Does Anaplan Work in China? Forecasts, Workforce Data, PIPL & Data Residency
Anaplan runs on Amazon Web Services in regions across the Americas, EMEA, and Asia-Pacific — with no mainland-China region — so the budgets, forecasts, consolidated figures, and employee compensation plans your China entity feeds in come to rest offshore as a PIPL cross-border transfer. A compliance-first look at Anaplan and China's data-residency and cross-border rules.
Does Anaplan work in China?
Whether Anaplan works in China is a data-residency question, not a speed one.
Anaplan hosts customer data on Amazon Web Services in regions across the Americas, EMEA, and Asia-Pacific — Virginia, Ireland, Germany, the UK, the UAE, Australia, India, Indonesia, and Singapore — and by its own account each region keeps data "within" that country under local rules. None of those regions is in mainland China. So the budgets, forecasts, consolidated figures, and workforce and compensation plans your China entity feeds into Anaplan come to rest offshore: a cross-border transfer of personal information PIPL governs — notice, separate consent, and a transfer mechanism, plus an in-country storage duty under the Cybersecurity Law for a CIIO or high-volume handler. Much of what it holds is also material non-public information, and employee payroll and bank details are sensitive personal information under Article 28.
This is a risk map, not a ruling — your duties turn on your data volumes and your role. Our China team can map your Anaplan exposure →
What Anaplan's own documentation says about China
| Fact | Primary source |
|---|---|
| Anaplan hosts customer data on Amazon Web Services, region by region — with no mainland-China region. Announcing its Singapore data center, Anaplan says the site "ensures that data remains within Singapore, adhering to local regulations," alongside AWS "data center expansions in the Asia-Pacific region, including in India, Indonesia, and Australia." None is in mainland China. | Anaplan newsroom, "Anaplan Launches AWS Data Center in Singapore" (retrieved 2026-10-10) |
| Anaplan's own sub-processor list names AWS as its hosting provider across the Americas, EMEA, and Asia-Pacific — none in mainland China. It records AWS hosting in Ohio, Oregon, and Virginia (Americas); Australia, India, and Indonesia (Asia-Pacific); and Ireland, Germany, the United Kingdom, and the United Arab Emirates (EMEA). There is no mainland-China location to select. | Anaplan Support, "List of subprocessors" (last modified September 11, 2026; retrieved 2026-10-10) |
| Feeding a China entity's records into an offshore Anaplan region is a cross-border transfer of personal information under PIPL. Articles 38–40 require notice, a separate consent, and a transfer mechanism, and employees' payroll and bank-account details are sensitive personal information under Article 28, which raises the bar further. | Personal Information Protection Law of the PRC, Articles 28 and 38–40 (retrieved 2026-10-10) |
| A critical-information-infrastructure operator or high-volume handler also owes an in-country storage duty. Cybersecurity Law Article 39 (formerly Article 37) requires personal information and important data collected in China to be stored on the mainland, and a CAC security assessment can be required before any export. | PRC Cybersecurity Law, Article 39 (formerly Article 37, renumbered by the 2025 amendment in force January 1, 2026) (retrieved 2026-10-10) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question to settle about Anaplan is not whether a planner can open the dashboard or whether a model recalculates on time — it is where the numbers inside it are allowed to come to rest. Anaplan is a connected-planning platform: it holds the budgets, forecasts, and driver-based models a company plans on, its sales quotas, territories, and commissions, its demand and supply plans, and its workforce plans down to headcount and employee-level compensation. Much of that is personal information — employee and counterparty details — and some is the most sensitive kind, because pay and financial-account data sit inside it; much of the rest is material, non-public financial information. Anaplan runs all of this on Amazon Web Services, in regions across the Americas, EMEA, and Asia-Pacific, and there is no mainland-China region to select — so a China entity’s planning records come to rest offshore.
Anaplan in China at a glance
| What decides it | In Anaplan's own terms — and China's law |
|---|---|
| What it is | Anaplan — a connected-planning / FP&A platform spanning finance, sales, supply-chain, and workforce planning. It is operated by Anaplan from its own Amazon Web Services regions, and there is no Anaplan mainland-China region or China entity you run it from. |
| Where the planning records live | Anaplan's own sub-processor list names AWS as its hosting provider across the Americas (Ohio, Oregon, Virginia), Asia-Pacific (Australia, India, Indonesia — and, since January 2026, Singapore), and EMEA (Ireland, Germany, the UK, the UAE). No mainland-China region exists to select, so the budgets, forecasts, models, and workforce plans tied to your China entity come to rest offshore. |
| What it holds, and why it is personal (and sensitive) information | Budgets, forecasts, consolidated results, scenario models, sales quotas and commissions, and workforce plans with headcount and employee-level compensation. Employee and counterparty identifiers are personal information; payroll and bank-account details are sensitive personal information under PIPL Article 28; and un-released forecasts and consolidated figures are material non-public information. Held offshore, the personal data is a cross-border transfer (PIPL Articles 38–40): notice, a separate consent, and one transfer mechanism. |
| Your China data crossing the border, and the storage duty | Records sent from or about people in China to an offshore Anaplan region are a cross-border transfer of personal information (PIPL Article 40). In-country storage can also bite for a critical-information-infrastructure operator or high-volume handler (Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). Anaplan is not "blocked"; it simply is not an in-country, China-resident option. |
| The lawful path | Whether the app loads is not the test; where the records rest is. Map the PIPL, residency, and sensitive-PI exposure; localize consented in-country processing and storage for the records that must stay on mainland soil; and deliver any China-facing surface — a planning portal or intake form — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the Anaplan stack you already run. |
No mainland region, so the forecasts and models leave the country
Anaplan runs on Amazon Web Services, and it has made a point of standing up a region per country so that customer data stays local to it. Announcing its Singapore data center in January 2026, the company said the new Amazon Web Services site “ensures that data remains within Singapore, adhering to local regulations,” and framed data sovereignty as “a stringent requirement for our clients.” It describes the same logic for its other Asia-Pacific sites — “data center expansions in the Asia-Pacific region, including in India, Indonesia, and Australia” — and for its 2025 investment in an AWS region in the UAE, each pitched at customers who need in-country residency. That is what lawful in-region operation looks like, and Anaplan has built it across EMEA and Asia-Pacific and the Americas. It has not built it for mainland China. There is no Anaplan mainland-China region, so when a China-based entity plans in Anaplan, the budget, the forecast, the model, and the workforce record are written to infrastructure outside the mainland. Sent from or about people in China to a platform hosted offshore, that is a cross-border transfer of personal information under PIPL, and for a critical-information-infrastructure operator or a high-volume handler it can require a CAC security assessment before the data may leave.
Budgets, forecasts, and workforce plans are personal — and material — information
A planning platform is dense with the two things China’s rules care most about. The first is personal information: workforce plans carry named or employee-ID-level headcount, salaries, bonuses, merit increases, and attrition assumptions, and vendor, customer, and counterparty records carry the identities of real people and businesses. Where those records reach into payroll or bank-account details, they are sensitive personal information under the Personal Information Protection Law (Article 28), which raises the bar: handling them requires a specific purpose, strict necessity, and a separate consent, and moving them across the border layers on the Article 38–40 duties of notice, a distinct cross-border consent, and one approved transfer mechanism. The second is commercial sensitivity: un-released budgets, forecasts, scenario models, and consolidated figures are material, non-public financial information, the kind a listed company is obliged to protect until it is disclosed. The duty to get the cross-border basis right falls on the handler — the business that owns the plan — not only on Anaplan as the vendor. None of this turns on how quickly a model opens; it turns on whether that content had a lawful basis to leave the country, and whether it had to stay in the first place.
Narrowing the exposure doesn’t close the door
Anaplan gives you real levers to reduce what crosses. You can choose which region hosts your tenant, keep employee-level compensation out of certain models, hold detail at an aggregated or masked level, and limit which lists carry personal data. Each of these narrows what leaves the mainland. None of them changes that it leaves. As long as the hosting region is in the Americas, EMEA, or Asia-Pacific, a China entity’s planning data is still crossing the border the moment it is written — region choice only decides which offshore region, and masking only decides how much. Self-hosting is not an escape either: Anaplan is a multi-tenant cloud service with no mainland-China deployment to point an on-premises install at. And ICP filing governs any China-facing surface you expose, whatever the back end — a planning portal or an intake form reachable from the mainland needs an ICP filing. So the residency question is not softened by configuration; it is only made smaller. Because the specifics — whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, and how the renumbered Cybersecurity Law Article 39 (formerly Article 37) bears on you — turn on facts only your team and your counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.
The lawful path — map, localize, deliver
Reaching Chinese users and entities with an enterprise planning stack the lawful way has a shape, and it keeps Anaplan where it already runs. 21YunBox is a compliant overlay, not a migration, and for a platform like Anaplan we are a partner to it, not a competitor. We map your exposure first — reading the PIPL cross-border, data-residency, and sensitive-PI obligations against your entity, your data volumes, and whose information actually sits in the plan, so you know exactly what counsel needs to confirm. We localize the records that must stay on mainland soil — standing up consented, in-country processing and storage for the workforce, compensation, and counterparty data that cannot lawfully come to rest offshore, and using self-hosted deployment where a tool supports it. And we deliver every China-facing surface — the planning portal, the dashboard, the intake form — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the Anaplan stack you already run, with no rebuild and no second codebase. The result is an enterprise planning stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s data export security assessment measures
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- How to get an ICP filing for China
