Deemed Export Compliance and Technical Data

Deemed export compliance for protecting controlled technical data

A deemed export happens when controlled technology or technical data is released to a foreign national inside the United States no shipment, no border crossing, no physical export required. The release itself is treated, legally, as if it were exported to that person’s home country.

Deemed export rules exist under both the Export Administration Regulations (EAR) and the International Traffic in Arms Regulations (ITAR), and both trace back to the same underlying purpose: protecting national security by controlling who can access sensitive technology, not just where it physically travels.

This catches manufacturers off guard because it applies to something that feels entirely domestic: hiring a foreign employee, hosting a foreign visitor, or sharing a technical drawing internally. 

Here’s what actually counts, who’s exempt, and what this looks like in practice. 

Related Topic: ITAR vs EAR: Which Rules Apply to You?

What Is a Deemed Export? 

Under both EAR and ITAR, a “release” of controlled technology, technical data, or source code to a foreign person is treated as a deemed export to that person’s most recent country of citizenship or permanent residency regardless of where the release actually happens. Release, in this context, covers more than handing someone a document. Visual inspection of controlled equipment, oral discussion of technical information, and giving someone access to a network or file share containing controlled technical data can all qualify. 

The trigger isn’t international travel or shipping. It’s giving a foreign person access to something controlled, wherever that access happens to occur. 

Related Topic: What Is DFARS 252.204-7012? Requirements, Compliance & CMMC?

Do US Citizens Need a Deemed Export License? 

No. Deemed export rules specifically concern foreign persons — a U.S. citizen accessing the same controlled technology doesn’t trigger a deemed export question at all. The relevant factor is the individual’s citizenship and immigration status, not their job title, role, or level of access otherwise. 

That said, “foreign national” doesn’t mean everyone who wasn’t born in the U.S. Lawful permanent residents (green card holders), and individuals granted asylum or refugee status, are collectively treated as “protected individuals” and generally excluded from the definition of foreign person under both EAR and ITAR the same as U.S. citizens for deemed export purposes. The employees who actually trigger deemed export considerations are typically those on temporary visas H-1B holders, for example who haven’t obtained permanent resident status. 

Related Topic: ITAR Compliance: Requirements & Cybersecurity

What Is Not a Deemed Export? 

A few categories fall outside deemed export rules entirely. Publicly available technology generally avoids export controls, so sharing unrestricted published information does not trigger a deemed export. General scientific, mathematical, or engineering principles taught in courses at accredited institutions typically fall outside the rule as well. Sharing information with permanent residents, asylees, or refugees does not count because regulations exclude them as foreign persons.

Related Topic: Is Your Business Ready for SOC 2? | What a Readiness Assessment Reveals

What Does This Actually Look Like in Practice? 

This shows up in ordinary HR and IT decisions more often than manufacturers expect. In one internal situation we managed directly, a new hire’s visa status meant their laptop provisioning and system access had to be deliberately restricted and staged around a specific deadline, rather than handled the same way as any other new employee’s onboarding a straightforward IT process suddenly had a compliance dimension attached to it. 

We’ve also seen this addressed on the visitor side, not just employment. One aerospace client created visitor training because facility tours can expose foreign nationals to controlled equipment and processes.

Both examples point to the same underlying lesson: deemed export isn’t a one-time registration question. Companies must routinely review hiring, IT provisioning, facility access, and visitor management through a deliberate export-control compliance process.

Related Topic: SOC 2 Requirements: What Your Business Needs to Know

Is a Deemed Export the Same Under ITAR and EAR? 

The underlying concept is consistent a release of controlled information to a foreign person is treated as an export to that person’s home country but the specific technology covered, and which agency’s rules apply, depends on whether the underlying technical data is ITAR-controlled (defense articles, administered by the Department of State) or EAR-controlled (dual-use items, administered by the Department of Commerce). We cover how those two frameworks differ more broadly in our guide to ITAR vs. EAR. 

Related Topic: Why Every Business Needs a Disaster Recovery Plan

Is This the Same as the “50 Percent Rule” for Export Controls? 

No, and this is worth clarifying directly since the two get confused. The 50 Percent Rule formally the Bureau of Industry and Security’s (BIS) “Affiliates Rule,” effective since September 2025 — concerns foreign entity ownership: a foreign company that’s 50% or more owned by a party on BIS’s Entity List or Military End-User List automatically inherits that party’s restrictions. It’s a real, current, and increasingly important EAR concept, but it’s about corporate ownership screening, not about individual foreign persons accessing controlled technology. Manufacturers may meet deemed export requirements but still must separately screen foreign customer or supplier ownership under Affiliates Rule.

Review hiring, IT access, and visitor policies now to address deemed export risks before questionnaires or incidents expose gaps. Our team works with manufacturers in the DoD and aerospace supply chain on exactly this kind of access-control and compliance planning, backed by managed IT services built for compliance-heavy environments. For the broader ITAR picture, see our guide to ITAR requirements and cybersecurity. 

👉 Schedule a free consultation with our team to talk through how deemed export rules actually apply to your hiring and IT provisioning. 

Related Topic:

FAQs

What is the deemed export rule?

The deemed export rule treats releasing controlled technology to foreign nationals within America as exports to their associated countries.

What are the requirements for a deemed export license?

Employers must obtain required deemed export licenses before granting foreign persons access to controlled technology based on applicable classifications.

What is a deemed export under ITAR regulations?

ITAR treats sharing controlled technical data with foreign persons through discussions, viewing, or system access as regulated exports requiring authorization.

Do universities and research institutions have different deemed export rules?

Universities may use the Fundamental Research Exclusion for qualifying public research, but export controls can still restrict other activities.

Our Blog

Deemed Export Compliance and Technical Data

Deemed Export Compliance and Technical Data

A deemed export happens when controlled technology or technical data is released to a…

ITAR vs EAR: Which Rules Apply to You?

ITAR vs EAR: Which Rules Apply to You?

 ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) are two separate…

How Manufacturers Can Strengthen Operational Technology Security

How Manufacturers Can Strengthen Operational Technology Security

Operational technology (OT) security means protecting the systems that actually run your production floor…