Export controlled data is technical information, software, and know-how that the U.S. government restricts from leaving the country or reaching foreign persons without authorization. Two regulatory systems do the work: the International Traffic in Arms Regulations (ITAR) for defense-related items and the Export Administration Regulations (EAR) for dual-use technologies. Handling this data legally means figuring out which system applies, classifying the information correctly, screening whoever will see it, securing how it is stored and sent, and either obtaining a license or fitting inside a specific exception. Getting it wrong exposes individuals and companies to criminal fines up to $1,000,000 per violation and up to 20 years in prison under either regime.
What Export Controlled Data Is
The government treats an emailed technical drawing the same as a shipped part. Both are exports. Controlled information includes blueprints, engineering schematics, software source code, manufacturing instructions, chemical formulas, proprietary algorithms, and operational manuals for regulated equipment. Even a face-to-face conversation about a controlled design can trigger export control obligations.1U.S. Department of State. Controls Tangible / Intangible
Not everything technical is controlled. Information already published in books, periodicals, patents, or on unrestricted websites is generally outside export controls, as is material presented at open conferences in the United States. “Fundamental research” is also excluded when the results are intended for broad publication in the scientific community and the researcher has not accepted publication restrictions or specific government access controls. That carve-out disappears the moment a lab agrees to limit who can see the results. General scientific and engineering principles taught in college catalog courses are excluded under both ITAR and EAR, which is why a professor lecturing on thermodynamics to a class with foreign students is not making a controlled transfer. Bringing that same student into a restricted, defense-funded lab with publication controls is a different situation entirely.
ITAR or EAR: Which System Governs Your Data
Jurisdiction turns on what the technology is and what it does, not on who is shipping it.
ITAR, at 22 CFR Parts 120–130, covers items and data specifically designed for military applications. The State Department’s Directorate of Defense Trade Controls (DDTC) administers it, and the touchstone is the United States Munitions List, which runs from firearms and ammunition to missiles, military electronics, and certain biological agents. If your data is associated with something on that list, ITAR almost certainly applies.2Directorate of Defense Trade Controls. The International Traffic in Arms Regulations
EAR, at 15 CFR Parts 730–774, covers “dual-use” items with commercial applications that could also serve military or strategic uses. The Bureau of Industry and Security (BIS) at the Commerce Department runs the program. Items are organized on the Commerce Control List using Export Control Classification Numbers (ECCNs), which sort technologies by performance characteristics and technical parameters.3eCFR. 15 CFR Part 730 – General Information4International Trade Administration. Export Control Classification Number (ECCN) and Export Administration Regulation (EAR99)
Close calls happen. A satellite with military-grade encryption may sit on the Munitions List while a standard commercial communications satellite sits on the Commerce Control List. When you genuinely cannot tell, submit a Commodity Jurisdiction request to the State Department through the DECCS portal using Form DS-4076. You do not need to be registered with DDTC to file one, and you receive a case number immediately upon submission.5U.S. Department of State – Directorate of Defense Trade Controls. Commodity Jurisdictions
Foreign Persons on U.S. Soil Count as Exports
Sharing controlled data with a foreign person inside the United States counts as an export under both systems. Under the EAR, this is called a “deemed export”: giving a foreign national access to controlled technology is legally equivalent to exporting that technology to their home country.6Bureau of Industry and Security. Deemed Exports7eCFR. 15 CFR 734.13 – Export
A “foreign person” under the EAR is anyone who is not a U.S. citizen, lawful permanent resident, or protected individual (such as someone granted political asylum). The ITAR definition is effectively identical. International students, visiting researchers, and employees on temporary work visas all qualify, and sharing controlled technical data with any of them requires the same authorization as sending it overseas.8eCFR. 15 CFR 772.1 – Definitions of Terms as Used in the Export Administration Regulations9eCFR. 22 CFR Part 120 – Purpose and Definitions
The trigger is low. A verbal explanation of a controlled process, a glance at a restricted blueprint, or screen-sharing a controlled design file during a video call can each be a deemed export. Once a foreign person acquires the knowledge, the government treats it as transferred. If your organization employs foreign nationals in technical roles or hosts international visitors, screening has to be in place before they walk through the door.
What Requires a License and What Doesn’t
Not every controlled transfer requires an individual license. Both systems include carve-outs, and missing them wastes months on an application you never needed.
The EAR provides several license exceptions under 15 CFR Part 740, each with specific eligibility criteria: LVS for shipments below a dollar threshold that varies by classification; TMP for temporary exports such as trade-show equipment or tools you keep control of and return; TSU for operational technology, software updates, and mass-market software, which also authorizes universities to release certain technology to bona fide full-time foreign employees; RPL for items sent abroad for repair, testing, or calibration, provided the service does not improve the item’s original capabilities; and GOV for transfers to cooperating government agencies, certain military end users in allied countries, and organizations like NATO. Every exception has destination restrictions, item exclusions, and documentation requirements, and using one incorrectly draws the same penalties as exporting with no authorization at all.10Bureau of Industry and Security. Part 740 – License Exceptions
ITAR has its own exemptions for technical data transfers. Transfers made under an approved manufacturing or technical assistance agreement, basic operation and maintenance information for lawfully exported defense articles, technical data related to firearms up to .50 caliber (excluding detailed production information), and certain disclosures by U.S. universities to bona fide full-time foreign employees are all covered. The university exemption requires that the employee’s permanent home is in the United States and that the employee is not a national of a prohibited destination country.11eCFR. 22 CFR 125.4 – Exemptions of General Applicability
How to Apply for an Export License
Before filing, know exactly what you are exporting and to whom. For EAR items, identify the correct ECCN from the Commerce Control List. For ITAR items, identify the specific category on the United States Munitions List. These classifications drive whether a license is required and which exceptions might apply.4International Trade Administration. Export Control Classification Number (ECCN) and Export Administration Regulation (EAR99)
Identify the end user precisely: full legal name, physical address, and intended use. An end-use statement signed by the recipient certifying they will not divert the information to unauthorized parties is typically part of the application package. Vague use descriptions are a common reason applications are returned without action; the government wants specifics like frequency ranges, material compositions, and operational parameters. For EAR-regulated shipments, a Destination Control Statement must appear on the commercial invoice and shipping documents, stating that the items are controlled by the U.S. government, authorized only for the identified country and end user, and cannot be resold or transferred without U.S. government approval.12eCFR. 15 CFR 758.6 – Destination Control Statement and Other Information Furnished to Consignees
EAR license applications are filed electronically through SNAP-R, the Simplified Network Application Process Redesign, using Form BIS-748P.13Bureau of Industry and Security. Licensing14eCFR. Supplement No. 1 to Part 748 – BIS-748P Multipurpose Application Instructions ITAR submissions go through DECCS, the Defense Export Control and Compliance System.15Directorate of Defense Trade Controls. DECCS – Defense Export Control and Compliance System Both portals require an established account and a digital signature. BIS must resolve all license applications or refer them to the President within 90 calendar days of registration. Straightforward applications often clear faster; complex cases involving sensitive destinations or technologies push closer to the limit.16Bureau of Industry and Security. 15 CFR Part 750 – Application Processing, Issuance, and Denial Approvals often include specific conditions the exporter must follow.
Any entity manufacturing, exporting, or brokering defense articles or services must register with DDTC before applying for ITAR licenses. As of January 2025, registration fees run on a three-tier structure starting at $3,000 per year for new registrants, rising with the number of favorable license determinations an organization received in the prior year.17Directorate of Defense Trade Controls. Registration Payment18Federal Register. International Traffic in Arms Regulations: Registration Fees All records related to an export transaction must be retained for five years.19eCFR. 15 CFR 762.6 – Period of Retention
Screening the Recipient
Before any export or deemed export, verify the recipient against the government’s restricted-party lists. The Consolidated Screening List combines lists from Commerce, State, and Treasury into a single searchable tool. Commerce’s contributions alone include the Denied Persons List, the Entity List, the Unverified List, and the Military End User List.20International Trade Administration. Consolidated Screening List
Screening is not the whole obligation. BIS expects exporters to watch for behavioral red flags during transactions. The agency’s “Know Your Customer” guidance in Supplement No. 3 to Part 732 flags warning signs like customers who are evasive about end use, decline routine installation or training, order items inconsistent with their business, or route transactions through unusual intermediaries or transshipment points. Ignoring obvious red flags is not a defense if a transaction turns out to involve a prohibited party.21Bureau of Industry and Security. Identify Red Flags
Storing and Transmitting Controlled Data Securely
Under the EAR, storing or transmitting controlled technology electronically is not treated as an export if the data meets four conditions: it must be unclassified; protected with end-to-end encryption; secured using cryptographic modules compliant with FIPS 140-2 or its successors; and not intentionally stored in a country on the restricted Country Group D:5 list. Data merely passing through the internet in transit does not count as being “stored” in a country.22eCFR. 15 CFR 734.18 – Activities That Are Not Exports, Reexports, or Transfers
The regulation defines “end-to-end encryption” as protection where data is never in unencrypted form between the originator and the intended recipient, and the means of decryption are not provided to any third party. If your cloud provider holds the decryption keys, that arrangement likely does not qualify. Failing to meet all four conditions risks having your cloud-stored data treated as an export to whatever country hosts the server.
Organizations working with export-controlled materials often need a Technology Control Plan (TCP). A typical TCP identifies all personnel with access along with their citizenship, describes the export classification of the data, sets physical security measures like locked storage and restricted lab access, specifies digital protections such as password controls and encryption, and lays out procedures for destroying or returning materials when the project ends. The principal investigator or project lead is usually responsible for the plan and for ensuring everyone involved signs individual acknowledgment certifications.
Carrying Controlled Data Abroad
The moment you board an international flight with a laptop, phone, or portable drive holding controlled technical data, export control obligations kick in. Under the EAR, License Exception TMP may cover temporary exports of tools and equipment, and the BAG exception permits taking certain controlled items as personal baggage if you maintain physical control at all times and return the item to the United States. BAG does not cover ITAR-controlled items, satellite or space-related equipment, or high-level encryption products.
U.S. Customs and Border Protection can also search electronic devices at any port of entry, and CBP explicitly identifies export-controlled information as a category of “digital contraband” it looks for during inspections.23U.S. Customs and Border Protection. Border Search of Electronic Devices at Ports of Entry The safest approach for many organizations is to issue clean travel devices with no controlled data and provide access to needed files only through properly encrypted remote connections that satisfy 15 CFR 734.18.
Penalties and Voluntary Disclosure
Criminal violations of the Arms Export Control Act carry fines up to $1,000,000 per violation and imprisonment up to 20 years, applied to anyone who willfully violates the statute or makes material misrepresentations in a registration, license application, or required report.24Office of the Law Revision Counsel. 22 USC 2778 – Control of Arms Exports and Imports Civil penalties under ITAR reach $1,271,078 per violation or twice the transaction value, whichever is greater.25eCFR. 22 CFR Part 127 – Violations and Penalties
Under the Export Control Reform Act, willful criminal violations of the EAR carry fines up to $1,000,000 per violation and imprisonment up to 20 years for individuals.26Office of the Law Revision Counsel. 50 USC 4819 – Penalties Civil penalties reach $374,474 per violation as of January 2025, adjusted annually for inflation, or twice the transaction value, whichever is greater. BIS can also revoke export licenses and bar a person or company from exporting entirely.27Bureau of Industry and Security. Enforcement Penalties
Both DDTC and BIS encourage organizations that discover their own violations to come forward before the government finds out. Under 22 CFR 127.12, DDTC treats voluntary self-disclosure as a mitigating factor and weighs whether the transaction would have been authorized under proper procedures, why the violation occurred, how cooperative the organization was during the investigation, and whether internal compliance programs have been improved.28eCFR. 22 CFR 127.12 – Voluntary Disclosures On the BIS side, timely and comprehensive disclosure with full cooperation substantially reduces civil penalties, and minor or technical infractions can be resolved on a fast track, sometimes with a warning letter within 60 days. Where a company voluntarily discloses, fully cooperates, and remediates, DOJ guidance creates a presumption of a non-prosecution agreement with no criminal fine. That presumption falls away if the conduct was egregious, upper management was involved, or the violation concerned particularly sensitive items or destinations. Choosing not to investigate or disclose a known violation is treated as an aggravating factor; self-blinding is not a defense.