Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Boomi Work in China? Integration Data, PIPL & Data Residency

Boomi hosts its platform on Amazon Web Services in the United States, with account data processed there and no mainland-China region — so the personal information your integrations move out of China is a PIPL cross-border transfer. Its self-managed runtime can keep China data in-country; the control plane stays offshore. A compliance-first look at residency, cross-border and ICP.

Does Boomi work in China?

Reachable, but a compliance question: Boomi is an iPaaS that moves your data estate through a US-hosted platform, so the China personal information it carries crosses the border.

Boomi's own sub-processor list hosts the platform on Amazon Web Services in the United States and processes account data there, naming no mainland-China region. Because an integration platform sits across your whole estate, a single pipeline can carry Article 28 sensitive personal information out of China — a PIPL cross-border transfer that needs notice, separate consent, and a transfer mechanism, with an in-country storage duty on top (Cybersecurity Law Article 39, formerly Article 37). Boomi's self-managed runtime can keep China data in-country, but the control plane, metadata and logs still reach the offshore platform.

Which obligations bite depends on your entity, volumes and users — settle specifics with counsel. Our China team can map your exposure →

What Boomi's own documentation says about China

FactPrimary source
Boomi hosts its platform offshore, in the United States. Boomi's sub-processor list names Amazon Web Services for "Third Party Hosting for platform and runtime services" with the location of processing given as the "United States," and states that account data "will continue to be processed in the United States." No mainland-China region is listed. Boomi Sub-Processors list (retrieved October 10, 2026)
The runtime can execute in your own environment, keeping data local. Boomi documents a runtime that runs "Boomi-hosted ... in multiple regions, or in your own environment across cloud, hybrid, and on-premises behind your firewall," where "Data is processed and persisted within the runtime, and never transits through Boomi's platform for execution" — the lever for keeping China data in-country, though the control plane and logs stay offshore. Boomi platform runtime page (retrieved October 10, 2026)
Moving personal information out of China is a regulated cross-border transfer. Under PIPL Articles 38–40, the handler must give notice, obtain a separate consent for the overseas transfer, and clear one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification); above thresholds a data-export security assessment may apply. Personal Information Protection Law (PIPL), Arts. 38–40
China-generated personal information may have to stay in China. For critical information infrastructure operators and large-volume handlers, personal information generated in the mainland must be stored there — Cybersecurity Law Article 39 (formerly Article 37), the 2025 amendment in force January 1, 2026 renumbering the data-localization article from 37 to 39 with its substance unchanged, and PIPL Article 40 — a duty an offshore AWS region cannot meet. Cybersecurity Law Art. 39 (formerly Art. 37); PIPL Art. 40

Sources verified by the 21YunBox compliance team on 2026-10-10.

Whether Boomi “works” in mainland China is a data-residency question long before it is a connectivity one. Boomi is an integration platform as a service (iPaaS) — its whole job is to move and process records between your applications, databases, and clouds — so the decision does not turn on whether you can open the Boomi Enterprise Platform from Shanghai. It turns on where the data those integrations carry, and the metadata the platform keeps about them, are allowed to come to rest. Much of what crosses a Boomi pipeline is personal information: customer and employee names, contact details, order, payroll and account records, device and user identifiers, and the transaction and event logs that trail them. Boomi answers the residency question in its own documents — it hosts the platform on Amazon Web Services in the United States, names no mainland-China region, and states that your account data continues to be processed in the United States.

Boomi's own sub-processor list showing Amazon Web Services as Third Party Hosting for platform and runtime services located in the United States, with a footnote that account data will continue to be processed in the United States — naming no mainland-China region
Boomi's own sub-processor list names Amazon Web Services for “Third Party Hosting for platform and runtime services” located in the “United States,” and notes that account data “will continue to be processed in the United States.” No mainland-China region appears, so the platform and the metadata it keeps rest offshore. Source: boomi.com/legal/sub-processors

Boomi in China at a glance

What decides it In Boomi's own terms — and China's law
Where it runs Boomi splits into a hosted control plane — the Boomi Enterprise Platform, where you build, deploy and monitor integrations — and a runtime that executes them. Boomi's sub-processor list hosts the platform on Amazon Web Services with the location of processing given as the United States, and names no mainland-China region. The runtime can run Boomi-hosted in multiple regions or in your own environment.
What it holds, and why it is personal information An iPaaS moves records between your CRM, ERP, HR, finance and databases, so it sits across the whole data estate. Much of that is personal information, and a single pipeline can carry Article 28 sensitive personal information — financial and payment fields, government-ID numbers, precise location, and health or biometric data.
Your China data crossing the border When the platform processing those flows sits in the United States, the personal information your integrations carry out of China is a cross-border transfer under PIPL Articles 38–40: notice, a separate consent for the overseas transfer, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification).
In-country storage duty For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in China — PIPL Article 40, and Cybersecurity Law Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged). An offshore AWS region cannot meet that duty.
Reachability is not the axis Being able to open the Boomi Enterprise Platform from China does not make the data movement lawful — residency and consent attach to where the records rest, not to load speed. A China-facing surface built on these integrations (portal, dashboard, intake form) also carries an ICP filing duty. 21YunBox maps, localizes and delivers over lawful, ICP-filed, in-country infrastructure.

No mainland region, so your integration data leaves the country

Boomi — the integration platform Dell divested to Francisco Partners and TPG in 2021, now an independent company and no longer branded “Dell Boomi” — is built from a hosted control plane and a runtime that executes your integrations. The control plane is the Boomi Enterprise Platform, where you build, deploy and monitor processes; Boomi’s own sub-processor list hosts it on Amazon Web Services and gives the location of processing as the United States, adding that data relating to your account will continue to be processed in the United States. Boomi names regional runtime options, and in 2022 a Japan cloud data center, but no sub-processor entry or region places the platform in mainland China. So “we already run Boomi” does not carry into the mainland on Boomi’s own terms: the platform and the metadata it keeps sit offshore, and the personal information your China integrations move out of the country becomes a cross-border transfer the moment it leaves.

What a Boomi pipeline carries is personal information

This is the part most teams underestimate. An integration platform exists to move records between systems — a CRM, an ERP, an HR or payroll system, a database, a payment or messaging service — and because it sits across the whole data estate, the exposure is unusually broad. Much of what passes through is personal information, and a single pipeline can carry Article 28 sensitive personal information: financial and payment fields, government-ID numbers, precise location, and health or biometric data. When the platform processing those flows sits in the United States, the personal information your integrations carry out of China is a cross-border transfer the moment it leaves, and it lands on you, the personal-information handler, not on Boomi the processor. Under the Personal Information Protection Law, Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where the data is “important data,” China’s data-export security assessment (数据出境安全评估) may have to clear before anything leaves.

Narrowing the exposure doesn’t close the door

There is a lawful way to keep the integration data in China, and Boomi’s own architecture leaves room for it. Alongside the Boomi-hosted runtime, Boomi documents a self-managed runtime that runs “in your own environment across cloud, hybrid, and on-premises behind your firewall,” where “Data is processed and persisted within the runtime, and never transits through Boomi’s platform for execution.” Run that runtime on infrastructure inside the mainland and the data your China flows carry can stay in China by default, with only what may lawfully leave flowing out to the rest of your estate.

But an in-country runtime is not automatic compliance. The Boomi Enterprise Platform control plane, the process metadata, and the execution and audit logs still reach the offshore, US-hosted SaaS — so some data about your China processing crosses the border even when the payload does not. Redaction, field filtering, and choosing a “different region” reduce what crosses; they do not change that something crosses, and they do not satisfy an in-country storage duty on their own. For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in China under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37) — a duty an offshore AWS region cannot meet — and a public-facing surface over these integrations also carries an ICP filing (备案) duty. This is a risk map, not a verdict: whether you owe a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes, and who your users are, and it is worth settling with counsel before your integrations depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run Boomi for a China-facing business, and it has a shape. First, map: our China compliance team works through your PIPL exposure pipeline by pipeline — which integrations carry personal information out of China, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty applies, and what your notice and consent must cover. We build the technical picture; the legal conclusions are settled with your counsel.

Then localize: we stand up and integrate an in-country Boomi runtime — self-managed inside the mainland — so the China integration data is processed and persisted in the country, keeping only the data that may lawfully leave flowing out, and leaving the Boomi Enterprise Platform exactly where it runs for every other market.

Then deliver: the public-facing apps, portals and APIs that expose these integrations to users in the mainland are an internet service in China, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. 21YunBox is a compliant overlay, not a migration, and a partner to Boomi, not a competitor. 21YunBox never uses or suggests circumvention of any kind. The result is a Boomi estate that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is using Boomi in mainland China a data-residency problem even if the platform loads fine?
Yes — reachability is not the axis. Because Boomi hosts the platform on AWS in the United States with no mainland-China region, the personal information your integrations carry out of China is a PIPL cross-border transfer regardless of load speed. The residency, notice and consent duties attach to the data movement, not to whether you can open the console. Confirm the specifics with counsel against what you actually move and store.
Does running Boomi's self-managed runtime in China make it compliant?
It helps, but it is not automatic compliance. A runtime deployed in your own in-country environment can process and persist China data locally so it stays resident, but the Boomi Enterprise Platform control plane, the process metadata, and the execution and audit logs still reach the offshore, US-hosted SaaS. You still have to design which records may lawfully leave and satisfy a cross-border mechanism for those that do.
What about a China-facing dashboard or portal built on Boomi integrations — does that need anything extra?
Yes. Any public-facing surface served to users in the mainland is an internet service in China and carries an ICP filing (备案) duty, separate from the data-residency question. 21YunBox stands up ICP-filed, in-country delivery in front of your existing stack, keeps the China integration data resident, and maps what may lawfully cross the border — with no rebuild and no second codebase.

ARTICLES RELATED TO BOOMI

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.