What Happens to Your Payroll Data When You Outsource It in China

When you hand China payroll to a provider, the work moves and the responsibility doesn’t. Under China’s Personal Information Protection Law, your company almost always remains the party accountable for employee payroll data. The provider acts on your instructions, and you carry a legal duty to supervise what it does. Nearly everything else in this guide follows from that single fact.

This is written for whoever is negotiating the service agreement, or answering an internal question about whether the current arrangement holds up. If you’re still deciding whether to outsource payroll at all, start with the overview of payroll outsourcing in China instead.

Reviewed 26 August 2026, against the Personal Information Protection Law and current Cyberspace Administration guidance, including the CAC’s data export Q&A of July 2026. Cross-border rules in China change without much notice. Check the source linked beside any claim before relying on it.

Short answers, if that’s all you need

Do we need employee consent to outsource payroll?
Usually not. Payroll runs on the human-resources basis rather than consent, and a payroll vendor is normally an entrusted party rather than a separate recipient. Both come with conditions worth checking.

Can payroll data go to our overseas parent?
Potentially, if the transfer is genuinely necessary for cross-border HR management and the statutory conditions are met. The exemption is narrower than it first appears.

What must the service agreement say?
Six specific terms, required by statute rather than recommended as best practice.

Who is liable if the provider leaks it?
You are, in the first instance, and fault is presumed unless you can prove otherwise. That’s the whole point of what follows.

Before the detail, the shape of it. The obligations arrive at four distinct moments, and they’re easier to hold onto in that order than as a list of article numbers.

Is Payroll Data “Sensitive” Personal Information?


Yes, in ordinary circumstances. PIPL Article 28 defines sensitive personal information as data that, if leaked or misused, could readily harm someone’s dignity, personal safety or property, and the list it gives expressly includes financial accounts and specific identity. A routine payroll run handles employee bank account details and national ID numbers. Both are named categories.

This matters because the sensitive classification isn’t a label, it’s a switch. Article 28 permits processing sensitive data only where there is a specific purpose, demonstrated necessity, and strict protective measures in place. Article 30 requires telling employees not just that you process their data but why the sensitive processing is necessary and what effect it has on them. And Article 55 makes a documented impact assessment mandatory rather than advisable.

Most companies treat payroll files as ordinary confidential HR material. The statute treats them as a regulated category with its own rules. That gap is where most of the exposure sits.


If your instinct is that you need employee consent to run payroll, that’s a reasonable assumption from a GDPR background, and it’s the wrong one here. PIPL Article 13(2) permits processing personal information where it is necessary for human resources management, without consent. Payroll plainly qualifies, since you cannot employ someone and not pay them.

This is also more than a technicality. Consent under PIPL can be withdrawn (Article 15). A payroll basis that depends on consent is a payroll basis an employee can revoke, which is an unworkable position for an employer. The HR-management basis exists precisely to avoid that.

But it is conditional, and this is the part that gets skipped. Article 13(2) permits HR-management processing carried out “in accordance with the labor rules and regulations established in accordance with the law and the collective contracts signed in accordance with the law.” The exemption rests on those internal labor rules existing and having been properly adopted. China’s Labor Contract Law sets procedural requirements for how such rules are made and publicised. They are not simply whatever the employee handbook happens to say.

Worth checking before anything else on this page. If your China internal labor rules were never formally adopted through the required procedure, the basis you are relying on to process payroll data without consent may not be as solid as assumed. It’s an unglamorous document to go and verify, and it turns out to be load-bearing twice over. See the cross-border section below.

Entrusting Versus Providing: The Distinction That Decides Everything


PIPL treats “someone else processes this data for me” and “I give this data to someone else” as two different things, with different requirements. Getting the classification wrong pulls in obligations that don’t apply, or misses ones that do.

The dividing line is Article 73(1): a personal information processor is whoever autonomously determines the purposes and means of processing. If your provider follows your instructions, you are still the processor and they are an entrusted party under Article 21. If they decide for themselves what to do with the data and why, you are providing data to a separate processor under Article 23, which expressly requires separate consent from each employee.

 Entrustment (Art 21)Provision (Art 23)
Who decides why and howYou do; the provider follows instructionsThe recipient does, independently
Separate employee consentNot stated in Article 21Expressly required
What you must doAgree six specified contract terms; supervise their processingGive notice of the recipient’s identity, purposes, means and data categories; obtain consent
Typical payroll caseA vendor running payroll for your own China entityLess common in pure payroll; arises where a counterparty uses the data for its own purposes

You will occasionally see it asserted that outsourcing payroll requires employee consent under Article 23. That reads across from the wrong mechanism. A vendor calculating payroll to your specification, on your data, to your timetable, is not determining its own purposes and means, which is what Article 23 is addressing. The classification turns on the facts of the arrangement rather than what the contract is titled, so it’s worth confirming rather than assuming in either direction.

Where an EOR is genuinely different

One case deserves separating out, because buyers file it under the same heading. If you use an Employer of Record, the EOR is the legal employer. It isn’t processing employee data purely on your instruction. It processes as an employer, for its own employment purposes, with its own statutory obligations to those employees. That is a materially different data-protection posture from a vendor administering payroll for an entity you own, even though both get described commercially as “outsourced payroll”. If you’re weighing the two models, the data question is one more axis on which they aren’t interchangeable.

What PIPL Requires Your Service Agreement to Contain


Article 21 doesn’t suggest these terms. It requires them. If your current payroll agreement is silent on any of the first four, it is incomplete as a matter of law, not just of practice.

  1. Purpose, period and method of processing. Why the provider handles the data, for how long, and how.
  2. Categories of personal information. Which data fields are in scope: salary, bank details, ID numbers, tax profile.
  3. Protection measures. The safeguards applied, not a general assurance of security.
  4. Rights and obligations of both parties. Explicitly allocated, not implied.
  5. No sub-contracting without your consent. Directly relevant, since providers sometimes use downstream agents for city-level filings.
  6. Return or deletion when the contract ends. The provider may not simply retain the data afterwards.

Two duties sit alongside the contract itself. Article 21 obliges you to supervise the provider’s processing, an active duty, so a signed agreement filed away and never revisited doesn’t discharge it. And Article 59 requires the entrusted party to take security measures and to assist you in meeting your own obligations, which is useful leverage: a provider declining to help you satisfy an obligation is declining something the statute already asks of it.

The Assessment You’re Supposed to Do Before Signing


Article 55 requires a documented personal information protection impact assessment in advance, in several circumstances. Outsourcing payroll triggers it on two independent grounds at once: processing sensitive personal information, and entrusting processing to another party. If data also goes offshore, that’s a third.

Article 56 sets out what it has to cover: whether the purposes and means are lawful, justified and necessary; the impact on employees and the security risks; and whether the protective measures are proportionate to those risks. The report and processing record must be kept for at least three years.

The operative word is before. This is meant to inform the decision to appoint a provider, not to be reconstructed afterwards if someone asks. It is among the most commonly skipped obligations in the whole framework, and among the easiest to evidence once done.

Sending Payroll Data to Your Overseas Parent


If headquarters outside China receives payroll reports containing employee-level data, or if group HR can log into a system and see it, that is a cross-border transfer, whatever it’s called internally.

The baseline in PIPL Chapter III is demanding. Article 38 requires one of three routes: a security assessment organised by the national cyberspace department, personal information protection certification, or a standard contract with the overseas recipient. Article 39 separately requires informing employees about the overseas recipient and obtaining separate consent.

The CAC’s March 2024 provisions relaxed this substantially for employers. Article 5(2) exempts transfers where it is genuinely necessary to send employee data abroad to carry out cross-border human resources management, again in accordance with lawfully formulated labor rules and collective contracts.

The nuance that summaries tend to flatten. The exemption is from the three mechanisms: security assessment, standard contract, certification. It is not a general exemption from PIPL. Article 10 of the same provisions states that data handlers providing personal information overseas must still perform obligations including giving notice, conducting an impact assessment, and complying with consent requirements where they apply. The heavy administrative machinery drops away; the underlying duties do not automatically drop with it.

Notice also what the exemption is conditioned on: lawfully formulated labor rules, the same precondition as the domestic HR-management basis. That is worth pausing on, because it means one document is doing double duty. Properly adopted internal labor rules underpin both your ability to process payroll data domestically without consent and your route to sending it to a parent company without the heavier cross-border process. Few HR documents earn their keep twice over like that, and it’s an unusually cheap thing to get right relative to what rests on it.

If the HR exemption doesn’t apply: the general thresholds

Where the transfer isn’t genuinely necessary for cross-border HR management, the volume thresholds in the March 2024 provisions decide which mechanism applies. These are the general positions for a data processor that is not a critical information infrastructure operator.

Annual export volumeGeneral mechanism
Fewer than 100,000 individuals, non-sensitiveGenerally exempt from all three mechanisms
100,000 to fewer than 1 million, non-sensitiveStandard contract or certification
Fewer than 10,000 individuals, sensitiveStandard contract or certification
At least 1 million, non-sensitiveCAC security assessment
At least 10,000 individuals, sensitiveCAC security assessment

Volumes are generally counted cumulatively from 1 January of the relevant year. The two rows in bold are the ones that matter here, because payroll data is sensitive personal information, as the first section of this guide sets out. A company with fewer than 10,000 China employees sits in the standard-contract or certification band; above that, a security assessment. Important-data rules, critical-information-infrastructure status and any applicable free-trade-zone negative list can all change the answer.

Sending candidate CVs to an overseas parent is a separate question

Recruitment data is not payroll data, and the CAC addressed it directly in its data export Q&A of July 2026. The answer is unusually clear-cut.

If the overseas headquarters or affiliate does not participate in the hiring decision for domestic applicants, sending their CVs abroad is not necessary, and the necessity test therefore fails. If the overseas entity does participate directly in that decision, the transfer can proceed, but the number of applicants sent must be the minimum needed for the overseas decision, the data fields must be the minimum scope needed, and the transfer must still use one of the three mechanisms, obtain separate consent, and be supported by an impact assessment.

Group HR dashboards that give an overseas team visibility of every China applicant, without that team making hiring decisions, are the arrangement this most directly calls into question.

Security, Retention, and Switching Providers


Security measures. Article 51 lists what is expected: internal management systems and operating procedures, classified handling of personal information, technical measures including encryption and de-identification, defined access permissions with regular staff training, and incident contingency plans. This doubles as a practical yardstick when assessing whether a provider’s security posture is real or asserted.

Breach. Article 57 requires immediate remedial action and notification to both the authorities and affected individuals, covering what was affected, the likely harm, what you’ve done, and what employees can do. There is a narrow carve-out where measures effectively prevent harm, but the regulator retains authority to require individual notice anyway. Worth knowing who makes that call in your organisation before you need to.

Retention, and the obvious tension. Article 19 limits storage to the minimum period necessary, and Article 47 requires deletion once the purpose is achieved. Payroll records, meanwhile, must be kept for tax and labor purposes. Article 47 resolves this directly: where a statutory retention period hasn’t expired, you stop processing the data for other purposes and confine yourself to storing it securely.

Switching providers. This is where the framework becomes concrete. Article 21 requires the entrusted party to return or delete the data when the contract ends. It may not simply keep the file. In practice that means the offboarding sequence should be written into the agreement at signature rather than negotiated during a transition: what is returned, in what format, what is deleted, on what timetable, and what evidence of deletion you receive.

What Getting It Wrong Costs


Article 66 sets two tiers. At the first, authorities order correction and may issue warnings and confiscate unlawful gains; refusing to correct brings a fine of up to RMB 1 million, plus RMB 10,000 to 100,000 on the individuals directly responsible. Where circumstances are serious, the ceiling rises to RMB 50 million or 5% of the previous year’s turnover, with possible suspension of business or revocation of permits, personal fines of RMB 100,000 to 1 million, and potential bars on serving as a director, supervisor or senior manager.

Those upper figures are the statutory ceiling for serious violations, not the automatic consequence of choosing the wrong transfer mechanism.

Two features make this sharper than a headline number. Article 69 reverses the burden of proof: where processing infringes personal information rights, the processor bears liability unless it can prove it was not at fault, which makes documentation, including that impact assessment, the thing standing between you and a presumption against you. And Article 67 provides for violations to be entered in credit records.

The Consent Question That Remains Unsettled


Part of this was resolved in July 2026. In its data export Q&A, the CAC confirmed that where a cross-border transfer falls within one of the non-consent grounds in PIPL Article 13(1)(2) to (7), including qualifying human resources management, individual consent is not required. The cross-border notice obligation still applies, along with the necessity, impact-assessment, minimisation and security duties.

The same guidance is worth reading for what it says about consent generally. Where separate consent is required, it must be specific and unbundled: it cannot be obtained through a blanket or package authorisation covering several processing activities at once. The CAC points to GB/T 42574-2023 for acceptable methods, naming written signature, pop-up confirmation and email or SMS reply.

A narrower question remains, and it concerns domestic processing rather than transfers. Article 29 requires separate consent to process sensitive personal information, and payroll data is sensitive personal information. Article 13’s closing paragraph states that where consent is required elsewhere in the law, that requirement does not apply in the circumstances listed at subparagraphs (2) through (7), and human resources management is subparagraph (2). Read one way, the HR basis displaces Article 29 entirely. Read the other, Article 29 is a specific safeguard for sensitive data that survives the general carve-out. Authoritative guidance has not addressed that interaction as squarely as it has the cross-border point.

What turns on it is not academic. The practical response is to put a specific question to China-qualified counsel rather than a general one: whether your particular payroll arrangement needs separate Article 29 consent for domestic processing given that you rely on the Article 13(2) basis, and what your internal labor rules need to say to support that position. That is answerable for a specific setup, even where the general question is not.

What to Ask Your Payroll Provider


Everything above, converted into questions you can put to a provider or use to review an existing arrangement.

AskWhat a good answer sounds likeRed flag
Are you an entrusted party or a processor in your own right?A clear answer, and a reason grounded in who determines purposes and meansThe distinction is unfamiliar to them
Does our agreement carry all six Article 21 terms?They can point to each one in the documentA general confidentiality clause offered as equivalent
Do you sub-contract any part of processing?A direct yes or no, and if yes, who and where, with your consent soughtVagueness about downstream agents or local filing partners
How is payroll data encrypted, and who can access it?Named controls and defined access rolesSpreadsheets over email; “our systems are secure”
What happens to our data if we leave?A defined return-and-delete process with a timetable and evidenceNever been asked; no documented process
Will you support our impact assessment?Yes, with the detail you need to complete itTreated as your problem alone, when Article 59 says otherwise
If data reaches our overseas parent, how is that handled?They know the 2024 exemption and its limitsCross-border treated as a non-issue

How NNRoad Handles Payroll Data


NNRoad runs payroll in China for companies with a local entity, and provides the employment structure through Employer of Record for companies without one. Because those two models sit differently under the framework above, the data questions worth asking differ too, and either way the answers should be specific rather than reassuring.

Want to know how your payroll data is actually handled?

Send us the questions from the table above, the ones your current provider hasn’t answered clearly. We’ll tell you how we’d answer them for your setup, and where your arrangement needs a lawyer rather than a vendor.

Ask NNRoad about China payroll data handling →

FAQ


Do we need employee consent to outsource payroll in China?

Generally not, because payroll rests on the human-resources basis rather than consent, and a payroll vendor is normally an entrusted party rather than a separate recipient. Both points come with conditions, and one related question about sensitive data in domestic processing remains genuinely unsettled.

Does the analysis change if we use an EOR instead of a payroll vendor?

Yes. An EOR is the legal employer and processes employee data for its own employment purposes, rather than purely on your instruction, which is a different position from a vendor administering payroll for an entity you own.

What happens to our payroll data when we switch providers?

The outgoing provider must return or delete it rather than retain it. Agree the format, timetable and evidence of deletion when you sign, not when you leave.

Is the impact assessment genuinely mandatory, or best practice?

Mandatory, and payroll outsourcing triggers it twice over. It must be done in advance and the record kept for at least three years, which also matters because liability for infringement is presumed unless you can show you were not at fault.

Can we store China payroll data on servers outside China?

Sending it abroad is a cross-border transfer subject to Chapter III, though the 2024 provisions exempt genuine cross-border HR management from the security assessment, standard contract and certification routes. The underlying notice and assessment duties still apply, so this needs deliberate handling rather than an assumption.

Can we send China candidate CVs to our overseas parent?

Only if the overseas entity directly participates in the hiring decision. The CAC confirmed in July 2026 that where the overseas headquarters or affiliate does not take part in the decision, exporting domestic applicants’ CVs is not necessary and the necessity test fails. Where it does take part, the transfer must be limited to the minimum applicants and data fields required, and still needs a compliant mechanism, separate consent and an impact assessment.