2 June 20268 min read
Somewhere between the shortlist and the contract, an outsourcing decision usually meets a lawyer, and the first question is whether the supplier is inside the EU. It is a sensible question with a genuine answer, and it gets treated as a binary when it is closer to a cost.
Nothing here is legal advice, and your data protection officer's view outranks anything on a supplier's website. What follows is what changes structurally when you cross the line, so the conversation with them is a shorter one.
What staying inside the EEA genuinely gives you
Three things, and they are real.
- Personal data moving to the supplier is not an international transfer, so Chapter V of the GDPR does not apply and there is no transfer mechanism to put in place
- Contracting, invoicing and VAT sit in a framework your finance and legal functions already operate, usually in your own currency
- The supplier is subject to the same regulator, so your customers and your own compliance function have less to be persuaded of
For an organisation selling into the public sector, healthcare, finance or anywhere with data residency commitments in its own customer contracts, that can be the end of the analysis, and it should be. If you have promised a customer that their data stays in the EEA, no cost comparison overrides that promise.
What actually happens when you cross the line
For a supplier outside the EEA in a country without an adequacy decision, and most outsourcing destinations are in that category, transfers rely on the standard contractual clauses. In practice that is a package: the SCCs themselves, a transfer impact assessment considering the legal environment in the destination country, and a data processing agreement setting out what is processed, by whom, where and for how long, plus the technical and organisational measures.
This is not exotic. It is the same paperwork thousands of European companies complete for suppliers in India, the United Kingdom's neighbours, the Balkans, North Africa and the Middle East. It is a piece of work with a beginning and an end, typically measured in weeks rather than months, and it is done once per supplier rather than once per project.
The mistake is to start it late. If the transfer package is still in draft when the engagement is meant to begin, the engagement begins anyway, informally, and that is the situation you actually want to avoid.
Make the data question smaller before you make it harder
The most effective move is not a better contract, it is arranging the work so that less personal data leaves in the first place. Most engineering work does not need production personal data, and a lot of the compliance difficulty comes from arrangements where it does out of habit.
- Synthetic or pseudonymised data in development and test environments as the default, with a documented exception process
- Production systems accessed through your own EU-hosted environment rather than copied to the supplier's machines
- Named individuals with logged, time-bounded access instead of a standing grant to a team
- Support tooling configured to mask fields the agent does not need to see
Done properly this turns a large transfer discussion into a small one, and it improves your posture with EU suppliers too. It is the rare compliance measure that is worth doing on engineering grounds alone.
Employment law cuts the other way
The EU border helps you on data and hurts you on flexibility, and it is worth saying both. Hiring an employee in an EU member state means that country's employment law: notice periods, severance, works councils in some jurisdictions, and a serious process if the role turns out to be wrong. That protection is deliberate and mostly good, and it is also the reason a permanent hire is a heavier commitment than an engagement.
There is a middle option people forget: hiring through an employer of record inside the EU gives you the EEA position on data and contracting while outsourcing the employment mechanics. It is more expensive per head than a supplier outside the EU, and it is the right answer more often than its share of the discussion suggests.
The comparison that is usually being avoided
The real question is rarely EU versus non-EU. It is whether the compliance work plus the supplier's rate comes out below the cost of the EU option, given that the EU option is a real thing you could buy.
Run it as a total cost of ownership calculation rather than a rate comparison. On the non-EU side, add the transfer package, any external legal review, and the internal time to get it through your own governance. On the EU side, add the higher rate, and add the recruiting time if the alternative is a permanent hire rather than a supplier. Then compare the totals over the length of the engagement, because the compliance cost is largely fixed and the rate difference is not, which means the answer changes with duration.
A one-off cost and a recurring saving do not belong in the same column of a spreadsheet.
What to do with this
Decide the data question first, on its own terms, before you look at a single rate. If EEA residency is a hard requirement, your shortlist is EU suppliers or an employer of record, and everything else is noise. If it is not, treat the transfer package as a line item with a real cost and a real timeline, get it moving early, and then choose on the things that vary day to day: overlap hours, depth in the discipline you need, and whether the provider answers a hard question specifically.
