Nepal is a third country for EU data protection purposes, with no adequacy decision under Article 45 GDPR. We treat that as a design requirement, not an afterthought — and we apply the same rigour to clients outside the EU too.
Encryption alone is not a legally sufficient basis for moving personal data across borders. So our standard operating model avoids the question almost entirely.
Your personal data remains in your own EU-hosted or regionally-hosted environment at all times. Our Nepal-based team accesses it exclusively through your controlled cloud workspace — for example, Microsoft 365 or SharePoint with confirmed regional data residency.
Access is granted through named individual accounts only, with multi-factor authentication, role-based permissions, and full audit logging. No local download to Nepal-based infrastructure happens unless explicitly approved by you in writing.
Under this model, no personal data is transferred to Nepal at all — which means the EU's Chapter V third-country transfer provisions simply don't apply to the data itself. This eliminates the primary data-protection risk before it exists.
Where the specific nature of an engagement makes it unavoidable for personal data to be processed on Nepal-based infrastructure, the following apply as mandatory pre-conditions — every time, without exception.
A written DPA meeting all Article 28 requirements is signed before processing begins. It governs purposes, duration, data categories, our obligations, and your data subjects' rights. This is a legal requirement, not a preference.
All transfers are governed by EU Commission Implementing Decision (EU) 2021/914, specifically Module 2 — Controller to Processor. You are the Data Controller; Prime Quest is the Data Processor. These clauses apply in their standard, unmodified form.
Completed before go-live for any engagement involving personal data transfer to Nepal. It assesses Nepal's legal framework for government data access, the practical risk level for your specific data, and the effectiveness of our safeguards.
| Party | GDPR role | Responsibility |
|---|---|---|
| You (the client) | Data Controller (Art. 4(7)) | Determines the purposes and means of processing; issues written instructions to Prime Quest; retains ultimate responsibility for the lawfulness of processing. |
| Prime Quest Private Limited | Data Processor (Art. 4(8)) | Processes personal data only under your documented instructions; implements and maintains technical and organisational safeguards; maintains records of processing activities (Art. 30). |
| Regional governance partner | EU Representative (Art. 27), for EU clients | Formally designated as Prime Quest's EU Representative in writing where applicable; serves as the contact point for EU supervisory authorities; coordinates compliance documentation and communication. |
We're transparent about what's in place today and what's in progress — and happy to share our implementation timeline in more detail on request.
| Milestone | Target | Status | Notes |
|---|---|---|---|
| GDPR compliance framework | Ongoing | Active | DPA/SCC templates, TIA process, staff training and access controls are live and applied to every engagement involving personal data. |
| EU Representative designation | Per engagement | Active | Formally designated in writing under Article 27 GDPR where a regional governance partner is engaged for an EU client. |
| ISO 27001 (Information Security) | Within 12–18 months of first engagement | In progress | Certification body engaged; information security controls implementation underway. |
| ISO 9001 (Quality Management) | Within 18 months | Planning stage | Quality management system design in progress; internal quality procedures are already applied in daily delivery. |
Most offshore engagements fail on trust, not delivery. A regional governance partner closes that gap — they're who you actually call.
For European clients, there are potential governance partners in Germany and other markets across the region. For clients elsewhere, we structure an equivalent local governance arrangement, or work with you directly where a regional partner is not yet in place.
We're happy to walk your legal or procurement team through our DPA template, SCCs, and TIA process directly.