Back to BlogHiring & Outsourcing

Outsourcing Software Development for EU Startups: GDPR, SEPA and Overlap

Rupak Amin

Founder & Lead Engineer, RAITHub

17 min read

An EU startup can outsource software development to Bangladesh, but if the developers can see personal data, that is a GDPR transfer: Bangladesh has no adequacy decision, so you need the Module 2 standard contractual clauses and a transfer impact assessment. Scope SEPA Direct Debit as its own line item (Stripe lists €0.35 a charge) and expect 4 to 5 shared hours with Central Europe.

This guide is for founders and first CTOs of startups anywhere in the EU and EEA, with a short section for the Netherlands and the Nordics. German readers will find the AVV and the §13b reverse charge covered in more depth in outsourcing software development from Germany. RAITHub is a software studio in Dhaka, so we have an interest in the answer. We are offshore, not nearshore, we deliver in English only, and we have no office or entity in the EU. This is general information, not legal or tax advice. Confirm every legal point with your adviser or data protection officer, and with your national supervisory authority.

Should an early-stage EU startup outsource development at all?

Outsource when you need a defined product built faster than you can hire, and keep in-house the judgement you will need every week after launch. Many seed-stage startups do both: a small core team owns the product, and an outside team builds a scoped release. The table is a starting point, not a rule.

Your situationUsually the better fitWhy
Pre-seed, no technical founder, a clear first releaseA fixed-scope build with a written specYou pay for an outcome and keep the code; see fixed price vs time and materials
Seed stage, a CTO and an open-ended roadmapA dedicated monthly team alongside the CTOThe CTO keeps architecture; the team adds throughput
You need all-day live pairing in your own languageAn in-house hire or a vendor in your time zoneA full shared day matters more than price
Production data must never leave the EU, even for debuggingAn EU-based vendorAny third-country access becomes a transfer
Budget is the binding constraint and the scope is documentedAn offshore teamLower published rates, with the paperwork below

If Poland or Romania is on your list, nearshore Poland vs offshore Bangladesh sets out where the nearshore option wins, with sourced rates for each country.

How much does outsourced development cost an EU startup in euros?

Engineering hours times the rate. A first SaaS release with sign-in, teams, one core workflow, subscription billing and an admin area is often in the region of 700 to 900 hours. The table does the arithmetic for one illustrative 800-hour scope at two rate points. The hours are assumptions chosen to show how line items combine, and the rates are not RAITHub prices; RAITHub publishes no rates and quotes a fixed price after a free audit.

Line item (illustrative)Assumed hoursAt €40/hourAt €80/hour
Discovery and written specification50€2,000€4,000
UX and interface design for core flows80€3,200€6,400
Sign-in, roles and team accounts70€2,800€5,600
Core workflow (what customers pay for)260€10,400€20,800
Billing: cards, SEPA Direct Debit, invoices with VAT fields80€3,200€6,400
Admin area and reporting60€2,400€4,800
GDPR engineering: export, deletion, retention, consent log50€2,000€4,000
Automated tests and QA120€4,800€9,600
Deployment, monitoring and handover30€1,200€2,400
Total800€32,000€64,000

Two lines are routinely underpriced. Billing looks like one integration but is several flows with different timing, covered below. Tests look optional until a release breaks sign-up or payments. What a smaller budget buys is in what a $30k MVP budget gets you, and the MVP cost estimator lets you move the scope and watch the hours change. For sourced offshore hiring rates, see the cost to hire developers in Bangladesh.

Does the GDPR let a startup use developers outside the EU?

Yes. The GDPR does not ban transfers outside the EEA; Chapter V (Articles 44 to 49) sets the conditions (GDPR, EUR-Lex). The simplest condition is an adequacy decision. Bangladesh is not on the European Commission's list of adequacy decisions, so a transfer to a Bangladeshi vendor needs an Article 46 safeguard, which for a startup almost always means the standard contractual clauses (SCCs).

Two points catch founders out. First, a transfer does not require copying a database abroad: the European Data Protection Board treats remote access from a third country as a transfer too (EDPB Recommendations 01/2020). Second, the reverse also holds. If the offshore team works only on code and synthetic test data, and never has access to production personal data, most of the transfer question shrinks. That design choice is usually the most effective safeguard a startup has, and it is cheaper than any contract.

Whether or not data leaves the EU, you still need an Article 28 processing contract with any vendor that handles personal data for you. The SCCs add to it; they do not replace it.

Which standard contractual clauses does a startup sign, and what goes in the annexes?

For a startup hiring a development vendor directly, Module 2, controller to processor, is the usual fit. The current SCCs were adopted by the European Commission on 4 June 2021 in Implementing Decision (EU) 2021/914, and the Commission publishes Q&As on using them (European Commission: standard contractual clauses).

Your set-upModuleWhat it means in practice
Your startup hires the vendor to build and maintain your productModule 2 (controller to processor)The vendor works on your data only on your documented instructions
You are an agency or SaaS provider acting for your own clients, and subcontract offshoreModule 3 (processor to processor)Your clients' contracts must allow the sub-processor
The team never touches personal dataOften none needed for the transferConfirm with your adviser, and write the "no access" design into the contract

The clauses themselves are standard; the work is in the annexes. Annex I describes the parties and the transfer: which data categories, whose data, for what purpose, how often. Annex II lists the technical and organisational measures, and this is where vague answers such as "industry-standard security" should be rejected in favour of specifics: multi-factor authentication, access logging, device rules, encryption. Annex III lists sub-processors. A vendor that fills these in with concrete, checkable facts is making your transfer impact assessment easier.

How does a startup run a transfer impact assessment without a legal team?

Follow the EDPB's six-step roadmap, and split the work: you own the assessment, the vendor supplies the facts about its country and its set-up. The EDPB adopted version 2.0 of its recommendations on 18 June 2021 (EDPB Recommendations 01/2020).

EDPB stepWhat the startup doesWhat to ask the vendor for
1. Know your transfersMap which personal data the team could see, and how (access, copies or none)A list of every system the team needs, and why
2. Identify the transfer toolChoose the SCC moduleAgreement to sign that module unchanged
3. Assess the third country's law and practiceRecord whether local law could stop the SCCs workingFacts about applicable local laws; your adviser weighs them
4. Adopt supplementary measuresDecide what reduces exposure in practiceProduction in your EU account, synthetic data, access through your identity provider
5. Take procedural stepsComplete the annexes and signSigned SCCs, DPA and named contacts
6. Re-evaluateDiary a review, for example yearly or when scope changesPrompt notice of any change in access or sub-processors

For step 3, Bangladesh's data protection framework is new, and its effect on a transfer is a legal judgement. Ask your adviser for the current position rather than relying on a vendor's summary, including ours. Step 4 is where engineering does most of the work, which is why the next section matters more than the paperwork.

How can a startup keep personal data away from an offshore team?

Keep production where it already is and give the team code, not customers. In practice:

  • Production in your own EU cloud account, for example AWS Europe (Frankfurt), eu-central-1, or Europe (Stockholm), eu-north-1 (AWS Regions). Billing, root credentials and the account are yours.
  • Synthetic seed data in development and staging. Pseudonymised data is still personal data under the GDPR, so fully synthetic records are better wherever you can manage them.
  • Deploys through your CI pipeline, not personal logins. Human access to production is an exception: approved, time-limited and logged.
  • Access through your identity provider with multi-factor authentication, so you can switch every account off in one place.
  • No production exports on laptops, written into the DPA.

This is how RAITHub works by default: we sign DPAs and SCCs and follow your controls. RAITHub is not SOC 2 or ISO 27001 certified and makes no compliance claim. Whether your arrangement meets the GDPR is your adviser's call. How we handle code and access is on the security page, and answering your first security questionnaire without SOC 2 shows how to describe these controls to your own enterprise customers.

Should a startup build SEPA Direct Debit, SEPA Instant or cards first?

For B2B subscriptions in euros, SEPA Direct Debit is often the lowest-cost recurring rail, but it is slow to confirm and reversible, so it changes your data model. Cards confirm in seconds and cost more. SEPA Instant is a push payment, useful for one-off invoices rather than subscriptions.

RailHow it behavesPrice exampleWhat it adds to scope
Standard EEA cardsResult in seconds1.5% + €0.25 on Stripe Ireland (Stripe pricing)Card retries and dunning
SEPA Direct Debit (Core)Business-initiated under a mandate; Stripe settles at T+6 business days€0.35 per charge on Stripe IrelandMandate capture, debit notifications, a "processing" state, late failures and refunds on request
SEPA Instant Credit TransferCustomer pushes money; the ECB describes a confirmation in "no more than ten seconds" (ECB: instant payments)Set by your bank or providerReconciling incoming transfers to invoices by reference

Stripe's SEPA Direct Debit documentation lists the details that drive the build. Each transaction is limited to €10,000, and new accounts start with a weekly limit. Most failures arrive within 6 business days, and Stripe advises waiting at least that long before treating a payment as successful. The rulebook requires you to notify the customer of each debit. Customers can dispute a debit "no questions asked" for eight weeks, and for up to 13 months if they say it was unauthorised, and those disputes cannot be appealed. A cancelled mandate is only discovered when the next debit fails.

So "paid" needs more than one state. A minimal TypeScript sketch, as engineering guidance:

// SEPA Direct Debit: 'succeeded' is not the end of the story.
type SddState = 'processing' | 'succeeded' | 'failed' | 'disputed'

const EIGHT_WEEKS_MS = 8 * 7 * 24 * 60 * 60 * 1000

// Map Stripe webhook events to the state stored on the invoice.
export function stateFor(eventType: string): SddState | null {
  switch (eventType) {
    case 'payment_intent.processing':
      return 'processing'
    case 'payment_intent.succeeded':
      return 'succeeded'
    case 'payment_intent.payment_failed':
      return 'failed'
    case 'charge.dispute.created':
      return 'disputed'
    default:
      return null
  }
}

// What finance should see: money can still come back for 8 weeks
// (and up to 13 months if the payer claims the debit was unauthorised).
export function financeView(state: SddState, succeededAt: Date | null, now = new Date()) {
  if (state === 'failed' || state === 'disputed') return 'unpaid'
  if (state === 'processing' || succeededAt === null) return 'pending'
  return now.getTime() - succeededAt.getTime() < EIGHT_WEEKS_MS ? 'paid, refundable on request' : 'paid'
}

Test the unhappy paths before launch: a debit that fails on day five, a dispute after the invoice was marked paid, a refund issued while the customer's bank is also processing a dispute. The guide to testing payments and webhooks lists the cases. RAITHub has shipped Stripe payments in production, in PropDesk's rent collection; it has not shipped a SEPA Direct Debit or SEPA Instant integration, so that part of any quote is priced and tested as new work, and this section is engineering guidance from Stripe's and the ECB's documentation.

What changes for startups in the Netherlands and the Nordics?

The GDPR and the SCC process are the same across the EU; Norway, Iceland and Liechtenstein apply the GDPR as EEA members. What differs is the supervisory authority you answer to, the local payment methods your customers expect, and, for Finland, the clock.

CountrySupervisory authorityLocal payment method to scopeStripe Ireland list price
NetherlandsAutoriteit PersoonsgegevensiDEAL | Wero€0.29 per transaction
SwedenIntegritetsskyddsmyndigheten (IMY)Swish1% + €0.30, capped at €0.70
Denmark and FinlandDatatilsynet (DK); Office of the Data Protection Ombudsman (FI)MobilePay1.5% + €0.36
NorwayDatatilsynetCards and bank payments; check local method support with your providerSee the provider's Norway page

Sources: EDPB members list for the authorities; Stripe local payment methods pricing, where a 2% currency conversion fee can also apply. Klarna is priced separately by region on the same page. Each local method is its own integration and its own set of test cases, so add them one at a time, in the order your customers ask for them.

Language is rarely the obstacle. Dutch and Nordic teams usually work in English already, which suits RAITHub's English-only delivery. Localised interfaces are built from copy you or your translator supply.

How many working hours does an EU startup share with Dhaka?

Dhaka is UTC+6 with no daylight saving. Dhaka is 5 hours ahead of Central Europe in winter and 4 hours ahead in summer, so with a 9:00 to 18:00 day at both ends, Berlin, Amsterdam, Copenhagen, Stockholm and Oslo share about 4 hours in winter and 5 in summer. EU clocks change on the last Sunday of March and of October (Directive 2000/84/EC).

City (time zone)SeasonDhaka ahead byShared hoursWindow in local time
Dublin, Lisbon (UTC+0)Winter6 hours309:00–12:00
Dublin, Lisbon (UTC+1)Summer5 hours409:00–13:00
Berlin, Paris, Amsterdam, Stockholm (CET, UTC+1)Winter5 hours409:00–13:00
Berlin, Paris, Amsterdam, Stockholm (CEST, UTC+2)Summer4 hours509:00–14:00
Helsinki (EET, UTC+2)Winter4 hours509:00–14:00
Helsinki (EEST, UTC+3)Summer3 hours609:00–15:00

The shared window is your morning. A 10:00 stand-up in Amsterdam lands in the Dhaka afternoon all year, and the team's work is waiting in a written handoff when you start the next day. What does not work well is expecting answers late in your afternoon: decisions need to happen before lunch or in writing. The working week is agreed per client when the engagement starts, including around your public holidays.

Who pays VAT on an invoice from a Bangladeshi software company?

Usually you do, through the reverse charge. The EU's Your Europe portal says that if you receive services for business purposes from a supplier outside the EU, you should usually pay VAT at the applicable rate in your country, as if you had supplied the service yourself (Your Europe: cross-border VAT). The invoice carries no EU VAT, and your accountant records it in your return. This is general information, not tax advice: confirm the treatment for your company with your accountant, including any withholding or reporting rules in your country. RAITHub gives no tax advice; it issues invoices and answers your accountant's questions about them.

Why RAITHub for this

  • The transfer paperwork is routine. We sign DPAs and the Module 2 SCCs, fill in Annexes I to III with real, checkable measures, and answer TIA questionnaires with facts.
  • Data stays with you by design. Production in your EU account, synthetic data in development, deploys through your pipeline. That is the default, not an upsell.
  • Tested money paths. PropDesk, the property management platform RAITHub built, collects rent through Stripe and runs 1,024 automated tests; Sundor Skin, a B2B wholesale platform, enforces row-level security across 146 PostgreSQL tables with 530+ tests.
  • Startup-shaped terms. A free 15-minute technical audit, then a fixed written quote, as fixed scope or a dedicated monthly team. You own the IP and an NDA is standard. The MVP development service sets out what a first release includes.
  • A morning overlap every working day, 4 to 5 hours with Central Europe, plus written daily handoffs.

When you don't need us

  • Your data must never be accessible from outside the EU, even to debug an incident. Choose an EU-based vendor.
  • You need delivery in German, Dutch, French or a Nordic language. RAITHub works in English only.
  • Your investors or customers require a SOC 2 or ISO 27001 certified supplier. RAITHub holds neither.
  • You want developers placed inside your team under your management. RAITHub does not offer staff augmentation.
  • You need a native iOS or Android app. RAITHub builds web applications and PWAs, not native mobile apps.
  • A no-code tool or an off-the-shelf product already does the job. Use it, and spend the budget on customers.

Before any vendor call, the checks in is it safe to hire a Bangladesh software agency apply to us too.

Sources checked on 30 September 2026. General information only; confirm legal and tax points with your adviser and your supervisory authority.

If none of those rule us out, book the free 15-minute technical audit. Bring a one-page description of the first release, the countries your customers pay from, and whether the team would ever need to see production data.

Frequently asked questions

Can an EU startup legally outsource development to Bangladesh?

Yes. The GDPR allows transfers outside the EEA under Chapter V. Bangladesh has no EU adequacy decision, so if the team can access personal data you need an Article 46 safeguard, usually the standard contractual clauses, plus a transfer impact assessment and an Article 28 processing contract. Confirm the details with your adviser.

Which SCC module does a startup need to hire an offshore development team?

Usually Module 2, controller to processor, when your startup hires the vendor directly to work on its product. If you are yourself a processor for clients and subcontract the work, Module 3 is the likely fit. Your adviser should confirm the module for your set-up.

Does remote access by developers outside the EU count as a transfer?

The European Data Protection Board treats remote access from a third country as a transfer. If developers can see personal data from Bangladesh, plan for SCCs and a transfer impact assessment. If they work only with synthetic data and never access production, the exposure is much smaller.

What does SEPA Direct Debit cost and how long does it take?

Stripe Ireland lists €0.35 per SEPA Direct Debit charge, against 1.5% + €0.25 for standard EEA cards. Stripe settles at T+6 business days, customers can request a refund for eight weeks, and unauthorised-debit claims can arrive for up to 13 months, so software must track a pending state.

How many hours overlap between Dhaka and Central Europe?

Dhaka is UTC+6 with no daylight saving, 5 hours ahead of Central Europe in winter and 4 in summer. On a 9:00 to 18:00 day at both ends that gives about 4 shared hours in winter and 5 in summer, in the European morning. Helsinki shares 5 to 6.

Do I pay VAT on an invoice from a software company in Bangladesh?

Usually yes, under the reverse charge: the invoice carries no EU VAT and your business accounts for VAT at your country's rate. The Your Europe portal describes the rule. This is general information; confirm how it applies to your company with your accountant.

Is Bangladesh nearshore for European startups?

No. Bangladesh is offshore for Europe: outside the EU, with a 3 to 6 hour time difference depending on the country and season. Nearshore usually means a nearby country in an adjacent time zone, such as Poland, Romania or Portugal.

outsourcing software development for startupsEU startup offshore teamGDPR third-country transferstandard contractual clauses module 2transfer impact assessmentSEPA Direct DebitNetherlands Nordics outsourcing

Ready to discuss your project?

Book a free 15-minute technical audit with our engineering team.