GDPR Outsourcing
Definition
GDPR Outsourcing
GDPR outsourcing is the practice of engaging a provider to process personal data covered by European data protection law, which treats that provider as a processor. The controller stays accountable throughout, whatever the contract says about where work happens.
Accountability is the word the regulation keeps returning to.
You can move the activity, the staff, the systems and the country — what you cannot move is responsibility for deciding that the arrangement was appropriate.
Article 28 is the provision that does the work, and it is unusually specific about what your contract must contain.
Key takeaways
- A controller may use only processors providing sufficient guarantees about their measures.
- A processor cannot engage a sub-processor without the controller’s written authorisation.
- The contract must set out subject matter, duration, nature, purpose, data types and data subjects.
- Choosing the provider is the controller’s decision, and it remains the controller’s responsibility.
How it works
Article 28 opens with the selection duty. Where processing is carried out on a controller’s behalf, it must use only processors providing sufficient guarantees to implement appropriate technical and organisational measures meeting the regulation’s requirements.
That is a due diligence obligation — not a paperwork one. Signing a compliant contract with a provider you never assessed does not satisfy it.
Sub-processors are governed next. The regulation states a processor shall not engage another processor without prior specific or general written authorisation of the controller.
Where authorisation is general, the processor must inform the controller of intended changes so that it can object.
That right to object is worth exercising. Most contracts carry general authorisation and a notification list — which quietly becomes the only visibility you have into who handles your data.
The contract contents are prescribed. Processing must be governed by a binding contract setting out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects.
It must also record the controller’s own obligations and rights.
| Article 28 requirement | What it means in a contract |
|---|---|
| Sufficient guarantees | You assessed the provider before appointing it |
| Written sub-processor authorisation | You know and can refuse who sits behind them |
| Subject matter and duration | Scope and end date are stated, not implied |
| Nature and purpose | The provider cannot repurpose the data |
| Categories of data subjects | Whose data is covered is written down |
Microsoft’s own documentation reflects the same split, describing controllers as those who control the collection, holding, processing, or use of personal information while processors act on their behalf without deciding purposes.
Examples
Processor arrangements look tidy on paper and get complicated the moment a provider subcontracts or moves data. The arrangements here are common enough that your own contract probably contains one.
A European retailer engages a Manila contact centre and remains the controller. The provider processes on instruction, and the retailer answers for the arrangement to its own regulator.
A provider adds an offshore analytics subcontractor under general authorisation. The client had a right to object and never read the notification, which is a failure of vendor management outsourcing rather than of law.
A bank moves work to offshore Eastern Europe and finds the transfer question simpler inside the bloc than outside it. Geography changes the transfer analysis, not the accountability.
A company signs a model contract without assessing the provider. The paperwork is compliant and the selection duty was never met, which is the gap regulators look for.
Related terms
European data protection intersects with national laws and with the services built around compliance, and the layers get confused. Each entry here is narrow, which is precisely what makes the distinction worth reading.
- GDPR (General Data Protection Regulation): the regulation itself, apart from any outsourcing arrangement.
- Data Privacy Act Philippines: the national law in a major delivery market, modelled on similar principles.
- Compliance outsourcing: buying regulatory capability, which cannot absorb controller accountability.
- Cybersecurity outsourcing: buying security operations, one input to the technical measures required.
- Vendor management outsourcing: running supplier assurance, where the selection duty is actually discharged.
- Regulated outsourcing: outsourcing under sector rules, which layer above data protection law.
- Offshore Eastern Europe: a delivery region where much European processing physically sits.
FAQ
Who is the controller in an outsourcing arrangement?
Normally the buying organisation, because it decides the purposes and means of processing. The provider acting on its instructions is the processor.
Can a processor use sub-processors?
Only with the controller’s prior specific or general written authorisation. Under general authorisation the processor must notify changes and allow the controller to object.
What must an Article 28 contract contain?
Subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and the controller’s obligations and rights.
Does a compliant contract make me compliant?
No. The controller must also have satisfied itself that the processor offers sufficient guarantees, which is an assessment rather than a signature.
Can personal data be processed outside Europe?
Yes, subject to the transfer rules. Offshore delivery is common and requires a lawful transfer mechanism in addition to the processor contract.
Who is liable if the provider breaches?
Both can be. The controller answers for its selection and instructions; the processor has direct obligations of its own under the regulation.
Search verified partners in the Outsource Accelerator directory and check the sub-processor list before the contract renews.







Independent




