Does Boomi Work in China? Integration Data, PIPL & Data Residency
Boomi hosts its platform on Amazon Web Services in the United States, with account data processed there and no mainland-China region — so the personal information your integrations move out of China is a PIPL cross-border transfer. Its self-managed runtime can keep China data in-country; the control plane stays offshore. A compliance-first look at residency, cross-border and ICP.
Does Boomi work in China?
Reachable, but a compliance question: Boomi is an iPaaS that moves your data estate through a US-hosted platform, so the China personal information it carries crosses the border.
Boomi's own sub-processor list hosts the platform on Amazon Web Services in the United States and processes account data there, naming no mainland-China region. Because an integration platform sits across your whole estate, a single pipeline can carry Article 28 sensitive personal information out of China — a PIPL cross-border transfer that needs notice, separate consent, and a transfer mechanism, with an in-country storage duty on top (Cybersecurity Law Article 39, formerly Article 37). Boomi's self-managed runtime can keep China data in-country, but the control plane, metadata and logs still reach the offshore platform.
Which obligations bite depends on your entity, volumes and users — settle specifics with counsel. Our China team can map your exposure →
What Boomi's own documentation says about China
| Fact | Primary source |
|---|---|
| Boomi hosts its platform offshore, in the United States. Boomi's sub-processor list names Amazon Web Services for "Third Party Hosting for platform and runtime services" with the location of processing given as the "United States," and states that account data "will continue to be processed in the United States." No mainland-China region is listed. | Boomi Sub-Processors list (retrieved October 10, 2026) |
| The runtime can execute in your own environment, keeping data local. Boomi documents a runtime that runs "Boomi-hosted ... in multiple regions, or in your own environment across cloud, hybrid, and on-premises behind your firewall," where "Data is processed and persisted within the runtime, and never transits through Boomi's platform for execution" — the lever for keeping China data in-country, though the control plane and logs stay offshore. | Boomi platform runtime page (retrieved October 10, 2026) |
| Moving personal information out of China is a regulated cross-border transfer. Under PIPL Articles 38–40, the handler must give notice, obtain a separate consent for the overseas transfer, and clear one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification); above thresholds a data-export security assessment may apply. | Personal Information Protection Law (PIPL), Arts. 38–40 |
| China-generated personal information may have to stay in China. For critical information infrastructure operators and large-volume handlers, personal information generated in the mainland must be stored there — Cybersecurity Law Article 39 (formerly Article 37), the 2025 amendment in force January 1, 2026 renumbering the data-localization article from 37 to 39 with its substance unchanged, and PIPL Article 40 — a duty an offshore AWS region cannot meet. | Cybersecurity Law Art. 39 (formerly Art. 37); PIPL Art. 40 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
Whether Boomi “works” in mainland China is a data-residency question long before it is a connectivity one. Boomi is an integration platform as a service (iPaaS) — its whole job is to move and process records between your applications, databases, and clouds — so the decision does not turn on whether you can open the Boomi Enterprise Platform from Shanghai. It turns on where the data those integrations carry, and the metadata the platform keeps about them, are allowed to come to rest. Much of what crosses a Boomi pipeline is personal information: customer and employee names, contact details, order, payroll and account records, device and user identifiers, and the transaction and event logs that trail them. Boomi answers the residency question in its own documents — it hosts the platform on Amazon Web Services in the United States, names no mainland-China region, and states that your account data continues to be processed in the United States.
Boomi in China at a glance
| What decides it | In Boomi's own terms — and China's law |
|---|---|
| Where it runs | Boomi splits into a hosted control plane — the Boomi Enterprise Platform, where you build, deploy and monitor integrations — and a runtime that executes them. Boomi's sub-processor list hosts the platform on Amazon Web Services with the location of processing given as the United States, and names no mainland-China region. The runtime can run Boomi-hosted in multiple regions or in your own environment. |
| What it holds, and why it is personal information | An iPaaS moves records between your CRM, ERP, HR, finance and databases, so it sits across the whole data estate. Much of that is personal information, and a single pipeline can carry Article 28 sensitive personal information — financial and payment fields, government-ID numbers, precise location, and health or biometric data. |
| Your China data crossing the border | When the platform processing those flows sits in the United States, the personal information your integrations carry out of China is a cross-border transfer under PIPL Articles 38–40: notice, a separate consent for the overseas transfer, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). |
| In-country storage duty | For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in China — PIPL Article 40, and Cybersecurity Law Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged). An offshore AWS region cannot meet that duty. |
| Reachability is not the axis | Being able to open the Boomi Enterprise Platform from China does not make the data movement lawful — residency and consent attach to where the records rest, not to load speed. A China-facing surface built on these integrations (portal, dashboard, intake form) also carries an ICP filing duty. 21YunBox maps, localizes and delivers over lawful, ICP-filed, in-country infrastructure. |
No mainland region, so your integration data leaves the country
Boomi — the integration platform Dell divested to Francisco Partners and TPG in 2021, now an independent company and no longer branded “Dell Boomi” — is built from a hosted control plane and a runtime that executes your integrations. The control plane is the Boomi Enterprise Platform, where you build, deploy and monitor processes; Boomi’s own sub-processor list hosts it on Amazon Web Services and gives the location of processing as the United States, adding that data relating to your account will continue to be processed in the United States. Boomi names regional runtime options, and in 2022 a Japan cloud data center, but no sub-processor entry or region places the platform in mainland China. So “we already run Boomi” does not carry into the mainland on Boomi’s own terms: the platform and the metadata it keeps sit offshore, and the personal information your China integrations move out of the country becomes a cross-border transfer the moment it leaves.
What a Boomi pipeline carries is personal information
This is the part most teams underestimate. An integration platform exists to move records between systems — a CRM, an ERP, an HR or payroll system, a database, a payment or messaging service — and because it sits across the whole data estate, the exposure is unusually broad. Much of what passes through is personal information, and a single pipeline can carry Article 28 sensitive personal information: financial and payment fields, government-ID numbers, precise location, and health or biometric data. When the platform processing those flows sits in the United States, the personal information your integrations carry out of China is a cross-border transfer the moment it leaves, and it lands on you, the personal-information handler, not on Boomi the processor. Under the Personal Information Protection Law, Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where the data is “important data,” China’s data-export security assessment (数据出境安全评估) may have to clear before anything leaves.
Narrowing the exposure doesn’t close the door
There is a lawful way to keep the integration data in China, and Boomi’s own architecture leaves room for it. Alongside the Boomi-hosted runtime, Boomi documents a self-managed runtime that runs “in your own environment across cloud, hybrid, and on-premises behind your firewall,” where “Data is processed and persisted within the runtime, and never transits through Boomi’s platform for execution.” Run that runtime on infrastructure inside the mainland and the data your China flows carry can stay in China by default, with only what may lawfully leave flowing out to the rest of your estate.
But an in-country runtime is not automatic compliance. The Boomi Enterprise Platform control plane, the process metadata, and the execution and audit logs still reach the offshore, US-hosted SaaS — so some data about your China processing crosses the border even when the payload does not. Redaction, field filtering, and choosing a “different region” reduce what crosses; they do not change that something crosses, and they do not satisfy an in-country storage duty on their own. For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in China under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37) — a duty an offshore AWS region cannot meet — and a public-facing surface over these integrations also carries an ICP filing (备案) duty. This is a risk map, not a verdict: whether you owe a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes, and who your users are, and it is worth settling with counsel before your integrations depend on it.
The lawful path — map, localize, deliver
There is a compliant way to run Boomi for a China-facing business, and it has a shape. First, map: our China compliance team works through your PIPL exposure pipeline by pipeline — which integrations carry personal information out of China, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty applies, and what your notice and consent must cover. We build the technical picture; the legal conclusions are settled with your counsel.
Then localize: we stand up and integrate an in-country Boomi runtime — self-managed inside the mainland — so the China integration data is processed and persisted in the country, keeping only the data that may lawfully leave flowing out, and leaving the Boomi Enterprise Platform exactly where it runs for every other market.
Then deliver: the public-facing apps, portals and APIs that expose these integrations to users in the mainland are an internet service in China, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. 21YunBox is a compliant overlay, not a migration, and a partner to Boomi, not a competitor. 21YunBox never uses or suggests circumvention of any kind. The result is a Boomi estate that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
