The bottom line is this: Although an organization may outsource some of its business processes, and with it part of its responsibility for privacy, the organization cannot outsource its accountability for privacy. In this article, we will pinpoint 10 critical questions management should ask about outsourcing and discuss specific privacy concerns associated with outsourcing. Finally, we will explore how outsourced personal data can be protected by implementing good privacy practices using the relevant criteria in the Generally Accepted Privacy Principles (GAPP) developed by the American Institute of CPAs and the Canadian Institute of CAs (AICPA/CPA Canada).