LavaStaff

Free tool

What should a remote Latin America hire be allowed to touch

Pick the data the role requires and the planner returns an access decision for each class, the controls that have to be true first with their SOC 2 and ISO 27001 references, the documents that need signing and by whom, and the data protection regime in the market you are hiring into. 15 controls, 9 documents, 11 markets.

Built for the founder who just received a vendor security questionnaire and realised the honest answer is longer than a yes or a no.

  • Free to use
  • No signup required
  • Not legal advice

Access planner

Start from the data, not from the country

The frameworks that govern this decision are written around what a person can reach and whether that access was authorised, reviewed, and removed. None of them are written around where the person sits. Select the data classes the work actually requires and the plan follows from there.

Describe the role

What will this person actually touch

Pick the data the work requires rather than the data the person could plausibly be shown. Every additional class adds controls and paper, which is the argument for designing the role narrowly before you design the access.

Data and systems in scope

Managed staffing supplier. A supplier engages the worker and delivers the person to your team. Fastest to start, and the model where the chain from your customer's data to the individual has the extra link people forget to inspect.

Device: Company-issued hardware keeps the full control set available. Budget for import duty and customs lead time, which in several markets in the region is long enough to delay a start date if it is discovered in the same week the person is meant to begin.

Result

14 controls, 6 documents

Across 2 selected classes of data, engaged as managed staffing supplier in Colombia.

Access decisions

  • Internal documents and collaboration tools: Grant

    Grant on the ordinary schedule. This is the access that makes someone a colleague rather than a visitor, and withholding it produces the failure everyone actually experiences on nearshore teams, which is a person who cannot do the job because the context lives in a document they were never added to.

    The edge case people miss: The trap is that internal tools accumulate customer data nobody classified. Search your own wiki for a customer name before you decide this class is empty.

    How a customer will ask about it: Rarely asked about directly. It becomes relevant when a customer asks where its data is stored and someone remembers that support transcripts live in the shared drive.

  • Customer personal information: Grant scoped

    Grant scoped access through the application rather than the database, limited to the records the work requires, with export disabled or logged. This is the class where support and operations roles genuinely need the data and where the control is about shape rather than about permission.

    The edge case people miss: Bulk export is the line. A support agent who can open one customer record at a time and a support agent who can download the customer list are two different risk positions wearing the same job title.

    How a customer will ask about it: Asked as whether personnel outside the United States can access customer data, and if so under what controls. A truthful yes with named controls reviews better than a no that a customer later discovers was approximate.

    Regime in play: CCPA service provider or contractor terms; your customer contracts

Before the first credential is issued (8)

  • Give the person a named identity in your identity provider
    SOC 2 CC6.1, CC6.2. ISO 27001 A.5.16, A.5.17.
  • Require phishing-resistant multi-factor authentication
    SOC 2 CC6.1. ISO 27001 A.5.17, A.8.5.
  • Define the role's access as a named role, not a person
    SOC 2 CC6.1, CC6.3. ISO 27001 A.5.15, A.5.18.
  • Put the work on a managed device you can wipe
    SOC 2 CC6.6, CC6.7. ISO 27001 A.8.1, A.7.9.
  • Keep the data in systems rather than on the endpoint
    SOC 2 CC6.7. ISO 27001 A.8.10, A.8.12.
  • Define one network path and close the others
    SOC 2 CC6.6. ISO 27001 A.8.20, A.8.22.
  • Have confidentiality and data terms signed before the first login
    SOC 2 CC1.4, CC9.2. ISO 27001 A.6.2, A.6.6.
  • Verify the person is who the contract says they are
    SOC 2 CC1.4. ISO 27001 A.6.1.

In the first week (2)

  • Run security onboarding in the person's working language
    SOC 2 CC2.2, CC1.4. ISO 27001 A.6.3.
  • Log the access and keep the log somewhere the person cannot reach
    SOC 2 CC7.2, CC6.1. ISO 27001 A.8.15, A.8.16.

For as long as the access exists (4)

  • Review access on a schedule with a named owner per account
    SOC 2 CC6.2, CC6.3. ISO 27001 A.5.18.
  • Commit to a revocation clock and test it
    SOC 2 CC6.2. ISO 27001 A.5.11, A.8.18.
  • Record the arrangement where your customers can see it
    SOC 2 CC9.2, CC3.4. ISO 27001 A.5.19, A.5.21.
  • Write down how the hardware and the data come back
    SOC 2 CC6.5, CC6.7. ISO 27001 A.5.11, A.7.14, A.8.10.

Paper to have signed

  • Confidentiality and acceptable use terms

    A confidentiality obligation that survives the engagement, plus a written statement of what the person may and may not do with company systems.

    Signed by: The individual, directly, whatever else is in the chain.

    Why: This is the one artifact that should reach the individual in every engagement model. A confidentiality clause that binds only a staffing supplier leaves you with a claim against a company and none against the person holding the data.

  • Present assignment of work product

    A present-tense assignment of the work product from the individual, with a further-assurances clause and, in civil law markets, attention to moral rights and to what economic rights an employer receives by default.

    Signed by: The individual, and the supplier where a supplier sits in between.

    Why: Ownership of the output is a separate question from access to the input, and both surface in the same diligence process. A chain that stops at the supplier is the common defect.

  • Data processing terms

    Written instructions covering purpose, categories of data, security measures, confidentiality of personnel, subprocessing, assistance with data subject requests, breach notice, and deletion or return at the end.

    Signed by: You and whichever entity processes on your behalf. Where a staffing supplier engages the worker, that supplier is usually the processor and the worker is its personnel.

    Why: Mexico's 2025 statute made processor obligations explicit, Brazil's LGPD has always distinguished the controlador from the operador, and Chile's new law adopts the same split when it takes effect. The terms are also what a customer's security review asks you to produce.

  • California service provider or contractor language

    The specific contract terms the CCPA requires before a recipient of personal information counts as a service provider or contractor rather than a third party receiving a sale or share.

    Signed by: You and the entity receiving the personal information.

    Why: Without the required terms the transfer can be characterised as a sale or share, which changes your own disclosure and opt-out obligations. This is a US law question that a nearshore engagement triggers, and it is routinely missed because people file it under international.

  • Breach notice and cooperation terms with a clock in them

    An obligation on the supplier or worker to notify you without undue delay, with a stated number of hours, and to cooperate with your investigation.

    Signed by: You and the supplier, flowed down to the individual.

    Why: Your own notification clocks start when you know. Peru's regulation sets 48 hours for notifying its authority and Brazil's regulator has fixed a short window of its own, so a supplier who notifies you in a week has consumed a deadline that was never theirs.

  • Flow-down of personnel obligations

    A term requiring the supplier to bind its own personnel to confidentiality, security, and assignment obligations at least as strict as yours, and to evidence it on request.

    Signed by: The supplier.

    Why: This is the clause that closes the gap between your agreement and the human being. Ask for evidence once, early, while you are still a prospect rather than a customer.

The paper chain for this model

  1. Your customer contract commits you to how customer data is handled.
  2. Your master agreement with the supplier carries processor terms, security requirements, breach notice, and a flow-down obligation.
  3. The supplier's own agreement with the worker carries confidentiality, assignment, and security obligations.
  4. The individual holds the access.

Where it usually breaks: Step three. Buyers negotiate the master agreement carefully and then never ask to see the supplier's worker agreement, which is where the flow-down either exists or does not. Ask for a redacted copy before you sign, and ask who notifies you within what number of hours when a worker leaves.

Colombia

Ley 1581 de 2012, with Decreto 1074 de 2015. In force and actively enforced, with a national database registry that catches foreign companies by surprise more often than the substantive rules do.

Supervisory authority: Superintendencia de Industria y Comercio, Delegatura para la Proteccion de Datos Personales

Processing on your behalf: The statute separates the responsable from the encargado and requires the arrangement to be documented, with the encargado processing only under instruction and applying a security duty of its own.

Breach reporting: Incidents affecting the administration of data must be reported to the Superintendencia, which operates a reporting channel for the purpose.

EU adequacy: No adequacy decision. Colombia does maintain its own list of countries it recognises as offering adequate protection, which matters for data leaving Colombia rather than for data arriving.

A planning instrument, not legal advice and not a security assessment. LavaStaff is a staffing company, not a law firm, an auditor, or a tax adviser. Data protection law in the region is moving quickly, so confirm the current position with counsel and with your own security team before you act on it.

Why it matters

Nobody decides this. It gets decided for them

The question arrives from a customer, not from you

Most companies first confront this when an enterprise prospect sends a vendor security questionnaire asking whether personnel outside the United States can reach customer data. By then the access already exists and the answer is a description rather than a decision.

The auditor samples the account, not the country

A SOC 2 or ISO 27001 assessment tests whether access was authorised, reviewed, and removed on time. Contractor and supplier accounts fail the removal test most often, because the person who requested the access has moved on and nobody owns the account.

The paper chain has a link people never inspect

Buyers negotiate the master agreement with a staffing supplier carefully, then never ask what that supplier signed with the worker. That second agreement is where confidentiality, assignment, and security obligations either reach the individual or stop short.

There is a predictable sequence to how this goes wrong, and it is worth describing because almost every company that hits it believes it is the only one that has. A team hires its first nearshore operator or engineer. The person is good, ramps quickly, and within a few weeks has accumulated the access that makes them useful: the shared drive, the support tool, the repository, a read-only production credential someone issued during an incident and never revoked. Nothing about this is careless. It is how access works on every small team, domestic or not.

Then one of three things happens. An enterprise prospect sends a vendor security questionnaire with a question about personnel outside the United States. An auditor preparing a first SOC 2 report pulls the user list and asks who owns an account nobody recognises. Or a laptop goes missing and somebody has to work out what was on it. All three arrive at the same question from different directions, and in all three the company is answering it retroactively, in writing, under time pressure, about decisions made months earlier by people who were not thinking about audits.

The useful observation is that the retroactive version of this question is much harder than the version you can answer in advance. Deciding what a role should reach takes about twenty minutes at the point of hiring. Reconstructing what a role did reach takes a week and produces an answer you have to qualify. This planner is built for the twenty minute version.

The finding people do not expect

Four fifths of this is not about Latin America at all

The framing that brings people to this question is usually geographic. Is it safe to give someone in another country access to our systems. That framing is understandable and it is the wrong axis, and you can demonstrate this from the source documents rather than by assertion.

The AICPA Trust Services Criteria, which is what a SOC 2 report is tested against, organises logical access around registering and authorising users before issuing credentials, restricting access to what is needed, and removing access when a user is no longer authorised. The 2022 points of focus asked entities to consider access by user type, naming employee, contractor, vendor, and partner. There is no criterion keyed to nationality or location. ISO/IEC 27001:2022 does the same thing through its Annex A controls on access rights, privileged access, and the return of assets. HIPAA imposes no geographic restriction on where a business associate's workforce sits. PCI DSS scopes by system component and data flow. Every one of these frameworks asks what the person can reach and whether that was authorised, reviewed, and removed on time.

What genuinely does change across a border is narrower and more specific than the geographic framing suggests. It is which regulator supervises the personal data once someone in that country is handling it. It is whether the entity you would have a claim against has assets and can be reached by a court you can afford to use. It is whether shipping a managed laptop is a two day errand or a six week customs exercise. And it is the revocation clock, which nearshore engagements genuinely do fail more often, for an organisational reason rather than a security one: when a staffing supplier engages the worker, the supplier knows the person has left before you do, so the notification path from supplier to your identity provider has to exist in the contract or it does not exist at all.

That is the whole delta. It is real, it is worth planning for, and it is a much smaller thing than the question usually implies. If you are already applying named identity, phishing-resistant multi-factor authentication, least privilege, managed devices, logging, quarterly access review, and same-day revocation to your domestic contractors, then most of your nearshore work is already done and what remains is paper.

Adequacy

Three markets here sit on the easy side of a European transfer analysis

3

Markets here with an EU adequacy decision

2003

Argentina, the region's first adequacy decision

2012

Uruguay, the second

2026

Brazil, adopted 26 January and mutual

This one is worth pulling out because it inverts an assumption. If your company holds personal data of people in the European Economic Area or the United Kingdom, then giving anyone outside that jurisdiction remote access to it is a transfer, and transfers need a lawful mechanism. For most destinations that means standard contractual clauses and a documented assessment of the destination country. That is ordinary work, and it is work.

Argentina has held a European Commission adequacy decision since 2003 and Uruguay since 2012, and both survived the Commission's review of the decisions adopted before the GDPR. On 26 January 2026 the Commission adopted an adequacy decision for Brazil under Article 45, concluding that Brazilian law provides protection essentially equivalent to the EU standard, and Brazil's ANPD adopted a reciprocal recognition of the EU the following day under Article 33 of the LGPD. The two were announced together on 27 January 2026. It is the first mutual arrangement of its kind in the region and it covers the public and private sectors at once.

The practical consequence for a company weighing where to put a data-handling role is that a hire in Sao Paulo, Buenos Aires, or Montevideo sits on the simple side of a transfer analysis that a hire in most of the rest of the world does not, including a hire in the United States, where the position depends on a separate framework and a company's participation in it. That is not a reason on its own to choose a country. It is a reason to stop treating the region as the complicated option in a conversation about European data.

The regimes

Data protection law in 11 Latin America markets

Sorted by how built out the supervisory apparatus is. This ranks regulatory maturity and nothing else. It is not a risk score for the country and it says nothing about talent, infrastructure, or whether you should hire there.

  • Brazil: Comprehensive, actively enforced

    Lei Geral de Protecao de Dados Pessoais, Lei 13.709/2018. In force with an active regulator that has been issuing binding resolutions steadily since 2023. The most built-out regime in the region and the closest in structure to the GDPR.

    Authority: Autoridade Nacional de Protecao de Dados (ANPD)

    Processing on your behalf: The LGPD splits the controlador from the operador and imposes direct security obligations on both, so a staffing supplier processing on your instructions carries its own statutory duties rather than only contractual ones.

    Breach reporting: Communication to the ANPD and to affected individuals is required, and the regulator has fixed a short reporting window by resolution rather than leaving it to a reasonableness test.

    EU adequacy: The European Commission adopted an adequacy decision for Brazil on 26 January 2026, with a reciprocal recognition adopted by the ANPD. It is the first mutual arrangement of its kind in the region and it removes the need for standard contractual clauses on flows between the EU and Brazil.

    Source: ANPD

  • Uruguay: Comprehensive, EU recognised

    Ley 18.331 de Proteccion de Datos Personales, with Ley 19.670 and Decreto 64/020. In force since 2008 and amended to add accountability duties, breach notification, data protection officers, and impact assessments for defined categories of processing.

    Authority: Unidad Reguladora y de Control de Datos Personales (URCDP)

    Processing on your behalf: Processors act on the controller's instructions under written terms, and the 2020 decree tightened what those terms and the surrounding security duties have to cover.

    Breach reporting: Notification to the regulator is required promptly once a breach affecting personal data is identified, with communication to affected individuals where the impact warrants it.

    EU adequacy: Uruguay has held a European Commission adequacy decision since 2012, one of only two in the region for over a decade until Brazil joined in 2026.

    Source: URCDP

  • Colombia: Comprehensive, registry obligations

    Ley 1581 de 2012, with Decreto 1074 de 2015. In force and actively enforced, with a national database registry that catches foreign companies by surprise more often than the substantive rules do.

    Authority: Superintendencia de Industria y Comercio, Delegatura para la Proteccion de Datos Personales

    Processing on your behalf: The statute separates the responsable from the encargado and requires the arrangement to be documented, with the encargado processing only under instruction and applying a security duty of its own.

    Breach reporting: Incidents affecting the administration of data must be reported to the Superintendencia, which operates a reporting channel for the purpose.

    EU adequacy: No adequacy decision. Colombia does maintain its own list of countries it recognises as offering adequate protection, which matters for data leaving Colombia rather than for data arriving.

    Source: Superintendencia de Industria y Comercio

  • Argentina: Comprehensive, EU recognised, ageing text

    Ley 25.326 de Proteccion de los Datos Personales. In force since 2000 and the oldest comprehensive regime in the region. A modernising bill has been in and out of Congress for years without passing, so the operative text remains the original statute plus regulator guidance.

    Authority: Agencia de Acceso a la Informacion Publica (AAIP)

    Processing on your behalf: Processing on behalf of a controller requires written terms, and the data may not be used for any purpose other than the one instructed or retained after the relationship ends.

    Breach reporting: The statute predates the modern notification model, and the reporting expectations come from regulator guidance rather than from a statutory clock. Treat your contractual clock as the operative one.

    EU adequacy: Argentina has held a European Commission adequacy decision since 2003, which was maintained following the Commission's review of pre-GDPR decisions.

    Source: AAIP

  • Mexico: Comprehensive, newly reorganised authority

    Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares, published 20 March 2025. A completely new statute rather than an amendment. It replaced the 2010 law of the same name and took effect the day after publication, following the dissolution of INAI and the move of enforcement into the executive branch.

    Authority: Secretaria Anticorrupcion y Buen Gobierno, through Transparencia para el Pueblo

    Processing on your behalf: The new text addresses processors directly, so a supplier handling personal data on your behalf has obligations under the statute and not only under your contract. This is a change from the 2010 position and is the detail most likely to be missing from a supplier's template.

    Breach reporting: Security breaches materially affecting the rights of data subjects must be reported to those subjects without delay so they can act. Penalties are set in multiples of the Unidad de Medida y Actualizacion, with a higher band for sensitive data.

    EU adequacy: No adequacy decision. Where EU or UK personal data is involved, the transfer needs its own mechanism.

    Source: Diario Oficial de la Federacion

  • Peru: Comprehensive, recently modernised

    Ley 29733, with the regulation approved by Decreto Supremo 016-2024-JUS. The statute dates from 2011, and the regulation that gives it teeth was replaced in 2024 and took effect on 30 March 2025. The most significant change to Peruvian data protection practice since the law was passed.

    Authority: Autoridad Nacional de Proteccion de Datos Personales, Ministerio de Justicia y Derechos Humanos

    Processing on your behalf: The new regulation sets out processor duties in detail, adds a data protection officer requirement in defined cases, and raises the transparency and security standard across the board.

    Breach reporting: The regulation sets a 48 hour window for notifying the authority of a security incident, which is shorter than most contracts in this market currently provide for.

    EU adequacy: No adequacy decision, though the 2024 regulation was explicitly drafted to move Peruvian practice toward the European standard.

    Source: Ministerio de Justicia y Derechos Humanos

  • Chile: Modern statute, effective December 2026

    Ley 21.719, published 13 December 2024. Published and not yet fully operative. Law 19.628 of 1999 continues to apply until the end of November 2026, and Law 21.719 takes effect on 1 December 2026 with a new regulator, GDPR-style roles, and a penalty regime the old law never had.

    Authority: Agencia de Proteccion de Datos Personales, being established

    Processing on your behalf: The new statute introduces the controller and processor split that Chilean law has lacked, with written terms and direct security obligations. Contracts written against the 1999 law will need revisiting before the changeover.

    Breach reporting: Law 21.719 introduces breach notification to the new agency and to affected individuals, which the current statute does not require. Build the process now rather than in the last quarter of 2026.

    EU adequacy: No adequacy decision. Chile has been open about wanting one, and the 2024 statute was drafted with that in view.

    Source: Biblioteca del Congreso Nacional de Chile

  • Costa Rica: Comprehensive, registration duties

    Ley 8968 de Proteccion de la Persona frente al tratamiento de sus datos personales. In force since 2011 with an established regulator. Compact by regional standards, and notable for a database registration duty that applies to private parties distributing or trading in personal data.

    Authority: Agencia de Proteccion de Datos de los Habitantes (PRODHAB)

    Processing on your behalf: Transfers to a processor require the data subject's informed consent under the statute's transfer rules, which is a stricter default than the instruction-based model most of the region has moved to.

    Breach reporting: The controller must inform the data subject and the agency of irregularities in the handling or storage of personal data within five working days of becoming aware.

    EU adequacy: No adequacy decision.

    Source: PRODHAB

  • Ecuador: Modern statute, young authority

    Ley Organica de Proteccion de Datos Personales, published 26 May 2021. A modern GDPR-influenced statute whose sanctions regime became applicable two years after publication, with the supervisory authority established more recently. The text is strong and the enforcement history is short.

    Authority: Superintendencia de Proteccion de Datos Personales

    Processing on your behalf: The statute uses the controller and processor split, requires written terms, and imposes a security duty proportionate to the risk of the processing.

    Breach reporting: Breach notification to the authority is required within a short window of becoming aware, with communication to affected individuals where the risk warrants it.

    EU adequacy: No adequacy decision.

    Source: Superintendencia de Proteccion de Datos Personales

  • Dominican Republic: Statute in force, limited supervision

    Ley 172-13 sobre Proteccion de Datos de Caracter Personal. A comprehensive statute on paper without the general supervisory apparatus the rest of the region has built. Reform has been discussed for years. Treat the statute as binding and the contract as your practical enforcement mechanism.

    Authority: No dedicated general-purpose authority. Oversight of credit reporting bodies sits with the Superintendencia de Bancos.

    Processing on your behalf: The statute contemplates processing on a controller's behalf, but there is no regulator issuing the detailed processor guidance that Brazil, Colombia, and Peru now publish.

    Breach reporting: No general statutory notification clock comparable to Peru's or Brazil's. Set the clock in the contract, because nothing else will set it for you.

    EU adequacy: No adequacy decision.

    Source: Superintendencia de Bancos

  • Guatemala: No general statute

    No comprehensive private-sector data protection statute. The country has no general data protection law in force. Decreto 57-2008 on access to public information covers personal data held by public bodies and provides a habeas data mechanism against those bodies, which does not reach a private employer. A comprehensive bill has been before Congress since 2022 without passing.

    Authority: None for private-sector processing

    Processing on your behalf: There is no statutory processor concept to rely on. Everything you want to be true has to be in the contract, and the contract is the only instrument that will be enforced.

    Breach reporting: No statutory notification duty. Your obligations here come entirely from your own customer contracts and from the law governing the data subjects rather than the worker.

    EU adequacy: No adequacy decision.

    Source: Congreso de la Republica de Guatemala

Two entries on that list deserve a second look before you plan around them. Chile's Law 21.719 was published on 13 December 2024 and takes effect on 1 December 2026, with Law 19.628 of 1999 continuing to apply until the end of November 2026. It introduces the controller and processor split, a new supervisory agency, and a penalty regime that Chilean data protection law has never had, so an agreement drafted against the current statute will need revisiting rather than renewing. Mexico is the other: the statute in force is not an amended version of the 2010 law but an entirely new one, published on 20 March 2025 and effective the following day, with enforcement moved out of the dissolved INAI and into the executive branch. A supplier template written against the old regime will name a regulator that no longer exists.

Common mistakes

Six things that go wrong, in order of frequency

Treating the border as the control

Blocking a country and calling it a security posture. Nothing in the Trust Services Criteria, ISO 27001, HIPAA, or PCI DSS is written around where a person sits, and a geographic rule substitutes for the access decision rather than making it.

Granting production access on day one

If any new joiner can reach the production database in week one, the nearshore engagement is not the finding. The standing access is, and a staffing hire is a good reason to finally implement time-bound elevation.

Signing the terms after the first login

Confidentiality and security terms belong before the credential is issued, not on the first day of work. The obligation needs to exist at the moment of access, and a person who has already started has less reason to accept a term they dislike.

Allowlisting by address

Residential connections across the region are commonly dynamic and sit behind carrier-grade address translation, so an address allowlist either breaks every week or is written broadly enough to mean nothing. Use one sanctioned network path instead.

Assuming the supplier will tell you someone left

The supplier knows before you do, which makes the notification path a contract term rather than a courtesy. Same-day revocation for an ordinary departure and same-hour for a contested one, driven from your identity provider.

Forgetting the customer contract you already signed

Subprocessor notice and personnel-location commitments live in your own customer paper, and a nearshore engagement can trigger them without feeling like adding a vendor. Read the clause before the start date.

Answering the questionnaire

What to write when a customer asks

Vendor security questionnaires converge on four questions once a nearshore engagement is in the picture, and each has a shape of answer that ends the thread and a shape that generates three more emails.

Can personnel outside the United States access customer data. If yes, say yes, then name the countries, the engagement model, and the fact that access is scoped to specific records through the application rather than granted against the database. The answer that causes damage is not a yes. It is a no that a customer later discovers was approximate, because from that point the conversation is about your disclosure rather than your architecture.

Who holds privileged or administrative access. Name individuals and give a review cadence. If elevated access is time-bound and requires an approver, say so, because that single fact resolves most follow-up questions. Standing administrative rights held by a contractor is the answer that does not survive review, and it is worth fixing before you are asked rather than explaining afterwards.

How quickly is access removed when someone leaves. Give a number and describe the mechanism. Same-day for an ordinary departure, same-hour for a contested one, driven from the identity provider so one action closes every downstream tool. If a staffing supplier engages the worker, describe how you learn that the person has left, because the reviewer is really asking whether your clock can start.

Are subcontractors and their personnel covered by equivalent obligations. This is the flow-down question, and it is the one to have evidence for rather than assurances. Ask your supplier for a redacted copy of the agreement it signs with its own workers before you sign with them, while you are still a prospect and the request is easy to make.

Questions

Data access for nearshore hires, answered

Can offshore contractors access customer data under SOC 2?

Yes, and nothing in the Trust Services Criteria says otherwise. The criteria are written around user types and access authorisation rather than around user locations, and the 2022 points of focus asked entities to evaluate access by type, naming employee, contractor, vendor, and partner as the categories to consider. There is no criterion that treats a contractor in Medellin differently from a contractor in Denver. What a SOC 2 audit will test is whether the access was authorised before it was granted, whether it is reviewed, and whether it is removed on time when the person leaves. Contractor accounts fail that last test more often than employee accounts do, and the reason is organisational rather than technical: the manager who requested the access has often moved on, so nobody owns the account when the engagement ends.

What should I put in a security questionnaire answer about offshore staff?

Say yes if the answer is yes, then name the controls. The pattern that damages a deal is not disclosing that personnel outside the United States can reach customer data. It is a no that a customer later discovers was approximate, because at that point the finding is about your answer rather than about your architecture. A strong answer names the countries, states the engagement model, describes the access as scoped rather than general, and says that privileged access is time-bound and logged. If your customer contracts require notice of personnel outside a named region, read that clause before the person starts rather than after a customer asks, because a nearshore engagement can trigger a subprocessor or personnel-location obligation without ever feeling like adding a vendor.

Does HIPAA allow protected health information to be handled outside the US?

HIPAA does not contain a geographic restriction on where a business associate's workforce sits, and it does not offer a workaround for an incomplete agreement chain either. If protected health information is reachable, the business associate agreement chain has to reach the entity that actually engages the person, which in a staffing arrangement means a downstream agreement as well as your own. The practical failure is not a legal one. It is that a buyer signs an agreement with a supplier, never asks what the supplier signed with the worker, and discovers the gap when an incident makes the question retroactive. Ask for the downstream agreement while you are still a prospect. Note also that customer contracts frequently impose location restrictions that the statute does not, so read your own paper as well as the rule.

Do I need standard contractual clauses to give a Latin America hire access to data?

It depends entirely on whose personal data is involved, and for most US buyers the answer is no. Standard contractual clauses are a European transfer mechanism. If the data is US customer data governed by US law, the question is whether your contracts and your state privacy obligations are satisfied, not whether you have European clauses in place. Where you do hold personal data of people in the European Economic Area or the United Kingdom, remote access from outside the exporting jurisdiction is itself a transfer, so the mechanism question arrives whether or not anything is copied anywhere. Three markets in this region now hold a European Commission adequacy decision, which removes the clause requirement for flows into them.

Which Latin American countries have EU data protection adequacy?

Three: Argentina, Uruguay, and Brazil. Argentina has held a decision since 2003 and Uruguay since 2012, and both were maintained through the Commission's review of the pre-GDPR decisions. Brazil is the newest and the most significant, with the European Commission adopting its adequacy decision on 26 January 2026 and Brazil's ANPD adopting a reciprocal recognition, announced together on 27 January 2026. It is the first mutual arrangement of its kind in the region and it covers the public and private sectors together. For a company holding European personal data, this is a genuinely interesting fact about nearshore hiring, because it means a hire in Sao Paulo, Buenos Aires, or Montevideo sits on the simple side of a transfer analysis that a hire in most of the rest of the world, including the United States, does not.

Should a nearshore contractor use their own laptop?

For a role that touches internal documents, it is workable. For a role that touches production systems, cardholder data, protected health information, or administrative credentials, it is not, and no policy closes that gap because the controls involved depend on owning the endpoint. Disk encryption you cannot verify, patching you cannot enforce, and a remote wipe you cannot execute are not controls. The honest choice is between shipping managed hardware and narrowing what the personal device can reach. Shipping hardware into the region carries import duty and customs lead time that a US-only company has usually never had to plan for, and the common failure is discovering that in the week the person is meant to start rather than a month before.

What is the difference between a controller and a processor in Latin America?

The same split the GDPR uses, adopted at different speeds across the region. Brazil's LGPD has distinguished the controlador from the operador since 2018 and imposes direct security duties on both. Colombia separates the responsable from the encargado. Mexico's new 2025 statute addresses processors directly, which its 2010 predecessor did less clearly, and that is the detail most likely to be missing from a supplier template written years ago. Chile's Law 21.719 introduces the split for the first time when it takes effect on 1 December 2026, which means contracts drafted against the 1999 statute will need revisiting. Peru's 2024 regulation, in force since 30 March 2025, sets out processor duties in detail. Guatemala has no general statute at all, so there is no statutory processor concept to rely on and the contract is the only instrument that will be enforced.

How fast do I have to report a data breach involving a nearshore worker?

Your own clocks start when you know, which is why the supplier's notification obligation is the term that actually matters. Peru's regulation sets 48 hours for notifying the national authority. Brazil's ANPD has fixed a short reporting window by resolution rather than leaving it to a reasonableness standard. Costa Rica requires the controller to inform the agency and the data subject of irregularities within five working days. Chile introduces notification for the first time under Law 21.719. Against those, a supplier contract that says notice will be given without undue delay has consumed a deadline that was never the supplier's to spend. Put a number of hours in the contract and make sure the person who first learns that a worker has left, or that a device is missing, has a path to your security team that does not route through an account manager.

Is a nearshore hire riskier than a US contractor from a security standpoint?

The controls are the same, and the honest answer is that most of the difference is in enforceability of paper rather than in the security of the arrangement. Roughly four fifths of what this planner outputs is what a well-run company already applies to a domestic contractor: named identity, phishing-resistant authentication, least privilege, managed device, logging, access review, and a revocation clock. What genuinely changes across a border is who the regulator is, which court would hear a dispute, and whether the entity you have a claim against has assets. Those are contract and diligence questions rather than security questions. The place where nearshore engagements really do fail more often is the revocation clock, because the supplier knows the person has left before you do.

Hire with the controls already in place

Ready To Move

Hire nearshore talent from Latin America

LavaStaff sources, vets, and launches Latin America talent that works your hours, and on managed engagements handles payroll and compliance, directly or through a vetted EOR partner. Tell us what the role needs to reach and we will answer the flow-down and revocation questions in writing before you sign.