Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · EU

EU vs SECO: Deemed exports and technology transfer: the key divergences

A Swiss-based technology group licences proprietary software to its EU subsidiary, then seconds an engineer from a non-EEA country to work on the code in Munich. Two regulators may have a view. The EU dual-use rules ask whether a controlled technology has been transferred to a non-authorised recipient inside the Union. SECO, Switzerland's State Secretariat for Economic Affairs, asks whether the same transfer triggers obligations under the Swiss export-control ordinances. The answers are not the same – and the gap between them decides how the group structures its secondment, its IT access policy, and its technology-transfer documentation.

As of April 2026, the EU and Switzerland both apply export controls to deemed exports and technology transfers, but they diverge materially on how a "deemed export" is defined, which transfers require a prior authorisation, how the nationality of the recipient triggers control, and what the licensing routes look like. Under the EU rules, technology transfer to a non-EU-authorised recipient can constitute a controlled export regardless of whether the technology physically crosses a border. SECO applies a comparable concept, but the trigger conditions, the control-list architecture, and the authorisation mechanisms differ in ways that create practical compliance gaps for businesses operating across both regimes.

This analysis maps those divergences criterion by criterion, identifies where the regimes converge and where they do not, and sets out the practical steps a cross-border business should take before the next secondment, joint-development agreement, or cloud-based knowledge-sharing arrangement is signed.

What is a "deemed export" and how do the EU and SECO each define it?

A deemed export occurs when a controlled technology is released to a foreign national within a jurisdiction, treating that release as if the technology had been exported to the person's country of origin or allegiance. Neither the EU nor Switzerland uses the term "deemed export" in exactly the way US rules do, but both regimes capture the same economic reality through their definitions of "technology transfer" and "technical assistance."

Under the EU dual-use rules – principally the Council Regulation on controls over exports, brokering, technical assistance, and transit of dual-use items – technology transfer is defined broadly. It encompasses the oral transmission of knowledge, written communications, electronic exchanges, and the making available of controlled technology to persons established outside the EU or to non-EU nationals operating inside the EU. The transmission of software by electronic means across a border is equally caught. The practical result is that a French engineer explaining a controlled manufacturing parameter to a non-EU colleague over a video call may fall within scope, even if no document is exchanged and the colleague is physically present in France.

SECO's regime, grounded in the Swiss Goods Control Act and the implementing ordinances, takes a functionally similar approach. Technology transfer is controlled where it involves items on the Swiss Dual-Use Goods Control List. The nationality dimension is present but operationally weighted differently: Swiss rules focus more directly on the destination country of the transfer rather than on a pure nationality trigger for individuals. This distinction matters. An EU business running a joint-development programme with Swiss partners may face a SECO authorisation requirement calibrated to the end-destination of the knowledge flow rather than the passport of the individual receiving a document in Zürich.

The divergence here is not merely terminological. It has direct consequences for how a business maps its technology flows, which transfers it flags for pre-clearance, and how it designs its internal export-compliance programme.

How do the control-list architectures compare?

Both regimes draw on the Wassenaar Arrangement, the Nuclear Suppliers Group, and other multilateral export-control regimes for their core control-list content, but the manner in which each translates those international commitments into national law differs – and the gaps are operationally significant.

The EU Dual-Use Regulation incorporates the Wassenaar Control List directly into its annex, which is updated periodically through amending regulations. The list is common to all EU Member States. A technology that is controlled in Germany is equally controlled in Austria, the Netherlands, and Sweden; there is a single licensing authority architecture, even if individual Member States issue licences through their own competent authorities. For a multinational with subsidiaries across the EU, this creates administrative efficiency but does not eliminate risk: different Member State authorities interpret borderline classification questions with varying degrees of strictness, and the categorisation of emerging technologies such as certain artificial intelligence tools and advanced semiconductor design software remains unsettled.

Switzerland maintains its own dual-use control list, which is broadly aligned with Wassenaar but is not identical to the EU annex. SECO reviews and updates the list through its own regulatory cycle. In our experience advising on cross-border technology licensing, the most acute gaps appear in two areas: first, certain software tools that fall within EU catch-all provisions but sit outside the current Swiss list; second, items in the nuclear and missile-related categories where Switzerland's status as a non-EU member means it is not bound by EU regulations tightening controls in response to specific proliferation concerns.

What does this mean in practice? A company transferring technology that is controlled under the EU regime but not currently listed under the Swiss ordinances faces a risk of asymmetric compliance: over-controlled on the EU side, under-flagged on the Swiss side. The stricter prohibition governs in each jurisdiction, but businesses sometimes mistakenly assume alignment where none exists.

Where do the regimes diverge on authorisation and licensing routes?

The EU offers a tiered authorisation structure: Union General Export Authorisations cover certain lower-risk transfers to defined destination countries; national general authorisations are issued by Member State authorities for recurring, lower-risk technology transfers; and individual licences are required for transfers that fall outside the general authorisation scope or that involve higher-risk destinations or recipients. The EU Dual-Use Regulation also introduced an enhanced catch-all mechanism for transfers to destinations where there are grounds to suspect end-use concerns, even where the item is not otherwise listed.

SECO operates through a different architecture. Switzerland's general authorisation mechanism – the General Export Authorisation (GEA) system – allows qualifying exporters to make multiple transfers under a single authorisation for defined item categories and destinations. The GEA reduces administrative burden for established, trusted exporters but requires the exporter to have adequate internal compliance controls in place. Individual applications to SECO are required for transfers outside GEA scope. SECO also has an extraordinary-measures power that allows it to impose controls on items not otherwise listed where national-security or foreign-policy grounds exist.

The divergence is sharpest for technology transfers to certain countries. The EU's catch-all mechanism can be triggered by intelligence assessments at the Member State level, meaning a transfer that appears to fall outside the list may still require a licence. SECO's extraordinary-measures power achieves a broadly similar result, but the trigger threshold and the procedural pathway differ. A business that has obtained an EU licence for a technology transfer cannot assume SECO concurrence, and vice versa.

The position above covers the standard licensing scenario. Your facts – the technology, the recipient's nationality, the destination, and the route of transfer – change the analysis. For an assessment of your exposure under the EU or Swiss regime, contact Calder & Vance at info@caldervance.com.

Does nationality of the recipient trigger control differently under each regime?

This is one of the most practically consequential divergences between the two regimes, and it is the question that generates the most uncertainty in cross-border secondment, joint-research, and cloud-access scenarios.

Under the EU Dual-Use Regulation, technology transfer to a non-EU national present within the EU can constitute an export to that person's country, depending on the specific technology, the mode of transfer, and whether the person is acting in a professional capacity that implies onward transfer. The regulation does not set out a single bright-line rule. Instead, it uses the concept of "making available" to a person outside the EU or to a non-EU national within the EU, which requires a case-by-case assessment. EU Member State competent authorities have issued varying guidance on this point. Some apply a stricter reading that would capture any controlled-technology access by a non-EU national; others focus more narrowly on actual transmission of the technology.

Switzerland's approach is destination-focused rather than nationality-focused as a primary trigger. The operative question under SECO's ordinances is typically where the technology is ultimately going and whether that destination is subject to restrictions. The nationality of an individual receiving a document in Switzerland is relevant context but does not automatically constitute a transfer to that individual's country of nationality in the way US rules treat the matter. This creates a gap: a technology-sharing arrangement within a multinational group that the EU regime treats as a transfer requiring authorisation may not trigger a SECO requirement on the same facts.

In our cross-border practice, we regularly advise on exactly this asymmetry. The risk for a business with EU and Swiss operations is that it calibrates its compliance controls to the more familiar regime – often whichever jurisdiction houses the compliance team – and under-flags transfers that fall squarely within the other regime's scope. Have you mapped your technology flows against both regimes' nationality and destination triggers, not just one?

What are the key risk flags for cross-border businesses?

Cross-border technology transfer generates a predictable set of compliance failures. Identifying them before they produce a regulatory exposure is the core function of a well-designed internal control programme.

The first risk flag is misclassification at source. Both the EU and Swiss regimes require the exporter to determine the classification of the technology before transfer. A business that applies only the EU control list to a technology that also appears on the Swiss list – or that assumes alignment where the lists diverge – is exposed to an undetected breach on the Swiss side. Classification should be conducted against both lists where the transfer crosses the EU-Switzerland border or involves Swiss-connected parties.

The second risk flag is the assumption that intangible transfers are lower risk. The oral briefing in a meeting room, the technical annex shared over an encrypted channel, the code repository access granted to a contractor – all of these constitute technology transfer under both regimes. Internal IT policies that allow non-EU or non-Swiss nationals unrestricted access to controlled-technology repositories are a recurring source of compliance failures we observe when reviewing existing programmes.

The third risk flag is the gap between group-level policy and entity-level execution. A parent company in Geneva may have a SECO-calibrated export-compliance programme. Its EU subsidiary in Amsterdam operates under EU rules. Where the group-level programme does not map the subsidiary's obligations under the EU Dual-Use Regulation, the subsidiary's technology transfers – including internal transfers from parent to subsidiary – may be uncontrolled. We have acted for groups where this exact gap produced a reportable breach.

A fourth risk flag is the interaction with sanctions controls. Technology transfer restrictions under export-control regimes operate alongside, and independently from, financial sanctions. A transfer that is permissible under export-control licensing rules may still be caught by a separate financial-sanctions prohibition, or by a catch-all clause triggered by end-use concerns. Both the EU dual-use catch-all and SECO's extraordinary-measures power can apply even where no formal financial-sanctions designation is in place. Businesses that treat export controls and sanctions as entirely separate compliance workstreams are exposed to gaps in exactly these overlap scenarios.

If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment.

How does the EU Blocking Regulation interact with SECO's position?

The EU Blocking Regulation creates an additional layer that is largely absent from Switzerland's export-control architecture. The EU Blocking Regulation – formally the EU instrument prohibiting compliance with specified extraterritorial laws – restricts EU persons from complying with certain extraterritorial measures imposed by third countries, particularly where those measures seek to restrict trade or technology transfer in ways the EU considers contrary to its interests.

For businesses managing technology transfers across the EU-Switzerland corridor, the Blocking Regulation adds a potential conflict-of-laws dimension. A Swiss-based parent receiving instruction from a third-country group policy that imposes extraterritorial controls on technology transfer may find that its EU subsidiary is prohibited by EU law from complying with the same group instruction. Switzerland has no equivalent instrument. Swiss entities are not bound by the EU Blocking Regulation and may, in principle, comply with third-country extraterritorial measures without the EU-law complications that would arise if the same compliance were required from an EU affiliate.

This divergence creates a specific risk for multinational groups that implement centralised technology-access controls in response to third-country regulatory pressure. The group policy that satisfies SECO and the third-country regulator may put the EU entity in breach of the Blocking Regulation. Conversely, the EU entity's non-compliance with the group policy – mandated by EU law – may create exposure under the third-country regime. We regularly advise on this three-way conflict. It requires careful structuring of technology-access arrangements, entity-level documentation of the legal basis for each compliance decision, and in some cases separate advice from local counsel in the relevant jurisdiction.

What practical steps should a business take before the next technology transfer?

The analysis above identifies where the EU and SECO regimes diverge. The practical question is what a business should do with that information. The answer is a sequenced set of steps, each of which builds on the last.

The first step is a dual-list classification review. Every technology that a business transfers – whether as software, technical documentation, oral disclosure, or cloud-accessible data – should be classified against both the EU control list annex and the Swiss Dual-Use Goods Control List. Where the lists diverge, the stricter control governs in each jurisdiction. This classification exercise should be conducted by qualified personnel and documented in a record that can be produced to a regulator on request.

The second step is a mapping of technology flows against regime triggers. For EU-controlled transfers, this means identifying every transfer of controlled technology to a non-EU national or to a location outside the EU, including internal transfers within a multinational group. For SECO-controlled transfers, the mapping focuses on destination and end-use, with additional attention to the nationality dimension in borderline cases.

The third step is an authorisation gap analysis. Once the classification and flow-mapping are complete, the business can identify which transfers require a prior authorisation, which fall within a general authorisation, and which are uncontrolled. Transfers in the first category need a licence application before they proceed. Transfers in the second category need documentation of the applicable general authorisation. Transfers in the third category need to be documented as uncontrolled to provide an audit trail.

The fourth step is programme design. A compliance programme that adequately covers deemed exports and technology transfer under both regimes needs clear policies on IT access for non-nationals, a secondment protocol that integrates export-control checks, a process for reviewing joint-development and licensing agreements before signature, and a training programme for personnel who handle controlled technology. In our experience, the training component is the most consistently underdeveloped – particularly for technical staff who do not recognise that their day-to-day knowledge-sharing constitutes a regulated activity.

The fifth step is periodic review. Both the EU control list and the Swiss list change. New entries, new general authorisations, and new catch-all guidance are issued on a regular cycle. A compliance programme that was accurate at implementation may be materially out of date within twelve to eighteen months without a structured review process.

Is your technology-transfer compliance programme mapped to both the EU and SECO regimes, or only to the jurisdiction where your headquarters sits?

Related practices

Frequently asked questions: deemed exports and technology transfer, EU vs SECO

Where do the regimes diverge on deemed exports and technology transfer?

The EU and SECO diverge on four principal points: the definition and trigger for a deemed export (nationality-led under EU rules versus destination-led under Swiss rules); the control-list architecture (a single EU annex versus a separate Swiss list not fully aligned with the EU version); the authorisation mechanisms (EU general and individual licences versus SECO's General Export Authorisation system and individual SECO applications); and the interaction with the EU Blocking Regulation, which has no Swiss equivalent. A transfer that requires an EU licence may not require a SECO authorisation on the same facts, and vice versa. Operating under the assumption of alignment between the two regimes is a consistent source of compliance gaps.

Which regime is stricter on deemed exports and technology transfer?

Neither regime is uniformly stricter. The EU regime is broader in its nationality trigger: making controlled technology available to a non-EU national within the EU can constitute a transfer requiring authorisation, regardless of physical movement. SECO's regime applies a destination-focused analysis that may not capture the same fact pattern. Conversely, SECO's extraordinary-measures power can apply controls outside the standard list where national-security grounds exist, creating exposure for items that the EU catch-all does not currently reach. In practice, the stricter regime depends on the specific technology, the recipient, and the transfer route. A dual-regime classification and authorisation review is the only reliable way to identify where each regime bites harder on a given set of facts. Compliance counsel should conduct this analysis before the transfer is made, not after a regulator queries it.

What should a cross-border business do about deemed exports and technology transfer?

A cross-border business operating across the EU and Switzerland should take five steps: conduct a dual-list classification review against both the EU control list annex and the Swiss Dual-Use Goods Control List; map all technology flows against each regime's trigger conditions; carry out an authorisation gap analysis to identify which transfers require a prior licence; build or update a compliance programme that addresses IT access for non-nationals, secondment protocols, and joint-development agreement review; and establish a periodic review process to capture list and guidance changes. Businesses that have not conducted a dual-regime review recently should treat that as an immediate priority. Where a transfer has already occurred without the required authorisation, specialist export-control counsel should be instructed promptly to assess whether a voluntary disclosure to the relevant authority is appropriate.

About the author

Claire Dubois advises on EU sanctions and export controls, including Council-regulation analysis, dual-use classification questions, ownership-and-control analysis under the EU rules, and annulment actions before the EU General Court. She regularly advises multinationals, technology companies, and financial institutions on cross-border technology transfer compliance across the major EU-linked regimes. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.