Your Payroll Provider Knows How Much Your CEO Earns. So Does Their Cloud Infrastructure Provider.
Payroll Data Chain-of-Custody Analysis in Multi-Tenant Cloud Software Architecture
---
Last month, your payroll software filed your DSN. That's the Déclaration Sociale Nominative — the mandatory monthly report filed with URSSAF, the agency that collects social security contributions, declaring every employee's salary, social security number, sick days, and deductions. Filing went through. URSSAF received it. Payroll ran.
What didn't appear on your dashboard: the data made a detour first, stopping on an Amazon or Microsoft server where it joined every previous filing you've made since signing up. You didn't explicitly authorize that stop. You agreed to it in the terms of service you accepted when you created your account — paragraph 14 or 17, depending on the vendor.
Filing status: complete. Data chain: not what you think.
---
Two Transactions in One Sign-Up
Choosing cloud payroll software meant making two transactions simultaneously.
First: you paid for automation. DSN files on time. Payroll runs without manual calculations. Deadlines stop being a source of dread. That transaction was explicit and you got what you paid for.
Second: you granted a third party permanent custody of your company's complete salary history and your employees' social security numbers. Every monthly filing adds to it. A company that has used cloud payroll software for five years has uploaded 60 months of payroll records — every salary negotiation, every sick day, every hire and departure, all sitting on infrastructure outside your control. That transaction was invisible in the sign-up flow.
Chain of custody is a term from criminal investigations: who touched this evidence, when, and what did they do with it? Payroll data has a chain too. Liberté's chain is two steps: your machine, then net-entreprises.fr, the government's own portal. Most cloud payroll software's chain runs to six or more stops.
---
Reading the Sub-Processor List
Your payroll vendor is legally required to maintain a list of sub-processors — every third party with access to your data. Reading it takes five minutes. Most French business owners never do.
Typically the list runs 8-15 entries. Not just the cloud provider — also the monitoring tool (Datadog or New Relic), the customer support platform (Zendesk or Intercom), the content delivery network (Cloudflare), the backup service. Each of these has technical access to some part of the infrastructure processing your employees' data. This list updates quarterly. You're rarely notified when it changes.
Names behind the cloud infrastructure are well-known. Payfit runs French client data on AWS EU in Frankfurt. Silae — used by thousands of expert-comptables (the accountants who handle French business compliance) for their clients' payroll — runs on Microsoft Azure. Pennylane, which combines accounting and payroll, stores data on Google Cloud. All three cloud providers are US companies.
This matters because of a law signed in Washington on March 23, 2018.
---
CLOUD Act, GDPR, and the Conflict Between Them
Signed March 23, 2018, the Clarifying Lawful Overseas Use of Data Act — the CLOUD Act — authorizes US law enforcement to compel US companies to disclose data stored anywhere in the world, including EU data centers, without notifying the data subjects and without needing a French court order.
Payfit runs on AWS. AWS is a US company. The CLOUD Act means the US government can request your employees' salary and social security data from Amazon — without telling you, without telling your employees, and without going through French courts first.
Compliance paperwork addresses a different question. A signed data processing agreement (DPA) means the vendor documented their sub-processors. It does not mean the data is architecturally private. A company can be fully GDPR-compliant and still store your employees' data on US cloud infrastructure subject to CLOUD Act requests — both statements are simultaneously true because they answer different questions. France's data protection authority, the CNIL, confirmed this legal conflict in a 2023 ruling: a French company received a €600,000 fine for transferring employee data to US servers, with the CNIL specifically noting that standard contractual clauses cannot fully resolve the tension between GDPR and the CLOUD Act.
---
What Each DSN Filing Actually Contains
A single DSN declaration for a 20-person company contains 200+ sensitive data fields. Social security numbers for every employee. Gross salary and net salary. Sick days and medical leave periods. Any wage garnishments. Employer social contribution amounts. Filed every month. Accumulated year over year.
GDPR Article 9 classifies health-related data — including sick days and medical leave records in payroll filings — as "special category" data requiring the highest protection level. France requires HDS certification (Hébergeur de Données de Santé — specific French accreditation for health data hosting) for medical record storage, with strict geographic and audit requirements. Medical records get regulated hosting and French geographic requirements. Payroll records containing the same categories of health data? Stored on American cloud servers, no equivalent requirement.
Data accumulates with time. Standard cloud payroll contracts retain data 3-7 years after cancellation. Switching software doesn't delete what's already been uploaded. Five years of Payfit or Silae means 60 months of complete payroll history remains on their infrastructure after you leave.
Nobody on your team agreed to any of this explicitly. Employment contracts were with you. As the legal data controller under GDPR, you carry the accountability for how their data is handled — even when it lives on your vendor's servers.
---
A Direct Route That Was Always Available
Net-entreprises.fr — the government portal that receives DSN declarations — has had a documented, publicly available machine-to-machine API since 2016. Any developer can read the specification at api.net-entreprises.fr today. Authentication via SIRET number and certificate. Submission to France's social security infrastructure directly.
Every cloud payroll software uses this API. So does Liberté. Cloud software routes your data through their own servers first, stores it indefinitely, and passes it through a chain of sub-processors before it reaches the government. Liberté generates the DSN file on your machine and transmits it once, directly to net-entreprises.fr. Nothing stored in between.
Legal outcome: identical. DSN filed, on time, correctly. Data chain: entirely different.
Liberté handles French payroll with all 200+ variables — 35-hour week calculations, RTT (Réduction du Temps de Travail — additional leave days for companies on 35-hour weeks), mutuelle obligatoire (mandatory complementary health insurance), tickets restaurant, primes. Bulletins de paie (payslips) meet all seven mandatory zones required by French labor law. Same compliance your current software delivers. None of the data accumulation.
---
Stopping the Ratchet
Next month's DSN is already scheduled. After you file it through your current cloud payroll software, your employees' data lands on a server in Frankfurt and stays there for years.
Switching to Liberté stops the accumulation from continuing. What's already on other platforms stays there — and next month's filing creates no new copies, touches no sub-processors, and leaves no trail on American cloud infrastructure.
Setup takes less than an hour. Your next DSN can go directly to net-entreprises.fr — the same declaration, correctly filed, with nothing stored in between. Free.
Employees negotiated their salaries in a conversation with you. That data should travel two places: into your payroll records, and to the government. Not to Amazon. Not to Microsoft. Not to the eight sub-processors on the list you've never read.