A technology company based in the EU hires a research engineer who holds citizenship in a third country. The engineer will work on controlled software at a domestic facility – no export paperwork in sight. Yet the act of granting that person access to the technical data may constitute a transfer of controlled technology requiring authorisation under EU dual-use rules. This scenario plays out daily in laboratories, engineering departments, and research institutions across Europe, largely unnoticed until an audit or enforcement action makes it visible.
Under the EU dual-use regime – governed by Council Regulation (EU) 2021/821 – a deemed export (the transfer of controlled technology or software to a foreign national within the exporting state, treated as an export to that person's country) triggers the same authorisation requirements as a physical cross-border shipment. The governing authority is the competent national authority of the EU Member State where the transfer occurs, applying the EU Dual-Use Regulation and, where relevant, additional national controls. Unlike the US Bureau of Industry and Security (BIS) deemed-export rule, the EU regime has no single codified deemed-export definition, but the core technology-transfer obligation is explicit and enforceable.
This guide walks through the classification step, the jurisdictional question, the authorisation route, cross-regime comparison, and the risk flags that practitioners encounter most often. It covers the position as of April 2026.
Step 1: Classify the technology before you assess the transfer
Classification under the EU Common Control List (CCL equivalent – the Annex I list of the EU Dual-Use Regulation) is the threshold question. Until you know whether the technology is controlled, no transfer analysis is possible.
The EU list is based on multilateral export-control arrangements and is directly applicable across all Member States. Items are listed by category (0–9), product group (A–E), and control parameter. Category E covers technology. A technology note attached to the list defines the scope of what counts as controlled technology: information necessary for the development, production, or use of a listed item.
Practical classification involves three steps. First, identify the relevant item category for the underlying product or system. Second, apply the General Technology Note (GTN) to determine whether the specific technical information you plan to transfer falls within the controlled technology parameters. Third, check whether any decontrol exclusions apply – for example, information in the public domain, basic scientific research, or the minimum necessary for patent applications.
The decontrol exclusions are narrower than they look. "Public domain" means information that has been made available to the public without restriction on further dissemination – not merely information that is widely known in academic circles. In our experience, in-house teams frequently over-rely on the public-domain exclusion for technical information shared at conferences or in journal articles. The question is whether the specific combination of parameters disclosed in the article corresponds to controlled performance levels.
Where classification is genuinely unclear, the competent national authority in the relevant Member State can issue a binding product classification. That route adds time but removes uncertainty before a transfer takes place.
Step 2: Identify the type of technology transfer in scope
EU dual-use controls cover not just physical shipments but all forms of technology transfer, including electronic transmission, verbal disclosure, and physical access to equipment at a domestic site. This is the conceptual basis for deemed exports under the EU regime.
The EU Dual-Use Regulation uses the defined term technology transfer broadly. It encompasses transfers by electronic media, fax, telephone, and "access to technology" – which includes enabling a foreign national to read, handle, or work with controlled items or information without those items leaving the territory. The nationality of the recipient (and, where dual nationality is present, the nationality most relevant to the controlled-country concern) determines the deemed destination.
Three practical scenarios arise most often:
- A foreign-national employee or contractor is given system access to a controlled software platform for development or testing purposes.
- A visiting researcher from a third country is permitted to enter a facility and handle controlled equipment or review technical drawings.
- Controlled technical specifications or design files are shared via a collaboration platform accessible to personnel whose nationality creates a country concern.
The EU regime does not publish a consolidated deemed-export FAQ or guidance document of the kind BIS maintains in the US. Practitioners must read the technology-transfer provisions alongside the General Technology Note and the case law of national authorities. Several Member States have issued national guidance, but it is not harmonised. This gap is one reason early advice is valuable – the applicable national rules differ.
Step 3: Determine which Member State's competent authority has jurisdiction
The EU Dual-Use Regulation is directly applicable, but licensing is administered at national level. Each Member State designates a competent authority. The authority with jurisdiction is generally that of the Member State where the exporter (or transferor) is established.
This creates a practical issue for multinational groups. If a French parent employs personnel in Germany and those personnel access technology controlled under the EU list, the question of which competent authority must be engaged – the French SBDU or the German BAFA – turns on where the technology is held and where the transfer occurs. In our cross-border practice, we regularly advise groups that have not mapped which of their Member State entities holds the controlled technology and, accordingly, which licence must be obtained before access is granted.
The answer matters because authorisation types and processing timelines differ between Member States, even though the underlying EU list is uniform. A company that obtains a French individual export licence has not thereby authorised its German affiliate to permit access by the same foreign national.
Where a transfer takes place simultaneously or sequentially in multiple Member States – for example, during a pan-European product-development programme – each relevant entity must assess its own obligations under the authority of its Member State. Coordination across the group is essential.
Step 4: Select the correct authorisation route
EU dual-use authorisations fall into three principal categories. Choosing the wrong one is a common compliance failure.
The first is the Union General Export Authorisation (UGEA). UGEAs are pre-published authorisations for defined categories of exports to listed destinations. They do not, as a general rule, cover deemed exports in the form of intangible technology transfers to individuals. Exporters who assume that a UGEA covers access by a foreign-national employee to controlled technology at a domestic site are likely wrong.
The second is a national general authorisation, available in some Member States for defined categories of technology and recipient. Scope and conditions vary significantly by Member State. Where a national general authorisation exists and the transfer falls squarely within its conditions, use of it is straightforward but must be documented.
The third is an individual export licence – a case-by-case authorisation issued by the competent national authority for a specific transfer to a specific recipient. For deemed exports to foreign nationals not covered by a general authorisation, this is usually the required route. Applications require a description of the technology, the recipient's nationality and role, an end-use statement, and, in many Member States, additional supporting materials.
Processing timelines for individual licences vary. Some Member States publish indicative timelines; others do not. In our experience, applicants who submit incomplete or poorly framed applications face material delays and requests for further information that can extend the process significantly. Front-loading the application with a clear technical description and a credible end-use statement shortens review time.
If a transfer is genuinely time-sensitive, consider whether an interim access restriction (limiting the employee's access to non-controlled technical parameters until the licence is in place) is a viable option. That approach avoids a breach while the authorisation is processed.
The position above covers the standard authorisation pathway. Your facts – the technology category, the recipient's nationality, the Member State of transfer, and the current licence stock – change the analysis significantly.
For an assessment of your authorisation options under the EU dual-use regime, contact Calder & Vance at info@caldervance.com.
How does the EU deemed-export position compare to the US BIS regime?
The US regime under the Export Administration Regulations (EAR) contains an explicit deemed-export rule: releasing controlled technology to a foreign national in the United States is treated as an export to that national's home country. BIS has published detailed guidance on how the rule applies, including the concept of deemed re-export for transfers by US persons abroad.
The EU approach is functionally similar but structurally different. No single article in the EU Dual-Use Regulation uses the phrase "deemed export". Instead, the same outcome is reached through the technology-transfer definition and the General Technology Note. The practical effect is that EU compliance teams must work harder to derive the rule from first principles.
Three differences between the regimes matter for cross-border businesses:
- Nationality test: BIS focuses on the country of most recent citizenship or permanent residence for persons with multiple nationalities. The EU approach requires an assessment of the nationality most relevant to the controlled-country concern, and national guidance on this point is not uniform across Member States.
- List alignment: Both the EU CCL and the US Commerce Control List (CCL) derive from the multilateral arrangements (Wassenaar, NSG, MTCR, AG). They are largely aligned on dual-use items but are not identical. An item that is EAR99 (not listed under the US CCL) may still be listed under the EU regime, or vice versa. Dual-regime compliance requires separate classification analysis for each.
- National fragmentation: Under BIS, there is one competent authority and one set of rules. Under the EU regime, there are 27 Member States, each with its own competent authority. A company with operations in three Member States may need three separate licence applications for what is functionally the same deemed-export scenario.
For businesses with both EU and US operations, the interaction of these two regimes is a live compliance question. We regularly advise on precisely this cross-regime alignment. Related guidance on the US BIS position is available at our BIS deemed-export service page.
Where a transfer involves US-origin technology held by an EU entity, the EAR's re-export controls may also apply – requiring the EU entity to assess BIS requirements in addition to those of the relevant Member State. The stricter prohibition governs.
What are the principal risk flags in a deemed-export programme?
Risk flags in a deemed-export programme cluster into four areas. Knowing them shapes both the initial programme design and ongoing monitoring.
Ownership and control of the technology: Groups that restructure or acquire often inherit a technology holding without a corresponding licence audit. A controlled technology asset that was properly managed by the target company may lack the authorisations needed for the acquiring group's personnel to access it post-closing. M&A due diligence should map controlled technology holdings and identify access rights as a specific workstream.
Contractor and secondee arrangements: Individual export licences or national general authorisations obtained for employees do not automatically extend to contractors, secondees, or agency workers. Each access arrangement should be assessed separately against the authorisation in place.
Cloud and collaboration platforms: Technology stored in a cloud environment accessible from multiple jurisdictions raises two distinct issues. First, which Member State's authority has jurisdiction over the transfer? Second, does making controlled technology available on a shared platform constitute a transfer to every user with access credentials, regardless of whether they actually download or review the material? Competent authorities have taken different positions on this. Conservative compliance practice treats potential access as access, pending clearer national guidance.
Updates and re-classification: The EU Dual-Use Regulation is periodically updated to reflect changes in the multilateral arrangements. An item or parameter that was not controlled when a compliance programme was designed may become controlled following a list revision. Periodic re-classification reviews are not optional; they are a basic feature of a functioning programme.
If a transfer has already taken place without authorisation, an early review of the apparent violation can identify whether voluntary disclosure to the competent authority is appropriate. The approach to voluntary disclosure differs between Member States, but the principle – that early engagement with the regulator is preferable to later discovery – is consistent. We advise on voluntary disclosure strategy as part of our enforcement-defence work.
If a transaction has already been flagged or a filing has been refused, acting promptly preserves options. Write to info@caldervance.com for a confidential review.
Common misconceptions about deemed exports under the EU regime
A persistent myth in cross-border businesses is that EU dual-use controls apply only to physical exports and that access by employees at domestic facilities falls outside the regime. This is incorrect. The technology-transfer definition in the EU Dual-Use Regulation is explicit that transfers by electronic means and physical access to items are within scope. No physical shipment is required.
A related misconception is that the EU regime is effectively enforced only at the border and that internal access controls are a US-law concern. In fact, enforcement of technology-transfer rules is within the mandate of national competent authorities across Member States. Enforcement actions for unlicensed technology transfers – though less frequent in public record than shipment-related enforcement – do occur, and the range of potential consequences includes criminal penalties under national implementing legislation.
A third misconception concerns dual nationals. Some businesses assume that a person holding citizenship in both an EU Member State and a third country does not require a deemed-export licence because their EU citizenship removes the transfer concern. The EU regime does not work that way. The competent authority must assess the relevant nationality and the associated controlled-country concern. Where the third-country nationality creates a concern, a licence may still be required. National guidance on this point should be checked.
For further detail on technology-transfer classification questions, see our companion guide on EU dual-use classification and our guide on licensing procedure across Member States.
When should you involve export-control counsel?
Export-control counsel adds value at four points in the deemed-export lifecycle.
First, at programme design: when a company first recognises that it holds controlled technology and employs or engages foreign nationals, building the programme correctly from the outset is significantly cheaper than retrofitting controls after an audit finding.
Second, at classification: where a technology item sits at the boundary of a control parameter, a formal legal opinion supporting the classification decision provides a defensible record. Self-classification without documented reasoning is the most common vulnerability we see in client programmes.
Third, at licence application: individual export-licence applications for deemed exports require precise framing. An application that describes the technology too broadly will attract unnecessary conditions; one that describes it too narrowly may not cover the actual transfer. We prepare and submit licence applications, manage the competent authority's queries, and advise on conditions.
Fourth, at apparent violation: if a review reveals that controlled technology was accessed without authorisation, immediate legal advice on voluntary disclosure, breach containment, and communication with the competent authority is essential. Early engagement typically produces better outcomes than waiting for enforcement contact.
In a recent matter, a European industrial group discovered, during a post-acquisition integration review, that the acquired company had permitted access to controlled manufacturing-process technology by personnel whose nationalities had not been assessed against the EU dual-use list. We conducted a classification review, identified the applicable Member State authority, prepared voluntary disclosure filings, and designed an access-control protocol to prevent recurrence. The matter was resolved through cooperation with the competent authority without escalation to formal penalty proceedings.
Related practices
- BIS / EAR Deemed Export Service – US deemed-export analysis, classification, and licence applications under the EAR
- EU Dual-Use Classification Guide – step-by-step classification methodology for the EU Common Control List
- EU Licensing Procedure Across Member States – national authorisation routes and competent authorities compared