Skip to content
Share

SecurePoint Education · Regulatory analysis

Education
October 4, 2026

Section 117 Is Becoming a Data-Governance Problem, Not Just a Reporting Problem

The court fight over foreign-donor identities shows why universities need to keep collection, screening, institutional review, federal reporting, and public disclosure as separate, governed steps.

Published
October 4, 2026
Reading time
11 minutes
Case status
TRO in effect through Oct 29

On October 1, 2026, the Association of American Universities asked a federal court to stop the U.S. Department of Education from publishing the identities of foreign donors and contract counterparties that its member universities had reported under Section 117 of the Higher Education Act. The same day, after a hearing, Judge Tanya S. Chutkan of the U.S. District Court for the District of Columbia issued a temporary restraining order. The Department had scheduled the release for October 2.

The case will draw attention for its politics. The more durable lesson is operational, and it holds no matter how the litigation ends. Every vice president for research, general counsel, controller, and research-security officer should be able to answer one question for their own institution:

What happens to sensitive foreign-source information between the moment a university receives it and the moment it is reported, reviewed, retained, or disclosed?

At many institutions, the honest answer depends on which office you ask. That is the problem this article is about.

The record

What happened

Section 117 (20 U.S.C. § 1011f) requires institutions that receive federal financial assistance to disclose foreign gifts and contracts worth $250,000 or more from a single foreign source in a calendar year, counted alone or in combination. Reports are filed on January 31 or July 31, and the statute makes all disclosure reports public records.

The statute itself asks for amounts and the country a gift is attributable to, with more detail for restricted or conditional gifts. The Department’s reporting instructions go further and ask institutions for the name and address of each foreign source. According to AAU, the Department assured institutions and donors in writing for years that this identifying information would remain confidential and be used to verify compliance.

That posture changed in 2026. In April, the Department proposed a revised information collection, and higher-education associations objected in June that it would allow donor names to be made public. In July, the Department announced it would publish “the names of all foreign sources from prior reporting cycles.” The date moved several times. On July 15 it published a narrower list of 92 foreign entities that also appear on U.S. government lists, and it later set October 2 for the broader release.

AAU filed suit on October 1 against the Departments of Education and State and their secretaries. The State Department has supported Section 117 administration under an interagency agreement signed in February 2026. AAU argues that the statute does not call for publishing private donors’ personal information, that the Constitution protects donors from compelled public exposure of their charitable associations, and that the reversal came without notice to affected donors and without the rulemaking the law requires. The Department has described publication as consistent with Section 117’s transparency requirements.

Case at a glance

Case
Association of American Universities v. U.S. Department of Education, et al.
Court
U.S. District Court for the District of Columbia, No. 1:26-cv-03438
Defendants
U.S. Department of Education, U.S. Department of State, Secretary of Education Linda McMahon, Secretary of State Marco Rubio
Filed
October 1, 2026
Order
Temporary restraining order granted October 1, 2026, by Judge Tanya S. Chutkan
Expires
October 29, 2026, unless the court extends it
Next
Government's preliminary-injunction response due October 13; AAU's reply due October 20

What the order does

  • Bars the government from publishing the names or other identifying information of foreign donors and contract counterparties reported by AAU member institutions under Section 117.
  • Took effect immediately.
  • Lasts until October 29, 2026, unless the court extends it.
  • Rests on a preliminary finding that AAU is likely to succeed on its Administrative Procedure Act claim.

What it does not do

  • Strike down or suspend Section 117.
  • Change what institutions report or when. The next statutory filing date is January 31, 2027.
  • Decide the case on the merits.
  • Reach institutions outside AAU's membership, as AAU describes the order.

In granting the order, the court found AAU likely to succeed on its claim that publishing after six years of written assurances to the contrary was arbitrary and capricious, and found that publication could cause irreparable harm. The practical logic is plain: once a name is published, it cannot be unpublished. That is why the order preserves the status quo while the court considers a preliminary injunction.

How we got here

  1. Apr 23, 2025

    Executive Order 14282 directs stronger Section 117 enforcement and transparency.

  2. Jan 2, 2026

    A new Section 117 reporting portal goes live.

  3. Feb 2026

    Education and State sign an interagency agreement; State begins supporting Section 117 administration.

  4. Apr 15, 2026

    The Department proposes a revised Section 117 information collection.

  5. Jun 15, 2026

    Higher-education associations file comments objecting to publication of donor names.

  6. Jul 6, 2026

    The Department announces it will publish the names of all foreign sources from prior reporting cycles.

  7. Jul 15, 2026

    It publishes the names of 92 foreign entities that also appear on U.S. government lists. The broader release is postponed.

  8. Sep 25, 2026

    The broader release is rescheduled for October 2.

  9. Oct 1, 2026

    AAU sues. The court grants a temporary restraining order the same day.

SecurePoint analysis

The distinction universities cannot afford to blur

Collection is not screening. Screening is not review. Review is not reporting. Reporting is not publication.

Five activities. Five owners. Five different questions about the same information.

Most foreign-source problems start when these five activities are treated as one.

Collection is the moment information enters the institution: a gift agreement in advancement, a wire in finance, a sponsored-research contract, a faculty appointment, a department’s agreement with a foreign university. Collection has its own questions: what was captured, from whom, for what purpose, and who can see it.

Screening checks parties against relevant authoritative sources, such as the OFAC Specially Designated Nationals List or the BIS Entity List, when the relationship calls for it. A screen produces a result, not a conclusion. A potential match is a reason to look closer.

Institutional review is where people with authority decide what a relationship means: whether a counterparty is governmental, whether conditions attach, whether research-security or export-control review is needed, and whether to escalate. It is a human determination, and it should leave a record.

Federal reporting is providing what Section 117 and the Department’s current instructions require, on the statutory schedule. It rests on a specific legal authority, and that authority defines its scope.

Publication is making information public. It is a different act, governed by a different authority, and as of this writing the subject of active litigation. Information reported to the government is not, by that fact alone, information the public receives.

A compliance system has to keep these as separate states of the same record. When a screening hit, a reviewer’s note, a reported field, and a published field collapse into one spreadsheet column, the institution can no longer show what was decided, what was submitted, or what was ever meant to be public.

Figure 1

Five stages. Four gates. No automatic pass-through.

  1. 1

    Collection

    Information enters from advancement, finance, sponsored research, contracts, and academic departments.

    Governed by: Institutional data policy and the purpose the information was collected for.

    GATEPurpose and need-to-know
  2. 2

    Screening

    Parties are checked against relevant sanctions and restricted-party sources when the relationship calls for it.

    Governed by: The applicable lists and the institution's screening policy.

    GATEA match is not a decision
  3. 3

    Institutional review

    People with authority decide what the relationship means and whether it needs escalation.

    Governed by: Internal policy, research-security and export-control review, and conflict rules.

    GATEReporting authority: § 1011f
  4. 4

    Federal reporting

    Required information goes to the Department of Education on the statutory schedule.

    Governed by: Section 117 and the Department's current reporting instructions.

    GATEPublication authority: contested
  5. 5

    Public disclosure

    Information is made public.

    Governed by: A separate authority and policy decision, now in active litigation.

Each gate is a decision point with its own owner and its own legal or policy basis. Stage names describe common institutional activities, not statutory terms.

SecurePoint analysis

Why this is a data-governance issue

Section 117 used to look like a finance exercise: total the foreign gifts and contracts twice a year and file. The information now in play is more sensitive and more structured than that:

  • Donor identities, including donors who asked the institution for anonymity
  • Source classifications: individual, company, university, government entity, state-owned organization, or an intermediary acting for someone else
  • Country attribution, which can turn on citizenship, residence, or place of incorporation
  • Agreements, payments, and the conditions attached to them
  • Access: who inside the institution can see identifying information, and why
  • Provenance: where each fact came from, and whether it was later corrected
  • Version history: which Department instructions applied when a field was completed
  • What was submitted to the Department and, separately, what was made public

None of that is generic cybersecurity. It is record governance. Federal handling of Section 117 has shifted repeatedly in 2026: a new reporting portal in January, a proposed information collection in April, a process for amending historical submissions in June, and a run of announced publication dates from July to October. A reviewer who classified a counterparty in 2023 applied 2023 instructions. If the institution cannot show which rule applied at the time, it will struggle to defend the determination later.

The reconstruction test

For any foreign-source relationship, the institution should be able to answer:

  1. 01What did we know?
  2. 02When did we know it?
  3. 03Where did the information come from?
  4. 04Who reviewed it?
  5. 05What rule or guidance applied?
  6. 06What did we submit?
  7. 07What did we disclose?

If the answers live in five systems and three inboxes, the institution has a reporting process. It does not yet have a governed record.

SecurePoint analysis

The connection to research security

Section 117 increasingly sits beside research security in daily practice. In July 2026, the Department published a list of foreign entities from Section 117 data that also appear on U.S. government lists, and the State Department wrote to the governing boards of R1 universities about reported funding from counterparties on cautionary and restricted U.S. government lists. Recent federal foreign-funding investigations have requested records well beyond gift ledgers, including faculty agreements, research collaborations, and participation in foreign talent programs. We walked through one such records request in an earlier analysis.

One foreign organization

Five records, often in five offices

  • Donation recordAdvancement
  • Sponsored-research agreementResearch administration
  • Faculty affiliationFaculty affairs
  • Export-control reviewExport control
  • Restricted-party screening resultCompliance

The same foreign organization may appear in a donation record, a sponsored-research agreement, a faculty affiliation, an export-control review, and a restricted-party screening result. Those records should not live as five unrelated facts.

When they do, the institution answers the same question five times, sometimes in five different ways. Advancement may record a counterparty as a private foundation while research administration treats the same organization as state-affiliated. Neither office is necessarily wrong; each may be applying a different rule for a different purpose. The governance failure is that no one can see both answers side by side, or explain the difference when asked.

Connecting the records does not mean merging the legal questions. They stay distinct:

  • Foreign relationship ≠ wrongdoing

    A foreign gift, contract, or collaboration is not, by itself, evidence of wrongdoing.

  • Section 117 reporting ≠ sanctions compliance

    A complete filing says nothing about whether a party is sanctioned.

  • Sanctions screening ≠ Section 117 reporting

    Screening a donor does not satisfy a disclosure obligation.

  • A list match ≠ an unlawful transaction

    Some U.S. government lists prohibit dealings outright. Others restrict specific activities, such as exports, or call for closer review.

  • Research-security review ≠ export-control determination

    A risk review is not a classification or license decision under the EAR or ITAR.

SecurePoint analysis

What universities should be building now

None of this requires waiting for the court. These ten capabilities hold up under any outcome:

  1. 01

    A normalized foreign-source record

    One entry per source, with legal name, aliases, source type, and country attribution, instead of free-text names copied between systems.

  2. 02

    Relationship records

    Links from each source to the people, organizations, projects, agreements, payments, and funding it touches.

  3. 03

    Source provenance

    Which system or document each fact came from, and when it arrived.

  4. 04

    Screening history

    Which lists were checked, when, against which list versions, and with what result.

  5. 05

    Human review and disposition records

    Who reviewed, what they decided, and why, in the reviewer’s own words.

  6. 06

    Rule and version history

    The statute, Department instructions, and internal policy in force when each determination was made.

  7. 07

    Reporting history

    Exactly what was submitted for each reporting period, including later amendments.

  8. 08

    Disclosure classification

    For each field: internal only, reportable to the government, or approved for public release, and on what authority.

  9. 09

    Role-based access

    Identifying information visible only to people whose role requires it, with access logged.

  10. 10

    Evidence retention

    The record and its supporting documents, kept on a defined schedule that meets the longest applicable requirement.

The pattern across all ten is the same: keep the fact, the decision, and the disclosure as separate things, each with an owner and an audit trail.

SecurePoint Education

Where SecurePoint Education fits

SecurePoint Education is built on a simple premise: compliance decisions should not disappear into spreadsheets, email threads, and one-time searches.

Its existing workflow foundation is designed around people, organizations, screening evidence, human review, monitoring, and retained records. That is the screening and review layer described above, and for each party screened, it preserves what a reviewer decided, when, and why.

What it does today

  • Screens people and organizations, including donors, sponsors, payors, researchers, faculty, vendors, and foreign institutions, against sanctions and restricted-party sources such as the OFAC SDN List and the BIS Entity List.
  • Routes potential matches to human case review, where reviewers record decisions and notes.
  • Re-screens active parties on a 30- or 90-day schedule.
  • Retains screening evidence, ten years by default, and exports it as evidence packs.

What it does not do

  • File Section 117 reports with the Department of Education.
  • Decide whether a gift or contract is reportable.
  • Determine what an institution may disclose publicly.
  • Provide legal advice.

It is not a Section 117 reporting system. Decisions about what is reportable, and what may be disclosed, belong to the institution and its counsel. SecurePoint’s job is to preserve the screening and review evidence those decisions rest on.

Looking ahead

As foreign-source and research-security expectations evolve, those same foundations can support more connected institutional workflows, in which an institution can see who a party is, how that party relates to the university, what authoritative sources were reviewed, what decision was made, and what evidence supported it. SecurePoint USA is actively evaluating additional foreign-source and research-security workflows for SecurePoint Education as universities face increasingly connected reporting, review, and evidence requirements. These are workflows under evaluation, not current features.

SecurePoint analysis

The question that outlasts the lawsuit

The court will decide whether the Department can publish these names, and on what terms. Whatever it decides, the long-term compliance challenge is not simply whether a university can file a report. It is whether the institution can reconstruct the reasoning behind that report months or years later, for a regulator, a court, a board, or a donor who asks what happened to their information.

  • Know the source.
  • Know the relationship.
  • Know what was reviewed.
  • Know what was reported.
  • Preserve the evidence.

SecurePoint Education

Compare notes on foreign-source review

If your compliance, research-security, finance, advancement, or legal team is working through how foreign-source information moves across your institution, we would welcome the conversation. We will show how SecurePoint Education handles screening, review, and evidence today, and we will be direct about where it stops.

Frequently asked questions

No. On October 1, 2026, the U.S. District Court for the District of Columbia issued a temporary restraining order that bars the government from publishing the names or other identifying information of foreign donors and contract counterparties reported by AAU member institutions under Section 117. It is a preliminary order that expires October 29, 2026, unless the court extends it. It does not suspend Section 117 or change reporting obligations, and the next statutory filing date is January 31, 2027.

Primary sources

This article describes active litigation and evolving agency guidance as of October 4, 2026. A temporary restraining order is a preliminary, time-limited order, not a final ruling, and the dates above can change. Verify current status against the primary sources before relying on any statement here. SecurePoint supports compliance workflows; it does not provide legal advice or guarantee regulatory compliance. Final access and compliance decisions rest with the controlling organization.

Found this helpful? Share it with a colleague.

Visitor Compliance Checklist

  • ITAR/EAR and CMMC L2 requirements
  • Audit-ready evidence collection
  • Possible matches go to a reviewer
Download PDF

Stay ahead of compliance changes

Get occasional notes on sanctions, export controls, and visitor compliance when we publish them.

No spam. Unsubscribe anytime.

Related posts

Keep exploring compliance playbooks

More guidance on sanctions, export controls, and visitor management for regulated facilities.

View all articles
Section 117 Is Now a Data-Governance Problem | SecurePoint USA