Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Bazaarvoice Work in China? Content-Moderation Duty, PIPL & Cross-Border Review Data

Bazaarvoice's review widgets are reachable from the mainland, so the China question isn't speed. Displaying shopper reviews and other user-generated content to people in China makes the site operator responsible for moderating unlawful content under China's network and content rules, while the reviewer identities and behavioral data Bazaarvoice collects sit in its U.S. and EU AWS data centers — a cross-border transfer of personal information under PIPL, on an offshore display host that cannot be ICP-filed. A compliance-first look at the content-moderation duty, the cross-border and data-residency questions, and the lawful in-country path.

Does Bazaarvoice work in China?

Bazaarvoice's review widgets are reachable from mainland China, so the honest answer is that speed is not the problem — the China decision turns on two compliance doors. One: showing shopper reviews and other user-generated content to people in China makes you, the site operator, responsible for moderating unlawful content. Two: the reviewer data Bazaarvoice holds sits offshore.

Bazaarvoice's Trust Center states its SaaS is “hosted in… AWS data centers strategically located in the U.S. and EU” and that it “processes data on servers in the USA,” with no mainland-China region — so collecting your China shoppers' identities and behavioral records into it is a cross-border transfer (数据出境) under PIPL (notice, a separate consent, and a transfer mechanism), which may also trigger China's data-export security assessment. Separately, the Cybersecurity Law (Article 49, formerly Article 47) and the CAC's comment-service rules put a content-moderation and real-identity duty on the operator of the China-facing site — not on the vendor. An offshore UGC-display host also carries no ICP footing.

21YunBox maps both doors, localizes the China UGC and reviewer data onto a consented, in-country footing with in-country moderation, and delivers your review widget on ICP-filed infrastructure — no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Bazaarvoice's own documentation says about China

FactPrimary source
Bazaarvoice hosts in the U.S. and EU, with no mainland-China region. Its Trust Center FAQ states that Bazaarvoice's “SaaS offerings are hosted in secure, state-of-the-art AWS data centers strategically located in the U.S. and EU,” and that “all data is stored in AWS data centers.” No mainland-China region is named, so the reviewer identities and behavioral records it collects from your China shoppers rest offshore. Bazaarvoice Trust Center — Frequently Asked Questions (bazaarvoice.com), retrieved 2026-10-09
Bazaarvoice processes data on servers in the USA and treats cross-border transfers under Standard Contractual Clauses. Its Trust Center states: “As a US company, Bazaarvoice processes data on servers in the USA. Transfer of personal data between the EU and US is governed by fully compliant Standard Contractual Clauses.” SCCs answer an EU transfer question; for data collected in mainland China the same offshore-processing posture is a cross-border transfer under PIPL, which SCCs do not satisfy. Bazaarvoice Trust Center — Frequently Asked Questions (bazaarvoice.com), retrieved 2026-10-09
Displaying user-generated content to people in China puts a content-moderation and real-identity duty on the site operator. The Cybersecurity Law (Article 49, formerly Article 47) requires a network operator to manage the information its users publish and to stop, remove, record and report unlawful content; the CAC's Provisions on the Administration of Internet Comment and Posting Services (effective December 15, 2022) and Provisions on the Governance of the Online Information Content Ecosystem (effective March 1, 2020) extend this to reviews and comments and expect back-end real-identity authentication of contributors. The duty falls on the China-facing operator — you, not Bazaarvoice. Provisions on the Administration of Internet Comment and Posting Services (effective 2022-12-15); Provisions on the Governance of the Online Information Content Ecosystem (effective 2020-03-01); Cybersecurity Law Article 49 (formerly Article 47) — cac.gov.cn, retrieved 2026-10-09
Sending China-collected reviewer data to an offshore Bazaarvoice is a PIPL cross-border transfer. Moving personal information collected from shoppers in mainland China to a Bazaarvoice account hosted in the U.S. or EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — and it may be subject to China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

Ask whether Bazaarvoice “works” in mainland China and the honest first answer is that the review widgets render — reachability is not where this decision is made. It is made at two gates that sit above performance. The first opens the moment your storefront shows shopper reviews, questions and other user-generated content to people in China: Chinese law then treats the site displaying that content as a network operator with a duty to moderate it. The second is where the reviewer identities and the behavioral record Bazaarvoice keeps actually live — because collecting them from your Chinese shoppers into an offshore platform is a cross-border transfer of personal information. Bazaarvoice sets out where that data lives in its own words.

Bazaarvoice Trust Center Frequently Asked Questions page, Security FAQs section, stating that Bazaarvoice's SaaS offerings are hosted in AWS data centers in the U.S. and EU and that all data is stored in AWS data centers — naming only US and EU regions, with no mainland-China data center
Bazaarvoice's own Trust Center FAQ: its “SaaS offerings are hosted in secure, state-of-the-art AWS data centers strategically located in the U.S. and EU,” and “all data is stored in AWS data centers” — so the reviewer identities and behavioral records it collects from your Chinese shoppers rest offshore, with no mainland-China region to store or serve them from. Source: Bazaarvoice Trust Center — Frequently Asked Questions

Bazaarvoice in China at a glance

What decides it In Bazaarvoice's own terms — and China's law
What it is Bazaarvoice is a ratings, reviews and user-generated content (UGC) syndication platform. It collects shopper reviews and questions, builds a profile of each contributor, and displays syndicated UGC through its own content delivery network — so it both holds reviewer personal data and publishes user content to your storefront.
Is it reachable from the mainland? Yes. Bazaarvoice's collection and display endpoints are callable from China, and it is not a service blocked at the border. Reachability is not the China question. (Serving the widget cross-border from offshore can be inconsistent — an operational matter, below, not the decision.)
Who must moderate the UGC shown in China? You, the operator of the China-facing site. The Cybersecurity Law (Article 49, formerly Article 47) and the CAC's content-ecosystem and comment-service provisions put the duty to manage user-published information — and to stop, remove and report unlawful content — on the operator. Running Bazaarvoice as-is does not discharge it.
Where does the reviewer data sit? Offshore. Bazaarvoice's Trust Center says its SaaS is “hosted in… AWS data centers strategically located in the U.S. and EU” and that it “processes data on servers in the USA.” There is no mainland-China region. Collecting China shoppers' identities and behavior into it is a cross-border transfer (数据出境) under PIPL (Articles 38–40).
Serving the public A China-facing site actually served from inside the mainland needs an ICP filing bound to a mainland hosting resource. An offshore UGC-display host provides none, so there is nothing of Bazaarvoice's to file against.
The lawful path Store and moderate the China UGC in-country on a consented, PIPL-compliant footing, deliver the review widget in-country on ICP-filed infrastructure, and keep Bazaarvoice for your other markets. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention.

Door one — showing UGC to users in China is a moderation duty, and it is yours

This gate is structural, not a detail of configuration. A reviews program exists to publish what your shoppers write — and the instant that content is displayed to people in mainland China, Chinese law treats the site showing it as a network operator carrying a content-management duty. Under the Cybersecurity Law, Article 49 (formerly Article 47 — the Law’s October 28, 2025 amendment, in force January 1, 2026, inserted new articles and renumbered the later provisions, including moving the data-localization duty from Article 37 to Article 39; the obligations themselves are unchanged), a network operator must strengthen the management of information its users publish, and on finding content whose publication or transmission is prohibited must immediately stop transmitting it, take disposal measures such as removal, preserve the records, and report to the authorities.

Two CAC rules sharpen this for review and comment services specifically: the Provisions on the Governance of the Online Information Content Ecosystem (effective March 1, 2020) and the Provisions on the Administration of Internet Comment and Posting Services (effective December 15, 2022). The latter reaches reviews and questions directly — it expects real-identity authentication of contributors on a “back-end real name, front-end optional” basis, and it contemplates the operator being able to hide or remove unlawful comment content on request.

The duty lands on the operator of the China-facing site — you, Bazaarvoice’s customer — not on Bazaarvoice the vendor. Running the platform as it ships does not hand you an in-country moderation workflow, the real-identity footing, or the takedown control these rules assume, and UGC syndicated in from your other markets was never screened against Chinese content standards to begin with. Whether, and how, each of these bites your specific review program is a risk to settle with counsel before you rely on it.

Door two — the reviewer data lives offshore, so collecting it is a cross-border transfer

Bazaarvoice is unusually clear about where its data rests. Its Trust Center states that its “SaaS offerings are hosted in secure, state-of-the-art AWS data centers strategically located in the U.S. and EU,” that “all data is stored in AWS data centers,” and that “as a US company, Bazaarvoice processes data on servers in the USA,” with EU–US transfers “governed by fully compliant Standard Contractual Clauses.” Those clauses answer a European question; they do not answer a Chinese one. There is no mainland-China region on offer.

So the reviewer identities, the contact and device data, and the behavioral trail Bazaarvoice records about your shoppers in China are personal information held outside the mainland. Loading them into a U.S. or EU Bazaarvoice is a cross-border transfer of personal information under China’s Personal Information Protection Law, and the duty sits on the handler — you, not Bazaarvoice the processor: PIPL Articles 38–40 require notice, a separate consent distinct from any general sign-up, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the relevant thresholds, or where the data counts as important data, the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves — and a reviews platform is exactly where identifiable personal information concentrates. For a critical information infrastructure operator or a large-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37) requires personal information collected in China to be stored in China — an in-country storage duty an offshore Bazaarvoice region cannot meet. None of this turns on how quickly a review renders; it turns on whether the data had a lawful basis to leave at all.

No mainland region — no ICP footing, and an offshore widget to deliver

The same geography settles the licensing-and-delivery half. A public-facing site actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) bound to a hosting resource physically in the mainland. Bazaarvoice names only U.S. and EU regions, so the host that stores and serves your review content provides nothing to file against. And because the display originates offshore — a reasonable inference from Bazaarvoice publishing no mainland region for its UGC delivery — the review widget is fetched from outside the mainland, where it can load slowly or fail for a shopper in China. On a product page a stalled review block quietly degrades the social proof it is there to provide, but that is the delivery half of the question, not the legal half that decides whether you may run it this way. What closes the gap is never a network workaround: 21YunBox neither uses nor suggests any form of circumvention, which is both a compliance risk and beside the point.

The lawful path — map, localize, deliver

A China-facing reviews program can run on a compliant footing, but it takes three moves rather than a setting change. Map comes first: our China team walks both doors with you — the moderation duty that attaches to any UGC shown in the mainland, and the PIPL cross-border and residency exposure that attaches to the reviewer data Bazaarvoice stores — weighed against your entity, your data volumes and who your shoppers are, so the obligations are visible before launch. We build the technical picture; your counsel draws the legal conclusions.

Localize comes next: we stand up the lawful in-country pattern — China reviewers’ data collected and held in the mainland on a consented, PIPL-compliant basis, and the UGC moderated in-country to Chinese content standards with the real-identity and takedown controls the rules call for — while Bazaarvoice keeps serving the markets where it already works for you. Where a clean domestic equivalent exists we adopt it; where it does not, we build the consented, in-country pattern rather than naming a product for its own sake.

Deliver closes it: the storefront that renders those reviews is a public-facing service in the mainland, so it carries an ICP-filing duty and needs compliant in-country delivery. The 21YunBox Optimizer provides that delivery from inside China, set in front of the stack you already run — no rebuild, no second codebase, no re-platform. The outcome is a review program that runs legally and compliantly for your users in China. What we will not do — because no one lawfully can — is route personal information out of the mainland by stealth or sidestep China’s content and data-export rules; we keep what must stay in the country and deliver the rest in-country.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Bazaarvoice blocked in China?
No — Bazaarvoice's review collection and display endpoints are callable from the mainland, so availability is not the obstacle. The China question is compliance, on two fronts: showing user-generated content to people in China makes you, the site operator, responsible for moderating unlawful content (Cybersecurity Law Article 49, formerly Article 47, plus the CAC's comment-service rules), and the reviewer data Bazaarvoice holds sits offshore in its U.S. and EU data centers, making its collection a cross-border transfer under PIPL. Serving the widget cross-border from offshore can also be inconsistent, but that is operational, not the decision — and the answer is never a network workaround. Confirm the specifics with counsel.
Who is responsible for moderating Bazaarvoice reviews shown to users in China?
The operator of the China-facing site — you, Bazaarvoice's customer — not Bazaarvoice the vendor. China's Cybersecurity Law (Article 49, formerly Article 47) and the CAC's Provisions on the Administration of Internet Comment and Posting Services (effective December 15, 2022) place the duty to manage user-published content, authenticate contributors' real identity, and remove and report unlawful content on the network operator. Running Bazaarvoice as it ships does not give you the in-country moderation, real-identity footing or takedown control those rules assume, and UGC syndicated in from other markets was never screened against Chinese content standards. How this applies to your program is a question for counsel.
Is sending China reviewer data to Bazaarvoice a cross-border transfer?
If your Bazaarvoice account is in the U.S. or EU region — anywhere outside the mainland — then the reviewer identities and behavioral records it holds for your China shoppers are stored offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and above the thresholds it may require China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. 21YunBox localizes the China data in-country and delivers the storefront on ICP-filed infrastructure — it is not a route around China's data-export rules. Confirm your exact obligations with counsel.

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.