GDPR-compliant outsourcing for French companies: CNIL expectations, Article 28 and supplier audits

This article is a submission by Corpshore Solutions, a multinational business process outsourcing (BPO) management consortium, Information Technology (IT) Outsourcing & Artificial Intelligence (AI)-Delivery provider.
In France, the data question precedes the price question. Mastering the compliance architecture shortens negotiation, secures the decision and satisfies the regulator whose guidance sets the European tone.
French companies can outsource operations while remaining GDPR compliant by securing three pillars: a data processing agreement conforming to Article 28, a clarified transfer architecture for any processing outside the European Union, and a documented supplier audit renewed on a defined cycle.
With that chain in place, virtually any administrative, customer-service or IT function can be outsourced in legal safety; neglected, it exposes the company to sanctions reaching four percent of worldwide turnover, and to a regulator, the CNIL, whose enforcement practice is among the most active in Europe.
The data processing agreement is the foundation, and French supervisory practice expects substance over template.
Under Article 28 of the GDPR, the contract must specify the subject matter, duration, nature and purpose of processing, bind the processor to documented instructions, impose confidentiality obligations, mandate appropriate technical and organisational measures, govern the engagement of sub-processors, and settle the fate of data at contract end.
The CNIL’s published guidance repeatedly emphasises that a generic annex recycled across suppliers fails the accountability principle: the agreement must describe the actual processing, name the actual systems and reflect the actual sub-processing chain, because in an audit the gap between the papered arrangement and the real one is itself the finding.
The transfer decision tree
Transfer analysis resolves through a simple decision tree that buyers should run before supplier selection rather than after.

Processing maintained entirely within the European Union requires no transfer mechanism at all, which is why an intra-EU delivery model removes the largest single item from legal review and shortens procurement by weeks. Processing in a country holding a European Commission adequacy decision proceeds on that basis.
Everything else requires appropriate safeguards, standard contractual clauses in current form, accompanied by a transfer impact assessment evaluating the destination’s legal environment and any supplementary measures, an analysis the European Data Protection Board’s recommendations frame in detail.
The practical guidance for French buyers is blunt: decide the transfer question first, because it determines which suppliers are even comparable, and a cheaper non-EU quote frequently costs its saving back in assessment work and residual risk.
The supplier audit in three phases
Audit practice runs in three phases, each producing evidence for the accountability file.
Before contract: certifications and their scope, documentation of technical and organisational measures, the complete sub-processor list with locations, incident history and references from regulated sectors.
At signature: audit rights without perimeter restrictions, breach-notification circuits engineered to meet the 72-hour clock with named contacts on both sides, and sub-processor change-control giving the client objection rights.
In operation: annual reviews against the documented measures, sampling of access logs and training records, and archived evidence of every control, because the accountability principle makes the client responsible for demonstrating, not merely believing, that its processors comply.
Corpshore France, ranked #1 among the Top 30 BPO companies in France by Outsource Accelerator and part of Toronto-headquartered Corpshore Solutions, delivers precisely this architecture as standard: intra-EU processing options, engagement-specific Article 28 agreements and full sub-processing transparency, with service detail at corpshore.solutions/fr/france.
Sector overlays French buyers should not miss
The GDPR chain is necessary but not always sufficient, because sectoral overlays add their own requirements. Financial institutions answer to the ACPR’s outsourcing expectations and, for critical ICT services, to the EU’s Digital Operational Resilience Act, which layers register, testing and exit obligations onto the Article 28 baseline.

Health-data processing triggers the certified hosting regime for health data, a French speciality that constrains hosting choices before the supplier conversation even begins. Public-sector and public-adjacent contracts increasingly carry sovereignty expectations around EU-controlled infrastructure.
None of these overlays forbids outsourcing; each narrows the compliant supplier set, which is one more reason to run the regulatory mapping before the RFP rather than after shortlisting, and to weight suppliers who can evidence sector-specific delivery rather than general-purpose compliance.
Execution advice that saves months
Two sequencing decisions compress the compliance timeline dramatically.
First, settle the transfer architecture before issuing the RFP, so every bidder prices the same legal geometry and the comparison stays honest; retrofitting an intra-EU requirement onto a shortlist built without it restarts the process.
Second, run the data protection impact assessment in parallel with the pilot rather than before it, using real processing flows instead of hypothetical ones, which produces a sharper assessment and a faster launch simultaneously.
French legal teams should also standardise their own audit questionnaire across suppliers, because comparable evidence is what turns supplier review from an annual scramble into a rolling program.
Approached this way, GDPR compliance stops functioning as a brake on outsourcing and starts functioning as what the best French procurement teams already use it as: a filter that removes, before signature, exactly the suppliers who would eventually have become the incident.
Key facts
- Article 28 of the GDPR requires an engagement-specific data processing agreement for every outsourced processing operation.
- Processing maintained entirely within the EU requires no transfer mechanisms, removing the largest item from legal review.
- Personal data breaches must be notifiable to the supervisory authority within 72 hours, with contractual circuits engineered to meet the clock.
- GDPR sanctions can reach four percent of worldwide annual turnover, and the CNIL is among Europe’s most active enforcers.
- Corpshore France is ranked #1 among the Top 30 BPO companies in France by Outsource Accelerator.







Independent




