Outsourcing AI development raises a question that ordinary software projects do not: where does your data go, and what happens to it? Add a foreign jurisdiction and the questions multiply. The good news is that most of them can be settled on paper and in configuration before the first line of code is written. This checklist is written for US companies working with a Brazilian partner, but the principles apply anywhere. It is not legal advice; have your counsel review contracts and any regulated-data plans.
1. Intellectual property
The default in software contracts varies, so state it explicitly.
- Assignment of work product. The contract should assign all code, prompts, models fine-tuned on your data, documentation and other deliverables to your company on creation or payment.
- Pre-existing and third-party components. Ask the partner to list any reusable libraries or tools they bring and the licenses involved. Open-source licenses differ, and some impose obligations you may not want in a commercial product.
- Individual contributors. Make sure every person who works on your project, employee or contractor, is bound by an agreement that passes rights up the chain to the partner and then to you.
- Repositories and accounts. Source code and cloud accounts should live in your organization, with the partner as an invited collaborator. Ownership by access is stronger than ownership by clause alone.
2. Confidentiality and NDAs
Sign a mutual NDA before sharing anything beyond a general description. Confirm that it covers subcontractors and specialists brought in on demand, defines how long obligations last and requires return or deletion of materials at the end. Ask how the partner controls who can see your information internally, and whether specialists get access only to the parts they need.
3. Classify the data before you share it
Most AI projects do not need all your data. Sort it into categories:
- Public or low-risk: marketing copy, public documentation.
- Internal: processes, pricing, non-public reports.
- Sensitive: customer personal information, employee records, financial data.
- Regulated: health information, payment card data, anything subject to sector rules.
Then decide what the partner needs. Developing against synthetic or anonymized samples is often enough for prototyping. Where real data is required, limit the fields, mask identifiers and keep processing inside environments you control.
4. Privacy and regulatory obligations
Your obligations stay with you when work is outsourced. Depending on your business, relevant frameworks may include state privacy laws such as California’s CCPA/CPRA, HIPAA for health data, GLBA for financial institutions, PCI DSS for card data, and customer contracts that impose their own requirements. If you handle data of individuals in the EU, GDPR may apply as well. Brazil has its own data protection law, the LGPD, which shares many principles with GDPR, and that can help when mapping controls, but it does not replace your own US obligations.
Practical steps: document what personal data the project touches, sign a data processing agreement where appropriate, specify permitted purposes, and define breach notification duties and timelines. If you need a HIPAA business associate agreement or similar instruments, raise it at the start, because some partners will not or cannot support it.
5. AI-specific questions
- Which model providers will be used? Ask for the list, and confirm the terms: is your data used to train models, how long is it retained, and can you opt out?
- Where is data processed? Confirm the regions for model APIs, hosting and storage.
- Prompt and output logging. Decide what gets logged, who can read it and how long it is kept, since logs can contain sensitive content.
- Guardrails. For customer-facing features, define what the system must not do, how it handles uncertain answers and when it hands off to a human.
- Human review. For decisions with legal, financial or health impact, keep a person accountable.
6. Access control and secure engineering
- Named accounts only, with single sign-on or multi-factor authentication; no shared passwords.
- Least-privilege access to production systems and data, granted for the duration of the work and revoked afterward.
- Secrets such as API keys stored in a managed secrets tool, never in code repositories.
- Separate development, staging and production environments, with no production data in development unless approved.
- Code review before merge, dependency scanning and a documented deployment process.
- Encrypted devices and secure connections for the people doing the work. Ask how this is enforced for remote specialists.
7. Incident response
Ask what happens when something goes wrong. The contract and process should state who to notify, within what time window, how affected credentials get rotated and how the post-incident report will be shared. A partner that has thought this through will answer quickly and specifically.
8. Contract mechanics that matter in cross-border work
- Governing law and dispute resolution. Agree on the law and venue, or on arbitration, in the contract.
- Invoicing and payment. USD invoicing and clear payment terms avoid currency ambiguity.
- Liability and insurance. Discuss limits of liability and whether the partner carries professional liability coverage appropriate to the project.
- Exit plan. Define handover of code, documentation, credentials and data, plus deletion of copies, if the engagement ends.
9. Evidence, not promises
Ask the partner to show their practices: a sample status report, the staging environment, how access is provisioned, how repositories are structured. A project run with written specs, previews of what will be built, regular check-ins and a staging environment is easier to audit, because decisions and changes are documented as they happen.
Printable summary
- IP assignment in writing, including subcontractors.
- Mutual NDA before details are shared.
- Data classified, minimized and masked where possible.
- Applicable privacy laws mapped; DPA or BAA in place if needed.
- Model providers, data retention and processing regions confirmed.
- Repositories and cloud accounts owned by you.
- Least-privilege access, MFA and secrets management.
- Incident response and notification terms agreed.
- Exit plan and data deletion defined.
Spending a few days on this before kickoff costs little and prevents the problems that are hardest to fix later. A serious partner will welcome the questions.
Want to put this to work? Convertty runs an AI assessment of your workflows and delivers an implementation plan with a pilot in production in 30–60 days. Book a call.