1. Direct answer: access from outside China is usually the starting point
A China subsidiary does not keep processing domestic merely by hosting its HR database on a server in China. CAC policy guidance states that where data is stored in China but an overseas organisation or individual can query, retrieve, download or export it, the relevant location is where the access or invocation occurs. An overseas HR or management user logging in from abroad should therefore be included in the export analysis.
Capability and use should both be documented. A global administrator account, reporting interface or broad query permission creates a governance issue before anyone downloads a file. Once the overseas account actually views or retrieves China employee personal information, the export scenario is clearer. Disabling the download button does not necessarily prevent the overseas recipient from obtaining the information.
2. Map four facts before relying on an exemption
A single global HR platform can support legally different activities. Map who accesses the data and from which country, the fields available to that role, the precise HR task, and whether information is retained or passed to another system. The system label matters less than the actual access chain.
For example, an overseas payroll team using identity and employment-status fields for a global equity plan differs from a regional manager browsing individual performance, health or salary details. The first still requires evidence that the fields are necessary for the task; the second cannot be justified merely by saying that headquarters needs management visibility.
- People and location: headquarters, regional centre, shared service centre or external vendor
- Fields: identity, contract, pay, performance, health, family, banking and background checks
- Purpose: payroll, benefits, mobility, investigation, talent analytics or general reporting
- Onward flow: screen access, local download, data warehouse, another group company or third party
3. The HR exemption has three substantive gates
China's Provisions on Promoting and Regulating Cross-Border Data Flows exempt qualifying HR exports from the security assessment, filed standard contract and certification mechanisms. The exporter should be able to demonstrate lawful employment rules or a lawfully concluded collective agreement, necessity for the particular cross-border HR task, and a data and population scope limited to what that purpose requires.
A handbook sentence permitting sharing with all global affiliates does not, by itself, prove necessity for every later use. Check how the rules were adopted and communicated, what management activity the recipient performs, and why each field is needed. Recruitment marketing, talent-pool reuse, commercial analytics and profiling unrelated to administering employment may require a different legal basis and export route.
- A valid employment-rule or collective-agreement foundation
- A specific HR task that genuinely requires overseas access
- Fields, population, frequency and retention limited to necessity
- Separate review of sensitive personal information, important data and sector rules
4. A transfer-mechanism exemption is not a PIPL exemption
The HR exemption principally addresses whether the exporter must use the CAC security assessment, SCC filing or certification route. The China subsidiary still needs a lawful processing basis and clear purpose, transparency to employees, data minimisation, access controls, individual-rights procedures and continuing oversight of the overseas recipient.
The PIPL requires a personal information protection impact assessment before providing personal information overseas, with records retained. A useful assessment explains why the overseas role is necessary, why the field set cannot be reduced, whether the recipient and foreign legal environment can protect employee rights, and how misuse or an incident will be detected, stopped and remedied.
5. Separate consent turns on the purpose and lawful basis
Article 13 of the PIPL recognises processing necessary for HR administration under lawfully adopted employment rules or a lawfully concluded collective agreement. CAC guidance issued in July 2026 further states that where an export falls within Article 13(1)(2) to (7), individual consent is not required, although the export notice obligations remain.
That does not permit every employee-data use to be relabelled as HR administration. Maintain a purpose-by-purpose basis: mandatory tax and payroll processing or necessary mobility administration differs from optional benefits, group marketing, profiling and a long-term talent pool. Sensitive personal information requires strict necessity, a specific purpose and enhanced protection. One onboarding signature should not be treated as approval for undefined future uses.
6. Sensitive information, important data and scale can change the route
Cross-border HR datasets may contain identity documents, bank details, salary, health, location, background checks and family information. Identify sensitive personal information and then check sector regulation, CIIO status and important-data rules. The HR exemption cannot be used to bypass a mandatory important-data security assessment.
If the platform also holds customer, supplier, research, production or operational data, do not apply the employee exemption to the entire environment merely because the entry point is an HR system. Separate the datasets and purposes. Population counts, sensitive-information volumes, recipient changes and system redesign may also require the existing route to be reassessed.
7. Replace ‘HQ can see everything’ with a purpose-based access matrix
Permissions should be derived from the job to be performed. An overseas payroll team may need employee ID, employment status and defined compensation fields. A global IT administrator may maintain the platform without seeing clear-text records. A regional manager may need aggregate workforce information but not individual banking, health or family data.
The matrix should cover view, search, bulk export, API calls, administrator impersonation and onward delegation, with logs for access country, user, device, time, fields and action. Shared accounts, dormant leavers, unusual downloads and off-hours access should trigger review. Masking names alone may not work where employee number, role and pay identify the individual in combination.
8. What the company should be able to prove
A regulator or employee complaint is unlikely to be resolved by producing a privacy notice alone. The company should show that its legal position matches system reality: how employment rules were validly adopted and communicated, why overseas roles need access, what they accessed, how the recipient is bound, how employees exercise rights, and how identified risks were remediated.
A privacy compliance audit should sample permissions and logs, not just document titles. If the vendor cannot provide country-, account- and field-level audit trails, the exporter may struggle to prove that access stayed within the exemption. Remediation should first restrict unexplained high-risk permissions, then complete the factual and documentary record rather than manufacture broad authorisations after the event.
- Governance: employment rules, adoption procedure, publication, employee notices and version history
- Necessity: role descriptions, purpose record, field mapping and less intrusive alternatives
- Risk: PIPIA, sensitive-data classification, recipient diligence and foreign legal environment
- Technology: access matrix, query and export logs, alerts, deletion and account offboarding
- Contract: purpose limitation, confidentiality, security, onward transfer, incident notice, audit and exit
9. A defensible remediation sequence
The aim is not to shut down every global access path. It is to stop permissions that cannot be explained and build verifiable controls around access that is genuinely necessary.
- Now: export all overseas accounts, roles, access countries, interfaces and recent logs; freeze shared accounts and permissions with no business owner
- Within seven days: classify fields by necessary, aggregatable, approval-only and prohibited for overseas access
- Then confirm: employment-rule foundation, employee notice, sensitive information, important data and the applicable exemption or transfer route
- Before expansion: complete the PIPIA, recipient terms, least privilege, logging, incident response and employee-rights workflow
- Avoid: relying on a blanket workforce consent or deleting and recreating access records before an audit
Conclusion
The immediate task is to obtain an accurate overseas-access inventory rather than review the privacy notice in isolation. Confirm the access location, HR task, field necessity, sensitive information or important data, employment-rule foundation and recipient controls. Broad global-admin access, missing audit logs, an employee objection or an imminent global HR rollout warrants a focused PRC data-export and employment review before access expands. This article provides general information only and is not legal advice for a particular matter.

