Loading…
Loading…
Structured register of government actions in the geoeconomic space — export controls, tariffs, sanctions, FDI screening, subsidies, industrial-policy laws — cross-referenced into the country, minerals, and ETF surface. Charter: docs/IPTM_CHARTER.md.
Severity 1-5 is the qualitative impact rating (1=minor, 5=structural). The bilateral-trade-grounded quant scorer is the next IPTM milestone. RBI (Register Breadth Index) is a complementary structural-breadth indicator from scripts/py/iptm/breadth.py; divergence between RBI and severity is itself informative (high-sev / low-RBI = strategic chokepoint; low-sev / high-RBI = broad but shallow). Every action has at least one primary source URL. Verify-or-don't-file. See also themes, timeline, graph, sankey, map, country exposure, sector exposure, material exposure (+ graph), weekly briefs, portfolio scan, escalation monitor, trans-shipment hubs. Internal triage tools (RSS-poller candidate feed, source-feed health) live under /admin/candidates + /admin/sources. Subscribe via Atom feed (accepts ?country=CN, ?material=lithium, ?issuer=BIS, ?type=export_control, ?etf=SOXX, ?company=NVDA, ?minSeverity=4, ?year=2026, ?q=…) or pull /api/iptm/actions.
Korea's National Assembly passed amendments to Chapter V of the Act on the Adjustment of International Taxes (AITA) on 23 December 2022; promulgated 31 December 2022. The amendment codifies the OECD/G20 Pillar Two GloBE (Global Anti-Base Erosion) rules — specifically the Income Inclusion Rule (IIR) — directly within Korea's existing international-tax statute (Articles 60–83), making Korea the first jurisdiction globally to enact binding primary legislation implementing Pillar Two. The IIR applies to Korean members of MNE groups with consolidated revenue ≥ EUR 750 million for fiscal years beginning on or after 1 January 2024; the Undertaxed Profits Rule (UTPR) was subsequently delayed by the 2024 tax reform bill to fiscal years beginning on or after 1 January 2025. Korea did not initially adopt a Qualified Domestic Minimum Top-up Tax (QDMTT); proposals to add one have been debated in subsequent amendment cycles. The law directly interacts with the K-Chips Act (2023) enhanced investment tax credits: those credits reduce Korean effective tax rates and may trigger Pillar Two top-up exposure unless structured as Qualifying Refundable Tax Credits.
On 21 December 2022 OFAC published final rule FR Doc 2022-27564, amending 30 CFR parts (31 CFR Parts 510, 525, 536, 539, 541, 542, 544, 546, 547, 548, 549, 551, 552, 555, 558, 560, 561, 562, 569, 576, 579, 582, 583, 584, 585, 591, 594, 596, 597, 598) to add or update general licenses authorising (1) official business of the US government and (2) official business of designated international organisations and entities across the full OFAC program library. The rule also updates the 50 Percent Rule interpretive provision, clarifying that an entity's property is blocked when one or more blocked persons own an aggregate interest of 50 percent or more — directly or indirectly — and corrects CFR citations to meet current Federal Register formatting requirements. Published as companion to FR Doc 2022-27639 (NGO and humanitarian GLs), both rules effective 21 December 2022.
Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities, published OJ L 333, 27 December 2022, entered into force 16 January 2023, with Member State transposition deadline 17 October 2024 (rules applicable from 18 October 2024). The CER Directive repeals Council Directive 2008/114/EC on European Critical Infrastructures, extending the scope from two sectors (energy, transport) to eleven essential-service sectors: energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, public administration, space, and food. Member States must adopt national resilience strategies, conduct risk assessments at least every four years, identify "critical entities" providing essential services whose disruption would have significant cross-border impacts, and ensure those entities implement technical, security, and organisational resilience measures, business-continuity plans, incident-reporting obligations, and personnel-security background checks. The CER Directive is the physical and hybrid resilience twin to the NIS2 Directive (2022/2555) — the two instruments form the binding EU critical-infrastructure-protection architecture replacing the 2008/114/EC regime.
Regulation (EU) 2022/2554 (Digital Operational Resilience Act, DORA) is the EU's first horizontal cyber- and ICT-resilience instrument for the financial sector. Adopted 14 December 2022 and published in the Official Journal on 27 December 2022, it entered into force on 16 January 2023 and applies from 17 January 2025. DORA covers approximately 22,000 EU regulated financial entities across ~20 entity types (credit institutions, insurers, investment firms, CCPs, trading venues, crypto-asset service providers, etc.) under five pillars: ICT risk management, ICT-incident reporting, digital operational resilience testing (including threat-led penetration testing for significant entities), ICT third-party risk management, and information sharing. Structurally novel, DORA establishes the Critical ICT Third-Party Provider (CTPP) oversight regime under which the European Supervisory Authorities (EBA, ESMA, EIOPA) acquire direct supervisory powers over hyperscale cloud providers (AWS, Azure, GCP, Oracle) servicing EU financial entities — the first EU mechanism for ESA direct oversight of non-financial cloud providers.
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive), published OJ L 333, 27 December 2022, entered into force 16 January 2023. NIS2 repeals and substantially expands the 2016 NIS1 Directive (2016/1148), extending the scope from ~7 sectors to 18 enumerated essential and important sectors, imposing binding cybersecurity risk- management and incident-reporting obligations on covered entities, introducing board-level management accountability, and mandating Member State transposition by 17 October 2024. NIS2 is the structural EU statutory anchor for national cybersecurity frameworks across the bloc, operating alongside DORA (Reg 2022/2554) for financial-sector digital resilience and CRA (Reg 2024/2847) for product cybersecurity.
Council Directive (EU) 2022/2523, adopted 14 December 2022 and published in OJ L 328 on 22 December 2022, transposes the OECD/G20 Inclusive Framework Pillar Two model rules into binding EU law. It requires all 27 Member States to impose a minimum 15% effective tax rate (ETR) on the jurisdictional income of MNE groups with consolidated annual revenue ≥ EUR 750 million via three interlocking charges: an Income Inclusion Rule (IIR) for fiscal years beginning on or after 31 December 2023, an Undertaxed Profits Rule (UTPR) backstop from 31 December 2024, and an optional Qualified Domestic Minimum Top-up Tax (QDMTT). The directive is the largest international-tax instrument in EU history and the operative legal anchor for the cross-border Pillar Two architecture inside the single market, structurally rebalancing FDI location decisions for an estimated 12,000+ in-scope MNE groups globally.
Regulation (EU) 2022/2065 on a Single Market For Digital Services (Digital Services Act, DSA) was adopted by the European Parliament and Council on 19 October 2022, published in OJ L 277 on 27 October 2022, entered into force on 16 November 2022, and applied in full from 17 February 2024 (with VLOP/VLOSE obligations applying from 25 August 2023 following the Commission's initial designation letters of February 2023). The DSA establishes a graduated intermediary-liability and platform-safety framework covering all online intermediaries serving EU users, with the heaviest obligations falling on designated Very Large Online Platforms (VLOPs, ≥45m monthly active EU users) and Very Large Online Search Engines (VLOSEs): systemic-risk assessments, annual independent audits, vetted-researcher data access, recommender-system transparency, online-advertising transparency, and crisis-response cooperation mechanisms under Commission coordination. The European Commission holds exclusive enforcement authority over VLOPs and VLOSEs, with fines up to 6% of global turnover. The DSA is the structural twin-pillar to the Digital Markets Act (Reg (EU) 2022/1925): the DMA governs ex-ante competition obligations on designated gatekeepers; the DSA governs ex-post intermediary-liability, content-moderation, and platform-safety obligations across all online intermediaries.
The Bureau of Industry and Security (BIS) Office of Antiboycott Compliance amended Supplement No. 2 to Part 766 of the Export Administration Regulations to update penalty determination guidance for administrative enforcement cases involving antiboycott violations. The rule recategorizes violations — Category A now contains only the most serious violations with penalties beginning at the statutory maximum — and eliminates "no admit/no deny" settlements, requiring all settlement agreements to include admissions of fact. The changes apply to all US persons subject to antiboycott provisions, principally those receiving or complying with requests tied to the Arab League boycott of Israel.
FinCEN issued a final rule (87 FR 59498, September 30, 2022) implementing the Corporate Transparency Act (CTA) by requiring most corporations, limited liability companies, and similar entities created in or registered to do business in the United States to file beneficial ownership information (BOI) reports with FinCEN. Reporting companies must identify two categories of individuals: beneficial owners (persons exercising substantial control or owning ≥25% of the entity) and company applicants (persons who filed the formation documents). Entities formed before January 1, 2024 had until January 1, 2025 to file; entities formed on or after that date had 30 days. Non-compliance carries civil penalties of up to $500/day and criminal penalties of up to $10,000 and two years imprisonment.
Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector (Digital Markets Act, DMA) was published in OJ L 265 on 12 October 2022, entered into force on 1 November 2022, and applied for the most part from 2 May 2023. The DMA establishes an ex-ante competition framework imposing binding obligations and prohibitions on designated "gatekeepers" operating Core Platform Services (CPS) in the EU — covering search engines, social-networking services, video-sharing platforms, number-independent interpersonal communications, operating systems, web browsers, virtual assistants, cloud computing, online intermediation services, and online advertising. The European Commission designated six gatekeepers on 6 September 2023 (Alphabet, Amazon, Apple, ByteDance, Meta, Microsoft); full compliance with all obligations was required by 7 March 2024. Subsequent designations added Booking.com (May 2024) and Apple iPadOS (April 2024). The DMA functions as the EU's structural anchor for ex-ante digital competition regulation, closing the enforcement gap left by ex-post competition law (Articles 101–102 TFEU) where market-tipping dynamics make remedies ineffective after the fact.
The Bureau of Industry and Security (BIS) issued an interim final rule (IFR, 87 FR 55241, FR Doc. 2022-19415) amending the Export Administration Regulations (EAR) to authorize the release of specified items to all entities on the Entity List without a licence when such release occurs in the context of a "standards-related activity." The IFR expanded a narrower June 2020 predecessor that had applied only to Huawei and its affiliates; this 2022 rule extended equivalent authorization to the full Entity List. Authorized items include EAR99 technology and software, items controlled solely for anti-terrorism (AT) reasons, and certain cryptographic technology (ECCNs 5D002 and 5E002) used in standards development. The rule amended 15 CFR §§ 734.10, 744.11, 744.16, and Part 772 and was superseded by a broader 2024 IFR that recasted the carve-out as an activity-based exclusion from EAR jurisdiction entirely.
Guinea's Minister of Mines and the Minister of Finance and Budget issued a joint ministerial arrêté (approximately July–September 2022, official date recorded as 2022-09-01) establishing a mandatory bauxite reference price mechanism — the first fiscal-transparency instrument requiring all bauxite exporters operating in Guinea to apply a government-set benchmark FOB price on all export transactions. Any declared export price below the reference benchmark triggers an automatic upward adjustment to the benchmark level for purposes of royalty and tax computation, eliminating the transfer-pricing and underpricing loophole that the International Monetary Fund and the Intergovernmental Forum on Mining, Minerals, Metals and Sustainable Development (IGF) estimated caused >$1 billion per year in revenue leakage for the Guinean state. The mechanism operates separately from export quota and cap actions; it functions as a fiscal floor applicable across all operators. Chinese joint-venture operators — which control the majority of Guinea's bauxite production and export volumes — were the primary target given the prevalence of intracompany transfer pricing in Chinese-financed bauxite-to-aluminium supply chains.
The US Department of Defense published a final rule (DFARS Case 2020-D007) in the Federal Register on 25 August 2022, effective the same day, amending the Defense Federal Acquisition Regulation Supplement to implement section 849 of the FY2020 National Defense Authorization Act. The rule prohibits DoD's acquisition of tantalum metals and alloys melted or produced in North Korea, China, Russia or Iran, and of any end item manufactured in one of those countries that contains such tantalum.
Government Decree 53/2022/ND-CP, signed 15 August 2022 and effective 1 October 2022, implements Article 26 of Vietnam's 2018 Law on Cybersecurity. It mandates in-country storage of three categories of data — personal data of users in Vietnam, user-generated data, and user-relationship data — for both domestic and foreign cyberspace- service providers, with a minimum 24-month retention period. Foreign enterprises providing telecoms, data storage, domain names, e-commerce, online payments, social networks, online video games, or messaging services to users in Vietnam must establish a Vietnamese branch or representative office within 12 months of a Minister of Public Security written request. The decree closes a four-year implementation gap on the 2018 Cybersecurity Law and is the principal Vietnamese digital-trade barrier alongside Decree 13/2023/ND-CP (Personal Data Protection).
On 29 June 2022 the Government of Fiji formally joined the Alliance of Countries for a Deep Sea Mining Moratorium at the United Nations Ocean Conference in Lisbon, Portugal. Prime Minister Voreqe Bainimarama committed Fiji to a precautionary moratorium on commercial seabed mining pending finalisation of the International Seabed Authority (ISA) mining code and comprehensive scientific assessment of environmental impacts. Fiji confirmed it would not operationalise its International Seabed Minerals Management Act 2013 ahead of the ISA regulatory framework. The moratorium stance has been consistently reaffirmed under the subsequent Rabuka administration (2024, 2025), and at the ISA Pacific SIDS Regional Workshop in Suva in May 2026 Minister Filimoni Vosarogo confirmed Fiji remains aligned with the ISA process and will not activate domestic seabed-minerals licensing.
Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European data governance — the Data Governance Act (DGA) — was published in the Official Journal on 3 June 2022, entered into force on 23 June 2022, and became fully applicable on 24 September 2023. The DGA is the second pillar of the EU data-economy framework (alongside GDPR for personal data and the Data Act 2023/2854 for industrial/IoT data) and establishes four structural mechanisms: (i) a harmonised public-sector data re-use regime for protected data held by public-sector bodies; (ii) a mandatory notification and structural-separation regime for data-intermediation service providers; (iii) a voluntary recognition framework for data-altruism organisations (RDAOs); and (iv) the European Data Innovation Board (EDIB) to co-ordinate national competent authorities and advise on common European data spaces and interoperability standards. The regulation is the foundational parent statute of the existing French SREN law filing (2024-05-21) and functions as enabling legislation for the EU's sectoral common-data-space programme (Health, Agriculture, Finance, Mobility, Green Deal, Energy, etc.).
Russian Government Resolution No. 506 of 29 March 2022, signed by Prime Minister Mikhail Mishustin and effective 30 March 2022, authorises the Ministry of Industry and Trade (Minpromtorg) to designate categories of goods exempt from articles 1252(4), 1359(6) and 1487 of the Russian Civil Code on national/regional exhaustion of trademark and other intellectual- property rights. Followed by Minpromtorg Order No. 1532 of 19 April 2022 publishing an initial list of 55 goods categories and named brands — including pharmaceuticals, electronics, automotive parts, mineral fuels, industrial chemicals, paper, textiles, base metals, and consumer goods — for which parallel (grey-market) imports without IP-holder consent are legalised. Designed as a sanctions-circumvention and supply-substitution instrument after the Western corporate exodus of March 2022; extended annually and most recently re-authorised through 31 December 2026.
OFAC published a final rule on February 9, 2022 adjusting the maximum civil monetary penalty (CMP) ceiling amounts across multiple statutory sanctions authorities as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015). The 2022 adjustment reflects the October 2020 to October 2021 CPI-U change (approximately 6.2%), raising the IEEPA ceiling from $311,562 to $330,947, the TWEA ceiling from $91,816 to $97,529, and the Narcotics Kingpin Act maximum from $1,548,075 to $1,644,396. The rule is issued as a final rule effective on publication without prior notice and comment under the non-discretionary "good cause" exemption.
FinCEN published a final rule on January 24, 2022 (87 FR 3729) adjusting the maximum civil monetary penalties (CMPs) for Bank Secrecy Act (BSA) violations under 31 CFR § 1010.821, as mandated by the Federal Civil Penalties Inflation Adjustment Act of 1990 (as amended by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015). The 2022 multiplier is 1.06222, reflecting the October 2020 → October 2021 CPI-U change per OMB Memorandum M-22-07 of December 15, 2021 — the same unusually large ~6.2% inflationary adjustment applied across all federal agency CMP schedules that cycle. The largest single-penalty ceiling rises to $1,556,481 (due-diligence and special-measures violations under 31 U.S.C. § 5321(a)(7)).
The Government of Serbia adopted, on 20 January 2022, the "Uredba o prestanku važenja Uredbe o utvrđivanju Prostornog plana područja posebne namene za realizaciju projekta eksploatacije i prerade minerala jadarita 'Jadar'" — a decree terminating the 2020 Spatial Plan of the Special Purpose Area (SPSPA, Sl. glasnik RS 26/2020) that had underpinned Rio Tinto's Jadar lithium-borate project in the Mačva District. Published in Sl. glasnik RS br. 8/2022. Five days later, on 25 January 2022, the Ministry of Environmental Protection separately annulled its decision approving the project's environmental impact assessment study. Together the two acts cancelled all administrative permits, decisions and resolutions tied to the Jadar project, following weeks of nationwide protests against the mine.
BIS published an interim rule on January 12, 2022 delaying the effective date of its October 21, 2021 cybersecurity items interim final rule by 45 days, from January 19, 2022 to March 7, 2022. The underlying October 2021 rule establishes new Export Control Classification Numbers (ECCNs) for cybersecurity items — including intrusion software, command-and-control platforms, and surveillance tools — and introduces License Exception ACE (Authorized Cybersecurity Exports) for national security and anti-terrorism purposes. The delay was granted after twelve public comments highlighted significant compliance challenges, with BIS acknowledging the need for additional time for industry to update procedures and for BIS to issue supplemental guidance before the controls took effect.