Rules and ethics
Part of Payroll compliance in 2027 starts with a map of the rules, not a marketing claim
The UK rule areas that reach into payroll software, from PAYE to marketing claims
Map the main UK rule areas affecting payroll software used in England, including PAYE, pensions, data protection, security, access and claims.
There is no single "payroll software law" that certifies an entire product. A supplier serving England must map the rules and official processes that apply to its calculations, submissions, pension functions, personal-data role, contract, marketing and operational design. This overview is orientation, not legal or tax advice.
PAYE calculation and reporting
HMRC's running payroll guide describes work around payday, including recording pay, calculating deductions, producing payslips and reporting through a Full Payment Submission. The PAYE developer collection links technical specifications and test resources.
Maintain a versioned inventory of supported tax years, calculations, fields, exceptions and customer situations. Apply current guidance to actual facts rather than treating an old implementation as permanently correct.
HMRC recognition has a narrower meaning. The official list says recognised products can report PAYE online, while HMRC does not recommend one product over another. Do not present recognition as approval of the whole service.
Workplace pension duties
The Pensions Regulator says automatic enrolment duties continue after setup. Its ongoing duties guidance covers monitoring, contributions, worker requests, records and re-enrolment.
A supplier should state which pension tasks it performs and which remain with the employer, bureau or pension provider. Test named formats, tax-relief methods and rejection paths. Software does not transfer the employer's legal responsibility merely by automating a calculation.
Personal data and employment records
Payroll processing can involve identity, pay, deductions, bank and absence information. The ICO's employment information guidance provides current worker-data resources under the UK GDPR and Data Protection Act 2018.
Determine controller, processor and sub-processor roles from actual decisions and instructions. Document purpose, lawful basis, transparency, minimisation, retention, rights, security, transfers and incident handling. The Data (Use and Access) Act 2025 amended rather than replaced the existing data-protection framework, so use current ICO material.
Access and software security
HMRC's web-services access policy says third parties must not request, collect or use HMRC sign-in details belonging to someone else. It also states HMRC's position on automating navigation of Government Gateway.
The voluntary Software Security Code of Practice supplies a current government security benchmark for developers and vendors. Assess which legal, contractual and good-practice controls apply rather than calling voluntary guidance a statutory certification.
Contracts, service information and marketing
Contracts should define parties, supported service, customer inputs, access, payment, change, support, liability, termination and export. B2B, consumer and data-processing terms can require different analysis. Obtain legal review where exposure is material.
Marketing must match evidence. The CAP Code's misleading advertising section covers substantiation, material information, prices, comparisons and testimonials. Payroll claims such as "error free", "fully compliant" or "HMRC approved" need especially careful scrutiny.
Keep a compliance register containing requirement, scope, source, owner, control, evidence and review date. Reopen it at each tax year, material product change and legal update. The responsible conclusion is never that a product is universally compliant, but that a defined version supports stated workflows under a maintained, reviewed control set.
Assign every register entry to someone able to investigate and pause release. Record customer impact, workaround and expiry for unresolved matters. After launch, use submission errors, pension rejections, access incidents, complaints and corrections to test whether the mapped controls work in practice.