This section captures essential employee information, destination country specifics, and travel timeline to establish the foundation for compliance assessment. Accurate completion is critical for downstream risk evaluation.
Employee Full Legal Name (as appears on passport)
Employee ID Number
Official Job Title
Primary Department/Division
Direct Manager Name
Manager's Email Address
Home Country (Primary Employment Jurisdiction)
Destination Country (Remote Work Location)
Specific City/Region in Destination Country
Proposed Start Date of Remote Work Assignment
Proposed End Date of Remote Work Assignment (must not exceed 90 days)
Total Number of Business Days Requested
Will this remote work period be continuous, or will it involve multiple trips?
Please provide detailed itinerary with specific dates for each segment of travel and work periods
Physical Work Address in Destination Country (if known)
Will employee be working from a fixed location (e.g., leased office, home) or multiple locations?
Describe the nature of fixed location and any contractual arrangement (e.g., lease agreement, home ownership)
List all anticipated work locations and frequency of movement between them
Primary Business Justification for Overseas Remote Work Request
Has employee completed any previous short-term overseas remote work assignments (under 90 days) in the past 24 months?
List each assignment: country, dates, duration, and approval reference number
Emergency Contact Information (Name, Relationship, Phone, Email, Time Zone)
Employee's Preferred Contact Phone Number During Assignment
This section evaluates whether the employee's activities could create a Permanent Establishment (PE) in the destination country, triggering corporate tax obligations. PE risk is the most critical tax consideration for cross-border remote work. A PE could expose the company to corporate income tax, reporting requirements, and regulatory scrutiny.
Key PE risk factors include: fixed place of business, dependent agent authority, habitually concluding contracts, and revenue generation activities. Please answer each question carefully as 'yes' responses may require detailed follow-up and could trigger mandatory consultation with Corporate Tax Counsel.
Will employee have authority to conclude contracts on behalf of the company while in the destination country?
Describe the types of contracts, typical value range, and frequency. Explain why this authority is necessary during the overseas period.
Will employee be engaging in revenue-generating sales activities or business development with clients/customers located in the destination country?
Rate the intensity and nature of revenue-generating activities
None | Minimal | Moderate | Significant | Extensive | |
|---|---|---|---|---|---|
Direct sales negotiations with local clients | |||||
Maintaining stock of goods/samples in the country | |||||
Providing after-sales service to local customers | |||||
Conducting marketing campaigns targeting local market | |||||
Establishing local business relationships |
Will employee be working from a location that is formally leased, rented, or owned by the company in the destination country?
Provide lease agreement details: address, lease term, cost, and whether the space is available to other employees or exclusive to this employee
Will employee be the company's primary representative or point of contact in the destination country?
Explain the nature of representation and whether employee will be the 'face' of the company to local authorities, clients, or partners
Does the company currently have any employees, agents, or subsidiaries in the destination country?
Describe existing presence: number of employees, entity type, and nature of operations. This could aggregate PE risk.
What percentage of the employee's total annual work time will be spent in the destination country during this assignment?
Less than 10%
10-25%
26-50%
51-75%
More than 75%
WARNING: Spending more than 50% of work time in a single foreign jurisdiction significantly increases PE risk and may require establishment of a formal entity.
CRITICAL: Spending more than 75% of work time in a foreign jurisdiction creates substantial PE risk. This request will require mandatory Corporate Tax Counsel review and may be denied or require entity establishment.
Which categories of company data and systems will the employee access from the destination country? (Select all that apply)
Customer/client database
Financial records and accounting systems
Intellectual property and R&D materials
Employee personal data
Strategic planning and confidential documents
General email and communication tools only
Will employee be accessing customer data of residents of the destination country?
Could the IP-related work contribute to creating intangible property rights in the destination country?
Will employee receive compensation specifically tied to work performed in the destination country (e.g., location-based stipend, foreign service premium)?
Specify monthly amount and currency
Describe the employee's primary job functions during the overseas period and how they differ from home country responsibilities (if at all)
Overall Assessment: Based on the information provided, rate the likelihood that this arrangement could create a Permanent Establishment in the destination country
Very Low Risk
Low Risk
Moderate Risk
High Risk
Very High Risk
Additional Notes or Mitigating Factors for Corporate Tax Consideration
This section assesses immigration and local labor law compliance. Working remotely from a foreign country may violate tourist visa conditions or require specific work authorization. Additionally, local labor laws may inadvertently apply, creating obligations for both employee and employer.
CRITICAL: Most tourist visas explicitly prohibit employment, including remote work for a foreign employer. Business visas typically allow meetings but not substantive work. Digital nomad visas or specific remote work visas may be required. Violation can result in deportation, fines, and future entry bans.
What is the employee's citizenship status?
Citizen of home country only
Dual/Multiple citizenship (includes destination country)
Citizen of third country (neither home nor destination)
Does the employee hold valid passport/citizenship documentation for the destination country?
Does the destination country offer a specific 'digital nomad visa' or 'remote work visa' for foreign employees?
Has the employee applied for or obtained such a visa?
Not yet applied
Application in process
Visa approved/obtained
Not eligible/Will not apply
Planned application date
Application submission date
Visa validity start date
Explain why employee is not eligible or choosing not to apply
Under what immigration status will employee enter the destination country?
Tourist visa (or visa waiver)
Business visa
Existing residency permit
Other visa type
WARNING: Working on a tourist visa, even remotely for a foreign employer, violates immigration law in most jurisdictions. This request may be denied or require employee to obtain proper work authorization.
Does the business visa explicitly permit remote work for a foreign employer?
Will employee be subject to local labor law protections and regulations in the destination country?
Which aspects of local labor law may apply? (Select all that apply)
Maximum working hours and overtime rules
Mandatory rest periods and vacation entitlements
Anti-discrimination and harassment protections
Termination notice periods and severance pay
Health and safety regulations
Collective bargaining agreement obligations
Mandated employee benefits (e.g., healthcare, pension)
Maximum weekly hours permitted under local law
Will company agree to be bound by local termination protections?
Will employee remain covered under home country social security system, or will destination country social security contributions be required?
Which social security regime will apply?
Home country social security (via certificate of coverage)
Destination country social security (mandatory registration)
Both home and destination (dual coverage)
Uncertain - requires further analysis
Will employee require local health insurance coverage in the destination country?
How will health insurance be provided?
International private medical insurance (existing)
Local private health insurance (new policy)
Government/public health scheme (if eligible)
Travel insurance only
Combination of above
Will employee be registered with any local tax authorities for personal income tax purposes?
Describe tax registration requirements and timeline
Will employee be bringing family members (dependents) on this assignment?
List dependents, their relationship, and whether they will require dependent visas or have work authorization needs
Visa and Immigration Documentation Checklist
Document Type | Status (Required/Obtained/Exempt) | Expiry Date | Upload Document | Notes | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Passport (valid 6+ months) | Required | 6/30/2026 | Must be valid for entire duration | ||
2 | Visa/Entry Permit | Required | 6/30/2025 | Appropriate work authorization | ||
3 | Residence Permit (if applicable) | TBD | May be required for stays >30 days | |||
4 | Certificate of Coverage (Social Security) | TBD | To avoid dual contributions | |||
5 | ||||||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Has employee been screened against destination country sanctions, watchlists, and entry restriction databases?
Additional Immigration or Labor Law Considerations
This section evaluates compliance with data protection regulations and IT security requirements. Accessing company systems and data from overseas introduces cross-border transfer implications, potential GDPR applicability, and increased cybersecurity risks. Non-compliance can result in fines up to 4% of global revenue and mandatory breach notifications.
What categories of personal data will the employee process or access while in the destination country? (Select all that apply)
Customer personal data (names, contact details)
Customer financial data (payment info, credit cards)
Employee personal data (HR records, payroll)
Sensitive personal data (health info, biometric data)
Corporate confidential data (non-personal)
No personal data access - internal systems only
Other regulated data (specify in notes)
Will customer data include residents of the destination country?
Is explicit consent obtained for processing sensitive data in the destination jurisdiction?
Does the destination country have data localization laws requiring certain data to be stored domestically?
Specify which data types are affected and proposed compliance approach
Which legal mechanism will be used for cross-border data transfers to the destination country?
Adequacy Decision (destination country recognized as adequate)
Standard Contractual Clauses (SCCs)
Binding Corporate Rules (BCRs)
Explicit Consent of data subjects
Legitimate Interests Assessment
Not applicable - no personal data transferred
Mechanism not yet determined - requires legal review
Have SCCs been executed with any local entities (e.g., coworking space, local vendors)?
Even if no personal data is accessed, IT security protocols must still be followed. Continue with security verification below.
Data transfer mechanism must be determined before approval. This will require Data Privacy Officer consultation.
Will employee use a company-issued secure laptop/device, or personal device (BYOD)?
What BYOD security controls will be implemented?
Mobile Device Management (MDM) enrollment
Containerization of corporate data
Mandatory encryption
Remote wipe capability
Prohibited - BYOD not allowed for overseas access
Will employee use public Wi-Fi networks (e.g., cafes, coworking spaces, hotels)?
What VPN and encryption measures will be used?
Corporate VPN (always-on)
Split tunneling VPN
Zero Trust Network Access (ZTNA)
Encrypted DNS
No public Wi-Fi allowed - only secure networks
Will employee have physical security measures for devices and documents (e.g., lockable storage, privacy screens)?
Describe physical security protocols at the overseas location
Could employee's activities trigger application of GDPR or similar comprehensive data protection law?
Which GDPR obligations will be fulfilled?
Data Processing Impact Assessment (DPIA)
Appointment of EU/UK Representative (if threshold met)
Record of Processing Activities (ROPA) updated
Data Subject Rights procedure established
Breach notification procedure to EU/UK authority
All of the above
Will any personal data be transferred FROM the destination country TO other jurisdictions (including home country)?
Describe data flows and ensure appropriate transfer mechanisms are in place for each destination
Will employee handle any data subject access requests, privacy complaints, or regulatory inquiries while overseas?
Explain protocol for handling such requests and escalation path to Data Protection Officer
Will employee's location have access to any production databases, source code repositories, or critical infrastructure systems?
What additional privileged access controls will be implemented?
Just-in-Time (JIT) access provisioning
Multi-factor authentication (MFA) mandatory
Privileged Access Management (PAM) system
Session recording and monitoring
No privileged access allowed from overseas location
Has a Data Privacy Impact Assessment (DPIA) been completed for this overseas remote work arrangement?
Upload completed DPIA document
A DPIA may be required before approval can be granted, especially if processing high-risk data or operating in high-risk jurisdictions. Consult Data Privacy Officer.
IT Security Risk Assessment: Rate the adequacy of controls for each risk area (1=Inadequate, 5=Fully Mitigated)
Network security and VPN usage | |
Endpoint protection and anti-malware | |
Data encryption (at rest and in transit) | |
Physical device security | |
Incident detection and response capability | |
Employee security awareness training |
Will employee have access to IT support during destination country business hours?
Describe IT support contingency plan for technical issues or security incidents
Additional Data Privacy and IT Security Considerations
This final section consolidates risk assessments and obtains required approvals. All previous sections must be completed before sign-off. Approvals are conditional on accuracy of information provided. Material changes to circumstances may void approval and require resubmission.
RISK SUMMARY: The following flags have been identified based on previous responses. Each must be addressed before final approval.
Compliance Risk Summary and Mitigation Actions
Risk Category | Risk Level | Description of Risk | Mitigation Actions Required | Mitigation Confirmed | ||
|---|---|---|---|---|---|---|
A | B | C | D | E | ||
1 | Permanent Establishment | TBD | Based on Section 2 assessment | To be determined by Tax Counsel | ||
2 | Immigration Compliance | TBD | Based on Section 3 assessment | To be determined by Global Mobility | ||
3 | Data Privacy | TBD | Based on Section 4 assessment | To be determined by DPO | ||
4 | Labor Law | TBD | Based on Section 3 assessment | To be determined by HR Legal | ||
5 | IT Security | TBD | Based on Section 4 assessment | To be determined by CISO | ||
6 | ||||||
7 | ||||||
8 | ||||||
9 | ||||||
10 |
Has employee received and acknowledged the 'Overseas Remote Work Policy and Risks' disclosure document?
Upload signed acknowledgment form
Has employee completed mandatory 'International Remote Work Compliance Training'?
Training completion date
Final Approval Recommendation by Global Mobility Lead
Approve - Low Risk
Approve with Conditions - Moderate Risk
Defer - High Risk (requires mitigation)
Reject - Prohibitive Risk
Escalate to Executive Leadership
List all conditions that must be met before or during assignment
Specify required mitigation actions and timeline for resubmission
Provide detailed justification for rejection
Explain circumstances requiring executive escalation
Does Corporate Tax Counsel approve the PE risk assessment and accept potential tax exposure?
Specify any tax reporting obligations or profit allocation methodology
Specify required changes to eliminate or mitigate PE risk
Does Data Privacy Officer confirm adequate data protection safeguards are in place?
Specify required data protection measures before approval
Does HR Legal confirm compliance with applicable labor and employment laws?
Specify required employment law compliance actions
Does IT Security confirm adequate cybersecurity controls are implemented?
Specify required IT security enhancements
Global Mobility Lead Full Name
Global Mobility Lead Approval Date & Time
Global Mobility Lead Digital Signature
Corporate Tax Counsel Full Name
Corporate Tax Counsel Approval Date & Time
Corporate Tax Counsel Digital Signature
Is this approval subject to periodic review during the assignment period?
Review frequency in days
Post-Approval Conditions and Employee Obligations
Final Approval Reference Number
To configure an element, select it on the form.