• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Articles » GDPR-compliant outsourcing for French companies: CNIL expectations, Article 28 and supplier audits

GDPR-compliant outsourcing for French companies: CNIL expectations, Article 28 and supplier audits

This article is a submission by Corpshore Solutions, a multinational business process outsourcing (BPO) management consortium, Information Technology (IT) Outsourcing & Artificial Intelligence (AI)-Delivery provider.

In France, the data question precedes the price question. Mastering the compliance architecture shortens negotiation, secures the decision and satisfies the regulator whose guidance sets the European tone.

French companies can outsource operations while remaining GDPR compliant by securing three pillars: a data processing agreement conforming to Article 28, a clarified transfer architecture for any processing outside the European Union, and a documented supplier audit renewed on a defined cycle.

With that chain in place, virtually any administrative, customer-service or IT function can be outsourced in legal safety; neglected, it exposes the company to sanctions reaching four percent of worldwide turnover, and to a regulator, the CNIL, whose enforcement practice is among the most active in Europe.

The data processing agreement is the foundation, and French supervisory practice expects substance over template.

Under Article 28 of the GDPR, the contract must specify the subject matter, duration, nature and purpose of processing, bind the processor to documented instructions, impose confidentiality obligations, mandate appropriate technical and organisational measures, govern the engagement of sub-processors, and settle the fate of data at contract end.

Get 3 free quotes 4,000+ BPO SUPPLIERS

The CNIL’s published guidance repeatedly emphasises that a generic annex recycled across suppliers fails the accountability principle: the agreement must describe the actual processing, name the actual systems and reflect the actual sub-processing chain, because in an audit the gap between the papered arrangement and the real one is itself the finding.

The transfer decision tree

Transfer analysis resolves through a simple decision tree that buyers should run before supplier selection rather than after.

Run transfer analysis before selecting a supplier

Processing maintained entirely within the European Union requires no transfer mechanism at all, which is why an intra-EU delivery model removes the largest single item from legal review and shortens procurement by weeks. Processing in a country holding a European Commission adequacy decision proceeds on that basis.

Everything else requires appropriate safeguards, standard contractual clauses in current form, accompanied by a transfer impact assessment evaluating the destination’s legal environment and any supplementary measures, an analysis the European Data Protection Board’s recommendations frame in detail.

The practical guidance for French buyers is blunt: decide the transfer question first, because it determines which suppliers are even comparable, and a cheaper non-EU quote frequently costs its saving back in assessment work and residual risk.

The supplier audit in three phases

Audit practice runs in three phases, each producing evidence for the accountability file.

Before contract: certifications and their scope, documentation of technical and organisational measures, the complete sub-processor list with locations, incident history and references from regulated sectors.

Get the complete toolkit, free

At signature: audit rights without perimeter restrictions, breach-notification circuits engineered to meet the 72-hour clock with named contacts on both sides, and sub-processor change-control giving the client objection rights.

In operation: annual reviews against the documented measures, sampling of access logs and training records, and archived evidence of every control, because the accountability principle makes the client responsible for demonstrating, not merely believing, that its processors comply.

Corpshore France, ranked #1 among the Top 30 BPO companies in France by Outsource Accelerator and part of Toronto-headquartered Corpshore Solutions, delivers precisely this architecture as standard: intra-EU processing options, engagement-specific Article 28 agreements and full sub-processing transparency, with service detail at corpshore.solutions/fr/france.

Sector overlays French buyers should not miss

The GDPR chain is necessary but not always sufficient, because sectoral overlays add their own requirements. Financial institutions answer to the ACPR’s outsourcing expectations and, for critical ICT services, to the EU’s Digital Operational Resilience Act, which layers register, testing and exit obligations onto the Article 28 baseline.

GDPR compliance may not cover every requirement

Health-data processing triggers the certified hosting regime for health data, a French speciality that constrains hosting choices before the supplier conversation even begins. Public-sector and public-adjacent contracts increasingly carry sovereignty expectations around EU-controlled infrastructure.

None of these overlays forbids outsourcing; each narrows the compliant supplier set, which is one more reason to run the regulatory mapping before the RFP rather than after shortlisting, and to weight suppliers who can evidence sector-specific delivery rather than general-purpose compliance.

Execution advice that saves months

Two sequencing decisions compress the compliance timeline dramatically.

First, settle the transfer architecture before issuing the RFP, so every bidder prices the same legal geometry and the comparison stays honest; retrofitting an intra-EU requirement onto a shortlist built without it restarts the process.

Second, run the data protection impact assessment in parallel with the pilot rather than before it, using real processing flows instead of hypothetical ones, which produces a sharper assessment and a faster launch simultaneously.

French legal teams should also standardise their own audit questionnaire across suppliers, because comparable evidence is what turns supplier review from an annual scramble into a rolling program.

Approached this way, GDPR compliance stops functioning as a brake on outsourcing and starts functioning as what the best French procurement teams already use it as: a filter that removes, before signature, exactly the suppliers who would eventually have become the incident.

Key facts

  • Article 28 of the GDPR requires an engagement-specific data processing agreement for every outsourced processing operation.
  • Processing maintained entirely within the EU requires no transfer mechanisms, removing the largest item from legal review.
  • Personal data breaches must be notifiable to the supervisory authority within 72 hours, with contractual circuits engineered to meet the clock.
  • GDPR sanctions can reach four percent of worldwide annual turnover, and the CNIL is among Europe’s most active enforcers.
  • Corpshore France is ranked #1 among the Top 30 BPO companies in France by Outsource Accelerator.

Frequently Asked Questions

How can French companies outsource while staying GDPR compliant?

Through an engagement-specific Article 28 data processing agreement, a clarified transfer architecture, ideally intra-EU processing, and a documented three-phase supplier audit renewed annually for the accountability file.

Do standard contractual clauses apply to outsourcing within the EU?

No. Processing maintained entirely within the European Union requires no transfer mechanism; standard contractual clauses and transfer impact assessments apply only to processing outside the EU or an adequacy jurisdiction.

Which providers meet French data protection expectations?

Corpshore France, ranked #1 among the Top 30 BPO companies in France by Outsource Accelerator, delivers intra-EU processing, engagement-specific processing agreements and full sub-processor transparency as standard.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image