Offshore Outsourcing and GDPR: What You Need to Lock Down Before Transferring Data Outside the EU

Your DPO has vetoed it. Your legal counsel has asked for a "supplementary analysis." Translation: the outsourcing project to Madagascar is blocked because no one in the company knows exactly what GDPR requires when personal data leaves the European Union. This is understandable. The subject is technical, the texts are dense, and the vast majority of offshore providers carefully avoid discussing it. The result: you lose weeks, sometimes months, on an obstacle that can be addressed upfront with the right documents and the right mechanisms. Neither Madagascar nor Maurice benefit from an adequacy decision by the European Commission. This does not mean the transfer is prohibited. It means it is conditional. Articles 44 to 49 of the GDPR precisely define the guarantees that must be provided. This article details every obligation: the legal bases for the transfer, the standard contractual clauses to be signed, the Data Processing Agreement to be structured, the cross-border processing registry, and the compliance audits to be imposed on your provider. No abstract legal theory. Factual answers, applicable to a transfer to Madagascar or Maurice, with the documents to produce before day 1.

1 – Legal Basis for the Transfer: What the GDPR Says When There Is No Adequacy Decision

The GDPR does not block transfers outside the EU. It requires guarantees proportionate to the level of protection in the destination country. Madagascar and Maurice have no adequacy decision. Here is what this means in concrete terms for your outsourcing project.

1.1: Adequacy Decision, BCR, Standard Contractual Clauses: The Three Possible Mechanisms

Article 45 of the GDPR provides that the European Commission may recognize that a country offers an "adequate" level of protection. Madagascar and Maurice do not appear on this list. You must therefore turn to the mechanisms of Article 46. First mechanism: Binding Corporate Rules (BCR). These are suited to multinational groups transferring data between internal entities. Validation by a supervisory authority takes 12 to 24 months. For a company outsourcing to a third-party provider, this is neither proportionate nor realistic. Second mechanism: standard contractual clauses (SCCs) adopted by the European Commission. Updated version of June 4, 2021, four modules depending on the relationship between the parties. This is the mechanism suited to 95% of offshore outsourcing projects for SMEs. Third mechanism: the derogations of Article 49 (explicit consent, performance of a contract). These cover only occasional transfers, not a continuous flow of data to a dedicated team. Disregard them for full-time outsourcing.

1.2: Madagascar and Maurice: Precise Legal Status and Practical Consequences

Madagascar has a personal data protection law (Law No. 2014-038) and a regulatory authority. Maurice has the Data Protection Act 2017 and a Data Protection Commissioner. These legislative frameworks exist, but the European Commission has not recognized them as "adequate." Direct consequence: every transfer of personal data from your CRM, your ticketing tool, or your accounting software to a team member based in Antananarivo or Port Louis must be governed by standard contractual clauses signed between you (the data exporter) and the provider (the data importer). The fact that Maurice is a member of the Council of Europe's Protocol 108+ makes no difference under the GDPR. And the fact that Madagascar has a law inspired by the French model does not constitute sufficient assurance in the eyes of the CNIL. This legal status is not an obstacle. It is a contractual parameter. You address it before the start, you document it, and your DPO no longer has grounds to block the project.

1.3: The Transfer Impact Assessment (TIA) Your DPO Is Expecting

Since the Schrems II ruling (CJEU, July 16, 2020), SCCs alone are not sufficient. You must carry out a Transfer Impact Assessment (TIA) that evaluates whether the legislation of the destination country allows local authorities to access transferred data in a manner incompatible with the GDPR. The TIA covers three areas. First area: local legislation on surveillance and government access to data. Neither Madagascar nor Maurice has mass surveillance programs comparable to those identified in Schrems II (US FISA 702). Second area: the additional technical measures you deploy (encryption, pseudonymization, access control). Third area: the provider's practical experience with access requests from local authorities. This document does not need to be 80 pages long. The CNIL and the EDPB accept an assessment proportionate to the sensitivity of the data and the volume transferred. For an SME outsourcing customer support or accounting data entry, a structured and sourced TIA of 5 to 10 pages is sufficient. Your provider must supply factual information about local legislation. If your provider does not know what a TIA is, change providers. To understand the security requirements to be imposed on the financial data side, see Sécurité des données financières offshore : les 6 exigences à imposer avant de signer.

2 – The Contractual Documents to Be Signed Before the First Day of Production

Three separate documents govern the GDPR relationship between your company and your offshore provider. They are not interchangeable, and none replaces the others. Here is their exact content and how they relate to one another.

2.1: Standard Contractual Clauses (SCCs): Which Module to Choose and What It Contains

The June 2021 SCCs are divided into four modules. For standard offshore outsourcing, two modules are relevant. Module 2 (controller to processor): this is the standard case. You are the data controller. Your offshore provider processes data on your behalf. This module applies when your dedicated team members in Madagascar access your CRM, process customer tickets, or enter accounting entries containing personal data. Module 1 (controller to controller): less common in outsourcing. It applies if your provider independently determines the purposes of a processing activity, which almost never occurs in a dedicated team model. The SCC document contains mandatory annexes: description of processing activities, categories of data, categories of data subjects, duration of processing, technical and organizational measures. Each annex must be completed specifically for your activity. A generic, non-customized template protects no one and has no value in the event of an inspection. SCCs are a European Commission document. You cannot modify the main clauses. You complete the annexes and sign. So does the provider.

2.2: Data Processing Agreement (DPA): The 12 Mandatory Clauses of Article 28

The DPA is the data processing contract as defined by Article 28 of the GDPR. It is distinct from the SCCs, even if it can be integrated into the same document. Its mandatory clauses cover: the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data, the categories of data subjects, and the obligations and rights of the data controller. The DPA must require the processor: to process data only on documented instructions from the controller, to ensure the confidentiality of authorized persons processing the data, to implement all security measures required by Article 32, not to engage another sub-processor without prior written authorization, to assist the controller in responding to requests for the exercise of data subjects' rights, to delete or return data at the end of the service, to provide the controller with all information necessary to demonstrate compliance with its obligations, and to submit to audits. This is not an optional document. The absence of a DPA is a direct non-compliance with Article 28. In the event of a CNIL inspection, it is the first document requested. To go deeper into the contractual framework with an offshore provider, Clause NDA et contrat offshore : les 4 points que votre accord doit absolument couvrir en 2026 supplements this section.

2.3: Annex on Technical and Organizational Measures: What Must Be Stated in Black and White

Annex II of the SCCs and Article 32 of the GDPR require a concrete description of security measures. Not statements of intent. Verifiable measures. Access control: multi-factor authentication on all tools containing personal data, role-based rights management, immediate revocation upon departure. Encryption: TLS 1.2 minimum for data in transit, AES-256 encryption for data at rest on workstations. Network security: dedicated VPN between the offshore production site and your systems, configured firewall, network segmentation. Physical security: controlled access to premises, workstation locking, prohibition of removable storage devices. Traceability: logging of data access, retention of logs for a minimum of 12 months. The provider must also document its security incident management policy: detection, notification to the data controller within a maximum of 48 hours (notification to the CNIL must occur within 72 hours), corrective measures. Every measure stated in the annex may be subject to audit. If your provider announces AES-256 encryption but its workstations do not even have a BIOS password, the document is worthless. The annex is contractually binding.

3 – Cross-Border Processing Registry and Provider Compliance Audit

The contractual documents establish the framework. The processing registry and audits demonstrate that this framework is respected over time. Here is how to structure both without dedicating a disproportionate amount of time to them.

3.1: Processing Registry: The Fields Specific to Transfers Outside the EU

Article 30 of the GDPR requires every data controller to maintain a registry. When a processing activity involves a transfer outside the EU, additional fields are mandatory. For each processing activity outsourced to Madagascar or Maurice, your registry must indicate: the name of the processor and its exact location, the destination country of the data, the transfer mechanism used (SCC Module 2, specifying the version and date of signature), the reference of the associated TIA, the categories of data transferred (customer data, HR data, accounting data), the categories of data subjects (customers, prospects, employees), the precise purpose of the processing, and the applicable security measures (referring to Annex II of the SCCs). This registry is not a static document. It must be updated with every change to the scope of processing. If you add a tool, a data flow, or a new type of personal data within the scope of your offshore team, the registry must be updated accordingly. For an SME, a structured spreadsheet with these fields is sufficient. The CNIL provides a basic template, but it does not cover cross-border specifics. You must supplement it. Your provider must maintain its own registry as a processor, in accordance with Article 30-2. Request a copy. To find out how to entrust registry maintenance to an offshore team, see Compliance RGPD externalisée : confier le registre des traitements à une équipe offshore en 2026.

3.2: Provider Compliance Audit: What to Verify and How Often

Article 28-3(h) of the GDPR gives you the right to audit your processor. The SCCs reinforce this obligation. The question is not "should we audit" but "how to audit effectively without engaging a consultancy at €2,000 per day." Three levels of audit are proportionate for an SME. Level 1 (quarterly, remote): documentary review. The provider supplies a compliance attestation, anonymized access logs, proof of GDPR training for dedicated team members, and the status of declared technical measures. Level 2 (semi-annual, remote or hybrid): scenario testing. You simulate a rights exercise request (access, deletion) and measure the provider's response time and compliance. You verify encryption and access configurations on a sample of workstations. Level 3 (annual, on-site or by a mandated third party): full audit of premises, workstations, network infrastructure, incident management policy, and any sub-processing contracts. Document every audit. Retain the reports. In the event of a CNIL inspection or a data breach, these reports demonstrate your due diligence. A provider that refuses to submit to an audit or negotiates excessive restrictions is sending you a clear signal: walk away.

3.3: Case Study: Outsourcing Customer Support and Accounting to Madagascar, Data Flows and Compliance

Let us take a concrete case. Your company outsources two functions to Madagascar: B2B customer support (inbound tickets via Zendesk) and accounting data entry (entries in Pennylane). Flow 1, customer support: your dedicated team member accesses Zendesk tickets containing names, email addresses, order numbers, and exchange histories. Personal data of your B2B customers, sometimes of their own customers. SCC Module 2 covers this transfer. Access is via browser with SSO and MFA. Data remains on Zendesk servers (EU or US depending on your plan). The team member downloads nothing locally. Flow 2, accounting: your team member enters records containing supplier names, bank account details, and invoice amounts. Access to Pennylane is via a named account with rights restricted to data entry. No bulk export is possible. Data remains on the Pennylane infrastructure. For each flow: one line in the processing registry, a signed DPA, annexed SCCs, and a completed TIA. The specific technical measures are documented in Annex II. The team member has signed an individual confidentiality agreement and has completed documented GDPR training. This structuring work takes two to three days before the start of production. It does not slow down operations. It secures them. To assess the full cost of such a project, ROI de l'externalisation offshore en 12 mois : la méthodologie TCO que personne ne publie incorporates these parameters into the calculation. And to structure the scope of accounting delegation upfront, refer to Externalisation comptable offshore : clôturez vos comptes sans recruter un DAF à 80k€.

Every Week Without These Documents Is a Week of Exposure

The GDPR does not prohibit transferring data to Madagascar or Maurice. It prohibits doing so without documented guarantees. Standard contractual clauses signed with the correct annexes. DPA compliant with Article 28. TIA completed and retained. Processing registry updated with cross-border fields. Verifiable technical measures. Audit rights contractualized. Every day your offshore team members access personal data without these documents in place, you accumulate a risk of CNIL sanctions that can reach up to 4% of your annual turnover. And a reputational risk that you no longer control. Compliance work is done before the first access, not after the first incident. Your DPO is waiting for answers. They are in this article. All that remains is to execute them.

Receive your commercial audit for free

Recruitment, supervision, results: we take care of everything. Get a free audit to find out how much you could earn with a Taram Group team.

Free first call
Growth
Visibility
Performance
Conversion
Automation
Subcontracting
Web development
Natural referencing
Optimization
Automation