Skip to main content
Shakewell

Explainer

ITAR 'Technical Data,' Explained for Publications Teams

Read the ITAR's definition of technical data and you'll recognize it immediately: it's a description of your library. Educational background for the teams who live with it — not legal advice.

The Definition

Your Library, in Regulatory Language

The International Traffic in Arms Regulations control defense articles — and, just as forcefully, the information about them. The definition (in 22 CFR Part 120) covers information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modificationof defense articles, explicitly including drawings, plans, instructions, and documentation. That's not adjacent to technical publications; that is technical publications. The manual family for a defense article sits inside the definition's plain center.

The exclusions matter equally: general principles commonly taught in schools, basic marketing information, and information properly in the public domain— with the crucial asterisk that unauthorized publication doesn't launder anything. A leaked document is still controlled; it's just also an incident. (And the whole topic is one where this page informs and your empowered official and counsel decide.)

The Operation

Control Is an Architecture, Not a Stamp

Decades of controlled technical data requiring disciplined handling
Showing controlled data to an unauthorized person can be an export without anything leaving the building — which makes access control the whole game.

Day to day, ITAR awareness for a publications operation reduces to a familiar architecture. Controlled content identified and consistently marked — alongside its distribution statement siblings. Access constrained to authorized persons, with the sobering detail that disclosure to a foreign person can constitute an export without anything crossing a border. Delivery through channels that enforce and record — not email, not the share drive, but permission-scoped platforms with audit trails, where “who saw which revision, when” has an answer. And the supply chain held to the same discipline the prime signed up for — the flow-down principle, applied to control.

The encouraging part: none of this requires exotic machinery. The same governed-delivery architecture this site argues for on every other ground — versions, permissions, page-level audit — is the export-control architecture too. Organizations that built it for operational reasons discover their compliance posture came along free. Organizations distributing controlled manuals by email discover the opposite, eventually, and never at a convenient moment.

FAQ

Questions We Hear

How does the ITAR define technical data?

In substance (the definition lives in 22 CFR Part 120): information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles — including blueprints, drawings, plans, instructions, and documentation. Read that list against a technical publications library and the overlap is nearly total: maintenance manuals, repair procedures, and IPCs for defense articles are squarely the kind of information the definition describes. Which is why export control isn't a side topic for defense tech pubs teams; it's the water they swim in. (This page is educational background, not legal advice — export determinations belong with your empowered official and counsel.)

What does the definition exclude?

Three families matter most in practice: general scientific, mathematical, or engineering principles of the kind commonly taught in schools; basic marketing information about function or purpose; and information properly in the public domain — published and generally accessible through books, patents, open conferences, or public websites via authorized release. The trap inside that last one: information published without proper authorization does not become uncontrolled just because it's accessible. A leaked or wrongly-posted document is still controlled — and now also a problem.

What does ITAR awareness mean day-to-day for a publications operation?

Knowing which content is controlled, and having systems that respect it. Practically: controlled documents identified and marked consistently (alongside their distribution statements); access limited to authorized persons — remembering that showing controlled data to a foreign person can be an export even on U.S. soil; delivery through channels with real access control and audit trails rather than email and share drives; and suppliers and partners handled under the same discipline. None of that is exotic — it's the same permission-scoped, auditable delivery architecture controlled content needs for every other reason.

Does this affect non-U.S. companies and mixed programs?

Constantly. ITAR follows the data: a non-U.S. company holding U.S.-origin controlled technical data is inside the regime's reach, retransfer requires authorization, and multinational programs live under agreements that govern exactly who may see what. For publications teams the operational consequence is the same one: per-person, per-document access control with evidence — which is why 'who saw which revision, when' recurs on this site as the question your delivery platform must always be able to answer.

Get In Touch

Controlled Content, Controlled Delivery

Your counsel decides what's controlled; we build the delivery architecture that honors the decision — scoped access, watermarking, and the audit trail that answers the hard question.