Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Data Breach: OFAC Settles with Swiss Firm over Digital Services for Sanctioned Airlines

By Wendy Wysong, Ali Burney, Nicholas Turner, Ed Krauland, Brian Egan, Meredith Rathbone, Peter Jeydel & Evan Abrams on March 3, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

On February 26, 2020, the Office of Foreign Assets Control (OFAC) announced a $7,829,640 settlement with Switzerland-based Société Internationale de Télécommunications Aéronautiques (SITA) for 9,256 violations of the Global Terrorism Sanctions Regulations (GTSR). The settlement, which concerns SITA’s provision of computer services and software subject to U.S. jurisdiction for the benefit of sanctioned airlines, is the latest OFAC enforcement action to highlight the importance of sanctions compliance for software and digital service providers inside and outside the United States.

The takeaway: Non-U.S. providers of software and digital services should avoid the provision of U.S.-origin products or the involvement of U.S.-based infrastructure or subsidiaries in activities with U.S.-sanctioned customers and territories, unless licensed under, or exempted from, OFAC regulations.

High-Risk Customers

SITA provides telecommunications and IT services to civilian airlines, including reservation, flight operations, baggage and cargo handling, and messaging services, among others. According to the OFAC settlement notice, some of SITA’s services “are provided from or supported in the United States,” including servers operated by SITA’s U.S.-based subsidiary.

From April 2013 to February 2018, SITA operated three services that “benefited the . . . airlines, directly or indirectly” and which relied on data processing or servers located in the United States or U.S.-origin software. Prior to the initiation of OFAC’s investigation, SITA took steps to reduce its exposure to the SDGT airlines, including by reviewing contracts and terminating some services other than the three services at issue in the settlement.

Digital Jurisdiction  

In its settlement notice, OFAC explained its enforcement jurisdiction as follows: “These services and software were subject to U.S. jurisdiction because they were provided from, or transited through, the United States or involved the provision of U.S.-origin software with knowledge that customers designated as SDGTs would benefit from the use of that software.” (Emphasis added.)

Rather than giving SITA credit for having reduced its exposure to the SDGT airlines, OFAC appears to have taken the opposite position —that these moves showed that the company had “actual knowledge” that they were providing the remaining services and software directly or indirectly for the benefit of the SDGTs. In other words, the SITA settlement does not appear to be a case in which sanctioned persons accessed online services unbeknownst to the provider.

While the basis for OFAC’s jurisdiction over U.S.-origin software is not fully elaborated, the settlement appears to reflect a view that dealings in US-origin software outside the United States may be viewed as involving US persons for the purposes of the GTSR.

Although not directly at issue in the case, the settlement may also raise questions about the limits of OFAC’s so-called “inventory exception” under the Iranian Transactions and Sanctions Regulations (ITSR), which, in summary, permits non-U.S. distributors to provide some U.S.-origin products and services to sanctioned persons or territories, where the U.S.-origin goods or services were not obtained specifically or predominantly for that purpose. As shown in other cases, such as OFAC’s settlement with California-based Epsilon Electronics, OFAC may view the inventory exception as not applying where an enforcement target knew or should have known of the involvement of sanctioned customers or territories when engaging in exports from the United States.

Compliance and Technology

Like non-U.S. financial institutions, software and digital service providers can face considerable OFAC risks owing to the complexity of data networks with a potential nexus to the United States and the difficulty of identifying particular parties or other details of high frequency of online transactions for the purpose of sanctions compliance screening.

For example, in November 2015, a California-based company paid $38,930 to settle violations involving web-based software sold by a UK subsidiary to customers in Iran, Sudan, and Syria. In January 2017, a Canadian financial institution received a finding of violation of OFAC’s Iran and Cuba sanctions regulations in relation to online services provided through a Luxembourg-based subsidiary. In November 2019, a U.S.-based technology company paid $466,912 to settle violations of the Foreign Narcotics Kingpin Sanctions Regulations for providing online services to a Specially Designated National (SDN) based in Slovenia.

U.S. technology companies and non-U.S. companies that rely on U.S.-origin software or digital infrastructure in the United States are advised to implement risk-based sanctions compliance programs incorporating, at a minimum, name screening controls to identify sanctioned customers (including any ultimate or beneficial owners) and, to the extent possible, geographical (e.g., country code top-level domain or IP address) screening to identify users located in or otherwise affiliated with territories subject to U.S. comprehensive sanctions (i.e., Crimea, Cuba, Iran, North Korea, and Syria).

The statutory maximum civil monetary penalty applicable in SITA’s case was approximately $2.45 billion. The final penalty reflects OFAC’s determination that the case was “non-egregious” and the agency’s assessment of various mitigating factors, including SITA’s “extensive remedial efforts and enhancements to its compliance program,” and that SITA terminated its relationships with the SDGT airlines.

For more analysis on sanctions risks for non-U.S. companies with operations in the United States, see this April 2015 Steptoe Client Advisory.

For guidance on how OFAC regulations may apply to your company’s software or digital services inside or outside the United States, contact a member of Steptoe’s economic sanctions team.

Photo of Ed Krauland Ed Krauland

Edward J. Krauland focuses on export controls/economic sanctions. Ed’s extensive experience includes representing clients on matters involving US and multilateral economic sanctions, defense and nuclear export controls, dual-use export controls under the EAR, anti-boycott compliance, internal investigations and enforcement work, and review of…

Edward J. Krauland focuses on export controls/economic sanctions. Ed’s extensive experience includes representing clients on matters involving US and multilateral economic sanctions, defense and nuclear export controls, dual-use export controls under the EAR, anti-boycott compliance, internal investigations and enforcement work, and review of government procurement regulations in the cross-border context. His practice spans all aspects of these laws, including counseling, compliance work, transactional advice, licensing and opinion work, internal reviews, disclosures, and enforcement actions. He has served as co-chair of the International Trade Committee of the ABA Section of International Law and Practice. He is former Chairman of an ABA-wide Task Force on Gatekeeper Regulation (anti-money laundering compliance), and senior adviser to the ABA Section of International Law and Practice’s anti-money laundering committee.

Read Ed’s full bio.

Read more about Ed KraulandEmail
Show more Show less
Photo of Brian Egan Brian Egan

Brian Egan advises on a number of international legal issues that affect US and foreign clients, including economic sanctions, export controls, and anti-money laundering programs; national security trade and investment reviews; international arbitration and other cross-border disputes; international cybersecurity and data privacy; and…

Brian Egan advises on a number of international legal issues that affect US and foreign clients, including economic sanctions, export controls, and anti-money laundering programs; national security trade and investment reviews; international arbitration and other cross-border disputes; international cybersecurity and data privacy; and issues of public international law. He has worked in various senior legal positions for the US government, giving him keen insight into domestic and international legal matters that influence US government national security and foreign relations policies and programs. Before joining Steptoe, Brian served as the Legal Adviser to the US Department of State, the Legal Adviser to the National Security Council, Deputy White House Counsel, and Assistant General Counsel for Enforcement and Intelligence with the US Department of the Treasury. Brian has regularly appeared in public fora to speak on international legal issues, including testifying before Congress, public speaking engagements, and panel presentations.

Read Brian’s full bio.

Email
Show more Show less
Photo of Meredith Rathbone Meredith Rathbone

Meredith Rathbone focuses on export controls and economic sanctions, and has assisted clients in the energy, manufacturing, telecommunications, information security, banking, insurance, pharmaceutical, and service industries, among many others, in navigating the requirements of the Export Administration Regulations (EAR), International Traffic in Arms…

Meredith Rathbone focuses on export controls and economic sanctions, and has assisted clients in the energy, manufacturing, telecommunications, information security, banking, insurance, pharmaceutical, and service industries, among many others, in navigating the requirements of the Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR) and US sanctions regulations administered by the Office of Foreign Assets Control (OFAC) and US Department of State. She regularly assists companies in developing compliance policies, conducting internal investigations, performing training, and conducting due diligence in M&A transactions. She has represented individuals and companies facing civil and criminal investigations in this area, and has also represented clients in their efforts to be removed from OFAC’s list of Specially Designated Nationals (SDNs). She is a frequent writer and speaker on export controls and sanctions topics. She is the co-chair of the American Bar Association’s Export Controls and Economic Sanctions Committee, and also serves on the Sanctions Subcommittee of the State Department’s Advisory Committee on International Economic Policy.

Read Meredith’s full bio.

Read more about Meredith RathboneEmail
Show more Show less
Photo of Peter Jeydel Peter Jeydel

Peter Jeydel‘s practice focuses on US export controls and economic sanctions, including the Commerce Department’s Export Administration Regulations (EAR), the State Department’s International Traffic in Arms Regulations (ITAR), and sanctions regulations administered by the Treasury Department’s Office of Foreign Assets Control (OFAC)…

Peter Jeydel‘s practice focuses on US export controls and economic sanctions, including the Commerce Department’s Export Administration Regulations (EAR), the State Department’s International Traffic in Arms Regulations (ITAR), and sanctions regulations administered by the Treasury Department’s Office of Foreign Assets Control (OFAC) and the State Department. His practice spans all aspects of these regimes, including counseling, compliance, transactional advice, licensing and opinions, disclosures, and enforcement actions. He has also represented companies and individuals seeking de-listing from OFAC’s sanctions list. In addition, Pete has assisted clients in anti-corruption matters, including under the US Foreign Corrupt Practices Act (FCPA), and has experience handling reviews and investigations by the Committee on Foreign Investment in the United States (CFIUS).

Read Pete’s full bio.

Read more about Peter JeydelEmail
Show more Show less
Photo of Evan Abrams Evan Abrams

Evan Abrams counsels multinational corporations, financial institutions, and individuals on various international regulatory and compliance matters. He assists foreign and domestic companies in navigating national security reviews by the Committee on Foreign Investment in the United States (CFIUS). He has represented companies in…

Evan Abrams counsels multinational corporations, financial institutions, and individuals on various international regulatory and compliance matters. He assists foreign and domestic companies in navigating national security reviews by the Committee on Foreign Investment in the United States (CFIUS). He has represented companies in industries including semiconductors, metals, and digital security. Evan’s anti-money laundering (AML) practice focuses on helping financial institutions comply with federal and state AML rules, particularly money transmitters and entities involved in creating, exchanging, or dealing in cryptocurrencies and tokens. Evan counsels clients in a variety of export controls and sanctions matters related to the Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR), and various sanctions programs under US and international law. In addition, Evan routinely assists clients on anti-corruption investigations and enforcement actions.

Read Evan’s full bio.

Read more about Evan AbramsEmail
Show more Show less
  • Posted in:
    Administrative and Regulatory
  • Blog:
    International Compliance Blog
  • Organization:
    Steptoe LLP

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo