Wyoming buyer guide

Outsourcing software development from Wyoming

A Wyoming guide to international software and AI outsourcing: government-data purpose, contractor transfer, retention, resident requests, breach evidence, pilot, and exit.

For: Wyoming founders, product and engineering leaders, government entities, public-sector contractors, privacy and security teams, counsel, procurement leaders, and buyers evaluating software, automation, analytics, support, or AI delivery outside the United StatesBy Outsourcing.ai Editorial Team
The decisionA Wyoming buyer should classify private commercial work separately from work performed for a Wyoming government entity; connect every government-data field to a documented lawful purpose and policy; permit contractor processing only within the contracted government service; preserve resident access and objection evidence; give retention, public-records, incident, release, and exception decisions to named buyer owners; and require verifiable return or destruction when the data is no longer necessary or the service ends.Evidence references: [1][2][3][4][5][6][7][8][9][10]
Four abstract data streams narrowing through a purpose gate into a manifest capsule, crossing a buyer-controlled hub and bounded supplier network before separating into return, preserved-record, verified-destruction, resident-request, and urgent-incident paths
Wyoming government-data work needs a purpose-to-field gate before contractor transfer, buyer-controlled rights and incident loops during delivery, and a verified return-or-destruction decision reconciled with records retention and public-records preservation at exit. Original Outsourcing.ai editorial illustration, generated with AI and reviewed for relevance and accuracy.
No local-office claim. Outsourcing.ai is an online research and delivery platform. This guide is for Wyoming buyers; it does not represent a Wyoming office, Wyoming staff, completed Wyoming client work, State contractor status, procurement eligibility, regulator approval, certification, or legal, privacy, public-records, cybersecurity, employment, tax, export, sanctions, digital-asset, or intellectual-property advice.
Direct answerA Wyoming organization can use software and AI contributors outside the United States, but government-related work now needs a particularly explicit data path. Wyoming's 2026 Data Privacy in Government Entities Act permits a government entity to transfer personal data to a nongovernment contractor providing or assisting with the government service when the contract protects the data consistently with the Act. The contractor may maintain, sell, transfer, process, or otherwise use that data only as necessary for the contracted service and must return or destroy it when it is no longer necessary. Resident access and objection workflows, a purpose-specific inventory, policy-backed retention, public-records handling, and staggered compliance dates must remain buyer-controlled. Ordinary private work and commercial breach duties use separate perimeters. Start with classification, not a country shortlist.

Wyoming outsourcing at a glance

Proposed workFirst buyer decisionEvidence required before access
Ordinary private software, automation, support, analytics, or AIProve why the work remains outside an activated government-data, public-records, customer-contract, sector, export, or other restricted laneWork package, contracting entity, named people and locations, code and data boundary, synthetic-data plan, permissions, acceptance, release owner, recovery, and exit
Service for a Wyoming government entityIdentify the government entity, contracted government service, governing solicitation and contract, exact data, current policy, applicable compliance date, and accountable officialsClause matrix, purpose record, policy map, field inventory, contractor and subprocessor graph, approved systems and locations, access plan, resident-request interface, retention rule, incident route, and exit test
Transfer of government personal data to a contractorProve that the recipient is contracted to provide or assist with the government service and that every use is necessary to that serviceSigned data-protection terms, purpose-to-field trace, instructions, least privilege, approved operations, onward-transfer restriction, monitoring, return-or-destruction trigger, and buyer approval
Product or system holding current or former resident dataPreserve access, correction, restriction, deletion, dissemination, disagreement-statement, and written-decision capabilities without giving the supplier legal authorityIdentity-verification interface, authoritative source map, complete search procedure, exception escalation, 60-day objection clock, audit log, response package, and regression test
Data retained beyond three years under the future policy requirementIdentify the written policy, extended period, reasonable justification, records schedule, system limitation, and disposal ownerRecord series, trigger, legal hold or schedule, policy citation, approved duration, copy and backup map, exception, review date, and disposition proof
Public-records request touching a supplier-hosted systemRoute the request to the responsible government custodian; do not let the supplier infer that privacy language makes the record exempt or that openness makes every field publicPreservation notice, search plan, export, metadata, chain of custody, custodian decision, redaction instruction, production record, and access reset
Suspected compromise of Wyoming personal identifying informationSeparate the commercial owner-or-licensee and maintainer roles from any activated State incident policy and contract clocksDiscovery and determination times, affected systems and people, acquisition facts, misuse analysis, encryption and key facts, preservation, containment, resident-notice decision, communications, and recovery
AI, analytics, search, or support using government dataProve the allowed purpose, input fields, retrieval sources, prompts, outputs, logs, training status, human authority, retention, and deletion before enabling the toolModel and service register, data-flow trace, prompt and output controls, no-training evidence where required, evaluation set, human-review gate, monitoring, rollback, rights search, and exit export

These are classification prompts, not legal conclusions. The 2026 Act excludes the judicial branch and Wyoming law-enforcement agencies from its definition of government entity, contains conflict-of-laws provisions, treats HIPAA and FERPA transfers expressly, and phases part of the policy requirement by entity type. An exclusion from this Act does not prove that a system is unrestricted. The solicitation, executed contract, public-records law, records schedule, sector rules, federal requirements, current State standards, and actual facts may create a different boundary.

The distinct Wyoming model: purpose–transfer–return ledger

The hard outsourcing question is not simply whether a server or developer sits abroad. It is whether a specific government entity may disclose a specific field to a specific contractor for a specific government service, what the contractor may do with it, how a resident request reaches every relevant copy, how long the record must remain, and how its return or destruction will be proved.

Use a purpose–transfer–return ledger with nine connected records:

  1. Entity and authority card: contracting entity, government-entity status, exclusions, service owner, data owner, records custodian, privacy official, security official, procurement owner, legal owner, and approval limits.
  2. Service-purpose charter: government function, contracted service, desired outcome, users, legal and policy basis, prohibited secondary uses, success criteria, end condition, and change owner.
  3. Field necessity map: each personal-data field, source, person, purpose, necessity rationale, transformations, outputs, recipients, copies, and a synthetic or deidentified alternative decision.
  4. Transfer manifest: sender, recipient entity, named delivery people and cities, employer, system, environment, cloud region, subprocessor, data class, transfer mechanism, date, and authorizer.
  5. Instruction and access envelope: allowed actions, denied actions, repositories, jobs, tools, identities, time window, approval boundary, logging, suspension, and emergency stop.
  6. Resident-rights trace: authoritative sources, searchable copies, identity handoff, access export, objection workflow, correction or restriction propagation, deletion decision, disagreement statement, written response, and 60-day clock.
  7. Retention and public-records crosswalk: record series, policy, schedule, default or extended period, legal hold, request preservation, custodian decision, production format, redaction path, and disposition trigger.
  8. Incident and recovery packet: detection, preservation, facts, maintainer and owner roles, contractual and policy clocks, misuse analysis, notification authority, containment, trusted restore, reconciliation, and after-action evidence.
  9. Return-or-destruction certificate: service end or necessity-ending trigger, buyer-accepted export, format and integrity, access revocation, primary and downstream deletion, backup treatment, exception, verification, sign-off, and residual risk.

The ledger prevents a common failure: a broad contract says “protect confidential information,” while tickets, analytics events, support tools, AI prompts, backups, and subprocessors silently create uses that nobody traced to the contracted service. It also prevents an opposite failure: deleting a record merely because the supplier engagement ended when an applicable records schedule, public-records preservation duty, legal hold, or written justified retention policy requires the government entity to keep it. The buyer owns the reconciliation.

Separate private commercial work from government work

A Wyoming mailing address, LLC registration, government customer, or provider marketing label does not determine the operating perimeter. Build the perimeter from the actual entity, service, contract, data, and system.

Classify each work package into one or more lanes:

  • Ordinary private delivery: code and content that do not use protected customer, employee, regulated, government, or production data. The buyer still controls intellectual property, secrets, access, security, acceptance, and exit.
  • Private personal-information custody: a commercial entity owns or licenses Wyoming resident information, or a supplier maintains it. The Title 40 security-breach roles and evidence path may apply if an incident occurs.
  • Government service without personal data: the contract, security standards, public-records handling, source-code custody, accessibility, procurement, and delivery-location terms can still apply even when the Act’s personal-data path is not activated.
  • Government service with personal data: the government entity’s transfer authority, contractor protection terms, necessity restriction, return or destruction, rights support, retention, policy, and records handling need an executable trace.
  • Excluded or separately governed government context: judicial, law-enforcement, HIPAA, FERPA, federal tax, criminal-history, payment-card, export-controlled, or other data may have a different rule set. An Act exclusion is a routing instruction, not a permission slip.

Create a one-page classification decision with supporting evidence and review triggers. Reopen it when the purpose, field list, audience, entity, contract, data source, model, supplier, location, subprocessor, integration, or retention period changes. If classification is unresolved, keep the overseas team in an isolated environment using public, synthetic, or buyer-approved nonpersonal test data.

Read the 2026 Act as a set of operational interfaces

The enacted law creates W.S. 9-21-201 through 9-21-203. It defines personal data broadly as information linked or reasonably linkable to an identified or identifiable natural person or personal digital identity and excludes deidentified data. It defines government entity broadly across State and local government, but excludes the judicial branch and Wyoming law-enforcement agencies.

The useful outsourcing interfaces are concrete:

  • Government entities generally may not purchase, sell, trade, or transfer personal data without the person’s express written consent unless a stated exception applies.
  • One exception permits transfer to a nongovernment entity contracted to provide or assist with government services.
  • The services contract must require protection of personal data consistently with the Act.
  • The contractor must return or destroy transferred data once it is no longer necessary for the government service.
  • The contractor may not maintain, sell, transfer, process, or otherwise use the data except as necessary to provide that service.
  • A current or former Wyoming resident or authorized representative may request a copy from the government entity maintaining the data.
  • A resident may object to accuracy, completeness, pertinence, timeliness, relevance, retention, dissemination, or denial of access. The government entity has 60 days to review, act when meritorious or retain the resident’s statement when not, and provide a written decision.
  • The law preserves other State or federal law when it conflicts and does not override Wyoming Public Records Act disclosure.
  • The policy provision requires collection and retention to be reasonably necessary for lawful functions and tied to a specific purpose identified in adopted policies.
  • Under that future policy provision, retention beyond three years needs a written policy identifying the extended period and reasonable justification; statutory records-retention requirements are recognized as a reasonable justification.

Translate each interface into a named system capability and owner. A contractual promise without search, propagation, audit, export, expiry, and deletion mechanisms will fail when a real request or exit reaches the system.

Use the staggered dates without postponing architecture

The law does not create one uniform “2027 deadline.” The enacted schedule distinguishes provisions and entity types. Sections 1, 3, 4, and 5 became effective when the bill became law. The collection-and-retention policy section, W.S. 9-21-203, is effective for State agencies on July 1, 2027; for counties, cities, public institutions of higher education, and towns on July 1, 2028; and for other political subdivisions on July 1, 2029. The chief information officer, in consultation with the State Archivist, was directed to develop sample policies by January 1, 2027.

Do not convert that sequence into “vendors can wait.” The transfer restriction, contractor service limitation, contract protection, resident paths, and return-or-destruction design need current attention. Future policy adoption also depends on present inventories. A system commissioned today may still be operating through every compliance date.

Maintain a transition board:

Transition fieldEvidence
Entity typeFormation or enabling source, government relationship, exclusion analysis, accountable official
Applicable sections nowSource version, effective-date analysis, legal approval
W.S. 9-21-203 dateState agency, city/county/town/higher education, other political subdivision, or not applicable
Existing policyCurrent data policy, gaps, owner, approval status
State sample-policy comparisonAdopted, adapted, not used, reason, legal and records review
System limitationMissing capability, interim manual control, risk owner, delivery date
Supplier remediationContract amendment, field reduction, rights integration, logging, retention, export, deletion
ValidationTest case, expected outcome, evidence, defect, retest, approver

Treat the official ETS material as an implementation baseline, not as proof that a particular entity adopted every sample unchanged. Ask for the entity’s approved policy and the executed contract that actually governs the work.

Make purpose and necessity executable

“Improve services” is not a usable purpose boundary. It does not tell a developer whether a support transcript may train a model, whether precise location belongs in an analytics event, whether a resident identifier may enter an error-monitoring service, or whether a subcontractor may keep prompts to improve its product.

Write a service-purpose charter at operation level:

  1. The lawful government function and the exact contracted service.
  2. The decision or output the operation supports.
  3. The people affected and authoritative source systems.
  4. Every input field and why it is reasonably necessary.
  5. Every output, inference, score, summary, embedding, log, and cached copy.
  6. Allowed actions such as view, validate, transform, calculate, support, correct, export, or delete.
  7. Prohibited actions such as advertising, unrelated analytics, provider model training, cross-customer benchmarking, sale, or disclosure.
  8. Approved recipients, people, locations, systems, tools, subprocessors, and integrations.
  9. Retention and service-end triggers.
  10. Buyer owners for scope change, release, public-records response, resident decisions, incidents, and exit.

Then enforce it. Use separate service identities, field-level views, allowlisted repositories, short-lived credentials, environment boundaries, data-loss controls, log review, and technical blocks on unapproved exports. Make a purpose change a buyer-approved change request before code or data moves.

An international provider may use employees, independent contributors, cloud hosts, code forges, observability tools, ticket systems, AI assistants, translation services, support desks, and other processors. The primary supplier’s headquarters does not reveal that chain.

Require a live delivery and data manifest containing:

  • legal name and role of every organization;
  • named contributor or controlled role, employer, city, and country;
  • service performed and government-service necessity;
  • systems, repositories, environments, data fields, metadata, logs, and backups reached;
  • cloud and support regions rather than only the vendor’s billing address;
  • subcontractor approval and change procedure;
  • confidentiality, training, screening, access, device, and remote-work controls;
  • onward-transfer and separate-use prohibitions;
  • incident escalation and evidence-preservation duties;
  • resident-request search and action support;
  • public-records preservation, export, and custodian-instruction support;
  • return, deletion, backup expiry, verification, and dispute handling; and
  • buyer audit, suspension, transition assistance, and survival rights.

A certification or questionnaire can support diligence, but it does not identify the actual data path. Map assurance evidence to the service, system, locations, dates, exceptions, and remediation. If a provider will not disclose where the work and data go, do not place government personal data in that service.

Preserve resident access and objection as a controlled workflow

The government entity maintains the legal relationship with the resident. A supplier may search, export, correct, restrict, or delete data under documented instruction, but it should not decide identity sufficiency, legal exceptions, objection merit, public-records consequences, retention overrides, or the final written response.

Build a rights trace with these stages:

  1. Intake: request ID, entity, channel, resident or representative, receipt time, requested action, and scope.
  2. Verification: buyer-approved method, minimum additional data, failed-attempt handling, authorized representative evidence, and security escalation.
  3. System search: authoritative sources, supplier systems, logs, archives, AI stores, vector indexes, backups, subprocessors, and manual files.
  4. Evidence return: structured results, provenance, confidence, exceptions flagged rather than decided, and a completeness attestation.
  5. Buyer decision: access, correction, restriction, dissemination change, deletion, denial, or another action; public-records and retention review; legal approval.
  6. Propagation: instruction to every affected copy and downstream recipient, with immutable event evidence.
  7. Disagreement statement: when an objection lacks merit, preserve the resident’s statement with the relevant record in the manner the government entity directs.
  8. Written closure: outcome, date, decision owner, delivery evidence, unresolved limitations, appeal or contact information supplied by the entity, and quality review.

Test the workflow before launch with at least six cases: current resident, former resident, authorized representative, identity mismatch, corrected field propagated across a subprocessor, and a disputed record that must retain the resident’s statement. Include a data set large enough to expose pagination and identifier-matching failures.

Reconcile three-year retention, records schedules, public records, and exit

Retention is not one countdown. The future W.S. 9-21-203 rule creates a three-year default unless a written policy identifies a longer period and reasonable justification. State archival requirements and schedules may justify longer retention. A public-records request or legal hold can suspend routine disposition. The contractor-transfer provision separately requires return or destruction when personal data is no longer necessary for the government service.

Create a copy-level retention crosswalk:

CopyRecord series and purposeTrigger and periodAuthorityExit treatment
Government system of recordOfficial function and resident recordApproved schedule or written policyGovernment records ownerRetain or transfer under buyer custody
Supplier production storeContracted processingOnly while necessary for the service and within approved policyContract and buyer instructionExport, reconcile, then delete
Support ticketDiagnose a named incident or requestNarrow ticket rule, not indefinite conveniencePolicy and service scheduleRedact, transfer, or delete as instructed
Application and access logsSecurity, audit, or operationsDefined rolling period or justified extensionSecurity and records policyExport needed evidence; validate expiry
BackupRecovery of approved recordsBackup lifecycle and hold behaviorRecovery policyPrevent restoration into active use; expire and attest
AI prompt, output, embedding, or evaluation setApproved operation onlyExplicit purpose and periodService charter and policySearch, export, delete, and test residual retrieval
Subprocessor copyNecessary contracted taskNo longer than the approved upstream needFlow-down contractDownstream certificate and verification

Do not instruct a supplier to “delete everything” without the government’s records and public-records owners. Do not accept “backups cannot be deleted” without documenting architecture, isolation from ordinary use, expiry, restoration controls, and the buyer’s decision. At exit, reconcile what the government must retain with what the contractor may no longer keep.

Keep public-records decisions with the government custodian

The Act states that it does not abrogate disclosure under the Wyoming Public Records Act. That means privacy and openness cannot be collapsed into a provider rule. A record may contain releasable material, exempt material, security-sensitive details, personal data, and metadata requiring a government decision.

Require the supplier to support—not own—the process:

  • preserve potentially responsive material when instructed;
  • search all approved systems and downstream services;
  • retain original formats, timestamps, relationships, and audit metadata;
  • export in a reviewable, reproducible format;
  • identify search limitations and inaccessible stores;
  • keep the review set separated and access-controlled;
  • apply redactions or productions only under government instruction;
  • preserve the instruction and transformation history; and
  • revoke temporary review access after closure.

Test an export during the pilot. A contractual promise to cooperate is weak if the provider cannot reconstruct threaded messages, linked attachments, AI inputs and outputs, version history, or audit events without a costly custom project.

Design an urgent incident lane separately

The government policy, contract, sector, and Title 40 commercial breach paths can have different scopes and clocks. Do not wait to classify the incident perfectly before preserving evidence and safely containing it.

Give every supplier a tested urgent path containing:

  1. 24-hour buyer contacts and verified backups.
  2. A broad contractual signal threshold that can precede a legal breach determination.
  3. Safe containment authority and explicit actions requiring buyer approval.
  4. Preservation of source logs, images, affected identities, commands, alerts, tickets, communications, and custody history.
  5. Discovery time, determination time, suspected start and end, system, data, people, locations, and subprocessors.
  6. Facts about unauthorized access and acquisition, misuse likelihood, encryption and key exposure, and affected Wyoming residents without premature conclusions.
  7. Separate routing to the government incident owner, privacy owner, records custodian, counsel, communications owner, insurer, and law enforcement when authorized.
  8. Trusted restore, credential rotation, integrity validation, reopened-work reconciliation, and monitored return to service.

For the general commercial lane, W.S. 40-12-502 requires an owner or licensee to investigate promptly and in good faith when it becomes aware of a system breach and to notify affected Wyoming residents if misuse occurred or is reasonably likely. A person maintaining data for another business must disclose a qualifying breach to that business as soon as practicable after the determination described in the statute. The maintainer and business may allocate notice, with a direct-relationship fallback if they cannot agree. Do not treat that allocation as permission for the provider to publish notice or contact residents without buyer authorization.

Control AI and analytics as data operations

An AI assistant is not “just a developer tool” when it receives government personal data, source code, tickets, documents, screenshots, logs, or credentials. Map the full operation:

  • provider and model version;
  • hosting, support, logging, and inference locations;
  • prompts, attachments, retrieval stores, embeddings, outputs, feedback, moderation records, and telemetry;
  • training, improvement, human-review, and retention settings;
  • tenant isolation and administrator access;
  • permitted purpose and field necessity;
  • hallucination, extraction, injection, access-control, memorization, and bias tests;
  • human review and decision authority;
  • resident search, correction, restriction, export, and deletion behavior;
  • public-records export and metadata;
  • incident evidence and shutdown path; and
  • model, provider, and contract exit.

Begin with public or synthetic inputs. For a retrieval system, enforce access at query and document level rather than assuming the model will respect a prompt. For automated summaries or recommendations, retain source citations and give the accountable government owner the final decision. For coding assistants, prevent secrets and production records from entering unapproved services. A provider’s “zero retention” label needs contract, configuration, technical, and test evidence tied to the actual account.

Compare destinations only after the boundary is known

No country is universally best for a Wyoming buyer. A nearshore team may offer more live overlap; an offshore team may provide a useful follow-the-sun window; a specialist market may offer deeper experience. None compensates for an unidentified employer, undisclosed subprocessor, weak export capability, or uncontrolled government data.

Compare the proposed team—not a country stereotype—on:

  • legal contracting entity and contributor engagement;
  • every work and data location;
  • current sanctions, export, customer, procurement, and sector restrictions;
  • destination privacy, surveillance, secrecy, employment, and intellectual-property questions reviewed by qualified owners;
  • required transfer or contract mechanisms;
  • English and domain communication demonstrated in a work sample;
  • exact city-to-city overlap calculated for dated seasons using maintained time-zone identifiers;
  • security, device, workplace, access, and incident controls;
  • government-data purpose and rights capabilities;
  • subprocessor and cloud dependencies;
  • continuity across power, network, staffing, and geopolitical disruption;
  • complete cost, including buyer management, assurance, travel, tooling, transition, and risk; and
  • return, deletion, evidence export, knowledge transfer, and replacement readiness.

Use the nearshore versus offshore guide to frame overlap and handoffs, then examine country-specific pages such as Colombia, Mexico, India, and Poland. Revalidate material legal and operational facts before award.

Calculate overlap from cities, dates, and decision needs

Wyoming buyers normally plan on Mountain time, but a durable operating model still uses a named city and an IANA zone rather than a fixed UTC offset. Contributor cities may change clocks on different dates or not at all.

Build a dated overlap table for representative winter, transition, and summer weeks. Separate:

  • collaboration overlap for pairing and discovery;
  • buyer-decision windows for scope, security, release, and incident authority;
  • asynchronous build periods;
  • handoff deadlines and evidence fields;
  • emergency contacts and backup owners; and
  • access expiry at the end of an approved session.

Do not optimize for the largest possible overlap. Optimize for sustainable work and reliable decisions. A two-hour window with prepared questions, clear authority, and evidence-complete handoffs can outperform eight hours of constant interruption.

Normalize complete cost before comparing bids

The lowest hourly rate is not the lowest delivery cost. Compare a defined work package using one complete-cost model:

Complete cost = supplier fees + buyer management + security and privacy controls + tooling and cloud + travel + rework + delay exposure + transition and exit cost.

Request the same assumptions from every provider:

  • role, level, allocation, and named team;
  • included management, design, QA, DevOps, security, and documentation;
  • work locations, holidays, working hours, and backup coverage;
  • currency, taxes, payment fees, rate review, and termination charges;
  • third-party tools, model usage, cloud, observability, and licenses;
  • government-data controls, assurance, resident-request support, and records exports;
  • incident, recovery, and after-hours coverage;
  • knowledge transfer, repository transfer, data return, deletion, and transition assistance; and
  • buyer-side owners and hours required.

Run base, delay, incident, and replacement scenarios. If one bid excludes the work needed to make the service controllable, add that work before comparing totals.

Run a paid purpose-to-exit pilot

Do not validate the model with a disposable design exercise. Choose a real but bounded work package that can begin without unrestricted production access. Four to six weeks is usually enough to test the system when scope is narrow.

Week 0: classify and contract

  • Confirm entity, contract, government-service purpose, Act perimeter, policy, data, records, security, and other restrictions.
  • Record every contributor, location, system, subprocessor, and tool.
  • Execute the service schedule, data-protection terms, purpose boundary, incident route, rights support, public-records support, return or deletion, and exit terms.
  • Establish buyer owners and decision windows.

Week 1: map and minimize

  • Build the field necessity map and copy inventory.
  • Replace real data with synthetic, masked, tokenized, or buyer-hosted alternatives where possible.
  • Configure identities, access expiry, logs, repositories, secrets, environments, and data-loss controls.
  • Baseline quality, security, performance, accessibility, and cost.

Weeks 2–3: deliver a vertical slice

  • Deliver a small end-to-end outcome with code, tests, decisions, provenance, and operations notes.
  • Review purpose adherence, scope change, data movement, tool use, handoff quality, defect escape, and forecast accuracy.
  • Exercise one buyer-decision handoff and one rejected unauthorized action.

Week 4: exercise rights, records, and incident paths

  • Run a former-resident objection through search, correction or restriction, downstream propagation, written-decision evidence, and the 60-day timer.
  • Preserve and export a mock public-records set with attachments, metadata, version history, and documented search limits.
  • Inject a suspected supplier incident, preserve evidence, suspend access, route facts, restore trusted service, and reconcile work.

Weeks 5–6: test return, destruction, and continuity

  • Export code, documentation, configurations, decision history, records, and approved data in buyer-controlled formats.
  • Revoke one contributor and one service identity.
  • Validate primary-store deletion, downstream instructions, backup expiry treatment, and residual search or retrieval.
  • Have a buyer or replacement engineer operate the delivered slice from the handover.

Score the pilot on accepted outcomes, evidence completeness, purpose adherence, request accuracy, public-records export, incident latency, recovery, sustainable overlap, complete cost, and exit independence. Expand only if the evidence supports expansion.

Minimum evidence before production access

  • Contracting entity and actual government or private context are confirmed.
  • The exact solicitation, contract, policy, records schedule, and current source versions are indexed.
  • Applicable dates and exclusions are approved by accountable buyer owners.
  • The government-service purpose and every necessary field are documented.
  • Every contributor, city, employer, system, cloud region, tool, and subprocessor is disclosed.
  • Contractor uses are technically and contractually limited to the approved service.
  • Rights search, objection, correction, restriction, deletion, disagreement statement, and written closure are tested.
  • Retention, public-records preservation, legal holds, backups, and disposal are reconciled.
  • The urgent incident route is tested with preserved evidence and trusted recovery.
  • AI and analytics inputs, outputs, training, logs, human authority, and exit are explicit.
  • The buyer controls repositories, secrets, releases, notifications, exceptions, and production authority.
  • Complete cost and destination-specific diligence are documented.
  • Return, deletion, revocation, evidence export, and replacement operation pass before scale.

If a material item is missing, narrow the work package, remove the data, isolate the environment, or pause production access. Do not compensate with a broad warranty or a provider logo.

Frequently asked questions

Can a Wyoming government entity use an overseas software team?

Potentially, but geography is only one part of the decision. The government entity must confirm its authority, procurement and contract terms, security standards, data classification, records duties, sector and federal requirements, and the exact service. For personal data covered by the 2026 Act, the contractor-transfer route is tied to providing or assisting with the government service, contractual protection consistent with the Act, use only as necessary for that service, and return or destruction when no longer necessary. An accountable government owner and counsel should decide the specific case.

Does the Act apply to every Wyoming business?

No. It is a government-entity statute, and its definition and exclusions matter. Private businesses still need to address contracts, security, commercial breach rules, regulated data, intellectual property, export and sanctions questions, and any federal or sector obligations. A private supplier performing a government service may receive contract duties and operational restrictions through that relationship.

Is all government data personal data?

No. The Act’s personal-data definition and deidentified-data exclusion require fact-specific classification. Code, public records, confidential business material, security information, and nonpersonal government records can still be restricted by contract, policy, law, or operational risk. Conversely, removing a name may not deidentify information that remains reasonably linkable to a person or personal digital identity.

The Act generally restricts government-entity purchase, sale, trade, or transfer without express written consent, then states exceptions. One permits transfer to a nongovernment contractor providing or assisting with government services under the required protections and limitations. The government entity—not the supplier—should classify and approve the transfer and document the exact exception or consent path.

What happens when a resident objects to data?

The government entity maintains the decision. The enacted text provides a 60-day response path for reviewing the objection, taking appropriate action when meritorious, permitting a statement reflecting the resident’s view when not, and notifying the resident in writing. The supplier needs search and action capabilities, but should act only on documented government instruction.

Must every record be deleted after three years?

No. The future policy provision says a government entity may not maintain personal data beyond three years without a written policy identifying the extended period and reasonable justification, and it recognizes statutory retention requirements as a reasonable justification. Records schedules, holds, public-records duties, and other law matter. Separately, contractor-held data must be returned or destroyed when no longer necessary for the government service. Reconcile these paths copy by copy.

Does privacy law override public-records law?

The enacted Act expressly says it does not abrogate disclosure under the Wyoming Public Records Act. The responsible government custodian should decide search, preservation, exemption, redaction, and production. The supplier supplies complete, reproducible evidence under instruction.

Can a provider use government data to improve its AI model?

Do not assume so. The contractor’s use under the Act is limited to what is necessary to provide the contracted government service, and the actual contract and policy may be more specific. Record training and improvement settings, human review, retention, subprocessors, and locations. Disable separate use unless the accountable government entity has a documented lawful and contractual basis.

Is a provider certification enough?

No. It may support assurance, but it does not prove purpose limitation, field necessity, correct locations, rights propagation, public-records export, retention, incident handling, or exit for the actual service. Map the report’s scope and exceptions to the live architecture and test the missing controls.

Should a Wyoming buyer choose nearshore or offshore delivery?

Choose after classifying the work. Nearshore delivery may simplify live collaboration; offshore delivery may create a useful overnight build window or deeper specialist pool. Compare named teams using dated overlap, capability, data path, controls, continuity, complete cost, evidence, and exit—not geography alone.

Who should control releases, notices, and exceptions?

Named Wyoming buyer or government owners. Suppliers may prepare evidence and execute approved technical actions. They should not silently expand purpose, approve a public-records response, decide an objection, grant a statutory exception, notify residents, accept residual risk, or release to production without delegated and recorded authority.

What is the best first outsourced project?

A bounded vertical slice with measurable value, synthetic or minimized data, a buyer-owned repository, clear acceptance, and a real handover. Include a rights exercise, records export, incident drill, access revocation, and return-or-destruction test so the pilot validates the operating system rather than only coding speed.

Next step

Use the project brief generator to define the outcome, then add the government-service purpose, entity and Act classification, field necessity map, contract and policy sources, resident-request path, records schedule, supplier and location manifest, incident route, return-or-destruction test, complete-cost assumptions, and named buyer authorities. Score proposed teams with the provider scorecard and require a paid purpose-to-exit pilot before production expansion.

Evidence ledger

Sources used on this page

  1. Data Privacy in Government Entities Act — Enrolled Act No. 32, Senate — Wyoming Legislature. Supports: Final enacted text creating W.S. 9-21-201 through 9-21-203, including government-entity scope, contractor transfers, purpose limitation, return or destruction, resident access and objection, retention, exclusions, and staggered effective dates. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  2. Wyo. Stat. 9-21-101 — Data policies — Wyoming Enterprise Technology Services. Supports: Existing executive-branch agency data-policy requirements for inventory, access, safeguards, compliance, incident response, destruction, and communication. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  3. Wyoming data privacy policies and standards — Wyoming Enterprise Technology Services. Supports: Current official policy catalog for classification, data owners and custodians, protection, backup and restoration, breach handling, residency and transportation, exceptions, destruction, and data-sharing documentation. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  4. Wyoming security and privacy policies and standards — Wyoming Enterprise Technology Services. Supports: Current official policy catalog for access, authentication, communications, risk, incident response, acquisition, integrity, remote access, source control, and generative-AI use. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  5. Wyoming Statutes Title 40 — Wyoming Legislature. Supports: Current official compilation containing W.S. 40-12-501 and 40-12-502 definitions, commercial breach investigation, resident notice, maintainer-to-owner disclosure, notification allocation, and enforcement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  6. Wyoming Public Records — Wyoming Department of Administration and Information. Supports: Official public-records resources and operational routing, reinforcing that privacy handling and public-records decisions require the responsible government custodian. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  7. Records retention schedules — Wyoming State Archives. Supports: Official retention schedules for State agencies and local governments, which must be evaluated before applying a deletion or three-year default. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  8. Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for protected environments, software provenance, release integrity, vulnerability response, and buyer-supplier evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  9. IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between Wyoming buyer locations and proposed contributor cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  10. Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for investigating contributor and assignment questions instead of assuming a Wyoming contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.

Next scheduled review: September 30, 2026. Corrections: hello@outsourcing.ai.