How to keep critical information and technology away from those who wish to harm our country, our families, and ourselves.
By Mark D. Harris[1]
The MDHI’s work in Ukraine and the Middle East has stimulated discussion on bringing technology into these countries, which could be considered de facto technology transfers. For example, we have asked if it is permissible to bring new ultrasound machines into Ukraine to take care of patients. The answer that we discovered was a qualified “yes”, if we were willing to cut through thickets of red tape and wade through rivers of regulations. Ultrasound machines are not “prohibited/restricted”, and they are not “dual use” (military and civilian), but they are “high technology” and therefore subject to scrutiny. There have also been questions about robotics parts and 3D printers, both of which can be considered “dual use”
In an era of rapid innovation and global collaboration, the protection of sensitive technology is no longer just a matter of corporate security; it is a critical component of national security and international law. For organizations operating across borders, understanding the intricacies of export controls is essential to avoid severe legal penalties and reputational damage.
Export Control Obligations and Technology Transfers
A technology transfer occurs whenever controlled technical data is shared with a foreign person, whether through email, cloud access, visual inspection of equipment, verbal briefings, or something else.[2] Organizations must identify the Export Control Classification Number (ECCN) for their technologies to determine if a license is required before any transfer takes place.[3] Failure to secure the necessary authorizations can lead to massive fines, the loss of export privileges, and even criminal prosecution.
Export Control Classification Numbers (ECCN)
- First digit – category, such as electronics or materials
- Second digit – product group, such as software or hardware
- Final three digits – unique identifier
The special designator, EAR99, applies to items not specifically listed on the Commerce Control List (CCL), which is maintained by the Bureau of Industry and Security (BIS). The ECCN helps exporters:
- Identify whether an item is controlled for export.
- Determine the reason for control, such as national security, anti-terrorism, or nuclear nonproliferation
- Check if a license is required for a specific country or end user.
- Identify available license exceptions that may allow export without a license
People can find ECCNs from manufacturers and from the CCL.
Best Practices for Safeguarding Sensitive Technologies
Safeguarding sensitive technology requires a defense-in-depth strategy that combines physical, digital, and procedural controls. Organizations should adopt a principle of least privilege, ensuring that only individuals with a verified “need to know” and the appropriate legal authorization can access controlled data.[4] Key measures include:
- Digital Segmentation: Maintaining controlled technical data on secure, encrypted servers with multi-factor authentication and robust activity logging
- Physical Security: Using badges, biometric scanners, and restricted areas to prevent unauthorized visual access to prototypes or sensitive hardware
- Marking and Labeling: Clearly marking all documents and files containing controlled technology with their specific classification and handling instructions
- Secure Communications: Mandating the use of approved, encrypted platforms for any discussions involving sensitive technical details
Elements of an Effective Internal Compliance Program (ICP)
An Internal Compliance Program (ICP) is the foundational framework that ensures an organization meets its legal obligations consistently. A robust ICP is not a static document but a living system of oversight and improvement. The essential elements of an ICP in a corporate environment include:
- Management Commitment: Clear, written support from senior leadership prioritizing compliance over short-term commercial gains. For example, management at all levels must commit to full compliance with laws such as the Arms Export Control Act (AECA)[5] and International Traffic in Arms Regulations (ITAR).[6]
- Continuous Training: Regularly updated training programs tailored to different roles, from engineers and sales teams to IT and HR.
- Risk Assessment: Ongoing evaluation of the organization’s products, customers, and geographic reach to identify and mitigate potential compliance gaps
- Recordkeeping: Maintaining meticulous records of all export classifications, licenses, and communications for at least five years
- Auditing and Reporting: Internal and external audits to verify that procedures are being followed, coupled with a clear mechanism for reporting and correcting violations
Academic institutions and even individuals must consider whether their actions violate law. For example, in July 2009, a professor at the University of Tennessee working on an Air Force contract was convicted of violating the AECA by sharing technical data with Chinese and Iranian graduate students. He served over two years in prison.
Due Diligence for International Partnerships and Investment
International partnerships, mergers, and acquisitions present significant export control risks. Before entering into an agreement, organizations must perform rigorous due diligence to ensure they are not inadvertently facilitating illegal technology transfers.
This process begins with Restricted Party Screening (RPS). Organizations must vet all potential partners, investors, and vendors against government “watchlists,” such as the Entity List or the Specially Designated Nationals (SDN) List. Beyond basic screening, firms must investigate the end-use and end-user of their technology. If a prospective partner has ties to a restricted military program or a sanctioned government, the risk may be prohibitive. Furthermore, foreign investments in sensitive domestic technology sectors may trigger a review by the Committee on Foreign Investment in the United States (CFIUS), which has the power to block or unwind deals that threaten national security.
Conclusion
In summary, the intersection of technology and international law requires a proactive and disciplined approach. By integrating robust compliance programs and rigorous due diligence into their core operations, organizations can innovate with confidence, knowing they are protecting both their assets and the security of the global community
Footnotes
[1] Augmented by artificial intelligence
[2] A deemed export is the sharing or release of controlled technology, technical data, or source code to a foreign national within the United States, which is considered an export to the foreign person’s country of nationality or permanent residency, even though no physical item crosses borders
[3] An ECCN is a five-character alphanumeric code used to classify U.S. export-controlled items on the Commerce Control List (CCL) to determine licensing requirements.
[4] The principle of least privilege (PoLP) ensures that users, processes, or applications are granted only the minimum access necessary to perform their tasks, reducing security risks and limiting potential damage from breaches. It is also known as the Principle of Minimal Privilege (PoMP) or the Principle of Least Authority (PoLA).
[5] Provisions of the AECA:
- Foreign Military Sales (FMS) and Commercial Sales: AECA provides the framework for both government-to-government and commercial defense transactions
- End-Use Monitoring: Ensures that exported defense articles are used as intended and not diverted to unauthorized users
- Restrictions on Certain Countries: Prohibits sales to nations supporting terrorism or not cooperating with U.S. antiterrorism efforts
- Congressional Oversight: Requires reports and certifications to Congress on significant arms sales and potential violations
- Licensing and Compliance: U.S. exporters must obtain licenses for defense articles and services, with strict documentation and adherence to AECA regulations
[6] International Traffic in Arms Regulations (ITAR) is a is a set of U.S. Department of State regulations controlling the export and import of defense-related articles, services, and technical data to safeguard national security and enforce foreign policy objectives. ITAR covers defense articles (guns, bombs, US munitions list), defense services, and technical data.







