Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFAC

OFAC vs Canada: Deemed exports and technology transfer compared

A technology company with offices in Toronto and San Francisco is recruiting a software engineer who holds citizenship in a country subject to US sanctions controls. The hiring manager wants to know whether sharing the company's encryption source code with that employee — in a routine product briefing — triggers an export-control licence requirement. The question is not hypothetical. Two distinct regulatory regimes, operating on different legal bases, may each apply to the same moment of disclosure. Getting the analysis wrong exposes the firm to enforcement action on both sides of the border.

The concept of a deemed export (the legal fiction that releasing controlled technology to a foreign national within your own country constitutes an export to that person's country of nationality) is recognised under both the US Export Administration Regulations administered by the Bureau of Industry and Security and Canada's export-control regime administered by Global Affairs Canada. The two regimes share the same foundational logic but diverge sharply on scope, classification methodology, nationality-screening obligations, and the licensing routes available to employers. As of April 2026, businesses operating across both jurisdictions must satisfy both sets of controls simultaneously; the stricter prohibition governs any given act of disclosure.

This analysis compares the deemed-export rules under the US EAR and Canada's applicable export-control instrument, identifies the points of practical divergence, and maps the risk flags that cross-border employers and technology companies must manage before any controlled disclosure.

What is a deemed export under the US EAR, and who administers it?

A deemed export under the US EAR occurs when technology or source code subject to the Commerce Control List is released to a foreign national inside the United States, treating that release as an export to the foreign national's country or countries of nationality. The Bureau of Industry and Security administers the EAR under authority delegated through the Export Control Reform Act. BIS enforces the deemed-export rule as a first-order obligation, not an administrative technicality.

The classification of the technology is the starting point. Each item on the Commerce Control List carries an Export Control Classification Number (ECCN — the alphanumeric identifier that determines which countries and end-uses require a licence). If the ECCN and the destination country combination triggers a licence requirement on a physical export, the same requirement generally applies to a deemed export of the same technology to a national of that country. Where an item is designated EAR99 — outside any specific ECCN — a deemed-export licence is typically not required, though end-use and end-user controls still apply.

The deemed-export analysis is therefore a two-stage inquiry: classify the technology, then assess the nationality of every person who will receive it. Neither stage is optional. In our experience, firms frequently complete one stage and assume the other is clear. That assumption fails when the technology has been recently reclassified, or when an employee holds dual or multiple nationalities.

Dual nationality creates a specific complication. BIS treats a foreign national who holds both a third-country nationality and another nationality as a national of each country, not the most benign one. A Canadian citizen who also holds nationality in a country subject to US licence requirements does not benefit from a Canada exemption. The more restrictive nationality controls the analysis.

How does Canada's export-control regime define and apply the deemed-export concept?

Canada's export-control regime, administered by Global Affairs Canada under the applicable national legislation, applies a parallel but not identical deemed-export concept. The Canadian rules treat the release of controlled technology, software, or source code to a foreign national within Canada as a deemed export to that person's home country, subject to Canada's Export Control List and the Group of Countries lists that determine licence requirements.

The Group of Countries lists are central to the Canadian analysis. They function similarly to BIS's country-chart matrix — a controlled technology released to a national of a country on a restricted list requires a permit from Global Affairs Canada, regardless of whether the disclosure occurs in Canada or abroad. However, the Canadian list structure differs from the US country chart, and the two do not map neatly onto each other. A country that falls within a US licence exception may still require a Canadian permit, and vice versa.

Canada's deemed-export assessment also begins with classification, but the Canadian control list — based on the Wassenaar Arrangement, the Nuclear Suppliers Group, and other multilateral export-control regimes — uses control parameters that largely track international standards. That alignment with Wassenaar means the Canadian and US control parameters often overlap, particularly for dual-use goods and technology. But the national implementation of those parameters differs in the categories of persons whose nationalities trigger scrutiny and in the exceptions available to academic institutions and research bodies.

One area where Canada's rules diverge meaningfully is the treatment of permanent residents. Under the Canadian regime, a permanent resident of Canada who is a national of a restricted country may still trigger a deemed-export licence requirement when receiving controlled technology. The Canadian rules do not automatically exempt permanent residents on the basis of their status in Canada. BIS takes a comparable position for US permanent residents who are nationals of countries subject to US controls. That parallel is important for cross-border employers who rotate staff between the two countries.

Where do the regimes diverge on deemed exports and technology transfer?

The most consequential divergence between the US and Canadian deemed-export rules lies in the interaction between nationality screening and the available licence exceptions. Under the EAR, certain licence exceptions — including provisions that cover releases to nationals of countries with which the United States maintains close export-control cooperation — can reduce or eliminate the licence burden for specific categories of controlled technology. Canada maintains its own equivalent provisions, but the countries covered and the technology categories exempted do not map one-for-one onto the US exceptions.

A second divergence concerns the treatment of technology developed jointly or under collaborative research arrangements. Both regimes address intra-company transfers and research collaborations, but the threshold for triggering a licence requirement differs. Under the EAR, the release of technology in the context of a fundamental research exclusion — where results are ordinarily published and shared broadly — can remove the licence requirement entirely for certain academic settings. Canada's research exemption is structured differently and applies a distinct set of qualifying conditions. A cross-border research consortium cannot assume that a US fundamental-research determination automatically satisfies Canadian requirements.

Third, the enforcement posture of the two regimes diverges. BIS maintains a formal voluntary self-disclosure programme — a VSD (a mechanism allowing a party that has identified an apparent violation to report it proactively, which BIS considers a significant mitigating factor in penalty calculations) — with documented treatment as a mitigating factor. Global Affairs Canada has its own enforcement approach, but the mechanics of voluntary reporting and the credit accorded to it differ from the BIS process. A firm that has made a cross-border deemed-export error cannot assume that a VSD filed with BIS satisfies any reporting obligation or creates equivalent mitigation credit in Canada.

Finally, the two regimes use different record-keeping periods and documentation standards. Verify the current position under each regime before relying on any specific deadline, but it is safe to say that maintaining documentation under both sets of rules simultaneously is the minimum standard for a cross-border employer operating in this space. We regularly advise firms that discover, during due diligence, that a target company has maintained records to one standard only — leaving a gap that creates enforcement exposure in the other jurisdiction.

Which regime is stricter on deemed exports and technology transfer?

Neither regime is uniformly stricter than the other; the answer depends on the specific technology, the nationality of the person receiving it, and the context of the disclosure. For US-origin technology controlled under a high-tier ECCN — particularly items with significant military, nuclear, or intelligence applications — the EAR will almost invariably impose the more demanding licence requirement, reflecting the depth and reach of the US control regime. For technology that has a Canadian-origin component but falls outside the higher tiers of the US control list, the Canadian regime may impose the heavier burden, particularly where the receiving national's country is on a Canadian restricted list but benefits from a US licence exception.

The practical answer for a cross-border business is that the stricter prohibition governs at every point of disclosure. That means the compliance programme must be designed to the higher of the two standards for each category of technology and each category of personnel. Running a single-jurisdiction analysis — satisfying BIS and assuming Canada is covered, or satisfying Global Affairs Canada and assuming the EAR is addressed — is not a defensible position when both regimes independently apply to the same disclosure.

Is your screening programme identifying every nationality-trigger, or only the obvious ones? In our cross-border practice, the most common failure mode is not a deliberate decision to skip the analysis but an assumption — embedded in HR processes built around one jurisdiction — that a single screening layer is sufficient. That assumption is wrong where both regimes apply.

There is also an interaction with OFAC sanctions that must not be overlooked. OFAC sanctions (restrictions imposed by the US Treasury's Office of Foreign Assets Control on transactions involving designated persons or countries) are a separate and parallel legal layer. A technology disclosure to a foreign national who is also a Specially Designated National (a person listed on OFAC's SDN List as blocked) triggers not only an EAR deemed-export analysis but also a potential OFAC violation. The SDN overlay is nationality-agnostic; it turns on the individual's designation status. Canada maintains its own list of prohibited persons through the Regulations Implementing the United Nations Resolutions on the Suppression of Terrorism and related instruments, and those lists do not always replicate the OFAC SDN List in full or in real time. A person who is listed by OFAC may not yet appear on the equivalent Canadian list, and vice versa.

Risk flags and the decision sequence for cross-border employers

The risk profile for a cross-border employer managing deemed-export obligations under both the EAR and Canada's regime is shaped by four recurring failure patterns. Recognising them early — ideally before a hire or a disclosure occurs — is the minimum standard of care.

Failure to classify is the most common. Many technology companies have never formally classified their core technology under either the US Commerce Control List or the Canadian Export Control List. They assume that because their product is commercial and widely available, it falls outside any control. That assumption is frequently wrong for items with dual-use applications — encryption, certain sensors, advanced materials, and specific software categories appear on both control lists at parameters that catch products many firms assume are uncontrolled.

Incomplete nationality data is the second pattern. HR systems typically capture one nationality per employee, the passport submitted at the time of hiring. Where an employee holds a second nationality, particularly one that triggers a licence requirement, the system does not surface the risk. The compliance obligation runs to the actual nationality of the person, not the nationality the employer has on file.

Unreviewed technology transfers within corporate groups present a third risk. A parent company in the United States that shares a technical data package with its Canadian subsidiary, or vice versa, is making a deemed export — or a real export — that triggers licence analysis. Intra-group transfers are not exempt from either regime by virtue of common ownership alone. A deemed-export licence or permit may be required even within the corporate family.

Inadequate VSD planning is the fourth. When a deemed-export violation is discovered, the window for beneficial self-disclosure is short. Acting without a pre-existing process — who decides to disclose, to which regulator, on what timeline, with what documentation — produces delays that reduce or eliminate the mitigating credit available. Both the US and Canadian enforcement regimes recognise proactive disclosure; neither rewards delay.

The position above covers the standard analysis. Your facts — the specific technology, the nationals involved, the disclosure setting, the presence or absence of a classified product, and the regime status of the nationalities in question — change the outcome materially.

For a preliminary assessment of your deemed-export exposure under both the EAR and Canada's regime, contact Calder & Vance at info@caldervance.com.

How a cross-border deemed-export licence application works in practice

Where the analysis confirms that a deemed-export licence is required — under the EAR, under Canada's regime, or both — the employer must apply before the disclosure occurs. A retroactive licence is not available. This is a hard procedural constraint that surprises firms accustomed to other regulatory processes where after-the-fact authorisation is possible.

Under the EAR, a deemed-export licence application to BIS follows the same procedural path as a standard export licence application, submitted through the relevant agency portal. The application identifies the technology by ECCN, the receiving foreign national by nationality, and the proposed disclosure activity in sufficient detail for BIS to assess the application against its licensing criteria. BIS may impose conditions on any licence it grants — restrictions on the categories of technology the licence covers, record-keeping requirements, and reporting obligations.

Under the Canadian regime, the permit application to Global Affairs Canada follows Canada's standard export permit process. The supporting documentation requirements differ from those BIS expects, and the processing timeline — while generally comparable in order of magnitude for straightforward applications — is subject to its own review cycle. A firm that has filed with BIS cannot assume that the Canadian permit will follow automatically or on the same timeline.

We have acted for technology companies managing parallel BIS and Global Affairs Canada applications for the same disclosure context. The key lesson from those matters is that the applications must be planned in sequence — or, where timelines allow, in parallel — with the same underlying facts documented to satisfy both sets of evidentiary requirements. Preparing the BIS application first and then adapting it for Canada wastes time and typically requires material additions to satisfy the Canadian documentation standard.

If a transaction has already been flagged — a disclosure has occurred without a required licence — an early review can preserve options that narrow with time. The VSD analysis must be conducted before any regulatory contact occurs.

For confidential advice on a pending or retrospective deemed-export situation, write to info@caldervance.com.

The OFAC dimension: secondary-sanctions risk and cross-border screening

The deemed-export analysis under the EAR is export-control law. But it sits alongside — and sometimes intersects with — the OFAC sanctions layer, and the two must not be conflated. A firm managing a deemed-export programme solely through its export-control compliance team, without input from its sanctions-screening function, creates a gap that OFAC enforcement action can reach through.

The SDN overlay is the clearest intersection point. A foreign national employed by a US or Canadian company who appears on OFAC's SDN List is a blocked person. Any transfer of value to that person — including wages, benefits, and employment itself — may constitute a prohibited transaction under OFAC's regulations, entirely separately from whether a deemed-export licence is required or granted. The EAR licence does not authorise an OFAC-prohibited transaction. Both authorisations are needed.

Canada's sanctions regime, administered under its applicable domestic legislation and implementing UN Security Council resolutions, maintains its own list of prohibited persons and entities. As noted above, the Canadian and OFAC lists are not identical. A cross-border employer screening only against one list — typically OFAC because of its size and enforcement visibility — may miss a Canadian-listed person who does not appear on the SDN List. The reverse also occurs: an OFAC-listed person may not yet appear on the Canadian consolidated list.

The practical requirement is a screening programme that checks each relevant individual against all applicable lists — OFAC's SDN List, the UN Security Council Consolidated List, and the relevant Canadian consolidated lists — as part of the same pre-disclosure workflow. The classification analysis and the screening analysis must feed into a single decision before any controlled disclosure occurs. Treating them as sequential, where the export-control classification is done first and the sanctions screening is done later (or not at all), is not a compliant programme design.

The EU dimension is also relevant for multinationals with European operations. An employer with offices in the EU faces a parallel set of deemed-export-equivalent obligations under EU dual-use rules, and the EU's ownership-and-control test for designated persons differs from both the OFAC SDN analysis and the Canadian approach. For a detailed treatment of the EU position, our analysis at OFAC vs EU: Deemed Exports and Technology Transfer Compared addresses the cross-Atlantic divergence in detail. For the UK and Australian comparison, see OFSI vs Australia: Deemed Exports and Technology Transfer Compared.

A common misconception: one jurisdiction covers the other

The most persistent myth we encounter in cross-border deemed-export work is the belief that satisfying BIS requirements automatically satisfies Canada's obligations, or that a Canadian export permit relieves a US person of EAR obligations. Neither is correct, and neither regime provides for that kind of mutual recognition on deemed exports.

The US and Canada cooperate closely on export-control policy through the bilateral defence and trade relationship and through participation in the same multilateral export-control regimes — Wassenaar, the Nuclear Suppliers Group, the Missile Technology Control Regime, and the Australia Group. That cooperation has produced some harmonisation of control lists and some alignment of licence exceptions. It has not produced a mechanism by which a licence or permit granted in one country covers the legal obligation in the other.

A deemed-export licence from BIS authorises the release of US-controlled technology under the EAR. It says nothing about whether the same release requires a Canadian export permit under the Canadian control list. A Canadian export permit authorises an export under Canadian law. It does not satisfy the EAR's licence requirement for a US-origin technology.

This is not a theoretical point. In our cross-border practice, we have advised firms that received BIS approval for a deemed-export programme and then discovered — during a Canadian regulatory inquiry — that no Global Affairs Canada permit had been obtained. The BIS licence was not a defence in the Canadian context. The reverse situation also arises: a firm with a Canadian permit that assumed its EAR obligations were thereby addressed.

The corrective action in both situations is the same: map each disclosure activity to both sets of requirements before any release occurs, obtain the necessary authorisations from each authority independently, and maintain records that demonstrate compliance with each regime on its own terms.

Related practices

Frequently asked questions

Where do the regimes diverge on deemed exports and technology transfer?
The two regimes diverge most sharply on three points: the scope of licence exceptions available to nationals of cooperative-partner countries; the treatment of fundamental research and academic collaboration; and the credit accorded to voluntary self-disclosure in enforcement proceedings. The country lists that determine licence requirements are structured differently, so a nationality that falls within a US exception may still require a Canadian permit, and vice versa. Neither set of exceptions is a substitute for the other, and a firm operating across both jurisdictions must satisfy each regime independently.
Which regime is stricter on deemed exports and technology transfer?
There is no single answer. For US-origin technology at the higher tiers of the Commerce Control List — particularly dual-use items with military, nuclear, or intelligence applications — the EAR typically imposes the more demanding requirement. For technology that falls outside the highest US control tiers but is captured by Canada's Export Control List, the Canadian regime may be more demanding for specific nationalities. The practical rule is that the stricter prohibition governs each act of disclosure, and the compliance programme must be built to the higher of the two standards for each technology category and each nationality.
What should a cross-border business do about deemed exports and technology transfer?
A cross-border business should take four steps before any controlled disclosure occurs. First, classify the technology under both the US Commerce Control List and Canada's Export Control List — these classifications may differ. Second, screen every person who will receive the technology against both regimes' nationality-trigger lists and against all applicable sanctions lists, including OFAC's SDN List and the relevant Canadian consolidated lists. Third, obtain any required licences or permits from BIS and Global Affairs Canada independently, before the disclosure. Fourth, implement a record-keeping programme that satisfies the documentation standards of both regimes and prepare a VSD process to deploy if a compliance gap is identified.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.