Can foreign companies transfer employee data from China to global HR systems?

Date:

Share post:






Can foreign companies transfer employee data from China to global HR systems?


Can foreign companies transfer employee data from China to global HR systems?

This is one of the most pressing compliance questions for multinational companies with operations in China. The short answer is: yes, foreign companies can transfer employee data from China to global HR systems, but only if they comply with China’s cross-border data transfer regulations under the Personal Information Protection Law (PIPL). Employee data transfers are subject to the same legal framework as any other cross-border personal information transfer, and companies must ensure they have a lawful basis and follow the prescribed transfer mechanism.

1. Why employee data transfers from China are uniquely challenging

Employee data transfers present unique compliance challenges compared to customer or business partner data transfers:

  • Inherently sensitive data: Employee data almost always includes categories that qualify as sensitive personal information under Chinese law — salary information, health data (medical insurance claims, fitness program participation), performance evaluations, disciplinary records, and biometric data (fingerprint scans for attendance, facial recognition for access control).
  • Large cumulative volumes: While an individual subsidiary may have only a few hundred employees, a multinational company with thousands of employees across China may exceed the transfer volume thresholds requiring a full CAC Security Assessment.
  • Essential business necessity: Global HR systems are critical infrastructure for multinational companies. Disruption to these transfers can affect payroll, benefits administration, performance management, talent acquisition, and compliance with global reporting obligations.
  • Data subject rights: Employees have rights under the PIPL to access, correct, delete, and restrict processing of their data. These rights must be honored even when data resides in a global HR system.
  • Consent concerns: The employment context raises questions about whether employee consent is freely given, given the inherent power imbalance between employer and employee. Chinese regulators recognize this concern and expect companies to rely on alternative legal bases where possible.

2. Legal bases for employee data transfers

Under the PIPL, cross-border transfers of employee personal information require both a lawful basis for processing and a compliant transfer mechanism. The primary lawful bases available to employers include:

2.1. Necessity for human resource management (Article 13(2))

The PIPL allows processing of personal information where it is necessary for the conclusion or performance of a contract to which the data subject is a party, or for implementing human resource management in accordance with the employer’s rules and collective contracts. This provision specifically acknowledges that employee data processing is inherent to the employment relationship. However, this basis applies to the processing of employee data, not necessarily to the cross-border transfer of that data — the transfer mechanism requirements are separate.

2.2. Consent (Article 13(1))

Employee consent remains a potential basis, but its validity in the employment context is questionable. The PIPL requires consent to be “informed and voluntary,” and regulators have expressed skepticism about the voluntariness of consent given by employees. Best practice is to:

  • Obtain separate, specific consent for cross-border transfers (not bundled with the employment contract)
  • Provide clear information about what data is transferred, to whom, for what purpose, and for how long
  • Ensure that refusal of consent does not result in adverse employment consequences
  • Document the consent process thoroughly

2.3. Necessity for the conclusion or performance of a contract (Article 13(2))

Where the cross-border transfer is necessary for the performance of the employment contract (e.g., paying salary through a global payroll system that processes data outside China), this basis may be available. Companies should document the direct necessity — for example, explaining why the payroll function cannot be performed within China alone.

3. Applicable cross-border transfer mechanisms for employee data

Once a lawful basis for processing is established, the company must use one of the following transfer mechanisms, depending on the volume and nature of employee data being transferred:

Transfer Mechanism Applicable When Key Requirements
CAC Security Assessment Transferring data of 1M+ employees annually, or sensitive data of 10K+ employees Full PIPIA, CAC approval, re-assessment every 2 years
Standard Contractual Clauses (SCCs) Below Security Assessment thresholds CAC filing, SCC agreement, PIPIA, ongoing compliance monitoring
Certification Company holds recognized data protection certification Certification by CAC-accredited body, annual audits
Data localisation exceptions Limited, specific cases defined by regulations Demonstrated necessity, CAC approval

4. Practical compliance steps for HR data transfers

Foreign companies transferring employee data from China to global HR systems should follow this implementation roadmap:

  1. Data mapping for HR data: Identify all categories of employee data currently transferred overseas. Include data transmitted through:
    • Global HRIS/HRMS platforms (Workday, SAP SuccessFactors, Oracle HCM)
    • Global payroll systems (ADP, cloud-based payroll platforms)
    • Benefits administration platforms (insurance, pension, stock options)
    • Performance management and talent management systems
    • Travel and expense management systems
    • Learning management systems (LMS)
    • Background check and verification services
  2. Assess transfer volumes: Count the number of current and former employees whose data is transferred, and identify which categories constitute sensitive personal information. This determines whether the Security Assessment or SCC pathway applies.
  3. Select the appropriate transfer mechanism: Based on the volume assessment, determine whether SCCs or a Security Assessment is required. Most companies with fewer than 1 million current/former employees in China can use the SCC pathway.
  4. Prepare the PIPIA: Conduct a Data Protection Impact Assessment specifically for the HR data transfers. The PIPIA should address:
    • The necessity and proportionality of each data transfer
    • The risks to employees’ rights and interests
    • The technical and organizational measures in place at the overseas recipient
    • The data protection framework of the receiving jurisdiction
    • Mitigation measures for identified risks
  5. Draft and execute SCCs: Use the CAC-mandated SCC template, customized with the specific HR data categories and processing purposes. Ensure the overseas recipient (typically the parent company or global HR system provider) signs the SCC.
  6. File with the CAC: Submit the SCC filing through the CAC’s online platform, attaching the PIPIA, the signed SCC, and supporting documentation.
  7. Implement transparency measures: Update employee privacy notices to clearly describe cross-border data transfers. Provide this information at the time of data collection (onboarding) and make it continuously accessible through internal HR portals.
  8. Establish data subject rights processes: Implement procedures for handling employee requests to access, correct, delete, or restrict transfer of their data. Ensure these procedures work across the global HR system architecture.
  9. Maintain ongoing compliance: Monitor changes in HR data processing activities, re-file SCCs when material changes occur, and conduct annual compliance reviews.

5. Special considerations for different HR data categories

Not all employee data is treated equally under Chinese law. Categories that require additional attention include:

Biometric data

Many companies use fingerprint scanning or facial recognition for attendance tracking. Biometric data is classified as sensitive personal information under the PIPL. If this data is transferred to global HR systems (e.g., for consolidated time tracking), the company faces heightened requirements for consent, PIPIA detail, and transfer restrictions. Consider implementing local-only biometric processing with aggregated (non-biometric) data transferred overseas.

Health data

Employee health insurance claims, medical examination results, and wellness program data are sensitive personal information. Many global HR systems include benefits administration modules that process this data. Companies should consider whether health data can be processed through China-local insurance platforms and only anonymized aggregate data transferred to global systems.

Performance evaluations and disciplinary records

These are not explicitly classified as sensitive under the PIPL but carry significant implications for employees, increasing the risk assessment burden in the PIPIA. Companies should ensure transparent communication about the purpose and necessity of transferring these records.

Salary and compensation data

While salary data is treated as personal financial information (potentially sensitive), it is one of the most common categories for cross-border transfer due to global payroll consolidation. Documenting the necessity of global payroll processing is critical for the PIPIA.

6. Alternatives to full cross-border HR data transfer

For companies that want to minimize compliance risk or have failed a CAC assessment, several alternatives exist:

  • China-local HR system instance: Deploy a separate instance of the global HR system within China (e.g., a China-hosted Workday or SAP instance) that processes employee data locally, with only anonymized or aggregated data transferred to the global system.
  • Local payroll processor: Use a China-based third-party payroll processor that does not require data to leave China, with global reporting satisfied through aggregated data.
  • Hybrid approach: Keep sensitive data categories (biometrics, health data) within China while transferring less sensitive categories (basic personal information, job title, department) through the SCC pathway.
  • Anonymization and pseudonymization: Where possible, strip direct identifiers before transferring data to global systems, reducing data protection obligations.

Conclusion

Transferring employee data from China to global HR systems is legally permissible under the PIPL, but it requires careful compliance with China’s cross-border data transfer framework. Foreign companies must conduct thorough data mapping, select the appropriate transfer mechanism (typically SCCs for most companies, or a Security Assessment for large employers), prepare a comprehensive PIPIA, and maintain ongoing compliance monitoring. Given the sensitivity of employee data and the inherent challenges of consent in the employment context, companies should prioritize documenting necessity, implementing robust technical safeguards, and considering data localisation alternatives for the most sensitive data categories. A well-designed HR data transfer compliance program not only satisfies regulatory requirements but also builds employee trust by demonstrating respect for privacy rights.


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's