Export Controls on Cyber-Surveillance Technology: Regulation (EU) 2021/821 and the ARGA Position

Export Controls on Cyber-Surveillance Technology: Regulation (EU) 2021/821 and the ARGA Position

Published
October 1, 2026
Author
Khrabrykh S. A.
Original language
English

The report examines export controls on cyber-surveillance technology and the practical application of Regulation (EU) 2021/821. Its central question is how to determine what capability is actually being transferred to a particular user, whether that transfer falls within export-control rules, and what factors should be assessed when technology may be used for internal repression or serious violations of human rights or international humanitarian law.

The analysis distinguishes two principal control routes. For items listed in Annex I, the starting point is accurate technical classification. For non-listed cyber-surveillance items, Article 5 establishes a separate mechanism focused on particularly sensitive end uses. Absence from Annex I does not end the assessment, but neither does the theoretical possibility of using ordinary software for surveillance create an automatic licensing requirement. The actual functions of the supplied version, the transfer route, the end user and the intended use remain decisive.

A substantial part of the report addresses end-use due diligence. It distinguishes the purchaser, recipient, system operator and the person or body deciding whom to place under surveillance, while also examining intermediaries, remote and cloud access, software updates, technical assistance and changes in users or countries after initial approval. The report carefully separates the different thresholds under Article 5, including notification by a competent authority, exporter awareness of a sensitive intended use, and national rules that may apply where there are grounds for suspicion.

The practical model proposed by ARGA includes a functional product record, a structured transaction dossier, an unresolved-issues register, precise licence conditions, contractual and technical safeguards, event-based post-delivery review and a protected procedure for reports of abuse. Particular emphasis is placed on evidential discipline: identifying traces of a product, establishing who operated it and proving unlawful use are treated as separate conclusions that require different levels of support.

ARGA’s position is that export controls should be targeted enough to prevent grave abuse while preserving legal certainty for legitimate cybersecurity, research and commercial activity. The resulting practical standard is built around five questions: what capability was transferred, to whom, why the transfer was permissible, what facts would change that conclusion, and how the organisation would become aware of those facts.

Full text of the document
ARGA Observatory

Citation Rules

  1. Mandatory source attributionWhen using ARGA Observatory materials, the full name must be cited.
  2. Date and version indicationFor analytical reports, the year of publication is mandatory.
  3. Link to the originalElectronic materials must be accompanied by an active link to the official website.
  4. Context preservationCitations must not be shortened or altered in a way that distorts the original meaning.
  5. Note on adaptationIf the text is abridged or translated, state: "adapted from ARGA Observatory report".
  6. No commercial use without written permission from the organization
  7. Data accuracy preservationCharts and tables must be reproduced without changes.
Confidential enquiry

Ask the ARGA experts

Four short steps. We reply within one business day.

Step 1 of 4
What situation are you facing?
What stage is the case at?
Describe the situation
You can skip this field.
How should we reach you?
Your enquiry goes straight to ARGA experts. We do not publish it or pass it to third parties.
Official registration
ARGA in international registries
UNGM ID
1232417
ARGA is registered in the United Nations procurement system.
View registration
UN Global Compact
213173
Participant of the UN Global Compact.
ADB GMS Number
049963
Asian Development Bank — registered participant.
Scroll to Top