Does Confluence Work in China? Data Residency, PIPL Cross-Border & ICP
Confluence is reachable from mainland China — but reaching it is not the question. Atlassian Cloud stores your Confluence pages, attachments and the identities behind every edit offshore (data residency is offered in a dozen regions, mainland China not among them), so documentation created by a China team is a cross-border transfer of personal information under PIPL — with an in-country storage duty for some handlers and an ICP filing for any public China-facing space. A compliance-first look at the data-residency question and the lawful in-country path, with no circumvention of any kind.
Does Confluence work in China?
Confluence usually reaches China, so reachability isn't the question. What decides compliance is where your Confluence content lives — the pages, attachments and the identity of whoever wrote them sit in Atlassian Cloud, outside mainland China.
Atlassian's own data-residency documentation lets you pin in-scope product data — Confluence included — to one of a dozen locations (Global, Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the UK or the USA), and "By default, all Atlassian apps are hosted in the Global location, which includes all of our AWS regions." None of those is mainland China. So documentation created by a team in China is held offshore — a cross-border transfer of personal information under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–40), with an in-country storage duty for a critical information infrastructure operator (Cybersecurity Law Article 39 (formerly Article 37)) and an ICP filing for any public China-facing space.
This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it is worth settling with counsel. Our China team can map your exposure with you →
What Atlassian Confluence's own documentation says about China
| Fact | Primary source |
|---|---|
| Atlassian lists the locations your Confluence data can live in — and mainland China isn't one. Atlassian's data-residency documentation says "The following locations are available for you to select from:" and names Global, Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, adding that "By default, all Atlassian apps are hosted in the Global location, which includes all of our AWS regions." Confluence is named among the in-scope products, and no option sits inside mainland China — so documentation created by a China team is held offshore, a cross-border transfer of personal information under PIPL (notice, separate consent and a transfer mechanism, Articles 38–40). | Atlassian Support — Understand data residency, retrieved 2026-10-09; PIPL Articles 38–40 |
| With "Global," Atlassian itself chooses where the content sits and can move it between offshore realms. Atlassian's Confluence data-residency page (last updated October 9, 2026) describes the default as "Global: In-scope data is hosted within realms determined by Atlassian: data may be moved between realms as needed," and the pinnable realms it lists — Frankfurt, Dublin, US East, US West, Sydney, Singapore, Mumbai, Seoul, Tokyo, London and Zurich — are all outside the mainland. There is no mainland-China realm to pin to, so residency cannot be set to China. | Atlassian Developer — Confluence data residency, retrieved 2026-10-09 |
| For some handlers the content must stay in China — and a public space served from the mainland needs an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty an offshore Confluence site cannot meet. And any public-facing space actually served to mainland visitors from inside China turns on an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Atlassian Cloud does not provide. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33 |
| The self-managed path is Confluence Data Center — but Atlassian has set its wind-down. Confluence Server reached end of support on February 15, 2024, leaving Data Center as the self-managed option, which could be deployed on in-country infrastructure. By Atlassian's own licensing page, "On March 30, 2026 at 23:59 PST, new customers will no longer be able to purchase new Data Center subscriptions," and "End of life for impacted Data Center products will take place on March 28, 2029 at 23:59 PST." Treat a self-managed in-country deployment as a shape to confirm with counsel and weigh against that lifecycle, not a permanent fix. | Atlassian — Data Center end of life, retrieved 2026-10-09; Atlassian Support — Confluence Server end of support (Feb 15, 2024) |
Sources verified by the 21YunBox compliance team on 2026-10-09.
Ask whether Confluence works in China and the honest first answer is that reaching it is not usually where a China-facing team gets stuck. Confluence Cloud runs on Atlassian’s offshore infrastructure and ordinarily loads from the mainland, so this is not a speed story. The decision that actually matters sits one layer down, in what Confluence is for: it is where a team keeps its documentation — the spaces, the pages, the specs and meeting notes, the files people attach, and, recorded against every edit, who wrote it and when. All of that is content, and by Atlassian’s own account it is stored in Atlassian Cloud, outside mainland China. The moment that documentation is created by a team in China, you have a data-residency and cross-border question under Chinese law — and it would stand even if every page opened instantly, which is why this is a compliance decision rather than a performance one.
To be clear from the outset: 21YunBox never uses or suggests circumvention of any kind, and nothing on this page depends on it. The question here is not how to reach Confluence — it already reaches China — but whether the content it holds is allowed to live where Atlassian keeps it.
Atlassian Confluence in China at a glance
| What decides it | In Confluence's own terms — and China's law |
|---|---|
| What it is | Confluence is Atlassian's team-documentation, knowledge-base and wiki product (Atlassian Cloud): the spaces, pages, attachments, comments and the identity of whoever created or edited each one are stored in Atlassian's cloud. There is no Confluence Cloud region or operating entity inside mainland China. |
| Can it be reached from the mainland? | Generally, yes — Confluence Cloud runs on Atlassian's offshore infrastructure and reaching it is not usually where a China-facing team gets stuck. But reachability is not the China question, and 21YunBox never uses or suggests circumvention of any kind. |
| Where does the content actually live? | Offshore. Atlassian's data-residency documentation lets you pin in-scope data — Confluence included — to Global, Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the UK or the USA, defaulting to Global across all of its AWS regions. None is in mainland China. |
| Keeping China-created content in an offshore site | A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Above the regulator's thresholds it may trigger China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore site cannot meet. |
| Serving a public China-facing space | A space served to mainland visitors from inside China needs an ICP filing (备案) bound to a mainland hosting resource. Atlassian Cloud names no mainland region, so there is nothing of its own to file against. |
| The lawful path | Keep China-resident content in-country on a consented in-country store (a self-managed Data Center deployment is one possible shape — mind Atlassian's end-of-life), move only what may lawfully leave, and deliver the China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention. |
The documentation itself is personal information — and it lives offshore
Here is the gate most teams miss. A knowledge base feels like neutral text, but a Confluence space is full of personal information: the names and email addresses of its members, the edit history that attributes each change to a person, the comments and @-mentions, and whatever your pages and attachments happen to record about customers, employees or partners in China. Atlassian stores all of it in Atlassian Cloud, and — by its own data-residency documentation — that storage is in one of a fixed set of offshore locations. The selectable set is “Global,” “Australia,” “Canada,” “EU,” “Germany,” “India,” “Japan,” “Singapore,” “South Korea,” “Switzerland,” “United Kingdom,” and “USA,” with “By default, all Atlassian apps are hosted in the Global location, which includes all of our AWS regions.” None of those is mainland China.
So the ordinary act of a Shanghai colleague writing up a spec, or attaching a signed contract to a page, puts personal information collected in China onto storage outside the country. That is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL places the duty on the handler — you, not the documentation vendor. Articles 38–40 call for notice, a separate consent distinct from a user’s agreement to use the product, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where a page or attachment contains “important data,” that transfer may additionally require China’s data-export security assessment (数据出境安全评估) before anything leaves. Which of these bite on your particular spaces is a risk to confirm with counsel against what your Confluence actually holds.
No mainland-China region to pin to — so no in-country storage, and no ICP footing
Atlassian’s residency controls are real, but they stop at the water’s edge. The default, in Atlassian’s own words, is “Global: In-scope data is hosted within realms determined by Atlassian: data may be moved between realms as needed” — meaning Atlassian chooses where the content sits and can relocate it among its realms. The realms you can pin to instead map to Frankfurt and Dublin, US East and West, Sydney, Singapore, Mumbai, Seoul, Tokyo, London and Zurich. There is simply no China realm on the menu, so “set residency to China” is not an option Confluence can offer.
That absence settles two further questions before performance ever enters the picture. First, residency: if you are a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 — formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, with the obligation itself unchanged). An offshore Confluence site cannot satisfy that, whichever realm you pick. Second, licensing: a public-facing Confluence space actually served to mainland visitors from inside China turns on an ICP filing (备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing must attach to a hosting resource physically in the mainland. Atlassian Cloud provides none, so there is nothing of Atlassian’s own to file against. “We already run Confluence for the team” does not carry across the border on its own.
The self-managed path exists — but weigh Atlassian’s own lifecycle
With some vendors the fix is to move onto a mainland instance you run yourself. Confluence leaves a narrow version of that open, and it is worth being precise about its shape today. Confluence Server reached end of support on February 15, 2024, so the self-managed line now is Confluence Data Center, which you could in principle deploy on in-country infrastructure. But Atlassian has published an end-of-life for that line too: by its own licensing page, “On March 30, 2026 at 23:59 PST, new customers will no longer be able to purchase new Data Center subscriptions,” and “End of life for impacted Data Center products will take place on March 28, 2029 at 23:59 PST.”
The practical reading is that a self-managed in-country Confluence is a shape to confirm with counsel and to weigh against that timeline — not a permanent fix to build a China strategy around. This is exactly why the lawful in-country pattern matters more than any single product: the goal is consented, in-country processing and storage for the China-resident content that must stay, on infrastructure whose lifecycle you control, with a deliberate split between what stays and what may lawfully leave. The product is a detail; the pattern is the decision.
The lawful path — map, localize, deliver
There is a lawful way to run team documentation for a China-facing team, and it has a clear shape — three moves, in order.
Map. Our China team works through the PIPL cross-border exposure and the data-residency duties attached to what your Confluence actually holds: which spaces, pages and attachments carry personal or important information that must stay in-country, which may lawfully be transferred, and where a data-export security assessment or an Article 39 storage duty applies. The legal conclusions are settled with counsel; we frame the technical picture that feeds them.
Localize. Keep the China-resident content in-country, on a consented in-country store — a self-managed Data Center deployment is one possible shape, weighed against the lifecycle above — and let only what may lawfully leave reach the Confluence your global team already uses. The spaces and workflows people depend on keep working, without the knowledge base becoming the thing that quietly carries China-collected content out of the country.
Deliver. Any public China-facing surface built on or around that content — a customer knowledge base, a published space, a documentation portal — is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is team documentation and a China-facing surface that run legally and compliantly for your users in China. What we never do, and what no one lawfully can, is offer a way around anything: we localize what must stay and deliver in-country, and circumvention is never on the table.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
