Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Collibra Work in China? Metadata, PIPL & Data Residency

Collibra Platform is a hosted SaaS managed on AWS and Google Cloud across the US, EU, Canada, UK, Australia and Singapore, with no mainland-China region — so the metadata, data-steward PII and profiling samples it holds over your whole data estate come to rest offshore: a PIPL cross-border transfer. A compliance-first look at where your governance layer is allowed to live.

Does Collibra work in China?

Reaching Collibra isn't the question — where the metadata, steward PII and profiling samples it holds across your data estate come to rest is, and that's offshore.

Collibra Platform is a hosted SaaS managed on AWS and Google Cloud in the US, EU, Canada, UK, Australia and Singapore — no mainland-China region. So the catalog metadata, the PII of the data stewards and owners it records, and the samples its profiling and classification pull from the underlying data are stored outside the mainland: a cross-border transfer under PIPL, with an in-country storage duty under Cybersecurity Law Article 39 (formerly Article 37) for CII operators and large-volume handlers.

An in-country Edge runtime narrows what crosses but leaves the catalog offshore — a risk map, not a ruling. Our China team can map your exposure →

What Collibra's own documentation says about China

FactPrimary source
Collibra Platform is a hosted SaaS, managed on AWS and Google Cloud. Collibra's infrastructure documentation describes the platform as "primarily deployed as a Software-as-a-Service (SaaS) solution, managed by Collibra on leading public cloud platforms, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)," a "multi-cloud deployment" with no mainland-China hosting region among its public-cloud locations. Collibra Documentation — Infrastructure and base components (retrieved 2026-10-10)
Collibra's in-country runtime, Edge, still reports to an offshore control plane. A Collibra Edge site "processes the data source information on the Edge site and sends the process results to Collibra Platform," and its integration capability repository "resides on the Collibra Platform" — the offshore SaaS — so raw data can stay local while the catalog, metadata and results do not. Full in-country residency requires the self-hosted edition (CPSH). Collibra Documentation — About Edge sites (retrieved 2026-10-10)
Sending mainland personal information offshore is a regulated cross-border transfer. Moving personal information collected in China to an offshore region requires notice, a separate consent, and a transfer mechanism — a CAC security assessment, the standard contract, or certification (PIPL Articles 38–40). Metadata, steward PII and profiling samples all count. PIPL Articles 38–40
Critical-infrastructure and large-volume handlers must store mainland personal information in China. The data-localization duty sits at Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered it from 37 to 39 (substance unchanged) — alongside PIPL Article 40. Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a team serving mainland China, the question about Collibra was never whether the catalog loads. It almost always does. The question is where the records behind it are allowed to come to rest — and Collibra answers that in its own documentation. The Collibra Platform is, in the company’s words, “primarily deployed as a Software-as-a-Service (SaaS) solution, managed by Collibra on leading public cloud platforms, including Amazon Web Services (AWS) and Google Cloud Platform (GCP).” Collibra’s subprocessor list places those cloud hosts in the US, EU, Canada, UK, Australia and Singapore — none in mainland China. Yet Collibra is the governance layer sitting over your entire data estate: it holds the metadata that maps every system, table and column, the names, emails and roles of the data stewards and owners written throughout it, and — through profiling and classification — sampled values pulled from the underlying data itself. Reaching the catalog is the delivery half; where that governance layer comes to rest is the exposure.

Collibra's Infrastructure and base components documentation stating the Collibra Platform is deployed as SaaS managed on Amazon Web Services (AWS) and Google Cloud Platform (GCP) — a multi-cloud deployment with no mainland-China region
"This multi-cloud deployment supports global reach and compliance with regional data protection regulations." Collibra Platform Cloud is managed on AWS and Google Cloud, and its documented hosting regions — the US, EU, Canada, UK, Australia and Singapore — include none in mainland China. Source: productresources.collibra.com/docs/collibra/latest

Collibra in China at a glance

What decides it In Collibra's own terms — and China's law
Where the records live The Collibra Platform is "managed by Collibra on leading public cloud platforms, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)," and its subprocessor list places those hosts in the US, EU, Canada, UK, Australia and Singapore. None is in mainland China, and the regulatory region is fixed once, at onboarding.
What it holds, and why it's personal information The metadata that maps every system, table and column across your estate; the names, emails, roles and reporting lines of the data stewards, owners and users recorded throughout it; and, through profiling and classification, sampled values drawn from the source data. Those samples can surface Article 28 sensitive personal information — national ID, financial, health, biometric or location fields.
Your mainland data on the platform Metadata, steward PII and profiling samples collected in China and written to an offshore AWS or Google Cloud region are a cross-border transfer PIPL governs — notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40).
In-country storage duty A critical information infrastructure operator or large-volume handler owes an in-country storage duty the hosted platform cannot meet — mainland personal information must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39.
Is it reachable? Treat reachability as the delivery half, not the question. A China-facing surface — a catalog view, a data-access request workflow, a dashboard shared with mainland staff — also needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33).

No mainland region, so the governance layer leaves the country

Collibra’s infrastructure documentation is explicit about where the Platform runs: it is “primarily deployed as a Software-as-a-Service (SaaS) solution, managed by Collibra on leading public cloud platforms, including Amazon Web Services (AWS) and Google Cloud Platform (GCP),” and that “multi-cloud deployment supports global reach and compliance with regional data protection regulations.” The regions behind that phrase, as set out in Collibra’s subprocessor list, are the US, the EU, Canada, the UK, Australia and Singapore. Not one is in mainland China, and a tenant’s regulatory region is chosen once, at onboarding, from that offshore set. So when your mainland teams catalog a new source, assign a steward, or run a classification job, the metadata and results are written to whichever offshore region your environment sits in. Under China’s Personal Information Protection Law, sending personal information collected in the mainland to one of those regions is a cross-border transfer — and the handler on the hook is you, not the vendor.

The metadata Collibra holds is personal information

It is tempting to treat a catalog as holding only “data about data,” not personal data — but that distinction does not survive contact with PIPL. Collibra’s records are dense with people: every asset carries the name, email, role and reporting line of the steward who owns it, the reviewer who certified it, and the users who requested access. Those identifiers are personal information the moment they describe an identifiable person, and a mainland employee’s or user’s personal information sent to an offshore region is governed by PIPL on export. The exposure widens because of what a modern catalog does to the data itself: profiling and classification read samples of the underlying columns to detect and label what they contain. A column flagged as holding national ID numbers, salaries, health codes or precise location is, by definition, carrying examples of exactly the Article 28 sensitive personal information that profiling pulled in to classify it — and Article 28 sets a higher bar: a specific purpose, strict necessity, and separate consent. For a handler that crosses the data-export security assessment threshold, the whole export may need a CAC review before any of it lawfully leaves. Because the governance layer sits across the entire estate, the exposure is not one pipeline — it is a map of, and a sample from, everything.

Narrowing the exposure doesn’t close the door

Collibra gives you real levers to reduce what crosses the border, and they are worth pulling. A Collibra Edge site is “a cluster of Linux servers for accessing and processing data close to where it resides”; it “processes the data source information on the Edge site and sends the process results to Collibra Platform,” so the raw source records can stay inside your network while only outputs travel out. The fuller lever is Collibra Platform Self-Hosted (CPSH), which “enables you to install your Collibra Platform on an infrastructure of your choice.” Be clear, though, about what each one does. With the managed Collibra Platform, Edge still sends its results — the metadata, profiling output and classification labels — to a control plane whose integration capability repository “resides on the Collibra Platform,” which is the offshore SaaS. Edge changes the contents and timing of the transfer; it does not change the fact of it, and the catalog, the steward PII and the classification results still come to rest offshore. Only running the platform itself in-country — the self-hosted path — keeps the governance layer on mainland soil, and even then a China-facing surface needs an ICP filing tied to a mainland hosting resource before it may be served, whatever you do about the data behind it. This is a risk map, not a verdict: whether you owe a transfer mechanism, a separate consent, in-country storage under Cybersecurity Law Article 39 (formerly Article 37), an ICP filing, or some combination turns on your entity, your data volumes, how much of the catalog is personal or sensitive, and who your users are — worth settling with counsel before you point a single mainland user at the platform.

The lawful path — map, localize, deliver

You do not have to drop Collibra to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and for a platform like this, a partner that sits alongside the governance tool you already run, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads your PIPL cross-border, data-residency and sensitive-PI obligations against your actual entity, your data volumes, and who your mainland users and stewards are — so the exposure in your metadata, steward records and classification output is written down before anything is rewired.

Localize. Because the managed platform has no mainland region, we stand up consented, in-country storage and processing for the records that must stay on mainland soil — including the self-hosted and Edge deployments Collibra supports — so the governance data China requires to remain in-country does, while only the minimized, lawfully transferable subset ever reaches an offshore tenant.

Deliver. For any China-facing surface — a catalog view, a data-access request workflow, a dashboard shared with mainland staff — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase, no move off the platform. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.

The goal is plain: your data-governance program runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Collibra available in mainland China?
There is no mainland-China hosting region to select — Collibra Platform's managed cloud runs on AWS and Google Cloud in the US, EU, Canada, UK, Australia and Singapore. The catalog is typically reachable, but the metadata, data-steward PII and profiling samples it holds come to rest offshore, which is the compliance question. Reaching the tool is not the same as lawfully storing Chinese personal information in it.
Does running Collibra over China data trigger PIPL?
If you catalog, profile or steward the personal information of mainland users or employees in it, yes. Sending that metadata, PII and sampled data to an offshore AWS or Google Cloud region is a cross-border transfer under PIPL Articles 38–40, requiring notice, a separate consent, and a transfer mechanism. Classification samples can also be Article 28 sensitive personal information, which carries a higher bar. Confirm the specifics with counsel.
Does running Collibra Edge in our own network make us compliant?
Not on its own. Edge processes data close to the source and sends only results to Collibra Platform, so raw records can stay in-country — but the metadata, profiling output and classification labels still land on the offshore managed Platform, and its control plane lives there. Full in-country residency means the self-hosted edition (CPSH). 21YunBox maps the exposure, localizes what must stay on mainland soil, and delivers any China-facing surface over ICP-filed infrastructure — as a compliant overlay, not a migration.

ARTICLES RELATED TO COLLIBRA

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.