Does BlackLine Work in China? Close Data, PIPL & Data Residency
BlackLine is a hosted financial-close platform, so using it in mainland China is first a data-residency question, not a speed one. Its sub-processor list hosts BlackLine Financial Close in the US, EU, Australia and Saudi Arabia — no mainland-China region — so the close records your China books feed in rest offshore. A compliance-first look at the cross-border and residency exposure, and the lawful in-country path.
Does BlackLine work in China?
Reachability is not the question — data residency is, and BlackLine runs no mainland-China region, so the close records your China entity feeds in come to rest offshore.
BlackLine Financial Close is the system of record for the close — journal entries, account and bank reconciliations, intercompany balances and general-ledger detail — and BlackLine’s own sub-processor list hosts it only in the US, EU, Australia (Sydney) and Saudi Arabia (Dammam), stating data stays in “the hosting region you request at the time of sign-up.” Those records are personal information, and bank-account numbers are sensitive financial data under PIPL (Article 28). Holding them in an offshore region is a cross-border transfer under PIPL Articles 38–40 (notice, a separate consent, and one transfer mechanism), it may trigger China’s data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law’s Article 39 (formerly Article 37) requires in-country storage.
This is a risk map, not a ruling — settle the specifics with counsel. Our China team can map your exposure →
What BlackLine's own documentation says about China
| Fact | Primary source |
|---|---|
| BlackLine hosts BlackLine Financial Close in four offshore regions — none in mainland China. Its Subprocessors list (effective July 1, 2026) states: “In general, Customer Data is stored in data centers in the hosting region you request at the time of sign-up as set forth in your agreement with us,” and names only US, EU, APAC (Sydney, Australia) and Middle East (Dammam, Saudi Arabia) hosting regions. | BlackLine Subprocessors list (blackline.com/legal/subprocessors), effective July 1, 2026, retrieved 2026-10-10 |
| The nearest BlackLine region to China is Sydney, and BlackLine stood up an in-country Saudi region but offers no China equivalent. The list maps each instance to named data centers and cloud sub-processors — US (Las Vegas on Switch; Iowa on Google Cloud), EU (Amsterdam on Verizon; Frankfurt on Google Cloud), APAC (Sydney, Australia on Google Cloud, Singapore secondary) and Middle East (Dammam, Saudi Arabia on Google Cloud) — so an APAC instance still rests outside the mainland. | BlackLine Subprocessors list (blackline.com/legal/subprocessors), effective July 1, 2026, retrieved 2026-10-10 |
| Close records collected in China resting in an offshore region are a PIPL cross-border transfer, and bank-account numbers are sensitive data. PIPL Articles 38–40 require notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification); financial-account information is sensitive personal information under Article 28, adding a necessity test, a separate consent and a protection-impact assessment. | Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| A critical information infrastructure operator must store China-collected personal information in China. The Cybersecurity Law’s Article 39 (formerly Article 37 — the October 2025 amendment, in force January 1, 2026, renumbered the data-localization article, substance unchanged) and PIPL Article 40 impose an in-country storage duty on CIIOs and on handlers above the CAC volume threshold — a duty an offshore BlackLine region cannot meet. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37), 2025 amendment effective 2026-01-01 (cac.gov.cn); PIPL Article 40, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
If your China finance team runs its month-end on BlackLine, the instinct is to ask whether the close dashboard loads quickly — or even opens — from Shanghai or Shenzhen. That is the wrong starting point. BlackLine is a hosted financial-close platform, and what decides whether you can use it for a mainland entity is where the records it holds come to rest: the journal entries, account and bank reconciliations, intercompany balances and general-ledger transaction detail your China books feed into it, together with the names and sign-offs of the accounting staff who prepare and approve each task. Most of that is personal or commercially sensitive information — and some of it, like bank-account numbers, is sensitive under China’s law. BlackLine’s own sub-processor list is explicit that it runs no data center in mainland China. So this is a data-residency and cross-border question, not a speed one.
BlackLine in China at a glance
| What decides it | In BlackLine's own terms — and China's law |
|---|---|
| Where the records live | Offshore. BlackLine's Subprocessors list hosts BlackLine Financial Close in four regions — US (Las Vegas; Iowa), EU (Amsterdam; Frankfurt), APAC (Sydney, Australia) and the Middle East (Dammam, Saudi Arabia) — and says data stays in “the hosting region you request at the time of sign-up.” None is in mainland China; the nearest, APAC, is Sydney. |
| What it holds, and why it's personal (and sensitive) | BlackLine is the system of record for the close: journal entries, account and bank reconciliations, intercompany balances, general-ledger transaction detail, and the preparer/reviewer/approver sign-offs on every task. That means bank-account numbers (financial-account data = sensitive personal information under PIPL Article 28), the names and roles of your accounting staff and counterparties, and un-released close results that are material non-public information. |
| China staff & counterparty data = cross-border | The records a mainland entity feeds in are personal information. Holding them in an offshore BlackLine region is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Bank-account numbers add a necessity test, a separate consent and a protection-impact assessment. |
| In-country storage duty | At volume a data-export security assessment can apply before anything leaves; a critical information infrastructure operator — and any handler above the CAC volume threshold — owes in-country storage under PIPL Article 40 and the Cybersecurity Law's Article 39 (formerly Article 37 — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore region cannot meet it. |
| Reachability is not the axis | Whether the close dashboard opens quickly from Shanghai is not the China question; where the close records are allowed to rest is. Any China-facing surface you then deliver — a reporting portal, an intake or approval page — is a public service in the mainland and carries an ICP filing (备案) duty, met on in-country infrastructure. |
No mainland-China region, so the close records leave the country
BlackLine’s Subprocessors list settles where the data sits. For BlackLine Financial Close it names four hosting regions — US (primary data centers in Las Vegas on Switch and in Iowa on Google Cloud), EU (Amsterdam on Verizon and Frankfurt on Google Cloud), APAC (Sydney, Australia on Google Cloud, with Singapore as the secondary) and the Middle East (Dammam, in the Kingdom of Saudi Arabia, on Google Cloud) — and states that “In general, Customer Data is stored in data centers in the hosting region you request at the time of sign-up as set forth in your agreement with us.” None of the four is in mainland China; the nearest, APAC, is Sydney. Notably, BlackLine has stood up an in-country Saudi Arabia region precisely to meet that market’s data-residency expectations — so the model is real where a market requires it — but it offers no equivalent mainland-China region.
The moment personal information collected in China lands in a US, EU, Sydney or Dammam region, you have made a cross-border transfer (数据出境) under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, BlackLine’s customer, not BlackLine the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use the platform, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where the data counts as “important data,” the transfer may first require China’s data-export security assessment (数据出境安全评估) before anything leaves. Which route applies turns on your volumes and what you actually export.
The close ledger is personal — and sensitive — information
Close data is not neutral traffic. Account and bank reconciliations match your books against bank statements, so they carry bank-account numbers and payment detail; under PIPL, financial-account information is sensitive personal information (敏感个人信息), and processing it requires a specific purpose and a showing of necessity, a separate consent, and a personal-information protection impact assessment beforehand — obligations that stack on top of the cross-border duties, not in place of them. BlackLine’s task and close management also records the identities of the accounting staff who prepare, review and approve each item — names, work emails, roles and timestamped approvals — which is employee personal information in its own right, and supporting documents attached to a reconciliation routinely carry invoices and counterparty detail.
There is a second kind of sensitivity that privacy law does not even reach: un-released consolidated close and reconciliation results are commercially sensitive, and for a listed group they are material non-public information. Where those numbers come to rest, and who can reach them, is a governance question that sits alongside the residency one. BlackLine’s security controls — encryption, access governance, and certifications such as SOC 2 and ISO 27001 — genuinely reduce security risk, but they do not discharge the consent, necessity and residency duties, which remain with you as the personal-information handler.
Narrowing the exposure doesn’t close the door
The levers you have reduce what crosses the border, not that it crosses. Region choice is the obvious one: provisioning the China entity’s instance in APAC puts the data nearest, in Sydney with a Singapore secondary — but closeness is not residency. Sydney and Singapore sit outside the mainland, so an APAC instance resolves no China data-localization duty; it merely relocates the same cross-border transfer to a different offshore country. Data-minimization and redaction — sending offshore BlackLine only the fields that may lawfully leave — genuinely shrink the transfer, but the ledger still comes to rest abroad. And BlackLine is a cloud-only, multi-tenant service: there is no on-premises or self-managed deployment you can stand up on mainland soil, so none of these levers puts the records in China.
For a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37) requires personal information and important data generated in the mainland to be stored in the mainland, and PIPL Article 40 extends an in-country storage duty to CIIOs and to handlers whose processing reaches the CAC-specified volume — duties an offshore BlackLine region cannot satisfy by design. Which of these actually bite your deployment turns on your entity, your data volumes and who your users are. This page maps the exposure; it is a risk map, not a ruling — settle the specifics with qualified counsel, which is the only place a ruling can come from.
The lawful path — map, localize, deliver
There is a compliant way to run a financial close for a China operation, and it has three moves. First, map: our China team works through your PIPL exposure end to end — which close records collected in China must stay in the country, what may lawfully cross to BlackLine, where a data-export security assessment or an Article 40 and Article 39 storage duty applies, which fields are sensitive, and what your consent and notice have to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we help stand up and integrate a China-resident footing for the China close data — a lawful in-country pattern of consented processing and storage — so the records that must stay in China stop leaving it by default, while you keep BlackLine as the global close platform for the markets it already serves. Because BlackLine itself is cloud-only, this is about the China-resident data footing around it, not a BlackLine install on your own hardware.
Then deliver: the China-facing surfaces around your close stack — a reporting or approval portal, an intake form, the integration edge your mainland users actually reach — are public services in the mainland, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no second codebase. What we never do, and what no one lawfully can, is engineer a way around China’s data-export rules: 21YunBox never uses or suggests circumvention of any kind. 21YunBox is a compliant overlay, not a migration — and a partner to BlackLine, not a competitor. The result is a close process that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
