Fill in your contact details below to discuss your needs and learn more about Datapay.
Fill in your contact details below to discuss your needs and learn more about Datapay.
Thank you for submitting your interest in learning more about Datapay. A member of our Datapay sales team will be in touch to discuss your needs and provide more information about the solution.
Protecting your sensitive payroll data is a key priority for Datapay. Our payroll system is built to meet the highest standards of data protection, undergoes regular testing, and is certified by the industry-leading standards ISO 27001:2022 and ISAE 3402 Type II.
Whether you manage your payroll in-house with Datapay’s powerful platform or use our managed payroll service, your organisation benefits from the same robust security features and expert support, giving you confidence that your employee and payroll data is secure.
Datapay is ISO 27001:2022 certified, the latest edition of this internationally recognised standard for information security, demonstrating our payroll system employs strict security and risk management practices to protect your sensitive data. Datapay undergoes two annual surveillance audits for compliance and a full recertification audit every three years.
Datapay’s ISAE 3402 certification shows our payroll solution meets stringent operational and security requirements for financial reporting, and we conduct an annual audit to review these measures.
Datapay employs industry-leading measures to protect your data, and we carry out regular system updates to optimise security performance.
Built specifically for medium to large enterprises in New Zealand, Datapay’s powerful platform and expert support help you stay on top of your organisation’s payroll security.
To keep your data safe, we engage third-party specialists to carry out regular penetration testing to confirm our payroll system cannot be hacked.
Datapay has robust processes in place to keep your information secure and restore your data in the event of an emergency or security incident.
We perform thorough supplier and integration partner checks against stringent data security standards as part of our ISO27001 policies to check that vendor processes align with our security policy, and regular security reviews are performed on these at a cadence based on risk level.
Our dedicated compliance experts keep the Datapay team abreast of new and upcoming payroll requirements, allowing us to update our system to support security and compliance according to new legislation.
With Datapay your payroll is supported by a team of local experts who keep up with the latest security trends to provide you with optimal data protection.
Our team takes a security-first approach to strengthen your safety net, with Datapay staff completing annual security training relevant to their role to understand the latest requirements and best practices.
Our expert Datapay team is involved in security working groups to stay ahead of evolving threats and informed about new rules and regulations in the payroll data landscape.
Our Datapay team works closely with Datacom’s expert in-house cybersecurity teams to update and optimise our security measures.
Cybersecurity risks are rising sharply, and businesses must take a fresh look at how sensitive personal information is managed and protected, particularly when it comes to payroll data.
Datapay is designed to meet the complex payroll demands of medium to large enterprises, integrating with your existing systems to drive productivity and accuracy while providing ongoing support from our team of experts.
Payroll security comprises the software features, processes, testing and employee training that are designed and implemented to protect sensitive payroll information from unauthorised access.
Key payroll security measures include:
Data residency in secure data centres
Data encryption, both at rest and in transit
Multi-factor authentication
Robust access controls
Features to monitor in-app activity
Regular penetration testing
Backup and disaster recovery protocols
Regular system updates according to local legislation
Staff security and privacy training
Cloud-based software with regular, real-time backup
Practices in accordance with international security standards such as ISO27001, with regular audits for compliance
Security is crucial for payroll data because payroll systems host sensitive employee information, including personal details and pay information, making it critical to have robust features and practices to protect it from unauthorised access.
A security beach relating to payroll data can potentially have serious consequences for employers, such as:
Long-term disruptions to business operations
Financial losses
Contract breaches, for example paying staff late
Compliance issues, for example late filing or tax payments
Vulnerability to ransom demands
Impact on employee and stakeholder morale and trust
Reputational damage, such as negative media coverage
Legal and regulatory penalties
For employees, unauthorised access to their personal details can make them vulnerable to identity theft and fraud, which may result in financial loss and/or issues relating to personal security.
Due to the sensitive nature of payroll data and strict regulatory environment in which payroll operates, there are several critical risks associated with payroll systems and processes:
Potential for cyberattacks and unauthorized access to sensitive information
Non-compliance with local payroll, labour and tax legislation
Errors in calculation of employee pay, deductions and entitlements
Inaccurate or insufficient record-keeping
Employee fraud, for example timekeeping fraud or false expenses
Adopting cloud-based payroll software developed and supported by local experts can help to mitigate these risks by providing a solution that automates calculations, includes strict access and monitoring tools, is updated regularly to align with the latest legislation, and is supported by industry-leading security features and practices.
Critical measures to keep your payroll operation secure are:
Using a cloud-based payroll solution that adheres to recognized, up-to-date payroll security standards and procedures
Strict access controls and ability to monitor and audit activity
Segregation of payroll duties
Regular staff security awareness training
Authorisation and approval procedures
Yes, Datapay has the latest ISO 27001:2025 certification, an international standard for information security. Datapay is audited twice a year for compliance according to this standard, and undergoes a full recertification audit once every three years.
Datapay also has ISAE 3402 Type II certification, demonstrating that our solution meets international standards for financial reporting and data security, and an audit is done each year to review these measures.
All Datapay data is hosted in Datacom’s best-in-class data centre facilities. Our data centres have a 30-year record of providing services to customers and we are committed to protecting customer data with industry-leading security measures.
Absolutely. Datapay data is encrypted both at rest and in transit to provide another layer of protection. Where file-based integrations are used, we employ PGP file encryption.
For customers using our managed payroll service we also encrypt files sent to you as part of the pay run approval process.
Datapay employs several measures to protect against cyberattacks:
ISO 27001:2022 and ISAE 3402 Type II measures for security and risk management, alongside security requirements for financial reporting and data security.
Secure cloud hosting in world-class data centres
Multi-factor authentication to minimise the risk of unauthorised access
Configurable access controls for access to sensitive information
Data encryption at rest and in transit, alongside PGP file encryption Controlled online access with OAuth 2.0 authorisation
Regular penetration testing by third-party specialists to protect against hacking
Vetting of suppliers and partners against our stringent security policies
Involvement in security working groups to stay updated on the latest security trends and best practice.
Annual staff security training to instil a security-first mindset