Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

clarify export compliance information for ios #515

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

menaechmi
Copy link
Contributor

I think something like this should address the ios issues. Defold-engine only code meets the exemption requirements for the US, EU, and France. It's unlikely but possible that someone creates a project that would change that.

As for the French declaration - an in-depth look of the requirements are in the details below. But it is a mistake on Apple's part to be requiring the document for all apps with cryptography in France.

I included the link to the form, because it's more than Apple provides, but I didn't feel instructions for filling it out were appropriate for the manual - where would it go best?

Closes #322

Analysis of each country's law

US Rules

Per https://www.bis.doc.gov/index.php/all-articles/15-policy-guidance/encryption/560-encryption-faqs#15

Examples of items that are excluded from Category 5, Part 2 by Note 4 include, but are not limited to, the following:
Consumer applications. Some examples:
piracy and theft prevention for software or music;
music, movies, tunes/music, digital photos – players, recorders and organizers
games/gaming – devices, runtime software, HDMI and other component interfaces, development tools
printers, copiers, scanners, digital cameras, Internet cameras – including parts and sub-assemblies
household utilities and appliances

Additionally, the use of industry standard algorithms means US export requirements do not apply to Defold.

French Rules

Per https://cyber.gouv.fr/controle-reglementaire-sur-la-cryptographie-demarches-accomplir
Use in France requires no declaration to ANSSI (Utilisation en France). Import might (Importation en France).

Either way, the table of exceptions specifies that Protection against duplication is exempt for any operation (Protection contre la duplication - Exemption pour toute opération).

For confirmation: Décret n°2007-663 du 2 mai 2007

Chapter 1 Article 1 states that usage of cryptology in Annex 1 is exempt from the processes of the law.

Sont dispensées des formalités préalables prévues aux chapitres II et III du présent décret les opérations de fourniture, de transfert, d'importation ou d'exportation des moyens et prestations de cryptologie mentionnées à l'annexe 1 du présent décret.

Annex 1, Category 6: Equipment designed to limit the protection of software or computer data against copying or illegal use and the cryptography is not accessible to the user.

Equipements spécialement conçus et limités pour assurer la protection de logiciels ou de données informatiques contre la copie ou l'utilisation illicite et dont la capacité cryptographique n'est pas accessible à l'utilisateur.

French law is of course also compliant to EU law:
Delegated Regulation (EU) No 1382/2014

Category 5 – Part 2 does not control items incorporating or using “cryptography” and meeting all of the following:
a. The primary function or set of functions is not any of the following:

  1. “Information security”;
  2. A computer, including operating systems, parts and components therefor;
  3. Sending, receiving or storing information (except in support of entertainment, mass commercial broadcasts, digital rights management or medical records management); or
  4. Networking (includes operation, administration, management and provisioning);
    b. The cryptographic functionality is limited to supporting their primary function or set of functions;

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Add clarification and course of action for Apple export compliance
1 participant