Best-Practice Checklist for Deemed-Export Risk in Translation
- 2 hours ago
- 5 min read
Send a controlled maintenance manual to an unvetted translator and you may have just made an unlicensed transfer. Regulation (EU) 2021/821 treats the transmission of working knowledge as technical assistance under Article 2, so the act of sharing a document for translation can itself be the export. No shipment crosses a border. The file lands in an inbox, and the control has already fired.
What counts as a deemed export
EU law has no phrase called "deemed export." The mechanism lives inside the definition of technical assistance in Article 2 of Regulation 2021/821, which covers support tied to the repair, development, manufacture, or use of a controlled item, including transmission by electronic means. Hand a controlled technical file to a linguist and you transmit working knowledge about a controlled item. If that linguist sits outside the authorised scope, the transfer needs a licence you probably do not hold.
Annex I lists the controlled items. Annex IV lists the most sensitive ones, where even an intra-EU transfer needs authorisation. The 2025 update to Annex I (Commission Delegated Regulation 2025/2003, in force 15 November 2025) widened the list into quantum systems, advanced semiconductors, and additive manufacturing, so a file that read as clear last year may not read as clear now.

Document types that carry exposure
Four categories account for most of the risk. Check any translation project against them before it leaves your building.
Technical specifications tied to an Annex I or Annex IV item, including performance thresholds, tolerances, and materials data.
Design and development documentation such as drawings, schematics, and source models that reveal how a controlled item is built.
Test and performance data, including trial results, qualification reports, and measured capability figures.
Maintenance, repair, and overhaul manuals, which pass on the working knowledge needed to keep a controlled system in service.
One project can mix all four. A tender pack for a defence contract under Directive 2009/81/EC often bundles specifications, drawings, and manuals into a single delivery, and certified defence documentation translation has to treat every part of that pack as controlled until proven otherwise.
The safeguards that actually hold
An NDA records a promise. It does not vet a person, isolate a system, or produce an audit trail. The controls that survive a BAFA or DGA inquiry are structural, not contractual. We at AD VERBUM run controlled-data translation on vetted linguists, EU-hosted infrastructure, and ISO 27001 information security, with AQAP 2110 quality records behind every defence project. The safeguards that matter:
Linguist nationality and residency vetting, so controlled material reaches only people inside the authorised scope under Article 2.
EU-hosted, single-tenant infrastructure, so files never route through public cloud tooling or a jurisdiction outside your control.
ISO 27001 access control and logging, so every touch of a controlled file is recorded for a later audit.
Pre-project classification screening against Annex I and Annex IV, so a controlled document is flagged before anyone opens it.
A licensing check with the national competent authority whenever Annex IV or an intra-EU transfer is in scope.
Miss the first item and the rest cannot save you. A perfectly logged system that hands controlled data to an uncleared linguist has still made the transfer.

Who enforces it, and what a breach costs
Enforcement sits with national authorities, not Brussels. In Germany that is BAFA, in France the DGA, in Italy UAMA. They license, inspect, and prosecute. Penalties reach past a fine: criminal prosecution of named individuals, disqualification from the bid you were translating for, and exclusion from future defence procurement. For a supplier chasing work created by Europe's defence spending surge, losing procurement eligibility is the more expensive outcome.
Where teams get caught out
Three mistakes recur, and each one is avoidable with a check that takes minutes.
Treating an NDA as an export control. It is a confidentiality contract, not a licence, and it vets no one.
Assuming intra-EU is always safe. Annex IV items need authorisation even between member states.
Running a controlled file through a public machine-translation tool, which ships the data to a third-party server in a jurisdiction you cannot audit.
The cleanest fix is to catch controlled material at intake, before a file is ever assigned. Teams that pair tender monitoring across the EEA with a classification step at the point of receipt rarely reach the licensing question in a panic the night before a deadline.
Our defense translation services
Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as AQAP 2110 quality assurance and Regulation 2021/821 controlled-data handling applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.
FAQ
What is a deemed export under EU dual-use law?
There is no separate term in EU law. The effect comes from the definition of technical assistance in Article 2 of Regulation 2021/821, which covers transmitting working knowledge about a controlled item, including by electronic means. Sharing a controlled file for translation can meet that definition.
Does sharing a file for translation count as a transfer?
It can. If the document relates to an Annex I or Annex IV item and the linguist is outside the authorised scope, transmitting it is a controlled act under Regulation 2021/821 Article 2. The file moving to an inbox is enough; nothing has to cross a physical border.
Which documents trigger dual-use controls?
Technical specifications, design and development files, test and performance data, and maintenance or repair manuals tied to Annex I or Annex IV items. The 2025 update under Delegated Regulation 2025/2003 extended the controlled list, so a document should be screened against the current Annex I, not last year's.
Is an intra-EU transfer always exempt?
No. Annex IV of Regulation 2021/821 lists the most sensitive items, and moving those between EU member states still needs authorisation. Treating "inside the EU" as automatically safe is a common and costly error.
Who are the national competent authorities?
Member states enforce the regulation through their own authorities: BAFA in Germany, the DGA in France, and UAMA in Italy. They issue licences, run inspections, and bring prosecutions, and their penalties include fines, criminal charges, and exclusion from defence procurement.
Is an NDA enough to cover controlled data?
No. An NDA is a confidentiality contract, not an export licence, and it performs no vetting. Defensible handling needs vetted linguists, EU-hosted and ISO 27001 controlled infrastructure, and a classification step before any file is assigned.