GDPR and offshore outsourcing: a practical guide for businesses
Outsourcing to Morocco, Tunisia, or Madagascar while staying GDPR-compliant is entirely possible, but it requires careful preparation. The EU regulation on data protection fully applies to processing carried out outside the EU on behalf of a controller established in Europe. Here are the pillars to verify before signing an outsourcing contract.
The principle is clear: offshoring processing never exempts you from GDPR obligations. The controller remains accountable for its customers' data, wherever it is processed. The good news is that, with a structured partner, appropriate safeguards and careful documentation, offshore outsourcing is fully compatible with the regulation.
1. The legal framework: adequacy decision or not?
Transferring personal data to a third country (outside the EU) is only possible in two scenarios, framed by Chapter V of the GDPR (Articles 44 to 49). Either the European Commission has adopted an adequacy decision recognising that the country ensures an essentially equivalent level of protection — for example Japan, Switzerland or New Zealand. Or, failing that, the transfer must rely on appropriate safeguards.
Morocco, Tunisia and Madagascar do not have an adequacy decision. Any transfer to these destinations must therefore rest on Standard Contractual Clauses (SCC), Binding Corporate Rules(BCR) or, in certain cases, codes of conduct and certifications. At Altavista360, we use the European Commission's Standard Contractual Clauses (SCC 2021), updated following the Schrems II ruling of the Court of Justice of the EU. These clauses are incorporated into every service contract and supplemented by a transfer impact assessment (TIA) where the local situation requires it.
2. The data processing agreement (Article 28)
Article 28 of the GDPR requires the processor to process personal data only on the documented instructions of the controller. In practice, this takes the form of a data processing agreement (DPA) that formalises: the subject matter, duration, nature and purpose of the processing; the type of personal data and categories of data subjects; and the security, confidentiality and cooperation obligations towards the supervisory authority.
This contract must also cover the conditions for engaging a subsequent sub-processor (with prior authorisation), how the processor assists with data-subject rights requests, and the deletion or return of data at the end of the contract. Without a properly negotiated Article 28 agreement, an outsourcing project is legally fragile.
3. Security, pseudonymisation and Article 32
Article 32 of the GDPR requires technical and organisational measures appropriate to the risk. In an offshore centre, this translates into several complementary controls. Customer data travels over encrypted connections (VPN, TLS). Internally, data is pseudonymised wherever possible: agents see a customer identifier, not a full name. Access is controlled by role (RBAC) on a least-privilege basis, and every lookup is recorded in an immutable audit log.
On the organisational side, you add controlled-access premises, a ban on personal phones and USB drives, a clean-desk policy, and a formal data-breach notification procedure (Article 33) back to the controller. ISO/IEC 27001 certification of the centre is the reference standard: it ensures that an information security management system is in place and audited.
4. Accountability: who answers for what?
In the context of outsourcing, Altavista360 acts as a data processor under GDPR. The client remains the data controllerand bears the primary responsibility towards data subjects and the supervisory authority. This distinction is clearly formalised in the contract: we make no decisions regarding the purposes and means of processing — we act solely on the client's documented instructions.
This split does not, however, discharge the processor: it must be able to demonstrate compliance (the accountability principle, Article 5(2)), maintain a record of processing activities (Article 30) and cooperate with the controller. Operational tracking of these obligations is what separates a serious partner from an ordinary vendor.
5. The rights of data subjects
Your clients' customers retain the same GDPR rights regardless of the country where processing takes place: right of access, rectification, erasure, restriction, data portability and objection (Articles 15 to 22). We have therefore established procedures to forward and handle these requests within the statutory deadline (in principle one month), including for data hosted in Morocco or Tunisia. The offshore centre is integrated into the rights-management workflow, with a designated point of contact and a contractual transmission deadline.
Sectors that demand extra vigilance
Not all sectors are equal when it comes to offshore GDPR. Two deserve particular attention. Banking and fintech handle sensitive financial data and are subject to overlapping obligations (GDPR, banking secrecy, PSD2, PCI-DSS) that demand reinforced safeguards. Healthcare and health insurance process health data, classed as a special category of data (Article 9 of the GDPR) requiring additional guarantees and, most often, a data protection impact assessment (Article 35).
In these contexts, a Data Protection Impact Assessment(DPIA) is generally required before go-live. It documents the risks to the rights and freedoms of individuals and the measures taken to mitigate them. We routinely run this exercise in collaboration with the client's DPO.
Compliance audits
Before any deployment, we audit the partner centre against a grid of GDPR criteria: physical and logical security, agent training, access-rights management, breach-notification procedures, handling of data-subject rights, retention periods, and the record of processing activities. An audit report is provided to the client. These checks are then repeated periodically, because compliance is a continuous process, not an acquired state. For the broader context of outsourcing to Morocco, our article on the Morocco destination details the regulatory framework and available certifications. And to secure your administrative processes too, see our guide on back-office outsourcing.
In summary
Offshore outsourcing is fully compatible with GDPR, provided the project is structured correctly from the outset: a solid legal basis (SCC), a detailed Article 28 contract, Article 32 security measures, effective handling of data-subject rights, and regular audits. The key is a partner who understands the regulation, integrates it into their processes and documents every step. That is precisely what Altavista360 does.
Want to secure your outsourcing project from a GDPR standpoint?
Request a compliance audit