GDPR (General Data Protection Regulation): An European Union regulation (formally adopted in 2016, enforceable from May 2018) that governs the collection, processing, storage, and transfer of personal data belonging to EU and UK residents. In a BPO context, it splits legal accountability between the business that decides why data is processed (the Data Controller) and the vendor that processes it on instructions (the Data Processor), binding both parties through a mandatory written contract under Article 28.

If you are outsourcing any function that touches EU or UK personal data, whether that is customer support, billing, claims processing, or debt collections, GDPR is not the vendor’s problem to solve. It is yours. The vendor helps you comply. You remain accountable.

What Does GDPR Mean in Practice for a BPO Buyer?

As the Data Controller, you determine the purpose and legal basis for processing personal data. Your BPO vendor, as the Data Processor, may only act on your documented instructions. That split sounds clean, but the operational implications are not. If your vendor’s agent in Manila opens a customer record without a legitimate reason, that is a data breach that traces back to you. The vendor does not absorb your regulatory exposure just by being offshore.

The seven GDPR principles (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability) govern how data must be handled end-to-end. Vendors can say they follow these principles; your contract and audit rights are what actually enforce them.

A realistic example: an UK debt collections firm outsourcing to a Philippine BPO for roughly GBP 60,000 per month is not just buying capacity. It is creating a cross-border data flow where every agent session, every recorded call, every exported spreadsheet containing EU or UK debtor records must be governed by a compliant legal transfer mechanism. Without that, the collections firm is exposed, not the BPO.

What Is an Article 28 DPA and Why Does It Disqualify Vendors Without One?

An Article 28 Data Processing Agreement (DPA) is the mandatory contract that must exist between every Data Controller and every Data Processor before any personal data is shared. It is not optional, and a vendor’s ISO 27001 certificate or SOC 2 report does not substitute for it. Those certifications tell you something about information security controls. They say nothing about whether the vendor will only process data on your instructions, report breaches within 72 hours, delete data on termination, or allow you audit rights.

I would treat the absence of a signed Article 28 DPA as an immediate disqualifier, regardless of how strong the vendor’s security posture looks on paper.

Key Article 28 requirements a vendor must agree to in writing:

ObligationWhat to Verify in the Contract
Process only on documented instructionsWritten scope in the DPA, not just a verbal briefing
Confidentiality of processing staffAgent NDAs, access controls, clean-desk policies
Security measures (Art. 32)Encryption, access logging, breach response SLA
Sub-processor approvalYou must consent before the vendor adds a sub-processor
Data subject rights assistanceVendor must help you respond to access/erasure requests
Breach notificationVendor notifies you promptly to keep you inside the 72-hour window
Deletion or return on terminationHard deletion with written confirmation
Audit cooperationVendor must allow your audits or a third-party audit

How Do Cross-Border Data Transfers Work When Outsourcing to India or the Philippines?

Neither India nor the Philippines holds EU adequacy status, meaning the EU has not determined that their data protection laws are equivalent to GDPR. That does not make outsourcing to these locations illegal. It means you must use an approved transfer mechanism to make the transfer lawful.

The most commonly used mechanism is Standard Contractual Clauses (SCCs), specifically the 2021 EU SCCs (and the UK International Data Transfer Agreement, or IDTA, for UK GDPR). These are pre-approved contract modules that impose GDPR-equivalent obligations on the importer of data in the third country. You attach them to your Article 28 DPA.

The catch is that SCCs are not self-executing. Under the Schrems II ruling, you must also conduct a Transfer Impact Assessment (TIA) to evaluate whether local laws in the vendor’s country (government surveillance access, for example) undermine the protections the SCCs are supposed to guarantee. Most buyers skip this step. Skipping it does not make the transfer compliant; it just means the gap is undocumented.

I would be careful with any vendor that says “we are GDPR compliant” without being able to show you the specific SCC module they use, who signs it, and whether they have supported a TIA before.

Does GDPR Apply to US Companies Outsourcing to Offshore BPOs?

Yes, GDPR applies to any organization that processes the personal data of EU or UK residents, regardless of where that organization is based. An US company running customer support for EU customers is subject to GDPR. If that company then outsources to a BPO in Colombia or India, the same rules on Article 28 contracts and cross-border transfer mechanisms apply. GDPR does not care about the nationality of the business; it follows the data subject.

GDPR is also still fully in force. The UK retained an equivalent framework (UK GDPR) after Brexit. Both carry fines up to 4% of global annual turnover or EUR 20 million, whichever is higher, for serious violations.

Is GDPR More Strict Than HIPAA?

GDPR is broader in scope but the frameworks are not directly comparable. HIPAA is sector-specific, covering protected health information in US healthcare. GDPR covers all categories of personal data for EU residents across every sector. GDPR’s individual rights (the right to erasure, right to portability, right to object to processing) are more expansive than HIPAA’s equivalents. HIPAA imposes more prescriptive technical safeguards in some areas. If your BPO process involves EU health data, both frameworks may apply simultaneously, and you need a vendor that can demonstrate compliance with each separately.

If you are evaluating BPO vendors for any process touching EU personal data, get outsourcing quotes from vendors who can show you a signed Article 28 DPA template and explain the transfer mechanism they use before the first data file changes hands.