Defense & controlled data

ITAR (22 CFR Parts 120-130)

The International Traffic in Arms Regulations control defense articles and technical data. Storing or transmitting that data in a way that exposes it to unauthorized persons can be a regulated export, even without anything physically crossing a border.

Official source (opens in a new tab): 22 CFR Parts 120-130 — U.S. Dept. of State (DDTC)

Scope

Who it applies to.

ITAR reaches any person who, in the United States, manufactures, exports, or temporarily imports defense articles or furnishes defense services — and anyone holding the associated technical data. Coverage follows the U.S. Munitions List at § 121.1, not your industry: a law firm or engineering consultancy that receives a client’s controlled drawings holds technical data under § 120.33. Registration with DDTC is required under § 122.1(a) — one occasion is enough, and manufacturers must register even if they never export. Brokers register separately under Part 129.

Register with DDTC
Anyone in the business of manufacturing, exporting, or temporarily importing defense articles, or furnishing defense services, must register with the Directorate of Defense Trade Controls (§ 122.1(a)). A single occasion counts. Registration confers no export rights — it is generally a precondition to any license. Fees are tiered, starting at $3,000 per year for new registrants (§ 122.3(a)).
Get authorization before exporting
Exporting or temporarily importing a defense article, including technical data, requires DDTC approval beforehand unless a specific exemption applies, and the applicant must already be registered (§ 123.1(a)). Part 125 governs technical-data exports; authorized data may not be reexported, transferred, or disclosed to a national of another country without prior written approval (§ 125.1(c)).
The deemed-export rule
Releasing technical data to a foreign person inside the United States is itself an export — a deemed export (§ 120.50(a)(2)) — and counts as an export to every country where that person holds or has held citizenship or permanent residency (§ 120.50(b)). Release includes oral or written exchange, visual inspection, and giving a foreign person access information such as keys or passwords (§§ 120.55, 120.56).
Keep records for five years
Registrants must keep records of the manufacture, acquisition, and disposition of defense articles and technical data, defense services, brokering, and Part 130 political contributions and fees (§ 122.5(a)). Electronic records must be reproducible on paper and stored so nothing can be altered without recording the change, who made it, and when. Records must be available for inspection (§ 122.5(b)).
The encryption carve-out — all five conditions
Sending, taking, or storing technical data is not an export if the data is: unclassified; secured using end-to-end encryption; secured with cryptographic modules “compliant with… (FIPS 140-2) or its successors” per NIST guidance, or of comparable strength to AES-128; not intentionally sent to or stored in a § 126.1 proscribed country; and not sent from one (§ 120.54(a)(5)). All five must hold.
What “end-to-end encryption” actually requires
The carve-out’s hardest condition is definitional: data must stay encrypted between originator and intended recipient, and “the means of decryption are not provided to any third party” (§ 120.54(b)(1)). The intended recipient must be the originator, a U.S. person in the United States, or someone otherwise authorized (§ 120.54(b)(2)). Merely being able to access properly encrypted data is not a release (§ 120.54(c)).

The vendor & sub-processor obligation

What it puts on you.

Putting technical data on a cloud or AI service can constitute an export if foreign-person administrators or systems can access it, so you must certify that every provider and subprocessor restricts access appropriately — a heavy, ongoing diligence burden.

Releasing or otherwise transferring technical data to a foreign person in the United States (a deemed export).
22 CFR § 120.50(a)(2) (official text)

How self-hosting addresses it

Remove the third party, remove the burden.

Keeping technical data on an appliance inside your own facility, with access limited to your own authorized people, avoids the uncontrolled disclosure to third parties that triggers the hardest ITAR questions.

How FileFerret applies

Running indexing, search, and AI on hardware inside your own facility keeps technical data out of any third party’s hands, so the deemed-export and provider-access questions a cloud or hosted AI service raises are not presented, and you are not depending on § 120.54(a)(5). Controlling foreign-person access to your own systems remains entirely your obligation. See how it’s built →

Full, current text is maintained at the official source: 22 CFR Parts 120-130 — U.S. Dept. of State (DDTC).

Enforcement

Who enforces it, and how.

Willful violations of the Arms Export Control Act or ITAR are criminal: § 127.3 applies the penalties in 22 U.S.C. 2778(c) — a fine of up to $1,000,000 per violation, up to 20 years’ imprisonment, or both. Civil penalties, imposed by the Assistant Secretary of State for Political-Military Affairs, reach the greater of an inflation-adjusted statutory maximum or twice the value of the transaction (§ 127.10(a)(1)(i)). Conviction also brings statutory debarment, generally three years, with no automatic reinstatement (§ 127.7(b)).

Common questions

Questions firms ask.

Does storing ITAR technical data in a U.S. cloud region satisfy the § 120.54 carve-out?

Not by itself. The carve-out turns on end-to-end encryption, which § 120.54(b)(1)(ii) defines to require that “the means of decryption are not provided to any third party.” If the provider holds or can reconstruct your keys — as with most provider-managed encryption — that condition fails, regardless of region. U.S.-only data residency is not one of the five conditions and does not substitute for them.

Can a foreign-national employee work on technical data if it never leaves the country?

Location does not matter. Releasing technical data to a foreign person inside the United States is itself an export under § 120.50(a)(2), and § 120.50(b) treats it as an export to every country of that person’s citizenship or permanent residency. Absent a license or other authorization, access must be restricted. Note that lawful permanent residents and protected individuals are U.S. persons under § 120.62.

If the storage is encrypted, can we give a foreign-national administrator the password?

No. § 120.55 defines access information — decryption keys, network access codes, passwords — and § 120.56(a)(3) makes it a release to use access information to enable a foreign person to access, view, or possess unencrypted technical data. § 120.50(a)(6) treats the release of previously encrypted technical data as an export. Handing over the key is the export, even if the ciphertext never moved.

More in Defense & controlled data

Related guides.

CMMC certification & assessments

Defense contractors handling Controlled Unclassified Information (CUI) must implement the security controls in NIST SP 800-171, with CMMC 2.0 adding assessment and certification to prove it.

CJIS Security Policy

The CJIS Security Policy sets the minimum security controls for handling criminal justice information (CJI), covering access control, encryption, auditing, and personnel screening.

← All compliance guides

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.