Outsourcing Software Development from Germany: GDPR, SCCs and the DPA
Founder & Lead Engineer, RAITHub
A German company can outsource software development to Bangladesh under the GDPR (DSGVO), but it needs paperwork a German vendor would not: Bangladesh has no EU adequacy decision, so personal data transfers need standard contractual clauses (Module 2 for controller to processor), a transfer impact assessment and an Article 28 processing agreement (AVV). Invoices normally fall under the §13b UStG reverse charge.
This guide is for founders, CTOs and Geschäftsführer in Germany weighing an offshore team. RAITHub is a software studio in Dhaka, so we have an interest in the answer, and we want to be plain about what we are: offshore, not nearshore, and delivering in English, not German. This is general information, not legal or tax advice. Confirm every point with your data protection officer (Datenschutzbeauftragter) and your tax adviser (Steuerberater) before you sign.
Can a German company legally outsource development to a country outside the EU?
Yes. The GDPR does not ban transfers of personal data outside the European Economic Area; Chapter V (Articles 44 to 49) sets the conditions under which they may happen (GDPR, EUR-Lex). The simplest route is an adequacy decision, where the European Commission has found a country's protection essentially equivalent. Bangladesh is not on the Commission's list of adequacy decisions, and neither is India or Vietnam.
Without adequacy, you need an "appropriate safeguard" under Article 46. For a small or mid-sized company hiring a vendor, that almost always means the European Commission's standard contractual clauses (SCCs).
One point surprises people: a transfer does not require copying a database abroad. The European Data Protection Board treats remote access from a third country, for example a developer in Dhaka logging into a server in Frankfurt, as a transfer too (EDPB Recommendations 01/2020). If the offshore team can see personal data, you should assume Chapter V applies.
The reverse also holds. If the team works only on code, with synthetic test data, and never has access to production personal data, much of the transfer question shrinks. That design choice is covered below, because it is usually the most effective safeguard you have.
Which standard contractual clauses do you need, and what is Module 2?
The current SCCs were adopted in Commission Implementing Decision (EU) 2021/914 and come in four modules (Decision 2021/914, EUR-Lex; European Commission SCC page). You pick the module by the roles of the two parties.
| Module | Exporter (in the EU) | Importer (outside the EU) | Typical case |
|---|---|---|---|
| Module 1 | Controller | Controller | Sharing customer data with a partner who uses it for its own purposes |
| Module 2 | Controller | Processor | Your company hires a development vendor that works on your data on your instructions |
| Module 3 | Processor | Processor (sub-processor) | A German agency, itself a processor for its clients, subcontracts development offshore |
| Module 4 | Processor | Controller | Rare in software outsourcing |
For a German company hiring a development team directly, Module 2 is the usual fit. If you are an agency passing your clients' data to a subcontractor, Module 3 applies, and your clients' own contracts need to allow the sub-processor.
Three practical notes. The clauses themselves cannot be edited; you fill in the annexes (Annex I: parties and a description of the transfer; Annex II: technical and organisational measures; Annex III: sub-processors). You choose the governing law and courts, and German companies usually pick German law and German courts. And the SCCs sit alongside your commercial contract rather than replacing it.
What is a transfer impact assessment, and who writes it?
A transfer impact assessment (TIA) is a written assessment of whether the law and practice in the importer's country could stop the SCCs from working, and what extra measures close the gap. Clause 14 of the SCCs requires both parties to warrant that they have made this assessment, and the EDPB's recommendations set out the method (EDPB Recommendations 01/2020).
In practice the exporter (you) owns the TIA, and the vendor supplies the facts about its country and its own set-up. A usable TIA for a Bangladeshi vendor answers:
- What data, whose, and how. Categories of personal data, data subjects, and whether the team gets remote access, copies, or neither.
- Which local laws could give authorities access. Bangladesh's Cyber Security Act 2023 is the main statute summarised by DLA Piper's data protection guide for Bangladesh.
- The new data protection law. Bangladesh's Advisory Council approved a Personal Data Protection Ordinance in October 2025. It introduces consent, rights and penalties, and critics have focused on its government-access provisions, which are exactly what a TIA must weigh (The Daily Star editorial, October 2025). Ask your adviser for its current status and text.
- Supplementary measures. What you do so that, even if the local law is a concern, the data is not practically exposed.
Which supplementary measures work for a development team?
The strongest measure is architectural: keep production personal data where it already is, and give the offshore team code, not customers.
- Production stays in your EU cloud account. For example, AWS runs a Frankfurt region, eu-central-1 (AWS Regions). The account, billing and root credentials are yours.
- Synthetic or pseudonymised data for development and staging. Pseudonymised data is still personal data under the GDPR, so fully synthetic seed data is better where you can manage it.
- Deploys through your CI, not personal logins. The team merges code; your pipeline deploys it. Human access to production is exceptional, time-limited and logged.
- Access through your identity provider, with multi-factor authentication and accounts you can switch off in one place.
- No local copies of production exports on laptops, written into the AVV.
Where staging needs realistic records, pseudonymise inside your EU environment before anything is shared. A minimal example in TypeScript, run in your own account, with the key kept there:
import { createHmac } from 'node:crypto'
// Replace a real email with a stable, non-reversible stand-in.
// Run this inside your EU environment. The key never leaves it.
export function pseudonymiseEmail(email: string, key: string): string {
const digest = createHmac('sha256', key)
.update(email.trim().toLowerCase())
.digest('hex')
.slice(0, 16)
return 'user-' + digest + '@example.invalid'
}
The same address always maps to the same stand-in, so joins and uniqueness constraints still work in staging, while the developer never sees the real value.
What goes into the AVV (the data processing agreement)?
The Auftragsverarbeitungsvertrag (AVV), called a data processing agreement or DPA in English, is the contract Article 28(3) GDPR requires whenever a processor handles personal data for you (GDPR, EUR-Lex). It is separate from the SCCs, although Module 2 covers much of the same ground and many vendors sign both together.
| Article 28(3) requirement | What to ask an offshore vendor for |
|---|---|
| Processing only on your documented instructions | A written scope: which systems, which data, for which purpose |
| Confidentiality of the people involved | Signed confidentiality terms for every engineer with access |
| Security measures under Article 32 | A concrete list for Annex II: MFA, encryption, access logging, device rules |
| Rules for sub-processors | A named list, and prior notice before any change |
| Help with data subject requests and breaches | A contact, a response time, and a breach notification window |
| Deletion or return at the end | A written confirmation step in the offboarding checklist |
| Information and audits | Willingness to answer questionnaires and show evidence |
RAITHub's position is simple: we sign DPAs and SCCs and follow your controls. We are not SOC 2 or ISO 27001 certified, and we do not describe ourselves as "GDPR-certified" or anything like it. If your procurement process requires a certified vendor, that is a genuine reason to choose someone else. How we handle code, access and IP is on the security page.
How does VAT work on an invoice from a Bangladeshi software company?
For a German business buying services from a company established abroad, the reverse charge (Steuerschuldnerschaft des Leistungsempfängers) usually applies: the German recipient, not the foreign vendor, owes the German VAT (§13b UStG). The IHK explains the mechanism for businesses in its guide to the Umkehr der Steuerschuldnerschaft (IHK München).
In practice that means the vendor's invoice shows no German VAT, your bookkeeping records the reverse-charge VAT in your return, and a business entitled to deduct input tax can usually deduct the same amount. Whether that applies to your company, and exactly how it is booked, is a question for your Steuerberater. RAITHub gives no tax advice; we issue invoices and answer your adviser's questions about them.
Two related items worth raising with your adviser at the same time: how payments in a foreign currency are handled, and whether any withholding or reporting obligation applies to your specific contract.
How many working hours do Berlin and Dhaka share?
Dhaka is on UTC+6 with no daylight saving. Germany moves its clocks, so Dhaka is 4 hours ahead in summer and 5 hours ahead in winter. With both sides working 9:00 to 18:00, that leaves 5 shared hours in summer and 4 in winter.
| Season in Germany | Dhaka is ahead by | Shared hours | Window in Berlin time | Window in Dhaka time |
|---|---|---|---|---|
| Summer time (CEST, UTC+2) | 4 hours | 5 | 09:00–14:00 | 13:00–18:00 |
| Winter time (CET, UTC+1) | 5 hours | 4 | 09:00–13:00 | 14:00–18:00 |
EU clocks change on the last Sunday of March and the last Sunday of October (Directive 2000/84/EC), so for 2026 the switch to the winter pattern is on 25 October. A German morning stand-up at 10:00 lands in the Dhaka afternoon all year. What does not work well is a German team that expects answers late in its own afternoon; the offshore day has ended by then, so decisions need to happen before lunch or in writing.
Is Bangladesh nearshore or offshore for Germany?
Offshore. Nearshore usually means a neighbouring or nearby time zone, which for Germany points to Poland, Romania or Portugal. Bangladesh is several hours ahead and outside the EU, and any other label would be inaccurate. Nearshore vs offshore software development compares the two models, and Bangladesh vs India vs Vietnam vs Eastern Europe puts rates, overlap and English side by side.
The honest trade-offs for a German buyer:
- Language. RAITHub works in English only. Tickets, documentation and meetings are in English; German-language user interfaces are built from the copy you supply or your translator provides.
- Paperwork. SCCs, a TIA and an AVV are extra work compared with a vendor inside the EU, where only the AVV is needed.
- No local presence. RAITHub has no office in Germany and no EU entity. Your contract is with a studio based in Dhaka.
- What you gain. Lower published market rates than Western Europe (the comparison above has the sources), a morning overlap every working day, and a team whose work arrives while Germany sleeps.
Why RAITHub for a German company?
- The paperwork is normal for us. We sign your AVV and the Module 2 SCCs, fill in the annexes with real measures, and answer TIA questionnaires with facts rather than reassurance.
- We design so personal data stays with you. Production in your EU account, synthetic data in development, deploys through your pipeline.
- Measured quality. Sundor Skin, a B2B wholesale platform built for a client, runs 146 PostgreSQL tables with row-level security and 530+ automated tests; PropDesk runs 1,024 tests. Every engagement includes a real test suite gated in CI.
- Clear commercial terms. Fixed-scope projects or a dedicated monthly team, a free 15-minute technical audit, then a fixed written quote. You own the IP; an NDA is standard. See the SaaS development service for what a build includes.
When should a German company not hire RAITHub?
- You need delivery in German, including German-language meetings and documentation.
- Your data must stay inside the EU with no third-country access at all, for contractual or regulatory reasons. Choose an EU-based vendor.
- Procurement requires SOC 2 or ISO 27001. RAITHub holds neither.
- You want developers placed inside your team under your management. RAITHub does not offer staff augmentation.
- You need someone on site in Germany on a regular basis.
Sources checked on 29 September 2026. General information only; confirm with your data protection officer and tax adviser.
If none of those rule us out, book the free 15-minute technical audit. Bring your AVV template if you have one; we will tell you on the call whether anything in it is a problem.
Frequently asked questions
Does Bangladesh have an EU adequacy decision?
No. Bangladesh is not on the European Commission's list of adequacy decisions, so transfers of personal data to a vendor there need an Article 46 safeguard, usually the standard contractual clauses, together with a transfer impact assessment.
Which SCC module do I need to hire a development company in Bangladesh?
Usually Module 2, controller to processor, when your company hires the vendor directly. If you are an agency acting as a processor for your own clients, Module 3, processor to processor, is the likely fit. Confirm the choice with your data protection officer.
Is an AVV still needed if we sign the SCCs?
Article 28 GDPR requires a processing contract whenever a processor handles personal data for you. Module 2 of the SCCs covers many of the same points, and many companies sign both. Ask your data protection officer which approach your company uses.
Does remote access by offshore developers count as a transfer?
The EDPB treats remote access from a third country as a transfer. If developers can see personal data from Bangladesh, plan for the SCCs and a TIA; if they work only with synthetic data and never access production, the exposure is much smaller.
Do I pay German VAT on an invoice from a Bangladeshi software company?
Usually yes, through the reverse charge under §13b UStG: the invoice carries no German VAT and your business accounts for it, often with a matching input-tax deduction. This is general information; your Steuerberater should confirm it for your company.
How many working hours overlap between Germany and Bangladesh?
With a 9:00 to 18:00 day on both sides, 5 hours in German summer time and 4 in winter, because Dhaka is 4 hours ahead in summer and 5 in winter. The shared window is the German morning.
Can RAITHub work in German?
No. RAITHub delivers in English only. It can build German-language interfaces from copy you provide, but meetings, tickets and documentation are in English.
Related posts
Ready to discuss your project?
Book a free 15-minute technical audit with our engineering team.