matteocontrini no, it doesn't. That's correct. What it DOES enforce is governance and controls over that third party entity as your data is being processed by someone else. By inference, that third party becomes both custodian and controller whilst they are processing that data and you need to have and be able to prove controls are in place.
By not sending the data to any third party, you negate that requirement and will instantly be compliant for this sense.