Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Cookiebot Work in China? Consent Records, PIPL Cross-Border & Data Residency

Cookiebot is a cookie-consent platform — now a trademark of Usercentrics A/S, whose own privacy policy keeps consent records on EU servers (Denmark and Ireland), with no mainland-China region. For China that turns every Chinese visitor's consent record and the IP behind it into a cross-border transfer under PIPL — and a GDPR-style banner is not the separate, specific consent PIPL asks for. A compliance-first look at the data-residency, consent-regime and ICP exposure — and the lawful in-country path.

Does Cookiebot work in China?

The irony is the answer: Cookiebot is a consent-management platform that, used as-is for mainland China, can become a compliance exposure of its own. Reaching it isn't the problem — where it keeps your Chinese users' consent records, and whether a GDPR banner is the consent China asks for, is.

Cookiebot is "a trademark of Usercentrics A/S," a Copenhagen company, and its own privacy policy lists the CMP's consent-data hosting on databases "within EU member states, specifically Ireland," Usercentrics' "Consent Data" in "Denmark," and the geo-IP lookup through a US database — no mainland-China region anywhere. So every consent decision and the IP behind it that Cookiebot logs from a Chinese visitor is personal information held offshore: a cross-border transfer PIPL governs (notice, separate consent and a transfer mechanism, Articles 38–40), with an in-country storage duty for a CIIO or large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). On top of that, a banner built for GDPR is not automatically PIPL's separate, specific consent — nor the further consent PIPL wants before data leaves China (Article 39). And the banner itself is fetched from offshore, so from inside China it can load slowly or fail — and a consent gate that can't load can hold up the page it guards.

This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →

What Cookiebot's own documentation says about China

FactPrimary source
Cookiebot is a Usercentrics A/S product, and its consent records sit in the EU — not China. Cookiebot's own privacy policy states it is "a trademark of Usercentrics A/S" (Copenhagen), names Usercentrics A/S as the controller, and in its processor list puts the CMP's consent-data hosting on databases "within EU member states, specifically Ireland" and Usercentrics' own "Consent Data" in "Denmark." For a consent platform that is the point in reverse: the record proving a Chinese user consented is itself personal information held offshore — a cross-border transfer of personal information under PIPL (notice, separate consent and a transfer mechanism, Articles 38–40). Cookiebot (Usercentrics A/S) — Privacy Policy, retrieved 2026-10-09; PIPL Articles 38–40
Cookiebot publishes no mainland-China hosting region, and its geo-IP lookup runs through a US database. The locations named in Cookiebot's privacy policy span Denmark, EU member states (Ireland, the Netherlands), the United States and Singapore — none inside mainland China — and it lists the geolocation that picks the right banner running through Akamai's "Database in the USA." With no in-country region on offer, there is no mainland hosting resource for consent records to live on, and none to attach an ICP filing to. Cookiebot (Usercentrics A/S) — Privacy Policy, retrieved 2026-10-09
A GDPR cookie banner is not automatically PIPL consent. Cookiebot's consent flow is built around the European opt-in model. PIPL runs on its own logic: consent must be specific and, in defined cases, separate — a distinct, standalone act rather than one bundled acceptance (PIPL Articles 13–14) — and sending personal information outside China calls for a further, separate consent plus individual notice about the overseas recipient (PIPL Article 39). A banner valid under GDPR may still fall short of those China-specific consents; whether yours clears the bar is a determination for counsel. PIPL Articles 13–14 and 39; Cookiebot (Usercentrics A/S) — Privacy Policy, retrieved 2026-10-09
For some handlers the records must stay in China — and serving from inside the mainland triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an EU consent store cannot satisfy. And any public site actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Cookiebot does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-09.

For an audience in mainland China, Cookiebot carries a question with a twist built into it. Cookiebot is a consent-management platform — the tool a company installs in order to handle privacy law: it scans the site, shows a cookie-consent banner, and logs each visitor’s consent decision together with the IP address and technical signals used to produce and prove it. Pointed at China as it ships, that very record-keeping is where the exposure begins. The question is not whether the banner loads — it reaches China. It is that the consent records Cookiebot keeps for your Chinese users come to rest on servers outside the mainland, that the IP-based lookup deciding which banner to show runs through an offshore database, and that a banner built for Europe’s consent rules is not the consent China’s law asks for. The first two are data-residency and cross-border questions under Chinese law; the third is a consent-regime one. All three sit ahead of performance — and Cookiebot’s own privacy policy settles where the data lives.

Cookiebot's own privacy policy processor list, showing the CMP's consent-data host keeping databases within EU member states (Ireland) and Usercentrics A/S listed for Consent Data in Denmark — with no mainland-China hosting region named
Cookiebot's own privacy policy, in its list of processors: the CMP's consent-data host keeps the databases on EU servers — “Databases are hosted on servers within EU member states, specifically Ireland” — while Usercentrics A/S, the Copenhagen company behind Cookiebot, is listed for “Consent Data and other data as mentioned in this privacy policy” in “Denmark.” No locality is inside mainland China — so the record of a Chinese user's consent is itself held offshore. Source: Cookiebot (Usercentrics A/S) — Privacy Policy

Cookiebot in China at a glance

What decides it In Cookiebot's own terms — and China's law
Who operates it, and from where Cookiebot's privacy policy states it is “a trademark of Usercentrics A/S,” a Copenhagen company, and names Usercentrics A/S (Denmark) as the controller. The platform and the consent records it keeps sit in the EU, not the mainland.
What Cookiebot records It scans your site and logs each visitor's consent decision — the categories chosen, the timestamp, the consent key and the IP address behind it. Every item of that is personal information.
Where the records live Its privacy policy lists consent-data hosting on databases “within EU member states, specifically Ireland,” Usercentrics' own “Consent Data” in “Denmark,” and the geo-IP lookup through Akamai's “Database in the USA.” None is inside mainland China.
Your China users' records Consent decisions and the IP behind them, collected from people in China and held in the EU or US, are a cross-border transfer of personal information PIPL governs (Articles 38–40): notice, a separate consent, and one transfer mechanism.
A GDPR banner vs PIPL consent Cookiebot's flow is built around GDPR consent. PIPL asks for its own separate, specific consent — and a further, distinct consent before personal information leaves China — which a European banner does not automatically produce.
Residency & serving the public A critical information infrastructure operator or large-volume handler must keep China-collected personal information in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). A site served from inside China also needs an ICP filing bound to a mainland hosting resource Cookiebot does not provide.

The awkward part here is structural, not a detail. Cookiebot’s entire purpose is to produce and keep proof that you handled personal information properly — the consent a visitor gave, the categories they accepted, the record standing behind it. But Cookiebot’s own privacy policy shows that proof coming to rest offshore: the platform is “a trademark of Usercentrics A/S,” a Copenhagen company; its processor list puts the CMP’s consent-data hosting on databases “within EU member states, specifically Ireland,” and Usercentrics’ own “Consent Data” in “Denmark.” So the record that proves a Chinese user consented is held in Europe — which means the privacy tool has quietly produced the very cross-border transfer it exists to help you document.

Under China’s Personal Information Protection Law that is a cross-border transfer, and the duty falls on the personal-information handler — you, not Cookiebot. You owe notice, a separate consent for the overseas transfer, and one cleared transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). The platform that gathers the consent does not absorb the obligation that attaches to wherever that consent then lives.

There is a second half the residency question tends to hide, and for a consent tool it is the sharper one. Cookiebot’s consent flow is designed around the European model — informed opt-in, categories, a stored record of the choice. China’s PIPL runs on its own consent logic, and the two do not map one-to-one. PIPL expects consent that is specific and, in defined situations, separate — a distinct, standalone act rather than a single bundled acceptance (PIPL Articles 13–14). Where personal information is to be sent outside China, it expects a further, separate consent for that transfer, on top of individual notice about the overseas recipient (PIPL Article 39). A banner tuned to pick the right experience by geo-IP — and to satisfy GDPR — does not automatically produce those China-specific consents.

So the tool you installed to collect consent may be collecting the wrong kind for China: valid under GDPR, yet short of PIPL’s separate-consent and cross-border-consent expectations. Whether your configuration clears that bar is a determination for counsel — but it is one more reason that “we already run a consent platform” does not carry across the border on its own.

No mainland region, so no in-country storage and no ICP footing

Cookiebot, through Usercentrics A/S, names EU hosting for its consent data and a US geolocation database; it publishes no mainland-China region. That geography answers two more questions before speed is ever in the frame.

First, residency. If you are a critical information infrastructure operator or a large-volume handler, personal information collected in China has to be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 — the data-localization provision renumbered from Article 37 by the 2025 Cybersecurity Law amendment that took effect on January 1, 2026, with its substance unchanged). An EU-resident consent store cannot meet that duty however it is configured, and above certain volume thresholds — or where the records qualify as important data — the transfer may itself require China’s data-export security assessment before anything leaves. Second, licensing. A public-facing site actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing must attach to a hosting resource physically in the mainland. Cookiebot offers none, so there is nothing on Cookiebot to file against. “We already run Cookiebot for consent” does not travel across the border; the clean data-handling story the platform is meant to give you is exactly what it leaves open in China.

The reachability half is real too, and for a consent banner it bites harder than for an ordinary asset. Cookiebot’s banner is a client-side script the browser fetches before the page settles, and its privacy policy records the geolocation that picks the right banner running through Akamai’s “Database in the USA.” Both the script and that lookup originate outside the mainland — the same cross-border hop every offshore asset makes to reach a user in China.

So when an offshore-served consent gate loads slowly or fails from inside China, it does not fail quietly off to one side — it can stall the very content it is meant to guard. That is a delivery problem, not a legal one, but on a China-facing site the two compound: the gate that is hardest to deliver is also the one carrying the cross-border and consent exposure. We publish no first-party China latency figure for Cookiebot here, because speed is not the axis this decision turns on, and a number without a method, a sample and a date would only mislead. And one thing 21YunBox never does — and what no lawful provider can offer — is route around China’s data-export rules or any network restriction: we never use or suggest circumvention of any kind.

This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, in-country storage, a data-export assessment, an ICP filing, or some combination depends on your data volumes, your role as handler and who your users are — worth settling with counsel before you depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run consent management for a China-facing audience, and it has a shape. First, map: our China team works through the PIPL cross-border, consent-regime and data-residency obligations that attach to the consent decisions and IP data Cookiebot records — against your entity, your data volumes and who your users are — and marks where a separate cross-border consent, a data-export assessment or an Article 39 storage duty applies. The legal calls are made with counsel; we build the technical picture that feeds them.

Then localize: for the records that must stay in the country, we stand up and integrate a China-resident consent store and a consent flow that runs on an ICP-filed, in-country footing — the lawful in-country pattern of consented, in-country processing and storage, shaped to PIPL’s separate-consent expectations — so what cannot lawfully leave the mainland no longer does, while you keep Cookiebot for the markets where it already serves you.

Then deliver: the China-facing site or app that presents the consent gate is itself a public service in the mainland, so it carries an ICP-filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is a consent and privacy setup that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Cookiebot store Chinese users' consent data in China?
No. Cookiebot's own privacy policy lists its consent-data hosting on databases "within EU member states, specifically Ireland" and its provider, Usercentrics A/S, in "Denmark," with the geo-IP lookup running through a US database — no mainland-China region. The consent decisions and IP data it logs from Chinese visitors are held offshore, which makes them a cross-border transfer of personal information under PIPL: the handler (you, not Cookiebot) owes notice, a separate consent and a transfer mechanism.
If Cookiebot is a privacy tool, how can it be a compliance risk in China?
Because compliance in China turns on where the data lives and what consent you actually hold — not on what the tool is for. A consent platform exists to prove you handled personal information lawfully, but if the proof is stored in the EU, you have created the cross-border transfer PIPL regulates; and a banner built for GDPR may not deliver PIPL's separate, specific consent or the further consent it wants before data leaves China. Treat both as risks to work through with counsel — using a privacy tool does not exempt the personal information it collects from China's transfer, residency and consent rules.
Can 21YunBox help make our Cookiebot setup work in China?
Yes. Our China team can map your exposure — the PIPL cross-border, consent-regime and data-residency obligations that attach to the consent and IP data Cookiebot collects, for your entity, data volumes and users — and stand up the ICP-filed, in-country delivery and storage a compliant China presence requires, in front of the Cookiebot stack you already run. Get in touch to work through your specific case.

ARTICLES RELATED TO COOKIEBOT

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.