Calder & Vance International Sanctions & Compliance Counsel

Export Controls & Dual-Use · OFSI

OFSI vs EU: Deemed exports and technology transfer: what businesses miss

A UK-based engineering firm grants its German subsidiary access to a secure technical database. The subsidiary's team includes nationals of a state subject to multiple sanctions programmes. No physical goods cross any border. No export licence has been sought. Is this a problem?

Under both the UK and EU regimes, the transfer of controlled technology to a person – even within a single organisation – can constitute a deemed export requiring authorisation. The rules governing this analysis differ materially between OFSI's enforcement environment, the relevant UK export-control instruments administered by ECJU, and the EU dual-use regime. Getting the comparison wrong exposes a business to enforcement on both sides of the Channel simultaneously. As of April 2026, the divergence in how each regime defines "technology transfer," handles intangible transmissions, and treats intra-group access is the compliance gap our clients most frequently underestimate.

This analysis sets out the governing tests under each regime, maps the points of divergence, flags the practical risks, and explains when cross-border counsel is needed before access is granted.

What is a deemed export, and why do both regimes reach further than most businesses expect?

A deemed export is the transfer of controlled technology or software to a foreign national that is treated as an export to that person's country of nationality – regardless of where the transfer physically occurs. The concept means that handing a technical document to a colleague in a London office, granting system access to a contractor in Brussels, or delivering a presentation to a client's engineers can all trigger the same licence requirement as shipping goods across a border.

Under the UK export-control regime, the Export Control Order and related statutory instruments capture "the transfer of technology" broadly. The relevant instruments cover oral, written, electronic, and visual transmission of controlled technical data. ECJU administers this regime; OFSI sits alongside it with responsibility for financial sanctions prohibitions that can intersect where a counterparty or recipient is designated. The two UK authorities operate on different legal bases and different trigger conditions – a point many compliance teams miss.

The EU regime under the applicable Council Regulation on dual-use items similarly reaches intangible transfers. "Technology" for EU purposes follows the definitions in Annex I to the relevant regulation, and a transmission is caught whether it occurs by electronic means, fax, telephone, or in person. Crucially, the EU regime also includes a catch-all provision allowing competent authorities to require a licence for transfers not otherwise listed, where the exporter has reason to believe the end use presents a risk.

In our experience, the gap between what businesses perceive as an "export" and what these instruments actually capture is widest in sectors where technical collaboration is constant: defence supply chains, semiconductor research, advanced manufacturing, and financial technology. Have you audited every channel through which controlled data leaves your control – not just the warehouse?

How the UK and EU regimes define controlled technology: two tests, one transaction

Both regimes use control lists derived from multilateral arrangements, but the administrative mechanics and the scope of national discretion differ in ways that change the outcome for a given transfer.

Under the UK regime post-Brexit, ECJU administers the UK Strategic Export Control Lists. These lists were initially aligned with EU predecessor lists, but the UK now updates them independently. A technology item that has moved off the EU list – or been reclassified – may remain controlled in the UK, and vice versa. A business that performs a single classification exercise and applies it to both regimes is taking a risk that our practice sees crystallise regularly in sector audits.

The EU dual-use regulation, as updated and currently in force, applies to all EU member states and to their nationals and residents. It carries an extraterritorial element: EU persons and EU-incorporated entities can be caught by the regulation's provisions in respect of activities they conduct outside the EU. This means a UK-incorporated subsidiary of a German parent group may face obligations under both the UK and EU regimes for the same intangible transfer.

The control-list divergence is operational, not theoretical. In a recent matter, a precision-engineering group discovered that a component specification that had been de-listed in the EU following a regulatory review remained controlled under the UK lists. The group had relied on an EU classification memo for its global programme. The UK exposure was identified only when a transaction screening triggered an internal query. We were instructed to scope the apparent violation, assess VSD eligibility, and redesign the classification workflow. No export had in fact been completed without authorisation, but the control failure would have produced unlicensed transfers within the following quarter.

Where do the regimes diverge on intra-group and intra-facility access?

Intra-group technology access is one of the most contested areas of deemed-export analysis, and the UK and EU regimes treat it differently in ways that affect multinational group structures.

Under the UK regime, the question is whether a transfer has occurred to a person outside the UK, or whether a foreign national within the UK has been given access in circumstances that amount to a transfer. The Export Control Order does not carve out intra-group transfers from the prohibition; the relationship between the transferor and the recipient does not, on its own, create an exemption. ECJU's published guidance acknowledges that access control within a facility can be a mitigating factor, but it does not substitute for a licence where one is required.

The EU regime takes a comparable position on the absence of a general intra-group exemption. However, several EU member states operate national internal compliance programme frameworks that provide a degree of regulatory credit for exporters who can demonstrate certified internal controls. The UK has no equivalent certified-programme mechanism with direct licensing relief. This creates a structural asymmetry: a multinational group that has obtained EU regulatory credit for its internal programme must still seek individual ECJU authorisation on the UK side.

The practical consequence is that a group operating a unified technology-access platform must maintain two separate compliance tracks. The access rights matrix that satisfies the relevant EU competent authority may not satisfy ECJU. We regularly advise groups on how to architect access-control systems that meet both sets of requirements without creating two entirely parallel administrative structures.

The nationality question: how each regime handles mixed-nationality teams

Mixed-nationality research and engineering teams are the norm in modern business, and both regimes require companies to perform individual-level analysis of who can access what technology.

Under the UK regime, the deemed-export analysis focuses on whether a person who is not a UK national (or who holds a nationality of a controlled destination) is given access to technology controlled for that destination. The analysis does not require intent. An inadvertent grant of access – a shared drive, an unlocked laboratory, an unguarded presentation – is sufficient. The statutory framework does not distinguish between deliberate and negligent transfers for the purposes of establishing the prohibition; the distinction matters at the enforcement stage.

The EU approach is structurally similar but carries an additional layer where the technology is controlled for specific end uses rather than specific destinations. The end-use catch-all provisions can reach a transfer that would not otherwise require a licence, where the competent authority has issued a specific notification to the exporter. EU exporters who have received such a notification – and then allowed broad access to their technical teams – face heightened exposure.

One question that cross-border compliance teams ask us regularly: does a person's dual nationality affect the analysis? Under both regimes, the answer is broadly yes – the stricter of the applicable restrictions governs, and the burden of demonstrating that a person's access does not constitute a deemed export rests with the exporter, not the regulator.

What happens when an individual's nationality changes between the time of access-rights assignment and the time of actual transfer? Neither regime provides a mechanical safe harbour. The answer requires a fact-specific review, and the prudent course is a periodic re-screening of access-rights holders against current control parameters.

Cloud, remote access, and electronic transmission: the modern exposure points

Both regimes were drafted to capture intangible transfers, but the technology through which those transfers occur has evolved faster than the guidance. Cloud platforms, remote-desktop systems, collaborative engineering tools, and AI-assisted design environments all raise deemed-export questions that the original regulatory text did not anticipate in their current form.

Under the UK regime, ECJU's guidance addresses electronic transmission in general terms. The question of where a server is located, and who administers access to it, is relevant but not determinative. What matters is whether a person in a controlled destination, or a national of such a destination, obtains effective access to controlled technology. A UK company that stores controlled technical drawings on a US-based cloud platform with global access permissions may face exposure under the UK regime, under the US EAR administered by BIS, and potentially under the EU regime if EU employees are involved. These three exposures are separate, concurrent, and require separate analysis.

The EU regime is similarly clear that electronic transmission is a "transfer" for the purposes of the dual-use rules. The location of the server does not create a safe harbour. The nationality and location of the person obtaining access is the primary analytical variable.

In our cross-border practice, cloud-based technology access is now the most common source of unremediated deemed-export exposure. We have acted for technology companies, financial-data providers, and advanced-materials manufacturers where the primary control gap was not an export shipment but an unmanaged cloud-access policy. The fix requires both a technical control (access-rights architecture) and a regulatory one (licence or licence exception determination).

For businesses operating under US export controls alongside UK and EU obligations, the BIS deemed-export rules under the EAR add a further layer. The BIS framework, which applies to technology subject to the Commerce Control List under the EAR, has its own definitions of technology, its own nationality-based triggers, and its own licence-exception architecture. All three regimes can bite on the same transfer event, and the strictest applicable prohibition governs.

Licensing routes compared: UK ECJU, the EU competent authorities, and what diverges

Where a transfer is controlled, both regimes offer licensing routes, but the processes, timelines, and available authorisation types differ materially.

Under the UK regime, ECJU issues Standard Individual Export Licences (SIELs), Open Individual Export Licences (OIELs), and Open General Export Licences (OGELs). An OGEL can cover certain deemed-export scenarios without a per-transaction application, provided the exporter meets the conditions attached to the licence – including record-keeping and compliance requirements. ECJU's published processing targets for individual licences are set in business days, but the actual timescale for complex dual-use technology cases can extend considerably beyond those targets, particularly where the end use or end user requires in-depth assessment.

EU competent authorities – one per member state, operating under the common regulatory framework – issue national licences and can endorse the use of Union General Export Authorisations where the transfer qualifies. The general authorisations are EU-wide, but they do not apply to all controlled items or all destinations. A business that relies on a Union General Export Authorisation for its EU operations has no equivalent instrument on the UK side; it must separately assess ECJU coverage.

An important practical difference: licence conditions imposed by ECJU and those imposed by EU competent authorities are not automatically harmonised. A research consortium that holds both a UK SIEL and a French national licence for the same technology transfer programme must comply with the conditions of both, and those conditions can require different record-keeping formats, different end-use undertakings, and different reporting frequencies.

For businesses that frequently conduct similar transfers across multiple transactions, an OIEL or an EU global licence can reduce administrative burden. But these instruments require the exporter to demonstrate an effective internal compliance programme, and both ECJU and EU authorities have shown willingness to revoke or suspend authorisations where a compliance failure is identified during a post-shipment audit.

Enforcement posture: how OFSI, ECJU, and the EU authorities approach technology-transfer breaches

Understanding the enforcement environment is as important as understanding the substantive obligations, because the posture of the relevant authority shapes the risk calculus for a business managing a potential breach.

OFSI's role in technology-transfer enforcement is specific: OFSI acts where the transfer involves a designated person or entity – for example, where payment for a technology-transfer service flows to a sanctioned counterparty, or where the transfer itself is to a designated individual. OFSI does not administer export-control licences, but its enforcement activity can intersect with ECJU matters where the recipient of controlled technology is on the UK Consolidated List. A single transaction can produce a financial-sanctions violation investigated by OFSI and an export-control violation investigated by ECJU, with different penalty regimes and different enforcement procedures applying to each.

ECJU refers the most serious export-control cases to HMRC for criminal investigation. Civil compounding is available for lower-level cases, and ECJU publishes compound-settlement data that provides a qualitative sense of the enforcement environment, though specific penalty amounts from that data are not reproduced here. What the published record shows is that knowledge of the relevant control parameters – demonstrated through classification records and compliance policies – is a material mitigating factor.

EU enforcement varies by member state. The dual-use regulation sets a framework of obligations, but penalty levels, investigative powers, and enforcement philosophy differ across the EU. A business with operations in multiple member states faces a heterogeneous enforcement environment: a compliance failure that is managed through a civil process in one jurisdiction may be subject to criminal referral in another. This is a point that centralised compliance functions at the group level often fail to account for.

Voluntary self-disclosure (VSD) – the voluntary reporting of a potential violation to the relevant authority before it is discovered through an audit or third-party complaint – is recognised as a mitigating factor under both the UK and EU regimes. The appropriate timing and form of a VSD varies by regime and by the nature of the potential breach. Acting early preserves options; delay narrows them. If you have identified a potential deemed-export control failure, the decision about whether and when to disclose is one of the first questions to resolve with counsel.

Common mistakes: what businesses regularly miss on deemed exports and technology transfer

Across our advisory work, the same categories of error recur. Understanding them is the first step to avoiding them.

The first and most common is assuming that a physical-goods classification exercise covers the associated technology. It does not. The classification of a controlled item does not automatically determine the classification of the technology required to develop, produce, or use it. Technology classification is a separate exercise, and the control parameters for technology often extend to destinations and end uses that the physical-goods licence does not cover.

The second is treating EU and UK control lists as identical post-Brexit. As noted above, the two lists are updated independently. A classification review that was accurate at the point of Brexit may now be wrong on one or both sides. Businesses that have not refreshed their technology classification since 2020 are, in our experience, operating on outdated assumptions.

The third – and one that AUDIENCE_MYTH addresses directly – is the belief that intra-group transfers are automatically exempt. They are not. The corporate relationship between transferor and recipient is not, in itself, a licence. Where employees of a related entity in a controlled destination have access to controlled technology, the deemed-export analysis applies in full, and neither the UK nor the EU regime provides a blanket corporate-group carve-out.

The fourth is inadequate record-keeping. Both regimes require exporters to maintain records of their technology transfers for a significant period. The records must be sufficient to demonstrate the basis on which a transfer was made – whether under a licence, under an exception, or on the basis that the technology was not controlled. Generic file notes are not adequate. ECJU's guidance on what constitutes an adequate record is more detailed than many compliance teams appreciate.

The fifth is failing to screen access-rights holders periodically. An individual whose access rights were correctly assessed at the point of onboarding may have changed nationality, changed role, or become associated with a sanctioned entity in the interim. Static screening is not sufficient where controlled technology access is concerned.

Related practices

When to involve export-control and sanctions counsel

The decision to instruct specialist counsel is not always obvious, and businesses sometimes wait until a problem is acute before seeking advice. In our experience, the cost of early involvement is consistently lower than the cost of managing a disclosure, an enforcement inquiry, or a licensing refusal that follows from unadvised action.

There are four situations in which early instruction is particularly important.

First, before any new technology-access arrangement is established for a team that includes foreign nationals from controlled destinations. The analysis should be completed before access is granted, not after. Retrospective licensing is more difficult, and the period of unlicensed access creates a technical exposure even where the authority does not ultimately pursue it.

Second, when a classification review reveals that a technology previously treated as uncontrolled is in fact controlled – or when a control-list update changes the classification of a technology already in use. The response needs to cover both the forward position (can we continue to grant access?) and the historic one (do we have an apparent violation requiring disclosure?).

Third, when a business is moving controlled technology onto a new platform – a cloud migration, a new collaboration tool, a shared engineering environment – that will be accessible to a broader or different group of users. The platform change is the trigger for a fresh deemed-export analysis, not a continuation of the old one.

Fourth, when a regulator makes contact – whether through a routine audit request, a post-shipment verification inquiry, or a direct enforcement communication. The appropriate response is time-sensitive, and the framing of early correspondence can have a material effect on how the matter develops. We have advised on enforcement responses before ECJU, before OFSI, and before EU competent authorities, and in each case the early decision on how to engage shaped the outcome more than almost any later step.

The position above covers the principal scenarios. Your specific facts – the technology, the access arrangement, the nationalities involved, the destination, and the regime in play – will change the analysis in ways that only a review of your actual programme can identify.

If a transaction has already been flagged, or an access arrangement is under review, an early assessment can preserve options that narrow with time. Contact Calder & Vance at info@caldervance.com for a confidential initial review.

Frequently asked questions: deemed exports and technology transfer under OFSI and the EU

Where do the regimes diverge on deemed exports and technology transfer?

The UK and EU regimes diverge in three material respects. First, the control lists are now maintained independently: post-Brexit updates mean that a technology may be controlled in one regime and not the other. Second, the EU operates a framework of national certified internal-compliance programmes that can provide regulatory credit; the UK has no equivalent mechanism with direct licensing relief under ECJU. Third, enforcement responsibility under the UK regime is split between OFSI (financial-sanctions matters) and ECJU (export-control matters), while EU enforcement is administered by national competent authorities whose posture and penalty levels vary across member states. A single technology-transfer event can trigger obligations under both UK authorities simultaneously, requiring coordinated management of two separate regulatory processes.

Which regime is stricter on deemed exports and technology transfer?

Neither regime is uniformly stricter; the answer depends on the specific technology, destination, and end user. The EU regime's end-use catch-all provisions can reach transfers that fall below the UK control threshold, making the EU the more demanding regime in certain scenarios. In others – particularly where the UK has retained controls on technologies that the EU has de-listed – the UK regime is more restrictive. Where both regimes apply, the stricter applicable prohibition governs each element of the transfer, and a business must satisfy both. The practical answer for any cross-border business is that both regimes must be assessed independently for every technology and every access arrangement; relying on a single-regime analysis creates an unmanaged exposure under the other.

What should a cross-border business do about deemed exports and technology transfer?

A cross-border business should take four steps. First, classify all controlled technology separately from controlled goods: technology classification is a distinct exercise and requires its own review under both the UK and EU control lists. Second, map all access arrangements – including cloud platforms, collaboration tools, and remote-access systems – against the nationality and location of every person who can obtain effective access. Third, establish a periodic re-screening process for access-rights holders, since nationality, role, and sanctions status can change after onboarding. Fourth, maintain records sufficient to demonstrate the basis of every access decision, whether under a licence, an exception, or a finding that the technology is not controlled. Where an arrangement cannot be brought within an existing authorisation, a licence application should be made before access is granted, not after.

About the author

Henry Ashworth advises on UK financial sanctions and export controls, including OFSI licensing and enforcement, ECJU export-licensing matters, and judicial-review challenges to designations. He regularly advises multinationals, financial institutions, and exporters on the interaction between UK and EU sanctions and export-control obligations in cross-border transactions. Calder & Vance – International Sanctions & Export Control Counsel.

About Calder & Vance

Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.

Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.