How to answer questions about Export Compliance?

Dear all,


I have an application that consumes REST web services over HTTP and HTTPS, and use AES-256 encrption for data encryption/decryption (more specifically for encrypting user password and other sensitive data). Based on this information, how do you suggest I answer questions about Export Compliance while submitting the application to the App Store?


Thanks.

The following links might be helpful:

Cryptography and U.S. Export Compliance

Most Mac and iOS applications are breaking the rules and could be removed, is yours?

How to legally submit an app to Apple’s App Store when it uses encryption (or how to obtain an ERN)


Also, see the iTunes Connect FAQs for relevant information. For example:

  • What does "trade compliance" mean on the App Store?
  • How can I include export compliance documentation with my build?
  • What do I need to know to answer each export compliance questions accurately?
  • How long does the trade compliance review take?
  • Where can I find more information on French encryption regulations?
  • Do I need to get a French import declaration if my app does not use, access, implement, or incorporate any encryption other than the encryption in iOS and/or OS X?
  • Does my app require a trade compliance review if I only distribute it on the App Store in the U.S. and Canada?
  • I am not based in the U.S. Why does my app require an encryption review?
  • I am from Germany and intend to distribute my app only on the German App Store Does my app require an encryption review?
  • Where can I get more information on the encryption registration process?
  • I use the encryption available in iOS and/or OS X. Do I still need to obtain U.S. government approval?
  • Does my app require ERN approval?
  • Does my app require CCATS approval?
  • How can I obtain the requested document from the U.S. Bureau of Industry and Security (BIS)?
  • Where can I find more information about Apple’s export process?

    Submit your questions through the iTunes Connect Contact Us page and choose export compliance from the drop down menu. Your questions will be forwarded to Apple’s Export Compliance Department and they will contact you with their response.

I suggest you answer as honestly as you can. Search the Internet for relevant definitions. Depending on what you mean be 'and other sensitive data' you may be eligible for the exemption (or whatever it is called) and can check that box and there will be no issues. Otherwise you may be SOL.

Assuming this email is still active...


If you have questions related to export compliance and your app's use of encryption, please contact the App Store Export Compliance team at appstore.ec@apple.com.

How to answer questions about Export Compliance?
 
 
Q