The 2026 Outsourcing Compliance Checklist for Businesses Hiring Remote Staff From India
- Buyers with GDPR, DPDPA, or industry-compliance exposure hiring remote staff from India
- In-house counsel reviewing an offshore staffing arrangement
- Founders who want the compliance checklist before signing anything
How we sourced this article
This compliance framework draws from LegelpTech Outsourcing Pvt Ltd’s ISO 27001:2022 documentation, 2024–2026 procurement engagement records across 500+ placements, and external research from Fisher Phillips on India’s DPDP Act, Emapta’s GDPR outsourcing guide, Amazon Business’s 2026 vendor compliance guidance, and Copla’s third-party risk types. For neutral encyclopedic background on outsourcing compliance, see Remote Staffing Wiki.
ISO 27001:2022 certified operator · GDPR DPA available on request · DPDPA 2023 alignment (Feb 2026 effective) · NDA + IP assignment from Day 1
Compliance is no longer a back-office concern when outsourcing to India. GDPR extraterritoriality, India’s DPDP Act 2023 (effective Feb 2026), and increased vendor risk scrutiny make compliance posture a first-line buying criterion. This is the 8-point checklist every international buyer should walk before signing — and how Zedtreeo, through LegelpTech Outsourcing Pvt Ltd, meets each item.
Why compliance matters more in 2026
Three shifts changed the compliance conversation for offshore staffing in 2026:
- GDPR extraterritoriality is fully enforced. EU and UK buyers remain liable as controllers regardless of where data is processed — including India.
- India’s DPDP Act 2023 is in active implementation through 2026–2027, with reasonable security and contractual data-processor obligations now baseline (Fisher Phillips).
- Third-party risk scrutiny has hardened. Vendor compliance is now an annual audit item for most mid-market and enterprise buyers (Amazon Business vendor compliance 2026, Copla third-party risk).
If you can’t tick the boxes below in a procurement review, you can’t close the deal.
The 8-point outsourcing compliance checklist
1. Information security certification (ISO 27001 or equivalent)
The independent audit baseline. Buyers commonly evaluate vendors against ISO 27001 (or, in US enterprise procurement, against the comparable SOC 2 Type II framework). Without a third-party audit baseline, vendor security claims are unverifiable.
Zedtreeo / LegelpTech (verified): ISO 27001:2022 certified by QFS Management Systems LLP. SOC 2 is not currently part of Zedtreeo’s verified compliance stack; ISO 27001:2022 is the third-party audit cert on file.
2. Data Processing Agreement (DPA) and GDPR alignment
Required if you process EU/UK personal data. The DPA codifies the controller-processor relationship and locks in SCCs where applicable.
Zedtreeo / LegelpTech: GDPR-aware workflows; DPA available on request; SCCs where applicable.
3. India DPDP Act 2023 compliance posture (2026 transition)
The provider should have a documented DPDPA alignment plan, fiduciary responsibilities mapped, and reasonable security practices implemented.
Zedtreeo / LegelpTech: DPDPA 2023 tracked; reasonable security practices documented under ISO 27001:2022; planning-aligned for full effect.
4. Employment classification and Indian labour law compliance
The provider should employ remote staff directly under proper Indian employment contracts — covering Shops & Establishments Act registration, PF/ESI as applicable, and gratuity provision.
Zedtreeo / LegelpTech: Standard direct employment under LegelpTech Outsourcing Pvt Ltd; full compliance with applicable Indian labour law.
5. NDA and IP protection for every placement
Confidentiality and IP assignment should be signed before Day 1 of any trial. The IP assignment must transfer full ownership to the client.
Zedtreeo / LegelpTech: NDA + full IP assignment executed pre-trial.
6. Incident response and breach notification protocol
Documented IR plan, named incident commander, and breach notification window (72 hours under GDPR).
Zedtreeo / LegelpTech: IR plan documented under ISO 27001; 72-hour notification standard.
7. Audit rights and ongoing vendor monitoring
The contract should permit annual vendor security questionnaires and, for regulated industries, on-site or remote audit rights.
Zedtreeo / LegelpTech: Audit rights provisioned in the standard staffing agreement; annual security questionnaire support standard.
8. Exit and termination clause
Clean exit terms, data return/destruction obligations, and notice periods that protect the buyer.
Zedtreeo / LegelpTech: 30-day termination notice as standard; documented data return and destruction protocol under ISO 27001 Annex A.8.
Request the full compliance pack →
GDPR and India outsourcing — what international buyers need to know
Three concrete obligations for EU/UK buyers engaging Indian providers:
- You remain the GDPR controller. Your provider is the processor. Liability for compliance does not transfer.
- You need a signed DPA + SCCs. India is not a GDPR adequacy country; standard contractual clauses are required for cross-border transfer.
- You should document the data flow. What personal data does your provider touch, where does it live, and how is it returned/destroyed at exit.
See Emapta’s practical GDPR outsourcing guide for buyer-side context.
The DPDPA framework helps: an Indian provider processing data on behalf of an overseas controller absorbs Indian-law obligations, leaving the buyer to focus on its primary regime (typically GDPR/CCPA).
Common compliance mistakes buyers make
Across our 500+ placements and procurement conversations, three mistakes appear repeatedly:
- Not requesting the ISO certificate. Buyers ask “are you certified?” and accept a yes. Always request the certificate PDF and the scope statement.
- No DPA in the contract. EU/UK buyers sign a staffing agreement without the data processing addendum. You become non-compliant the moment data is shared.
- Assuming GDPR obligation transfers to the vendor. It doesn’t. You remain controller; the vendor is processor. Read the ICO controller/processor guidance before signing.
Asking for the documentation up front separates real providers from marketing copy.
Compliance comparison — Zedtreeo vs. typical unmanaged outsourcing
| Compliance item | Marketplace freelancer | Unmanaged BPO | Zedtreeo / LegelpTech |
|---|---|---|---|
| ISO 27001:2022 cert | ✖ | Variable | ✓ ISO 27001:2022 |
| GDPR DPA | ✖ | Variable | ✓ Available |
| DPDPA 2023 posture | ✖ | Variable | ✓ Tracked, aligned |
| Indian labour law compliance | ✖ (freelancer = unregulated) | Variable | ✓ Standard direct employment |
| NDA + IP assignment pre-Day-1 | ✖ | Sometimes | ✓ Always |
| Documented IR + 72-hr notification | ✖ | Variable | ✓ Yes |
| Audit rights | ✖ | Sometimes | ✓ Yes |
| Clean exit + data destruction | ✖ | Variable | ✓ Documented |
The word to watch in this comparison is “Variable.” A marketplace freelancer fails every row outright — no certification, no DPA, no incident response — but an unmanaged BPO is arguably riskier, because you assume coverage that may not exist. Before signing with any provider, ask for the specific artifacts: the ISO 27001:2022 certificate, a signed DPA, an NDA and IP assignment executed before day one, and a documented 72-hour breach notification commitment. If the answer is “we can discuss that,” treat it as a no.
How to request compliance documentation from Zedtreeo
The compliance pack we send on request includes:
- ISO 27001:2022 certificate (PDF) with scope statement
- Data Processing Agreement (DPA) template
- Standard NDA + IP assignment template
- Incident Response Plan summary
- DPDPA 2023 alignment memo
- Indian labour law and employment compliance memo
- Vendor security questionnaire (pre-filled responses to common SIG/CAIQ items)
Turnaround on the pack is 1–2 business days. Procurement teams routinely close the compliance line item from this pack alone. Request the compliance pack →
The vendor vetting process, step by step
The eight-point checklist above tells you what to verify. This section is the how: a five-step process that takes a longlist of offshore staffing vendors down to one signed agreement, without relying on marketing pages for any load-bearing claim.
Step 1 — Longlist on verifiable basics (30 minutes)
Before any calls, eliminate vendors that fail on public facts: no identifiable legal entity on the website, no named operating company, no physical address, no certification claim you can trace to a certificate number. A staffing vendor that won't tell you who you would be contracting with has already answered your first due-diligence question.
Step 2 — Send a written RFI, not a discovery call
Ask for documents in writing before you take the sales call: certificate copies, a specimen contract or MSA, the DPA template, and the entity name that appears on invoices. Written requests do two things — they produce artifacts you can file in your compliance memo, and they surface the vendors whose claims evaporate when asked for paper.
Step 3 — Review the documents against the checklist
Map every document you receive to the eight checklist items: certification (verify the certificate number with the issuing body, not the vendor), DPA terms against your GDPR or DPDPA obligations, employment classification (who is the employer of record?), NDA and IP assignment language, breach notification windows, audit rights, and the exit clause. Anything the documents don't cover goes on the call agenda — anything the vendor refuses to document goes in the red-flag column.
Step 4 — Reference and pilot
Ask for a reference client in your industry or timezone, and treat a paid pilot as part of vetting, not as commitment. A vendor confident in its bench offers a short trial with a real deliverable — Zedtreeo's version is a 5-day risk-free trial — because the fastest way to verify a staffing vendor's claims is to watch one of its people work for a week.
Step 5 — Negotiate the contract on the items that matter
The commercial rate is the least negotiable part of a staffing agreement; the compliance terms are the most. Push on breach notification timelines, replacement terms, IP assignment on every placement (not just on request), audit rights, and a termination clause you could actually operate. A vendor that resists contractual versions of its verbal promises is telling you which promises were real.
Red flags that should end the conversation
- The contracting entity can't be named in writing, or differs from the brand with no explanation.
- "ISO certified" appears on the website but no certificate number or issuing body is provided on request.
- The vendor proposes to onboard your data before a DPA or NDA is signed.
- No employer-of-record answer — the vendor can't say who employs the worker and who carries payroll and statutory compliance.
- Pricing that only exists on a call — nothing published, everything "custom".
- No replacement or exit terms in the specimen contract, or a notice period measured in quarters rather than weeks.
- References that can't be produced in any form — not even anonymized or under NDA.
The copy-paste document request list
- Full legal name, registration number, and registered address of the contracting entity.
- Copy of the information-security certificate (with certificate number and issuing body we can verify independently).
- Specimen MSA or service agreement, including replacement, termination, and IP-assignment clauses.
- Data Processing Agreement template (GDPR Art. 28 terms if we're EU/UK; DPDPA posture for Indian processing).
- Specimen staff NDA and confirmation it is signed before system access is granted.
- Written description of the breach notification protocol and timeline.
- Statement of employer-of-record status: who employs the specialist and carries payroll, tax, and labour-law compliance.
- One reference client (anonymized is acceptable) in a comparable industry or engagement size.
Vendor scoring matrix
When you're comparing more than two vendors, score them instead of debating them. Weight the dimensions by your own risk profile — a healthcare buyer weights data handling heavier; a firm hiring one assistant weights exit terms lighter — and disqualify on any zero in the first three rows regardless of total score.
| Dimension | Weight | What a top score looks like |
|---|---|---|
| Verifiable entity & certification | 25% | Named legal entity; certificate number verified with the issuing body |
| Data protection terms | 20% | DPA signed pre-onboarding; breach notification in writing with timelines |
| Employment & IP chain | 20% | Clear employer of record; NDA + IP assignment on every placement by default |
| Contract operability | 15% | Replacement terms, audit rights, and an exit clause measured in weeks |
| Proof of delivery | 10% | References produced; paid pilot or trial offered without resistance |
| Pricing transparency | 10% | Published rates; the invoice entity matches the contracting entity |
Running the pilot as a compliance exercise
Most buyers treat the trial week as a skills test. It is also your best compliance probe — the one week where you can observe how the vendor actually operates before you depend on it. Use it deliberately: verify the NDA was signed before system access was granted (ask for the signed copy, dated); provision access on least-privilege terms and watch whether the vendor requests more than the task requires; send one security-relevant request mid-week — say, asking how to report a suspected phishing email — and time the response; and at the end of the week, revoke access and confirm the vendor's offboarding actually happens rather than lingering. A vendor that passes the working test of its own policies is worth more than one with a thicker policy PDF.
After signature: the re-verification cadence
Due diligence is not a one-time gate. Certificates expire, entities restructure, and the sub-processor list you approved in January may not be the one operating in October. A light annual cadence keeps the file honest without becoming a project:
- Re-verify the information-security certificate against the issuing body — check the expiry date, not just the logo.
- Confirm the contracting entity is unchanged on the latest invoice; a silent entity swap is a contract event, not a formality.
- Request the current sub-processor list and compare it to the one attached to your DPA.
- Re-test the breach-notification contact: does the escalation address still answer?
- Review access grants for your engaged specialists against current scope — remove anything the work no longer requires.
- Re-read the exit clause against your current dependency: could you actually operate the transition it describes?
Put the cadence in the calendar when you sign, not when you first worry. The buyers who get surprised by vendor risk are almost never the ones who skipped due diligence at signature — they're the ones who did it once and never looked again.
Frequently asked questions
Does Zedtreeo sign our GDPR DPA?
Yes. LegelpTech Outsourcing Pvt Ltd (the operating entity) signs standard GDPR Data Processing Agreements. SCCs are included where applicable for EU/UK cross-border transfers. DPA template is in the compliance pack.
Is data processed in India covered by GDPR?
Yes — GDPR follows the data, not the geography. If you are an EU/UK controller, your provider is a processor under GDPR regardless of processing location. India’s DPDPA 2023 runs in parallel for India-side obligations.
What Indian labour laws apply to my remote employee?
Your remote employee is employed directly by LegelpTech Outsourcing Pvt Ltd under Indian employment law (Shops & Establishments Act, applicable PF/ESI, gratuity). You contract with LegelpTech for the placement; you do not become an Indian employer.
Is Zedtreeo’s compliance documentation available before signing?
Yes. The full compliance pack — ISO 27001:2022 certificate, DPA, NDA template, IR summary, DPDPA memo, labour law memo, and pre-filled security questionnaire — is available on request, typically within 1–2 business days.
Who handles compliance escalation at Zedtreeo?
Compliance escalation runs through LegelpTech Outsourcing Pvt Ltd’s compliance function, with Chandra Prakash (Co-Founder) and Gaurav Gaur (External Legal Counsel) as escalation points. Day-to-day compliance contact comes via your assigned account manager.
Don’t write a compliance memo from a marketing page. Ask for the documents.
Which entity do I contract with, and is it certified?
Client agreements are issued by LegelpTech Outsourcing Private Limited — the ISO 27001:2022-certified operating company behind Zedtreeo — with entity, jurisdiction, and security terms stated in the MSA.
Is an NDA standard on every engagement?
Yes. Every Zedtreeo engagement includes an NDA covering the dedicated staff member and the operating entity, alongside access controls that keep your systems and data under your ownership and revocation.
How fast can I get the compliance documentation?
The compliance pack (ISO certificate, DPA template, NDA form, security overview) is available on request during evaluation — before you sign anything. Most buyers complete their compliance review within a few business days.

