Skip to main content
  • GDPR
  • Procurement

Using a processor outside the EU without exposing your compliance

Transfers outside the European Union are not prohibited, they are governed. What you must obtain from your provider, and what your DPO will check in your register.

· 4 min read · AzerOps

An IT department considering a provider outside the European Union usually gets two contradictory answers: "it has been prohibited since Schrems II" and "everyone does it, it is fine". Both are wrong. The transfer is possible, it is governed, and the governance produces specific documents you must hold.

Who is responsible for what

In a standard client-provider IT relationship, you are the controller and the provider is the processor. That classification has a direct consequence: you answer to the supervisory authority, not them. A non-compliant provider does not only create a risk on their side, it creates a non-compliance on yours.

That is why demanding the documents is not administrative box-ticking, it is protection.

The four documents to obtain

1. The data processing agreement, compliant with Article 28. It must specify the subject matter and duration of processing, its nature and purpose, the categories of data and data subjects, the processor's obligations, the named list of sub-processors, the technical and organisational measures, and the fate of the data at contract end. A two-page document saying "we comply with the GDPR" is not a DPA.

2. Standard contractual clauses. For a country without an adequacy decision, the transfer relies on the clauses of European Commission decision 2021/914. Check the right module is used: module 2 for controller to processor, module 3 for processor to sub-processor.

3. The transfer impact assessment. Since the Schrems II ruling, the clauses alone are not enough. You must assess whether the destination country's law allows local authorities access to data that would empty the clauses of effect, and document the supplementary measures that offset that risk.

4. The description of supplementary measures. This is where the arrangement's credibility is decided. Effective measures are concrete: bastion access with no local extraction, pseudonymised data in development environments, encryption in transit and at rest, access logging available on request, revocation at end of assignment.

The particular case of Morocco

Morocco has a data protection law, law 09-08, and a supervisory authority, the CNDP, with which any processing carried out on its territory must be registered. That registration is a local obligation of the provider; it does not replace the GDPR framework applicable to your relationship.

Morocco has no adequacy decision. The transfer therefore falls squarely under the standard contractual clauses and impact assessment described above. A provider who claims otherwise, or tells you the CNDP registration is enough, is either mistaken or misleading you.

What your register must contain

For each processing activity entrusted, your record of processing activities must name the processor, the destination country, the nature of the transfer, the legal instrument used and the signature date. It is the first thing a supervisory authority asks for, and also the first thing a large enterprise client will ask for in their own vendor questionnaire.

The shortcut that saves weeks

Ask for the four documents at the first commercial exchange, before any technical meeting. A provider who supplies them within forty-eight hours has already dealt with the subject. A provider who promises to produce them "at contract stage" does not have them, and you will discover the problem at the worst moment: once the decision is made and the schedule is committed.

Related articles

Twenty minutes is enough to know whether we are useful

No sales deck. You describe the need, we say whether it is in scope, at what price and on what timeline. If it is not for us, we say so during the call.