Can You Hire a Developer Abroad as a Contractor? The Tax Risk Nobody Mentions
Hiring a developer in another country on a contractor agreement looks like the simple option. It creates two liabilities most companies never price: permanent establishment and misclassification. Here is how each is triggered, and which of the four hiring structures avoids them.
Can You Just Hire a Developer in Another Country as a Contractor?
Legally, yes — nothing stops you from signing a contractor agreement with a developer in Poland, Serbia, Brazil or the Philippines and paying their invoices. The question is not whether you can, but what liabilities you accumulate while doing it, and those liabilities are invisible for exactly as long as nothing goes wrong.
The pattern is familiar to anyone who has scaled a distributed team. You find a strong engineer abroad. Your lawyer produces a contractor agreement. They invoice monthly, you pay, and for eighteen months this works perfectly. Then one of three things happens: the engineer is now effectively full-time on your product and asks about holiday pay; a tax authority sends a letter; or you go through diligence for a funding round or acquisition and someone asks how you have twelve people in four countries with no payroll registrations anywhere.
Two distinct risks sit underneath this, and they are commonly confused because both involve a foreign government wanting money. Permanent establishment is a corporate tax question: has your company created a taxable presence in that country? Misclassification is an employment law question: was this person actually your employee rather than a contractor? They are assessed by different authorities under different rules, and you can trigger either one without the other.
It is worth saying plainly that this article is orientation, not legal advice. The thresholds are jurisdiction-specific, tax treaties modify them bilaterally, and the analysis turns on facts about your specific arrangement. What follows should help you ask the right questions of someone qualified to answer them in the countries you actually operate in.
Key Takeaways
- Contractor agreements abroad are legal but accumulate two separate, invisible liabilities
- Permanent establishment is a corporate tax exposure; misclassification is an employment law exposure
- Either can be triggered independently of the other
- Exposure usually surfaces at diligence, at a worker dispute, or via a tax authority letter
What Is Permanent Establishment, and When Does a Remote Developer Create One?
Permanent establishment is the concept that lets a country tax a foreign company's profits when that company has a sufficient fixed presence there. You do not need an office or a registered subsidiary — a person can be enough.
The most useful available benchmark comes from Thomson Reuters' 2026 guidance on remote workers, which points to the OECD's 2025 Model Tax Convention update and flags someone working more than half their time from another country over a 12-month period as a significant indicator. Note carefully what that is and is not: it is an indicator, not a switch. The same guidance is explicit that there is no universal magic number of days that automatically triggers PE. What determines the outcome is the combination of permanence, business activity, authority, and employer dependence.
Beyond the fixed-place-of-business route, there is a second and often more dangerous path: the dependent agent rule. Under Article 5(5) of the OECD Model Tax Convention, a permanent establishment can arise where a person acting on behalf of an enterprise habitually concludes contracts, or habitually plays the principal role leading to contracts that are routinely concluded without material modification by the enterprise. In plain terms: if your person abroad is effectively closing deals for you, their authority can create a taxable presence even with no office anywhere.
This is why the risk profile of a remote engineer differs from that of a remote salesperson. A backend developer writing code is usually far from the dependent agent rule. A country manager negotiating customer contracts is close to its centre. If you are hiring purely engineering roles abroad, your PE exposure is generally lower than the alarmist version of this topic suggests — but it rises sharply the moment that person starts making commercial commitments, and it rises again if they are senior enough to be making binding business decisions from that location.
Key Takeaways
- PE lets a foreign country tax your company's profits without you having an office there
- OECD 2025 update flags >50% of working time from a country over 12 months as a key indicator
- No universal day count triggers PE automatically — permanence, activity, authority and dependence combine
- Dependent agent PE (Article 5(5)) makes deal-closing roles far riskier than pure engineering roles
What Actually Happens If You Trigger PE?
You inherit a compliance stack in a country where you have no infrastructure, and it applies retroactively to when the presence began — not from when you discovered it.
The Thomson Reuters guidance sets out how the exposure cascades: local payroll registration, wage tax withholding, social security contributions, statutory reporting, and employment law compliance. Each of those is an ongoing obligation with its own filing calendar, and none of them is something you can start doing next quarter without addressing the periods already elapsed.
The corporate tax consequence is the headline, but in practice the payroll and social security obligations are what generate the largest bills, because they accrue per person per month and typically carry interest and penalties for late payment. A two-year-old undeclared presence in a country with meaningful employer social contributions can produce a number that is materially larger than what the engineer was paid over the same period.
The practical damage is often not the assessment itself but the timing. These issues surface during acquisition diligence with striking reliability, because that is when someone finally reads every contract at once. Discovering an unquantified multi-country tax exposure during a transaction is a very expensive time to discover it — it moves from being a tax problem to being a valuation and indemnity problem, and the buyer will price it conservatively.
When Does a "Contractor" Legally Become an Employee?
When the substance of the relationship looks like employment, regardless of what the contract says. Essentially every jurisdiction applies a substance-over-form test, and your paperwork is evidence rather than a determination.
The factors that recur across jurisdictions are consistent enough to self-assess against. Does the person work set hours you determine? Do they use your equipment and systems? Do they have other clients, or are you effectively their only source of income? Can they subcontract the work or send a substitute? Do they carry any commercial risk, or are they paid regardless of outcome? Are they integrated into your team structure — attending your standups, in your management hierarchy, subject to your performance reviews?
Read that list against a typical long-term outstaffed developer and the problem becomes apparent. A person who works your business hours, uses your laptop, sits in your sprint ceremonies, reports to your engineering manager, has worked exclusively for you for two years, and cannot send a substitute, is describing an employee in most legal systems on earth. The contractor agreement is not doing the work people assume it does.
Consequences vary by country but reliably include back taxes and unpaid social contributions, penalties and interest, and exposure to employment claims the person could not otherwise have brought — unfair dismissal, holiday pay, notice periods, severance. In several European jurisdictions the liability sits with the engaging company rather than the worker, which is the direction that matters for you. Enforcement in this area has been tightening rather than loosening, and technology is a frequently cited focus sector precisely because long-term "contractor" relationships are so common in it.
Key Takeaways
- Substance beats contract wording in essentially every jurisdiction
- Key factors: control over hours, equipment, exclusivity, right of substitution, commercial risk, team integration
- A long-term exclusive outstaffed developer often fails the test on most factors
- Liability typically falls on the engaging company, and includes back taxes plus employment claims
What Are Your Four Options, and What Does Each Actually Cost?
There are four structures, and the honest framing is that you are choosing where the employment relationship legally sits — with you, with an intermediary, or with a separate company entirely.
Direct contractor. Cheapest and fastest: you pay invoices, no intermediary margin. It carries both risks described above, and the exposure compounds with duration and exclusivity. Genuinely defensible for short engagements with people who have multiple clients and control their own working methods. Increasingly indefensible for someone who has been full-time on your team for two years.
Employer of Record. A third party legally employs the person in their country and seconds them to you. This resolves misclassification cleanly — there is a real employment relationship, with a real employer, meeting local requirements. Current market pricing runs roughly $400 to $770 per employee per month in platform fees, with Deel and Remote both at $599 on annual billing and Remote at $699 month-to-month, according to 2026 provider comparisons. Critically, that fee sits on top of gross salary, employer taxes, statutory benefits and social contributions — it is a service fee, not the cost of the employee. EOR reduces but does not automatically eliminate PE risk, since PE turns on what the person does and where, not only on who signs their payslip.
Your own local entity. Full control, lowest per-head cost at scale, and the largest fixed overhead: incorporation, local accounting, payroll infrastructure, HR capability, and ongoing filings. The Thomson Reuters guidance puts the crossover at roughly 15 to 20 employees per country as the point where entity economics start beating EOR. Below that, you are usually paying a lot of fixed cost to save a variable fee.
Contract with a vendor company for services. You engage a company to deliver work; that company employs its engineers under its own local law and carries the employment relationship, payroll and statutory obligations. This is the structure behind most agency and nearshore arrangements — including how we operate at StepTo, where our engineers in Belgrade are our own direct employees rather than contractors we resell, which is the specific detail that makes the structure hold. It is worth checking, because a vendor that is itself a thin layer over freelance contractors passes a version of the same problem back to you.
Does Using an Agency Remove the Risk Automatically?
No — it removes it only if the arrangement is genuinely a contract for services rather than a contract for people wearing a services label.
The distinction that matters is whether you are buying an outcome or directing a worker. If you contract a company to deliver defined work, and that company manages its own employees, sets their working arrangements, and carries responsibility for delivery, you are buying services and the employment relationship is clearly theirs. If you contract a company to supply you with a named individual whom you then manage directly — you set their hours, you assign their daily tasks, you run their performance review, and the vendor's only function is to invoice you — some jurisdictions will look past the corporate wrapper.
This matters for staff augmentation and outstaffing specifically, because those models sit closest to the line by design. The point of outstaffing is that the engineer integrates into your team and takes direction from you. That is the product. It is also precisely the fact pattern that misclassification tests are built to detect, which is why the corporate structure underneath needs to be real rather than nominal.
The practical diligence question to ask any vendor is simple and revealing: are the engineers you would assign to us your employees, or your subcontractors? A vendor employing its engineers directly carries genuine employer obligations and absorbs that risk. A vendor operating as a marketplace over independent freelancers has not eliminated the exposure — it has added a margin to it and moved it one step further from your visibility, which is worse than handling it yourself because you can no longer see it.
A second question worth asking: which entity signs your contract, and where is it established? An agreement with an EU-established company that employs EU-based engineers is a materially different risk object from one with an offshore holding company that subcontracts to individuals in a third country. Both may deliver good software. They are not the same thing on your supplier register, and if you are subject to third-party risk rules, only one of them is straightforward to declare.
Key Takeaways
- The test is whether you are buying an outcome or directing an individual worker
- Outstaffing sits closest to the line because integration into your team is the product
- Ask directly whether a vendor's engineers are employees or subcontractors
- A marketplace-over-freelancers vendor adds margin to the risk rather than removing it
When Is the Direct Contractor Route Actually Fine?
More often than the cautious version of this article implies. Treating every international contractor as a latent catastrophe leads companies to spend real money solving hypothetical problems, and that is its own kind of mistake.
The direct contractor structure is genuinely defensible when the relationship has the substance of independent contracting. A specialist you engage for a three-month piece of work, who has several other clients, who works from their own setup on their own schedule, who could subcontract the work, and who carries some delivery risk — that person is a contractor by any reasonable test, and wrapping them in an EOR is paying several thousand dollars a year for paperwork you did not need.
It is also usually fine at the very start. A founding team engaging two contractors abroad in year one, with the intention of formalising as the relationship stabilises, is making a reasonable trade. The error is not starting there; it is staying there for four years while the arrangement quietly becomes something else and nobody revisits it.
The useful discipline is a periodic re-test rather than a permanent posture. Once a year, run the substance factors against each long-term international contractor and see whether the answers have drifted. When someone crosses into working exclusively for you, on your schedule, inside your management structure, that is the signal to change the structure — not because anything bad has happened, but because that is the point at which the paperwork stopped describing reality.
One qualifier that overrides all of the above: if you are in a regulated sector, subject to third-party risk regimes, or on any path toward acquisition or institutional funding, formalise earlier than the risk analysis alone would suggest. The cost of clean structure is predictable and the cost of explaining an informal one under diligence is not.
What Should You Do Before Your Next International Hire?
Five steps, in order, none of which require a tax advisor to start.
First, list every person working for you outside your home country, with their country, start date, exclusivity, and whether they make commercial commitments on your behalf. Most companies have never assembled this in one place, and the list itself is usually the moment the picture becomes clear.
Second, flag anyone who has been exclusive to you for more than twelve months, and anyone in a role that involves negotiating or concluding contracts. Those are your two highest-risk categories — one for misclassification, one for dependent agent PE.
Third, for each country with more than one person or anyone above twelve months, get a short written opinion from local counsel. This is not a large engagement; you are asking a specific question about a specific fact pattern, and the answer is far cheaper than the exposure it addresses.
Fourth, choose structure by country rather than globally. A single contractor in one country and eight people in another do not need the same answer, and companies that pick one global model usually over-engineer the small countries and under-engineer the large one.
Fifth, whatever structure you land on, put a calendar reminder to re-run the substance test annually. This exposure is created by drift, not by decisions. Nobody chooses to misclassify an employee — they choose a reasonable contractor arrangement and then do not revisit it for three years while everything about it changes.
The Bottom Line
The reason this catches so many companies is that nothing about it feels like a decision at the time. You engage a good engineer abroad on a contract that your lawyer drafted, and every month afterwards you simply keep doing what you were already doing. The liability is generated by continuation rather than by any single choice, which is exactly why it goes unexamined until diligence or a dispute forces the issue. The practical answer is neither paranoia nor indifference: build the list, identify the two high-risk categories, get country-specific advice where the numbers justify it, and re-test annually because the facts drift even when the contract does not. And when you are weighing structures, be clear about which one you are actually buying — a contract for services with a company that genuinely employs its own engineers puts the employment relationship somewhere specific and accountable, which is a large part of why the nearshore vendor model persists in markets where the compliance questions are asked seriously. Whatever you choose, choose it deliberately, and choose it again next year.
Building a team in Eastern Europe?
StepTo helps European and US companies build senior-led nearshore engineering teams in Serbia. Let's talk about what your next engagement could look like.
Start a conversationWritten by
Igor GazivodaCo-founder & CEO · StepTo
Igor has 15+ years in software engineering and business development. Former CTO at a Series A fintech startup, he specializes in scaling engineering teams, nearshore strategy, and AI-driven product development. He holds a Master's in Computer Science from the University of Belgrade and has published on distributed systems architecture.
LinkedIn →