Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Deel Work in China? Payroll & EOR Data Residency, PIPL Cross-Border & Sensitive PI

Deel is reachable from mainland China, so speed is not the question — data residency is. By Deel's own Security page it runs a fully AWS-hosted platform with primary operations in Ireland and disaster recovery in France, and its Privacy FAQs store client and user data predominantly in the EU, with no mainland-China region. That puts your China workers' payroll, identity and bank records in an offshore Deel environment — a cross-border transfer of often-sensitive personal information under PIPL. A compliance-first look at the residency, consent and ICP exposure, and the lawful in-country path.

Does Deel work in China?

Reaching Deel isn't the problem — where it keeps your China workers' records is. For a payroll and employer-of-record platform the China question is data residency and consent, not whether the dashboard loads.

By Deel's own Security page it runs “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and its Privacy FAQs state that because the Deel Platform's servers are in Ireland it stores client and user data “predominantly within the EU,” with sub-processing in the USA — no mainland-China region anywhere. So the identities, contracts, pay and bank details Deel holds for your China staff come to rest offshore, which makes their collection a cross-border transfer PIPL governs (notice, a separate consent and a transfer mechanism, Articles 38–40). Much of that payroll data is sensitive personal information (Article 28), adding a specific-consent and impact-assessment bar, and for a CIIO or large-volume handler an in-country storage duty applies (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) that an offshore region cannot meet. Deel's EU-US Data Privacy Framework, EU Standard Contractual Clauses and Transfer Impact Assessment are GDPR-world safeguards — none is a PIPL transfer mechanism.

21YunBox maps your cross-border, residency and consent exposure, localizes the China worker data that must stay onto a China-resident footing (sending Deel only what may lawfully leave), and delivers your China-facing surface in-country on ICP-filed infrastructure — with no rebuild, and never uses or suggests circumvention of any kind. Treat the specifics as a risk to confirm with counsel. Our China team can map your exposure with you →

What Deel's own documentation says about China

FactPrimary source
Deel runs a single offshore cloud footprint — Ireland and France — with no mainland-China region. On its own Security page Deel states it leverages “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France.” For your China workforce that geography is the point: the identity, contract, payroll and bank records Deel holds for your China staff rest in an offshore environment, making their collection a cross-border transfer of personal information under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–40). Deel — Security (deel.com/security), retrieved 2026-10-09; PIPL Articles 38–40
Deel stores client and user data predominantly in the EU, processes some in the USA, and safeguards it with GDPR-world mechanisms — none of them a PIPL route. Deel's Privacy FAQs state that because “the servers of the Deel Platform are located in Ireland,” it “stores the personal data of Clients and Users predominantly within the EU,” that it “engages with Sub-Processors to process personal data in the USA,” and that it relies on EU-US Data Privacy Framework self-certification, EU Standard Contractual Clauses and a Transfer Impact Assessment, alongside SOC 1/2/3 and ISO 27001 attestations. China does not accept those as a basis to export personal information from the mainland — the lawful routes are a CAC security assessment, the CAC standard contract, or CAC-accredited certification. Deel — Privacy FAQs (deel.com/privacy-faqs), retrieved 2026-10-09
Payroll and EOR records are largely sensitive personal information, which raises the bar. Government ID numbers, bank and compensation data, tax records and often benefits and attendance are sensitive personal information under PIPL (Article 28); processing them requires a specific purpose and demonstrated necessity, a separate consent, and a prior personal-information protection impact assessment (Article 55) — and moving them across the border at volume can trigger China's data-export security assessment (数据出境安全评估) before anything leaves. PIPL Articles 28 and 55; Measures for the Security Assessment of Data Exports (cac.gov.cn), retrieved 2026-10-09
For some handlers the data must stay in China — and any China-facing worker portal owes an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, information collected in China must be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore Deel environment cannot satisfy. And any public-facing worker or contractor surface actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Deel does not provide. PIPL's HR-management basis (Article 13(2)) does not remove the cross-border mechanism or these residency duties. PIPL Article 40 and Article 13(2); Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33, retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a payroll and employer-of-record platform, whether Deel “works” in mainland China is settled by where your people’s records are kept, long before it is settled by how quickly a dashboard paints. Deel is the book of record for a distributed workforce — the identities, contracts, pay runs, tax filings and bank details of everyone you hire or contract through it — and its web app answers from the mainland. So the live question is not whether the screens load for your China staff. It is which country holds those records, and whether they were permitted to leave China in the first place. By its own security documentation Deel runs a single cloud footprint that sits outside mainland China — and that geography, not latency, is what China’s law responds to.

Deel's Security page, under 'Data Infrastructure that's secure, scalable, and reliable', stating that Deel leverages a fully AWS-hosted infrastructure with primary operations in Ireland and a disaster recovery site in France — naming no mainland-China data center
Deel's own Security page: it runs “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France.” Deel names its hosting locations as Ireland and France — mainland China is not among them — so the identity, contract, payroll and bank records Deel holds for your China workers come to rest in an offshore Deel environment. Source: Deel — Security

Deel in China at a glance

What decides it In Deel's own terms — and China's law
What it is Deel is a global payroll, EOR and contractor-management platform — the system of record for worker identity, contracts, compensation, tax forms and bank details across many countries. It keeps a continuous, identifiable record of every person you employ or contract, much of it sensitive.
Is it reachable from the mainland? Yes. Deel's web app and APIs answer from China and it is not a service blocked at the border. Reachability is not the China question. (Cross-border access from the mainland to an offshore environment can be uneven — an operational matter, below, not the decision.)
Where do the worker records live? Offshore. Deel's Security page describes “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and its Privacy FAQs say that because its servers are in Ireland it stores client and user data “predominantly within the EU,” with sub-processing in the USA. No mainland-China region is named, so your China workers' records sit in an offshore Deel environment — an EU one by default.
Putting China worker data into it The records are personal information, much of it sensitive. Holding them in an offshore Deel environment is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, one transfer mechanism, and — where consent is the basis — a separate consent that is hard to treat as freely given in an employment relationship. PIPL's HR-management basis (Article 13(2)) does not switch off those cross-border duties.
In-country storage & volume For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and a CAC data-export security assessment may apply before data leaves — duties an offshore Deel region cannot meet. Any China-facing worker or contractor portal served from inside the mainland also owes an ICP filing.
The lawful path Hold the China worker data that must remain on a China-resident footing, forward Deel only what may lawfully cross the border, keep Deel for the rest of your people, and serve any China-facing worker surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

Reachable — but where do your workers’ records come to rest?

Deel’s applications answer from China, and it is not a service China blocks at the border, so the decision is not made at the network layer. Residency makes it. On its own Security page Deel describes “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and in its Privacy FAQs it explains that because the Deel Platform’s servers are located in Ireland it stores the personal data of clients and users predominantly within the EU, while sub-processors process some personal data in the United States. Mainland China appears nowhere on that map. So unless and until Deel opens an in-country region, the system-of-record data for your China workers lives in an offshore Deel environment — an EU one by default, reached in part by US sub-processors.

Cross-border access from the mainland to that offshore environment can be inconsistent, and the reflex is to force the connection through a network workaround. 21YunBox never uses or suggests circumvention of any kind — it is a compliance hazard and, for this decision, beside the point. That is also why this page publishes no first-party China latency figure for Deel: speed is not the axis for a question that turns on residency and consent. The productive question is where the worker data lives and whether it had a lawful basis to be there.

Worker records offshore are a cross-border transfer under PIPL

Here is the gate most HR and finance teams step over. Collecting personal information from staff and contractors in mainland China and keeping it in a Deel environment hosted abroad is a cross-border transfer (数据出境) of personal information under the Personal Information Protection Law. PIPL fixes the duty on the personal-information handler — your China entity as the employer, not Deel as the processor acting on its behalf: Articles 38–40 call for notice, one lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and, where consent is the basis you rely on, a separate consent for the overseas transfer.

Employment makes that consent delicate. PIPL does permit an employer to process staff personal information where it is necessary to carry out human-resources management under a lawfully adopted labor policy or collective contract (Article 13(2)), so routine HR processing need not always rest on consent. But that basis does not reach across the border: exporting the records to an offshore Deel tenant is a distinct act that engages the cross-border rules in their own right, and a separate, freely given consent is rarely something an employee can hand their own employer. And for a critical information infrastructure operator or a large-volume handler, personal information generated in China must additionally be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37 — the data-localization provision renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged)) — a duty no offshore Deel region can discharge. Which of these obligations actually bite your organization is a risk to settle with counsel against your real headcount and data volumes.

Payroll, government IDs and bank details are sensitive — a higher bar

Deel’s exposure is sharper than an ordinary application’s because of what it necessarily holds. To run payroll and act as employer of record, it gathers government identification numbers, bank and compensation data, tax records, and often dependents, benefits and attendance — a large share of it sensitive personal information under PIPL (Article 28). Processing sensitive personal information demands a specific purpose and demonstrated necessity, a separately obtained consent, and a prior personal-information protection impact assessment (Article 55) before the data is handled at all, let alone sent abroad. Moving sensitive worker data across the border at volume can further pull in China’s data-export security assessment (数据出境安全评估) ahead of anything leaving. None of this is a function of render speed; it turns on whether the data had a lawful basis to be offshore. Because these are sensitive records, treat every line here as a matter to confirm with counsel before you rely on it.

Deel’s safeguards are built for Europe, not for China

The instinct is to point at Deel’s compliance posture — SOC 1, SOC 2, SOC 3 and ISO 27001, AES-256 encryption at rest, EU-US Data Privacy Framework self-certification, EU Standard Contractual Clauses and a Transfer Impact Assessment — and treat the transfer as handled. Those are real controls, but every one of them is engineered for the GDPR world: they legitimize moving data between the EU, the UK and the United States. None of them is a PIPL transfer mechanism. China does not recognize the EU-US Data Privacy Framework or EU Standard Contractual Clauses as a basis to export personal information out of the mainland; the lawful routes are a CAC security assessment, the CAC standard contract, or CAC-accredited certification. And flipping a Deel tenant from its EU home toward a US sub-processor only relocates the cross-border transfer — it does not bring the data back inside China. Keeping China-collected worker data in-country means standing up a China-resident home for the records that must stay, and sending Deel only what may lawfully leave. That division — what must remain and what may travel — is a legal judgment before it is a configuration, and it is the center of the work.

The lawful path — map, localize, deliver

There is a compliant way to run Deel for a workforce that includes mainland China, and it has a definite shape. First, map: our China team walks your PIPL exposure — which worker records collected in China have to stay in the country, what may lawfully cross the border, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty applies, and what your notice, consent and impact-assessment flow must cover. The legal conclusions are reached with your counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a China-resident footing for the China worker data that must remain on the mainland — a consented, in-country home for those records — while you keep Deel as the system of record for the rest of your people, sending it only what may lawfully leave.

Then deliver: any China-facing surface of the platform — a worker self-onboarding page, a contractor portal, an expense-or-document flow actually served to people inside the mainland — is a public-facing service there, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. The 21YunBox Optimizer serves it from inside China, in front of the stack you already run, with no rebuild and no re-platform. The result is a payroll and EOR setup that runs legally and compliantly for your people in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: 21YunBox never uses or suggests circumvention of any kind. We localize what must stay and deliver what faces the public in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Deel store Chinese workers' data in China?
No. By Deel's own Security page it runs “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and its Privacy FAQs say that because its servers are in Ireland it stores client and user data predominantly within the EU, with sub-processing in the USA. Deel names no mainland-China region, so the identities, contracts, pay and bank details it holds for your China staff sit offshore — a cross-border transfer of (often sensitive) personal information under PIPL, on which the handler (your China entity, not Deel) owes notice, a separate consent and a transfer mechanism.
Doesn't Deel's SOC 2, ISO 27001 and EU-US Data Privacy Framework cover the transfer?
Those are genuine controls, but they are built for the GDPR world — they legitimize data moving between the EU, the UK and the United States. None of them is a PIPL transfer mechanism, and China does not recognize the EU-US Data Privacy Framework or EU Standard Contractual Clauses as a basis to export personal information from the mainland. The lawful China routes are a CAC security assessment, the CAC standard contract, or CAC-accredited certification. Switching a Deel tenant from its EU home toward a US sub-processor relocates the transfer; it does not end it. Treat your exact obligations as a matter for counsel.
Can 21YunBox help make our Deel setup work in China?
Yes. Our China team maps your PIPL cross-border, residency and consent exposure for the worker data Deel holds — for your entity, headcount and data volumes — then localizes the China worker data that must stay onto a China-resident footing and stands up the ICP-filed, in-country delivery any China-facing worker surface needs, in front of the Deel stack you already run. We never use or suggest circumvention of any kind. Get in touch to work through your specific case.

ARTICLES RELATED TO DEEL

CATEGORIES

HCM

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.