Export-Controlled Information

Overview

Export-controlled information may include technical data, technology, software, source code, and other information subject to U.S. export control regulations. Depending on the applicable regulations, restrictions may apply to releasing the information to foreign persons, transferring it internationally, or using it for certain activities.

Research involving export-controlled information may require administrative, physical, and technical safeguards to prevent unauthorized access, use, disclosure, or transfer.

The Office of Research Security (ORS) assists researchers in identifying export-controlled information, determining applicable regulatory requirements, and implementing appropriate safeguards.

CONTACT ORS


What Is Export-Controlled Information?

Export-controlled information may include:

  • Technical data
  • Controlled technology
  • Engineering drawings
  • Design information
  • Software and source code
  • Manufacturing processes
  • Defense-related technical information
  • Technical documentation
  • Other information subject to the Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR), or other federal export control regulations

Whether information is export controlled depends on the applicable regulations, the nature and classification of the information, and the circumstances of the research activity.

Information resulting from qualifying fundamental research or information that is publicly available may be excluded from certain export control requirements. However, these exclusions do not necessarily apply to proprietary, sponsor-provided, government-provided, or other third-party information used in a research project.


Applicable Regulations

Export-controlled information may be regulated under one or more U.S. export control regulations.

Regulation Description
Export Administration Regulations (EAR) Regulate commercial, dual-use, and certain less-sensitive military items, technology, and software.
International Traffic in Arms Regulations (ITAR) Regulate defense articles, defense services, and related technical data identified on the U.S. Munitions List.
Department of Energy Regulations Regulate certain nuclear technology, technical information, and activities involving Department of Energy-controlled technologies.

How Researchers May Receive Export-Controlled Information

Researchers may receive export-controlled information from a variety of sources, including industry partners, federal agencies, federal contractors, collaborators, and other third parties.

Industry Partners

Industry-sponsored research, Non-Disclosure Agreements (NDAs), Confidential Disclosure Agreements (CDAs), proprietary research agreements, and other contractual arrangements may involve the transfer of technical or proprietary information.

Technical or proprietary information is not automatically export controlled. ORS can assist in determining whether information provided under an agreement is subject to export control regulations and whether additional safeguards are required.

ORS works with Intellectual Property Partners (IPP), the Office of Sponsored Programs, and other appropriate University offices to identify applicable requirements.

Federal Agencies or Federal Contractors

Researchers conducting research for the Federal Government or participating in projects with federal contractors may receive export-controlled information.

Depending on the project, export-controlled information may also constitute Controlled Unclassified Information (CUI), Government Information, or information subject to additional sponsor or contractual safeguarding requirements.

Export control and CUI requirements are distinct. Information may be subject to one or both frameworks depending on the applicable federal requirements.


Protecting Export-Controlled Information

Research involving export-controlled information may require safeguards appropriate to the applicable regulations and project requirements.

Depending on the research activity, safeguards may include:

  • Access limited to authorized personnel.
  • Technology Control Plans (TCPs).
  • Secure storage of research information.
  • Appropriate research cybersecurity safeguards.
  • Physical security measures.
  • Restrictions on access, dissemination, or international transfer.
  • Export licenses or other government authorizations, when required.
  • Training or other project-specific compliance requirements.

The required safeguards depend on the applicable regulations, classification of the information, individuals requiring access, and specific research activity.

Researchers should not receive, store, access, or share export-controlled information until applicable requirements have been identified and appropriate safeguards are in place.


Technology Control Plans

A Technology Control Plan (TCP) establishes project-specific administrative, physical, and technical safeguards to prevent unauthorized access to export-controlled equipment, materials, software, technology, technical information, or other controlled items.

When required, ORS develops Technology Control Plans in collaboration with researchers and the appropriate University offices.

tablishes the administrative, physical, and technical safeguards necessary to prevent unauthorized access to export-controlled information.

When required, ORS develops Technology Control Plans in collaboration with researchers and the appropriate University offices.


When Should I Contact ORS?

Contact the Office of Research Security before:

  • Receiving information identified as export controlled.
  • Entering into an agreement involving controlled technical information or technology.
  • Receiving export-controlled information from a federal agency, contractor, sponsor, collaborator, or other third party.
  • Sharing export-controlled information with collaborators or other individuals.
  • Providing foreign persons access to export-controlled information.
  • Storing or processing export-controlled information in a research computing environment.
  • Transferring export-controlled information internationally.
  • Traveling internationally with export-controlled information.
  • Whenever you are uncertain whether information is subject to export control requirements.

Related Guidance

Researchers working with export-controlled information should also review:

Reference Guide Description
Government Information Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply.
Controlled Unclassified Information (CUI) Learn about federal safeguarding requirements applicable to Controlled Unclassified Information used in research.
Research Information Protection Learn how administrative, physical, and technical safeguards are identified and applied to protect research information.
Research Cybersecurity Baseline Review baseline cybersecurity practices that support University research activities.

Need Assistance?

If you believe your research may involve export-controlled information or you are uncertain whether export control regulations apply, contact the Office of Research Security before receiving, accessing, storing, processing, sharing, or transferring the information.

ORS will assist in identifying applicable export control requirements, determining appropriate safeguards, and developing Technology Control Plans or other project-specific measures when required.

CONTACT ors