Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does AdRoll Work in China? PIPL Consent, Profiling & Cross-Border Ad Data

AdRoll (NextRoll) is a retargeting and display-advertising platform that drops a cookie to build a behavioral profile and chase visitors across ad exchanges — and NextRoll states its servers and the data it collects sit in the United States, with no mainland-China region. For a China audience that turns an ad pixel into personal-information processing that needs PIPL consent, carries automated-decision and profiling duties, and makes a cross-border transfer — before China's advertising-content rules and an ICP filing even enter. A compliance-first look at the consent, profiling, residency and licensing exposure, and the lawful in-country path.

Does AdRoll work in China?

The real question isn't whether AdRoll's tag loads in China — it's whether you may collect what it collects and send it where it goes. AdRoll (NextRoll) builds a behavioral profile from cookies to retarget visitors, and for a mainland audience that makes an ad pixel a privacy-law matter, not a performance one.

NextRoll states in its own Help Center that “our servers and facilities that maintain our websites, services, and the data we collect are also located in the United States,” and its storage sub-processor (AWS) is listed only for “USA and Europe” — no mainland-China region. So the cookie IDs, IP addresses and hashed email the tag gathers from your China visitors are personal information collected on a PIPL lawful basis, in practice consent (Article 13); shared with ad partners (a separate consent under Article 23); used for automated profiling (Article 24); and moved offshore as a cross-border transfer (PIPL Articles 38–39: notice, a separate consent, a transfer mechanism), which may trigger a data-export security assessment. For a critical information infrastructure operator or large-volume handler, Cybersecurity Law Article 39 (formerly Article 37) and PIPL Article 40 require that data to stay in China. And the site that carries the tag needs an ICP filing, with China's advertising rules on top.

This is a risk map, not a verdict — what actually bites turns on what you collect, your data volumes, your role as handler and who your users are, and it's worth settling with counsel. 21YunBox never uses or suggests any form of circumvention. Our China team can map your exposure with you →

What AdRoll's own documentation says about China

FactPrimary source
NextRoll says the servers and data behind AdRoll are in the United States. On its own Help Center, NextRoll states: “NextRoll's headquarters are in the United States, and our servers and facilities that maintain our websites, services, and the data we collect are also located in the United States.” It names no mainland-China region — so the data an AdRoll cookie generates from your China visitors comes to rest offshore, a cross-border transfer of personal information under PIPL (Articles 38–39). NextRoll (AdRoll) Help Center — NextRoll FAQs: International Data Transfers, retrieved 2026-10-09; PIPL Articles 38–39
AdRoll's only disclosed storage locality is “USA and Europe” — there is no China region. NextRoll's sub-processor list names Amazon Web Services for “Storage” with location “USA and Europe,” the sole storage locality it discloses. With no in-country region on offer, there is nowhere in the mainland for the ad data to live, and nothing to attach an ICP filing to. NextRoll Sub-Processors (nextroll.com), retrieved 2026-10-09
The AdRoll tag collects personal information, not anonymous counts. Per NextRoll's own FAQ, the data collected through its technologies on customers' sites includes “browser data, such as IP addresses and time stamps, as well as unique cookie IDs, and sometimes a hashed email address.” Under PIPL those identifiers are personal information, so collecting them from mainland visitors needs a lawful basis — in practice, consent (Article 13) — and provision to ad partners adds a separate consent (Article 23). NextRoll (AdRoll) Help Center — NextRoll FAQs: International Data Transfers, retrieved 2026-10-09; PIPL Articles 13, 23
The only cross-border mechanism NextRoll names is the EU's Standard Contractual Clauses — a GDPR tool, not a PIPL one. NextRoll's FAQ states that because it is US-based, “the legal mechanism that NextRoll and its customers rely on is the European Commission's Standard Contractual Clauses (‘SCCs’).” China's PIPL requires its own mechanism for transfers out of the mainland — a CAC security assessment, the CAC standard contract, or certification (Articles 38–39) — which the SCCs do not satisfy. NextRoll (AdRoll) Help Center — NextRoll FAQs: International Data Transfers, retrieved 2026-10-09; PIPL Articles 38–39

Sources verified by the 21YunBox compliance team on 2026-10-09.

The question teams ask about AdRoll in China is usually whether the tag fires — whether the retargeting pixel loads and the ads come back. For a mainland audience that is the wrong test. AdRoll, the advertising brand of NextRoll, works by dropping a cookie on your site, recording who visits and what they do, and using that behavioral profile to follow them with display ads across ad exchanges. The moment that tag fires on a visitor in China it has collected personal information and started moving it offshore — and how fast it loaded has no bearing on whether you were allowed to do either. The decision is a compliance one: consent and profiling duties under China’s privacy law, a cross-border transfer of the data, the advertising-content rules on what you then serve, and an ICP filing on the site that carries the tag. NextRoll answers the data-location half in its own words.

AdRoll Help Center article 'NextRoll FAQs: International Data Transfers' stating that NextRoll's headquarters are in the United States and that the servers and facilities maintaining its websites, services and the data it collects are also located in the United States — naming no mainland-China region
AdRoll's own Help Center, on international data transfers: “NextRoll's headquarters are in the United States, and our servers and facilities that maintain our websites, services, and the data we collect are also located in the United States.” The data a Chinese visitor's cookie generates comes to rest offshore — and no mainland-China region is named. Source: AdRoll Help Center — NextRoll FAQs: International Data Transfers

AdRoll in China at a glance

What decides it In AdRoll's own terms — and China's law
What it is AdRoll (NextRoll) is a retargeting and display-advertising platform. It places a cookie and web beacon on your site, collects browser data — IP addresses, time stamps, unique cookie IDs, sometimes a hashed email — and builds a behavioral profile to retarget visitors with ads across ad exchanges.
Is the tag reachable? Not where the China question is settled. Even if the pixel loads, the instant it fires on a mainland visitor it has collected personal information and begun a cross-border transfer. Offshore ad-exchange and tag domains can be inconsistent from the mainland — an operational matter, below, not the decision.
What the cookie collects Per NextRoll's own FAQ, the data gathered through its technologies on customers' sites includes “browser data, such as IP addresses and time stamps, as well as unique cookie IDs, and sometimes a hashed email address.” Under PIPL those identifiers are personal information, so collecting them needs a lawful basis — in practice, consent (Article 13).
Profiling for ads Retargeting is automated decision-making used for commercial marketing. PIPL Article 24 adds transparency and fairness duties and requires a genuine option not targeted to the individual's personal characteristics, or an easy way to refuse.
Where the data lives NextRoll says its servers and the data it collects are “located in the United States,” and its storage sub-processor (AWS) is listed only for “USA and Europe.” No mainland-China region — so collecting China data into it is a cross-border transfer (数据出境) under PIPL (notice, a separate consent, a transfer mechanism), with a possible data-export security assessment above thresholds.
Serving the public The site that carries the tag and shows the ads is a public internet information service in the mainland: an ICP filing bound to in-country hosting, with China's advertising-content rules applying to the creative itself.

The uncomfortable part for a retargeting platform is that its raw material is personal information. In its own FAQ, NextRoll describes the data it collects through AdRoll’s technologies as “browser data, such as IP addresses and time stamps, as well as unique cookie IDs, and sometimes a hashed email address.” Under China’s Personal Information Protection Law those online identifiers are personal information, so firing the tag on a mainland visitor is processing that needs a lawful basis — and for behavioral advertising that basis is, in practice, informed consent obtained before the cookie is set (PIPL Article 13).

Consent does not stop at collection. Retargeting works by handing that visitor data to NextRoll and to the ad partners and exchanges it bids into — a provision of personal information to third parties, which under PIPL Article 23 requires its own notice and a separate consent, distinct from any blanket agreement to use your site. The data then leaves the country, which triggers a further separate consent of its own (below). The point is structural: an ad tag that quietly does all three is not discharged by a single cookie banner.

Retargeting is automated decision-making — Article 24’s profiling duties

Building a profile to decide which ad chases which user is the textbook case of what PIPL Article 24 governs: automated decision-making used for information push and commercial marketing. The article requires that the process be transparent and its outcomes fair, and — specifically for marketing aimed at individuals — that you offer an option not based on their personal characteristics, or a convenient way to refuse it. A China-facing campaign that only knows how to target by profile does not meet that on its own; the opt-out and the non-profiled path have to be built into the flow. Whether any of your identifiers rise to “sensitive” personal information, and what your notice must say, are questions to settle with counsel.

The behavioral profile comes to rest offshore — a cross-border transfer with no China region

Where that profile is stored decides the rest. NextRoll states in its Help Center that “our servers and facilities that maintain our websites, services, and the data we collect are also located in the United States,” and its sub-processor list names Amazon Web Services for storage in “USA and Europe” — the only storage locality it discloses. Neither is in the mainland. So the cookie and behavioral data AdRoll gathers from your China users is held offshore, which makes its collection a cross-border transfer (数据出境) under PIPL: the handler — you, not NextRoll — owes notice, a separate consent for the overseas transfer, and one transfer mechanism, a CAC security assessment, the CAC standard contract, or certification (Articles 38–39). Above certain volumes, or where the data is “important data,” China’s data-export security assessment (数据出境安全评估) may apply before anything leaves.

Two things follow. First, the mechanism NextRoll actually relies on is the EU’s Standard Contractual Clauses — its FAQ names “the European Commission’s Standard Contractual Clauses (‘SCCs’)” — and those are a GDPR tool, not a PIPL one; they do nothing for a transfer out of mainland China. Second, flipping NextRoll’s setup from its US to its EU environment changes nothing here: the EU is still outside the mainland, so it relocates the cross-border transfer rather than ending it. And for a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in China — Cybersecurity Law Article 39 (formerly Article 37 — the 2025 amendment that took effect on 1 January 2026 renumbered the data-localization provision without changing its substance); PIPL Article 40 — a duty an offshore ad platform cannot satisfy no matter how its regions are tuned.

Two more doors — China’s advertising rules and the ICP filing on the site

The data story is not the whole story. What you serve through AdRoll is advertising shown to people in China, so China’s Advertising Law applies to the creative — the claims it can make, the categories it can promote, and the review duties that sit on the advertiser and the platform. That is a content and licensing question separate from where the cookie data lives, and it does not go away because the ads are served from offshore.

And the site that carries the AdRoll tag and renders the ads is itself a public-facing service in the mainland. Served to Chinese visitors from inside China, it turns on an ICP filing (ICP 备案) bound to a hosting resource physically in the country — which AdRoll provides none of, because it has no mainland region to attach one to. “We already run AdRoll” does not carry across the border; the delivery footing the tag needs is a separate thing to stand up.

None of this is a ruling that AdRoll is banned in China. It is a risk map: which duties actually bite depends on what your tag collects, your data volumes, your role under Chinese law, and who your users are — worth settling with counsel before a campaign relies on it.

The lawful path — map, localize, deliver

There is a compliant way to run advertising for a China audience, and it starts by separating the legal question from the technical one.

First, map. Our China compliance team works through what your AdRoll tag actually collects from mainland visitors — cookie IDs, IP addresses, any hashed identifiers — and charts the duties that attach: the consent and notice your flow must capture before the pixel fires, the separate consent that provision to ad partners and the cross-border transfer each require, the Article 24 options you owe on profiled marketing, where a data-export security assessment or an in-country storage duty bites, and what China’s advertising rules demand of the creative. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.

Then localize. We stand up a consented, in-country, PIPL-compliant way to run the audience building and measurement that matters for China — the China-side data processed and stored on mainland infrastructure, on a lawful basis, rather than shipping each visitor’s profile offshore by default — while you keep AdRoll for the markets where it already serves you. The shape is a lawful in-country pattern, not a workaround bolted onto an offshore network.

Then deliver. The China-facing site that carries the tag and shows the ads is a public service in the mainland, so it needs an ICP filing and compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is advertising that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is route personal information out of China by stealth or slip past any network restriction; we keep what must stay in-country and deliver the rest in the open.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is AdRoll blocked in China?
Reachability is not where the AdRoll question is settled. Even where the tag fires, the moment it does on a mainland visitor it has collected personal information — cookie IDs, IP addresses, sometimes a hashed email — and begun moving it to NextRoll's US servers. That makes AdRoll a PIPL matter (consent on collection, a separate consent to share it and to transfer it offshore, Article 24 duties on profiling), not a speed one. Offshore ad-exchange domains can be inconsistent from the mainland, but that is operational, not the decision — and the answer is never a network workaround. Confirm your exact obligations with counsel.
Is sending AdRoll data to the US a cross-border transfer under PIPL?
Yes. NextRoll states its servers and the data it collects are in the United States, with storage in “USA and Europe” and no mainland-China region. So the cookie and behavioral data AdRoll gathers from your China visitors is held offshore — a cross-border transfer (数据出境) requiring notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and possibly a data-export security assessment above thresholds. The EU SCCs NextRoll relies on are a GDPR mechanism and do not satisfy PIPL. For a critical information infrastructure operator or large-volume handler, data localization (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) requires the data to stay in China.
Can 21YunBox make our AdRoll setup work in China?
Our China team can map the exposure — what the tag collects, the consent and notice your flow must capture before it fires, the separate consent that sharing and the cross-border transfer require, the Article 24 options you owe on profiled marketing, and what China's advertising rules demand of the creative — for your entity, data volumes and users. Where the data has to stay in-country, we localize the China audience building and measurement onto a consented, PIPL-compliant, in-country setup, and we deliver the China-facing site that carries the tag on ICP-filed infrastructure, in front of what you already run. We never use or suggest circumvention of any kind. Get in touch to work through your case.

ARTICLES RELATED TO ADROLL

CATEGORIES

Advertising

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.