Category Archives: All

OFAC: The Not To Be Forgotten Element of Export Compliance (Part 2 of 3)

Question: In your last post, you referred to “OFAC export authorizations” and the possibility that a U.S. company might apply for and obtain an “OFAC Specific License” for an export transaction involving a sanctioned country. Isn’t that a contradiction in terms? I thought the whole point of U.S. economic sanctions was that no financial transactions or business dealings whatsoever are permitted with a customer in, or from, an OFAC-sanctioned country.

While it’s true that economic sanctions administered and enforced by OFAC can impose sweeping prohibitions against trade with targeted countries—Cuba, Iran, and Sudan, for example—and that U.S. Government policy is normally to deny export licenses in such cases, exceptions do exist which permit exports to OFAC-sanctioned countries in certain cases.

For one thing, because each sanctions program is based on a unique set of foreign policy imperatives, no two are exactly alike. Each of the twenty-eight OFAC Sanctions Programs is distinct and different; the range and coverage varies greatly from country to country. Some programs are nearly total in scope, while others are much more narrowly focused. So the application of sanctions to a country does not necessarily mean that all commercial opportunities in that country or that country’s nationals are off limits. There is a huge difference, for example, between the fairly limited and selectively tailored sanctions currently imposed on certain individuals and entities under the Ukraine/Russia Sanctions Program, and the strict and comprehensive sanctions that that are currently imposed on most transactions with the Iranian government, Iranians, and Iranian entities. For that reason, a deal involving a sanctioned country will sometimes be able to go forward because it falls outside the scope of the applicable OFAC export prohibitions. Determining whether this is true in any particular case, of course, requires a detailed review of the regulations currently in force.

Even for comprehensively sanctioned countries such as Cuba, Iran, and Sudan, the prohibitions on trade, although stringent and far-reaching, are not absolute. Many companies are surprised to learn that the U.S. permits the imports and exports of certain items to and from these nations despite the tense political relationships.

What’s more, due to the political nature of sanctions and their use by the U.S. Government as diplomatic tools to influence the behaviors of other nations, OFAC regulations are constantly changing. On the positive side, this means that new opportunities for U.S. exporters can open up at any time. For example, on July 11, 2012, OFAC moved to lift a near-total ban on business with Myanmar (Burma), and began allowing certain U.S. investments in that country in response to the government’s promises of reform and transition to democracy. Other regulatory changes followed, and in April of this year OFAC took several Myanmar companies and individuals off the blacklist.

Some types of permitted transactions reflect long-standing and fundamental principles of U.S. foreign policy.

  • It has generally been U.S. foreign policy to promote and encourage the free flow of information and freedom of speech between the U.S. and other nations. The Berman Amendment, passed by Congress in 1988, as amended and expanded by the Free Trade in Ideas Act in 1994, makes it clear that OFAC does not have the statutory authority to regulate “directly or indirectly” transactions concerning the import or export of “information and informational materials” to or from sanctioned countries, “regardless of format or medium of transmission.” “Informational materials” in this context has been deemed to include most books, magazines, eBooks, and other publications; pre-recorded video and audio tapes and CDs; and paintings, sculptures, and other works of art; and it may include payments for such items, depending on the sanctions program involved. It is essential to keep in mind, however, that this does not cover CCL items: controlled software and controlled technical data do not fall within this exemption. Exporters should also be aware that the application of this “informational materials” exemption to such related activities as the development, marketing, and distribution of the materials is a matter of ongoing legal controversy; those related activities may require an OFAC Specific License.
  • It has not generally been the policy of the U.S. to withhold the supply of food and medicine to other nations as a means of furthering U.S. foreign policy goals. Thus, U.S. sanctions programs have usually included provisions explicitly allowing humanitarian exports of food, clothing, medicine, and other forms of humanitarian support. Even nations whose governments are notoriously hostile to the U.S. or who have been spotlighted as supporters of terrorism can receive exports of U.S.-origin humanitarian goods. To that end, the Trade Sanctions Reform and Export Enhancement Act of 2000 (TSRA), also known as the Nethercutt Amendment, authorizes the export of certain agricultural commodities, medical supplies, and medical devices to otherwise comprehensively embargoed countries under licenses issued by OFAC (for Iran and Sudan) or Commerce/BIS (for Cuba). This complicated measure authorizes exports of certain agricultural commodities, medicines, and medical devices to Cuba, Iran, Sudan, and Libya. The criteria for items that meet the TSRA definition of agricultural commodity or medicine/medical device are varied and complex, however, and close consultation with OFAC, BIS, and the FDA is highly advisable for U.S. exporters.

While compliance with TSRA licenses and adherence to the scope of the Berman Amendment exemptions can be complicated, these efforts can yield opportunities for U.S. companies that export eligible items.

Some other examples of transactions that may be permitted even with countries under strict U.S. economic sanctions include the provision of telecommunications services, research activities by U.S. persons (although this is sometimes conditioned on obtaining specific approval from either BIS or OFAC or both), and professional meetings. The applicability of these exemptions to specific occasions and circumstances must always be carefully analyzed and considered, however.

What kinds of OFAC authorization are available? There are three categories: Exemptions, OFAC General Licenses, and OFAC Specific Licenses. When someone tells you that you need to obtain an “OFAC license,” they are generally referring to the third category, Specific Licenses. But before pursuing such a license, you should look closely at the first two categories, and see if there is either an Exemption or an OFAC General License that covers the transactions you wish to engage in.

Exemptions. The legislation underlying the regulations administered by OFAC may expressly exempt a particular good, service, benefit, or activity from the kinds of transactions the agency is authorized to block or prohibit. The category of OFAC Exemptions includes those activities, goods, and services which are beyond the legal authority of the Executive Branch to sanction—and therefore outside the realm of OFAC’s regulatory powers. Some examples of activities that are usually exempt have already been mentioned. Another example of a common exemption is travel: freedom of movement is considered by many to be a fundamental liberty, and under most U.S. sanctions programs— which, like the ITAR and EAR, are authorized by the International Emergency Economic Powers Act (IEEPA)—transactions related to travel to and from the country by individuals who are U.S. persons are not prohibited.

A notable—and highly controversial—exception has been Cuba Sanctions, which are largely authorized by the Trading With the Enemy Act of 1917 (TWEA). The U.S. has imposed a comprehensive economic embargo against Cuba since the 1960s. The embargo regulations do not actually ban travel itself, and the Cuban Assets Control Regulations (CACR) do expressly authorize transactions incident to 12 categories of travel, among which are “journalistic activities” and “educational activities, including people-to-people contact.” In addition, OFAC Specific Licenses are issued a case-by-case basis. Nevertheless, the restrictions placed on financial transactions related to travel to Cuba have effectively banned all tourist travel from the U.S.—formerly a major source of revenue for that nation. Some Cuban travel restrictions have been significantly eased by amendments to the CACR during the past few years, most recently in January 2015; and nineteen U.S. airports are now officially authorized by Customs and Border Protection to serve flights to and from Cuba. But given that transactions for tourist activities are still expressly forbidden by a provision in the TSRA, the practical economic significance of these recent regulatory changes for the U.S. travel industry and other sectors is uncertain.

OFAC General Licenses. If no exemption covers the goods or services you want to export, and they are therefore subject to OFAC regulation, then you should determine whether OFAC has published a General License indicating that the agency consents to the export of goods or services of that kind to the sanctioned country. Some general licenses are contained within the OFAC regulations themselves. When an embargo is new, or has just been amended, there may be general licenses issued that have not yet been codified in the CFR, but can be found on the OFAC web site. Various regulatory interpretations are also issued from time to time by OFAC; the legal effect of these interpretations may be equivalent to that of a general license.

General licenses are open-ended authorizations: they grant blanket authority to engage in a certain kind of transaction and you don’t have to apply to use them—although sometimes there are notification or reporting requirements. One important way in which an OFAC General License differs from an Exemption is that OFAC can rescind a general license at any time, whereas it is beyond OFAC’s legal authority to apply sanctions to exempt goods, activities, or transactions.

OFAC Specific Licenses. If the goods or services you want to export are neither exempt from OFAC regulation nor covered by an OFAC General License, you have the option of applying for an OFAC Specific License.

OFAC has fairly broad legal authority to allow—on a case-by-case basis—transactions that would otherwise be prohibited under specific sanctions provisions. OFAC’s Licensing Division reviews all applications from exporters strictly in the order in which they were submitted, and issues or denies licenses based on U.S. foreign policy and national security goals.

Before you proceed to apply for a license, however, we suggest that you review the the details of your proposed export transaction thoroughly, asking the following questions:

(1)   Are there are any U.S. Persons involved in the transaction? (The definition of “U.S. Person” includes a U.S. citizen, a permanent legal resident, an entity formed under the laws of the United States, or anyone physically present in the U.S.)

(2)   Are any of the parties to your proposed export transaction targeted by U.S. economic sanctions (e.g., individuals, businesses, institutions, organizations, or other entities, or official government agents or agencies, who ordinarily reside or operate in sanctioned countries)? (Be sure to identify all parties—including brokers, intermediate banks, freight forwarders, shipping companies, and any other middlemen—their nationalities and their relationship to the transaction.)

(3)    Is the nature of the proposed transaction such that it comes under and is prohibited by the applicable laws and regulations?

If the answer to these three questions is Yes, then you should assume that an OFAC license will be needed before the transaction can be conducted.

How can I apply for a license? For official guidance related to applying for an OFAC Specific License, in addition to the information and instructions found on the OFAC web site, you should refer to 31 CFR 501.801.

You may submit your application electronically, using the online form on the OFAC website at http://licensing.ofac.treas.gov. Alternatively, you may send a letter of request providing a detailed description of the proposed transaction, including the names and addresses of all individuals or companies involved. You can mail your license request letter to the following address:

Office of Foreign Assets Control
U.S. Department of the Treasury
Treasury Annex
Attn: Licensing Division
1500 Pennsylvania Avenue, NW
Washington, DC 20220-0002

All U.S. exporters ought to take full advantage of the extensive compliance resources provided by OFAC on their web site. The agency devotes considerable effort to compliance outreach, and has compiled and published a veritable library of reference materials, including publications geared toward the specific concerns of exporters and importers, including summaries of each sanctions program. They also make an up-to-date SDN list available in a variety of searchable formats.

Finally, you should understand that an OFAC Specific License application, like any request for an exception to a rule, needs to be an advocacy document. That is to say, in order for your application to be granted in a situation of presumed denial, you will have to do more than merely provide the detailed facts concerning the transaction you are proposing; you will also need to make a convincing case for the issuance of the license by appealing to the provisions of the relevant laws and regulations—ideally, to a section or clause indicating the potential availability of special permits or export authorizations for certain reasons or in certain circumstances. You may want to appeal to the stated U.S. Government policy and rationale behind the specific export control regime as well.

In Part 3 of this post, we’ll offer you some practical advice and suggestions for ensuring that OFAC compliance is fully and effectively integrated with ITAR and EAR compliance processes and internal controls in your company’s overall export compliance program.

OFAC: The Not To Be Forgotten Element of Export Compliance (Part 1 of 3)

Question: I read in the Daily Bugle recently about a small family-owned business in Maryland with only ten employees that had to pay a $78,750 penalty for alleged export violations. The article said they had shipped three HVAC duct fabrication machines to a company in China and received payments for them “without authorization from OFAC.” Can you tell me what this is all about? I’m familiar with ITAR and EAR export controls, of course. As a U.S. manufacturer and exporter, my company is registered with the State Department’s DDTC, and we’ve applied for multiple BIS export licenses using the SNAP-R system, but this was new to me. How much do I need to know about OFAC? Bottom line: how critical is this for my company?

Yes, you should know about this. Not knowing can be costly and painful, as that company you read about in the news—Precision Products Inc. (PPI) of Charlotte Hall, Maryland—learned to their dismay earlier this year. You, too, are among those to whom OFAC regulations apply.

OFAC, the Office of Foreign Assets Control, is an often overlooked but extremely powerful and far-reaching agency of the Treasury Department. Its mission is to administer and enforce economic and trade sanctions based on U.S. foreign policy and national security goals. Many of these sanctions programs—prohibitions on financial dealing—have been put in place by the U.S. Government to ensure that companies don’t unwittingly do business with terrorist organizations, sanctioned countries, nationals of some countries, and other specified entities who are engaged in activities related to the proliferation of weapons of mass destruction or other threats. Some OFAC sanctions are based on United Nations and other international mandates, and are therefore multilateral in scope, involving close cooperation with allied governments.

OFAC acts under Presidential wartime and national emergency powers, as well as authority granted by specific legislation. The agency has the authority to prohibit U.S. citizens and corporations from making payments, or providing anything of value, to embargoed countries, businesses, organizations, or individuals. It has the power to impose controls on business transactions of all kinds and freeze any assets that are under U.S. jurisdiction. It publishes the constantly updated list of over 6,000 names–the Specially Designated Nationals List (“SDN List”)–of companies and individuals whose assets are blocked. This is a “black list”: Americans are expressly forbidden to enter into transactions with any of these companies and individuals. U.S. exporters and importers are required to exercise due diligence in searching the SDN List and confirming that dealings with foreign countries are not in violation of OFAC sanctions programs.

In addition, OFAC prohibits travel to, and certain other dealings with, embargoed countries and entities. There are a handful of countries commonly referred to as “OFAC countries” or “embargoed destinations”—a few of the most widely known in recent years have been Cuba, Iran, North Korea, Sudan, and Syria—to whom comprehensive trade sanctions, administered by OFAC, have been applied. In other cases, the economic sanctions have taken a variety of forms, including arms embargoes, capital restraints, asset freezes, and trade restrictions.

Has OFAC been around for a long time? As an arm of the Treasury Department that sets out and enforces trade sanctions issued by the U.S. Government, OFAC is arguably one of the oldest law enforcement agencies in the country. It dates back prior to the War of 1812, when Treasury was first authorized to administer U.S. economic sanctions imposed against a hostile foreign power—in that case, Great Britain, which was harassing American sailors. In more recent times, between 1940 and 1947, Foreign Funds Control (FFC) and the Office of International Finance (OIF) were established as units of the Treasury Department, with legal authority deriving from the Trading with the Enemy Act (TWEA). FFC administered controls over enemy assets and restrictions on trade with enemy states during World War II. It was abolished in 1947, and its functions were transferred to the OIF. In 1950, the OIF morphed into the Division of Foreign Assets Control, when President Truman declared a national emergency and blocked all Chinese and North Korean assets subject to U.S. jurisdiction following the entry of the People’s Republic of China into the Korean War. In 1962, the Treasury Department changed the agency’s name to OFAC.

How critical is OFAC compliance? Absolutely critical. Understanding and monitoring OFAC compliance is a must for U.S. businesses who have foreign suppliers, customers, or clients, or who work with overseas partners. Exporters and importers who are “U.S. persons”—a regulatory term that should be well known to any compliance officer acquainted with the ITAR—are responsible for following OFAC regulations designed to halt terrorist and other illegal funds from circulating. In certain cases, foreign subsidiaries owned by U.S. companies and foreign persons in possession of U.S.-origin goods are also required to comply. So, if you are a small business owner or an individual doing business overseas, you need to familiarize yourself with OFAC. And if you are a company officer or manager in an industry with significant foreign trade, you need to make sure that OFAC compliance is an essential component of your corporate compliance program.

Penalties for violating the regulations administered by OFAC are serious, and have grown even more serious in the last few years. Depending on the sanctions program, potential criminal penalties for willful violations include fines ranging up to $20 million and imprisonment of up to 30 years. Civil penalties for violations of the Trading With the Enemy Act (TWEA) can be as much as $65,000 for each violation. Civil penalties for violations of the International Emergency Economic Powers Act (IEEPA) can range up to $250,000 for each violation, or twice the gain from the violation, whichever is greater. Over the past several years, the number and monetary value of enforcement actions by OFAC have increased dramatically: civil penalties and settlements rose from about $3.5 million in 2008 to more than $1.2 billion in 2014. These are not penalties that can simply be written off as “the cost of doing business”!

Yet OFAC compliance is the most commonly misunderstood and most likely to be forgotten element in corporate export compliance programs. Discussions of U.S. export controls are frequently dominated by and focused on ensuring compliance with the ITAR and EAR, while OFAC regulations are overlooked or undervalued. Yet OFAC rules generally override all other export controls, and OFAC restrictions may apply even when an EAR license exception or ITAR exemption is available.

The widespread tendency to underestimate the importance of monitoring OFAC compliance is especially problematic because OFAC’s programs are dynamic: the embargoes and sanctions, the scope and details of the restrictions, and the names on the SDN List and other lists change very frequently. What is more, new lists may appear at any time, as U.S. foreign policy refocuses in response to a rapidly changing world scene—witness the Sectoral Sanctions Identification List (“SSI List”) that OFAC issued in 2014, targeting transactions with persons in four sectors of the Russian economy: financial services, energy, defense, and mining. It is essential therefore that exporters check the Treasury web site frequently and have the necessary processes and internal controls in place to monitor compliance continuously. Firms with weak processes and controls limit their ability to prevent violations, or to detect and quickly deal with them if they do occur. They run significant risks of heavy fines and other damaging consequences.

In Part Two of this post, we’ll take a look at the three kinds of OFAC export authorizations available to U.S. companies—Exemptions, General Licenses, and Special Licenses, explain when you may need an OFAC Special License and how you can apply for one, and clear up a couple of common misconceptions. (No, OFAC requirements don’t impact only banks and financial institutions!)

In Part Three, we’ll look at the essential ingredients of a robust corporate OFAC compliance program. (Hint: simply checking your customers’ names and addresses against the SDN List is not enough!)

In today’s challenging international environment, the economic and trade sanctions administered by OFAC are likely to play a larger and larger role in cross-border transactions. It will be important for U.S. exporters to understand these controls thoroughly and keep abreast of changing requirements in order to focus on maintaining full compliance. The Export Compliance Solutions Training Academy provides a variety of training options—including 2-day regional seminars, in-house training, and live web-based seminars—that afford comprehensive coverage of ITAR, EAR, and OFAC controls, supplemented by case studies, practical advice, and help with strategic planning for your business. Check out the information on our web site about course offerings and online video training in export compliance awareness for your employees. Contact us by phone or e-mail to learn more. The ECS staff represents the most recognized expertise in the compliance field. We’re here to help!

Redefining EAR and ITAR Terms: Little Changes Could Make a Big Difference for Exporters

Question: Thanks for the heads-up last week about the compliance risks of storing sensitive data in the cloud—and the good news that regulatory changes may be ahead. Are there other revisions to the EAR and ITAR in the works that are likely to impact my company’s policies for safeguarding export-controlled technology and technical data? As I look at the Proposed Rules published by State and Commerce on June 3, I get the impression that they’re mostly about definitions—clarifying the meanings of certain technical terms. How important is all that stuff, practically speaking, to a firm like ours?

Very important. Compliance requirements and potential violations often hinge on the definition of a single word! So you really need to review these proposed new definitions carefully—both the Commerce Department’s proposed revisions to the definitions in the EAR and the State Department’s proposed revisions to definitions in the ITAR— to determine what impact they would have on your operations and compliance obligations, should they be adopted.

As I’m sure you’re well aware, U.S. export controls under the ITAR for defense articles and services contrast sharply with the (generally) more liberal controls under the EAR for “dual-use” commodities, software, and technology. For that reason, it’s critically important that you determine accurately whether or not the items or technical data you plan to ship or transfer internationally are subject to ITAR controls. Making that jurisdictional determination requires paying careful attention to the current USML and the appropriate categories within the USML that apply to the export in question.

That’s one of the reasons it’s also vital that you follow closely all the recent changes that have been made to the USML—and the “600 series” ECCNs of the CCL— due to the ongoing Export Control Reform initiative, as well as those changes that are still being made. And that most emphatically includes proposed revisions to the definitions of terms!

The Proposed Rule published by the DDTC on June 3 is notable for its length (14 pages of hard copy in the small print of the triple-columned Federal Register) and for the unusually large number of revisions to the ITAR that are proposed. It contains a plethora of new definitions for regulatory terms, making it a veritable dictionary. Many of the proposed revisions are meant to harmonize the ITAR rules with those of the EAR. The BIS published a similar Proposed Rule with conforming amendments.

The key terms and phrases that would be redefined, clarified, updated, or adopted under the June 3 Proposed Rules include the following:

Technology
Technical Data
Public Domain
Fundamental, Basic, and Applied Research
Development
Production
Required
Defense Article
Defense Service
Characteristics and Functions (of an item)
Peculiarly Responsible
Export
Reexport
Release
Transfer (in-country)
Retransfer
End-to-end Encryption

For exports controlled by the ITAR, two of the proposed new definitions are especially noteworthy: “public domain” (vs. “technical data”) and “defense service.” That’s because these definitions potentially apply to every single category of the U.S. Munitions List.

We’ll take a closer look at the first of these this week, and discuss the second and more controversial of the two in a future post.

Revisiting “Public Domain”

The State Department proposes to revise the definition of “public domain” in ITAR Section 120.11 in order to simplify, update, and introduce greater versatility into the definition. The current version of ITAR Section 120.11 enumerates the ways in which “public domain” information might be published. State says that it now believes that defining “public domain” by a list such as this is unnecessarily limiting in scope and insufficiently flexible, given the continually evolving array of physical and electronic media and communication technologies by which information can be disseminated. The new definition they propose is intended to be more versatile than the list-based approach to identifying public-domain information sources.

Under the State Department’s proposed revisions to definitions in the ITAR, unclassified information and software are considered to be in the public domain—and thus not technical data or software subject to the ITAR—“when they have been made available to the public without restrictions upon their further dissemination such as through any of the following . . . .” Among the means of dissemination mentioned, 120.11(a)(4) is of special interest, as it includes in the “public domain” information available on publicly accessible web sites:

(4) Public dissemination (i.e., unlimited distribution) in any form (e.g., not necessarily in published form), including posting on the Internet on sites available to the public;

There are some important qualifications that should be carefully noted, however.

One well-known consequence of the open, uncontrolled nature of the internet is that a vast amount of information can be found online that was uploaded illegally, in violation of a wide range of national and international laws governing copyrights, patents, privacy, public safety, national security, and many other matters. Plainly, the discovery of certain technical data, information, or software on a web site carries no guarantee that the individual or organization posting it hasn’t done so in violation of U.S. export laws and regulations.

With regard to such contingencies, a note to the proposed revision to ITAR Section 120.11 warns that anyone exporting, reexporting, or retransferring export-controlled information found on the internet, or otherwise making it available to the public, will be committing an export violation.

Taken together, the new definition and the warning that accompanies it raise the specter of inadvertent illegal exports of ITAR-controlled technical data by U.S. exporters who had no reason to suspect that the information they were making use of was not in the public domain, given that it was already freely available to the public via the internet. Evidently foreseeing this concern, the DDTC immediately reassures exporters, in a second note to the new Section 120.11, that in such cases a person will not be considered guilty of an export violation . . . unless — as described in the revised Section 127.1(a)(6) — “such person has knowledge that the technical data or software was made publicly available without an authorization.”

But here’s the rub: how can your company be certain that any item of technical information found on the internet was properly cleared for public release before being uploaded? And if your company should inadvertently disseminate technical data that later turns out to have been controlled by the ITAR and uploaded to the internet by somebody else without DDTC authorization, how would you be able to prove that you did not “have knowledge” that it was export-controlled? Those are just a few of the questions and concerns that have been raised about the language of this proposed revision to ITAR Section 120.11. Discussions of these concerns between the regulatory agencies, the defense industry, the research universities, and the legal community are ongoing. It is possible that the language in the Proposed Rules will be revised as a result of those discussions. Whenever the DDTC and BIS publish their Final Rules on the definitions of these key terms — possibly within the next few months — we may find that some of these points have been addressed and further clarified.

Stay on the Safe Side

Be that as it may, here is what we recommend to you as the safest policy and procedure for your company under the current regulations — and none of the revisions currently under consideration by the DDTC or BIS is likely to change this greatly: before posting to the internet any technical information about your company’s products or research, other than non-proprietary general system descriptions or information on the basic function or purpose of an item, thoroughly review the USML and the CCL to determine if the information falls under U.S. export controls. If there is doubt about export jurisdiction, request a Commodity Jurisdiction determination from the DDTC; and if State should determine that ITAR controls apply, obtain an export license for the technical data, or request authorization for “release” of the document you want to post online from the appropriate agency, as described in Section 120.11(b).

Remember that knowingly uploading controlled technical data to the internet without appropriate authorization is a export violation that could have extremely serious penalties and consequences, for both you and your company, whether or not there is any evidence that a foreign national has read or downloaded the data. Don’t needlessly put yourself and your company at risk.

Paragraph (b) of the revised definition explicitly sets forth the DDTC’s requirement of authorization to release information into the “public domain.” This requirement is not new: it also exists under the current rules; the revised rules would state it more explicitly and amend some definitions to clarify the scope of the information covered, but the requirement is already there. Before you can make such information available, the U.S. Government must approve the release through one of the following agencies: (1) The State Department’s DDTC; (2) the DoD’s Office of Security Review (OSR); (3) a relevant U.S. Government contracting authority, if one exists, with the authority to allow the technical data or software to be made available to the public; or (4) another U.S. Government official with the proper authority for this.

In many cases, we believe that requesting a security review by the OSR will be the best and wisest route you can take in order to safeguard your company against the risk of an export violation. Guidelines for submitting documents for review can be found on their web site.

The experienced compliance professionals at Export Compliance Solutions (ECS) are well-positioned to advise you regarding the impact that the revised definitions in the June 3 Proposed Rules are likely to have on your operations and corporate export compliance programs, and to assist you with other export control issues as well. Our consultants frequently work with ECS clients to review their current classification policies and procedures, conduct large-scale or multi-national classification projects, train employees in navigating complex reporting and recordkeeping requirements, discover ways to enhance and streamline administrative processes, and more effectively implement internal compliance audits and assessments. As America’s premier trainers and consultants in EAR and ITAR compliance, we can help you make sure that your company maintains full compliance with the changing Commerce and State Department regulations.

Export-Controlled Data – Store It in the Cloud or Keep It Down Home?

Question: Is there any reason that our company can’t use a cloud storage service provider, such as Dropbox, Google Drive, Box, or Microsoft Office 365, to store and share export-controlled information and technical data? Most businesses are using the cloud these days. Are there any problems with this?

The simple answer is, Yes, there are problems. Serious ones. Uploading your ITAR-controlled technical data, or controlled technology subject to the EAR, to “the Cloud” while maintaining full compliance with U.S. export laws and regulations is very challenging, and carries with it a high risk of violations and penalties. As we’ll be explaining on this blog, regulatory changes appear to be on the way. In the not-too-distant future, U.S. companies may be able to use cloud computing and other online digital services, subject to certain encryption requirements, to transfer and store their unclassified technical data without the need to obtain licenses or other authorizations. Hope is on the horizon. At present, however—yes, there are problems.

Even though cloud computing is a rapidly advancing technology at present, with more and more businesses routinely using Dropbox, Google Drive, and similar online services, this has been—and still is—a confusing regulatory area for which State and Commerce have provided very limited guidance until recently. We’re glad that appears to be changing now.

Nevertheless—even after the long-awaited publication of new Proposed Rules by the DDTC and BIS on June 3 containing multiple clarifications and definitions, and even after the issuance of an interim rule by the DoD on August 26 addressing requirements for cloud computing services—it is still far from clear how exporters can be certain they are fully compliant with the EAR and ITAR and avoid inadvertent violations when uploading controlled data to the cloud. A storm of controversy continues to swirl around the subject of cloud computing, IT security, and export controls. Discussions between the defense industry, research universities, the legal community, and the regulatory agencies are intense and ongoing.

Until the dust settles on this, we recommend extreme caution in using any commercial cloud storage service for information storage and transmission when export controls apply. Without clear regulatory guidance, contracting with a third-party for transferring and storing your ITAR-controlled and EAR-controlled data and technology electronically may expose you and your organization to the risk of violating U.S. export laws, with severe penalties and consequences.

But my cloud service provider assures me that my data is absolutely secure—so secure that they themselves have no way to decrypt my files without my password, even if I asked them to.

Yes, Dropbox, Google Drive, Microsoft Office 365, and similar services offer a secure and convenient online environment for storing and sharing documents, and are widely used and trusted in industry for work collaboration, file sharing, and data maintenance. And it is true that they typically provide multiple security precautions, including using SSL for transmitting content and their own separate layer of AES-256 bit encryption server-side.

Nevertheless, even though these IT companies have strict internal security policies limiting access by their employees to their customers’ files, it is evident in many cases that user-data files stored on their servers are in principle accessible by their staff—which may include individuals who are not U.S. persons as defined by the ITAR.

Read the terms of your storage provider’s user agreement and privacy policy carefully. Those legal documents frequently include such warnings as the following: “If we are required to provide your files to a court or law enforcement agency, which we may do under the conditions set forth above, we will remove the encryption from the files before providing them to the authorized government officials.” You’ll also see various disclaimers of responsibility in case of data-security breaches, and statements indicating that the provider has a process in place for contingencies when their system is compromised. Some cloud storage providers claim in their promotional materials that your data is absolutely secure, but remember that what they advertise and what you agree to when you open an account are two different things.

The convenience, economy, and popularity of online services notwithstanding, the use of third-party providers for storing and sharing ITAR-controlled technical data remains problematic. Why?

Here’s one reason: U.S. export control regulations prohibit the unauthorized sharing of controlled technical data with non-U.S persons or foreign nationals, and also prohibit transactions with certain foreign individuals and states. This prohibition includes any form of sharing, including electronic “transmission,” and including even theoretical access to such data by IT administrators or employees who maintain the electronic data storage and transmission systems and who could potentially monitor them. Whenever you store or transmit controlled technical data via non-company servers, you are, in effect, sending your data through cyberspace on the back of a virtual postcard, and you are liable for any access to that data by unlicensed foreign nationals while it is in storage or transit—even if the access is unintentional, and even if you were not aware that the access was occurring.

Remember that commercial cloud computing and online data storage services are not U.S. defense firms; they are unlikely to have segregated systems to protect ITAR-controlled information from foreign-person access. Under the export regulations currently in effect—ignoring, for the moment, proposed revisions to the EAR and ITAR that are under consideration but haven’t been finalized—even high-level encryption is not an adequate security measure for protecting your company’s controlled technical data on non-company servers. Currently, transfer of the data to a server or network location outside the U.S. constitutes an “export” even if the data is encrypted. Furthermore, providing employees who are not U.S. persons, whether they are employed in the U.S. or at non-U.S. offices, with the ability to access ITAR-controlled data (even if they don’t actually access the data) may constitute an “export,” even if the data is protected by encryption.

Here’s another reason: using external providers of cloud storage and file-sharing services, such as Dropbox, Box, or Google Drive, for ITAR-restricted data is problematic because it is difficult or impossible to know where their servers are physically located (that is, whether they are in the U.S. or overseas), how they route data traffic (particularly during peak hours or off-times), or whether their security procedures are truly adequate all along the line to prohibit access to your data by foreign nationals. Most—if not all—cloud computing services routinely use a network of servers that extends beyond U.S. borders. In reality, you have no idea where your data is currently stored—and wherever that may be, it could change tomorrow. Yet any transfer of data from the user to a server outside the U.S., as well as any transfer of the controlled data between two foreign-located servers, constitutes a “transmission,” and thus an unauthorized export, according to current U.S. laws.

But didn’t all that change this year? I read in the news that BIS and DDTC have relaxed their rules now, in recognition of the growing popularity of cloud computing, and that the export regulations have been amended to permit cloud storage of ITAR and EAR data in certain circumstances. Did I hear you right? Are you telling me that’s not true?

You heard me right. That’s not true. Those amendments to the ITAR and the EAR you heard about have not been made—at least, not yet. Here’s what is true:

On June 3, 2015, both the Commerce Department and State Department published long-awaited proposals for revising the EAR and ITAR in order to provide security standards for the transmission and storage of ITAR- and EAR-controlled data and information. If these Proposed Rules are adopted and finalized, they could well represent an important step towards clarifying what exporters need to do in order to comply with U.S. export controls with regard to the transmission, storage, and “cloud” processing of export-controlled technical data, technology, and software.

Among other things, if the revisions proposed on June 3 are eventually adopted and published as final rules, transmitting or storing electronic data in a way that meets certain specified security standards will no longer constitute an “export” of the data, and therefore will not require a prior export authorization or be subject to some other restrictions. Specifically, the June 3 proposals from State and Commerce both say that sending, taking, or storing technical data, technology, or software will not be considered an export when the following conditions are met:

(1) The data must be unclassified;

(2) The data must be secured using “end-to-end encryption” (as defined in the proposed new rule);

(3) The data must be secured using cryptographic modules compliant with a certain encryption standard—FIPS 140–2, or its successors [in stating this condition, the BIS proposal adds the phrase “or other similar cryptographic means,” whereas the DDTC doesn’t wish to add that phrase]; and

(4) The data must not be stored in certain prohibited countries [for the BIS, this means the server locations can’t be in countries listed in Country Group D:5 (see Supplement No. 1 to Part 740 of the EAR) or in the Russian Federation; for the DDTC, this means no data should be stored on servers situated in ITAR Section 126.1 Proscribed Countries or in the Russian Federation].

At first glance, these proposed changes look very hopeful. By providing clarity and legal certainty in this regulatory area, they promise to simplify the compliance process greatly. If implemented, these provisions could offer U.S. companies the option of using the new cloud technologies for transmitting and storing export-controlled data without the risk of export violations, as long they exercise due diligence to ensure that those data security requirements are met.

On closer examination, however, there are some notable caveats in these Proposed Rules:

(1)        Both proposals make it clear that if information should be “released” that permits foreign persons to access your encrypted controlled data (e.g., decryption keys, network access codes, passwords, etc.), then this data transmission or storage will be considered an export, and will be subject to all applicable licensing requirements and restrictions—and penalties for export violations.

(2)        To qualify for this exclusion, your transmission or storage must utilize “end-to-end encryption.” In both the State and Commerce proposals, this means that cryptographic protection of the export-controlled data must be continuous and uninterrupted between the originator and the intended recipient (who could be the originator himself, in the case of simple file storage or archiving). At no point in the process can access in unencrypted form be given to any third parties. That includes internet service providers (ISPs), application providers (such as Microsoft Office 360 or Google Office), or cloud storage providers (such as Dropbox or Box), or any other online services.

(Note: BIS and DDTC are insisting on this condition because they are have found that the methods and procedures currently used by third-party digital service providers, including popular cloud software providers and some e-mail services may allow the data transmitted to be encrypted and decrypted multiple times before it reaches its intended recipient. BIS and DDTC both believe this presents an unacceptable risk of unauthorized release. Keeping the data encrypted from start to finish is the simplest and surest way to minimize the possibility that a foreign cloud service provider or a non-U.S. person employee of a domestic cloud service provider will get access to your ITAR-controlled data or EAR-controlled technology or software in unencrypted form.)

(3)        To qualify for this exclusion, your export-controlled data cannot be stored on, or pass through, any servers in certain specified countries that pose significant national security risks, including the Russian Federation.

On the whole, the provisions in the June 3 Proposed Rules allowing the transfer and storage of properly encrypted technical data are good news for U.S. exporters and should be welcomed. These changes would allow controlled technical data originating in the U.S. to be stored in one or more countries outside of the United States without export licensing, provided the data has been properly encrypted and isn’t stored in arms-embargoed countries or Russia. The proposed security requirements are strict and would almost certainly create complications for the current business model of most cloud storage providers, forcing them to make some changes in the way they operate if they want to serve customers with EAR- and ITAR-compliance requirements. But the requisite changes would appear to be within their capabilities, and the potential benefits of the new rules—which include, among other things, considerably reduced administrative burdens for U.S. manufacturers and suppliers of defense articles and services— are great.

Remember, however, that until State and Commerce have finalized their proposed amendments, the current regulations remain in effect. Until they have been changed, we recommend using locally hosted applications for storing and sharing sensitive technical data. The pundits may well be right when they tell us that the future of data storage is in the cloud, but for now, if your data is export-controlled, the safest place for it is in-house.

There are other important regulatory changes in the works with the potential to impact cloud computing, IT security, and export controls. Next week we’ll look at a few of them. Sign up today for notifications of future posts—and join the discussion by sending your own questions about export compliance to “An EAR . . . to the ITAR.”

Oops! I made a mistake… Can I amend a BIS-748P?

Question: I know what to do if it becomes necessary to amend a State/DDTC authorization for exports under the ITAR. But what if I need to make a change to a Commerce/BIS export license? Can I even do that?

The short answer to your question is, Yes, you can – but there’s a very good chance you won’t need to.

Here’s the skinny on correcting a BIS-748P application form or modifying a previously approved export license through the Commerce Department’s SNAP-R system:

You’ve determined that your export falls under the jurisdiction of Commerce and that the transaction requires a license from BIS. You’ve done your research, put together all the information and documentation you need, and have just successfully submitted a SNAP-R BIS-748P license application online. Not long afterwards, before you have even finished congratulating yourself on another job well done, you suddenly realize—to your embarrassment and disgust—that you entered some incorrect information in one of the data fields in your submission, or that you completely forgot to attach the required documents. You quickly log on again to your SNAP-R account and hunt around frantically for an “Undo” or “Recall” button, but fail to find one. Zero, zilch, zip, nada, nothing. What are you supposed to do? Visions of denied licenses, lost time, angry customers, and potential export violations swim before your eyes. Is this going to be a big problem?


Not to worry. Rest assured that you aren’t the first exporter to mess up a license application form. While it’s true that there isn’t any way to undo or recall your Form BIS-748P online once it’s been submitted, all you need to do is phone the BIS’s Office of Export Services and let them know about the mistake. The licensing officer will then simply mark your application “Returned Without Action” (RWA), which means in essence that your application has been rejected, but without any prejudice to future resubmissions. Once that’s done, you can breathe a sigh of relief, copy your original application, fix the mistakes or omissions, and re-submit it to BIS—correctly, this time!—through SNAP-R. Or, if your only mistake was failing to attach the documentation, the licensing officer will just send you an e-mail requesting those documents, to which you can reply directly and rectify the omission.

But what if your export license has already been approved by Commerce, but now you realize you’re going to have to modify it because some things have changed since then? What should you do?

Well, the good news is that you might not have to do anything at all, if:

(1) your modifications are considered “non-material changes,” according to the detailed description in EAR Section 750.7(c);

or

(2) your modifications are covered by the “shipping tolerances” provision of EAR Section 750.11.

The list of “non-material changes” includes such alterations as a change in unit price or total value, a change in intermediate consignee (if the new intermediate consignee is located in the country of ultimate destination), and a change in the address of purchaser or ultimate consignee (if the new address is located within the same country shown on the license). For the details, read through §750.7(c) carefully; there’s a very good chance you’ll find your change listed there. (And, while you’re doing that, take a couple of minutes more to familiarize yourself with the shipping tolerance exceptions in §750.11 as well; it’s practical knowledge that may prove handy!)

7507 75011 change_to_license

Even in the case of a minor change to your company’s name—assuming that the name change is not the result of a change of ownership, a merger, or an acquisition—you may find that all you really need to do is have the administrator for your SNAP-R account update the name online in the Administration Module. A word of caution, though: a company’s name change may or may not be considered a “non-material change” by the BIS; you’ll need to write to them on company letterhead and request an Advisory Opinion about that before proceeding.

Finally, what if you’ve carefully scrutinized Section 750.7(c) of the EAR and determined that the modification you need to make is unfortunately not among numerous exceptions designated there as “non-material changes”? If that is the case — assuming that you are still shipping the identical items to the identical ultimate consignee — you will need to notify BIS of the change, and it’s up to them to approve or not approve the modification.

You’ll be glad to know that you can deal with this situation online by applying for a “Replacement License” number from BIS. Simply make your request via a SNAP-R Form BIS-748P, using Block 11, “Replacement License Number,” stating concisely what change you are making to the original export license.

In the event that BIS does not approve your “Replacement License” request—they will give you their response in writing— a new export license application will need to be submitted, and approved by BIS, before you can make any further shipments.

easy_stSound easier than you thought it would be? Well, many companies who have entered the regulatory jurisdiction of BIS for the first time recently, thanks to the Export Control Reform Initiative (ECR), have said they were surprised and relieved to discover that Commerce’s controls and licensing regime are often simpler and less restrictive than State’s. Export Licensing Officers have generally found Commerce’s SNAP-R electronic application portal to be more user-friendly than the State Department’s D-Trade system.

There are other significant differences between the two export regimes as well. For example, you do not need to “return” your Commerce export license to BIS once it is no longer valid, as you are required to do with a DSP license from State/DDTC after expiration or exhaustion when it has not been decremented entirely electronically through AES. In future posts, we’ll be spotlighting some other similarities and differences between EAR and ITAR licensing, in addition to providing you with practical information you’ll need when applying for and using Commerce licenses for “600 series” items, which were formerly subject to the ITAR.

Even though the BIS application process is simpler in many ways, be aware that Commerce export licenses typically have more conditions attached than State/DDTC licenses or agreements. And remember this, too: whether you’re exporting your product under a Commerce or a State export license, you and your company are responsible and legally accountable to stay within authorized scope of the export authorization and strictly observe all its provisos and conditions.

penaltyCommerce and State have been increasingly active in export enforcement lately. Civil and criminal penalties for export violations in recent cases have been extremely heavy. Even “minor” export violations of the ITAR and EAR can have very serious consequences for companies and individuals.

Achieving and maintaining corporate ITAR and EAR compliance can be a daunting challenge for U.S. exporters, but we’re here to help. Export Compliance Solutions (ECS) has built a distinguished record based on many years of experience in the field of U.S. export controls. As the nation’s premier export compliance consultants and educators, we offer a wide variety of training, auditing, and advisory services, including live regional and on-site seminars, webinars, export compliance awareness video courses for employees, and other products to support our clients. Give us a call or send us an e-mail today. The ITAR and EAR compliance experts at ECS can help you successfully navigate the sometimes rough regulatory seas of U.S. export controls.