Does ClickUp Work in China? Data Residency, PIPL Cross-Border & ICP
ClickUp is reachable from the mainland, but reachability isn't the decision. ClickUp hosts your Workspace data on AWS — offering US, EU, Singapore, or APAC data residency, with no mainland-China region — so the tasks, docs, attachments, and member identities a China-facing team keeps in ClickUp sit offshore: a cross-border transfer of personal information under PIPL, with in-country storage duties for some handlers and an ICP filing for any public China-facing surface. A compliance-first look at ClickUp's data-residency and cross-border exposure, and the lawful in-country path — with no circumvention of any kind.
Does ClickUp work in China?
Reaching ClickUp isn't the China question — where it keeps your work is. ClickUp hosts your Workspace data offshore, so a workspace that opens fine from the mainland can still be an unlawful place to hold personal information collected in China.
ClickUp's own “Localized Data Hosting” page lets customers choose “US, EU, Singapore, or APAC Data Residency” — every option outside the mainland — and its sub-processor list (updated September 28, 2026) places its AWS infrastructure in the USA, Ireland, Germany, Australia, and Singapore. None is in China. So the tasks, documents, attachments, and member identities your China team keeps in ClickUp are a cross-border transfer of personal information under PIPL — notice, a separate consent, and a transfer mechanism (Articles 38–40) — and above certain thresholds a data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty no offshore region can meet, and any public China-facing surface you build needs an ICP filing an offshore workspace gives no footing for.
21YunBox maps your cross-border and data-residency exposure, localizes China-collected work onto a China-resident store, and delivers your China-facing surface in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.
What ClickUp's own documentation says about China
| Fact | Primary source |
|---|---|
| ClickUp offers data residency only in regions outside mainland China. On its “Localized Data Hosting” page, ClickUp invites customers to “Meet your data security goals by choosing US, EU, Singapore, or APAC Data Residency, and ensure that your core Workspace data remains within your chosen region.” Every region on offer sits outside the mainland and ClickUp names no China option, so the tasks, docs, attachments, and member records your China team keeps in it are held offshore — a cross-border transfer of personal information under PIPL (notice, separate consent, and a transfer mechanism, Articles 38–40). | ClickUp — Localized Data Hosting (clickup.com), retrieved 2026-10-09 |
| ClickUp's infrastructure runs on AWS, in regions that do not include mainland China. ClickUp's sub-processor list (last updated September 28, 2026) names Amazon Web Services as its infrastructure cloud service provider, with locations given as the USA, Ireland, Germany, Australia, and Singapore. There is no mainland-China region among them — so there is no in-country resource for Workspace data to rest on, and none to attach an ICP filing to. | ClickUp DPA — Sub-processors (clickup.com), last updated 2026-09-28, retrieved 2026-10-09 |
| China-collected work sent to an offshore workspace is a PIPL cross-border transfer. Moving personal information collected from people in mainland China into a ClickUp workspace hosted in the US, EU, Singapore, or APAC triggers PIPL Articles 38–40: notice, a separate consent distinct from the user's agreement to use the product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09 |
| For some handlers the data must stay in China, and a public surface must be filed. Where the handler is a critical information infrastructure operator, personal and important data collected in the mainland must be stored there (Cybersecurity Law Article 39, formerly Article 37; amended 2025, in force 2026-01-01) — a duty an offshore ClickUp region cannot satisfy — and large transfers or “important data” may require China's data-export security assessment before anything leaves. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37), amended 2025, in force 2026-01-01; Measures for the Security Assessment of Data Exports, CAC (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
Teams planning a China rollout usually ask whether ClickUp “works” there — by which they mean, will it load. For a work-management platform the decisive question is quieter: where do the tasks, documents, attachments, and the identities of the people doing the work actually live? ClickUp answers that in its own documentation, and the answer is offshore. That turns the real test from a performance question into a compliance one — because a ClickUp workspace that opens perfectly well from Shanghai can still be an unlawful place to hold personal information collected in China. And to be unambiguous from the outset: 21YunBox never uses or suggests circumvention of any kind — the work here is lawful data handling and compliant in-country delivery, not a network workaround.
ClickUp in China at a glance
| What decides it | In ClickUp's own terms — and China's law |
|---|---|
| What it is | ClickUp is a work- and project-management platform: tasks, documents, attachments, comments, and the identities of the team members who use it. There is no ClickUp region or operating entity inside mainland China. |
| Is reachability the question? | No. Even where the app loads from the mainland, the decision turns on where the data lives and whether that transfer is lawful — not on how fast a board renders. The only ways to force a connection a network declines to carry are forms of circumvention, which 21YunBox never uses or suggests. |
| Where does your work actually sit? | Offshore. ClickUp hosts Workspace data on AWS and offers US, EU, Singapore, or APAC data residency; its sub-processor list places that AWS infrastructure in the USA, Ireland, Germany, Australia, and Singapore. None is in mainland China, and there is no China region to select. |
| Keeping China-collected work in ClickUp | A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Above the regulator's thresholds it may need China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore workspace cannot meet. |
| Serving a public China-facing surface | A portal, client site, or intake form actually served to mainland visitors from inside China needs an ICP filing (备案) bound to a mainland hosting resource. An offshore ClickUp provides none, so there is nothing of its own to file against. |
| The lawful path | Keep China-collected work in-country on a China-resident store, move only what may lawfully leave, and deliver the China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention. |
The data-residency question: ClickUp keeps your work offshore
Here is the gate most teams miss. ClickUp’s residency page offers a choice — “US, EU, Singapore, or APAC Data Residency” — and promises that your “core Workspace data remains within your chosen region.” Every region on that menu sits outside mainland China. Its sub-processor list, last updated September 28, 2026, is more concrete still: the infrastructure cloud provider is Amazon Web Services, with locations given as the USA, Ireland, Germany, Australia, and Singapore. Data residency itself is an Enterprise option you request; absent that request, a workspace’s tasks, documents, and attachments are held in the United States. Either way there is no mainland-China setting to turn on.
So the ordinary act of a Shanghai-based colleague creating a task, uploading a file, or being added as a workspace member places personal information collected in China onto storage outside the country. That is a cross-border transfer of personal information under China’s Personal Information Protection Law. None of it depends on how quickly the board renders; it depends on whether that information had a lawful basis to leave the mainland at all.
The personal information is in the work itself — not just the login
It is tempting to picture a project tool as holding only abstract “tasks,” but the people are in the data: assignees, commenters, mentions, email addresses, and whatever your team writes into docs and attachments — customer names, contact details, HR notes, contract drafts. PIPL puts the duty on the handler — you, not the tool vendor. Articles 38–40 require notice, a separate consent distinct from a user’s agreement to use the product, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification.
Above the regulator’s thresholds, or where the content includes “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) — a review conducted before anything leaves. Which of these obligations bite on your specific workspace is a risk to confirm with counsel, measured against what your team actually keeps in ClickUp, not against the tool in the abstract.
No mainland region, so no in-country storage and no ICP footing
Two further questions settle before performance ever enters the picture. First, residency: if your organization is a critical information infrastructure operator — or moves personal information at volume — personal and important data collected in the mainland must be stored in the mainland. The Cybersecurity Law’s Article 39 — formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, with the obligation unchanged — sets that in-country storage duty, and no ClickUp region can satisfy it, because none of ClickUp’s regions is in China. Switching your residency region from US to EU or APAC relocates the data; it does not bring it onshore.
Second, licensing: any public China-facing surface you build around that work — a client portal, a help site, an intake form — that is actually served to mainland visitors from inside China carries an ICP filing (备案) duty, bound to a hosting resource physically in the mainland. An offshore ClickUp provides none, so there is nothing of ClickUp’s to file against. “We already run ClickUp” does not carry into China; the residency and licensing story the mainland asks for is exactly what an offshore workspace leaves open.
This is a risk map, not a verdict: whether you owe a separate consent, a transfer mechanism, in-country storage, an ICP filing, or some combination depends on your data volumes, your role as handler, and who your users are — worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
There is a lawful way to run work management for a China-facing team, and it has a clear order — three moves.
Map. Our China compliance team works through the PIPL cross-border exposure and the residency duties attached to what your team keeps in ClickUp — classifying which China-collected tasks, documents, attachments, and member records carry personal or important information that must stay in-country, which may lawfully be transferred, and where a data-export security assessment or an Article 39 storage duty applies. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.
Localize. Keep the China-collected material that must stay in the mainland on a China-resident store or a domestic work-management option, and let only what may lawfully leave sync to the ClickUp your global team already uses — so the boards, docs, and workflows people depend on keep working, without the tool itself becoming the thing that carries personal information out of China unlawfully. 21YunBox stands up and integrates that China-legal option in place of what cannot run compliantly in the mainland.
Deliver. The China-facing surface that serves or receives that work — portal, intake, client site — is a public mainland service in its own right, so it carries an ICP-filing duty and needs compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is work management and a China-facing surface that run legally and compliantly for your users in China. What we never do — and what no one lawfully can — is offer a way around a block or a border: we localize what must stay and deliver in-country, and circumvention is never on the table.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
