codexier.

Business Operations

Outsourcing Data Entry: The GDPR Paperwork

By CodexierPublished 5 min read

Handing data entry to an outside provider saves hours, but it also means someone outside your company handles personal data you are responsible for. GDPR does not forbid that; it requires paperwork and controls that match the risk. This guide explains when a provider becomes your processor, what the data processing agreement must contain, how to limit and log access, and what changes when the work happens outside the EU.

When a provider becomes your processor

The test is who decides why and how the data is used. You decide that customer orders are registered in Fortnox or that leads go into the CRM; the provider does the typing. That makes you the controller and them the processor. A provider who uses the data for their own purposes, for example to market to your customers, is no longer just a processor, and that is a line the agreement should forbid them to cross.

Even small jobs count. Registering supplier invoices includes contact names; scanning receipts may include employees' names; updating a customer list is pure personal data. If the task touches information about identifiable people, treat the provider as a processor.

The data processing agreement

Most reputable providers have a standard agreement. Read it against this list rather than signing on trust; the points below are what Article 28 requires, plus two that matter in practice.

  • The subject, duration, nature and purpose of the processing, and the types of data and people involved.
  • That the provider only acts on your documented instructions.
  • Confidentiality commitments for everyone who handles the data.
  • Security measures, described concretely enough to check: named accounts, two-factor login, encrypted devices.
  • Rules for sub-processors: which ones are used now, and that you are told before new ones are added.
  • Help with data subject requests and breach notification, with a deadline short enough for you to meet the 72-hour rule to IMY.
  • Deletion or return of all data when the assignment ends.
  • Your right to audit, or at least to receive documentation of compliance.
  • In practice: where the work is physically done, and who at the provider is your contact for data protection questions.

Access limits and logging

The paperwork is only half the job. Most real incidents come from too-broad access: a shared admin login, a full customer export sent by email, a spreadsheet left in someone's personal cloud storage. Set up access so that a mistake is small and visible.

ControlHow to do itWhy it matters
Named accountsOne user per person at the provider, never a shared loginYou can see who did what and remove one person without resetting everything
Least privilegeA role that can register and edit, not export or delete in bulkLimits damage from mistakes and compromised accounts
Two-factor loginRequired on every account the provider usesStops most password-based takeovers
No local copiesWork happens in your systems; files are shared through a controlled folder, not emailData does not spread to places you cannot delete it from
Logging and reviewCheck the system's activity log monthly and after the assignment endsUnusual exports or logins are spotted early

Writing down the routine before you delegate makes these limits easier to set, because you know exactly which fields the task touches. Our guide to documenting routines before delegating walks through it.

Transfers outside the EU

When someone outside the EU or EEA views or edits your data, that counts as a transfer, even if the data stays on a server in Sweden. A transfer needs a legal basis: an adequacy decision for the country (the United Kingdom and Switzerland have one, among others), or the EU's standard contractual clauses plus an assessment of whether local law lets authorities access the data. For many offshore data entry setups, that assessment is the part providers cannot answer well.

Cost is not the only factor when choosing where the work is done. Our comparison of admin support in Sweden, the EU or offshore covers the practical trade-offs alongside the legal ones.

Checking your provider

  1. Ask for their data processing agreement and list of sub-processors before you ask for a price.
  2. Ask where each person on your assignment works from, and what devices they use.
  3. Ask how they handle a mistake, such as data entered in the wrong customer record, and how fast you would hear about it.
  4. Ask what happens to your data on the last day of the assignment, and ask for written confirmation when it is done.
  5. Record the provider in your own register of processing activities, with a link to the signed agreement.

When you do not need to outsource at all: if the volume is a few hours a month, or the data is highly sensitive (health, children, criminal records), it is often better to keep the work in-house or automate the source instead of adding a processor. And if a provider cannot answer the questions above clearly, that includes us. Our data entry and back office service works inside your systems under a signed processing agreement, with EU-based handling.

Frequently asked questions

Is a confidentiality clause in the main contract enough?

No. GDPR requires specific content in the processing agreement: instructions, security, sub-processors, assistance, deletion and audit. A general confidentiality clause covers only one of those points.

Do I need to tell my customers that a provider handles their data?

Your privacy notice should state the categories of recipients, for example administrative service providers. You do not usually need to name each processor, but you must be able to say who they are if a customer asks.

What if the provider causes a data breach?

They must notify you without undue delay, and you remain responsible for reporting to IMY within 72 hours when the breach is reportable. That is why the agreement should set a short notification deadline for the provider.

Want a second pair of eyes on your setup?

Tell us which task you want to hand over and which systems it touches. In a short call we outline the access you need to set up and the agreement points to check, whether or not you end up working with us. Book a call.

Book a free 15-minute call