There is a misconception that comes up in almost every conversation we have with CTOs thinking about scaling their teams offshore. It goes something like this:
“Offshore access equals compliance risk. If someone outside the EU touches our data, we’re in breach.”
It is understandable. GDPR fines have made headlines. Data protection authorities have grown stricter. And ‘data leaving Europe’ has become a kind of shorthand for compliance risk. But the shorthand is wrong. And acting on it is causing companies to make mis-informed decisions.
What compliance actually requires
GDPR, ISO 27001, and the broader body of European data regulation are not geographic lockdowns. They are frameworks built around a single underlying principle: you must know what your data is, where your data is stored, who can access it, and under what conditions — and you must be in control of all four.
Geography is relevant only insofar as it affects that control. A third-country transfer is a compliance event not because of the location, but because of what typically happens to control when you send data somewhere else. The question regulators are actually asking is: does the controller retain meaningful governance over how personal data is processed?
If the answer is yes, the location of the engineer accessing it is secondary.
If the answer is no, you have a problem — and that problem can exist entirely within the EU.
Why traditional outsourcing actually breaks compliance
Here is where the real issue lies, and it has nothing to do where your outsourced teams are located in the world..
In a traditional outsourcing arrangement, there is almost always a middleman. A vendor sits between you and the people doing the work. That vendor manages the environment, the access credentials, the tooling, and the offboarding. You see outputs. You do not see — and often cannot audit — what happens in between.
Worse: those engineers typically work across multiple clients at the same time. Shared environments. Shared tooling. Access to systems that span multiple organisations, sometimes in the same session.
From a compliance standpoint, this is the actual danger. Not the timezone. Not the location. The fact that you no longer have clear sight of who has access to your data, under what conditions, and whether that access ends when the engagement ends.
This is the model that should make a CTO nervous.
The embedded model solves the problem traditional outsourcing creates
The embedded, dedicated model works differently in every way that matters for compliance.
There is no middleman between you and your team. Your engineers — based in Colombo or Lisbon— work directly inside your environment. Your cloud tenant. Your repositories. Your CI/CD pipelines. Accounts that your IT team creates, manages, and revokes. Role-based access. Least privilege. No Gapstars infrastructure in the data path.
Dedicated means dedicated. Your team is not simultaneously working across other clients. They are yours. That eliminates the shared environment risk entirely.
And because access runs through your own identity and access management, you retain full control at every point. You can see who has access to what. You can restrict it. You can end it immediately. The offboarding is clean, auditable, and demonstrable — because it happens in your own systems, not someone else’s.
In practice: nothing changes to your architecture or your data flows. Your engineers join the environment as it is and in the trusted datacenter where it is stored. They do not bring infrastructure of their own, and no data moves to other systems outside your ecosystem. The controller remains the controller throughout.
For clients where the third-country transfer question needs to disappear entirely, our Gapstars Lisbon hub offers a fully EU-based track. Same model. Zero transfer complexity.
Real environments,
real stakes
This is not a theoretical position. It is how we already operate for clients where data security is not a preference — it is a condition of continued existence.
Railway safety
Builds rail safety and security systems where every data incident is a safety event. Our Sri Lanka team works in a dedicated, restricted-access environment under client-controlled security.
Government and public sector
Municipal portals for Dutch local governments and the Dutch Senate's official application. Strict access governance. Public accountability.
Defence technology
Defence-related drone systems supported from our Lisbon hub. Client-controlled environment with no data transfer.
Mental health and sensitive personal data
A mental wellbeing platform handling highly confidential therapy and coaching data within the client's secure access model.
Pharma and life sciences
Successfully completed the independent audit and procurement process of a pharma AI client, with information security and privacy reviewed in depth. References available on request.
Fintech and insurance
Regulated financial and insurance data, where data handling obligations sit alongside strict regulatory frameworks.
The governance layer – How Gapstars’ model wins
Architectural control is one part of the answer. The compliance infrastructure behind it is the other.
We fix this by building compliance into onboarding, not bolting it on after.
Every engineer in our talent hubs Sri Lanka and Portugal go through ISMS training on onboarding: GDPR-compliant ways of working, information security principles, and responsible handling of partner systems and data. Every developer personally signs our IMS and security policy, alongside an NDA and Acceptable Use Policy.
Gapstars is ISO 27001 certified (information security management) and ISO 27701 certified — the specific certification for organisations operating as PII processors, directly mapped to GDPR processor obligations. Not a general privacy badge. The right one for exactly this context.
Contractually: our standard agreement includes a Data Protection Agreement. Where client-specific requirements exist, we document them in a separate DPA — covering access control, data processing, audit support, restricted environments, and security procedures. Structured on- and offboarding ensures access is granted on day one and demonstrably revoked on the last.
The question worth asking
The instinct to protect data is right. Judging it by geography is not.
Before asking “where is the employee based?”, the more useful questions are: Who owns the environment they work in? Who controls their access? Can I audit it? Can I end it?
In a traditional outsourcing model, the honest answers to those questions are often uncomfortable regardless of where the vendor is.
In the embedded, dedicated model, the answers are yours. Because the environment is yours. The access controls are yours. The data does not leave your infrastructure.
That is what compliance actually requires. And it is entirely compatible with a high-performing engineering or finance team based in Colombo or Lisbon.
If you want to walk through exactly how this works in practice — including the access architecture, the DPA structure, and how other clients in regulated sectors have approached it — we are happy to get specific.
Gapstars is ISO 27001 and ISO 27701 certified. Client references across railway safety, government, defence, pharma, fintech, and insurance are available on request.

