What Is a Deemed Export Under U.S. Law

Legal Guide Team

The concept of a deemed export sits at the intersection of U.S. export controls and information sharing within organizations. It refers to transmitting or transferring controlled technology, software, or technical data to a foreign national within the United States, or releasing controlled information to a person outside the United States, in ways that effectively export protection-relevant items. Understanding deemed exports is essential for researchers, companies, and contractors to avoid violations and penalties while maintaining compliance with U.S. law.

What Counts As A Deemed Export

A deemed export occurs when access to or transfer of controlled technology or information is provided to a foreign national, or when controlled information is released to an international audience inside the United States. The key factor is the nationality of the recipient and the nature of the information or item being accessed. In practice, this includes:

Want to talk through your situation?
A quick phone call can clarify your options and next steps. The conversation is confidential.
Call (855) 550-1270
Or dial: (855) 550-1270
  • Providing controlled technical data to a foreign national, whether in person, via email, or through collaboration.
  • Allowing a foreign national to access controlled software or source code without a formal license or authorization.
  • Disclosing restricted information in a conference, meeting, or collaboration where a non-U.S. person is present.
  • Allowing a foreign national to use controlled equipment or technology on site, resulting in a transfer of knowledge or capability.

Both the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR) govern deemed exports, but they apply to different types of items and activities. The EAR focuses on dual-use technologies with potential military and civilian applications, while ITAR covers defense-related articles and services.

Who Is A Foreign National?

Under U.S. law, a foreign national is an individual who is not a lawful permanent resident (green card holder) or a U.S. citizen. The definition extends to people with permanent residency in another country, visa holders, refugees, and asylees who are physically present in the United States. Determining whether a person is a foreign national for deemed export purposes hinges on their citizenship, national origin, and immigration status.

Organizations must evaluate access scenarios to determine if a foreign national is involved. Even well-credentialed researchers, students, or contractors can trigger deemed export concerns if they access controlled information or utilize controlled equipment.

What Types Of Information And Items Are Controlled?

Not all information or items are subject to deemed export controls. The relevant categories include:

  • Technical data: blueprints, schematics, software source code, manufacturing processes, and design parameters.
  • Certain software: especially encryption, cyber security, or specialized engineering software that controls sensitive capabilities.
  • Hardware: equipment or components that have military or dual-use applications and are listed on control lists.
  • Certain services: technical assistance, engineering services, or training related to controlled items.

Compliance hinges on identifying whether the item or data is listed on the EAR’s Commodity Jurisdiction or Commerce Control List (CCL), or ITAR’s U.S. Munitions List (USML). When in doubt, consult the relevant agency lists and licensing requirements.

Licensing And Compliance Requirements

In many cases, a deemed export requires a license or license exception to permit access by a foreign national. Key steps include:

Want to talk through your situation?
A quick phone call can clarify your options and next steps. The conversation is confidential.
Call (855) 550-1270
Or dial: (855) 550-1270
  • Performing a screening to determine whether the recipient is a foreign national.
  • Identifying the item or data as controlled and determining the applicable licensing jurisdiction (EAR or ITAR).
  • Requesting and obtaining the appropriate license or determining if a license exception applies.
  • Documenting access decisions and maintaining records for audits and enforcement reviews.

Companies often establish internal controls such as access approvals, controlled environment workspaces, and restricted data environments to prevent inadvertent deemed exports. Training programs and ongoing compliance reviews help reduce risk.

Common Scenarios And Examples

Understanding typical situations helps illustrate how deemed exports work in practice. Consider:

  • A foreign national research assistant accesses controlled schematics in a shared lab computer. This access could constitute a deemed export if the information is controlled.
  • A U.S.-based software engineer works with a non-U.S. teammate on a project involving encryption algorithms. Sharing code or technical guidance may trigger deemed export considerations.
  • A multinational corporation hosts an international conference in the United States, where a foreign national attends a technical session involving controlled data. Even if the information is spoken, a deemed export may occur if the disclosures are controlled.
  • Remote collaboration involving a foreign national accessing a secure database containing controlled information could be deemed export via electronic transfer.

These scenarios highlight the importance of clear access controls, license determinations, and documentation to ensure compliance with both EAR and ITAR regimes.

Penalties And Implications For Non-Compliance

Violations of deemed export controls can result in severe consequences. Penalties may include civil fines, criminal charges, and facility or program restrictions. In addition, non-compliance can damage a company’s export privileges, restrict government contracts, and expose organizations to heightened regulatory scrutiny. The consequences emphasize the need for robust compliance programs, especially in research institutions and global supply chains.

Accuracy in licensing determinations, thorough recordkeeping, and prompt corrective actions after a potential lapse are critical components of risk management.

Practical Steps For Compliance

Organizations can take concrete steps to manage deemed export risk. Practical measures include:

  • Implementing a formal deemed export screening process for all foreign nationals.
  • Maintaining an up-to-date inventory of controlled items and status under EAR and ITAR.
  • Establishing access controls, including segregated environments for handling controlled data and equipment.
  • Providing regular training on export controls, licensing requirements, and compliance responsibilities.
  • Documenting all licensing determinations, alternative procedures, and exceptions used.
  • Conducting periodic internal audits and third-party reviews to validate compliance programs.

Key Takeaways To Remember

Deemed export is not a physical export; it is a release of controlled technology or information to a foreign national that effectively transfers control. Both EAR and ITAR govern deemed exports, with licensing requirements varying by item and scenario. Proper licensing, recordkeeping, and staff training are essential to prevent violations. By establishing clear procedures and ongoing oversight, organizations can navigate the complexities of deemed exports while enabling productive collaboration with international partners.