
Information pursuant to Art. 26 Data Act when switching providers:
Switching and transfer methods, data structures and formats, limitations and open interoperability specifications
Below, we provide information pursuant to Art. 26 lit. a) and b) EU Data Act on the options and technical requirements for switching to another provider of data processing services that covers the same type of service.
| Procedure | 1. Public API (REST/JSON) | 2. Master data and Excel exports |
|---|---|---|
| Purpose in provider switching | Central procedure for structured, interoperable provider switching | Supplementary procedure for customers not API-affine |
| Switching & transfer method | Fully automated API-based export (REST/HTTPS), authentication via API key/JWT | Manual or partially automated export |
| Transfer / data formats | JSON (application/json); partly also multipart/form-data or application/x-www-form-urlencoded (especially for file uploads); Base64-encoded files | Excel, CSV |
| Covered data (selection) | Company and establishment data, employee master data, contract data, tax and social security data, remuneration components, carry-forward values | Master data, selected transaction and reporting data |
| Limitations | Technical implementation required; data in Paychex domain logic; pagination and rate limits; business mapping required | Not fully standardized; limited automation; higher manual effort |
If you wish to switch to another provider of data processing services that covers the same type of service, we generally recommend switching via our Public API.
Information pursuant to Art. 28 EU Data Act
Details on the jurisdictions to which our ICT infrastructure is subject and on measures to prevent access by foreign authorities
1. Details on the jurisdictions to which our ICT infrastructure is subject
The ICT infrastructure used to provide the contractual services is operated exclusively in data centers within the European Union, in particular in Denmark. Data processing takes place exclusively on servers physically located in the European Union. Access rights to the data are granted exclusively to employees entrusted with this task in Germany and Denmark, limited to the extent necessary in each case (need-to-know principle).
Due to the physical location of the infrastructure, its operation is primarily subject to the law of the European Union and to the respectively applicable Danish law, including the General Data Protection Regulation (GDPR) and the national regulations on IT security.
2. Indirect third-country references – measures to prevent access by foreign authorities
Our ultimate parent company in the United States, Paychex Inc., has no access to data that is the subject of the contractual service provision. However, as a company based in the United States, Paychex Inc. could in theory, and within narrow limits, be required by US authorities for purposes of law enforcement, national security or counter-terrorism to disclose data stored by us in Europe. To date, no such request has been made.
In the event of such a request, we would refer to our legal obligations to protect our customer data, as well as to the applicable European, and Danish legal provisions restricting disclosure. We would further direct the requesting authority to the relevant intergovernmental mutual legal assistance agreements.
1. Exportable Data (Input and Output Data)
Below you will find an overview of all generally exportable data categories.
Please note that the specific scope may vary depending on the selected export or transfer method (Public API or master data and Excel exports) (see export /transfer methods / Export- bzw. Übertragungsmethoden).
1.1. Company Data
- Account owner’s username
- Name, legal form
- Company registration number(s)
- Payroll start month
1.2. Employee Master and Contact Data
- Employee ID, personnel number
- Status (active/inactive/future)
- First name, last name
- Email address (optional)
- Street, house number, postal code, city, country, state
- Phone/mobile (optional)
1.3. Payment Data (Employee Bank Details)
- Account holder
- IBAN, BIC
- Bank name (optional)
- Indicator “Payment by bank transfer”
- NemKonto
1.4. Contract and Employment Data
- Job description (optional)
- Date of employment
- Exit date (if applicable)
- Reason for leaving (if applicable)
1.5. Pension Plan Data
- Whether contributions are paid into a group life insurance policy
1.6. Cost Center Allocation per Employee
- Reference to company cost center (if applicable)
1.7. Ongoing Remuneration Components / Wage Types
- Reference to wage type / remuneration component
- Amount / quantity / factor / percentage
- Validity (from/to month) (if applicable)
1.8. Carryover Values (Year)
- Balances for AM contributions (labour market contributions)
- Balances for A-tax (withholding tax)
- Where applicable, special carryovers for voluntary health insurance, unemployment insurance, etc.
2. Metadata
Metadata is descriptive information relating to the Exportable Data. Where necessary, it is provided to ensure comprehensibility and interoperability:
- 2.1. Designations and technical descriptions of wage types and deduction types (e.g., “base salary”, “overtime compensation”, “capital-forming benefits”, “private health insurance”).
- 2.2. Information on the data formats used, units, as well as date and time specifications (e.g., currency, payroll month, service period, due date, date formats used such as DDMMYYYY hh:mm:ss).
- 2.3. Structural and organizational information relating to the payroll data (e.g., table structure, field logic, references between master data and transactional data).
- 2.4. Information on the origin of individual data fields.
- 2.5. Timestamps relating to changes, entries, or processing, insofar as these are necessary to understand the functional context of the payroll results or their history.
3. Non-Exportable Data
The following data categories are specific to the internal functioning of the data processing service and are therefore excluded from exportable data, as their disclosure would pose a risk of violating trade secrets. There is no risk of obstruction or delay to switching pursuant to Article 23(c) of the Data Act.
- Log and protocol data that serve exclusively to document access, system usage, or provisioning processes, insofar as they are not themselves part of the data to be made available to the user.
- Internal testing and validation logs (e.g., rules for plausibility checks of wage types, validation matrices, technical rule sets for error detection), insofar as their disclosure would reveal trade secrets or the contractor’s internal system logic.
- Source code
- Scripts and other technical components used to generate work results, insofar as their disclosure would concern trade secrets or protected internal implementations.
- Internal database structures, relationships, linkages, and query logic (e.g., joins), insofar as their disclosure would allow conclusions about the internal system architecture or enable reverse engineering.
- Internal reference and configuration data used to map tax, social security, or company-specific rules (e.g., internally maintained parameter tables, calculation logics and algorithms), insofar as these are not already accessible as legally published regulatory frameworks and their specific implementation constitutes a trade secret.


