For different reasons, many companies outsource some job functions or services to a third
party on a contract basis. There are various outsourcing services; the most common
outsourcings are business process outsourcing ("BPO") and Information technology ("IT")
outsourcing. The BPO relates to outsourcing business processes, such as accounts payable,
payroll, and others business functions. While IT outsourcing could be considered a subclass of
BPO, it relates to network services, managed security operations, software implementation,
management, and other tasks. In addition, the outsourcing could be onshore, nearshore, or
offshore.
Offshore outsourcing means hiring an overseas third party. There are some benefits and risks
when a company uses outsourcing resources. For example, some benefits could be lower costs,
possible cash influx resulting from the transfer of assets to the new provider, or increased
flexibility to meet the business and commercial conditions. On the contrary, some risks of
offshore outsourcing include language and cultural barriers, time zone differences, lack of
business knowledge, and lack of controls (Overby, 2022). Furthermore, outsourcing, regardless
of whether offshore or onshore, could increase the risk of data protection or breach of
information security. Therefore, these risks could jeopardize the principles of confidentiality
and privacy.
The company, from the Board of Directors to the staff, including any hired third party, is
responsible for ensuring compliance with the principles of confidentiality and privacy.
Therefore, when a company decides to offshore outsourcing, management must ensure the
offshore legislation aligns or at least comply with certain requirements as if these functions
were performed in the country of the company hiring the third party. According to Hernandes
Rodrigues (2022) the:
Nearshore and offshore outsourcing are still relatively new options with considerable
differences in legislation between territories. The laws of the U.S., the GDPR and the
Brazilian LGPD, despite overlapping, will always have divergences. These divergences
must be addressed individually and according to previously adopted good practices that
are satisfactory for both parties. This makes the process more time-consuming and
complex, but it's a necessary step, at least for the time being. Soon, there will be
enough good practices to mediate nearshoring and offshoring obstacles while
respecting each territory's laws.
Therefore, addressing these divergences is key to ensuring the company can meet the legal and
compliance regulations of the outsourcing and company countries, along with gaining cultural
and territorial knowledge of the country where the company is considering outsourcing. In
addition, the company can create security committees between the outsourcing and the
company and take out cyber insurance. These additional steps or controls indicate that the
company is diligent and performs its duty to protect the privacy of its customers' personal
information.
References:
Hernandes Rodrigues, M. (2022, July 12). The Influence Of Data Protection Laws On Outsourcing
Software Development Projects. Forbes.
https://www.forbes.com/sites/forbestechcouncil/2022/07/12/the-influence-of-data-protection-
laws-on-outsourcing-software-development-projects/?sh=31eb195042dd
Overby, S. (2022, November 25). What is outsourcing? Definitions, benefits, challenges,
processes, advice. CIO. https://www.cio.com/article/272355/outsourcing-outsourcing-definition-
and-solutions.html