Supplier Awareness. Export Control/ ITAR



Similar documents
white paper Mitigate Risk in Handling ediscovery Data Subject to the U.S. Export Control Laws and Regulations

Export Control Basics

COMPUTER & INTERNET. Westlaw Journal. Expert Analysis Software Development and U.S. Export Controls

Using Technology Control Plans in Export Compliance. Mary Beran, Georgia Tech David Brady, Virginia Tech

Policy and Procedures Date:

EXPORT CONTROLS COMPLIANCE

SI/SAO Export Compliance Training 1/9/2014

Export Controls and Cloud Computing: Legal Risks

Export Controls. How to Comply with Export Controls. By Kimberly Marshall

Harvard Export Control Compliance Policy Statement

1. Not Subject to the EAR and Defense Article. (1) Reserved. (2) Reserved

A Primer on U.S. Export Controls

Export Control Compliance Procedure Guide June 8, 2012

EXPORT CONTROLS AND RESEARCH AT WPI TRAINING PRESENTATION

MyNextConsultant.com Privacy Policy. Last updated: October 01, 2013

Addressing ITAR compliance with Teamcenter

Second Annual Impact of Export Controls on Higher Education & Scientific Institutions

Welcome to the World of Public Cloud Collaboration Allowing Enhanced Security

ITAR: Welcome to Public Cloud Collaboration

University of Maryland Export Compliance Program

Director of Logistics & Compliance James Hall

(1) Anybody corporate having as its primary object, business relating to financial services.

Export Control Training

Department of Defense DIRECTIVE

Employment Application

Online Immigrant Visa and Alien Registration Application (DS-260)

Tennessee Reciprocity License Application Instructions

Great Idea Form. Requirement Summary. Origination. Source: Business Sponsor. GIF #: CSPO-GIF-960 Status: Pending Review Submit Date:

US Export Regulations Compliance. Presented by Larry Disenhof Cadence Design Systems, Inc.

Regulatory Compliance and Trade

Trade Compliance & Exports

Privacy and Cloud Computing for Australian Government Agencies

Terms of Service. Your Information and Privacy

Selected Troublesome/Unacceptable Clauses Related to Information Release and Foreign Nationals

Protecting the Value of Your Transaction y

COMPUTER SOFTWARE AS A SERVICE LICENSE AGREEMENT

Key Elements of International Trade Compliance. Presented by:

Export Control Management System

Stringent Guidelines. ITAR dictates control over the export and import of. defense-related articles and services on the United States

Outside Director and Proxy Holder Training: Module 2: Managing Foreign Ownership, Control, or Influence (FOCI) Mitigation Defense Security Service

Petition for Alien Fiancé(e) Department of Homeland Security U.S. Citizenship and Immigration Services. Fee Stamp. Mandatory Waiver.

Department of State Questions. 1. Why do I need to get the U.S. Government s approval to export and import defense articles and defense services?

Transit and Transhipment of Dual-Use Items. India. By Ritesh Kanodia and Aman Bhalla, Economic Laws Practice

Petition for Alien Fiancé(e)

COVER SHEET OF POLICY DOCUMENT Code Number Policy Document Name

How To Complete Form I-9 for International Employees and Permanent Residents

STATUS OF THE CITIZENS OF THE FREELY ASSOCIATED STATES OF THE FEDERATED STATES OF MICRONESIA AND THE REPUBLIC OF THE MARSHALL ISLANDS

Management and Storage of Sensitive Information UH Information Security Team (InfoSec)

Addendum 529 (5/13) Page 1 of 5

Data Transfer Policy. Data Transfer Policy London Borough of Barnet

Guide to INFORMATION SECURITY FOR THE HEALTH CARE SECTOR

DATA AND PAYMENT SECURITY PART 1

INFORMATION SECURITY POLICY

New Proposed Department of Energy Rules to Clarify and Update Part 810. By Shannon MacMichael and Michael Lieberman of Steptoe & Johnson, LLP 1

THE UNIVERSITY OF ALABAMA IN HUNTSVILLE. EXPORT COMPLIANCE PROGRAM MANUAL Updated August 2012

HIPAA Awareness Training

DHS / UKvisas Project

ARIZONA. Title 10 - Corporations and Associations

Introduction to Braumiller Schulz LLP Why Trade Compliance? Establishing an Internal Compliance Program (ICP) Contracting Services to Outside Experts

Form 313 General Information (Application for Registration of a Foreign Series Limited Liability Company) Commentary

SAMPLE TEMPLATE. Massachusetts Written Information Security Plan

THOROUGHBRED RACING VENDOR LICENSE FORM

CONTROL PROCEDURES FOR UNCLASSIFIED TECHNICAL DATA DISCLOSING MILITARILY CRITICAL TECHNOLOGY

Guidelines for Preparing Export License Applications Involving Foreign Nationals

ETHICS. Code of Conduct for Service Providers

The ITAR and the FCPA: What You Disclose May Hurt You. October 7, 2014

This Policy supersedes the Terex Corporation Policy on Transactions in Iran, dated June 7, 2013.

Somerset County Council - Data Protection Policy - Final

Seagate Rescue Data Recovery Service Program Terms & Conditions

Annual DoD Security Refresher Training

! EMPLOYMENT APPLICATION

LAW OF MONGOLIA ON ELECTRONIC SIGNATURE

MD #52 WASTE MANAGEMENT AUTHORITY CORPORATE HEALTH AND SAFETY PROGRAM

LAYOFFS / TERMINATION OF EMPLOYMENT FREQUENTLY ASKED QUESTIONS

Security Awareness. A Supplier Guide/Employee Training Pack. May 2011 (updated November 2011)

NOTE: All mailings will be sent to the address you indicate below; if you change your address, you must advise this office.

Application for Veterinary Technician Licensure in Nebraska

Adding Digital Signature and Encryption in Outlook

Exporting s from Outlook Version 1.00

Export Controls: What are they? Why do we care?

Transcription:

Export Control & ITAR Supplier Awareness Export Control/ ITAR THIS INFORMATION IS PROVIDED BY PAR SYSTEMS, INC. ("PAR"). PAR IS NOT A LAW FIRM, AND THE INFORMATION CONTAINED HEREIN IS NOT INTENDED TO BE RELIED UPON AS A LEGAL OPINION AND DOES NOT CONSTITUTE, IN ANY MANNER, LEGAL ADVICE. ALL INFORMATION IS PROVIDED AS IS, AND PAR DOES NOT ASSUME ANY LEGAL LIABILITY OR RESPONSIBILITY FOR THE ACCURACY OF COMPLETENESS OF SUCH INFORMATION. 1

What is Export Control? In general the U.S. Government controls the export and import of certain articles in order to keep sensitive technologies and material out of the hands of persons and countries determined to be hostile to the U.S. or our allies Export is controlled by different government agencies Department of Commerce Commercial items Dual use Items Contained on the Commerce Control List Department of State Directorate of Defense Trade Controls Defense Articles list ITAR International Trade In Arms Regulations Nuclear Regulatory Commission Commercial nuclear power technology Department of Energy Defense nuclear technology 2

Why Do We Care? Substantial Penalties A felony conviction, jail time and very large fines Companies Employees who knowingly violate or fail to follow the rules Supplier could lose ability to perform work for government and defense contracts Supplier could lose the ability to work on exportable contracts 3

PaR s Responsibility PaR is responsible for project classification and determination of license requirements Determine what agency has basic jurisdiction Determine dual use designation Determine the appropriate Commerce Control Define the country the export is for Determine if a license is required Confirm the excluded entities & denied persons lists Any drawings or documents that imply or provide specific information that are Export or ITAR controlled will be designated as such (example drawing stamp appears below) 4

Supplier Responsibility The Supplier is responsible to become familiar with the government requirements for Export Control and ITAR The Supplier is responsible to comply to applicable government requirements for Export Control and ITAR Supplier must register with the State Department Directorate of Defense Trade Controls (DDTC). Suppliers must provide PaR with a copy of its registration approval letter http://www.pmddtc.state.gov/registration/index.html The Supplier is responsible to flow-down Export Control and ITAR requirements through its supply chain Links provided for reference: http://www.pmddtc.state.gov/regulations_laws/itar_official.html http://www.pmddtc.state.gov/regulations_laws/documents/official_itar/itar_part_120.pdf 5

What is the scope of Export Control? Export Control includes control of knowledge, equipment, and services Technical information Process or application information or knowledge Physical objects and software Export Control applies to what you are sending and where it is sent Need to know all of the parties involved and the intended end-use 6

What is the scope of Export Control? Export Control applies to information passed to Foreign Persons A Foreign Person is not a lawful permanent resident or U.S. citizen is a foreign corporation, business, or organization not incorporated in the U.S. or a U.S. Citizen representing such a company is a foreign government embassy and any agency or agent of a foreign government requires a license to receive controlled technical information Transfers can occur within the U.S. 7

What is the scope of Export Control? Export Control does not apply to information or equipment passed to US Persons within the U.S. A U.S. Person : is a U.S. Citizen or is a lawful permanent resident (Green Card) or a protected individual or is any corporation, business, or organization that is incorporated to do business in the U.S. or is any U.S. government (local, state, or federal) entity. can receive controlled technical information without a license Note: US companies may employ foreign persons, so care is always required when sending technical data or export controlled equipment to US person 8

Examples of requiring Export Control and ITAR Providing controlled technical information or products to a Foreign Person either explicitly or inadvertently without a license is a violation. PaR products that get installed on a Navy ship are controlled under ITAR Even if the basic design is standard it may have been modified to Navy specifications Robotic machine designs may be export controlled and require a license to certain countries no matter what the use Automation applications and particular information known about the end use and parts to be processed may be ITAR controlled 9

What are some areas of concern? Providing technical information to a Foreign Person in the U.S. either explicitly or inadvertently is exporting When applicable, we need a license before we do this, doing so without a license is a violation and we are subject to penalties Allowing people to access controlled information without informing them can lead to a violation E.g leaving controlled information lying around when foreign persons are present (i.e. maintenance, cleaning personal, visitors) They could unknowingly retransfer that information to a Foreign Person We must pass knowledge of Export Control to all members of the supply chain Sending a technical proposal overseas or providing it to a Foreign Person in the US may need a license depending on classification Sending a technical RFQ or PO with technical information to a foreign supplier may require a license A Supplier Non Disclosure Agreement must be in place 10

Who Has Access? Employees Contractors Visitors Suppliers & Sub Contractors For key subs who have access to controlled information you are REQUIRED to flow down all control requirements Do you know who is in the building? Are all of these people US Persons? Don t leave controlled information out and available or on a computer screen if you are not there 11

Data Concerns Notebook Computers If you leave the country with controlled data on your computer you are violating the law unless you have a license to export that data This includes attachments and messages in email Deleting files does not remove the data from your computer Must use secure erase at least DOD level 3 Data security if stolen Email If you must carry critical information it should be protected (encrypted) and licensed Emails and email attachments are maintained in outlook until deleted You may have ITAR and Export controlled information in your outlook file in attachments Don t send file copies by email, send links for internal recipients Don t embed controlled technical data in email text Don t leave email and email attachments that you receive with controlled data in your email folder 12

Data Concerns Acceptable transmission Secure encrypted services PaR IS can set up a secure FTP for a supplier Secure courier services are also acceptable Encrypted email PaR IS has tools to use in data security Erasing Eraser provides several erasing options including DOD Once you erase something it cannot be recovered Encryption software Creates a virtual disk on a hard drive or memory stick 13

PaR Visitor Policy All PaR visitors are required to comply with PaR s Visitor Policy Visitors must sign in and disclose citizenship or immigration status Visitors must disclose if they are representing foreign governments or companies not incorporated in the U.S. Visitors must be aware of our safety policies and follow the policy explicitly Visitors must wear a badge at all times Visitors must be escorted at all times unless specifically stated otherwise A Non Disclosure Agreement must be in place prior to technical or commercial discussions Suppliers are restricted to assigned meeting areas No cameras or photography allowed What is your visitor policy? 14

In Closing It is every supplier s responsibility to control information If in doubt, ask and Use Common Sense 15