When you hand China payroll to a provider, the work moves and the responsibility doesn’t. Under China’s Personal Information Protection Law, your company almost always remains the party accountable for employee payroll data — the provider acts on your instructions, and you carry a legal duty to supervise what it does. Nearly everything else in this guide follows from that single fact.
This is written for whoever is negotiating the service agreement, or answering an internal question about whether the current arrangement holds up. If you’re still deciding whether to outsource payroll at all, start with the overview of payroll outsourcing in China instead.
Before the detail, the shape of it. The obligations arrive at four distinct moments, and they’re easier to hold onto in that order than as a list of article numbers.

Is Payroll Data “Sensitive” Personal Information?
Yes, in ordinary circumstances. PIPL Article 28 defines sensitive personal information as data that, if leaked or misused, could readily harm someone’s dignity, personal safety or property — and the list it gives expressly includes financial accounts and specific identity. A routine payroll run handles employee bank account details and national ID numbers. Both are named categories.
This matters because the sensitive classification isn’t a label, it’s a switch. Article 28 permits processing sensitive data only where there is a specific purpose, demonstrated necessity, and strict protective measures in place. Article 30 requires telling employees not just that you process their data but why the sensitive processing is necessary and what effect it has on them. And Article 55 makes a documented impact assessment mandatory rather than advisable.
Most companies treat payroll files as ordinary confidential HR material. The statute treats them as a regulated category with its own rules. That gap is where most of the exposure sits.
Your Legal Basis Isn’t Consent — and the Condition Most Companies Miss
If your instinct is that you need employee consent to run payroll, that’s a reasonable assumption from a GDPR background, and it’s the wrong one here. PIPL Article 13(2) permits processing personal information where it is necessary for human resources management, without consent. Payroll plainly qualifies — you cannot employ someone and not pay them.
This is also more than a technicality. Consent under PIPL can be withdrawn (Article 15). A payroll basis that depends on consent is a payroll basis an employee can revoke, which is an unworkable position for an employer. The HR-management basis exists precisely to avoid that.
But it is conditional, and this is the part that gets skipped. Article 13(2) permits HR-management processing carried out “in accordance with the labor rules and regulations established in accordance with the law and the collective contracts signed in accordance with the law.” The exemption rests on those internal labor rules existing and having been properly adopted. China’s Labor Contract Law sets procedural requirements for how such rules are made and publicised — they are not simply whatever the employee handbook happens to say.
Worth checking before anything else on this page. If your China internal labor rules were never formally adopted through the required procedure, the basis you are relying on to process payroll data without consent may not be as solid as assumed. It’s an unglamorous document to go and verify, and it turns out to be load-bearing twice over — see the cross-border section below.
Entrusting Versus Providing: The Distinction That Decides Everything
PIPL treats “someone else processes this data for me” and “I give this data to someone else” as two different things, with different requirements. Getting the classification wrong pulls in obligations that don’t apply, or misses ones that do.
The dividing line is Article 73(1): a personal information processor is whoever autonomously determines the purposes and means of processing. If your provider follows your instructions, you are still the processor and they are an entrusted party under Article 21. If they decide for themselves what to do with the data and why, you are providing data to a separate processor under Article 23 — which expressly requires separate consent from each employee.


| Entrustment (Art 21) | Provision (Art 23) | |
|---|---|---|
| Who decides why and how | You do; the provider follows instructions | The recipient does, independently |
| Separate employee consent | Not stated in Article 21 | Expressly required |
| What you must do | Agree six specified contract terms; supervise their processing | Give notice of the recipient’s identity, purposes, means and data categories; obtain consent |
| Typical payroll case | A vendor running payroll for your own China entity | Less common in pure payroll; arises where a counterparty uses the data for its own purposes |
You will occasionally see it asserted that outsourcing payroll requires employee consent under Article 23. That reads across from the wrong mechanism. A vendor calculating payroll to your specification, on your data, to your timetable, is not determining its own purposes and means — which is what Article 23 is addressing. The classification turns on the facts of the arrangement rather than what the contract is titled, so it’s worth confirming rather than assuming in either direction.
Where an EOR is genuinely different
One case deserves separating out, because buyers file it under the same heading. If you use an Employer of Record, the EOR is the legal employer. It isn’t processing employee data purely on your instruction — it processes as an employer, for its own employment purposes, with its own statutory obligations to those employees. That is a materially different data-protection posture from a vendor administering payroll for an entity you own, even though both get described commercially as “outsourced payroll.” If you’re weighing the two models, the data question is one more axis on which they aren’t interchangeable.
What PIPL Requires Your Service Agreement to Contain
Article 21 doesn’t suggest these terms. It requires them. If your current payroll agreement is silent on any of the first four, it is incomplete as a matter of law, not just of practice.
Required by Article 21
1. Purpose, period and method of processing. Why the provider handles the data, for how long, and how.
2. Categories of personal information. Which data fields are in scope — salary, bank details, ID numbers, tax profile.
3. Protection measures. The safeguards applied, not a general assurance of security.
4. Rights and obligations of both parties. Explicitly allocated, not implied.
5. No sub-contracting without your consent. Directly relevant — providers sometimes use downstream agents for city-level filings.
6. Return or deletion when the contract ends. The provider may not simply retain the data afterwards.
Two duties sit alongside the contract itself. Article 21 obliges you to supervise the provider’s processing — an active duty, so a signed agreement filed away and never revisited doesn’t discharge it. And Article 59 requires the entrusted party to take security measures and to assist you in meeting your own obligations, which is useful leverage: a provider declining to help you satisfy an obligation is declining something the statute already asks of it.
The Assessment You’re Supposed to Do Before Signing
Article 55 requires a documented personal information protection impact assessment in advance, in several circumstances. Outsourcing payroll triggers it on two independent grounds at once: processing sensitive personal information, and entrusting processing to another party. If data also goes offshore, that’s a third.
Article 56 sets out what it has to cover — whether the purposes and means are lawful, justified and necessary; the impact on employees and the security risks; and whether the protective measures are proportionate to those risks. The report and processing record must be kept for at least three years.
The operative word is before. This is meant to inform the decision to appoint a provider, not to be reconstructed afterwards if someone asks. It is among the most commonly skipped obligations in the whole framework, and among the easiest to evidence once done.
Sending Payroll Data to Your Overseas Parent
If headquarters outside China receives payroll reports containing employee-level data — or if group HR can log into a system and see it — that is a cross-border transfer, whatever it’s called internally.
The baseline in PIPL Chapter III is demanding. Article 38 requires one of three routes: a security assessment organised by the national cyberspace department, personal information protection certification, or a standard contract with the overseas recipient. Article 39 separately requires informing employees about the overseas recipient and obtaining separate consent.
The CAC’s March 2024 provisions relaxed this substantially for employers. Article 5(2) exempts transfers where it is genuinely necessary to send employee data abroad to carry out cross-border human resources management — again, in accordance with lawfully formulated labor rules and collective contracts.
The nuance that summaries tend to flatten. The exemption is from the three mechanisms — security assessment, standard contract, certification. It is not a general exemption from PIPL. Article 10 of the same provisions states that data handlers providing personal information overseas must still perform obligations including giving notice, obtaining individual consent, and conducting an impact assessment, in accordance with law. The heavy administrative machinery drops away; the underlying duties do not automatically drop with it.


Notice also what the exemption is conditioned on: lawfully formulated labor rules, the same precondition as the domestic HR-management basis. That is worth pausing on, because it means one document is doing double duty. Properly adopted internal labor rules underpin both your ability to process payroll data domestically without consent and your route to sending it to a parent company without the heavier cross-border process. Few HR documents earn their keep twice over like that, and it’s an unusually cheap thing to get right relative to what rests on it.
Security, Retention, and Switching Providers
Security measures. Article 51 lists what is expected: internal management systems and operating procedures, classified handling of personal information, technical measures including encryption and de-identification, defined access permissions with regular staff training, and incident contingency plans. This doubles as a practical yardstick when assessing whether a provider’s security posture is real or asserted.
Breach. Article 57 requires immediate remedial action and notification to both the authorities and affected individuals, covering what was affected, the likely harm, what you’ve done, and what employees can do. There is a narrow carve-out where measures effectively prevent harm — but the regulator retains authority to require individual notice anyway. Worth knowing who makes that call in your organisation before you need to.
Retention, and the obvious tension. Article 19 limits storage to the minimum period necessary, and Article 47 requires deletion once the purpose is achieved. Payroll records, meanwhile, must be kept for tax and labor purposes. Article 47 resolves this directly: where a statutory retention period hasn’t expired, you stop processing the data for other purposes and confine yourself to storing it securely.
Switching providers. This is where the framework becomes concrete. Article 21 requires the entrusted party to return or delete the data when the contract ends — it may not simply keep the file. In practice that means the offboarding sequence should be written into the agreement at signature rather than negotiated during a transition: what is returned, in what format, what is deleted, on what timetable, and what evidence of deletion you receive.
What Getting It Wrong Costs
Article 66 sets two tiers. At the first, authorities order correction and may issue warnings and confiscate unlawful gains; refusing to correct brings a fine of up to RMB 1 million, plus RMB 10,000–100,000 on the individuals directly responsible. Where circumstances are serious, the ceiling rises to RMB 50 million or 5% of the previous year’s turnover, with possible suspension of business or revocation of permits, personal fines of RMB 100,000–1 million, and potential bars on serving as a director, supervisor or senior manager.
Two features make this sharper than a headline number. Article 69 reverses the burden of proof: where processing infringes personal information rights, the processor bears liability unless it can prove it was not at fault — which makes documentation, including that impact assessment, the thing standing between you and a presumption against you. And Article 67 provides for violations to be entered in credit records.
The Question Nobody Can Answer for You Yet
There is a genuine tension on the face of the statute, and any source that resolves it confidently is telling you more than the text supports.
Article 29 requires separate consent to process sensitive personal information — and payroll data is sensitive personal information. But Article 13’s closing paragraph states that where consent is required elsewhere in the law, that requirement does not apply in the circumstances listed at subparagraphs (2) through (7) — and human resources management is subparagraph (2).
Read one way, the HR-management basis displaces the separate-consent requirement, and payroll needs no consent at all. Read the other way, Article 29 is a specific safeguard for sensitive data that survives the general carve-out. The same ambiguity carries into whether Article 39’s separate-consent requirement for cross-border transfers is displaced for HR data. Practitioner views differ, and the drafting does not settle it.
What turns on it is not academic — it is the difference between a compliant payroll arrangement and one exposed to the penalties above. The practical response is to take China-qualified advice on your specific setup, and to be wary of any provider or article that presents a confident answer without acknowledging the question exists.
What to Ask Your Payroll Provider
Everything above, converted into questions you can put to a provider or use to review an existing arrangement.
| Ask | What a good answer sounds like | Red flag |
|---|---|---|
| Are you an entrusted party or a processor in your own right? | A clear answer, and a reason grounded in who determines purposes and means | The distinction is unfamiliar to them |
| Does our agreement carry all six Article 21 terms? | They can point to each one in the document | A general confidentiality clause offered as equivalent |
| Do you sub-contract any part of processing? | A direct yes or no, and if yes, who and where — with your consent sought | Vagueness about downstream agents or local filing partners |
| How is payroll data encrypted, and who can access it? | Named controls and defined access roles | Spreadsheets over email; “our systems are secure” |
| What happens to our data if we leave? | A defined return-and-delete process with a timetable and evidence | Never been asked; no documented process |
| Will you support our impact assessment? | Yes, with the detail you need to complete it | Treated as your problem alone — Article 59 says otherwise |
| If data reaches our overseas parent, how is that handled? | They know the 2024 exemption and its limits | Cross-border treated as a non-issue |
How NNRoad Handles Payroll Data
NNRoad runs payroll in China for companies with a local entity, and provides the employment structure through Employer of Record for companies without one. Because those two models sit differently under the framework above, the data questions worth asking differ too — and either way, the answers should be specific rather than reassuring.
Want to know how your payroll data is actually handled?
Send us the questions from the table above — the ones your current provider hasn’t answered clearly. We’ll tell you how we’d answer them for your setup, and where your arrangement needs a lawyer rather than a vendor.
Ask NNRoad about China payroll data handling →
FAQ
Do we need employee consent to outsource payroll in China?
Generally not, because payroll rests on the human-resources basis rather than consent, and a payroll vendor is normally an entrusted party rather than a separate recipient. Both points come with conditions — and one related question about sensitive data remains genuinely unsettled.
Does the analysis change if we use an EOR instead of a payroll vendor?
Yes. An EOR is the legal employer and processes employee data for its own employment purposes, rather than purely on your instruction — a different position from a vendor administering payroll for an entity you own.
What happens to our payroll data when we switch providers?
The outgoing provider must return or delete it rather than retain it. Agree the format, timetable and evidence of deletion when you sign, not when you leave.
Is the impact assessment genuinely mandatory, or best practice?
Mandatory, and payroll outsourcing triggers it twice over. It must be done in advance and the record kept for at least three years — which also matters because liability for infringement is presumed unless you can show you were not at fault.
Can we store China payroll data on servers outside China?
Sending it abroad is a cross-border transfer subject to Chapter III, though the 2024 provisions exempt genuine cross-border HR management from the security assessment, standard contract and certification routes. The underlying notice and assessment duties still apply, so this needs deliberate handling rather than an assumption.
News
Berita Teknologi
Berita Olahraga
Sports news
sports
Motivation
football prediction
technology
Berita Technologi
Berita Terkini
Tempat Wisata
News Flash
Football
Gaming
Game News
Gamers
Jasa Artikel
Jasa Backlink
Agen234
Agen234
Agen234
Resep
Cek Ongkir Cargo
Download Film