Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Box Work in China? Data Residency, Box Zones & Cross-Border Transfer

Box is reachable from China, but reachability is not the decision. Box is an enterprise content cloud: the documents, files, metadata and collaborator identities a China-facing team puts in Box come to rest in one of Box's ten overseas Box Zones regions — none of them mainland China — so personal information collected in China and held there is a cross-border transfer under PIPL (notice, a separate consent, a transfer mechanism, possibly a data-export security assessment), with an in-country storage duty for a critical information infrastructure operator under the Cybersecurity Law's Article 39 (formerly Article 37), and a public China-facing surface still owes an ICP filing. A compliance-first look at Box's data-residency and cross-border exposure — and the lawful in-country path, with no circumvention of any kind.

Does Box work in China?

Box is reachable from the mainland, but that is the easy half — and not the decision. The decision is where your content lives: Box stores it in one of ten overseas Box Zones regions, none of them mainland China.

Box's own Box Zones page offers to "store your content in the geographic region of your choice," with "in-region storage across 10 regions" — Australia, Canada, the EU, France, Israel, Japan, Singapore, Switzerland, the UK and the US. There is no China Zone. So the documents, metadata and collaborator identities a China-facing team puts in Box are personal information that leaves the mainland — a cross-border transfer PIPL governs (notice, a separate consent and a transfer mechanism, Articles 38–40), with an in-country storage duty for a critical information infrastructure operator (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) that an offshore Zone cannot meet. A public China-facing surface serving those files also owes an ICP filing. The table below is Box's own wording and the rule each line triggers.

This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →

What Box's own documentation says about China

FactPrimary source
Box lets you choose a storage region — but mainland China is not one of them. Box's own Box Zones product page offers to "store your content in the geographic region of your choice," with "in-region storage across 10 regions," and notes that "Admins determine where content is stored." Box operates no China Zone and names no mainland data center, so content a China-facing team puts in Box comes to rest in one of its overseas regions — a cross-border transfer of personal information under PIPL (notice, separate consent and a transfer mechanism, Articles 38–40). Box — Box Zones product page, retrieved 2026-10-09; PIPL Articles 38–40
Box's ten Box Zones regions are all offshore. As of Box's June 2026 expansion, the Box Zones footprint is ten regions — Australia, Canada, the EU, France, Israel, Japan, Singapore, Switzerland, the UK and the US — Box's support note stating that the three newest Zones join "the existing seven Box Zones, bringing the total available regions to ten." None sits inside the mainland, and Box's own note records that "Other processing activities currently occur in the U.S." There is no mainland hosting resource for China-collected files, metadata or identities to live on. Box Support — New Box Zones in Switzerland, Singapore and Israel, retrieved 2026-10-09
It is not just the files — the metadata and collaborator identities cross the border too. Box's documentation describes a Zone as "a regional data storage unit" and stores files by top-level folder ownership; the record of who owns, shares and opens a file, and the account identities of your China-based collaborators, are personal information that moves to the chosen offshore Zone along with the content. Using a residency feature with no China option does not keep China-collected personal information in China — it routes it overseas, which is exactly the act PIPL's cross-border rules govern. Box Support — Complying with International Data Privacy Rules: Multizones, retrieved 2026-10-09
For some handlers the content must stay in China — and serving from inside the mainland triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which no offshore Box Zone can satisfy. And any public site actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Box does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-09.

Teams usually ask whether Box “works” in China the way they would ask about any app — can a colleague in Shanghai open it and sync a folder. For Box that is the easy half of the question, and it is not where the decision is made. Box is an enterprise content cloud: the documents, the files, their metadata, and the identities of the people collaborating on them are all uploaded to Box’s storage. By Box’s own account that storage sits in one of ten overseas regions — and mainland China is not among them. The moment content collected from users in China comes to rest in an offshore Box account, you have made a cross-border transfer (数据出境), and a separate body of law decides whether that was lawful. Even if every file opened instantly from Beijing, that question would still stand — which is why this is a data-residency decision, not a performance one. To be unambiguous from the start: there is no lawful route that circumvents China’s network controls, and 21YunBox never uses or suggests circumvention of any kind.

Box's own Box Zones product page under the heading about complying with data residency globally, stating that Box Zones lets you store your content in the geographic region of your choice, where one price grants access to all 10 Zones — none of which is mainland China
Box's own Box Zones page offers to “store your content in the geographic region of your choice,” and tells customers “One price grants access to all 10 Zones.” None of those ten regions is mainland China — Box operates no China Zone and names no mainland data center — so the files, metadata and collaborator identities a China-facing team puts in Box come to rest in one of Box's offshore regions. Source: box.com — Box Zones

Box in China at a glance

What decides it In Box's own terms — and China's law
What it is Box is an enterprise content cloud: documents, files, their metadata and the identities of collaborators are uploaded to Box's storage and shared across teams. There is no Box Zone, data center, or operating entity inside mainland China.
Where does your content sit? Offshore. Box Zones lets an enterprise pin content to one of ten regions — Box's own list runs Australia, Canada, the EU, France, Israel, Japan, Singapore, Switzerland, the UK and the US. None is mainland China, and content not assigned to a Zone rests on Box's primary (US) infrastructure.
Putting China-collected content in a Box account A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. It may trigger China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore Zone cannot meet.
Serving the public from inside China A China-facing portal or app that lets mainland users open and receive these files is a public service in the mainland, so it carries an ICP filing (备案) duty bound to a mainland hosting resource — something Box, with no in-country region, does not provide.
Is reachability the question? No. Box runs from offshore infrastructure, so how it performs from China varies — but the axis here is where the content is allowed to live, not whether it loads. There is no lawful way around China's network controls, and 21YunBox neither provides nor suggests circumvention.

The data-residency question: content put into Box comes to rest offshore

Here is the gate most teams miss. A Box account stores your content on Box’s servers, and Box’s own Box Zones page frames the whole product as choosing where that content lives: it offers to let you “store your content in the geographic region of your choice,” with “in-region storage across 10 regions.” That is the tell. The ten regions Box has built — Australia, Canada, the EU, France, Israel, Japan, Singapore, Switzerland, the UK and the US, per Box’s 2026 expansion of the service — are all outside the mainland, and Box operates no China Zone. So the ordinary act of a Shanghai-based colleague saving a contract to a shared folder puts personal information collected in China onto storage outside the country. That is a cross-border transfer of personal information under China’s Personal Information Protection Law.

And it is not only the file body. The metadata Box keeps — who owns a file, who it was shared with, who opened it and when — and the account identities of your China-based collaborators are themselves personal information. Routing them to an overseas Box Zone transfers them across the border just as the documents are. Box Zones is a genuine data-residency control; it simply does not have a China setting to turn on.

PIPL puts the duty on the handler — you, not the content vendor. Articles 38–40 require notice, a separate consent distinct from a user’s agreement to use the product, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the content includes “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves.

If your organization is a critical information infrastructure operator, the Cybersecurity Law adds a harder duty still. Its Article 39 — formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, with the obligation unchanged — requires that personal information and important data collected and generated in the mainland be stored in the mainland. No Box Zone can satisfy that, whichever region you select, because none of the ten is in China. Which of these obligations actually bite on your specific content is a risk to confirm with counsel against what you truly collect and store.

Why there is no Box “China region” to switch on

With some vendors the fix is to move onto a mainland instance the vendor itself runs. Box is not one of them. Its data-residency choices top out at the ten Box Zones regions above, and even those must be purchased and are assigned by an administrator — “Admins determine where content is stored,” as Box puts it — with no mainland option in the menu. There is simply no China Zone to enable, and nothing of Box’s own in the mainland for an ICP filing (备案) to attach to.

So localizing content for China is not a toggle inside Box — it is a change of where the China-resident material actually lives. The work is to decide which China-collected files, metadata and identities must stay in the country (and hold them on a genuinely China-resident store or in-country deployment), and which may lawfully leave (and only then let those reach the Box your team already uses). That split is the heart of it, and it is settled before any question of how fast a file syncs.

The lawful path — map, localize, deliver

There is a lawful way to run enterprise content and collaboration for a China-facing product, and it has a clear shape — three moves, in order.

Map. Our China team works through your PIPL cross-border exposure and your data-residency duties: sorting which China-collected files, metadata and collaborator identities carry personal or important information that must stay in-country, which may lawfully be transferred, and where a data-export security assessment or an Article 39 storage duty applies. The legal conclusions are settled with your counsel; we frame the technical picture that feeds them.

Localize. Keep the China-resident content in-country — on a China-resident content store or an in-country deployment — and let only what may lawfully leave reach your global Box, so the folders, shares and workflows your team relies on keep working without the content store becoming the thing that carries data out of China unlawfully. 21YunBox stands up and integrates that China-legal option in place of storage that cannot run compliantly in the mainland.

Deliver. The China-facing app or portal that serves and receives those files is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is enterprise content and a China-facing app that run legally and compliantly for your users in China. What we never do, and what no one lawfully can, is manufacture a route around China’s network controls: we localize what must stay and deliver in-country, and circumvention is never on the table.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Box store Chinese users' files in China?
No. Box Zones offers ten storage regions — Australia, Canada, the EU, France, Israel, Japan, Singapore, Switzerland, the UK and the US — and mainland China is not among them; content not pinned to a Zone rests on Box's primary US infrastructure. So the files, metadata and collaborator identities your China users put into Box are held offshore, which makes them a cross-border transfer of personal information under PIPL: the handler (you, not Box) owes notice, a separate consent and a transfer mechanism.
Box opens fine from our Shanghai office — isn't that enough?
Reachability is the easy half and not the axis. Compliance in China turns on where the data lives, not on whether the app loads. Even with Box opening normally, personal information your China team puts into an offshore Box account is a cross-border transfer under PIPL, and for a critical information infrastructure operator or a large-volume handler there is an in-country storage duty an offshore Zone cannot meet. Treat it as a risk to work through with counsel against what you actually collect.
Can 21YunBox help make our Box setup work in China?
Yes. Our China team can map your exposure — assessing the PIPL cross-border and data-residency obligations that attach to the files, metadata and identities Box holds, for your entity, data volumes and users — then localize the China-resident content onto an in-country store and deliver your China-facing app on ICP-filed, in-country infrastructure, in front of the Box stack you already run, with no rebuild and no circumvention of any kind. Get in touch to work through your specific case.

ARTICLES RELATED TO BOX

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.