top of page
Search

Can Sending a Technical Manual to a Translator Breach EU Dual-Use Rules

  • 2 hours ago
  • 6 min read
Hands connecting an encryption device in a secure translation office

Yes. Sending a controlled technical manual to a translator can breach EU dual-use rules, and the breach happens the moment the file leaves your building. Regulation (EU) 2021/821 treats the transmission of controlled technology by electronic means as an export, so emailing an Annex I maintenance manual to a linguist outside the authorised chain is an unlicensed transfer, not a clerical step.


AD VERBUM is an EU-hosted translation company that handles dual-use and defence technical data under AQAP 2110, ISO 27001, and ISO 17100, with vetted linguists and no routing through public marketplaces or public-cloud machine translation. We built our controlled-data workflow around the Article 2 test, not around a signature on a non-disclosure agreement.


If you manage export control or bids at a defence or dual-use manufacturer, this is the exposure most localisation budgets ignore. It sits in a routine step nobody flags: handing a file to whoever translates it.


What Regulation (EU) 2021/821 controls


Regulation (EU) 2021/821 came into force on 9 September 2021 and governs the export, brokering, technical assistance, transit, and transfer of dual-use items across the EU. Dual-use items are goods, software, and technology that have both civilian and military uses. Technology is the category that catches your documentation: the information required for the development, production, or use of a controlled item, which includes technical drawings, specifications, maintenance manuals, and design files. You can read the consolidated text on EUR-Lex.


Article 2 defines the transmission of that technology by electronic means as an export. Germany's export-control authority, BAFA, puts it plainly: an export or transfer occurs if technology is sent abroad by email or phone, or if someone abroad is granted access to technology stored on your servers. A translator opening your file on a laptop in the wrong country is that access.


Why sending the manual is the transfer


The transfer is the act of sharing, not the act of publishing. You don't need to sell anything, ship anything, or file the translated document anywhere for the control to bite. Once a controlled maintenance manual reaches a linguist outside the authorised chain, the transmission is complete and, without a licence, unauthorised.


This is where the ordinary translation supply chain fails an export-control audit. A generalist agency routes a job to whichever freelancer is free, often through an open marketplace, sometimes through a public-cloud engine that stores segments outside the EU. Every hop is a possible transfer of controlled technology to an unvetted party in an uncontrolled place. None of it shows up on the invoice. The same gap undermines secure enterprise translation when it's treated as a purchasing line rather than a controlled process.


Translator desk with an encryption token and an ISO certification badge

Annex I, Annex IV, and the intra-EU trap


Two annexes decide how far the control reaches. Read them against your document before it moves:


  • Annex I lists the dual-use items controlled for export outside the EU. If your manual describes an Annex I item, sending it to a translator in a third country needs an authorisation.

  • Annex IV lists the most sensitive items, controlled even for transfer between EU member states. If your document falls under Annex IV, moving it from Germany to a translator in another member state can require a licence too.


The intra-EU point catches teams who assume "inside the EU" means "no controls." It doesn't. Commission Delegated Regulation (EU) 2025/2003, published on 14 November 2025, replaced the Annex I list with updated controls on semiconductors, quantum systems, and advanced computing. An item that was uncontrolled last year may be controlled now, so check the current annex, not last year's memory.


Who enforces it


National authorities licence and enforce these controls, and they don't share one process. Where you're established decides whose desk you deal with:


  • Germany: BAFA examines whether an export or transfer needs a licence and whether it can be granted.

  • France: the DGA and the national export-control services run the licensing regime for controlled transfers.

  • Italy: UAMA authorises controlled materials and dual-use transfers.


There is no single EU-wide licence desk, so a cross-border bid can face several regimes at once. That is one reason terminology and file control matter as much as the words, a discipline we cover in terminology governance for regulated translation.


What a breach costs


The penalty is not only a fine. An unlicensed transfer of controlled technology can bring three separate hits:


  • Administrative and criminal penalties under national law, which for serious cases in Germany can include imprisonment.

  • Disqualification from the tender you were bidding, because a live export-control breach voids your standing.

  • Exclusion from future procurement, since contracting authorities screen compliance history, as they do on EU defence tenders under Directive 2009/81/EC.


For a defence contractor, the lost bid and the closed door to future work outweigh the fine. That cost never appears in a translation price comparison, which is exactly why cheap routing looks cheap.


Linguists reviewing controlled terminology decisions at a shared desk

Why an NDA is not the control


A non-disclosure agreement binds a person to secrecy. It does not make a transfer lawful. The Article 2 test turns on who received controlled technology and where, not on whether they promised to keep quiet. You can hold a signed NDA and still have committed an unlicensed export.


The control that actually answers the test is a closed, vetted chain: linguists cleared for the material, working inside EU-hosted infrastructure, with no public-cloud transit and no open-marketplace routing. That is the workflow we run at AD VERBUM. AQAP 2110 sets NATO-grade quality assurance and configuration management, ISO 27001 governs how the data is stored and accessed, and ISO 17100 defines the certified translation process. The linguists are vetted, and the data stays on infrastructure we control. If your work reaches other markets too, the same closed chain carries into export-controlled translation and into glossary sign-off for consistent controlled terminology.


Our dual-use and defence translation services


Our translation services for regulated sectors run on ISO 27001 and ISO 42001 certified, EU-hosted infrastructure, with no reliance on public cloud tooling for core processing. Every project runs through our AI+HUMAN hybrid workflow: we ingest client Translation Memories and Term Bases first, our proprietary LLM-based LangOps System generates output constrained by client terminology on client-tuned open-weight models, and our certified subject-matter experts review for technical accuracy and regulatory compliance. Our QA is aligned to ISO 17100 and ISO 18587, with sector-specific requirements such as AQAP 2110 quality assurance and Regulation (EU) 2021/821 controlled-data handling applied where relevant. We serve Life Sciences, Legal, Finance, Defense, and Manufacturing clients across 150+ languages with 3,500+ subject-matter linguists. For teams managing audit-sensitive content, contact us to discuss your security and compliance requirements directly.


FAQ


Can emailing a technical manual to a translator really count as an export?


Yes. Regulation (EU) 2021/821 Article 2 treats transmission of controlled technology by electronic means as an export. If the manual describes an Annex I or Annex IV item, sending it to a linguist outside the authorised chain is a transfer that can require a licence, whether or not money changes hands.


Does the control apply inside the EU?


For Annex IV items, yes. Annex IV of Regulation (EU) 2021/821 lists the most sensitive dual-use items, controlled even for transfer between member states, so moving such a document from one EU country to a translator in another can need an authorisation.


What changed on 14 November 2025?


Commission Delegated Regulation (EU) 2025/2003 replaced Annex I with an updated control list covering semiconductors, quantum systems, and advanced computing. An item uncontrolled before may now be listed, so re-check the current annex against your documentation before it moves.


Who decides whether a transfer needs a licence?


The national authority where you are established. In Germany that is BAFA; France runs its regime through the DGA and national export-control services, and Italy through UAMA. There is no single EU-wide licence desk, so a cross-border project can face several at once.


Is a non-disclosure agreement enough to stay compliant?


No. An NDA binds a person to confidentiality but does not authorise a controlled transfer. Article 2 turns on who received the technology and where, so you need a vetted linguist chain on controlled infrastructure and, where required, a licence.


How does AD VERBUM handle controlled technical data?


We run a closed, vetted linguist chain on EU-hosted infrastructure under AQAP 2110, ISO 27001, and ISO 17100, with no public-cloud machine translation and no open-marketplace routing. Controlled files stay on infrastructure we control, which answers the Article 2 test an NDA alone cannot.


Recommended



 
 
bottom of page