Export-Controlled Information
Overview
Export-controlled information may include technical data, technology, software, source code, and other information subject to U.S. export control regulations. Depending on the applicable regulations, restrictions may apply to releasing the information to foreign persons, transferring it internationally, or using it for certain activities.
Research involving export-controlled information may require administrative, physical, and technical safeguards to prevent unauthorized access, use, disclosure, or transfer.
The Office of Research Security (ORS) assists researchers in identifying export-controlled information, determining applicable regulatory requirements, establishing project-specific export control safeguards when required, and coordinating with the appropriate University offices to support implementation.
What Is Export-Controlled Information?
Export-controlled information may include:
- Technical data
- Controlled technology
- Engineering drawings
- Design information
- Software and source code
- Manufacturing processes
- Defense-related technical information
- Technical documentation
- Other information subject to the Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR), or other federal export control regulations
Whether information is export controlled depends on the applicable regulations, the nature and classification of the information, and the circumstances of the research activity.
Information resulting from qualifying fundamental research or information that is publicly available may be excluded from certain export control requirements. However, these exclusions do not necessarily apply to proprietary, sponsor-provided, government-provided, or other third-party information used in a research project.
Applicable Regulations
Export-controlled information may be regulated under one or more U.S. export control regulations.
| Regulation | Description |
|---|---|
| Export Administration Regulations (EAR) | Regulate commercial, dual-use, and certain less-sensitive military items, technology, and software. |
| International Traffic in Arms Regulations (ITAR) | Regulate defense articles, defense services, and related technical data identified on the U.S. Munitions List. |
| Department of Energy Regulations | Regulate certain nuclear technology, technical information, and activities involving Department of Energy-controlled technologies. |
How Researchers May Receive Export-Controlled Information
Researchers may receive export-controlled information from a variety of sources, including industry partners, federal agencies, federal contractors, collaborators, and other third parties.
Industry Partners
Industry-sponsored research, Non-Disclosure Agreements (NDAs), Confidential Disclosure Agreements (CDAs), proprietary research agreements, and other contractual arrangements may involve the transfer of technical or proprietary information.
Technical or proprietary information is not automatically export controlled. ORS can assist in determining whether information provided under an agreement is subject to export control regulations and whether additional safeguards are required.
ORS works with Intellectual Property Partners (IPP), the Office of Sponsored Programs, and other appropriate University offices to identify applicable requirements.
Federal Agencies or Federal Contractors
Researchers conducting research for the Federal Government or participating in projects with federal contractors may receive export-controlled information.
Depending on the project, export-controlled information may also constitute Controlled Unclassified Information (CUI), Government Information, or information subject to additional sponsor or contractual safeguarding requirements.
Export control and CUI requirements are distinct. Information may be subject to one or both frameworks depending on the applicable federal requirements.
Protecting Export-Controlled Information
Research involving export-controlled information may require safeguards appropriate to the applicable regulations and project requirements.
Depending on the research activity, safeguards may include:
- Access limited to authorized personnel.
- Technology Control Plans (TCPs).
- Secure storage, processing, and transmission of export-controlled information, as required.
- Appropriate research cybersecurity safeguards.
- Physical security measures.
- Restrictions on access, dissemination, or international transfer.
- Export licenses or other government authorizations, when required.
- Training or other project-specific compliance requirements.
The required safeguards depend on the applicable regulations, classification of the information, individuals requiring access, and specific research activity.
Researchers should not receive, access, store, process, share, or transfer export-controlled information until the applicable requirements have been identified and required safeguards are in place.
When computing, storage, cybersecurity, or other technical safeguards are required, ORS coordinates with the appropriate University technology offices to support implementation.
Technology Control Plans
A Technology Control Plan (TCP) establishes project-specific administrative, physical, and technical safeguards to prevent unauthorized access to export-controlled equipment, materials, software, technology, technical information, or other controlled research assets.
When required, ORS develops and administers Technology Control Plans in collaboration with the Principal Investigator and appropriate University offices. The TCP identifies authorized personnel, applicable access restrictions, information protection requirements, physical and technical safeguards, training requirements, and other controls necessary to comply with applicable export control requirements.
Researchers and other personnel covered by a TCP are responsible for following the controls and procedures established for the project.
Learn More about Technology Control Plans
When Should I Contact ORS?
Contact the Office of Research Security before:
- Receiving export-controlled information, technical data, technology, software, or source code from a sponsor, federal agency, contractor, collaborator, company, or other third party.
- Entering into an agreement involving export-controlled information or technology.
- Providing a foreign person with access to export-controlled technical data, technology, software, source code, or other controlled information.
- Sharing export-controlled information with collaborators or other individuals.
- Storing or processing export-controlled information using University computing or storage resources.
- Transferring export-controlled information internationally, including by electronic transmission.
- Traveling internationally with export-controlled information.
- Making a commitment involving access to, use of, or protection of export-controlled information when you are uncertain whether the University can meet the applicable requirements.
- Whenever you are uncertain whether information is subject to export control requirements.
Related Guidance
Researchers working with export-controlled information should also review:
| Reference Guide | Description |
|---|---|
| Research Information Classification | Learn how the University information classification framework and applicable sponsor, contractual, regulatory, export control, privacy, data access, and other requirements help determine the appropriate classification and protection of research information. |
| Government Information | Learn about government information that may be encountered in research and the safeguarding, cybersecurity, and contractual requirements that may apply. |
| Controlled Unclassified Information (CUI) | Learn about federal safeguarding requirements applicable to Controlled Unclassified Information used in research. |
| Research Information Protection | Learn how administrative, physical, and technical safeguards are identified and applied to protect research information. |
| Research Cybersecurity Baseline | Review baseline cybersecurity practices that support University research activities. |
| Secure Research Computing | Guidance for research requiring specialized computing, storage, access controls, or other project-specific cybersecurity safeguards. |
Need Assistance?
If you believe your research may involve export-controlled information or you are uncertain whether export control regulations apply, contact the Office of Research Security before receiving, accessing, storing, processing, sharing, or transferring the information.
ORS will assist in identifying applicable export control requirements, establishing required export control safeguards, developing and administering Technology Control Plans when required, and coordinating with the appropriate University offices when computing, storage, cybersecurity, physical security, or other implementation support is needed.