Not really, the shell company is the owner of the data and is responsible for the security of it by contract, that's the whole point.
Seagate will not in a million years sign anything like this when you buy a HDD.
You can't just absolve yourself of responsibility by saying "I hired a contractor". You are still responsible for doing your due diligence in picking your contractor.
It's not that easy. Companies are required to do due diligence on stuff like this. If they know (or should have known) that they are outsourcing something to an incompetent provider, they could still be liable.
That’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too.