Does Gusto Work in China? US-Hosted Payroll Data, PIPL Cross-Border & Employee PI Residency
Gusto is US-built payroll, benefits and HR for small businesses, and it hosts customer data in AWS regions inside the United States (principal US-West-2 Oregon, backup US-East-1 Virginia) with no mainland-China region — so for a China workforce the question is not speed, it is data residency. A mainland-China entity cannot run its own payroll on Gusto, and putting China-collected employee personal information — compensation, bank and government-ID details, benefits — into a US-hosted Gusto is a cross-border transfer of often-sensitive personal information under PIPL. A compliance-first look at the residency, cross-border and consent exposure, and the lawful in-country path.
Does Gusto work in China?
Gusto is United States payroll, benefits and HR for small businesses, hosted on AWS in US regions — so the honest answer for a China workforce is not about speed, and not about the border. Gusto's own security page names only US regions (principal Oregon, backup Virginia) and no mainland-China region, so a mainland-China entity cannot run its payroll on Gusto, and any China staff placed in it have their records kept in the United States.
Putting personal information collected from China employees — compensation, bank and government-ID details, benefits — into a US-hosted Gusto is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, one transfer mechanism, and a separate consent that is especially hard to treat as freely given at work. Much of what payroll holds is sensitive personal information (Articles 28–29), raising the consent bar and requiring a prior impact assessment, and above volume thresholds a data-export security assessment may apply. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires in-country storage a US region cannot meet.
21YunBox maps your cross-border, residency and consent exposure, localizes the China entity's payroll and employee data onto a China-resident footing (sending Gusto only what may lawfully leave), and delivers any China-facing employee surface in-country on ICP-filed infrastructure — no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.
What Gusto's own documentation says about China
| Fact | Primary source |
|---|---|
| Gusto hosts customer data on AWS in United States regions — it names no mainland-China region. Gusto's own security page states that “Gusto uses Amazon Web Services (AWS) to host its production servers, databases, and supporting services,” and that “The principal region for running the application is AWS region US-West-2 (Oregon), with AWS region US-East-1 (Virginia) for its backup.” Both regions are in the US, so the records of any China staff placed in Gusto rest in a US-hosted account. | Gusto — Security (gusto.com/security), retrieved 2026-10-09 |
| Gusto's hosting is multi-region but entirely inside the United States. Gusto says it “uses a multi-region setup for its infrastructure,” with the principal region in Oregon and the backup in Virginia, and that data is “encrypted at rest in AWS using AES-256 key encryption.” Multi-region resilience that never leaves the US creates no China-resident option: there is no mainland-China region for a China entity's employee data to sit in. | Gusto — Security (gusto.com/security), retrieved 2026-10-09 |
| Holding China employees' records in a US-hosted Gusto is a PIPL cross-border transfer — with a separate consent that is fraught for employee data. Moving personal information collected from staff in mainland China to a Gusto account hosted in the US triggers PIPL Articles 38–40: notice, one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and, where consent is the basis, a separate consent that is hard to treat as freely given in an employment relationship. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09 |
| Payroll data is sensitive personal information, and for some handlers it must stay in China. Compensation, bank-account and government-ID details, and benefits data are sensitive personal information under PIPL (Articles 28–29), needing a specific purpose, separate consent and an impact assessment; and for a critical information infrastructure operator or large-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires in-country storage, with a CAC data-export security assessment possible before anything leaves. | PIPL Articles 28–29; Cybersecurity Law Article 39 (formerly Article 37); Measures for the Security Assessment of Data Exports (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a company with people in mainland China, the question about Gusto is not how quickly its screens load — it is whether the service can lawfully hold those people’s records at all. Gusto is a United States payroll, benefits and HR platform built for small businesses: it runs US payroll and tax, and it keeps the compensation, bank and government-ID details, benefits and employment history of everyone inside it. Its own security page says it hosts on Amazon Web Services and names only US regions. So the decision for a China workforce is not reachability and not speed. It is residency — where those employee records come to rest, and whether they were ever allowed to leave the country — and, before that, applicability: whether a mainland-China entity can run its payroll on a US product in the first place.
Gusto in China at a glance
| What decides it | In Gusto's own terms — and China's law |
|---|---|
| What it is | Gusto is US-built payroll, benefits and HR for small businesses. It holds a continuous, identifiable record of each worker — pay, bank-account and government-ID details, benefits and employment history — much of it sensitive. |
| Can a China entity run its payroll on it? | No. Gusto's payroll and tax engine is built for US businesses; international hiring is offered only through a partner acting as employer of record, not a mainland-China payroll product. A China-registered entity cannot run its own payroll on Gusto. |
| Where do the records live? | In the United States. Gusto's security page hosts production data on AWS, principal region US-West-2 (Oregon) with US-East-1 (Virginia) for backup — a multi-region setup that never leaves the US, and no mainland-China region. China staff placed in Gusto have their records kept offshore. |
| Putting China employee data into it | The records are personal information, much of it sensitive. Keeping them in a US-hosted Gusto is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a transfer mechanism, and — where consent is the basis — a separate consent that is hard to treat as freely given in an employment relationship. Pay, bank and benefits data is sensitive personal information (Articles 28–29), adding a specific-purpose, separate-consent and impact-assessment bar. |
| In-country storage & volume | For a critical information infrastructure operator or large-volume handler, personal information generated in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and a CAC data-export security assessment may apply before data leaves — duties a US-hosted Gusto cannot meet. |
| The lawful path | Run the China entity's payroll on a China-resident, consented footing, send Gusto only what may lawfully leave, keep Gusto for your US workforce, and deliver any China-facing employee surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind. |
Reachable screens, but a US-only home for the data
Gusto is a US website, so its pages can be opened from the mainland — but that tells you nothing about whether you may use it for a China workforce. Gusto runs US payroll and tax and is sold to US small businesses; where it reaches beyond the border, it does so for contractor payments and for international hiring handled by a partner acting as employer of record, not by standing up payroll inside another country. Its security page is explicit about geography: Gusto hosts on Amazon Web Services, uses a multi-region setup, and places its principal region in Oregon and its backup in Virginia. Every one of those regions is in the United States, and none is in mainland China. So unless and until that changes, a China employee entered into Gusto has their system-of-record data kept in a US-hosted account.
Cross-border access to a US-hosted service from inside the mainland can be uneven, and the temptation is to force it through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. For the same reason this page publishes no first-party China latency figure for Gusto: speed is not the axis for a decision that turns on residency and applicability. The productive question is where the employee data comes to rest and whether it had a lawful basis to be there.
China employee data in a US-hosted Gusto is a cross-border transfer under PIPL
Here is the gate most small teams miss. Collecting personal information from staff in mainland China and keeping it in a Gusto account hosted in the United States is a cross-border transfer (数据出境) of personal information under the Personal Information Protection Law. PIPL places the duty on the personal-information handler — the employer, not Gusto the processor: Articles 38–40 require notice, one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and, where consent is your basis, a separate consent for the overseas transfer.
Employee data makes that consent awkward. PIPL does allow an employer to process staff personal information where it is necessary for human-resources management under a lawfully adopted labor policy or collective contract (Article 13(2)), so routine HR handling need not always rest on consent. But that basis governs the handling; it does not switch off the cross-border rules. Exporting those records to a US-hosted Gusto is a distinct act that engages the transfer regime in its own right — notice, a lawful basis and a transfer mechanism still apply, and a separate consent is rarely something an employee can give freely to their employer. And for a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37 — the data-localization provision renumbered by the 2025 amendment that took effect on January 1, 2026, its substance unchanged)) — a duty a US-hosted Gusto cannot satisfy. Which of these bite your organization is a risk to confirm with counsel against your actual headcount and data.
Payroll is sensitive personal information — a higher bar
The exposure is sharper for Gusto than for an ordinary application because of what payroll holds. Compensation, bonus and benefits figures, bank-account numbers, and the government-issued identifiers payroll depends on are sensitive personal information under PIPL (Articles 28–29), and processing sensitive personal information demands a specific purpose, a separate consent, and a personal-information protection impact assessment (Article 55). Where benefits administration reaches into health or insurance details, that too is sensitive. Moving sensitive employee data across the border above volume thresholds can additionally trigger China’s data-export security assessment (数据出境安全评估) before anything leaves. None of this turns on how fast a screen renders; it turns on whether the data had a lawful basis to be abroad. Because payroll data is sensitive by nature, treat every line here as a risk to settle with counsel before you rely on it.
Why “switch to a China region” isn’t on the menu — and the ICP piece
With many enterprise tools the instinct is to flip the tenant to a nearer region and call it localized. Gusto offers no such lever: its hosting is multi-region but wholly inside the US — Oregon for the application, Virginia for backup — so there is no mainland-China region to point China employee data at, and a US-to-US failover relocates nothing across the border. Keeping China-collected employee data in-country therefore means a different shape of work: standing up a China-resident home for the records that must stay, and sending Gusto only what may lawfully leave. That split — what must stay and what may go — is a legal question before it is a technical one, and it is the heart of the job.
The delivery half matters too. Any China-facing surface of the system — a self-service pay or benefits portal, an onboarding page actually served to people in the mainland — is a public service there, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery tied to a mainland hosting resource. Gusto names no mainland region, so there is nothing of its own to file against. “We already run Gusto for payroll” does not carry into China on its own.
The lawful path — map, localize, deliver
There is a lawful way to run payroll for a workforce that includes mainland China, and it has a shape. First, map: our China team works through your PIPL exposure — which employee records collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty bites, and what your notice, consent and impact-assessment flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we stand up and integrate a China-resident, consented footing for the China entity’s payroll and the employee records that have to stay in the country, while you keep Gusto as the system for the rest of your workforce, sending it only what may lawfully cross the border.
Then deliver: any China-facing surface — an employee pay or benefits portal, an onboarding page served to people in the mainland — carries an ICP-filing duty and needs compliant in-country delivery. The 21YunBox Optimizer delivers it in-country, in front of what you already run, with no rebuild and no re-platform. The result is a payroll and HR setup that runs legally and compliantly for your people in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
