies to repatriate post-1-January-2025 dividend profits, and replacement of the daily crawling-peg with a band float within a $1,000–$1,400 ARS/USD corridor with BCRA floor/ceiling intervention rules. The measure was coordinated with the IMF Extended Fund Facility (USD 20bn total; USD 15bn 2025 free-availability tranche) approved 11 April 2025, and operationalises the currency-stability guarantee embedded in the RIGI large- investment regime (Law 27.742, July 2024).
Ghana's Parliament passed the Ghana Gold Board Act, 2025 (Act 1140) on 29 March 2025; presidential assent followed on 2 April 2025, with full operational effect from 1 May 2025. The Act repeals PNDCL 219 (1989) and establishes the Ghana Gold Board (GoldBod) as the sole statutory licensor and exclusive primary buyer, seller, assayer, grader, weigher and exporter of all gold produced by the country's licensed Artisanal and Small-Scale Mining (ASM) sector. Large-scale mining operations remain outside the monopsony. Effective 1 May 2025, no person other than GoldBod may export ASM gold from Ghana, and all gold trading and marketing businesses must hold a GoldBod licence (application window for Ghanaian-owned firms opened 22 April 2025). Proceeds from all ASM gold exports settle through the Bank of Ghana, channelling foreign-exchange flows from roughly 30% of national gold output — Ghana is the world's #6 producer and Africa's largest — into formal central-bank reserves. The stated objectives are to combat smuggling, capture the smuggling-loss premium for the state, support Bank of Ghana gold-reserves accumulation, and generate foreign exchange. The Act sits alongside the Bank of Ghana's Domestic Gold Purchase Programme as the legal infrastructure for Ghana's gold-as-reserve-asset strategy.
Japan's National Diet enacted the Cyber Response Capability Enhancement Act (重要電子計算機に対する不正な行為による被害の防止に関する法律, Law No. 42 of 2025) on 16 May 2025, together with companion arrangement legislation. Commonly known as the Active Cyber Defense (ACD) Law, the statute authorises (i) government monitoring of foreign-origin internet traffic transiting designated Japanese communication infrastructure for national-security threat indicators, (ii) pre-emptive access and neutralisation operations against attacker infrastructure abroad by the National Police Agency and the Self-Defense Forces under unified command, and (iii) mandatory cyber-incident reporting and government cooperation duties on critical-infrastructure operators. Implementation is phased through November 2027, with the NISC reorganised into the National Cybersecurity Office (NCO) under the Cabinet Secretariat from July 2025.
Bolivia's Decreto Supremo 5309, signed by President Luis Arce on 8 January 2025, mandates that all public-sector entities migrate their information systems to Free Software and Open Standards by 12 January 2030. The decree includes a data-localization provision barring storage of non-public state data on servers outside Bolivian territory; government cloud workloads must run either on public-entity infrastructure or on state-operated cloud services within the country. AGETIC (Bolivia's ICT agency) is responsible for overseeing compliance and developing the implementation plan (approved via the companion Decreto Supremo 5322 on 23 January 2025).
Regulation (EU) 2025/38 of the European Parliament and of the Council of 19 December 2024 lays down measures to strengthen solidarity and capacities in the Union to detect, prepare for, and respond to cyber threats and incidents, and amends Regulation (EU) 2021/694 (Digital Europe Programme). Published in the Official Journal on 15 January 2025; entered into force on 4 February 2025 (20 days after OJ publication). The regulation establishes (i) a European Cybersecurity Alert System composed of national and cross-border Security Operations Centre (SOC) hubs interconnected EU-wide, (ii) a Cybersecurity Emergency Mechanism funded through the Digital Europe Programme, (iii) an EU Cybersecurity Reserve of trusted private-sector incident-response providers, and (iv) an ENISA-led post-incident review mechanism for significant or large-scale cybersecurity incidents. It complements the Cyber Resilience Act (Reg 2024/2847) and the NIS2 Directive as the third leg of the EU horizontal-cybersecurity stack.
The National Assembly of Vietnam passed the Law on Data (Luật Dữ liệu), No. 60/2024/QH15, on 30 November 2024; it enters into force on 1 July 2025. The Law is Vietnam's first comprehensive horizontal data-governance statute, extending regulation beyond personal data (already covered by Decree 13/2023/ND-CP) to all digital data — public, private, and sectoral. It introduces statutory categories of "important data" (dữ liệu quan trọng) and "core data" (dữ liệu cốt lõi) tied to national-defence and national-security review for cross-border transfer, and establishes the National Data Centre under the Ministry of Public Security plus a statutory data-broker / data-services licensing framework.
Australia's first standalone cyber-security statute (Act No. 98 of 2024), passed by Parliament on 25 November 2024 and granted Royal Assent on 29 November 2024, with provisions commencing in tranches through 30 May 2025. The Act creates four binding regimes: (i) mandatory security-of-things standards for connected and IoT products supplied in Australia under regulations administered by the Department of Home Affairs; (ii) a mandatory ransomware / cyber-extortion payment disclosure regime requiring reporting business entities with annual turnover above AUD 3 million to notify the Australian Signals Directorate within 72 hours of any ransom payment made by or on behalf of the entity; (iii) a statutory Cyber Incident Review Board to conduct no-blame post-incident reviews of significant cyber incidents; and (iv) a "limited use" protection restricting how information voluntarily shared with the National Cyber Security Coordinator may be used by Commonwealth agencies. The Act implements core initiatives from the 2023-2030 Australian Cyber Security Strategy and affects every firm selling connected devices into Australia or operating above the turnover threshold in Australia.
The Bureau of Industry and Security (BIS) finalized amendments to its Defense Priorities and Allocations System (DPAS) regulation at 15 CFR Part 700, originally proposed February 7, 2024. The final rule clarifies long-standing standards and procedures by which BIS provides Special Priorities Assistance (SPA) under the Defense Production Act of 1950, revises Schedule I to delineate Department of Commerce DPAS jurisdiction from other agencies' priority-rating authorities, and applies non-substantive technical edits reflecting updates since the regulation was last amended in 2014. The rule takes effect August 21, 2024.
Japan's National Diet enacted the Act on the Protection and Use of Critical Economic Security Information (重要経済安保情報の保護及び活用に関する法律, Act No. 27 of 2024) on 10 May 2024; it was promulgated on 17 May 2024 and came into full operation on 16 May 2025. The law establishes Japan's first peace-time economic-security clearance regime extending to private-sector employees. It designates "Critical Economic Security Information" (CESI) covering threat-intelligence on critical-infrastructure cyber attacks, regulatory-review information on essential infrastructure, and vulnerability data on critical-product supply chains; mandates Cabinet Office "適性評価" (suitability assessment) for cleared personnel; and imposes criminal penalties of up to five years' imprisonment for unauthorised disclosure. The CESI Act complements the 2022 Economic Security Promotion Act (ESPA), closing the information-protection gap and aligning Japan's framework with Five Eyes and EU partners for joint R&D and dual-use cooperation.
Three Commission Delegated Regulations (CDR 2024/1772, 1773, 1774) adopted 13 March 2024 and published in the EU Official Journal on 25 June 2024 constitute the first batch of binding Level 2 implementing rules under DORA (Regulation (EU) 2022/2554). CDR 2024/1772 sets ICT incident classification criteria and materiality thresholds for mandatory reporting; CDR 2024/1773 specifies the required content of contractual policies for ICT third-party services supporting critical or important functions; CDR 2024/1774 defines the ICT risk management tools, methods, processes, and policies — including a simplified framework for smaller in-scope entities. All three apply from 17 January 2025 alongside the parent DORA regulation, covering approximately 22,000 EU regulated financial entities.
Signed by President Javier Milei and the entire cabinet on 20 December 2023 and published in the Boletín Oficial extraordinario on 21 December 2023, Decreto de Necesidad y Urgencia 70/2023 declares a public emergency across economic, financial, fiscal, administrative, pension, tariff, sanitary, and social matters until 31 December 2025 (Article 1) and enacts 366 articles across 16 titles that fundamentally restructure Argentina's regulatory framework. The DNU repeals or amends dozens of statutes to deregulate foreign trade (repealing the Compre Nacional buy-preference law Ley 18.875 and the price-control framework Ley 27.345), opens privatisation of state enterprises (Aerolíneas Argentinas, ENARSA, Banco Nación, Correo Argentino, Trenes Argentinos), dismantles the Ley de Abastecimiento price-control regime, liberalises civil aviation cabotage to foreign carriers, deregulates hydrocarbons export and mining permitting, and replaces the severance-pay regime with a capitalisation-fund system. It is the foundational enabling framework for all subsequent Milei-administration deregulatory instruments filed on the IPTM register, including RIGI (Law 27.742), Decreto 38/2025, Decreto 449/2025, and Decreto 563/2025.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
The Data Security Law of the People's Republic of China (中华人民共和国数据安全法) was adopted at the 29th meeting of the 13th NPC Standing Committee on 10 June 2021 and entered into force on 1 September 2021, constituting the second pillar of China's cybersecurity and data-governance regulatory trinity alongside the Cybersecurity Law (2016) and the Personal Information Protection Law (2021). The DSL establishes a tiered data-classification regime — "important data" and "national core data" — with escalating security obligations including risk assessment, risk monitoring, breach reporting, and classified-protection requirements for data handlers. It introduces a data-export security review for "important data" generated or collected within China, the statutory parent authority operationalised by the 2024 CAC Cross-Border Data Flow Provisions, and enacts a §36 blocking statute prohibiting Chinese organisations and individuals from transferring data stored in China to foreign judicial or law-enforcement authorities without prior PRC government approval.
The Cybersecurity Law of the People's Republic of China (中华人民共和国网络安全法) was adopted at the 24th meeting of the 12th NPC Standing Committee on 7 November 2016 and entered into force on 1 June 2017, establishing the foundational legal framework for network security governance across all sectors. The law creates the Critical Information Infrastructure Operator (CIIO) designation and protection regime administered by the Cyberspace Administration of China (CAC), mandates data localisation for personal information and important data collected or generated by CIIOs in China, and establishes cross-border data-transfer security assessment requirements under Article 37 — the provision later operationalised by DSL 2021, PIPL 2021, and the 2024 CAC Cross-Border Data Flow Provisions. The CSL introduced multi-level protection scheme (等级保护制度 / MLPS) obligations for all network operators and network-product/service security-review procedures, under which CAC triggered the cybersecurity review of Didi Global in 2021 and the exclusion of Micron's products from Chinese critical-infrastructure projects in 2023.
Germany's Außenwirtschaftsgesetz (AWG, Foreign Trade and Payments Act; BGBl. I 2013 S. 1482 of 6 June 2013, replacing the original 1961 Act) is the foundational parent statute of the modern German economic-statecraft toolkit, providing the legislative authority for (i) export licensing of dual-use goods and technology administered by BAFA under the Außenwirtschaftsverordnung (AWV) implementing regulation — the national complement to EU Dual-Use Recast Regulation 2021/821; (ii) inward FDI screening by BMWK under §§ 55–62 AWG covering non-EU/non-EFTA acquisitions of ≥ 25% of voting rights cross-sectorally and ≥ 10%/20% in 27 sensitive-sector activities including defence, semiconductors, AI, quantum, biotech, space, and critical infrastructure; and (iii) German implementation of EU-level and autonomous trade and sanctions restrictions. As the EU's largest economy and a top-tier dual-use exporter, Germany's AWG-based regime is structurally peer-foundational to JP FEFTA 1949, UK NSI Act 2021, US ECRA 2018, CN Export Control Law 2020, and NL Wet Vifo 2022 in the G7+CN economic- statecraft parent-statute cluster.