U.S. buyer guides
Outsourcing guides for U.S. buyers by state
State-aware buyer guides for sourcing software, AI, automation, and international teams without fake local offices or duplicated location pages.
This section is for U.S.-based buyers evaluating delivery in suitable countries outside the United States. It does not claim that Outsourcing.ai has an office, staff, or completed client work in every state. A state guide is published only when the buyer context changes the decision enough to justify a distinct resource.
What a state guide should answer
A useful state page explains how the buyer’s location affects working-hour overlap, decision windows, travel assumptions, data handling, procurement constraints, and the evidence needed from an international team. It should connect those facts to an engagement model and a practical next action.
It should not replace a destination-country review. A California company considering teams in Colombia, Poland, India, or another eligible location must still examine the proposed entity, people, data flow, contract, intellectual-property rights, security, cost, and continuity for that country and provider.
What these pages do not claim
- No page represents a local Outsourcing.ai office or Google Business Profile.
- No state name implies local employees, customer references, or physical service delivery.
- No state is promised a universally best outsourcing country, provider, or rate.
- No guide replaces legal, tax, employment, privacy, security, or financial advice.
- No destination is presumed lawful or suitable without current sanctions, export, contracting, data, and engagement review.
Publication standard
Every state guide must contain current state-specific primary sources, a clear buyer decision, original analysis, a time-zone collaboration model, a visible local-presence disclaimer, outside-U.S. sourcing paths, internal links, reviewed and next-review dates, and at least one decision aid that differs materially from other states.
Pages that would only replace the state name remain unpublished. This makes the state program slower, but it keeps the site useful even if no search engine sends traffic.
Published state guides
Alabama
The Alabama outsourcing buyer guide builds an incident evidence compression ladder from the current third-party-agent handoff into buyer-controlled resident, Attorney General, and consumer-reporting-agency decisions. It keeps the 10-day and 45-day outside paths separate from faster contractual alerts, then adds a clearly dated processor-contract and rights-testing transition for the Alabama Personal Data Protection Act before May 1, 2027.
Alaska
The Alaska outsourcing buyer guide starts with a work-location manifest rather than a provider headquarters. It separates private commercial delivery from the State’s foreign-service waiver and information-security approval paths, then adds an Alaska/Aleutian authority relay, degraded-connectivity mode, immediate personal-information incident interface, and custody-tested record disposal.
Arizona
The Arizona outsourcing buyer guide replaces ambiguous “Arizona time” with named cities, maintained zones, dated overlap, and decision authority. It distinguishes most of Arizona from the Navajo Nation daylight-saving path and tests recurring calendars, sustainable hours, written handoffs, backup owners, and incident response through a clock-transition pilot.
Arkansas
The Arkansas outsourcing buyer guide builds a direction-to-decision custody ledger for international software and AI work. It traces lawful inputs, the person and entity giving direction, approved tools and exact results, employer-controlled assignments, meaningful evaluation, an authorized human final decision for covered public-entity work, state cybersecurity boundaries, a separately retained breach determination, and a tested exit package.
Hawaii
The Hawaii outsourcing buyer guide uses expiring authority capsules and decision-ready overnight packets instead of forcing permanent live overlap. It separates normal work, buyer-decision, and immediate incident lanes; keeps private, government-agency, and records-destruction duties distinct; and tests release expiry, emergency routing, clock changes outside Hawaii, custody, and exit in a paid pilot.
Idaho
The Idaho outsourcing buyer guide builds a high-water AI approval passport. It scores data sensitivity, decision impact, autonomy, transparency, scope, and novelty; routes the resulting tier through the correct governance gates; blocks Critical State data from international remote access; and connects eligible-artifact delivery to human review, GenAI evidence, public-record custody, accessibility, the public/private incident fork, exact Pacific or Mountain authority, and tested exit.
California
The California outsourcing buyer guide focuses on Pacific-time collaboration, state privacy questions when personal information enters a supplier workflow, complete cost, and team-level diligence. It is the pilot for the publication model; other states remain in research until they meet the same evidence standard.
Colorado
The Colorado outsourcing buyer guide separates current Colorado Privacy Act work from the enacted January 1, 2027 automated-decision and chatbot transition. It creates a consequential-decision register, developer–deployer evidence bridge, Mountain-time authority model, and short-cycle rulemaking review instead of treating an outdated AI-law summary as a release plan.
Connecticut
The Connecticut outsourcing buyer guide turns the current 2026 privacy framework into an operation-level processor instruction and role-drift record. It adds an AI-tool stop gate, tested consumer-rights support, and a separate third-party evidence and incident lane only for buyers within Connecticut’s insurance-licensee perimeter.
Delaware
The Delaware outsourcing buyer guide defeats the formation-state fallacy with an entity-to-operation authority crosswalk. It keeps formation, status, registered agent, operating locations, consumer reach, controller and processor roles, delivery people and systems, signing and release authority, incident ownership, and tested exit as separate evidence-backed facts.
Texas
The Texas outsourcing buyer guide starts from the buyer’s exact city because Texas crosses the federal Central–Mountain time-zone boundary. It adds Texas Data Privacy and Security Act diligence, an explicit AI service and data-path inventory, complete-cost normalization, and a representative operating-model pilot. It passed the same depth, primary-source, no-local-office, and distinctiveness controls as California.
New York
The New York outsourcing buyer guide separates general SHIELD Act supplier-security diligence from the additional third-party risk program a DFS-covered financial-services buyer may need. It builds an Eastern-time decision system, an AI service register, a critical-provider disruption exercise, and an evidence-led paid pilot without implying that every New York business shares one regulatory perimeter.
North Carolina
The North Carolina outsourcing buyer guide starts with record custody and turns G.S. 75-64/65 into two tested supplier interfaces: immediate non-owner-to-owner breach escalation and a monitored disposal chain with written policy, destruction-provider diligence, a written contract, transport controls, and reconciled evidence.
North Dakota
The North Dakota outsourcing buyer guide builds an agent capability lease and data-risk inheritance graph. It treats unclassified State data as Moderate pending review, makes joined or derived outputs inherit the highest contributing risk, constrains every human and machine actor by objective and action, and connects approved-tool change review, platform-independent records, prohibited-technology removal, immediate private incident relay, exact Central or Mountain authority, and tested exit.
Florida
The Florida outsourcing buyer guide starts with the buyer city because the state crosses the federal Eastern–Central boundary. It separates Part V applicability from the broader security and breach questions in section 501.171, then turns the provider incident handoff and buyer-side disruption into testable operating controls.
Georgia
The Georgia outsourcing buyer guide creates a supplier incident-evidence lane before access: safe containment authority, preserved systems and records, service-provider access review, fact-controlled communications, recoverable delivery, and a separate covered-record disposal workflow tested with Eastern-time command.
Illinois
The Illinois outsourcing buyer guide introduces a biometric stop gate before real-person data enters development and a separate employment-AI review for applicable decisions and applicant-video workflows. It treats legal classification, human authority, provider services, evidence, and deletion as prerequisites rather than post-build paperwork.
Indiana
The Indiana outsourcing buyer guide builds a maintenance-authority interlock. It keeps current consumer-data processor duties, ordinary engineering, digital-twin validation, production IT, and supervised OT maintenance on distinct buyer-controlled paths, with expiring access, observed commands, rollback, recovery, and exact Eastern or Central site scheduling.
Iowa
The Iowa outsourcing buyer guide builds an evidence-retention relay. It keeps ordinary engineering proof, current consumer-data instructions and deletion evidence, general breach facts, insurance investigation records and conditional regulator updates, and expressly activated State-system logs on separate clocks with buyer-owned retention, destruction, production, recovery, and exit decisions.
Kansas
The Kansas outsourcing buyer guide builds an origin-and-authority circuit breaker. It classifies inputs, distinguishes internal, public-facing, agentic, and autonomous AI, proves six sensitive-data conditions, traces model and component control, keeps the State-device AI and covered genetic-technology disconnects separate, and connects annotated code, human release, accessibility, records, incidents, exact Central or Mountain scheduling, and exit.
Mississippi
The Mississippi outsourcing buyer guide builds a data-stays / artifacts-travel execution membrane. It keeps covered State data, backups, and disaster recovery inside the United States; separates artifact-only international development from narrowly required technical support; and binds approved AI purpose, human release, prohibited-technology screening, public-record access, incidents, return, secure disposal, and tested exit to buyer-controlled evidence.
Missouri
The Missouri outsourcing buyer guide builds a work-location and recovery truth lock. It separates ordinary private work from State procurement, traces Executive Order 04-09 disclosure and its four distinct conditions into the prime and subcontractor execution ledger, and couples normal delivery to tested failover so support, cloud administration, AI tooling, or an alternate supplier cannot silently change the represented place of performance. Buyer-controlled artifact admission, incident evidence, public-record access, audit, complete cost, Central-time authority, and exit remain separately provable.
Kentucky
The Kentucky outsourcing buyer guide builds a context-to-authority control plane. It treats controller and processor status as operation-specific, prevents role drift, and keeps ordinary delivery, current consumer-data contracts and assessments, insurance-licensee evidence, Commonwealth-system access, incidents, exit, and the Eastern–Central authority window in distinct buyer-controlled lanes.
Louisiana
The Louisiana outsourcing buyer guide separates ordinary commercial work, private-data custody, an expressly activated public-body managed-provider path, and severe-weather continuity. Its progressive evidence capsule feeds the correct authority without inventing one universal breach clock, while a contract gate, registration lifecycle, tested Louisiana Fusion Center route, secure degraded mode, reconciliation, and buyer-owned recovery remain independently verifiable.
Maine
The Maine outsourcing buyer guide builds a permission-and-incident relay that keeps broadband customer consent and service exceptions, immediate general custodian notice, and insurance third-party or ancillary-provider duties on separate authority paths. It maps revocation through every supplier and model, prepares the January 1, 2027 insurance contract transition, preserves buyer-controlled regulator decisions, and tests the actual international service chain through a paid pilot.
Massachusetts
The Massachusetts outsourcing buyer guide traces resident personal-information decisions from a buyer’s written information security program into service-provider selection, contract instructions, technical controls, monitoring, incident evidence, and a recoverable Eastern-time pilot.
Michigan
The Michigan outsourcing buyer guide separates ordinary applications from engineering, connected-product, and plant-access work. It gives every supplier a bounded authority envelope, requires a reproducible engineering-custody packet, treats industrial access as an approved session, and tests revocation and trusted recovery across Michigan’s Eastern–Central boundary.
Montana
The Montana outsourcing buyer guide builds an age-and-data destination gate. It keeps minors-related product duties and assessment changes separate from ordinary privacy thresholds, then puts covered genetic or neurotechnology data behind granular consent, processor instructions, current country screening, revocation, destruction, and immediate incident-relay controls before any outside-U.S. storage or transfer.
Nebraska
The Nebraska outsourcing buyer guide creates a producer-authority custody gate for agricultural data. It keeps producer ownership, approved service, sale consent, consumer data, personal-information security, the January 2027 contract transition, AI use, and the Central–Mountain boundary as separately evidenced operating decisions.
New Jersey
The New Jersey outsourcing buyer guide separates ordinary software, consumer-data processing, clinical-record systems, and production or quality-system automation. It requires an evidence-continuity packet that preserves intended use, risk, identities, metadata, audit trails, assurance, exports, and record reconstruction after a hosted service or supplier exits.
New Hampshire
The New Hampshire outsourcing buyer guide builds an AI authority and decommission relay. It keeps ordinary private delivery separate from State-agency AI inventory, prohibited-use removal, human review and disclosure, current consumer-data processor and assessment duties, narrowly triggered child-directed harmful generative communication, general breach, and insurance cybersecurity while requiring proof of release, removal, return, deletion, revocation, and exit.
New Mexico
The New Mexico outsourcing buyer guide builds a prompt-to-record containment zone. It joins the State’s four data classes to approved AI tools, source and transformation evidence, accountable human review, public-facing disclosure, electronic-record custody, a separately scoped private-business incident lane, a restricted-work enclave, and a tested portable exit without treating executive-agency policy as universal private law.
Ohio
The Ohio outsourcing buyer guide translates a buyer-owned, framework-versioned cybersecurity program into a supplier work-order ledger with observable evidence, exception authority, incident handoff, revision monitoring, and tested exit. It keeps Chapter 1354’s limited affirmative-defense theory separate from the more prescriptive Chapter 3965 insurance-licensee lane.
Oklahoma
The Oklahoma outsourcing buyer guide builds a dual-date privacy cutover relay. It preserves operation commencement and material change for the January 1, 2027 controller-and-processor regime while keeping the already-effective breach owner–maintainer, resident-notice, Attorney General reporting, evidence, containment, and recovery path immediately operational.
Oregon
The Oregon outsourcing buyer guide follows original and derived data through suppliers, models, recipients, rights, universal opt-out signals, deletion, and exit. It adds release stop gates for sufficiently precise location and under-16 data paths, plus a contract-and-oversight packet for deidentified disclosures.
Pennsylvania
The Pennsylvania outsourcing buyer guide separates ordinary private work from personal-information incident duties, insurance-licensee oversight, and Commonwealth-governed systems. Its environment-and-authority ledger keeps overseas contributors inside approved lower or test environments when current Commonwealth policy applies, with non-linkable test or anonymized data and a tested handoff to CONUS production and support owners.
Rhode Island
The Rhode Island outsourcing buyer guide builds a notice-to-operation trace with three separate paths: commercial-site controller and disclosure facts, thresholded rights and controller-processor operations, and immediate incident evidence. It tests every public statement against the actual international data path, gives purpose or recipient changes a pre-code gate, and proves customer requests and exit in a paid pilot.
South Carolina
The South Carolina outsourcing buyer guide separates ordinary private delivery from State procurement before it evaluates any international team. Its clause-activation matrix reads the exact solicitation and executed contract, sends protected work into the required enclosure, routes only eligible artifacts across a buyer-controlled evidence bridge, and keeps proposal disclosure, actual contracting authority, urgent incident notice, and exit independently testable.
South Dakota
The South Dakota outsourcing buyer guide builds a consent-to-material custody gate for direct-to-consumer genetic-testing work. It keeps physical samples, derived genetic data, consumer identity, consent, provider possession, revocation, deletion, destruction, and general breach evidence traceable while treating the July 1, 2027 large-platform interoperability provisions as a separate future transition and scheduling the buyer from its actual Central or Mountain location.
Tennessee
The Tennessee outsourcing buyer guide ties each outsourced data operation to a written privacy program, controller instruction, consumer-rights regression test, assessment decision, supplier evidence, incident route, and framework-version watch. It distinguishes NIST’s current Privacy Framework 1.1 initial public draft from a published subsequent revision and schedules the named team from Tennessee’s actual Eastern or Central buyer city.
Utah
The Utah outsourcing buyer guide creates an obligation switchboard for ordinary commercial delivery, current UCPA rights, generative-AI consumer and regulated-service disclosures, and Utah governmental-data contracts. It adds separate incident clocks, July 2027 transition controls, a dated Mountain-time authority model, and a paid pilot that proves the activated capabilities without weakening a reusable multi-state baseline.
Vermont
The Vermont outsourcing buyer guide creates a data-provenance and purchaser-purpose gate before an international team or AI system receives information. It separates current data-broker registration, written security-program, service-provider, owner/maintainer, and incident operation from the enacted January 1, 2027 Act 138 transition, then tests source changes, purchaser identity, intended use, derived data, AI disclosure, exit, and the future incident path without presenting future law as current.
Virginia
The Virginia outsourcing buyer guide traces each work package from a consumer-data role, Commonwealth agreement, federal clause, CUI category, CMMC requirement, or export decision into the approved entity, system, people, tools, incident route, and release authority. Its controlled-data enclave and evidence bridge let eligible international work remain useful without treating every Virginia project as government work or every CUI item as export controlled.
Maryland
The Maryland outsourcing buyer guide converts a requested product or service into an enforceable supplier data budget. It adds a stricter sensitive-data stop gate, pre-processing algorithm assessment decision, processor-authority boundary, and an Eastern-time pilot that tests whether the named team challenges unnecessary data.
Minnesota
The Minnesota outsourcing buyer guide turns each processing path into a controller-to-processor evidence packet. It links instructions, data inventory, rights and event assistance, assessment inputs, inspection or independent evidence, and tested return or deletion through a Central-time operating model.
Nevada
The Nevada outsourcing buyer guide separates ordinary software work from gaming-system and regulated-data perimeters. It keeps independent log review and critical authority on the buyer side, contracts for immediate incident facts, handles West Wendover’s distinct clock, and tests trusted recovery without the supplier’s primary administrator.
Washington
The Washington outsourcing buyer guide starts with health-related inputs and inferences, creates a processor instruction packet for approved workflows, stops geofence features before implementation, and tests Pacific-time delivery through a deletion, revocation, or handover exercise.
West Virginia
The West Virginia outsourcing buyer guide builds a cyber-evidence classification relay. It keeps ordinary private delivery, the current State cyber program, public-entity incident reporting, scoped sensitive State access, private owner-or-maintainer breach analysis, and critical-energy operations on separate authority paths while linking public-safe delivery status to protected cyber evidence without copying sensitive findings into broad project systems.
Wisconsin
The Wisconsin outsourcing buyer guide builds a twin-to-cell release passport for industrial software and AI. It binds one immutable candidate to source, configuration, data and model provenance, physical assumptions, staged twin, interface, and shadow evidence, a buyer-owned production gate, trusted rollback, trade-secret custody, incident decisions, and complete exit artifacts.
Wyoming
The Wyoming outsourcing buyer guide builds a purpose–transfer–return ledger for international delivery. It separates ordinary private work from government personal-data processing, then traces the contracted service and field necessity through supplier access, resident requests, retention, public-records preservation, urgent incidents, and verified return or destruction across the Act’s staggered policy dates.
How to start before your state is published
- Define the outcome, internal owner, delivery model, and acceptance evidence.
- List the buyer’s city, decision-maker schedule, data, systems, travel, and legal constraints.
- Shortlist outside-U.S. locations from those requirements rather than a rate chart.
- Evaluate named providers and team members with the same evidence model.
- Run a representative paid milestone before scaling.
Use the nearshore versus offshore guide for collaboration design, the Latin America guide for one possible sourcing region, and the provider scorecard to record evidence consistently.
Evidence ledger
Sources used on this page
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: IANA's maintained time-zone data as the source for calculating actual buyer and delivery-team overlap instead of relying on static state or country labels. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Hire and manage employees — U.S. Small Business Administration. Supports: SBA guidance on the responsibilities involved in direct employment, supporting a clear distinction between hiring employees and buying contractor, agency, or managed delivery services. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: February 15, 2027. Corrections: hello@outsourcing.ai.
