Does ClickHouse Work in China? Data Residency, Localization & PIPL Cross-Border
ClickHouse is open-source and self-hostable, so the engine runs anywhere — including in mainland China. The real question is residency: ClickHouse Cloud runs on AWS, Google Cloud, and Azure with no mainland-China region, so a managed cluster of the event and behavioral data you collect in China rests offshore — a PIPL cross-border transfer, and at scale an in-country storage duty under Cybersecurity Law Article 39 (formerly Article 37). A compliance-first look at ClickHouse and the lawful China path.
Does ClickHouse work in China?
ClickHouse the engine runs fine in China — the real question is where its data comes to rest, and ClickHouse Cloud has no mainland-China region, so a managed cluster sits offshore.
ClickHouse is built to ingest enormous volumes of event, clickstream, and telemetry data — user IDs, IP addresses, device identifiers, and behavioral profiles — so a cluster is frequently a large concentration of China personal information. The engine is Apache-2.0 open source and self-hostable, so running it in-country is lawful and needs no migration; but ClickHouse Cloud's regions run on AWS, Google Cloud, and Azure with no mainland-China region, so loading China-collected personal data into it is a PIPL cross-border transfer, and for a critical information infrastructure operator or a large-volume handler the in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) is one an offshore region cannot meet.
Treat the specifics as a risk to confirm with counsel — we map exposure, we don't rule on it. Our China team can map your exposure →
What ClickHouse's own documentation says about China
| Fact | Primary source |
|---|---|
ClickHouse Cloud has no mainland-China region. Its own Supported cloud regions documentation says “The following tables list supported regions by cloud provider,” then lists every selectable region across AWS, Google Cloud, and Azure — from Africa to the Asia-Pacific. The nearest entries to the mainland are Hong Kong and Taipei; there is no cn- region. A managed cluster therefore comes to rest offshore. | ClickHouse Docs, “Supported cloud regions” (clickhouse.com/docs), retrieved 2026-10-10 |
| The ClickHouse engine is open source and self-hostable, so it is residency-neutral. ClickHouse is released under the Apache License 2.0 and runs wherever you install it — including self-hosted on mainland-China infrastructure. Whether your ClickHouse data has a residency problem is decided by where you deploy (an offshore managed region versus in-country), not by the software, which runs in-country without modification. | ClickHouse GitHub repository, Apache-2.0 license (github.com/ClickHouse/ClickHouse), retrieved 2026-10-10 |
| China personal data in an offshore ClickHouse cluster is a cross-border transfer under PIPL. Loading the event, clickstream, and behavioral records you collect from users in mainland China into a cluster hosted in an offshore region triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| At scale, an in-country storage duty applies that an offshore region cannot meet. For a critical information infrastructure operator — and, at the volumes the CAC specifies, a large-volume handler — personal information collected in the mainland must be stored in the mainland under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37). Because a ClickHouse cluster is often a very large concentration of behavioral data, it is precisely the kind of store that can cross that threshold. | PIPL Article 40; Cybersecurity Law of the PRC Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a product that serves mainland China, the first question about ClickHouse is not whether it installs or whether your application can connect to it — it can; ClickHouse is open-source software that runs wherever you deploy it. The question is where the data it holds is allowed to come to rest. ClickHouse is a high-performance, column-oriented OLAP database built to ingest enormous volumes of event, clickstream, log, and telemetry data — exactly the material that carries user IDs, IP addresses, cookie and device identifiers, and behavioral profiles. A ClickHouse cluster is therefore frequently one of the largest single concentrations of personal information a company holds about its China users. Two facts fix the compliance posture. The engine itself is Apache-2.0 open source and residency-neutral — self-hostable on mainland-China soil, which is the lawful lever. The managed ClickHouse Cloud, operated by ClickHouse, Inc. on AWS, Google Cloud, and Azure, publishes no mainland-China region, so a managed cluster comes to rest offshore.
ClickHouse in China at a glance
| What decides it | In ClickHouse's own terms — and China's law |
|---|---|
| Where does the data physically rest? | ClickHouse Cloud runs on AWS, Google Cloud, and Azure, and its own Supported cloud regions documentation lists every selectable region — from Africa to the Asia-Pacific. None is in mainland China; the nearest are Hong Kong and Taipei, both outside it. A managed cluster therefore rests offshore. The engine, by contrast, is Apache-2.0 open source and runs anywhere you install it, including self-hosted on mainland-China infrastructure. |
| What a ClickHouse cluster holds — and why it's personal information | ClickHouse exists for high-volume event, clickstream, log, and telemetry analytics. That data routinely carries user IDs, IP addresses, cookie and advertising identifiers, device fingerprints, precise timestamps, and the behavioral profiles built from them — personal information under PIPL, and sensitive personal information under Article 28 where precise location, financial, health, or minors' data appear. The volume is the point: a cluster is often a very large store of China user data. |
| Your China users' records = a cross-border transfer if offshore | Loading personal information collected from users in mainland China into a cluster hosted in an offshore region is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. |
| The in-country storage duty | For a critical information infrastructure operator — and, at the volumes the CAC specifies, a large-volume handler — personal information collected in the mainland must be stored in the mainland under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37); the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged). An offshore ClickHouse Cloud region structurally cannot meet it. |
| Reachability isn't the axis — the lawful path | That a cluster answers quickly changes nothing: the data still rests offshore, and the residency duty still applies. Because the engine is residency-neutral, the lawful path is to run it in-country — self-hosted on mainland infrastructure or on a licensed in-country/sovereign managed option — and to put any China-facing surface in front of it on ICP-filed delivery. |
Where the data actually rests
ClickHouse’s position is set by where a cluster runs, not by a load-time test. The managed service, ClickHouse Cloud, runs on Amazon Web Services, Google Cloud, and Microsoft Azure, and its own Supported cloud regions documentation lists every region you can choose. That list runs from Africa to the Middle East to the Asia-Pacific — and its nearest entries to the mainland are Hong Kong and Taipei. Neither is mainland China: there is no cn- region anywhere on the page. Data placed in those regions is still offshore relative to the mainland, and moving mainland-collected personal information to it is still a cross-border transfer out of China. ClickHouse’s own published sub-processor list places the ClickHouse Cloud control plane on AWS in the United States, Germany, and Singapore, with the data location you select drawn from that same offshore region list. Bring Your Own Cloud does not change the map either — it deploys the service into your own AWS, Google Cloud, or Azure account in those same offshore regions, still under an offshore control plane.
Because of all this, the familiar “does it respond from Shanghai?” test is the wrong question — which is why this page publishes no first-party China latency figure for ClickHouse; speed is not the axis for data that is sitting in the wrong country. The engine, by contrast, is residency-neutral: it is free, Apache-2.0 software, and it runs wherever you install it, including self-hosted on mainland-China infrastructure. So the residency question is entirely about how you deploy, not about whether the software works. See our explainer on cross-border data transfers under PIPL.
What it holds is personal information
A ClickHouse cluster is rarely a handful of rows. ClickHouse exists to make high-volume analytics fast: it is built to ingest and query event streams at massive scale — page views, clicks, app telemetry, ad impressions, logs, sensor and IoT streams, and user-behavior records. That is precisely the data that identifies people. User IDs, IP addresses, cookie and advertising identifiers, device fingerprints, precise timestamps, and the behavioral profiles you build from them are personal information under China’s Personal Information Protection Law wherever they relate to an identified or identifiable person, and sensitive personal information under PIPL Article 28 where precise location, financial, health, or minors’ data appear.
The volume is not incidental — it is the whole point of using ClickHouse, and it is also what sharpens the China question. A handler that processes personal information at the scale the Cyberspace Administration of China specifies falls under heightened duties: a mandatory data-export security assessment before personal information may leave the country, and, for a critical information infrastructure operator or a handler holding data at those volumes, an in-country storage duty. Under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37), personal information and important data collected in the mainland must be stored in the mainland. A ClickHouse Cloud region in an offshore jurisdiction structurally cannot satisfy that duty, and the larger your cluster, the more likely you are to be inside the threshold that triggers it.
Running it offshore doesn’t meet the residency duty — and what does
If a managed ClickHouse Cloud region in another country cannot hold mainland-collected personal information that the law requires to stay home, the fix is not to reach back to that offshore endpoint from inside China — it is to run ClickHouse where the data must live. This is where ClickHouse’s open-source nature is decisive, and it is good news: because the engine is residency-neutral and self-hostable, you do not have to migrate off ClickHouse or rebuild your analytics to become compliant. You run the same engine, in-country.
Two in-country patterns are lawful. The first is self-hosting the open-source ClickHouse server on mainland-China infrastructure, so the cluster and the personal information in it never leave the country; replicating or loading data into a mainland cluster is routine ClickHouse operation, not a re-platforming. The second is a licensed in-country or sovereign-cloud managed option operated on the mainland by a local operator, subject to that operator’s own availability and compliance, which you confirm with them directly. In either case you transfer offshore only the aggregated or de-identified results that may lawfully leave, and you keep the raw, user-level China data in-country. None of this is a verdict on your specific situation: whether you are a critical information infrastructure operator, which volume thresholds you cross, which transfer mechanism applies, and whether any transfer is lawful at all are questions to settle with your counsel against the data you actually hold and the entity that holds it.
The lawful path — map, localize, deliver
There is a lawful, durable way to run ClickHouse for users in China, and it keeps the shape of your stack intact. 21YunBox is a compliant overlay, not a migration — and a partner to ClickHouse, not a competitor. Our China team works in three moves. We map your exposure: the PIPL cross-border question, the data-export security assessment, the in-country storage duty for critical information infrastructure operators and large-volume handlers, and the ICP filing (备案) obligation on any China-facing surface — read against your entity, your data volumes, and whose personal information sits in the cluster. We localize the database by running it in-country — self-hosted open-source ClickHouse on mainland infrastructure, or a licensed in-country/sovereign managed option — so the personal information stays on mainland soil; localize means standing up a lawful in-country cluster, never a route back to an offshore endpoint. And we deliver every China-facing surface in front of the database — the application, the API edge, the admin and reporting portals your mainland users reach — in-country over ICP-filed infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild and no second codebase. The result runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization
- China’s data-export security assessment measures
- How to get an ICP filing for China
