Does Alteryx Work in China? Data Residency, Localization & PIPL Cross-Border
Alteryx Designer and Server run on infrastructure you control, so they can run in-country; but the Alteryx Analytics Cloud — now the Alteryx One Platform — is hosted on Google Cloud in the US, Australia and Germany, with no mainland-China region, so China data blended there rests offshore. A compliance-first look at where your analytics data is allowed to live.
Does Alteryx work in China?
Reachability was never the question — residency is. Alteryx Designer and Server run on infrastructure you control, so they can run in-country; but the managed Alteryx Analytics Cloud (now the Alteryx One Platform) has no mainland-China region, so any China personal information you blend or extract there rests offshore — a PIPL cross-border transfer, not a hosting detail.
In Alteryx's own words the platform “is hosted using Google’s Cloud Platform, currently offering hosting in the following locations”: the United States, Australia and Europe (Germany) — none in mainland China, and without Private Data Handling “an extract of the data is stored on our cloud.” Because a workflow blends records from many source systems into extracts, in-memory data and cached result sets, it concentrates customer, user and employee personal information — so moving mainland data into an offshore workflow is a cross-border transfer PIPL governs (notice, separate consent, a transfer mechanism), and for a critical-information-infrastructure operator or high-volume handler, data the law says must stay in the mainland and an offshore cloud cannot hold. Self-hosting Server on mainland infrastructure keeps it in-country.
This is a risk map, not a verdict — whether you owe in-country storage, a transfer mechanism, or both turns on your entity, your data volumes and whose personal information your workflows touch. Our China team can map your exposure →
What Alteryx's own documentation says about China
| Fact | Primary source |
|---|---|
| Alteryx's managed Analytics Cloud has no mainland-China region. Alteryx's own help documentation states the Alteryx One Platform — the managed Analytics Cloud, including Auto Insights — “is hosted using Google’s Cloud Platform, currently offering hosting in the following locations”: the United States, Australia and Europe (Germany). None is in mainland China, so data you blend or extract into the hosted platform comes to rest offshore; without Private Data Handling, Alteryx adds, “an extract of the data is stored on our cloud.” | Alteryx Help — Where Is Auto Insights and My Data Hosted? (help.alteryx.com), retrieved 2026-10-10 |
| Designer and Server run on infrastructure you control — the in-country lever. Alteryx Designer is a desktop-authoring tool that runs on your workstation, and Alteryx Server is self-managed: its install guide lists as a prerequisite “Admin access to the host server’s operating system or physical access to the server hardware.” Because you choose the host, you can deploy Server on mainland-China infrastructure and keep the data a workflow blends inside the country. Alteryx is not blocked — the processing happens where you deploy it. | Alteryx Help — Install or Upgrade Server (help.alteryx.com), retrieved 2026-10-10 |
| Blending China personal information into an offshore workflow is a cross-border transfer. Alteryx pulls from many source systems and builds extracts, in-memory data and cached result sets — each personal information in its own right. Routing mainland records into an offshore Analytics Cloud workflow moves them across the border: PIPL requires notice, separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). | PIPL Articles 38–40 (gov.cn); 21YunBox compliance analysis |
| A BI platform's data concentration can trigger an in-country storage duty. Because Alteryx consolidates personal information from across the business into one place, a single deployment is often among the largest concentrations of China personal data a company holds — which can push a handler over the regulated-volume threshold. A critical information infrastructure operator, or a handler above those thresholds, must store mainland personal information in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), which an offshore managed cloud structurally cannot do. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) (gov.cn) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a team serving mainland China, the question about Alteryx was never whether Designer opens or the Analytics Cloud console loads — it usually does. The question is where the records a workflow blends are allowed to come to rest. A data-prep and analytics platform pulls from many systems at once — CRM, ERP, databases, files — and stages the result, so one workflow concentrates customer records, user accounts, transactions and employee PII from across the business. Alteryx, taken private in 2024 by Clearlake Capital and Insight Partners, ships in three shapes: Designer, the desktop tool that runs on your workstation; Server, self-managed software you install on a host you control; and the managed Alteryx Analytics Cloud — now the Alteryx One Platform — hosted on Google Cloud Platform in the United States, Australia and Europe (Germany), with no mainland-China location. The first two run where you deploy them; the managed cloud rests offshore.
Alteryx in China at a glance
| What decides it | In Alteryx's own terms — and China's law |
|---|---|
| Where the data physically rests | The managed Alteryx Analytics Cloud (the Alteryx One Platform, including Auto Insights) is, in Alteryx's words, "hosted using Google's Cloud Platform, currently offering hosting in the following locations" — the United States, Australia and Europe (Germany). None is in mainland China. Designer runs on your workstation and Server installs on a host you control ("Admin access to the host server's operating system or physical access to the server hardware"), so those rest wherever you deploy them. |
| What it holds, and why it's personal information | Alteryx blends and preps data from many source systems into extracts, in-memory data and cached result sets — each personal information in its own right. One workflow can carry customer records, user accounts, transactions and employee PII, including Article 28 sensitive fields: financial, government-ID, location or health data. By design it is one of the largest single concentrations of China PI you hold. |
| Your mainland records on the platform | Records sourced in China and blended into an offshore Analytics Cloud workflow — or kept there, since without Private Data Handling "an extract of the data is stored on our cloud" — are a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). |
| In-country storage duty | A critical information infrastructure operator or large-volume handler owes an in-country storage duty the offshore cloud cannot meet — mainland personal information must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged), and Alteryx's data concentration can push you over the triggering volume threshold. |
| Is it reachable? | Treat reachability as the delivery half, not the question — Alteryx is not blocked. Designer and Server run in-country where you deploy them (the lawful lever), and any China-facing surface — a reporting portal, a data app, an intake form — also needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33). |
Where the data actually rests
Alteryx is explicit about where its managed cloud runs. Its own help documentation states the Alteryx One Platform — the managed Analytics Cloud, including Auto Insights — “is hosted using Google’s Cloud Platform, currently offering hosting in the following locations”, and the three it then lists are the United States, Australia and Europe (Germany). Not one is in mainland China; Australia is the nearest, and it sits well outside the border. That region set is chosen for you when your tenant is provisioned, from an offshore list. So when a workflow reads a mainland source — a transactional database, an application export, a file drop — and blends it in the Analytics Cloud, the records, and the extracts and cached result sets built from them, are processed and stored offshore. Under China’s Personal Information Protection Law, sending personal information collected in the mainland to one of those regions is a cross-border transfer — and the handler on the hook is you, the customer, not the vendor.
Alteryx does offer a Private Data Handling option, where the processing cluster and data sit inside a VPC your organization provisions rather than on Alteryx’s own cloud; without it, Alteryx notes, “an extract of the data is stored on our cloud.” That option narrows what the hosted cloud holds, but it is not automatic in-country compliance: the control plane remains Alteryx’s, and the VPC is provisioned in a region you select — which, on the Analytics Cloud’s clouds, is still not a mainland-China region. Designer, meanwhile, runs on the analyst’s own workstation, and Server is software you install and run yourself. Where those sit is your decision, and that is precisely the point this page turns on.
What it holds is personal information
Most tools hold one slice of your data. A data-prep and analytics platform, by design, reaches across all of it: it is the place every source system is pulled together, joined and staged. That breadth is the risk. The rows flowing through an Alteryx workflow carry the names, emails, account numbers, order histories and device identifiers of your China customers, and the payroll, identity and HR fields of your China employees — personal information the moment it describes an identifiable person, and governed by PIPL on export. The exposure sharpens because the platform does not just pass data through: it materializes it, building extracts, in-memory data and cached result sets that are themselves personal information and that have to rest somewhere. A single workflow can concentrate Article 28 sensitive personal information — financial records, government-issued IDs, precise location or health data — pulled from several systems into one place, which carries a higher bar under PIPL: a specific purpose, strict necessity, and separate consent.
That concentration is also what makes the residency question acute. Because Alteryx consolidates personal information from across the business, a single deployment is frequently among the largest concentrations of China personal data a company holds — which can push a handler over the regulated-volume threshold. For a critical information infrastructure operator, or a handler above those thresholds, personal information collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and an offshore managed cloud structurally cannot satisfy that localization duty. And for a handler that crosses the data-export security assessment threshold on volume or sensitivity, the whole export may need a CAC-led review before any of it lawfully leaves.
Running it on a no-China-region managed cloud doesn’t meet the residency duty — and what does
Here is the honest shape of it. The managed Alteryx Analytics Cloud has no mainland-China region, so where a data-localization duty applies it structurally cannot keep the data in-country — not because Alteryx is deficient, but because the region simply is not on the list. The lawful lever is the deployment shape Alteryx already gives you: Server is self-managed software you install on a host you control, and Designer runs on the analyst’s workstation. Run Server on mainland-China infrastructure and point the workflows that touch mainland records at it, and the data a job blends, and the extracts and result sets it builds, stay inside the country. No migration off Alteryx is required — the same product, deployed where the law needs it. Reaching the console was never the test; residency is, and residency follows where you deploy. This is a risk map, not a verdict — whether you owe a transfer mechanism, a separate consent, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes, how much of what your workflows touch is personal or sensitive, and who your users are, and is worth settling with counsel before you route a single mainland record through the platform.
The lawful path — map, localize, deliver
You do not have to drop Alteryx to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and for a platform like this, a partner that sits alongside the tool you already run, not a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization obligations against your actual entity, your data volumes, and whose personal information your workflows touch — so the exposure across the data estate Alteryx concentrates is written down before anything is rewired.
Localize. Localize means running the platform in-country, not tunneling back to an offshore endpoint. Because the managed cloud has no mainland region, we help you self-host Alteryx Server on mainland infrastructure — paired with in-country workstations for Designer where that fits — so the personal information China requires to stay in-country does, while only the minimized, lawfully transferable subset ever reaches an offshore tenant. Where a licensed in-country or sovereign managed option fits better, we stand that up instead.
Deliver. For any China-facing surface — a reporting portal, an embedded analytics app, a data-intake form — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase, no move off the platform. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your analytics program runs legally and compliantly for your users in China.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization
- China’s data-export security assessment measures
