Staff Payroll

Data Protection Policy

Protecting client and employee data is a core part of our payroll and HR service delivery. We recognise the sensitive nature of payroll and employment information and are committed to handling all data responsibly, securely, and in accordance with applicable data protection requirements.

1. Data Collection

We collect and process only the information necessary to deliver payroll and related HR services. This may include, where applicable:

 

  • Employee identification and contact information
  • Employment and compensation details
  • Attendance, leave, and overtime records
  • Statutory, tax, and bank-related information required for payroll processing

2. Data Usage

Collected data is used strictly for service delivery purposes, including:

 

 

  • Payroll calculation, processing, and payslip preparation
  • Statutory reporting and compliance obligations
  • Maintaining accurate employee records
  • Operational support and service administration

 

Data is not used for marketing or unrelated purposes.

3. Data Storage & Security

Employee data and supporting documents are encrypted prior to storage and securely maintained within our systems. We implement appropriate safeguards to protect data confidentiality and integrity, including:

 

  • Controlled, role-based access to data
  • Logical separation of client information
  • Secure storage and transmission practices
  • Ongoing monitoring and review of data handling procedures

 

These measures are designed to reduce the risk of unauthorized access, disclosure, or misuse.

4. Data Sharing

We do not sell, rent, or trade personal data. Information is disclosed only when necessary and limited to the following circumstances:

 

  • With the client’s authorisation for service delivery purposes
  • To comply with legal, regulatory, or statutory obligations
  • To appointed service providers acting under confidentiality and data protection obligations

 

All disclosures are limited to what is required for the specific purpose.

5. Data Retention

Personal data is retained only for as long as necessary to fulfil service obligations and statutory requirements. Upon expiry of the relevant retention period, data is securely archived or disposed of in accordance with applicable regulations.

6. Your Rights

Subject to applicable laws and operational requirements, individuals may:

 

  • Request access to personal data held
  • Request correction of inaccurate information
  • Request deletion or restriction of data, where permitted

 

Requests will be handled in a reasonable timeframe and in accordance with regulatory requirements.

This policy supports our commitment to responsible data handling and forms part of our broader governance and service assurance framework.