Important reminder: Please be mindful of websites or domains impersonating Datacom. Our official and only website is Datacom.com (Datacom.com/au or Datacom.com/nz)
Professional software engineer working in front of multiple screens
Datapay product mark

Payroll made powerful

Payroll security

Protect your payroll and employee data with Datapay’s robust security features and protocols.

Payroll security you can trust

Protecting your sensitive payroll data is a key priority for Datapay. Our payroll system is built to meet the highest standards of data protection, undergoes regular testing, and is certified by the industry-leading standards ISO 27001:2022 and ISAE 3402 Type II.

Whether you manage your payroll in-house with Datapay’s powerful platform or use our managed payroll service, your organisation benefits from the same robust security features and expert support, giving you confidence that your employee and payroll data is secure. 

‏‏‎ ‎

‏‏‎ ‎

Two happy employees in a meeting a modern office

How does Datapay protect your payroll and employee information?

A protection shield and circular arrows around a security lock

ISO 27001:2022

Datapay is ISO 27001:2022 certified, the latest edition of this internationally recognised standard for information security, demonstrating our payroll system employs strict security and risk management practices to protect your sensitive data. Datapay undergoes two annual surveillance audits for compliance and a full recertification audit every three years.

ISAE 3402 Type II

Datapay’s ISAE 3402 certification shows our payroll solution meets stringent operational and security requirements for financial reporting, and we conduct an annual audit to review these measures.

A protection shield over a database server

Industry-leading measures to protect your data

Datapay employs industry-leading measures to protect your data, and we carry out regular system updates to optimise security performance.

  • Controlled online access

    Datapay uses OAuth 2.0 online authorisation to protect your data by controlling access to resources.
  • Secure cloud hosting

    Your data resides in New Zealand in our world-class data centres, protected by industry-leading security and stringent access controls.
  • Two-factor authentication

    Datapay’s built-in 2FA provides an extra layer of security to minimise the risk of unauthorised access to sensitive information.
  • Access controls and auditing

    Datapay’s configurable user permissions allow you to control access, and changes are auditable, so you can see who has made these and when.
  • Data encryption

    Datapay employs encryption at rest and in transit to protect your payroll data and uses PGP file encryption for file-based integration.

Built specifically for medium to large enterprises in New Zealand, Datapay’s powerful platform and expert support help you stay on top of your organisation’s payroll security.

Penetration testing

To keep your data safe, we engage third-party specialists to carry out regular penetration testing to confirm our payroll system cannot be hacked. 

Backup and disaster recovery protocols

Datapay has robust processes in place to keep your information secure and restore your data in the event of an emergency or security incident.

Supplier and partner vetting

We perform thorough supplier and integration partner checks against stringent data security standards as part of our ISO27001 policies to check that vendor processes align with our security policy, and regular security reviews are performed on these at a cadence based on risk level.

Legislative updates

Our dedicated compliance experts keep the Datapay team abreast of new and upcoming payroll requirements, allowing us to update our system to support security and compliance according to new legislation.

With Datapay your payroll is supported by a team of local experts who keep up with the latest security trends to provide you with optimal data protection.

Security-first mindset

Our team takes a security-first approach to strengthen your safety net, with Datapay staff completing annual security training relevant to their role to understand the latest requirements and best practices.

Security working groups  

Our expert Datapay team is involved in security working groups to stay ahead of evolving threats and informed about new rules and regulations in the payroll data landscape.

Expert security teams

Our Datapay team works closely with Datacom’s expert in-house cybersecurity teams to update and optimise our security measures.

Leverage the power of Datapay’s payroll software

Datapay is designed to meet the complex payroll demands of medium to large enterprises, integrating with your existing systems to drive productivity and accuracy while providing ongoing support from our team of experts.

  • Compliance: Our dedicated team of experts regularly reviews and updates Datapay to align with New Zealand legislation, with a special focus on the Holidays Act.
  • Cloud-native: Built on Datacom Cloud infrastructure, our multi-tenanted SaaS platform is secure and scalable.
  • Proven track record: 60 years of delivering payroll solutions across Australia and New Zealand.

Enterprise payroll software for medium to large organisations, backed by Datacom

  • Support payroll compliance

    Safeguard against costly errors, enhance operational efficiency and improve employee experience. Explore compliance
  • Integrate your payroll seamlessly

    Empower your people, processes, and payroll to work in harmony with extensive API capabilities and strategic partnerships. See integrations
  • Outsource your payroll management

    Our payroll experts oversee your payroll complexities to support compliance and pay your employees on time, every time. Explore Managed Payroll
  • Give your employees direct access to their payroll

    Make payroll management accessible, easier and faster for your payroll team and employees via a self-service portal. Explore Direct Access
  • Simple payroll reporting

    Clear and concise reporting and regular updates from our expert team providing your organisation with actionable insights. Payroll reporting
  • Easily manage your payroll from anywhere

    Give your employees instant access to their pay and personal information anytime, anywhere – exclusively available with Datapay. Explore MyPay
  • Hands-on payroll onboarding and implementation

    Modernise your payroll with expert support from our local payroll team at every step of your onboarding journey. Implement payroll
  • Navigate complex legislation in seconds

    Datapay’s built-in AI gives payroll teams instant, audit-ready answers to complex legislative questions. Explore Payroll Assistant

Our payroll service experience

  • 1 out of 6

    employees in New Zealand has their pay processed by Datacom
  • 60 years

    of delivering payroll solutions across Australia and New Zealand
  • 1300+

    organisations currently using Datapay to manage payroll

Is your payroll under threat? 

Cybersecurity risks are rising sharply, and businesses must take a fresh look at how sensitive personal information is managed and protected, particularly when it comes to payroll data.

Cybersecurity engineer working in a server room
Book a payroll demo
Connect with our team to see Datapay in action.

Frequently asked questions

What is payroll security?

Payroll security comprises the software features, processes, testing and employee training that are designed and implemented to protect sensitive payroll information from unauthorised access.

Key payroll security measures include:

  • Data residency in secure data centres

  • Data encryption, both at rest and in transit

  • Multi-factor authentication

  • Robust access controls

  • Features to monitor in-app activity

  • Regular penetration testing

  • Backup and disaster recovery protocols

  • Regular system updates according to local legislation 

  • Staff security and privacy training

  • Cloud-based software with regular, real-time backup

  • Practices in accordance with international security standards such as ISO27001, with regular audits for compliance

Why is payroll data protection and privacy important?

Security is crucial for payroll data because payroll systems host sensitive employee information, including personal details and pay information, making it critical to have robust features and practices to protect it from unauthorised access. 

A security beach relating to payroll data can potentially have serious consequences for employers, such as:

  • Long-term disruptions to business operations

  • Financial losses

  • Contract breaches, for example paying staff late

  • Compliance issues, for example late filing or tax payments

  • Vulnerability to ransom demands

  • Impact on employee and stakeholder morale and trust

  • Reputational damage, such as negative media coverage 

  • Legal and regulatory penalties

For employees, unauthorised access to their personal details can make them vulnerable to identity theft and fraud, which may result in financial loss and/or issues relating to personal security.

What are the risks associated with payroll?

Due to the sensitive nature of payroll data and strict regulatory environment in which payroll operates, there are several critical risks associated with payroll systems and processes:

  • Potential for cyberattacks and unauthorized access to sensitive information

  • Non-compliance with local payroll, labour and tax legislation

  • Errors in calculation of employee pay, deductions and entitlements

  • Inaccurate or insufficient record-keeping

  • Employee fraud, for example timekeeping fraud or false expenses

Adopting cloud-based payroll software developed and supported by local experts can help to mitigate these risks by providing a solution that automates calculations, includes strict access and monitoring tools, is updated regularly to align with the latest legislation, and is supported by industry-leading security features and practices.

What security measures are appropriate when processing payroll?

Critical measures to keep your payroll operation secure are:

  • Using a cloud-based payroll solution that adheres to recognized, up-to-date payroll security standards and procedures

  • Strict access controls and ability to monitor and audit activity

  • Segregation of payroll duties

  • Regular staff security awareness training 

  • Authorisation and approval procedures

Is Datapay ISO 27001 certified?

Yes, Datapay has the latest ISO 27001:2025 certification, an international standard for information security. Datapay is audited twice a year for compliance according to this standard, and undergoes a full recertification audit once every three years.

Datapay also has ISAE 3402 Type II certification, demonstrating that our solution meets international standards for financial reporting and data security, and an audit is done each year to review these measures.

Is Datapay’s data hosting secure?

All Datapay data is hosted in Datacom’s best-in-class data centre facilities. Our data centres have a 30-year record of providing services to customers and we are committed to protecting customer data with industry-leading security measures.  

Does Datapay use data encryption?

Absolutely. Datapay data is encrypted both at rest and in transit to provide another layer of protection. Where file-based integrations are used, we employ PGP file encryption.

For customers using our managed payroll service we also encrypt files sent to you as part of the pay run approval process.

How does Datapay help to protect against cyberattacks?

Datapay employs several measures to protect against cyberattacks:

  • ISO 27001:2022 and ISAE 3402 Type II measures for security and risk management, alongside security requirements for financial reporting and data security.

  • Secure cloud hosting in world-class data centres 

  • Multi-factor authentication to minimise the risk of unauthorised access

  • Configurable access controls for access to sensitive information 

  • Data encryption at rest and in transit, alongside PGP file encryption Controlled online access with OAuth 2.0 authorisation

  • Regular penetration testing by third-party specialists to protect against hacking

  • Vetting of suppliers and partners against our stringent security policies

  • Involvement in security working groups to stay updated on the latest security trends and best practice. 

  • Annual staff security training to instil a security-first mindset