Expert knowledge for digital decisions
Do Ouhud's developers work in Germany, or is it outsourced?
Short answer
Why the question is justified
Not because of quality. There are good and bad developers in every country, and origin says nothing about that. The question is justified for four other reasons:
| Point | Why it matters |
|---|---|
| Data access | Anyone who sees production data triggers documentation and approval obligations |
| Time zone | More than three hours of difference costs half a working day for every inquiry |
| Technical language | Terms from accounting, medicine, or law translate poorly – misunderstandings end up in the code |
| Contract chain | Who is liable and who can be reached if the subcontractor fails |
What the GDPR specifically requires
- Art. 28 para. 2 GDPR: A processor may not engage another processor without prior specific or general written authorization from the controller. In the case of general authorization, they must notify intended changes and provide you with the opportunity to object.
- Art. 28 para. 4 GDPR: The same obligations must be imposed on the sub-processor; the first processor remains liable.
- Art. 30 GDPR: Transfers to third countries must be included in the record of processing activities.
- Art. 32 GDPR: Access rights, roles, and logging must be appropriate to the risk – this applies to external developers just as it does to internal ones.
The most effective lever is often overlooked
Development on anonymized or synthetic data. If there are no real personal data in the development and testing environment, this largely mitigates the location issue: There is no transfer of personal data, and the circle of people with production access remains small and identifiable.
This requires a one-time effort for a usable anonymization run – and saves ongoing discussions thereafter. It also has a side effect that no contractual clause offers: An accidental test run does not send emails to real customers.
Outsourcing honestly considered
Where it works: clearly defined, well-specified packages – interface connections according to documented specifications, surfaces according to existing designs, test automation, data migrations with a clear target schema.
Where it does not work well: Tasks whose requirements only become clear during construction. This is the norm in custom software. If every second decision triggers a query and every query costs a day, the cheaper hourly rate is consumed within a few weeks.
Another point that is rarely included in offers: turnover. If a position in an outsourced team changes, project knowledge is lost that no one has billed.
When public clients are involved
Public tenders often contain requirements regarding the location of service provision, the language of documentation, and sometimes security checks of the personnel involved. Check this before submitting your bid. A supply chain is difficult to restructure afterwards, and a false statement in the bid is a reason for exclusion.
Four questions that clarify
- Who has access to the production system – by name, with location and contractual relationship?
- Do external parties work with real or anonymized data?
- Who is my contractual partner, and who is liable for third parties in the chain?
- How quickly is access revoked when someone leaves – and who checks that?
What we do not promise
A small software house has limited capacity. Anyone who promises you unlimited availability and a complete waiver of any subcontracting at all is promising at least one of those things too much. The reliable promise is not "never external," but: You will know in advance who is involved, and you can object.
Key facts
- Art. 28 para. 2 GDPR
- Sub-processors may only be engaged with the controller's approval.
- Art. 28 para. 4 GDPR
- The same obligations must be imposed on the sub-processor; the liability of the processor remains.
- Legal basis
- Remote access from a third country to personal data is a transfer under Art. 44 et seq. GDPR.
- Principle
- Development on anonymized or synthetic data largely mitigates the legal location issue.
- Principle
- Public tenders often contain binding requirements regarding the location of service provision.
Sources
All external claims are backed by traceable sources.-
01
Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung) Amt für Veröffentlichungen der Europäischen Union