Employee data remains personal information under China’s Personal Information Protection Law. The law permits processing necessary for human-resources management carried out under lawfully formulated employment rules or a lawful collective contract, but that basis is not a general exemption. Employers must still provide notice, limit collection to what is necessary, protect sensitive information, govern vendors, support individual rights and assess high-risk processing.
The compliance map should cover the full workforce lifecycle—from recruitment and onboarding through payroll, attendance, performance, investigations and exit. Overseas headquarters access, global HR platforms and foreign payroll or benefits providers require a separate cross-border analysis; domestic HR necessity does not itself complete that transfer pathway.
Direct answer
Build a purpose-based employee-data register and connect each use to an appropriate PIPL basis and employment-law process. Collect only the fields needed for recruitment, contract performance, payroll, benefits, safety, workplace administration or another defined purpose. Tell workers what happens to their information, restrict access, set retention periods and assess monitoring, sensitive data and cross-border transfers before deployment.
Do not rely on one onboarding consent form for every future use. Employment can involve unequal bargaining power, and consent may be inappropriate or unstable where processing is necessary to administer the relationship. Conversely, an HR-management basis does not excuse unrelated analytics, intrusive monitoring or silent disclosure to headquarters.
Map the workforce lifecycle
The processing register should cover:
- candidate applications, interviews, assessments and background checks;
- identity, immigration, contract and emergency-contact records;
- payroll, tax, social-insurance and benefits administration;
- time, attendance, access, safety and travel records;
- performance, training, promotion and succession planning;
- complaints, investigations, discipline and litigation holds;
- health, disability, leave and workplace-accommodation information;
- devices, messaging, network and physical-security monitoring;
- separation, references and alumni records; and
- HR systems, group reporting, vendors and overseas access.
For each activity record the purpose, fields, source, users, system, recipients, legal basis, retention, security and rights process.
HR-management basis and employment rules
The PIPL permits processing necessary for human-resources management under employment rules formulated in accordance with law or collective contracts concluded in accordance with law. Test all parts of that formulation: the processing must be necessary, genuinely connected to HR management, and supported by a lawful employment-rule or collective-contract framework.
Where workplace rules directly affect employees’ interests, the Labor Contract Law consultation and publication process may be relevant. A privacy notice alone does not make an intrusive practice necessary, and a handbook clause does not waive PIPL protections.
Other PIPL bases may apply to statutory reporting, emergency protection, contract-related processing or other defined circumstances. Record the actual basis rather than defaulting automatically to consent.
Employee privacy notice
Provide an accessible notice stating the processor’s identity and contact details, purposes, methods, categories, retention, and how employees exercise rights. Add the enhanced information required for sensitive personal information and describe sharing, vendors and overseas recipients as applicable.
Use layered notices for candidates, employees, monitoring tools and investigations where one document would become unreadable. Update notices when purposes or recipients change materially. Publication on an intranet is useful only if employees can access the relevant version.
Necessity and minimization
Challenge each requested field. A manager’s preference, a global-system default or possible future usefulness is not the same as necessity. Limit access by role and geography, mask information in routine reports, and avoid distributing medical, salary or disciplinary details through group chats.
Background checks should match the role and applicable law. Collecting family, health, financial, criminal-history or social-media information can create heightened necessity, accuracy, fairness and sensitive-data risks.
Sensitive employee information
Employee files often contain financial accounts, medical and health information, biometric identifiers, precise location or specifically designated status. These may be sensitive personal information. The employer must establish a specific purpose and sufficient necessity, apply strict safeguards, give enhanced notice, and obtain separate consent where consent is the applicable basis.
Complete a personal-information protection impact assessment before sensitive processing. Payroll necessity does not justify broader access to bank-account data, and attendance needs do not automatically justify storing reusable facial templates.
Monitoring and investigations
Email review, CCTV, location tracking, productivity software, device inspection and biometric attendance require a defined purpose, necessity and proportionate design. Consider less intrusive alternatives, collection hours, private-use expectations, access, retention and notice.
For investigations, limit collection to the allegation and authorized reviewers. Preserve evidence lawfully, document searches and protect complainants, witnesses and accused employees. Do not publish disciplinary or medical information as a deterrent. The handbook and investigation procedure should align with the privacy notice and actual system settings.
HR vendors and systems
Map recruiters, background-check providers, payroll agents, benefits administrators, cloud HR platforms and investigation vendors. Determine whether each is an entrusted processor, separate processor or overseas recipient.
Entrustment contracts should define purpose, duration, method, data categories, safeguards, rights and supervision. Prohibit unauthorized reuse and subcontracting, require incident cooperation, and verify deletion or return. Procurement should test data location, administrator access, logs, encryption, backup and exit capability rather than accepting a generic security certificate.
Employee rights and accuracy
Create a channel for employees to access, copy, correct and request deletion or explanation as the PIPL provides, subject to lawful exceptions. Route requests involving performance assessments, investigations or legal holds to both HR and privacy personnel.
Accuracy is especially important where data affects pay, discipline, promotion or termination. Keep an audit trail for material corrections and ensure downstream systems and vendors receive updates.
Retention and deletion
Set retention by record type, legal duty and dispute risk. Candidate data, payroll records, access logs, investigation files and medical documents should not all share one indefinite period. Suspend ordinary deletion where a lawful investigation, claim or preservation duty applies, but control access during the hold.
At exit, remove system access promptly, collect devices and separate business records from unnecessary personal copies. Delete or anonymize information after the purpose and required retention end, including exports and vendor-held copies where applicable.
Overseas access and transfers
Foreign headquarters access, a globally hosted HR system, overseas support and foreign benefits providers may constitute cross-border provision of personal information. Map remote access and replication, not only formal file transfers.
The employer must identify and complete the applicable PIPL transfer mechanism, provide required notice, obtain separate consent where required, conduct an impact assessment, and bind the foreign recipient to the prescribed protection level. The Network Data Security Management Regulations include provisions relevant to employee-data exports necessary for cross-border HR management under lawfully formulated employment rules or collective contracts, but that language should not be treated as a blanket exemption from all PIPL obligations or transfer analysis.
The existing guide on transferring employee data out of China should remain the specialist resource for mechanism selection, thresholds, documentation and recipient controls.
Incident readiness
HR incident plans should cover misdirected payroll files, exposed candidate databases, compromised HR accounts, public disciplinary information and lost devices. Define containment, evidence, internal escalation, vendor coordination, regulator and employee notification analysis, and remediation.
Restrict spreadsheet exports and group-email attachments, which frequently bypass system access controls. Test the ability to identify whose data and which sensitive fields were affected.
Employee-data checklist
- Maintain a lifecycle processing register.
- Record the legal basis and HR necessity for each purpose.
- Complete the employment-rule process where relied upon.
- Provide current, layered employee notices.
- Minimize fields, reports, access and retention.
- Classify and assess sensitive employee information.
- Review monitoring and investigations for proportionality.
- Contract with and audit HR vendors appropriately.
- Operate employee rights and correction workflows.
- Map overseas access and complete the transfer pathway.
- Apply record-specific retention, holds and deletion.
- Test HR-specific incident response.
Common mistakes
- Treating employee information as company property outside the PIPL.
- Using one bundled consent for every present and future HR purpose.
- Assuming HR necessity eliminates notice, security or assessment duties.
- Deploying facial attendance or monitoring because the system supports it.
- Sending salary, health or disciplinary data through broad chat groups.
- Treating a global HR vendor as an ordinary domestic processor.
- Ignoring remote headquarters access when mapping exports.
- Retaining candidate and former-employee files indefinitely.
Sources
- Personal Information Protection Law of the PRC, National People’s Congress; effective 1 November 2021.
- Regulations on Network Data Security Management, State Council; effective 1 January 2025.
- Labor Contract Law of the PRC, National People’s Congress.
General legal information only; not legal advice for a specific workforce, monitoring system, vendor, transfer or incident.


