Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does SAP Concur Work in China? Data Residency, Sensitive Employee PI & PIPL Cross-Border

SAP Concur is reachable enterprise SaaS, so the China question isn't whether it loads — it's where your China employees' expense and travel data lives. SAP Concur's current C5 audit names six data centers (Dublin, Frankfurt, North Virginia, Ohio, Oregon, Tokyo), none in mainland China, so receipts, card and bank details, itineraries and often national-ID numbers collected from China staff rest offshore — a cross-border transfer of sensitive personal information under PIPL. A compliance-first look at the residency, sensitive-PI and cross-border exposure, and the lawful in-country path.

Does SAP Concur work in China?

SAP Concur is reachable from mainland China, so the honest answer is that loading isn't the problem. What decides the China question is data residency and consent — because an expense tool holds mostly sensitive personal information about your employees.

SAP Concur runs no data center in mainland China: its own 2026 C5 audit lists only six — Dublin, Frankfurt, North Virginia, Ohio, Oregon and Tokyo. So the receipts, card and bank details, itineraries and often passport or national-ID numbers your China staff enter rest offshore, which makes their collection a cross-border transfer (数据出境) of sensitive PI under PIPL (Articles 38–40, with the stricter Article 28 duties for financial, identity and whereabouts data), and it may trigger China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires such data to stay in China, which no offshore region can satisfy.

21YunBox maps your sensitive-PI, residency and cross-border exposure, localizes the China expense data onto a consented in-country footing, and delivers the China-facing app in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What SAP Concur's own documentation says about China

FactPrimary source
SAP Concur's current audit scope names six data centers — and none is in mainland China. SAP's SAP Concur C5 Audit Report 2026 page states, "The scope of this report covers the following data centers:" and lists Dublin (Ireland), Frankfurt (Germany), North Virginia, Ohio and Oregon (USA), and Tokyo (Japan), covering the audit period 1 April 2025 to 31 March 2026. No mainland-China location appears, so the expense and travel data SAP Concur holds for your China employees rests offshore. SAP Trust Center — SAP Concur C5 Audit Report 2026 (sap.com), retrieved 2026-10-09
An expense tool's core data is sensitive personal information under Chinese law. SAP Concur records financial accounts (corporate-card and bank-reimbursement details), travel itineraries and locations, and frequently passport or national-ID numbers. Under PIPL Article 28, financial accounts and individual whereabouts are expressly sensitive personal information, which requires a specific purpose and necessity, stricter safeguards, a separate consent, and a personal-information protection impact assessment (PIPL Articles 28–30, 55). Personal Information Protection Law of the PRC, Articles 28–30, 55 (cac.gov.cn), retrieved 2026-10-09
Holding China employees' expense data offshore is a PIPL cross-border transfer. Moving personal information collected from people in mainland China to a SAP Concur account hosted in the US, Ireland, Germany or Japan triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — with a data-export security assessment possible at volume or sensitivity. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09
For some handlers the data must stay in China — and a narrow HR route doesn't erase the duties. Where the handler is a critical information infrastructure operator, personal information generated in China must be stored in the mainland (Cybersecurity Law Article 39, formerly Article 37; PIPL Article 40) — which an offshore data center cannot do. China's 2024 cross-border-data-flow rules created a narrower route for data necessary for cross-border HR management, but it does not remove the consent, sensitive-PI or impact-assessment duties, nor a critical information infrastructure operator's in-country storage obligation. PIPL Article 40 (cac.gov.cn); PRC Cybersecurity Law Article 39 (formerly Article 37); Provisions on Promoting and Regulating Cross-Border Data Flows (2024), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a company running SAP Concur across a China workforce, the instinct is to ask whether employees in Shanghai or Shenzhen can open the app and file an expense report. They generally can — SAP Concur is enterprise travel-and-expense software reached from the mainland, not a consumer service blocked at the border. So loading is not where the China decision is made. What decides it is where the expense and travel data SAP Concur keeps about your China employees comes to rest, and whether that data — much of it sensitive under Chinese law — had a lawful basis to leave the country at all.

SAP Concur runs no data center in mainland China. Its own 2026 C5 audit report lists exactly six — Dublin, Frankfurt, North Virginia, Ohio, Oregon and Tokyo — so the receipts, corporate-card and bank-reimbursement details, itineraries and the passport or national-ID numbers your China staff enter come to rest in one of those offshore regions. The moment they do, you have made a cross-border transfer (数据出境) of personal information, and a separate body of law decides whether it was allowed.

SAP's own 'SAP Concur C5 Audit Report 2026' page, with the 'SAP Data Center Locations' section expanded, listing six data centers in scope — Dublin, Ireland; Frankfurt, Germany; North Virginia, USA; Ohio, USA; Oregon, USA; and Tokyo, Japan — with no mainland-China location
SAP's own SAP Concur C5 Audit Report 2026: “The scope of this report covers the following data centers:” — and it lists six, “Dublin, Ireland,” “Frankfurt, Germany,” “North Virginia, USA,” “Ohio, USA,” “Oregon, USA” and “Tokyo, Japan.” None is in mainland China, so the expense and travel records SAP Concur holds for your China employees rest offshore (audit period 1 April 2025–31 March 2026). Source: SAP Trust Center — SAP Concur C5 Audit Report 2026

SAP Concur in China at a glance

What decides it In SAP Concur's own terms — and China's law
What it is SAP Concur is cloud travel-and-expense management (Expense, Travel, Invoice). To reimburse and to book travel it records corporate-card and bank details, trip itineraries and locations, and frequently passport or national-ID numbers — a continuous record of identifiable employees' finances and movements.
Is it reachable from the mainland? Yes, in the ordinary sense: SAP Concur is enterprise SaaS reached from China, not a consumer platform blocked at the border. Reachability is not the China question. (Cross-border access and sync to an offshore data center can be inconsistent — an operational matter, not the decision.)
Where does the expense data sit? Offshore. SAP's current C5 audit names six data centers — Dublin, Frankfurt, North Virginia, Ohio, Oregon and Tokyo — none in mainland China. Your China employees' expense and travel records rest in one of them.
What kind of data is it? Largely sensitive personal information. PIPL Article 28 expressly treats financial accounts and individual whereabouts as sensitive PI, and the card, bank, location and ID data an expense tool holds falls inside it — requiring a specific purpose and necessity, stricter safeguards, a separate consent, and an impact assessment.
Collecting China expense data into it Holding it in an offshore SAP Concur is a cross-border transfer (数据出境) under PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism (CAC security assessment, CAC standard contract, or certification). A data-export security assessment may apply at volume or sensitivity. For a critical information infrastructure operator, Cybersecurity Law Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
The lawful path Keep the China expense and travel data in-country on a consented, PIPL-compliant footing, send abroad only what may lawfully leave, keep SAP Concur for your other markets, and deliver the China-facing app in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

An expense tool holds mostly sensitive personal information

Travel and expense management is, by its nature, a sensitive-data system. To reimburse an employee, SAP Concur records the financial accounts behind the payment — corporate-card numbers, bank-reimbursement details — and to book and settle travel it records itineraries, hotel stays and locations, frequently alongside a passport or national-ID number. Under China’s Personal Information Protection Law, sensitive personal information is data whose leak or misuse could readily harm a person’s dignity or their personal or property safety, and Article 28 names financial accounts and individual whereabouts among it expressly. The card, bank and location data an expense tool keeps sits squarely inside that category, and passport or national-ID numbers collected for travel are routinely handled as sensitive too.

That raises the bar rather than lowering it. Processing sensitive personal information at all requires a specific purpose and a demonstrated necessity, stricter protective measures, a separate consent distinct from any general HR or product agreement, and a personal-information protection impact assessment (PIPL Articles 28–30 and 55). Holding that sensitive data for your China employees in an offshore SAP Concur does not discharge those duties — and it adds another, because now the most tightly guarded category of data is also leaving the country.

Offshore expense data is a cross-border transfer under PIPL

Because SAP Concur stores your account in one of its six offshore data centers, the expense and travel records it keeps for people in mainland China sit outside the mainland by default. Moving them there is a cross-border transfer of personal information, and PIPL places the duty on the handler — you, the employer, not SAP Concur the processor. Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Where the volume or sensitivity is high, China’s data-export security assessment (数据出境安全评估) may be mandatory before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China, a duty an offshore data center cannot satisfy.

One nuance is worth naming, because a careful buyer will raise it. China’s 2024 rules on cross-border data flows opened a narrower route for personal information that is genuinely necessary for cross-border human-resources management under lawfully adopted labor rules, which can ease the transfer-mechanism step for some employee data. It is not a blanket exemption: it does not remove the notice, consent, sensitive-PI and impact-assessment duties; it does not cover data about people who are not your employees (a third party named in a trip or on an invoice); and it does not touch a critical information infrastructure operator’s in-country storage obligation. Whether your expense flows fit that route, and what your sensitive-PI handling must say, is a risk to confirm with counsel against what you actually collect.

A China “data option,” fapiao, and why it’s a question to confirm

SAP Concur does build for China — it has offered China-specific capabilities such as fapiao (发票) e-invoice handling for local expense reporting, and older product documentation tied certain China features to a China-based environment run with a local partner. That history matters, but it is not a current guarantee: SAP Concur’s present C5 audit scope names only the six offshore data centers above, with no mainland-China location among them. So whether a mainland-resident SAP Concur environment is available on your contract today, who legally operates it, and what data it actually keeps in-country are questions to settle directly with your SAP Concur account team and your counsel — not to assume. This page states only what SAP Concur publishes today, and today that is an offshore footprint.

None of this is a verdict that SAP Concur is “blocked” or “illegal.” It is a risk map: which obligations bite turns on your entity, the sensitive data your deployment holds, your role under Chinese law, and your China workforce — worth settling with counsel before your expense process depends on it.

The lawful path — map, localize, deliver

There is a lawful way to run travel and expense for a China workforce, and it has a shape. First, map: our China compliance team works through your PIPL exposure on both fronts — the sensitive-PI processing and the cross-border transfer — identifying which expense, card, travel and identity data collected in China must stay in-country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty applies, and what your consent and notice have to cover. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a China-resident footing for the China expense and travel data — a consented, in-country place for it to live and be processed — so reimbursement keeps working while that sensitive data stops leaving the mainland by default, and you keep SAP Concur for the markets where it already serves you.

Then deliver: the China-facing app your employees actually open is a service running in the mainland, so compliant in-country delivery matters as much as storage. The 21YunBox Optimizer sits in front of the SAP Concur access your China staff already use and delivers it from ICP-filed infrastructure inside the mainland, with no rebuild and no re-platform. What 21YunBox never does, and what no one lawfully can, is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never spirit personal information out of the country by some hidden route. The result is a travel-and-expense process that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Where does SAP Concur store my China employees' expense data?
Offshore. SAP Concur's current C5 audit names six data centers — Dublin, Frankfurt, North Virginia, Ohio, Oregon and Tokyo — none in mainland China, so your China employees' receipts, card and bank details, itineraries and ID numbers rest in one of those offshore regions. That makes their collection a cross-border transfer of sensitive personal information under PIPL. SAP Concur has historically referenced a China-based environment run with a local partner, but whether a mainland-resident option is available on your contract today, and who operates it, is a question to confirm with your SAP Concur account team and counsel.
Is sending China expense data to SAP Concur a cross-border transfer?
If your SAP Concur account is hosted in any of its offshore regions — the default, since it names no mainland-China data center in its current audit scope — then the expense and travel data it holds for your China employees is stored offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), plus the stricter Article 28 duties because card, bank, ID and location data is sensitive PI, and possibly a data-export security assessment. A narrow 2024 HR-management route may ease the mechanism for some employee data, but not the consent or sensitive-PI duties. Confirm your exact obligations with counsel.
Can 21YunBox make our SAP Concur setup compliant in China?
Yes — by mapping, localizing and delivering, never by circumvention. Our China team maps the PIPL cross-border, sensitive-PI and residency obligations that attach to the expense and travel data SAP Concur collects, for your entity, data volumes and workforce; localizes the China expense data onto a consented, in-country footing so it stops leaving the mainland by default; and delivers the China-facing app in-country on ICP-filed infrastructure, in front of the SAP Concur stack you already run. Get in touch to work through your specific case.

ARTICLES RELATED TO SAP CONCUR

CATEGORIES

Procurement

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.