Does Deel Work in China? Payroll & EOR Data Residency, PIPL Cross-Border & Sensitive PI
Deel is reachable from mainland China, so speed is not the question — data residency is. By Deel's own Security page it runs a fully AWS-hosted platform with primary operations in Ireland and disaster recovery in France, and its Privacy FAQs store client and user data predominantly in the EU, with no mainland-China region. That puts your China workers' payroll, identity and bank records in an offshore Deel environment — a cross-border transfer of often-sensitive personal information under PIPL. A compliance-first look at the residency, consent and ICP exposure, and the lawful in-country path.
Does Deel work in China?
Reaching Deel isn't the problem — where it keeps your China workers' records is. For a payroll and employer-of-record platform the China question is data residency and consent, not whether the dashboard loads.
By Deel's own Security page it runs “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and its Privacy FAQs state that because the Deel Platform's servers are in Ireland it stores client and user data “predominantly within the EU,” with sub-processing in the USA — no mainland-China region anywhere. So the identities, contracts, pay and bank details Deel holds for your China staff come to rest offshore, which makes their collection a cross-border transfer PIPL governs (notice, a separate consent and a transfer mechanism, Articles 38–40). Much of that payroll data is sensitive personal information (Article 28), adding a specific-consent and impact-assessment bar, and for a CIIO or large-volume handler an in-country storage duty applies (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) that an offshore region cannot meet. Deel's EU-US Data Privacy Framework, EU Standard Contractual Clauses and Transfer Impact Assessment are GDPR-world safeguards — none is a PIPL transfer mechanism.
21YunBox maps your cross-border, residency and consent exposure, localizes the China worker data that must stay onto a China-resident footing (sending Deel only what may lawfully leave), and delivers your China-facing surface in-country on ICP-filed infrastructure — with no rebuild, and never uses or suggests circumvention of any kind. Treat the specifics as a risk to confirm with counsel. Our China team can map your exposure with you →
What Deel's own documentation says about China
| Fact | Primary source |
|---|---|
| Deel runs a single offshore cloud footprint — Ireland and France — with no mainland-China region. On its own Security page Deel states it leverages “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France.” For your China workforce that geography is the point: the identity, contract, payroll and bank records Deel holds for your China staff rest in an offshore environment, making their collection a cross-border transfer of personal information under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–40). | Deel — Security (deel.com/security), retrieved 2026-10-09; PIPL Articles 38–40 |
| Deel stores client and user data predominantly in the EU, processes some in the USA, and safeguards it with GDPR-world mechanisms — none of them a PIPL route. Deel's Privacy FAQs state that because “the servers of the Deel Platform are located in Ireland,” it “stores the personal data of Clients and Users predominantly within the EU,” that it “engages with Sub-Processors to process personal data in the USA,” and that it relies on EU-US Data Privacy Framework self-certification, EU Standard Contractual Clauses and a Transfer Impact Assessment, alongside SOC 1/2/3 and ISO 27001 attestations. China does not accept those as a basis to export personal information from the mainland — the lawful routes are a CAC security assessment, the CAC standard contract, or CAC-accredited certification. | Deel — Privacy FAQs (deel.com/privacy-faqs), retrieved 2026-10-09 |
| Payroll and EOR records are largely sensitive personal information, which raises the bar. Government ID numbers, bank and compensation data, tax records and often benefits and attendance are sensitive personal information under PIPL (Article 28); processing them requires a specific purpose and demonstrated necessity, a separate consent, and a prior personal-information protection impact assessment (Article 55) — and moving them across the border at volume can trigger China's data-export security assessment (数据出境安全评估) before anything leaves. | PIPL Articles 28 and 55; Measures for the Security Assessment of Data Exports (cac.gov.cn), retrieved 2026-10-09 |
| For some handlers the data must stay in China — and any China-facing worker portal owes an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, information collected in China must be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore Deel environment cannot satisfy. And any public-facing worker or contractor surface actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Deel does not provide. PIPL's HR-management basis (Article 13(2)) does not remove the cross-border mechanism or these residency duties. | PIPL Article 40 and Article 13(2); Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33, retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a payroll and employer-of-record platform, whether Deel “works” in mainland China is settled by where your people’s records are kept, long before it is settled by how quickly a dashboard paints. Deel is the book of record for a distributed workforce — the identities, contracts, pay runs, tax filings and bank details of everyone you hire or contract through it — and its web app answers from the mainland. So the live question is not whether the screens load for your China staff. It is which country holds those records, and whether they were permitted to leave China in the first place. By its own security documentation Deel runs a single cloud footprint that sits outside mainland China — and that geography, not latency, is what China’s law responds to.
Deel in China at a glance
| What decides it | In Deel's own terms — and China's law |
|---|---|
| What it is | Deel is a global payroll, EOR and contractor-management platform — the system of record for worker identity, contracts, compensation, tax forms and bank details across many countries. It keeps a continuous, identifiable record of every person you employ or contract, much of it sensitive. |
| Is it reachable from the mainland? | Yes. Deel's web app and APIs answer from China and it is not a service blocked at the border. Reachability is not the China question. (Cross-border access from the mainland to an offshore environment can be uneven — an operational matter, below, not the decision.) |
| Where do the worker records live? | Offshore. Deel's Security page describes “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and its Privacy FAQs say that because its servers are in Ireland it stores client and user data “predominantly within the EU,” with sub-processing in the USA. No mainland-China region is named, so your China workers' records sit in an offshore Deel environment — an EU one by default. |
| Putting China worker data into it | The records are personal information, much of it sensitive. Holding them in an offshore Deel environment is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, one transfer mechanism, and — where consent is the basis — a separate consent that is hard to treat as freely given in an employment relationship. PIPL's HR-management basis (Article 13(2)) does not switch off those cross-border duties. |
| In-country storage & volume | For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and a CAC data-export security assessment may apply before data leaves — duties an offshore Deel region cannot meet. Any China-facing worker or contractor portal served from inside the mainland also owes an ICP filing. |
| The lawful path | Hold the China worker data that must remain on a China-resident footing, forward Deel only what may lawfully cross the border, keep Deel for the rest of your people, and serve any China-facing worker surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind. |
Reachable — but where do your workers’ records come to rest?
Deel’s applications answer from China, and it is not a service China blocks at the border, so the decision is not made at the network layer. Residency makes it. On its own Security page Deel describes “a fully AWS-hosted infrastructure, with primary operations in Ireland and a disaster recovery site in France,” and in its Privacy FAQs it explains that because the Deel Platform’s servers are located in Ireland it stores the personal data of clients and users predominantly within the EU, while sub-processors process some personal data in the United States. Mainland China appears nowhere on that map. So unless and until Deel opens an in-country region, the system-of-record data for your China workers lives in an offshore Deel environment — an EU one by default, reached in part by US sub-processors.
Cross-border access from the mainland to that offshore environment can be inconsistent, and the reflex is to force the connection through a network workaround. 21YunBox never uses or suggests circumvention of any kind — it is a compliance hazard and, for this decision, beside the point. That is also why this page publishes no first-party China latency figure for Deel: speed is not the axis for a question that turns on residency and consent. The productive question is where the worker data lives and whether it had a lawful basis to be there.
Worker records offshore are a cross-border transfer under PIPL
Here is the gate most HR and finance teams step over. Collecting personal information from staff and contractors in mainland China and keeping it in a Deel environment hosted abroad is a cross-border transfer (数据出境) of personal information under the Personal Information Protection Law. PIPL fixes the duty on the personal-information handler — your China entity as the employer, not Deel as the processor acting on its behalf: Articles 38–40 call for notice, one lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and, where consent is the basis you rely on, a separate consent for the overseas transfer.
Employment makes that consent delicate. PIPL does permit an employer to process staff personal information where it is necessary to carry out human-resources management under a lawfully adopted labor policy or collective contract (Article 13(2)), so routine HR processing need not always rest on consent. But that basis does not reach across the border: exporting the records to an offshore Deel tenant is a distinct act that engages the cross-border rules in their own right, and a separate, freely given consent is rarely something an employee can hand their own employer. And for a critical information infrastructure operator or a large-volume handler, personal information generated in China must additionally be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37 — the data-localization provision renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged)) — a duty no offshore Deel region can discharge. Which of these obligations actually bite your organization is a risk to settle with counsel against your real headcount and data volumes.
Payroll, government IDs and bank details are sensitive — a higher bar
Deel’s exposure is sharper than an ordinary application’s because of what it necessarily holds. To run payroll and act as employer of record, it gathers government identification numbers, bank and compensation data, tax records, and often dependents, benefits and attendance — a large share of it sensitive personal information under PIPL (Article 28). Processing sensitive personal information demands a specific purpose and demonstrated necessity, a separately obtained consent, and a prior personal-information protection impact assessment (Article 55) before the data is handled at all, let alone sent abroad. Moving sensitive worker data across the border at volume can further pull in China’s data-export security assessment (数据出境安全评估) ahead of anything leaving. None of this is a function of render speed; it turns on whether the data had a lawful basis to be offshore. Because these are sensitive records, treat every line here as a matter to confirm with counsel before you rely on it.
Deel’s safeguards are built for Europe, not for China
The instinct is to point at Deel’s compliance posture — SOC 1, SOC 2, SOC 3 and ISO 27001, AES-256 encryption at rest, EU-US Data Privacy Framework self-certification, EU Standard Contractual Clauses and a Transfer Impact Assessment — and treat the transfer as handled. Those are real controls, but every one of them is engineered for the GDPR world: they legitimize moving data between the EU, the UK and the United States. None of them is a PIPL transfer mechanism. China does not recognize the EU-US Data Privacy Framework or EU Standard Contractual Clauses as a basis to export personal information out of the mainland; the lawful routes are a CAC security assessment, the CAC standard contract, or CAC-accredited certification. And flipping a Deel tenant from its EU home toward a US sub-processor only relocates the cross-border transfer — it does not bring the data back inside China. Keeping China-collected worker data in-country means standing up a China-resident home for the records that must stay, and sending Deel only what may lawfully leave. That division — what must remain and what may travel — is a legal judgment before it is a configuration, and it is the center of the work.
The lawful path — map, localize, deliver
There is a compliant way to run Deel for a workforce that includes mainland China, and it has a definite shape. First, map: our China team walks your PIPL exposure — which worker records collected in China have to stay in the country, what may lawfully cross the border, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty applies, and what your notice, consent and impact-assessment flow must cover. The legal conclusions are reached with your counsel; we build the technical picture that feeds them.
Then localize: we stand up and integrate a China-resident footing for the China worker data that must remain on the mainland — a consented, in-country home for those records — while you keep Deel as the system of record for the rest of your people, sending it only what may lawfully leave.
Then deliver: any China-facing surface of the platform — a worker self-onboarding page, a contractor portal, an expense-or-document flow actually served to people inside the mainland — is a public-facing service there, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. The 21YunBox Optimizer serves it from inside China, in front of the stack you already run, with no rebuild and no re-platform. The result is a payroll and EOR setup that runs legally and compliantly for your people in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: 21YunBox never uses or suggests circumvention of any kind. We localize what must stay and deliver what faces the public in-country, and we never move personal information out of China by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
