Global Workforce, EOR & Cross-Border OperationsPlaybook3 min readUpdated September 2026

GDPR and Data Localization: A Checklist for Global Employers

Once you employ someone abroad, their personal data flows through your applicant tracking system, HRIS, and payroll or EOR provider. The GDPR applies to any EU resident's data wherever your company is incorporated, while a data localization law is narrower: it governs where certain data must be stored.

This isn't a substitute for legal advice, and it shouldn't be. It's a way to see the actual data flows before your lawyer or your first enterprise customer's security questionnaire forces you to.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Map what employee data you hold and where it actually goes

Start with an inventory, not a policy document. List every system that touches personal data about a candidate, employee, or contractor: the ATS, the HRIS, payroll or EOR platform, benefits administration, performance reviews, expense tools, even the Slack workspace and shared drives where offer letters and ID scans tend to end up. For each one, note where the vendor hosts the data, whether it's transferred outside the country where the person works, and who inside your company can see it.

Most founders are surprised by how much personal data sits in tools nobody thought of as HR systems. A recruiting spreadsheet with candidate national ID numbers, a Zoom recording of an interview, a scanned passport emailed to finance for a wire transfer: all of it counts.

GDPR applies more often than founders expect

The GDPR reaches any personal data belonging to someone in the EU or EEA, regardless of where your company is registered, if you're processing that data in connection with offering employment, goods, or services to them. That means a US company with one remote employee in Portugal is in scope for that employee's data, full stop.

The practical obligations that matter most for a small HR footprint: a documented lawful basis for processing employee data (usually the employment contract itself, or legitimate interest for things like security logs), a data processing agreement with every vendor that touches that data, a way to respond to a data subject's request to see or delete their own data, and breach notification to the relevant authority within 72 hours of becoming aware of a qualifying breach. None of this requires a large compliance team to satisfy for a headcount in the dozens, but it does require someone to actually own it.

Data localization is a separate, narrower problem

Data localization laws require that certain data physically reside on servers inside a specific country before, or instead of, being transferred elsewhere. Russia's personal data law is the clearest example: personal data of Russian citizens must first be recorded and stored on servers located in Russia. China's rules under the PIPL impose a security assessment for cross-border transfers above certain thresholds and for data classified as sensitive. A handful of other countries (Vietnam, Turkey, and India in specific sectors) have their own versions.

This is a different kind of rule than GDPR. GDPR is mostly principle-based: it cares about lawful basis, transparency, and safeguards for transfers, not physical server location by default. Localization laws are about where the bytes sit. A vendor telling you they're "GDPR compliant" says nothing about whether they satisfy a specific country's localization requirement, and the two get conflated constantly in vendor sales conversations.

Where compliance automation tools fit, and where they don't

Platforms like Vanta and Drata typically automate evidence collection: they can monitor access controls, track vendor risk assessments, confirm policies are acknowledged, and help assemble the audit trail that SOC 2 or ISO 27001 auditors, or an enterprise customer's security team, will ask for. That's genuinely useful once you're trying to demonstrate a working privacy and security program rather than just having one on paper.

What they don't do is tell you whether a specific country requires local storage for a specific category of employee data, or draft the data processing agreement you need with your EOR. Vanta and Drata operationalize a program that someone with legal or privacy expertise has to define first.

Mistakes that surface during a customer's security review

A few patterns come up repeatedly when a larger customer's due diligence team starts asking questions:

  • No signed data processing agreement with the payroll processor or EOR, even though personal data flows through them daily
  • Assuming the EOR's own compliance program covers your company's obligations as the entity that actually directs how the data is used
  • No documented process for a data subject access or deletion request, so the first one that arrives becomes an improvised scramble
  • Treating a vendor's marketing claim of being GDPR compliant as equivalent to your own company being compliant, when the two are legally distinct questions

Fixing these before they're asked about is far cheaper than fixing them under a deal deadline.

Executive Capability Standard

What Good Looks Like

Good practice here means a current data inventory, signed data processing agreements with every vendor touching employee data, a named owner for privacy requests, and a documented answer for each country where you have headcount on whether localization rules apply.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read through GDPR's employment-relevant articles (lawful basis, data subject rights, breach notification) and skim which countries where you have staff have their own localization requirement.
2. Do Manually:Build the data inventory spreadsheet yourself: every system, what it holds, where it's hosted, who has access.
3. Delegate:Hand the inventory and DPA collection to an operations or people-ops lead, with a clear deadline and a template DPA to send vendors.
4. Automate:Bring in a continuous-compliance platform to monitor access controls, vendor risk, and policy attestations once the underlying program exists.
5. Buy:Engage privacy counsel to confirm lawful basis, draft or review DPAs, and give a written answer on localization exposure per country.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Do we need a formal EU representative if we have no EU office?

Possibly. Companies outside the EU that offer goods or services to people in the EU, or monitor their behavior, may need to designate an EU representative under GDPR Article 27, with narrow exemptions for occasional, low-risk processing. Whether your situation qualifies for an exemption depends on your specific data flows, so confirm it with counsel rather than assuming either way.

Does hiring through an EOR remove our GDPR obligations?

No. An EOR becomes the legal employer of record in that country and typically takes on payroll and statutory compliance, but your company still directs how that employee's data is used for your own business purposes, which keeps you in scope as a data controller for at least part of the processing.

What's the real difference between GDPR and a data localization law?

GDPR sets rules for how personal data may be processed and transferred, wherever it's stored. A localization law requires certain data to be stored, or a copy kept, on servers inside a given country. A vendor can satisfy one without satisfying the other, so check both separately for any country where you have real headcount.

How fast do we have to respond to an employee's request to see their own data?

Under GDPR, generally within one month, extendable by two further months for complex requests if you notify the person why. Build a simple internal process now (who receives the request, who pulls the data, who reviews it before it goes out) so the first real request doesn't start from zero.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides