GDPR Compliance in BPO: What to Check Before Outsourcing
Key Takeaways
- When you outsource, you stay the data controller. Your vendor only becomes a processor. You keep primary legal responsibility, but the vendor can face direct liability too
- ICO fined British Airways, Marriott and Ticketmaster in 2020. Though they blamed vendors or inherited systems. Regulators denied their excuses outright.
- Article 28 makes a signed DPA mandatory the moment a vendor touches personal data, covering breach notification within 72 hours, audit rights and data deletion items.
- Your vendor must support fast access, correction and deletion of customer data whenever they request it.
- AI use by your vendor can trigger a DPIA requirement, with EU AI Act deadlines now pushed to December 2027 and August 2028 depending on the tool type.
- GDPR fines run up to €20 million or 4% of global turnover, as shown by Meta’s €1.2 billion penalty and TikTok’s €530 million fine for unlawful data transfers.
You can outsource business functions to a BPO service provider under GDPR, where the BPO provider handles the client’s data. GDPR requires a written data processing agreement between the customer and provider. The client still remains the data controller according to GDPR, even after passing the work to the provider.
This guide is built for small business owners and operations managers checking third-party vendors or VA vendors right now. The complete process must emphasize GDPR risks before the agreement is signed. This isn’t legal advice for regulators or big compliance teams. It’s a practical guide for buyers making the exact decision.
Who’s Liable When You Outsource to a BPO Vendor?
You remain the data controller when you outsource to a BPO vendor. Vendors only become data processors. This means the data controller carries primary legal liability, even after the vendor works on the data.
You give away the data, but you don’t bypass the risks. You hand over the data, but you don’t hand over the risk. Most buyers assume the opposite. They think a vendor’s promise to control compliance means the provider takes on the risk. That’s not how GDPR works.
Suppose your BPO vendor gets hacked. EU customer data is breached. Who is mainly liable, you or the vendor? Under GDPR, you’re the data controller. That means the main responsibility is yours.
In 2020, the ICO fined British Airways, Marriott and Ticketmaster for failing to secure customer data properly. BA and Ticketmaster blamed vendors in their supply chains. Marriott blamed a system inherited through its Starwood acquisition. The UK’s ICO rejected their excuse fast. Working with a vendor doesn’t hide your responsibility.
The three companies were fined as the data controller, not the vendor. Remember, a data processing agreement (DPA) helps. So does vetting your vendor and checking in regularly. These lower your risk. They don’t wipe it out.
What Must a Data Processing Agreement Include?
A compliant general data processing agreement (GDPR) spells out three things. What data the vendor can use it for? How they must protect? And how fast they must tell you about a breach?
This document is mandatory. Article 28 requires it the moment your vendor touches personal data.
A compliant DPA must address:
- Data Operations: The objective and scope of the data operations
- Data Overview: The classification of personal information and groups of people covered.
- Data Protection: The safety standards the provider agrees to use.
- Third-Party Hiring: The guidelines for using outside providers, including notice and permission.
- Data Breach Notification: A notification period strictly under 72 hours, enabling you to fulfill your independent regulatory obligations.
- Compliance Verification: You have the legal right to inspect and demand documentation of the contractor’s safety practices.
- Post-Contract Data: The rules for deleting or returning information once the partnership ends.
When a vendor won’t sign a privacy agreement, listen to that red flag and protect yourself.
What Data Subject Rights Mean for Your Vendor?
Under GDPR, Individuals have the right to access, update or delete their data. Your vendor must follow the same rules for your customers’ data.
- Your vendor must give your customers easy access to their own data, so they can review or correct it.
- Your vendor’s system must handle these requests within the legal deadline.
- Confirm your vendor can locate, correct and fully delete a customer’s personal data before you sign.
- Check whether your vendor already has a facility to allow access, correction and deletion requests.
- If a vendor isn’t ready to protect your customers’ data, they’re not ready to work with you.
Your vendor must follow your instructions exactly on data entry and processing. They should never change data without your approval and they must support your ability to respect customer rights like access, correction and deletion.
Vendor Vetting Checklist: Questions to Ask Before You Sign
Always ask your BPO vendor about data storage, user access, third-party workers and breach alerts before signing a contract. Competent vendors always answer right away. This checklist from YesAssistant focuses on the questions that reveal whether a vendor is being honest or hiding something.
See the questionnaires below:
- Where is our information hosted and what country is the data center in?
- What specific roles within your organization have data access and how is that authorization monitored and managed?
- Do you use third-party workers and will you tell us before giving them access to our information?
- What is your process for reporting a breach and what is your notification timeline?
- Can you provide a previously signed data protection agreement?
- Do you have current-year ISO 27001 or SOC 2 certification and would you please send us your most recent independent audit report?
- Have you appointed a Data Protection Officer or equivalent to manage privacy inquiries?
- How many times a year does your data protection officer take data safety classes? What does the training cover in detail?
- What is your exit plan when a customer ends their contract?
- Have you trained employees who are skilled in using AI tools and if yes, which AI model do you use?
If a vendor fences on these questions, or just says “we take data security seriously” without specifics, watch out. They likely don’t have a real security system in place.
Cross-Border Data Transfers: EU/EEA vs. Offshore Vendors
European vendors follow GDPR by law. Offshore vendors need specific legal agreements to ensure your data safety. This all depends on data residency, where your data physically lives. Both options can work. So, pick the one that best fits with your budget and safety goals.
| Factor | European (EU/EEA) Vendor | International (Offshore) Vendor |
| Legal Rules | GDPR laws apply automatically. | Needs special transfer contracts or approved status. |
| Contract Needed | Standard privacy agreement (DPA). | Privacy agreement plus extra international clauses. |
| Enforcement | Quick action by European privacy offices. | Slower process relying on international law. |
| Main Trade-off | Higher price, but much simpler rules. | Lower price, but more legal paperwork. |
An international vendor with a proper transfer agreement is as safe as an EU vendor. You just have to handle more forms to reach the same result.
What Happens If Your Vendor Uses AI to Process Your Data?
Under the GDPR, if an outsourcing partner uses AI to process customer data in a way that is likely high-risk, you must complete a privacy risk assessment (DPIA) before the project begins. More rules apply once the EU AI Act’s provisions take effect.
Note: Following the EU AI Act Digital Omnibus, high-risk AI systems under Annex III must comply from December 2, 2027, while high-risk systems under Annex I apply from August 2, 2028.
See carefully, if your BPO vendor uses AI for ticket prioritization or quick data entry, they should follow GDPR Data entry rules properly. Typically, vendors follow the rules while using AI for automated tasks. Let’s discuss this with your vendor regarding the issues sign off.
Please state which AI model your vendor uses, whether you data trains it and whether a DPIA was completed before launch. Your vendor may not have thought about this. Many vendors are still catching up on the regulations.
What Non-Compliance Actually Costs?
The GDPR uses a two-tier system to determine fines. The lower tier is up to €10 million or 2% of global annual turnover, whichever is higher. The upper tier is up to €20 million or 4% of global annual turnover, whichever is higher. The data violation fine tiers apply to data subject rights or unlawful transfers.
In May 2023, Ireland’s Data Protection Commission fined Meta 1.2 billion euros for illegally transferring European data to the US. In May 2025, the Commission again fined TikTok €530 million due to shifting EEA data to China without following the data protection guidelines.
Ireland’s DPC fined both companies as the data controller, applying the same principle the ICO used against British Airways. The company that decides how data is processed carries the liability. Responding to a breach quickly and with full cooperation can reduce the fine.
Under GDPR, Germany’s data protection authority reduced a fine to 20,000 euros as the company reported the breach immediately with full cooperation. This is a small portion of penalty, otherwise, it may result in more.
GDPR vs. HIPAA vs. CCPA for Multi-Market Vendors
A vendor working with clients in Europe, the US and California must follow three separate laws, GDPR, HIPAA and CCPA. GDPR covers no single framework, it is associated with a signed HIPAA business associate agreement and CCPA disclosure practices together.
| Framework | Who it covers | What’s required |
| GDPR | European individuals’ private information. | Data Processing Agreement requires a legal justification to process personal information and mandates that any security breach be reported within 72 hours. |
| HIPAA | This framework protects US patient health information | This mandate requires a signed business associate agreement. |
| CCPA | This framework regulates California residents’ personal data. | Mandates disclosure of data practices and opt-out rights. |
Your vendor may serve multiple regulated markets. In this case, ask them which specific framework governs each part of your data. Don’t simply accept whichever framework they mention first.
Is Full BPO Overkill for What You Actually Need?
If your task list is short, covering data entry, scheduling, or email management, hiring a virtual assistant is the lower-risk option. Hiring a BPO requires large-scale data infrastructure, not a small task list.
A smaller surface area is not a compliance guarantee. If your operational needs already require large-scale, full business process outsourcing makes more sense. The vendor evaluation checklist above still applies to any company you shortlist.
When you outsource work, you are still responsible for keeping individuals’ data safe. GDPR states that you remain the data controller even if you outsource tasks to a third-party service provider. Discuss this with your BPO partner before you sign a DPA.
Check if you need a large or small team for your work. Let’s explore with a virtual assistant and add more help only when you need it.
FAQ
Is it legal to outsource data processing under GDPR?
Yes, as long as you use a verified vendor with a signed data processing agreement. Data outsourcing is not inherently risky, but an unverified vendor is unsafe.
Who is liable if my BPO vendor causes a data breach?
According to GDPR, the client is the data controller and bears the primary responsibility. The third-party BPO vendor acts as the data processor and faces direct regulatory liability. This means both parties can be subjected to regulatory investigation and fines. The data controller retains main accountability, alongside the vendor’s direct liability as processor.
Does GDPR apply if my company isn’t based in the EU?
Yes, GDPR applies if you process the personal data of individuals located in the EU, regardless of where your company or your BPO vendor is physically based. The location of the processing work does not matter; what dictates compliance is the location of the data subjects
What is a data processing agreement and do I need one?
A DPA is a legal contract required by GDPR (under Article 28). It’s a mandatory document you must sign the moment a vendor touches any personal data for you.
What changes if my BPO vendor is outside the EU or EEA?
If your BPO vendor is outside the EU or EEA, transferring data to them becomes harder. To do it legally, you must use special legal tools like Standard Contractual Clauses (SCCs) or the vendor’s country must have an official “adequacy decision” (an approval from the EU saying their laws are safe).
Does using an AI-powered BPO vendor create extra GDPR obligations?
Yes. If your vendor’s AI use is likely high-risk, GDPR requires a DPIA before the tools go live. High-risk AI tools from the vendor may fall under additional requirements set by the EU AI Act.
How is GDPR different from HIPAA for a vendor serving both markets?
GDPR protects all personal data for people in the EU, while HIPAA protects US healthcare information. When a vendor serves both markets must sign separate paperwork for each. A data processing agreement for GDPR and a business associate agreement for HIPAA.