Sending and storing
Is your encrypted data an export
Both regimes say that properly encrypted data, stored in the right places, has not been exported by being sent or stored. Both attach conditions. This works through them one at a time and tells you which ones your stack does not meet, and which ones nobody has established.
The two are not the same rule. The EAR version has four conditions. The ITAR version has five, and its storage condition points at a different list, so a stack can satisfy one and fail the other. Both are assessed.
The rule, as it stands
§ 734.18 Activities that are not exports, reexports, or transfers.
EAR · 734.18 · version 2026-08-18, retrieved 2026-08-26
(a) Activities that are not exports, reexports, or transfers. The following activities are not exports, reexports, or transfers:
(1) Launching a spacecraft, launch vehicle, payload, or other item into space.
(2) Transmitting or otherwise transferring “technology” or “software” to a person in the United States who is not a foreign person from another person in the United States.
(3) Transmitting or otherwise making a transfer (in-country) within the same foreign country of “technology” or “software” between or among only persons who are not “foreign persons,” so long as the transmission or transfer does not result in a release to a foreign person or to a person prohibited from receiving the “technology” or “software.”
(4) Shipping, moving, or transferring items between or among the United States, the District of Columbia, the Commonwealth of Puerto Rico, or the Commonwealth of the Northern Mariana Islands or any territory, dependency, or possession of the United States as listed in Schedule C, Classification Codes and Descriptions for U.S. Export Statistics, issued by the Bureau of the Census.
(5) Sending, taking, or storing “technology” or “software” that is:
(i) Unclassified;
(ii) Secured using 'end-to-end encryption;'
(iii) Secured using cryptographic modules (hardware or “software”) compliant with Federal Information Processing Standards Publication 140-2 (FIPS 140-2) or its successors, supplemented by “software” implementation, cryptographic key management and other procedures and controls that are in accordance with guidance provided in current U.S. National Institute for Standards and Technology publications, or other equally or more effective cryptographic means; and
(iv) Not intentionally stored in a country listed in Country Group D:5 (see supplement no. 1 to part 740 of the EAR).
Data in-transit via the internet is not deemed to be stored.
(b) Definitions. For purposes of this section, End-to-end encryption means (i) the provision of cryptographic protection of data such that the data is not in unencrypted form between an originator (or the originator's in-country security boundary) and an intended recipient (or the recipient's in-country security boundary), and (ii) the means of decryption are not provided to any third party. The originator and the recipient may be the same person.
(c) Ability to access “technology” or “software” in encrypted form. The ability to access “technology” or “software” in encrypted form that satisfies the criteria set forth in paragraph (a)(5) of this section does not constitute the release or export of such “technology” or “software.”
§ 120.54 Activities that are not exports, reexports, retransfers, or temporary imports.
ITAR · 120.54 · version 2026-08-18, retrieved 2026-08-26
(a) The following activities are not exports, reexports, retransfers, or temporary imports:
(1) Launching a spacecraft, launch vehicle, payload, or other item into space;
(2) Transmitting or otherwise transferring technical data to a U.S. person in the United States from a person in the United States;
(3) Transmitting or otherwise transferring within the same foreign country technical data between or among only U.S. persons, so long as the transmission or transfer does not result in a release to a foreign person or transfer to a person prohibited from receiving the technical data;
(4) Shipping, moving, or transferring defense articles between or among the United States as defined in § 120.60;
(5) Sending, taking, or storing technical data that is:
(i) Unclassified;
(ii) Secured using end-to-end encryption;
(iii) Secured using cryptographic modules (hardware or software) compliant with the Federal Information Processing Standards Publication 140-2 (FIPS 140-2) or its successors, supplemented by software implementation, cryptographic key management and other procedures and controls that are in accordance with guidance provided in current U.S. National Institute for Standards and Technology (NIST) publications, or by other cryptographic means that provide security strength that is at least comparable to the minimum 128 bits of security strength achieved by the Advanced Encryption Standard (AES-128); and
(iv) Not intentionally sent to a person in or stored in a country proscribed in § 126.1 of this subchapter; and
Data in-transit via the internet is not deemed to be stored in a country it transits.
(v) Not sent from a country proscribed in § 126.1 of this subchapter;
(6) The taking of a defense article subject to the reexport or retransfer requirements of this subchapter on a deployment or training exercise outside a previously approved country, provided:
(i) There is no change in end-use or end-user with respect to the defense article;
(ii) The defense article is transported by and remains in the possession of the previously authorized armed forces of a foreign government or United Nations military personnel; and
(iii) The defense article is not being exported from or temporarily imported into the United States; and
(7) The transfer of a foreign defense article previously imported into the United States that has since been exported from the United States pursuant to a license or other approval under this subchapter, provided:
(i) The foreign defense article was not modified, enhanced, upgraded, or otherwise altered or improved in a manner that changed the basic performance of the item prior to its return to the country from which it was imported or a third country;
(ii) A U.S.-origin defense article was not incorporated into the foreign defense article; and
(iii) The defense article is not being exported from or temporarily imported into the United States.
(b)(1) For purposes of this section, end-to-end encryption is defined as:
(i) The provision of cryptographic protection of data, such that the data is not in an unencrypted form, between an originator (or the originator's in-country security boundary) and an intended recipient (or the recipient's in-country security boundary); and
(ii) The means of decryption are not provided to any third party.
(2) The originator and the intended recipient may be the same person. The intended recipient must be the originator, a U.S. person in the United States, or a person otherwise authorized to receive the technical data, such as by a license or other approval pursuant to this subchapter.
(c) The ability to access technical data in encrypted form that satisfies the criteria set forth in paragraph (a)(5) of this section does not constitute the release or export of such technical data.