EU’s new export due diligence guidance: keep an eye on it
EU’s new export due diligence guidance: keep an eye on it

In 2021, the EU passed an updated version of the EU Dual-Use Regulation, setting common standards for export control of dual-use items by EU member states. Among its new provisions, Regulation (EU) 2021/821 introduces “comprehensive controls” on network monitoring projects in its Article 5. This catch-all provision requires exporters to obtain approval if they know or suspect that their cyber surveillance programs may be used to commit human rights violations, even if the programs are not specifically subject to existing export controls. Telecom interception systems (5A001.f.), Internet surveillance systems (5A001.j.), intrusion software (4A005, 4D004), and forensic tools (5A004.b., 5D002.a.3.b., 5D002.b.) etc. items. c.3.b.) are examples of technologies subject to these controls. Despite growing concerns about the misuse of spyware and other surveillance tools, such comprehensive controls have so far been rarely applied, and many exporters remain unclear about how to apply it. To address this issue, the EU published new guidance on October 15, 2024 to help exporters meet these…