Skip to content
Share

SecurePoint Education · Regulatory analysis

Education
October 4, 2026

Section 117 Is Becoming a Data-Governance Problem

The court fight over foreign-donor names shows why universities should treat collecting, screening, reviewing, reporting, and publishing that information as five separate steps.

Reading time
10 minutes
Case status
Restraining order until Oct 29

On October 1, 2026, the Association of American Universities (AAU) sued the U.S. Department of Education to stop it from publishing the identities of foreign donors and contract counterparties. AAU member universities had reported those names to the Department under Section 117 of the Higher Education Act. The same day, after a hearing, Judge Tanya S. Chutkan of the U.S. District Court for the District of Columbia issued a temporary restraining order. The Department had planned to publish on October 2.

Most coverage will focus on the politics. For compliance, research-security, finance, and legal teams, one question matters no matter how the case ends:

What happens to sensitive foreign-source information between the moment a university receives it and the moment it is reported, reviewed, retained, or disclosed?

At many universities, the answer depends on which office you ask.

Verified facts

What happened

Section 117 (20 U.S.C. § 1011f) requires colleges and universities that receive federal financial assistance to report foreign gifts and contracts worth $250,000 or more, in total, from a single foreign source in a calendar year. Reports are due January 31 or July 31, and the statute makes them public records.

The statute itself asks for dollar amounts and the country each gift is tied to, with more detail for gifts that come with conditions. The Department’s reporting instructions go further. They ask for the name and address of every foreign source. According to AAU, the Department assured institutions and donors in writing for years that this information would stay confidential and be used only to verify compliance.

That changed this year, when the Department moved to publish the names. After several postponements, it set the release for October 2.

The suit names the Departments of Education and State and their secretaries. (State has helped administer Section 117 under an agreement with Education since February 2026.) AAU argues that the statute does not call for publishing private donors’ personal information. It says the Constitution protects donors from compelled public exposure of their charitable associations. And it says the Department reversed course without notice to donors and without the rulemaking the law requires. The Department has described the publication as consistent with Section 117’s transparency requirements.

Case at a glance

Case
Association of American Universities v. U.S. Department of Education, et al.
Court
U.S. District Court for the District of Columbia, No. 1:26-cv-03438
Defendants
U.S. Department of Education, U.S. Department of State, Secretary of Education Linda McMahon, Secretary of State Marco Rubio
Filed
October 1, 2026
Order
Temporary restraining order granted October 1, 2026, by Judge Tanya S. Chutkan
Expires
October 29, 2026, unless the court extends it
Next
Government's preliminary-injunction response due October 13; AAU's reply due October 20

What the order does

  • Bars the government from publishing the names or other identifying information of foreign donors and contract counterparties reported by AAU member institutions under Section 117.
  • Took effect immediately and holds things in place while the court decides whether to issue a preliminary injunction.
  • Rests on a preliminary finding that AAU is likely to succeed on its Administrative Procedure Act claim.

What it does not do

  • Strike down or suspend Section 117.
  • Change what institutions report or when. The next statutory filing date is January 31, 2027.
  • Decide the case on the merits.
  • Cover universities outside AAU's membership, as AAU describes the order.

The court found AAU likely to succeed on its claim that publishing, after six years of written assurances to the contrary, was arbitrary and capricious. It also found that publication could cause irreparable harm, since a published name cannot be taken back.

How we got here

  1. Apr 23, 2025

    Executive Order 14282 calls for stricter Section 117 enforcement and more transparency.

  2. Jan 2, 2026

    A new Section 117 reporting portal goes live.

  3. Feb 2026

    Education and State sign an agreement. State starts helping run Section 117.

  4. Apr 15, 2026

    The Department proposes changes to Section 117 reporting and says it intends to publish counterparty names.

  5. Jun 15, 2026

    Higher-education groups file comments objecting to publishing donor names.

  6. Jul 6, 2026

    The Department says it will publish “the names of all foreign sources from prior reporting cycles.”

  7. Jul 15, 2026

    It publishes a narrower list instead: 92 foreign entities that also appear on U.S. government lists. The full release is postponed.

  8. Sep 25, 2026

    The full release is set for October 2.

  9. Oct 1, 2026

    AAU sues. The court grants a temporary restraining order the same day.

SecurePoint analysis

The distinction universities cannot afford to blur

Collection is not screening. Screening is not review. Review is not reporting. Reporting is not publication.

The same information passes through five activities, each with its own owner and its own rules.

Many foreign-source problems start when these five activities get treated as one.

Collection is information coming in. It might be a gift agreement in advancement, a wire transfer in finance, a sponsored-research contract, a faculty appointment, or a department’s agreement with a foreign university. Each one raises the same basic questions. What was captured, from whom, and why? Who can see it?

Screening checks a party against authoritative lists, such as the OFAC Specially Designated Nationals List or the BIS Entity List, when the relationship calls for it. A screen produces a result. A person still has to decide what that result means.

Institutional review is where people with authority decide what a relationship means. Is the counterparty part of a government? Does the money come with conditions? Does the project need research-security or export-control review? Should the decision go up the chain? Review is a human judgment, and it should leave a record.

Federal reporting means sending the Department what Section 117 and its current instructions require, on the statutory schedule. The law that requires the report also sets its limits.

Publication means making information public. It is a separate act with its own legal authority, and right now it is the subject of a lawsuit. Reporting something to the government does not, by itself, make it public.

A compliance system has to track these as separate states of the same record. Put a screening hit, a reviewer’s note, a reported field, and a published field in one spreadsheet column, and the distinctions disappear. The institution can no longer show what it decided, what it submitted, or what was ever meant to be public.

Figure 1

Information moves forward only through a gate.

  1. 1

    Collection

    Governed by: Institutional data policy, and the purpose the information was collected for.

    GATEPurpose and need-to-know
  2. 2

    Screening

    Governed by: The lists that apply, and the institution's screening policy.

    GATEA match is not a decision
  3. 3

    Institutional review

    Governed by: Internal policy, plus research-security, export-control, and conflict-of-interest rules.

    GATEReporting authority: § 1011f
  4. 4

    Federal reporting

    Governed by: Section 117, and the Department's current reporting instructions.

    GATEPublication authority: contested
  5. 5

    Public disclosure

    Governed by: Its own legal authority and policy, now in active litigation.

Every gate is a decision that someone owns, backed by a legal or policy basis. Stage names describe common activities, not statutory terms.

SecurePoint analysis

Why this is a data-governance issue

Section 117 used to look like a finance task. Add up the foreign gifts and contracts, file twice a year, move on. The data behind those filings is now far more sensitive.

It starts with identity. Universities report donor names and addresses to the Department, including for donors who asked to keep their gift anonymous. Then come the judgment calls. Is the counterparty a company, a university, a government agency, a state-owned enterprise, or an intermediary acting for someone else? Which country is it tied to? Each answer is a classification that someone made, on some date, under some rule.

Then there is access. Who inside the university can see a donor’s identity, and why? And there is history. What was submitted, what was corrected later, and what was made public are three different facts.

The rules keep moving, too. In 2026 alone, the Department launched a new reporting portal, proposed changes to what reports collect, opened a process for correcting past filings, and announced a string of publication dates. A reviewer who classified a counterparty in 2023 applied 2023 instructions. If the institution cannot show which rule applied at the time, that call becomes hard to defend.

The reconstruction test

For any foreign-source relationship, the institution should be able to answer:

  1. 01What did we know?
  2. 02When did we know it?
  3. 03Where did the information come from?
  4. 04Who reviewed it?
  5. 05What rule or guidance applied?
  6. 06What did we submit?
  7. 07What did we disclose?

If those answers live in five systems and three inboxes, a federal records request will turn into a scramble.

SecurePoint analysis

The connection to research security

In practice, Section 117 now sits right next to research security. In mid-July, the Department published a list of reported foreign sources that also appear on U.S. government lists, and the State Department wrote to the boards of R1 universities about funding from counterparties on cautionary and restricted government lists. Recent federal records requests have also gone well beyond gift ledgers, asking for faculty agreements, research collaborations, and records of foreign talent program participation. We walked through one of those requests in an earlier analysis.

The same foreign organization may appear in a donation record, a sponsored-research agreement, a faculty affiliation, an export-control review, and a restricted-party screening result. Those records should not live as five unrelated facts.

One foreign organization

Five records, often in five offices

  • Donation recordAdvancement
  • Sponsored-research agreementResearch administration
  • Faculty affiliationFaculty affairs
  • Export-control reviewExport control
  • Restricted-party screening resultCompliance

When they do, the university answers the same question five times, sometimes five different ways. Advancement might log a counterparty as a private foundation while research administration treats the same organization as state-affiliated. Both offices may be right under the rule each one applies. The problem is that nobody can see the two answers side by side, or explain the difference when someone asks.

Linking the records gives a full picture of the relationship. The legal questions stay separate:

  • Foreign relationship ≠ wrongdoing

    A foreign gift, contract, or collaboration is not, by itself, evidence of wrongdoing.

  • Section 117 reporting ≠ sanctions compliance

    A complete filing says nothing about whether a party is sanctioned.

  • Sanctions screening ≠ Section 117 reporting

    Screening a donor does not satisfy a disclosure obligation.

  • A list match ≠ an unlawful transaction

    Some U.S. government lists prohibit dealings outright. Others restrict specific activities, such as exports, or call for closer review.

  • Research-security review ≠ export-control determination

    A risk review is not a classification or license decision under the EAR or ITAR.

SecurePoint analysis

What universities should be building now

None of this requires waiting for the court. These ten capabilities hold up under any outcome:

  1. 01

    One record per foreign source

    Legal name, other names, type of source, and country, entered once instead of retyped in every system.

  2. 02

    Links to everything it touches

    The people, departments, projects, agreements, payments, and grants connected to that source.

  3. 03

    Where each fact came from

    The system or document behind each fact, and the date it arrived.

  4. 04

    Screening history

    Which lists were checked, when, which version of each list, and what came back.

  5. 05

    Who decided, and why

    The reviewer, the decision, and the reasoning in the reviewer’s own words.

  6. 06

    Which rules applied

    The statute, Department instructions, and internal policy in force when each decision was made.

  7. 07

    What was filed

    Exactly what went to the Department for each reporting period, including amendments.

  8. 08

    What may be made public

    For each field: internal only, reportable to the government, or cleared for public release, and on whose authority.

  9. 09

    Need-to-know access

    Donor identities visible only to people whose role requires them, with access logged.

  10. 10

    Retention

    The record and its documents, kept for a set period that meets the longest rule that applies.

All ten come down to one habit. Keep the fact, the decision, and the disclosure apart, and give each one an owner and an audit trail.

SecurePoint Education

Where SecurePoint Education fits

SecurePoint Education is built on a simple premise: compliance decisions should not disappear into spreadsheets, email threads, and one-time searches.

Today it handles the screening and review steps described above. For each person or organization it screens, it keeps the result, the reviewer’s decision, when it was made, and why.

What it does today

  • Screens people and organizations, including donors, sponsors, payors, researchers, faculty, vendors, and foreign institutions, against sanctions and restricted-party lists such as the OFAC SDN List and the BIS Entity List.
  • Sends possible matches to human case review, where the reviewer records a decision and notes.
  • Re-screens active parties every 30 or 90 days.
  • Keeps screening evidence for ten years by default and exports it as evidence packs.

What it does not do

  • File Section 117 reports with the Department of Education.
  • Decide whether a gift or contract is reportable.
  • Determine what an institution may disclose publicly.
  • Provide legal advice.

Decisions about what to report, and what may be made public, belong to the institution and its counsel. SecurePoint’s job is to keep the screening and review evidence those decisions rest on.

Looking ahead

As foreign-source and research-security expectations grow, the same foundation can support more connected workflows: seeing who a party is, how it relates to the university, which sources were checked, what was decided, and on what evidence. SecurePoint USA is actively evaluating additional foreign-source and research-security workflows for SecurePoint Education. These are under evaluation, not current features.

SecurePoint analysis

The question that outlasts the lawsuit

The court will decide whether the Department can publish these names, and on what terms. Whatever it decides, the harder test comes later. Months or years from now, a regulator, a court, a board, or a donor may ask why a report said what it said, and what happened to the information behind it. The universities that can answer will be the ones that kept the record.

  • Know the source.
  • Know the relationship.
  • Know what was reviewed.
  • Know what was reported.
  • Preserve the evidence.

SecurePoint Education

Compare notes on foreign-source review

If your compliance, research-security, finance, advancement, or legal team is working through how foreign-source information moves across your institution, we would welcome the conversation. We will show how SecurePoint Education handles screening, review, and evidence today, and we will be direct about where it stops.

Frequently asked questions

No. On October 1, 2026, the U.S. District Court for the District of Columbia issued a temporary restraining order that bars the government from publishing the names or other identifying information of foreign donors and contract counterparties reported by AAU member institutions under Section 117. It is a preliminary order that expires October 29, 2026, unless the court extends it. It does not suspend Section 117 or change reporting obligations, and the next statutory filing date is January 31, 2027.

Primary sources

This article describes active litigation and evolving agency guidance as of October 4, 2026. A temporary restraining order is a preliminary, time-limited order, not a final ruling, and the dates above can change. Verify current status against the primary sources before relying on any statement here. SecurePoint supports compliance workflows; it does not provide legal advice or guarantee regulatory compliance. Final access and compliance decisions rest with the controlling organization.

Found this helpful? Share it with a colleague.

Free guide: The New Education Compliance Reality in 2026

  • Why Blackbaud and Flywire are not institutional sanctions screening
  • The IMG Academy OFAC settlement, and why Section 117 foreign-gift reporting is a separate obligation from sanctions screening
  • A 90-day sanctions-screening action plan for school business offices
Email me the whitepaper

Stay ahead of compliance changes

Get occasional notes on sanctions, export controls, and visitor compliance when we publish them.

No spam. Unsubscribe anytime.

Related posts

Keep exploring compliance playbooks

More guidance on sanctions screening and compliance records for schools and universities.

View all articles
Section 117 Is Now a Data-Governance Problem | SecurePoint USA