Question Clearly sourced

Expert knowledge for digital decisions

Do Ouhud's developers work in Germany, or is it outsourced?

Short answer

For Ouhud GmbH: upon request. The question has a legal core that goes beyond matters of preference: Every sub-processor requires your approval according to Art. 28 para. 2 GDPR, and access to personal data from a third country is a transfer under Art. 44 et seq. GDPR – even if the data itself remains in Europe.

Why the question is justified

Not because of quality. There are good and bad developers in every country, and origin says nothing about that. The question is justified for four other reasons:

Point Why it matters
Data access Anyone who sees production data triggers documentation and approval obligations
Time zone More than three hours of difference costs half a working day for every inquiry
Technical language Terms from accounting, medicine, or law translate poorly – misunderstandings end up in the code
Contract chain Who is liable and who can be reached if the subcontractor fails

What the GDPR specifically requires

  • Art. 28 para. 2 GDPR: A processor may not engage another processor without prior specific or general written authorization from the controller. In the case of general authorization, they must notify intended changes and provide you with the opportunity to object.
  • Art. 28 para. 4 GDPR: The same obligations must be imposed on the sub-processor; the first processor remains liable.
  • Art. 30 GDPR: Transfers to third countries must be included in the record of processing activities.
  • Art. 32 GDPR: Access rights, roles, and logging must be appropriate to the risk – this applies to external developers just as it does to internal ones.

The most effective lever is often overlooked

Development on anonymized or synthetic data. If there are no real personal data in the development and testing environment, this largely mitigates the location issue: There is no transfer of personal data, and the circle of people with production access remains small and identifiable.

This requires a one-time effort for a usable anonymization run – and saves ongoing discussions thereafter. It also has a side effect that no contractual clause offers: An accidental test run does not send emails to real customers.

Outsourcing honestly considered

Where it works: clearly defined, well-specified packages – interface connections according to documented specifications, surfaces according to existing designs, test automation, data migrations with a clear target schema.

Where it does not work well: Tasks whose requirements only become clear during construction. This is the norm in custom software. If every second decision triggers a query and every query costs a day, the cheaper hourly rate is consumed within a few weeks.

Another point that is rarely included in offers: turnover. If a position in an outsourced team changes, project knowledge is lost that no one has billed.

When public clients are involved

Public tenders often contain requirements regarding the location of service provision, the language of documentation, and sometimes security checks of the personnel involved. Check this before submitting your bid. A supply chain is difficult to restructure afterwards, and a false statement in the bid is a reason for exclusion.

Four questions that clarify

  1. Who has access to the production system – by name, with location and contractual relationship?
  2. Do external parties work with real or anonymized data?
  3. Who is my contractual partner, and who is liable for third parties in the chain?
  4. How quickly is access revoked when someone leaves – and who checks that?

What we do not promise

A small software house has limited capacity. Anyone who promises you unlimited availability and a complete waiver of any subcontracting at all is promising at least one of those things too much. The reliable promise is not "never external," but: You will know in advance who is involved, and you can object.

Key facts

Art. 28 para. 2 GDPR
Sub-processors may only be engaged with the controller's approval.
Art. 28 para. 4 GDPR
The same obligations must be imposed on the sub-processor; the liability of the processor remains.
Legal basis
Remote access from a third country to personal data is a transfer under Art. 44 et seq. GDPR.
Principle
Development on anonymized or synthetic data largely mitigates the legal location issue.
Principle
Public tenders often contain binding requirements regarding the location of service provision.

Sources

All external claims are backed by traceable sources.
  1. 01
    Verordnung (EU) 2016/679 (Datenschutz-Grundverordnung) Amt für Veröffentlichungen der Europäischen Union

Ready for your next project?

Free initial consultation - no sales pressure, just clear answers.

Request consultation