{"id":35834,"date":"2008-03-26T16:35:41","date_gmt":"2008-03-26T21:35:41","guid":{"rendered":"https:\/\/content.findlaw-admin.com\/ability-legal\/uncategorized\/summary-of-encryption-policy-update.html"},"modified":"2008-03-26T16:35:41","modified_gmt":"2008-03-26T21:35:41","slug":"summary-of-encryption-policy-update","status":"publish","type":"corporate","link":"https:\/\/corporate.findlaw.com\/law-library\/summary-of-encryption-policy-update.html","title":{"rendered":"Summary of Encryption Policy Update"},"content":{"rendered":"<section class=\"fl-gutenberg-byline\">\n    <div class=\"fl-gutenberg-byline-content\">\n                    <p><em>This article was edited and reviewed by <a href=\"https:\/\/www.findlaw.com\/company\/our-team.html\" rel=\"noopener\">FindLaw Attorney Writers<\/a><\/em><\/p>\n\n                | Last reviewed\n        <time>\n                            May 07, 2026\n                    <\/time>\n    <\/div>\n\n    \n    <details class=\"fl-gutenberg-byline-toggle fl-gutenberg-byline-legally-reviewed\">\n        <summary>\n            <i class=\"fl-gutenberg-byline-icon\" aria-hidden=\"true\"><\/i>\n            Legally Reviewed\n        <\/summary>\n\n        <div class=\"fl-gutenberg-byline-toggle-content\">\n            <p><em>This article has been written and reviewed for legal accuracy, clarity, and style by <a href=\"https:\/\/www.findlaw.com\/company\/our-team.html\" rel=\"noopener\">FindLaw\u2019s team of legal writers and attorneys<\/a> and in accordance with <a href=\"https:\/\/www.findlaw.com\/company\/company-history\/editorial-policy.html\" rel=\"noopener\">our editorial standards<\/a>.<\/em><\/p>\n\n        <\/div>\n    <\/details>\n\n    <details class=\"fl-gutenberg-byline-toggle fl-gutenberg-byline-fast-checked\">\n        <summary>\n            <i class=\"fl-gutenberg-byline-icon\" aria-hidden=\"true\"><\/i>\n            Fact-Checked\n        <\/summary>\n\n        <div class=\"fl-gutenberg-byline-toggle-content\">\n            <p><em>The last updated date refers to the last time this article was reviewed by FindLaw or one of our <a href=\"https:\/\/www.findlaw.com\/company\/our-team\/contributing-authors.html\" rel=\"noopener\">contributing authors<\/a>. We make every effort to keep our articles updated. For information regarding a specific legal issue affecting you, please <a href=\"https:\/\/lawyers.findlaw.com\/?fli=bylinelink\" rel=\"noopener\">contact an attorney in your area<\/a>.<\/em><\/p>\n\n        <\/div>\n    <\/details>\n<\/section>\n\n\n\n<div class=\"rxbodyfield\" xmlns:o=\"urn:www.microsoft.com\/office\" xmlns:st1=\"urn:www.microsoft.com\/smarttags\" xmlns:w=\"urn:www.microsoft.com\/word\" xmlns:x=\"urn:www.microsoft.com\/excel\"><p><u><strong><font face=\"Arial\">1. Release up to &quot;56 bit DES and equivalent&quot; hardware and software<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">Hardware and software exports of up to &quot;56 bits DES and equivalent&quot; products will be eligible for license exception treatment to all users and destinations (except the seven State supporters of terrorism) after a one-time technical review. No further key recovery plans or renewals of existing key recovery plans are required. This release includes up to 56 bit DES, RC2, RC4, RC5 and CAST. Products with asymmetric key sizes up to 1024 bits will be permitted. Semi-annual post-facto reporting of end users for non-mass market exports to military and government end-users will be required.<\/font><\/p><p><u><strong><font face=\"Arial\">2. Relax requirements for Key Recovery products<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">Remove from the regulations the requirement to name and review key recovery agents for exports of key recovery products. Require post-facto reporting of key recovery agents and the end users of key recovery products (currently semi-annual). Supplement 5 (Key Recovery Agent Criteria) will be removed from regulations.<\/font><\/p><p><u><strong><font face=\"Arial\">3. Sectors<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">Semi-annual post-facto reporting is required within each sector.<\/font><\/p><p><font face=\"Arial\"><u><strong>U.S. Subsidiaries:<\/strong><\/u> Approve exports of any encryption with <strong>any<\/strong> key length, with or without key recovery, to subsidiaries of U.S. companies (defined in Commerce regulation) world-wide (except the seven state sponsors of terrorism) under license exception, for the protection of internal business operations. <em>This policy will also extend favorable treatment, to &quot;strategic, partners&quot; under license.<\/em><\/font><\/p><p><font face=\"Arial\"><u><strong>Insurance Companies:<\/strong><\/u> Treat insurance companies like banks and securities firms by adding them to the definition of &quot;financial institution.&quot; The result is license exception treatment to institutions headquartered in nations listed in the recent amendments to the EAR relating to banks and financial institutions (63 FR 50156).<\/font><\/p><p><font face=\"Arial\"><u><strong>Health\/Medical:<\/strong><\/u> Permit the export under license exception of any encryption with any key length, with or without key recovery, to organizations in the strictly defined health and medical sectors (see attached definitions) located in the nations listed in the banking regulation. Exports outside the country list found in the banking regulation receive a policy of approval under Encryption Licensing Arrangements (ELAs), recognizing that certain destinations may be denied on foreign policy or other grounds. The EAR will exclude biochemical firms, pharmaceutical firms and military agencies from eligibility for the license exception. Exports to such end users are possible under individual license.<\/font><\/p><p><font face=\"Arial\"><u><strong>On-Line Merchants:<\/strong><\/u> The EAR will permit license exception treatment for the export of client-server applications (e.g., SSL) and applications tailored to on-line transactions, with any encryption algorithm and with any key length and with or without key recovery, to on-line merchants (see attached definitions), located in the country list found in the banking regulation . Exports would be limited to those that facilitate secure electronic transactions between merchants and their customers. Exports outside the country list found in the banking regulation receive a policy of approval under ELA, recognizing that certain destinations may be denied on foreign policy or other grounds. Foreign merchants (non-US owned and controlled) that sell items and services controlled on the U.S. munitions list are excluded from this policy. For merchants having separate business units, only those business units selling munitions items are excluded from this policy of approval and license exception.<\/font><\/p><p><u><strong><font face=\"Arial\">4. Recoverable Products<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">Permit exports, under Export Licensing Arrangements, of recoverable products (see attached definitions) to foreign commercial firms for internal company proprietary use, only (i.e. not sold for individual use) that are located in the following countries: <a id=\"The41\" name=\"The41\"><\/a><\/font><\/p><blockquote><blockquote><p><font face=\"Arial\">1. Austria, Australia, Belgium, Canada, Denmark, Finland, France, Germany, Iceland, Ireland, Italy, Japan, Luxembourg, The Netherlands, New Zealand, Norway, Portugal, Spain, Sweden, Switzerland, and the United Kingdom.<\/font><\/p><p><font face=\"Arial\">2. Anguilla, Antigua, Argentina, Aruba, Bahamas, Barbados, Brazil, Dominica, Ecuador, Greece, Hungary, Kenya, Monaco, Poland, Seychelles, St. Kitts and Nevis, St. Vincent\/Grenadines, Trinidad and Tobago, Turkey and Uruguay.<\/font><\/p><\/blockquote><\/blockquote><p><font face=\"Arial\">In addition, for those commercial firms headquartered in countries listed in 1 above, further permit exports, ELAs, of recoverable products to their foreign subsidiaries for internal company proprietary use in all destinations except the seven countries identified as State supporters of terrorism.<\/font><\/p><p><font face=\"Arial\">For both 1 and 2 above, this policy of approval excludes those commercial firms or separate business units of commercial firms engaged in the manufacturing and distribution of products or services controlled on the U.S. Munitions List. Service providers are also excluded from this policy. Semi-annual post export reporting of end users is required. Exports to those end users and countries not listed under this policy are possible under Validated Licenses or Export Licensing Arrangements on a case-by-case basis.<\/font><\/p><p><strong><font face=\"Arial\"><u>Definitions<\/u> (preliminary)<\/font><\/strong><\/p><p><strong><font face=\"Arial\"><u>Insurance company<\/u> means:<\/font><\/strong><\/p><p><font face=\"Arial\">a) A company organized and regulated under the laws of any of the United States and its branches and affiliates whose primary and predominant business activity is the writing of insurance or the reinsuring of risk, or<\/font><\/p><p><font face=\"Arial\">b) A company organized and regulated under the laws of a foreign country and its branches and affiliates, regulated by an insurance Commissioner or an equivalent foreign regulatory authority and whose primary and predominant business activity is the writing of insurance or the reinsuring of risks. <a id=\"HealthMedical\" name=\"HealthMedical\"><\/a><\/font><\/p><p><u><strong><font face=\"Arial\">Health\/Medical<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">Any entity, the primary purpose of which is the lawful provision of &quot;medical or other health services&quot;, not including biochemical and pharmaceutical manufacturers and military or government entities. <a id=\"On-line\" name=\"On-line\"><\/a><\/font><\/p><p><u><strong><font face=\"Arial\">On-line merchants<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">A seller of goods using electronic means (e.g., the Internet) to conduct commercial transactions and is defined to be a person that deals in goods of the kind involved in the transaction. <a id=\"Recoverable\" name=\"Recoverable\"><\/a><\/font><\/p><p><u><strong><font face=\"Arial\">Recoverable products<\/font><\/strong><\/u><\/p><p><font face=\"Arial\">1. A stored data product containing a recovery feature that, when activated, allows recovery of the plaintext<big><strong>*<\/strong><\/big> of encrypted data without the assistance of the end user; or<\/font><\/p><p><font face=\"Arial\">2. A product or system designed such that network administrator or other authorized persons who are removed from the end user can provide law enforcement access to plaintext without the knowledge or assistance of the end user. This includes, for example, products or systems where plaintext exists and is accessible at intermediate points in a network or infrastructure system, enterprise-controlled recovery systems, and products which permit recovery of plaintext at the server where a system administrator controls and\/or can provide recovery of plaintext across an enterprise, and so on.<\/font><\/p><p><big><strong>*<\/strong><\/big> <font face=\"Arial Narrow\">Plaintext indicates that data that is initially received by or presented to the recoverable product before encryption takes place.<\/font><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p> Hardware and software exports of up to &#8220;56 bits DES and equivalent&#8221; products will be eligible for license exception treatment to all users and destinations (except the seven State supporters of terrorism) after a one-time technical review. No &#8230;<\/p>\n","protected":false},"template":"","meta":{"_acf_changed":false,"_stopmodifiedupdate":true,"_modified_date":"","_cloudinary_featured_overwrite":false},"corporate_categories":[6512,6497],"class_list":["post-35834","corporate","type-corporate","status-publish","hentry","corporate_categories-law-library__international-law","corporate_categories-law-library"],"acf":[],"_links":{"self":[{"href":"https:\/\/corporate.findlaw.com\/legal-api\/wp-json\/wp\/v2\/corporate\/35834","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/corporate.findlaw.com\/legal-api\/wp-json\/wp\/v2\/corporate"}],"about":[{"href":"https:\/\/corporate.findlaw.com\/legal-api\/wp-json\/wp\/v2\/types\/corporate"}],"wp:attachment":[{"href":"https:\/\/corporate.findlaw.com\/legal-api\/wp-json\/wp\/v2\/media?parent=35834"}],"wp:term":[{"taxonomy":"corporate_categories","embeddable":true,"href":"https:\/\/corporate.findlaw.com\/legal-api\/wp-json\/wp\/v2\/corporate_categories?post=35834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}