Who is the controller and who is the processor?
This is the first point to settle. When payroll is outsourced, the employer remains the data controller: it decides the purpose and means of processing. The provider is a processor, acting on the controller's instructions and on its behalf.
It follows that the data stays under your direction throughout, and that a data processing agreement must be concluded with the provider. If a proposal does not mention this, that is information in itself.
The seven questions
- Is there a data processing agreement, and what does it contain? Check whether it records the purpose, scope and duration of processing, the security measures applied and the rules for engaging sub-processors.
- Who has access to the data, and is it logged? Access should be personal rather than shared. Logging matters because it makes the question "who looked at this?" answerable afterwards.
- How is data transferred? Pay data must not travel as an unprotected email attachment. Ask for an encrypted channel or a secure document space.
- Where is the data stored? Storage within the EEA is the simplest case. Transfer to a third country requires separate safeguards.
- Are sub-processors used, and do you know about them? A processor may engage a further processor only with the controller's authorisation. Ask for this to be named in the contract.
- What happens in the event of a data breach? The provider must notify you without delay so that you can meet your own notification obligation. Ask what notification time they commit to.
- What happens to the data at the end of the contract? In what format, by what deadline is it returned, and when are copies deleted? Settle this at the start, not at termination.
What it means in practice
What it means on our side
- A data processing agreement with every client, from the start of the engagement.
- Personal, logged access — no shared accounts.
- Encrypted transfer and a secure document space rather than email attachments.
- Confidentiality obligations extended to every participant in our network.
- A contractual data return process at the end of the engagement.
It is worth adding that data security is not one-sided. The most common weak point is not the provider's system but the email in which attendance data travels as an unprotected spreadsheet. One outcome of a transition is therefore always a safer flow of data as well.
Summary
Outsourcing pay data does not automatically mean greater risk — in many cases it means less, because a regulated process replaces an undocumented habit. The difference lies in whether you asked the seven questions above and received concrete, written answers.
