Export Control Reform: BIS Finalizes Strategic Trade Authorization License Exception
Client Alert | 2 min read | 06.17.11
On June 16, 2011, as part of the President's Export Control Reform Initiative, the Department of Commerce's Bureau of Industry and Security (BIS) issued a final rule (76 Fed. Reg. 35276) amending the Export Administration Regulations (EAR) to include a new license exception. In what BIS is characterizing as "an initial step in a broad export control reform effort," the Strategic Trade Authorization (STA) license exception will authorize the export, reexport, and in-country transfer of specific items to destinations where the administration has determined there is a relatively low risk of diversion.
In the final rule, BIS addressed the 41 comments it received in response to the December 9, 2010 proposed rule, and made several substantive changes, including to what items and destinations are eligible for the exception. Under the final rule, items controlled for reasons of encryption items (EI), short supply (SS), surreptitious licensing (SL), missile technology (MT), or chemical weapons (CW) are ineligible for STA treatment, and STA is not available for exports to prohibited end-users or end-uses, or to embargoed destinations. Finally, a number of items classified under particular ECCNs have either been removed from STA eligibility or are subject to additional requirements or limitations under STA.
Exporters invoking License Exception STA will have to meet certain conditions, including: furnishing the consignee with the ECCN for the exported item(s); obtaining written certifications from the consignee in advance of the export; and providing notification to the consignee that the export is being made pursuant to STA. Alternative requirements may apply for releases of software source code or technology within a single country. Finally, some exports made pursuant to STA will need to comply with the Wassenaar reporting requirements set forth in section 743.1 of the EAR.
Time will tell if STA truly lightens licensing burdens for exporters. The public comments BIS received after releasing the proposed rule were split between those that felt the STA would decrease licensing and those that believed STA was either inapplicable to their business models or too onerous to effectively ease their licensing burdens. Regardless of STA's eventual effectiveness (or lack thereof), this final rule reflects BIS's recognition that some license requirements simply are not justified by U.S. national security and foreign policy. Such recognition and rulemaking, even if only a small first step, demonstrates progress towards actual, broad export control reform.
Contacts
Insights
Client Alert | 5 min read | 08.21.26
FTC Proposes Enforcement Policy Statement on Personalized Pricing: What Businesses Need to Know
On August 19, 2026, the Federal Trade Commission (FTC) announced a proposed Enforcement Policy Statement on personalized pricing — the practice of companies using consumers’ personal data to set individualized prices, discounts, coupons, or other incentives. The proposed statement, which is open for public comment for 30 days following publication in the Federal Register, marks a major step up in the FTC’s focus on data-driven pricing strategies and puts businesses across industries on notice that undisclosed or inadequately disclosed personalized pricing will not be tolerated. Importantly, while the proposed statement is not a binding legal requirement and does not create new legal obligations, it serves as an enforcement warning that the FTC is prepared to use its existing enforcement authority under Section 5 of the FTC Act (Section 5) and is also a potential harbinger of rulemaking. Businesses that engage in — or are considering — personalized pricing should carefully assess their disclosure practices and data collection procedures against the standards articulated in this statement.
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
Client Alert | 2 min read | 08.19.26
Client Alert | 7 min read | 08.17.26
Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

