• videocam Live Webinar with Live Q&A
  • calendar_month September 10, 2026 @ 1:00 PM ET/10:00 AM PT
  • signal_cellular_alt Intermediate
  • card_travel International
  • schedule 90 minutes

Cloud Computing and National Security Regulation: Complying With the ITAR, EAR, Sanctions, and Data Security Laws

About the Course

Introduction

This CLE course will provide international trade counsel with a review of the compliance challenges under U.S. export controls, economic sanctions, and data security regulations for cloud users and providers. The panel will offer best practices to meet the requirements of the International Traffic in Arms Regulations (ITAR), Export Administration Regulations (EAR), Office of Foreign Assets Control (OFAC) sanctions regulations, and the Department of Justice's Data Security Program (DSP) regulations. 

Description

Storing data in the cloud creates significant legal challenges for companies. Cloud data may be located on servers housed in different countries, or managed by non-U.S. entities or using non-U.S. personnel. Uploading data to a server outside the U.S. is considered an export and may require authorization. Furthermore, recent guidance under the EAR creates questions about the extent of diligence that will suffice when providing remote access to EAR-controlled advanced computing items. The location of the users accessing the information and cloud administrators' nationality also present compliance risks. Additionally, use of U.S. cloud infrastructure can give rise to OFAC jurisdiction in transactions that otherwise have no U.S. nexus. Moreover, the DSP regulations impose requirements and restrictions on providing access to certain types of data outside the U.S., including in cloud environments. 

With the prevalence of storing information in the cloud and penalties for violating the ITAR, EAR, OFAC regulations, or other potentially severe national security restrictions, companies that use or provide cloud computing services must understand the limitations and requirements when using cloud computing to remain in compliance with these complex regulations.

Listen as our authoritative panel reviews these U.S. national security regulations that impact cloud computing, examines the compliance challenges for cloud users and providers, and offers best practices to meet the ITAR, EAR, OFAC, and DSP requirements.

Presented By

Evan T. Abrams
Partner
Steptoe LLP

Mr. Abrams counsels financial institutions, multinational corporations, and individuals on a variety of international regulatory and compliance matters. He regularly advises clients on issues related to anti-money laundering (AML), economic sanctions, export controls, foreign anti-corruption, the Committee on Foreign Investment in the United States (CFIUS), and the Defense Counterintelligence and Security Agency (DCSA). Among other sectors, his practice focuses on emerging technology and financial technology where he leverages his deep understanding of business trends and technological developments to help clients achieve their commercial objectives while complying with complex regulatory regimes.

Michael T. Gershberg
Partner
Fried Frank Harris Shriver & Jacobson LLP

Mr. Gershberg's practice focuses on the representation of foreign and domestic clients regarding the application of economic sanctions and export control laws and regulations, including EAR, ITAR, and economic sanctions administered by the OFAC. He also advises clients on their obligations under the antiboycott and anti-money laundering rules. Mr. Gershberg's work in the export control and economic sanctions area includes advocacy before governmental agencies, conducting internal investigations, and preparing voluntary self-disclosures and other legal submissions. He also assists clients in connection with export transactions and enforcement issues, due diligence for M&As, economic sanctions and export control training, determining export jurisdiction and classification, developing compliance plans and providing compliance counseling, and export licensing.

Peter E. Jeydel
Partner, Sanctions & Trade Controls Group Leader
Troutman Pepper Locke LLP

Mr. Jeydel focuses his practice on US export controls and economic sanctions, including counseling, compliance, transactional advice, licensing and opinions, jurisdiction and classification assessments, disclosures, and enforcement actions. In addition, he assists clients in anti-corruption matters, including under the Foreign Corrupt Practices Act (FCPA), and has experience handling reviews and investigations by the Committee on Foreign Investment in the United States (CFIUS). Prior to joining the firm, Mr. Jeydel worked on Central Asia policy in the Office of the Secretary of Defense (OSD). At OSD, he focused on the war in Afghanistan, working with governments and private sector entities in the surrounding region, from the Persian Gulf to the Caucasus, to Russia and China, and in particular the former Soviet states of Central Asia and Pakistan.  

Credit Information
  • This 90-minute webinar is eligible in most states for 1.5 CLE credits.


  • Live Online


    On Demand

Date + Time

  • event

    Thursday, September 10, 2026

  • schedule

    1:00 PM ET/10:00 AM PT

I. Applicable export controls, economic sanctions, and data security regulations

A. ITAR

B. EAR

C. OFAC

D. DSP

II. Compliance challenges

A. For cloud users

B. For cloud providers

III. Best practices for compliance

The panel will review these and other key issues:

  • What is BIS, DDTC, OFAC, and DOJ guidance on compliance for cloud services?
  • What compliance challenges do cloud users and providers face?
  • What best practices should cloud providers, users, and their counsel employ to ensure compliance with the ITAR, EAR, OFAC, and DSP requirements?