HomeEOR & PayrollEmployee Data Privacy and Cross-Border Transfers in EOR Arrangements: Where GDPR and Belarus Law Diverge
Employee Data Privacy and Cross-Border Transfers in EOR Arrangements: Where GDPR and Belarus Law Diverge
By Spex Team
13.08.2026
When a foreign company hires through an Employer of Record in Belarus, it rarely feels like standing up a cross-border data operation. It feels like hiring an engineer. But the moment that engineer signs a Belarusian employment contract, personal data starts to move — full name, home address, tax and social-insurance identifiers, salary, bank details, sick-leave records, performance notes — and a good deal of it crosses borders. The provider holds it in Minsk. The headquarters in London, Berlin, or Dubai want to see it. From that point on, two separate data-protection regimes apply to the same employee file: the GDPR on the headquarters side, and the Republic of Belarus’s own Law on Personal Data Protection on the local side.
The two regimes look similar on paper. They diverge sharply in practice. This piece walks through what each one demands of an EOR arrangement, and — more importantly — where the seams between them sit, because that is where compliance projects tend to fail.
Start by seeing the data, not just the hire. In an EOR arrangement, the provider that acts as legal employer — the model most foreign tech teams hire under — becomes the primary holder of the employee’s personal data. It drafts and signs the contract, runs payroll, withholds tax, files with the social protection fund, and keeps the HR record. That data lives in Belarus.
But it doesn’t stay contained there. Two flows are running at once. Going outbound, headquarters needs enough of the employee file to manage the person and close its own books — cost data to reconcile payroll, performance details for reviews, sometimes the entire record for a group-wide HR system. Coming inbound, headquarters sends data back into Belarus: corporate email identities, access credentials, project material that identifies the employee. Each direction is a cross-border transfer on its own, and each is assessed separately under each regime. An EOR isn’t a single data relationship. It’s at least two, and they point in opposite directions.
What Belarus Law Requires
Belarus regulates this through the Law of 7 May 2021 No. 99-Z “On Personal Data Protection,” in force since 15 November 2021, whose official English text is published by the National Personal Data Protection Center (NPDPC). The law borrows heavily from the GDPR’s vocabulary — “operator” for controller, “authorised person” for processor, “special personal data” for sensitive categories — but its transfer rules run on their own logic.
The core rule is a gatekeeper model. Personal data may be exported freely only to countries that ensure an “adequate” level of protection. The NPDPC defines and publishes that adequacy list; in practice it covers signatories to Council of Europe Convention 108/108+ and members of the Eurasian Economic Union. If the destination is not adequate, the transfer is prohibited unless it fits one of a handful of narrow gateways: explicit, informed consent from the data subject; necessity to perform a contract with that person; protection of life or vital interests; a Belarusian international treaty; specific anti-money-laundering transmissions; or a permit issued by the NPDPC. There is no soft middle ground.
Two further points matter for employers. Consent under Article 5 is a substantive instrument, not a checkbox: the operator has to state its identity and location, the purposes, the data categories, the validity term, the processors involved, the planned actions, the individual’s rights, and the consequences of granting or refusing. And breaches must be reported to the NPDPC promptly, no later than three working days after discovery — a clock worth memorising, because it is not the one most international teams carry in their playbook.
What the GDPR Requires
Now flip to the headquarters side. If the parent company is established in the EU or the UK, or otherwise falls within the GDPR’s reach, sending employee data to Belarus — or granting a Belarusian provider remote access to it — is a restricted transfer. Belarus has no EU adequacy decision, so it falls to be treated as a third country under the GDPR, in the same bucket as any other destination the European Commission has not blessed.
That triggers a familiar sequence. In the absence of adequacy, the exporter needs an Article 46 safeguard — in practice the European Commission’s 2021 Standard Contractual Clauses (SCCs), or Binding Corporate Rules for intra-group flows. But since the Court of Justice’s Schrems II ruling, SCCs alone are no longer enough. The exporter must also carry out a transfer impact assessment: an honest look at whether the destination’s laws actually let the SCC promises be honoured, taking in government access, surveillance powers, and the availability of redress. Where that assessment finds gaps, the exporter has to add safeguards or stop the transfer. Only as a genuine last resort do the Article 49 derogations — explicit consent, contractual necessity — come into play, and regulators dislike seeing them used for routine, repeated flows.
The GDPR also runs its own breach clock: notify the supervisory authority within 72 hours of becoming aware. And it treats employee data with particular suspicion, for reasons that turn out to matter a great deal below.
The Gaps Between
Here is where an EOR data programme gets difficult. The two regimes are not mirror images, and the differences are not cosmetic.
Standard Contractual Clauses only work one way. The GDPR leans on SCCs to legitimise the EU-to-Belarus leg. Belarus does not recognise SCCs or Binding Corporate Rules at all; they do nothing to authorise the Belarus-to-headquarters leg. The instrument at the centre of the European transfer toolbox is simply absent from the Belarusian one. Each direction of the flow needs its own legal basis, drafted to a different rulebook.
Employee consent is fragile under both — and weakest of all in employment. Under the GDPR, consent in the employment relationship is rarely treated as “freely given,” because the power imbalance between employer and employee undermines it. Under Belarusian law, Article 5 consent can be withdrawn at any moment, and it is hard to keep “informed” across a deep vendor chain. So the one basis that looks easiest — just ask the employee to agree — is the one neither regulator wants holding up a routine, ongoing HR flow.
The breach clocks don’t line up. One incident that exposes a single employee’s file can set both regimes running at the same time — 72 hours to the EU supervisory authority, three working days to the NPDPC. A response process designed around one of those deadlines will quietly fall short of the other.
The adequacy lists do not match either. A destination that Minsk considers adequate — an EAEU member, say — may be a third country from Brussels’ point of view, and a destination the EU accepts may not appear on the Belarusian list. Screening a vendor or a data centre against one list tells you nothing about the other.
Roles get misassigned. Under Belarusian law the EOR, as a legal employer, is the “operator” for the employment relationship. Under the GDPR the headquarters is often a controller in its own right. If the EOR contract does not spell out who is controller and who is processor for each flow, the duties that ride on those roles — breach notification, choice of transfer basis, liability — land on the wrong party or on nobody at all.
Schrems II demands a hard look at the destination. The transfer impact assessment is not a formality. It obliges the EU exporter to weigh the Belarusian legal environment for state access to data and, where the SCC guarantees cannot be relied on, to add supplemental measures — strong encryption with keys held in the EEA, data minimisation, pseudonymisation — or reconsider the flow. Done honestly, it shapes the whole architecture.
HR Consulting in Belarus
Professional HR consulting and recruitment for your it company in Belarus!
None of this makes hiring in Belarus through an EOR unworkable. It makes it a design problem, best solved before the first contract is signed rather than after the first data-subject request.
Map the flows first. Write down exactly what leaves Belarus, what enters it, who holds it at each step, and who controls the encryption keys. You cannot choose a transfer basis for a flow you have not identified.
Then minimize what actually crosses. A large share of the outbound need can be met by sending headquarters a clean monthly payroll report rather than the underlying employee records — a reporting discipline that also keeps the data footprint small and shrinks the surface a transfer assessment has to cover. Keep raw HR and payroll files in Belarus by default; export aggregates, not dossiers, wherever the business purpose allows.
Choose a basis per direction and per destination, not once for the whole relationship. Localise consent and privacy notices to the Article 5 content list rather than reusing an EU-facing template. Build one breach process that satisfies the shorter of the two clocks and names both regulators. Then get the controller-processor split, the transfer bases, and the incident-notification obligations written into the EOR contract itself — the kind of groundwork HR consulting exists to handle, because it is far cheaper to document up front than to reconstruct during an audit.
FAQ
Does an EU company need SCCs to hire through a Belarus EOR?
Usually yes, for any flow of employee data from the EU to Belarus or any remote access granted to the Belarusian provider. Belarus has no EU adequacy decision, so an Article 46 safeguard — typically the 2021 SCCs — plus a transfer impact assessment is the standard route. Note that those SCCs do the opposite job from Belarusian law’s perspective, so the return flow needs a separate basis.
Can we just rely on the employee’s consent?
Rarely as the main pillar. Both regimes will accept consent in principle, but the GDPR tends to view employment consent as something that’s rarely given freely, and under Belarusian law consent can be pulled back at any moment. It might work for a one-off, specific transfer, but as the foundation for a routine, day-in day-out HR flow, it’s shaky at best.
Belarus isn’t in the EU — does the GDPR even apply to our hires there?
It applies to you, the exporter, if your company falls within the GDPR’s scope. The obligation attaches to the act of transferring data out of the EEA, not to where the employee sits. Sending or exposing data to Belarus is a restricted transfer regardless of the fact that Belarus is outside the Union.
What is the breach-notification deadline if an employee’s data is exposed?
Possibly two deadlines running at the same time. The GDPR gives you 72 hours from the moment you become aware to notify the supervisory authority, while Belarusian law says you have to inform the NPDPC within three working days of discovery. A single incident can set both clocks ticking, so your response process needs to be built around whichever deadline is tighter.
Does the EOR or the client carry data-protection liability?
Both carry it, and where the responsibility falls depends on the part each one plays, so the breakdown belongs in the contract. In Belarus, the EOR acts as the operator for the employment relationship; the client, meanwhile, is frequently a controller on its own footing under the GDPR. When the roles aren’t clearly defined, neither is the liability — the two rise and fall together.
The Takeaway
Most people file employee data privacy in a Belarus EOR setup under one heading. That’s the mistake. There are two regimes here, not one, and they’re working at the same time over data that moves in opposite directions. They sound compatible because they use the same words. They aren’t. Justifying a transfer works differently under each. The adequacy lists don’t match. The breach clock starts at a different point and runs for a different length. And consent — the thing most people reach for first — barely holds up once there’s an ongoing employment relationship underneath it. The organizations that stay out of trouble decide how the data will be structured before anyone signs, not after the first paycheck clears.
That is a great deal easier when the party holding the data in Belarus already works to both rulebooks — which is exactly what a direct Employer of Record provider is set up to carry, alongside the payroll, tax, and HR obligations that come with being the legal employer.
About the Author
Spex Team
Spex Advisers is a team of experienced and professional consultants, accountants, HR specialists and lawyers based in Minsk, Belarus, advising foreign businesses and private clients since 2018.
EOR Services in Belarus
Hire employees in Belarus quickly through an employer of record without opening a local entity!
Angel investments are a key financing mechanism for early-stage startups and innovative projects. They provide not only capital but also experience, contacts, and strategic guidance. Unlike venture capital funds, angel investors usually act individually, risking their own money for promising ideas and teams that can impact the market. In Belarusian and international startup ecosystems, angel […]
For several years now, the Republic of Belarus has occupied one of the leading places in the world in terms of conducting IT business. This is largely due to the presence in Belarus of a special taxation regime for IT companies – the High Technologies Park. Introduction Today the Hi-Tech Park unites more than 1000 […]
The closure or sale of an IT company marks a critical and complex phase in the life cycle of any business. In the fast-evolving technology sector, such decisions may be driven by various factors: a strategic shift, the owners’ desire to focus on new projects, financial challenges, or an opportunity to exit the business profitably. […]