Remote work · Outsourcing · Offshoring

Dedicated German-speaking staff – access stays in Cologne

A fixed person who works exclusively for your company, speaks German and knows your processes. Your contract is solely with INFONET Computer GmbH in Cologne – you do not employ anyone abroad. All work is done exclusively via our access servers in Cologne: not a single copy of your data is created on the devices abroad, and every session is logged.

Fixed, named person Contract only with INFONET Access servers in Cologne Every session logged

The model

No agency, no third-party company – our own employees

The remote staff have an employment contract with INFONET Computer GmbH in Cologne. Not with an agency, not with a partner company abroad, not as freelancers. Only their place of work is in Egypt.

This difference sounds like a formality, but it is the most important point of the whole arrangement – legally and practically. Legally, because it determines whether there is a transfer of data to a third country at all (more on this below). Practically, because you have one contact person, not three.

The people who work for you are selected, trained and managed by us. There is no staff pool from which someone different turns up every week.

  • Fixed people. You work with the same people, who know your processes after a few weeks.
  • German as the working language. For phone, email and documentation – not just for the greeting.
  • German working hours. Egypt is in the same or a neighbouring time zone; there is no night-shift arrangement.
  • One contract with a German company. Your contractual partner is INFONET Computer GmbH in Cologne, under German law.

The dedicated model

One fixed person for you – one contract with a German company

You do not get a service number or a pool from which someone different calls every week, but a named person who works only for you.

What you get

A fixed member of staff who works exclusively for your company. They get to know your processes, your systems and your customers – just as your own employee would, except that you do not have to hire them.

  • Named, not anonymous
  • Works only for you, not for several clients at once
  • Scope and working hours are set out in the contract
  • Cover for holidays and sickness is arranged in advance

What you don’t get

No obligations abroad. You do not sign an employment contract, run no payroll, create no permanent establishment and do not deal with any foreign company.

  • Your only contractual partner is INFONET Computer GmbH
  • German law, German place of jurisdiction
  • All employer obligations lie with us
  • One invoice, no foreign element in your accounts

How access works

Four steps – and at no point does data leave your organisation

The technical set-up is the core of the whole thing. It determines what a remote employee can see and what never reaches their device.

  1. Sign-in to the access server in Cologne

    The employee signs in to a server on our premises – with a personal account and a second factor. Without this step, there is no way into your systems.

  2. Session on the screen, not on the device

    Your systems are accessed from there. What is transmitted is screen content, keyboard and mouse. The application runs on your side, not on the device abroad.

  3. No way for data to get out

    File transfer, clipboard and printing from within the session are blocked. There is no intended way to get a file onto the local device.

  4. Log kept with us in Cologne

    Sign-in, duration, target system and sign-out are recorded on our servers. The log is kept in Germany and you can inspect it.

Traceability

Who accessed what, and when

On request, we present the log to you every month – or you can look at it yourself at any time.

Access server Cologne · Session log
Sessions per month412all logged
File transfers0technically blocked
Log locationCologneown server
Retention90 daysthen deleted
StartEmployeeTarget systemDurationData outflow
2 Sep 08:14M. A.Terminal server client A01:42none
2 Sep 09:03S. F.Ticket system00:35none
2 Sep 10:20M. A.Inventory management client B02:11none
2 Sep 13:05N. H.Terminal server client A03:04none
Mock-up of the log view. All names, times and systems are sample data.

Data protection in detail

What applies – and what we do about it

We would rather tell you exactly what the legal position is than paint you a worry-free picture. You can show the following overview to your data protection officer.

RegulationWhat it requiresHow it looks here
Chapter V GDPR – transfer to a third countryStandard contractual clauses and an impact assessment as soon as data is made accessible to another entity in a third country.Not the case here. In its Guidelines 05/2021, the EDPB (European Data Protection Board) requires three conditions to be met at the same time, including an importer that is a separate legal entity. Our remote staff are employees of the same GmbH – the data stays within the same controller.
Art. 32 GDPR – security of processingTechnical and organisational measures appropriate to the risk. The EDPB expressly requires this assessment even where there is no transfer.Access only via our servers in Cologne, personal accounts with a second factor, file transfer and clipboard blocked, logging in Germany.
Art. 28 GDPR – processing on behalf of a controllerThe place of processing and the people involved belong in the contract; processing only on documented instructions.Egypt as the place of work is stated in the data processing agreement (DPA). It is neither concealed nor introduced later on.
Art. 30 GDPR – records of processing activitiesThe processor keeps its own records.Kept, including the access from Egypt. Extract available on request.
§ 203 StGB (German Criminal Code) – professional secrecyPeople involved in the work must be bound to confidentiality and instructed about criminal liability.Written undertaking and instruction before first access, for each person individually. We keep the evidence and send it to you.
AÜG (German Temporary Agency Work Act)Anyone who supplies staff to another company that deploys them like its own employees needs a permit. Without one, an employment relationship with the hiring company may be deemed to exist.Under the technical directive of the German Federal Employment Agency (in force since October 2025), no permit is needed for work carried out purely abroad without any connection to Germany. Our staff work only from abroad and do not travel to Germany for this work. We manage the staff; you say what needs doing, not when someone takes a break.
§ 43e(4) BRAO · § 62a(4) StBerGIf the work is carried out outside the EU, access to client secrets may only be granted if the protection of secrets there is comparable to that in Germany.Nobody can or may make this assessment for you – it is your decision as a law or tax firm. We provide the documents for it: measures, undertakings, logs. We do not claim that Egypt meets this requirement.
The last row is the uncomfortable one. For law firms and tax advisory firms, a separate professional-law hurdle applies in addition to the GDPR (§ 43e BRAO, the German Federal Lawyers’ Act, and § 62a StBerG, the German Tax Advisory Act), and it is a high one for a country outside the EU. We say so before the contract, not afterwards.
On the AÜG: this classification is based on a directive from the German Federal Employment Agency, not on a court ruling – no court has decided on it yet. It depends on the person not coming to Germany for the work. A single assignment on site would change the assessment.
Information as of September 2026. Based on Guidelines 05/2021 of the European Data Protection Board on the interplay between Art. 3 and Chapter V GDPR, as well as § 43e BRAO and § 62a StBerG. This overview describes our set-up; it is not legal advice.

Where we advise against it

What this model is not intended for

There are cases where we advise against it from the outset. We would rather have one assignment fewer than a client who has a problem afterwards.

  • Client and patient data without an explicit decision. Law firms, tax advisory firms and medical practices must assess and document for themselves whether the protection of secrets is comparable. Without that decision, we do not start.
  • Special categories of data under Art. 9 GDPR. Health data, trade union membership, biometric data – here the balancing of interests is different, and it has to be done beforehand.
  • Businesses subject to NIS2 without a supply chain assessment. If the directive applies to you, you must assess your service providers. We supply the information for this, but you have to carry out the assessment.
  • If a works council has not been involved. Access to systems containing employee data may be subject to the works council’s co-determination rights. That needs to be dealt with before introduction, not afterwards.

Frequently asked questions

Questions about remote staff

Is our data transferred to Egypt?

No copies are created there. The employee sees screen content that reaches them via our server in Cologne; the application runs on your side. File transfer, clipboard and printing from the session are blocked. Legally speaking, this is still processing of your data – just not a transfer to another entity within the meaning of Chapter V of the GDPR, because the people involved are employees of the same company.

Do we need standard contractual clauses?

According to Guidelines 05/2021 of the European Data Protection Board, no: standard contractual clauses require an importer that is a separate legal entity. There is none here, because the staff are employed by INFONET Computer GmbH. We still advise you to discuss this classification with your data protection officer – it is well founded, but it is a legal opinion.

What does our data processing agreement say?

Egypt as the place of work is named explicitly, as are the technical measures and the logging. Some providers leave this point out. We consider that a mistake: whatever is missing from the contract will come to light at the next audit at the latest – and then the client is left to deal with it alone.

Can we use this as a law firm or tax advisory firm?

Only if you yourself conclude that the protection of secrets in Egypt is comparable to that in Germany – this is required by § 43e(4) BRAO (German Federal Lawyers’ Act) and § 62a(4) StBerG (German Tax Advisory Act). We may not make this assessment for you, and we do not claim that it is an easy one. We provide the documents and accept a no.

Who is liable if something goes wrong?

Your contractual partner is INFONET Computer GmbH in Cologne, under German law and with a German place of jurisdiction. There is no chain through a foreign company at the end of which nobody can be held to account.

What happens when an employee leaves?

The account is locked the same day. As there is no data on the devices abroad, there is nothing to collect – that is the real advantage of this set-up compared with handing out laptops.

Can we inspect the log?

Yes. On request as a monthly extract, or for a specific period when you ask for it. It is kept for 90 days on our servers in Cologne and then deleted.

Initial consultation

Bring your data protection officer along

We go through the set-up with you and your data protection officer before anything is signed. Afterwards, you will know whether the model is an option for your organisation – and if it is not, we will tell you that too.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement