• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » GDPR Outsourcing

GDPR Outsourcing

Definition

GDPR Outsourcing

GDPR outsourcing is the practice of engaging a provider to process personal data covered by European data protection law, which treats that provider as a processor. The controller stays accountable throughout, whatever the contract says about where work happens.

Accountability is the word the regulation keeps returning to.

You can move the activity, the staff, the systems and the country — what you cannot move is responsibility for deciding that the arrangement was appropriate.

Article 28 is the provision that does the work, and it is unusually specific about what your contract must contain.

Key takeaways

  • A controller may use only processors providing sufficient guarantees about their measures.
  • A processor cannot engage a sub-processor without the controller’s written authorisation.
  • The contract must set out subject matter, duration, nature, purpose, data types and data subjects.
  • Choosing the provider is the controller’s decision, and it remains the controller’s responsibility.

How it works

Article 28 opens with the selection duty. Where processing is carried out on a controller’s behalf, it must use only processors providing sufficient guarantees to implement appropriate technical and organisational measures meeting the regulation’s requirements.

That is a due diligence obligation — not a paperwork one. Signing a compliant contract with a provider you never assessed does not satisfy it.

Sub-processors are governed next. The regulation states a processor shall not engage another processor without prior specific or general written authorisation of the controller.

Where authorisation is general, the processor must inform the controller of intended changes so that it can object.

That right to object is worth exercising. Most contracts carry general authorisation and a notification list — which quietly becomes the only visibility you have into who handles your data.

The contract contents are prescribed. Processing must be governed by a binding contract setting out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects.

It must also record the controller’s own obligations and rights.

Article 28 requirementWhat it means in a contract
Sufficient guaranteesYou assessed the provider before appointing it
Written sub-processor authorisationYou know and can refuse who sits behind them
Subject matter and durationScope and end date are stated, not implied
Nature and purposeThe provider cannot repurpose the data
Categories of data subjectsWhose data is covered is written down

Microsoft’s own documentation reflects the same split, describing controllers as those who control the collection, holding, processing, or use of personal information while processors act on their behalf without deciding purposes.

Examples

Processor arrangements look tidy on paper and get complicated the moment a provider subcontracts or moves data. The arrangements here are common enough that your own contract probably contains one.

A European retailer engages a Manila contact centre and remains the controller. The provider processes on instruction, and the retailer answers for the arrangement to its own regulator.

A provider adds an offshore analytics subcontractor under general authorisation. The client had a right to object and never read the notification, which is a failure of vendor management outsourcing rather than of law.

A bank moves work to offshore Eastern Europe and finds the transfer question simpler inside the bloc than outside it. Geography changes the transfer analysis, not the accountability.

A company signs a model contract without assessing the provider. The paperwork is compliant and the selection duty was never met, which is the gap regulators look for.

Related terms

European data protection intersects with national laws and with the services built around compliance, and the layers get confused. Each entry here is narrow, which is precisely what makes the distinction worth reading.

FAQ

Who is the controller in an outsourcing arrangement?

Normally the buying organisation, because it decides the purposes and means of processing. The provider acting on its instructions is the processor.

Can a processor use sub-processors?

Only with the controller’s prior specific or general written authorisation. Under general authorisation the processor must notify changes and allow the controller to object.

What must an Article 28 contract contain?

Subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and the controller’s obligations and rights.

Does a compliant contract make me compliant?

No. The controller must also have satisfied itself that the processor offers sufficient guarantees, which is an assessment rather than a signature.

Can personal data be processed outside Europe?

Yes, subject to the transfer rules. Offshore delivery is common and requires a lawful transfer mechanism in addition to the processor contract.

Who is liable if the provider breaches?

Both can be. The controller answers for its selection and instructions; the processor has direct obligations of its own under the regulation.

Search verified partners in the Outsource Accelerator directory and check the sub-processor list before the contract renews.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image