top of page

FAQ: EU Guidelines on the Export of Cyber-Surveillance Items

Oct 17, 2024
3 min read

In October 2024, the EU published Guidelines on Export Cyber-Surveillance Items under Article 5 of Regulation (EU) 2021/82. Here are the essential FAQs that you asked us.


Questions we answer:

  • What is the purpose of the Union Export Control Framework established by Regulation (EU) 2021/821?

  • Why were these new controls introduced?

  • What are the new requirements for exporters under Regulation (EU) 2021/821?

  • What are the key legal provisions under Regulation (EU) 2021/821?

  • What key definitions should exporters understand?

  • What constitutes internal repression and human rights violations?

  • What technical aspects should exporters be aware of regarding cyber-surveillance items?

  • What due diligence measures must exporters take?

  • What are some red flags exporters should watch for?

  • What should exporters do if risks are identified?

  • Where can exporters find a summary of controlled cyber-surveillance items?


You can also download the document below.



1. What is the purpose of the Union Export Control Framework established by Regulation (EU) 2021/821?

The Union Export Control Framework ensures that the EU and its Member States meet their international obligations related to regional peace, security, and human rights. The framework includes updates to the Union Control List (Annex I) to reflect the latest multilateral decisions on export controls.


2. Why were these new controls introduced?

Before the implementation of Article 5, Member States monitored the export of certain surveillance items due to misuse risks, with some exports restricted by sanctions. The Regulation aims to prevent cyber-surveillance tools from being used for internal repression or serious human rights violations, introducing new controls on exports of non-listed cyber-surveillance items.


3. What are the new requirements for exporters under Regulation (EU) 2021/821?

Exporters must notify authorities if their due diligence indicates that items they plan to export could be used for internal repression or to commit serious human rights violations. The guidelines assist exporters in complying with these new controls by outlining necessary due diligence measures and risk assessments.


4. What are the key legal provisions under Regulation (EU) 2021/821?

  • New Export Controls: Regulation controls non-listed cyber-surveillance items potentially used for repression or human rights abuses.

  • Recital (8): Addresses risks associated with non-listed cyber-surveillance items, particularly those enabling covert surveillance.

  • Recital (9): Emphasises the need for harmonised controls and information sharing among Member States.

  • Article 2, Point 20: Defines cyber-surveillance items as tools designed for covert monitoring.

  • Article 5: Mandates export authorisation if items may be used for repression or human rights abuses, and exporters must notify authorities if risks are identified.


5. What key definitions should exporters understand?

  • Cyber-Surveillance Items: Defined as dual-use items designed for covert surveillance of individuals by monitoring, extracting, collecting, or analysing data from information and telecommunications systems.

  • Covert Surveillance: Monitoring that occurs without the subject's awareness.

  • Natural Persons: Refers to individual human beings, not organizations.

  • Monitoring/Extracting/Collecting/Analysing Data: Technical capabilities associated with cyber-surveillance.

  • Awareness: Positive knowledge of potential misuse, not just theoretical risk.


6. What constitutes internal repression and human rights violations?

According to Article 15 of the Regulation and Common Position 2008/944/CFSP:

  • Internal Repression: Actions like torture or arbitrary executions.

  • Severe Human Rights Violations: Misuse of cyber-surveillance tools that infringe on rights such as privacy and free expression, particularly against vulnerable groups.

  • International Humanitarian Law Violations: Exporters must ensure that cyber-surveillance tools are not used in armed conflicts to violate these laws.


7. What technical aspects should exporters be aware of regarding cyber-surveillance items?

The guidelines outline the need to identify both listed and potential non-listed cyber-surveillance items, including:

  • Facial and Emotion Recognition Technology: May be non-surveillance tools unless designed for covert monitoring.

  • Location Tracking Devices: Can pose surveillance risks despite legitimate uses.

  • Video Surveillance Systems: Not classified as cyber-surveillance unless combined with other technologies.


8. What due diligence measures must exporters take?

Exporters should implement due diligence measures as part of an Internal Compliance Programme (ICP), including:

  • Item Classification: Determine if products are designed for covert surveillance.

  • Transaction Risk Assessment: Evaluate potential misuse and review product specifications.

  • Review of Transactions: Assess stakeholders and end-users to mitigate risks.


9. What are some red flags exporters should watch for?

  • Items marketed for covert surveillance.

  • Previous misuse of similar items.

  • Ties of the end-user to governments with poor human rights records.

  • The item's listing in the Official Journal of the European Union for potential misuse


10. What should exporters do if risks are identified?

Exporters must:

  1. Update company policies to prevent harm.

  2. Strengthen systems to track risks.

  3. Notify authorities of high-risk items or transactions.


11. Where can exporters find a summary of controlled cyber-surveillance items?

The guidelines' appendix provides an overview of cyber-surveillance items listed in Annex I of Regulation (EU) 2021/821, helping exporters identify non-listed items that could pose surveillance risks.


Comments


Terms of Website Use

Cookie policy

Privacy policy

© 2025 by Customs Manager Ltd.

bottom of page