View Categories

Country Restrictions in the Volunteering Program

Country Restrictions in the Volunteering Program #

Knowledge Base · Category: Security Policies · Status: Public · emgprd.org · Version 1.0

This policy applies to all individuals applying to the emgprd.org volunteering program. The restrictions described here are based exclusively on international security, sanctions, and threat intelligence criteria — not on personal origin or nationality as such. We value global participation and recognise that these restrictions may feel unfair to individuals. We ask for your understanding: these measures protect everyone involved.

The volunteering program grants participants access to internal systems, communication channels, data, and the growing digital infrastructure of emgprd.org. This access is a matter of trust — and as is standard practice in professional security frameworks worldwide, it requires a risk-based assessment of the applicant’s country context.

State-directed cyberattacks, espionage, and coordinated influence operations frequently originate from — or are structurally linked to — specific countries. This risk does not lie with individuals themselves, but with the legal and institutional environment they may be subject to. In some countries, citizens are legally obligated to cooperate with state intelligence services upon request, regardless of personal intent.

Sanctions LegalActive EU sanctions regime or OFAC designation. Cooperation would be legally impermissible for the organisation.
FATF high-risk FinancialCountries with significant deficiencies in combating money laundering or terrorist financing, as listed by the FATF.
Cyber threat CyberCountries with documented, state-directed cyberattacks against organisations like ours, as assessed by CISA, NCSC, and BSI.
Sanctions / LegalFATF high-riskState cyber threat
RussiaSanctionsCyber

Russia has been under comprehensive EU and OFAC sanctions since 2022. Beyond the legal dimension, state-coordinated threat actors including APT28, APT29 (Cozy Bear), and Sandworm actively target international infrastructure, NGOs, and civil society organisations. The BSI, CISA, and NCSC consistently rate Russia as a top-tier cyber threat. Volunteers with active ties to Russian state institutions or intelligence-linked entities pose a structural insider risk.

BelarusSanctionsCyber

Belarus is subject to comprehensive EU sanctions following the 2020 election crisis and ongoing human rights violations. The Belarusian KGB and the threat group Ghostwriter are known for coordinated disinformation and cyberoperations, frequently conducted in close alignment with Russian actors. The operational overlap between Russian and Belarusian intelligence makes Belarus a compounded risk.

IranSanctionsCyberFATF

Iran meets all three exclusion criteria. It is subject to extensive EU and OFAC sanctions, is listed as a FATF high-risk jurisdiction, and is home to state-directed threat actors including APT33 (Elfin) and APT34 (OilRig), which specifically target NGOs, critical infrastructure, and international organisations. Iran’s legal framework also imposes intelligence cooperation obligations on its citizens.

North Korea (DPRK)SanctionsCyber

North Korea is subject to the strictest UN, EU, and US sanctions regimes in existence. The Lazarus Group — a state-operated threat actor — is responsible for attacks on financial infrastructure, cryptocurrency platforms, and international organisations. Any operational connection to North Korean individuals or entities carries severe legal and security consequences.

People’s Republic of ChinaCyber

The PRC is consistently rated the single largest state cyber espionage threat by CISA, NCSC, NSA, and BSI. State-directed groups including Volt Typhoon, APT10, and APT40 specifically target NGOs, think tanks, and international organisations — not for financial gain, but for long-term strategic intelligence collection. Critically, China’s National Intelligence Law (2017) legally obliges Chinese citizens to cooperate with state intelligence services upon request. This is not a personal accusation — it is a structural, legally mandated risk that we cannot manage through trust alone. Unlike Russia, which tends to attack from outside, China systematically operates through insiders. Volunteers represent exactly the access vector this model exploits.

MyanmarSanctionsFATF

Myanmar has been under EU sanctions since the military coup of February 2021. The country is also on the FATF high-risk list due to severe deficiencies in anti-money laundering and counter-terrorist financing controls. Political instability makes reliable background verification of applicants effectively impossible.

SyriaSanctionsFATF

Syria is subject to comprehensive EU and US sanctions. The country is classified as high-risk by the FATF due to the absence of effective state control over financial flows and documented links to terrorist financing. The ongoing conflict further prevents any meaningful applicant verification.

Sudan & South SudanSanctionsFATF

Both countries are subject to EU sanctions. Sudan is listed by the FATF as a high-risk jurisdiction. Ongoing armed conflict and state fragility in both countries make credible identity and background verification of applicants factually impossible at this time.

CubaSanctions

Cuba is subject to longstanding US OFAC sanctions under the Cuban Assets Control Regulations (CACR). Cooperation with Cuban nationals may carry legal consequences for the organisation, particularly where US-based systems, partners, or payment services are involved in our infrastructure.

VenezuelaSanctionsFATF

Venezuela is sanctioned by both the EU and the United States, and is assessed by the FATF as having significant deficiencies in money laundering controls. State involvement in disinformation and coordinated influence operations has also been documented by international observers.


Important: This policy is directed at structural and institutional risk — not at individuals. Persons holding dual citizenship or residing in non-affected countries may be considered for individual review on a case-by-case basis. For enquiries, please contact corporatesecurity@emgprd.org.

This list is reviewed every six months against current EU sanctions registers, FATF plenary reports, and threat assessments published by CISA, NCSC, and BSI. All changes are documented in the knowledge base changelog.

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to Top