Does Branch Work in China? Data Residency, PIPL Cross-Border Device Data & App-SDK Rules
Branch is a mobile deep-linking and attribution platform — its SDK collects device identifiers, IP and click data and resolves them into a cross-device identity and attribution graph. Branch runs that data in only two regions, North America and an EU data center in Ireland, with no mainland-China region, so collecting it from your China users is a cross-border transfer of personal information under PIPL, the identity graph is profiling, and the app that embeds the SDK carries China's filing and app-store SDK personal-information duties. A compliance-first look at the residency, cross-border, profiling and app-SDK questions — and the lawful in-country path.
Does Branch work in China?
Whether you can run Branch for a mainland-China app is a data-residency, consent and app-licensing question under China's law — not a speed one. Branch's links mostly reach China, but reachability is not what decides it. Branch is a mobile deep-linking and attribution platform: its SDK collects device identifiers, IP and click data and resolves them into a cross-device identity and attribution graph, and where that personal data rests is what China's law responds to.
Branch runs that data in only two regions — North America and an EU data center in Ireland (AWS) — with no mainland-China region, so the device and click data its SDK gathers from your China users comes to rest offshore. That makes its collection a cross-border transfer (数据出境) PIPL governs (notice, a separate consent, and one transfer mechanism, Articles 38–40), and it may trigger China's data-export security assessment. Building a cross-device profile of identifiable users needs its own PIPL consent and may be automated decision-making under Article 24. The app that embeds the SDK is its own compliance object too: a mobile app distributed in the mainland carries an app filing duty and MIIT and app-store SDK personal-information rules. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet.
21YunBox maps your cross-border, residency, profiling and app-SDK exposure, localizes the China device and attribution data onto a consented, in-country footing (sending Branch only what may lawfully leave), and delivers your China-facing app in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel. Our China team can map your exposure with you →
What Branch's own documentation says about China
| Fact | Primary source |
|---|---|
| Branch runs your data in only two regions — North America and an EU data center in Ireland — with no mainland-China region. Branch's EU Hosted Data page states customers “can now choose to process and store your Branch data at our new AWS-powered data center in Ireland,” and that “data cannot be split between the NA and EU regions - all of the data associated with a single Branch App ID must flow to a single region.” The two regions it names are North America (NA) and the EU; there is no mainland-China option, so the device and click data your app collects in China rests offshore. | Branch Help Center — EU Hosted Data (help.branch.io), retrieved 2026-10-09 |
| Branch's SDK is built to collect device identifiers — including, via a China-specific setting, IMEI. In Branch's Advanced Link Configuration, the “Enable China Features” setting (disabled by default) is described as: “China Features include the ability to collect IMEI on non-Google Android devices.” Device identifiers such as IMEI are personal information under PIPL, and collecting them from users in China and sending them to an offshore Branch region is a cross-border transfer carrying notice, consent and transfer-mechanism duties. | Branch Help Center — Advanced Link Configuration (help.branch.io), retrieved 2026-10-09 |
| Branch itself documents that its links are not uniformly reachable in China. Branch's deep-link reference FAQ, “How do I deep link effectively in China?”, states: “We have found that our links don't work with some Chinese ISPs,” and lists its own tests — “China Mobile: Works as expected,” “China Net: Works as expected,” and “Great Wall: Timeout error, ERR_TIMED_OUT on link response.” Reachability is the delivery half of the question, not the legal half that decides whether you may use it — and the answer to any gap is never a network workaround. | Branch Help Center — Deep Linking Full Reference, “How do I deep link effectively in China?” (help.branch.io), retrieved 2026-10-09 |
| China-collected device and click data sent to an offshore Branch account is a PIPL cross-border transfer. Moving personal information collected from users in mainland China to a Branch account hosted in North America or the EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above thresholds it may also require China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty. | Personal Information Protection Law of the PRC, Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For an app that measures and deep-links users in mainland China, the instinct with Branch is to ask whether its links even reach — and on the major carriers they mostly do. But reachability is not where the China decision is made. Branch is a mobile deep-linking and attribution platform: its SDK collects device identifiers, IP addresses and click data from the handset, resolves them into a cross-device identity and attribution graph, and serves deferred deep links on its app.link domains. What settles whether you can run it for China is where that personal data comes to rest, whether you had a lawful basis to build that profile in the first place, and the duties that attach to the app itself — each a question China’s law answers before performance is ever in frame. Branch sets out the residency facts in its own documentation.
Branch in China at a glance
| What decides it | In Branch's own terms — and China's law |
|---|---|
| What it is | Branch is a mobile deep-linking and attribution platform. Its SDK collects device identifiers, IP addresses and click data, resolves them into a cross-device identity and attribution graph (the Branch Link Graph), and serves deferred deep links on its app.link domains — so it holds a continuous, identity-linked record of who clicked what and which device opened the app. |
| Is it reachable from the mainland? | Mostly, on the major carriers — but not uniformly. Branch's own FAQ says its links “don't work with some Chinese ISPs,” reporting China Mobile and China Net as “Works as expected” and the Great Wall ISP as a “Timeout error.” Reachability is the delivery half of the question, not the China decision — and it is never to be solved by circumvention. |
| Where does the data live? | Offshore. Branch documents only two regions — North America (NA) and an EU data center in Ireland (AWS) — and an App ID's data must flow to a single region. There is no mainland-China region, so your account and every record in it sit outside the mainland. |
| Collecting China device & click data into it | Device identifiers, IP and click data are personal information. Holding them in an NA or EU Branch is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Resolving them into a cross-device profile needs its own PIPL consent and may be automated decision-making under Article 24. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet. |
| The app that embeds the SDK | Its own compliance object. A mobile app distributed in mainland China carries a filing duty of its own — the app (APP) filing that extends China's ICP 备案 regime to mobile apps — and must meet MIIT and app-store SDK personal-information disclosure rules. An embedded offshore attribution SDK that gathers device identifiers — Branch even offers a China setting to collect IMEI on non-Google Android devices, disabled by default — is a known point of friction in app-store review. |
| The lawful path | Keep China-collected device and attribution data on a consented, in-country, PIPL-compliant footing; send Branch only what may lawfully leave; meet the app-store and SDK disclosure rules; and deliver the China-facing app in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention. |
Where the attribution data lives — an offshore store is a cross-border transfer
Branch’s position is set in its own documentation, not by a load-time test. Its EU Hosted Data page describes a single expansion of where your data can rest — “you can now choose to process and store your Branch data at our new AWS-powered data center in Ireland” — and states that “data cannot be split between the NA and EU regions - all of the data associated with a single Branch App ID must flow to a single region,” with aggregate data and account metadata remaining “stored in the NA region.” Put together, the two regions Branch names are North America and the EU. There is no mainland-China region to choose.
That settles the first question before performance enters it. The device identifiers, IP addresses and click data Branch’s SDK gathers from people in China are personal information, and loading them into an NA or EU Branch account is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the product team, not Branch the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your app, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the data is “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China, an in-country storage duty an offshore Branch region cannot satisfy. Flipping an App ID from the NA region to the EU region does not help: it relocates the cross-border transfer, it does not end it.
The identity graph is a profile — and profiling is its own PIPL duty
Residency is only half of it. Branch’s core value is resolving otherwise-disconnected signals — a click here, an install there, a device fingerprint, an IP — into a single, persistent cross-device identity and attribution graph tied to a user. That is, by design, a behavioral profile of an identifiable person. Under PIPL, tracking identifiable individuals is itself processing of personal information and needs its own lawful basis: in practice, informed consent obtained before the SDK begins collecting, with a clear notice of what is gathered and why. The cross-border transfer to an offshore Branch then needs a further, separate consent on top of that.
Building automated profiles across devices can also engage PIPL Article 24, which governs automated decision-making and attaches transparency and fairness obligations to it. Whether your identifiers count as “personal information” in a given flow, whether any field is sensitive, and whether your matching rises to automated decision-making are questions that sit with you as the handler and are worth settling with counsel — not points the SDK’s defaults resolve for you.
The app is its own compliance object — filing and app-store SDK rules
Even setting aside where the data rests, the app that embeds the Branch SDK is separately regulated in mainland China. A mobile app distributed to mainland users carries a filing duty of its own — the app (APP) filing that extends the country’s ICP 备案 regime to mobile apps — and Chinese app stores, together with MIIT’s personal-information rules, require apps to disclose the SDKs they embed and the personal information those SDKs collect. An offshore attribution SDK that gathers device identifiers is a well-known point of friction in that review: Branch’s own Advanced Link Configuration even exposes an “Enable China Features” setting whose stated function is “the ability to collect IMEI on non-Google Android devices” (disabled by default). IMEI is a hard device identifier, and collecting it from users in China feeds straight back into the residency and consent questions above. This is a licensing-and-disclosure exposure on the app itself, separate from — and stacked on top of — the data-transfer one, and no amount of network tuning resolves it.
Reachability is the smaller half — and never solved by circumvention
Branch’s own FAQ, “How do I deep link effectively in China?”, reports that its links “don’t work with some Chinese ISPs” — listing China Mobile and China Net as “Works as expected” and the Great Wall ISP as a “Timeout error, ERR_TIMED_OUT on link response.” That inconsistency is a delivery matter, not the legal one, and for that reason this page publishes no first-party China latency figure for Branch: speed is not the axis for a decision that turns on residency, consent and licensing. The temptation when links are flaky is a network workaround; 21YunBox neither uses nor suggests any form of circumvention — it is both a compliance risk and beside the point. The productive question is how to keep the China data and the China app on a lawful footing.
This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, in-country storage, an app filing, SDK disclosure, or some combination depends on your data volumes, your role as handler, your identifiers, and who your users are — worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
There is a lawful way to run attribution and deep-linking for a China-facing app, and it has a shape. First, map: our China team works through your PIPL exposure on every front — the device and click data the SDK collects, the cross-border transfer to an offshore Branch region, the profiling the identity graph performs, and the filing, app-store and SDK-disclosure duties on the app — identifying which data collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty bites, and what your consent and disclosure flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we stand up and integrate a consented, China-resident footing for the device and attribution data that must stay in the country — the lawful in-country pattern, consented and processed and stored in the mainland — so the measurement you depend on keeps working while that data stops leaving the country by default, and you keep Branch for the markets where it already serves you.
Then deliver: the China-facing app that emits those events is itself a public service in the mainland, so it carries a filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is attribution and deep-linking that run legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
