Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Amplitude Work in China? Data Residency, PIPL Consent & Cross-Border Behavioral Data

Amplitude's SDKs and ingestion endpoints are callable from mainland China, so reachability is not the real question. The decision is data residency and consent: Amplitude runs only two data centers — a US environment (US-West AWS) and an EU environment in Frankfurt — with no mainland-China region, so the event streams, user properties, and device identifiers your China-facing product collects rest offshore, making their collection a cross-border transfer (数据出境) under PIPL, while tracking identifiable individuals in China carries its own PIPL consent duty, and for a critical information infrastructure operator the Cybersecurity Law's in-country storage duty under Article 39 (formerly Article 37) is one an offshore region cannot meet. A compliance-first look at Amplitude's region availability, the data-residency and consent questions, and the lawful path.

Does Amplitude work in China?

Yes — Amplitude's SDKs and ingestion endpoints are callable from mainland China, so the honest answer is that reachability is not the problem. What decides the China question is data residency and consent.

Amplitude runs no data center in mainland China; its own documentation lists only two — a US environment on AWS and an EU environment in Frankfurt. So the event streams, user properties, and device identifiers your product collects from people in China come to rest offshore, which makes their collection a cross-border transfer (数据出境) under PIPL — requiring notice, a separate consent, and a transfer mechanism — and it may trigger China's data-export security assessment. Tracking identifiable individuals carries its own PIPL consent duty on top. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires such data to be stored in China, which neither Amplitude region can satisfy.

21YunBox maps your cross-border, residency, and consent exposure, localizes the China behavioral data onto a China-resident store (sending Amplitude only what may lawfully leave), and delivers your China-facing app in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Amplitude's own documentation says about China

FactPrimary source
Amplitude runs only two data centers — the US and the EU — with no mainland-China region. Amplitude's Trust, Security and Privacy page states, under “Data Residency”: “Amplitude maintains data centers hosted by AWS in the US and in the EU so that our diverse customer base can utilize our AI Analytics Platform while meeting their data storage and processing preferences and needs,” and that it “chose Frankfurt, Germany for our EU data center.” Amplitude, “Trust, Security and Privacy” (amplitude.com), retrieved 2026-10-08
Amplitude's ingestion API offers exactly two server zones — US (default) and EU — and no China zone. Amplitude's HTTP V2 API documentation states: “This API uses the event ingestion host api2.amplitude.com (default) or api.eu.amplitude.com (EU),” listing only the default (US) and EU base URLs. Amplitude Developer Docs, “HTTP V2 API” (amplitude.com), retrieved 2026-10-08
EU, EEA, and UK personal data is transferred into Amplitude's US-West AWS environment — the default region is offshore in the US. Amplitude's own page states that its EU-US Data Privacy Framework self-certification “provides a lawful mechanism for the transfer of personal data from the United Kingdom, EU, and EEA to our US-West-based AWS environment.” Amplitude, “Trust, Security and Privacy” (amplitude.com), retrieved 2026-10-08
China-collected behavioral data sent to an offshore account is a PIPL cross-border transfer. Moving personal information collected from users in mainland China to an Amplitude account hosted in the US or EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-08

Sources verified by the 21YunBox compliance team on 2026-10-08.

For a product measuring users in mainland China, the first instinct with Amplitude is to ask whether its SDKs can even reach it — and on the wire they can: Amplitude’s ingestion endpoints are callable from the mainland, and it is not a service China blocks at the border the way some foreign platforms are. So reachability is not where the China decision is settled. What settles it is data residency and consent — where the behavioral records Amplitude keeps about your users come to rest, and whether you had a lawful basis to track those users and move their data in the first place.

That is because Amplitude runs no data center inside mainland China. Its own documentation lists exactly two: a US environment on AWS and an EU environment in Frankfurt. The moment the event streams, user properties, and device identifiers your product gathers from people in China land in a US or EU Amplitude, you have made a cross-border transfer (数据出境) of personal information — and a different body of law decides whether that was allowed.

Amplitude's 'Trust, Security and Privacy' page, 'Data Residency' section, stating that Amplitude maintains data centers hosted by AWS in the US and in the EU, and that it chose Frankfurt, Germany for its EU data center — naming only two regions, with no mainland-China data center
Amplitude's own “Trust, Security and Privacy” page, under “Data Residency,” states: “Amplitude maintains data centers hosted by AWS in the US and in the EU so that our diverse customer base can utilize our AI Analytics Platform while meeting their data storage and processing preferences and needs.” The two regions it names are the US and the EU — its EU data center is in Frankfurt — so there is no mainland-China data center, and the behavioral and user data your China-facing product collects rests offshore. Source: amplitude.com — Trust, Security and Privacy

Amplitude in China at a glance

What decides it In Amplitude's own terms — and China's law
What it is Amplitude is a product-analytics platform. It ingests event streams, user properties, and device identifiers from your product and stores them in whichever region your account was provisioned in — so it holds a continuous behavioral record of identifiable users.
Is it reachable from the mainland? Yes. Amplitude's SDKs and ingestion endpoints (api2.amplitude.com by default, api.eu.amplitude.com for EU projects) are callable from China, and it is not blocked at the border. Reachability is not the China question. (Cross-border ingestion from the mainland to an offshore endpoint can be inconsistent — an operational matter, below, not the decision.)
Where does the behavioral data sit? Offshore. Amplitude documents only two data centers — a US environment (US-West AWS) and an EU environment in Frankfurt — and its ingestion API offers only a US (default) and an EU server zone. There is no mainland-China region.
Collecting China behavioral data into it The event streams, user properties, and device IDs are personal information. Holding them in a US or EU Amplitude is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Tracking identifiable individuals needs its own PIPL consent on top, and a data-export security assessment may apply above thresholds. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
The lawful path Keep the China behavioral and event data in a China-resident analytics or event store, send Amplitude only what may lawfully leave, keep Amplitude for your other markets, and deliver the China-facing app that emits the events in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention.

Availability: reachable — but where does the behavioral data live?

Amplitude’s position is set in its own documentation, not by a load-time test. Its HTTP ingestion API documents exactly two data-residency endpoints — the default host api2.amplitude.com and api.eu.amplitude.com for EU projects, selected by a server-zone setting in the SDK — and there is no China zone to choose. Its security page is just as plain: Amplitude keeps data centers only “in the US and in the EU.” Put together, the picture is unambiguous — your account, and every behavioral record in it, sits in one of two offshore regions.

So “does the SDK reach Amplitude from Shanghai?” is the wrong test. It reaches. The real question is where your China-collected behavioral data sits and whether it was allowed to leave the country at all. For that reason this page publishes no first-party China latency or reachability figure for Amplitude: speed is not the axis for a decision that turns on residency and consent. One operational note worth naming: cross-border ingestion from the mainland to an offshore endpoint can be inconsistent, and the temptation is to force it through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. The productive question is how to keep the China data on a lawful footing.

The data-residency question: offshore analytics is a cross-border transfer

Here is the gate most teams miss. An Amplitude account in the US or EU region is, by definition, outside the mainland. The event streams, user properties, and device identifiers it holds for your users in China are personal information, and loading them into an offshore Amplitude is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the product team, not Amplitude the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Above certain thresholds, or where the data is “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China — an in-country storage duty that an Amplitude account hosted in the US or EU simply cannot satisfy. None of this turns on how quickly an event is ingested; it turns on whether the data had a lawful basis to be there. Which of these bite your specific product is a risk to confirm with counsel against what you actually collect and store.

Residency is only half of it. Product analytics works by observing what identifiable people do — the pages they open, the taps they make, the funnels they move through, their retention over time — tied to a user ID or a device identifier. Under PIPL, that behavioral tracking is itself processing of personal information, and it needs its own lawful basis: in practice, informed consent obtained before the SDK begins collecting, with a clear notice of what is gathered and why. The cross-border transfer to an offshore Amplitude then needs a further, separate consent on top of that. Amplitude gives you controls that help here — filters for unexpected personally identifiable information, IP-address governance, and deletion and access-request APIs — and notes that many customers choose to send only anonymous or pseudonymous data. Those controls can genuinely reduce exposure, but they do not discharge the consent and notice duties, which sit with you as the handler. Whether your identifiers count as “personal information,” whether any field is sensitive, and what your consent flow must say are questions to settle with counsel.

Why pointing Amplitude at “a different region” isn’t the fix

The obvious move is to flip the server zone and keep the data in-region — but the only regions Amplitude offers are the US and the EU. Neither is in mainland China, so neither resolves a China residency duty; moving China behavioral data from the US zone to the EU zone merely relocates the cross-border transfer, it does not end it. Keeping China-collected behavioral data in-country means standing up a China-resident analytics or event store for that data, and sending to Amplitude only what may lawfully leave. That split — what must stay, what may go — is the heart of the work, and it is a legal question before it is a technical one.

The lawful path — map, localize, deliver

There is a lawful way to run analytics for a China-facing product, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the tracking and the transfer — identifying which event data, user properties, and identifiers collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your consent and notice flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a China-resident analytics or event store for the China behavioral data, so the measurement you depend on keeps working while that data stops leaving the country by default — and you keep Amplitude for the markets where it already serves you.

Then deliver: the China-facing app or site that emits those events — the screens your users actually tap — is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is China-facing analytics that run legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

====================================================================== ENHANCEMENT-JSON (insert into src/data/page-enhancements.json — keyed by permalink)

{

Frequently Asked Questions

Is Amplitude available in mainland China?
Amplitude's SDKs and ingestion endpoints are callable from the mainland — it is not a service China blocks at the border — so availability is not the obstacle. The real question for a China-facing product is data residency and consent: Amplitude runs only two data centers, the US and the EU (Frankfurt), with no mainland-China region, so the behavioral data you collect from China users rests offshore. Cross-border ingestion from the mainland to an offshore endpoint can be inconsistent, but that is an operational matter, not the decision — and the answer is never a network workaround. Treat the specifics as a risk to confirm with counsel.
Is sending China behavioral data to Amplitude a cross-border transfer?
If your Amplitude account is in the US or EU region — anywhere outside the mainland — then the event streams, user properties, and device identifiers it holds for your China users are stored offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and it may be subject to China's data-export security assessment. Tracking identifiable individuals also needs its own PIPL consent on top. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. Confirm your exact obligations with counsel.
Can I just switch Amplitude to a China region to keep data in-country?
No — the only regions Amplitude offers are the US and the EU, and neither is in mainland China, so neither resolves a China residency duty. Switching the server zone from US to EU merely relocates the cross-border transfer; it does not end it. Keeping China-collected behavioral data in-country means standing up a China-resident analytics or event store for that data and sending Amplitude only what may lawfully leave, while you keep Amplitude for your other markets. 21YunBox maps that split, localizes the in-country data, and delivers the China-facing app on ICP-filed infrastructure — it is not a route around China's data-export rules.

ARTICLES RELATED TO AMPLITUDE

CATEGORIES

Analytics

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.