GDPR and Data Protection When Working With an Offshore Development Team: What EU Companies Must Ask

Cumulative GDPR fines have now passed €7.1 billion since the regulation took effect in May 2018, with roughly €1.2 billion issued in 2025 alone, according to the DLA Piper GDPR Fines and Data Breach Survey, January 2026. Europe’s data protection authorities are now receiving an average of 443 breach notifications a day, a 22% year-on-year increase. For any EU business sending personal data to an offshore development team, that enforcement trend is not background noise. It is the reason data protection has to be a contractual, technical, and vendor-selection issue from day one, not a compliance checkbox at the end.

The Fact Most Offshoring Guides Skip: India Has No EU Adequacy Decision

The European Commission has issued adequacy decisions for a specific list of countries, including the UK, Japan, South Korea, and Switzerland, confirmed on the European Commission’s own Standard Contractual Clauses page. India is not on that list. As GDPR Local’s transfer guidance states plainly, any personal data transfer to an Indian processor requires the current EU Standard Contractual Clauses and, since the Schrems II ruling, a documented transfer impact assessment.

This is not a reason to avoid Indian development partners. It is a reason to make sure the legal groundwork exists before any data crosses the border, and to select a partner who already understands what that groundwork involves.


What to Ask Before You Sign: Six Non-Negotiable Questions

1. “Will you sign the current EU Standard Contractual Clauses?”

The European Commission adopted the modernised SCCs on 4 June 2021 via Commission Implementing Decision (EU) 2021/914. Older SCCs became invalid for all contracts from December 2022 onward. If a vendor offers to sign “a standard data agreement” without naming the current SCC modules, ask them to be specific.

2. “Who are your sub-processors, and where is data actually stored?”

Article 28 of the GDPR requires that any sub-processing be documented and authorised. Cloud hosting, backup providers, and even third-party QA or testing tools can all count as sub-processors. A partner who cannot name theirs cannot support your own Article 30 records of processing.

3. “What is your breach notification timeline?”

GDPR requires controllers to notify supervisory authorities within 72 hours of becoming aware of a breach. Your offshore processor needs to notify you fast enough that your own 72-hour clock is not already running out by the time you find out.

4. “Have you completed a Data Protection Impact Assessment for this kind of engagement before?”

The EDPB published its first harmonised DPIA template on 14 April 2026, per SecurityWall’s enforcement tracker. A vendor experienced with EU clients should already be familiar with the format, even if the DPIA itself is your organisation’s legal responsibility as controller.

5. “What security certifications do you hold, and can we see them?”

ISO 27001 and SOC 2 are the two most commonly requested independent verifications of information security practice for offshore vendors. Ask for the actual certificate and its expiry date, not a marketing reference to “bank-grade security.”

6. “Do we retain a right to audit?”

Article 28(3)(h) of the GDPR gives controllers the right to audit processor compliance, including via a mandated third party. This clause should be explicit in the contract, not implied.

Why This Matters Beyond Fines

Enforcement is no longer concentrated on Big Tech. The CMS GDPR Enforcement Tracker Report documents more than 2,600 fines to date, and a large share of enforcement activity now targets mid-sized organisations, financial services, healthcare, and public sector bodies, not just multinational platforms. Nixon Digital’s 2026 enforcement analysis notes that between January 2023 and early 2026, regulators issued more fines than in the preceding five years combined. A persistent misconception is that GDPR enforcement only targets large enterprises; the data says otherwise.

A Practical Question Table for Vendor Evaluation

Risk Area

Question to Ask

What a Good Answer Sounds Like

International transfer

Will you sign the current EU SCCs?

Yes, Module 2 or 4 as appropriate, ready to execute

Sub-processing

Who processes our data downstream?

Named list, updated on change, with notice period

Breach response

What is your notification SLA to us?

Within 24-48 hours of internal detection

Certifications

Can you share your ISO 27001/SOC 2 certificate?

Certificate provided with current validity date

Audit rights

Can we audit compliance directly or via a third party?

Explicit clause in the contract

Data residency

Where is data hosted and backed up?

Named regions, EU-hosting option available if needed


How Carmel Web Solutions Handles This

For European clients, Carmel Web Solutions builds data processing terms, sub-processor disclosure, and SCC execution into contracting from the outset rather than as a retrofit. Our services team works within documented security and access-control processes designed to support, not complicate, our clients’ own GDPR obligations.

If your legal or compliance team needs a data processing conversation before any technical scoping begins, reach out here — we’re glad to have that conversation first.

This article provides general information for planning purposes and does not constitute legal advice. Consult qualified EU data protection counsel for advice specific to your organisation.

Share:

More Posts

Send Us A Message