Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Crisp Work in China? PIPL Cross-Border, Data Residency & Consent

Crisp is an EU-hosted live-chat, shared-inbox and AI platform with no mainland-China region, so your China customers' conversations, tickets and profiles sit offshore — a PIPL cross-border transfer. Its embedded widget ships each visitor's IP and messages offshore before consent, MagicReply AI auto-answers as an automated decision, and the support surface needs an ICP filing. A compliance-first look at the residency, consent and automated-decision exposure.

Does Crisp work in China?

What decides whether Crisp works in mainland China isn't whether the chat widget loads — it's that your Chinese customers' conversations and profiles sit on Crisp's EU servers with no mainland-China region, the embedded widget ships each visitor's IP and messages offshore the moment the page loads, and its MagicReply AI can auto-answer a customer, so the support surface needs an ICP filing and a lawful in-country path.

Crisp is a French live-chat, shared-inbox and AI platform whose own GDPR page places all customer data in the EU — messaging data in the Netherlands, plugin data in Germany, on DigitalOcean — and states “We do not plan to store data outside the EU in the future.” Running China support on it moves your customers' conversations, contacts and profiles across the border, a PIPL cross-border transfer you make as the handler (Articles 38–40), while the widget's on-load data flow raises a PIPL Article 13/23 consent question and MagicReply raises an Article 24 automated-decision question. The lawful lever is to keep the conversations and PII in-country, gate and consent the widget, meet the Article 24 duties and ICP-file the surface — not to make the offshore widget reach further.

This is a risk map, not a verdict — what you owe turns on your entity, your data volumes and who your users are, so settle the specifics with counsel. Our China team can map your exposure →

What Crisp's own documentation says about China

FactPrimary source
Crisp hosts all customer data in the EU, with no mainland-China region. Crisp's own GDPR compliance page states that its messaging data is stored in the Netherlands and its plugin data in Germany, that “Servers are hosted by DigitalOcean (with a subsidiary in the EU subject to EU law),” and that “We do not plan to store data outside the EU in the future.” No server region sits inside mainland China, so your China customers' conversations and profiles come to rest offshore. Crisp — EU GDPR compliance status (help.crisp.chat), retrieved 2026-10-10
MagicReply AI answers customers, and the widget's relay servers log each visitor's IP abroad. Crisp says it relies on Mirage “for our AI features (eg. LiveTranslate, MagicReply, etc.),” and MagicReply can auto-answer a conversation once trained — an automated decision about a customer. Crisp also runs relay servers outside the EU that, in its words, keep only “connection logs (IP address, date of connection, user-agent and source website),” so the chat widget sends the visitor's IP and context abroad on page load. Crisp — EU GDPR compliance status (help.crisp.chat), retrieved 2026-10-10
Serving China on an EU platform is a PIPL cross-border transfer — and the widget needs consent before it fires. Because your customers' conversations, contacts and profiles are collected in the mainland and stored in the EU, you are the handler of a cross-border transfer under the Personal Information Protection Law: notice, a separate consent and a transfer mechanism (Articles 38–40). The embedded widget, which sends a visitor's IP and context to Crisp on page load, also needs a lawful basis and consent before it runs (PIPL Articles 13 and 23). China's Personal Information Protection Law, Articles 38–40 and 13/23, retrieved 2026-10-10
A CIIO or high-volume handler owes in-country storage Crisp cannot provide. If you are a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in the mainland under Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged) and PIPL Article 40. The public support surface — the help center, chat page and widget host — also carries an ICP filing duty. Crisp, hosted only in the EU, can meet neither. China's Cybersecurity Law Article 39 (formerly Article 37) & PIPL Article 40; ICP: State Council Order No. 292 / MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-10.

For customers in mainland China, the question about Crisp is not whether the chat bubble appears — it is where the conversations behind it are allowed to live, and what the widget sends abroad on load. Crisp is a French company running a live-chat widget, a shared inbox and AI assistant, and is explicit about geography: its own GDPR page says all Crisp data is held on EU servers — messaging data in the Netherlands, plugin data in Germany, on DigitalOcean — with no region inside the mainland. Three things decide the answer, and none is speed: your Chinese customers’ conversations and profiles sit on an EU platform (a cross-border transfer you make under PIPL), the embedded widget ships each visitor’s IP and messages offshore on load before any consent, and MagicReply AI can auto-answer a customer — an automated decision. The support surface carries an ICP-filing duty.

Crisp's EU GDPR compliance help article stating all Crisp data is held on servers in the European Union, with messaging data in the Netherlands and plugin data in Germany on DigitalOcean, and no mainland-China region
“We do not plan to store data outside the EU in the future.” Crisp's own GDPR compliance page places its messaging data in the Netherlands and its plugin data in Germany on DigitalOcean — EU-hosted, with no mainland-China region. Source: Crisp — EU GDPR compliance status

Crisp in China at a glance

What decides it In Crisp's own terms — and China's law
What it holds Live-chat transcripts, shared-inbox tickets and emails, plus each contact's name, email and profile — and, for the widget, the visitor's IP, user-agent and originating site. Personal information under China's law, not anonymous metrics.
Where it runs Crisp's own GDPR page puts all data on EU servers — messaging in the Netherlands, plugins in Germany, on DigitalOcean — and says it does “not plan to store data outside the EU.” No mainland-China region. For China customers that makes running Crisp a cross-border transfer (PIPL Articles 38–40; 数据出境).
The embedded-widget door The chat widget is third-party JavaScript that opens a connection to Crisp on page load; by Crisp's account its relay servers keep “connection logs (IP address, date of connection, user-agent and source website).” That ships visitor data offshore before any consent — a transfer plus a PIPL Article 13/23 consent problem.
AI decisions & residency Crisp's MagicReply, powered by its Mirage service, can auto-answer a customer once trained — automated decision-making under PIPL Article 24 (transparency, fairness, a route to human review). For a CIIO or high-volume handler, China-collected data must stay in-country under China's Cybersecurity Law — a duty an EU-only service cannot meet.
Reachability isn't the axis Whether the widget loads from China is the easy half. What decides it is where the conversations live, whether the widget fires before consent, and whether the AI auto-answers — answered by keeping the data in-country, gating the widget, meeting Article 24 and ICP-filing the support surface, not by making the offshore widget reach further.

What you actually hold — conversations, customer profiles, and a widget that phones home

A customer-support platform does not hold metrics; it holds people. On Crisp, that means the live-chat transcripts, the shared-inbox tickets and emails, and — tied to each one — a contact’s name, email address and the profile your agents build while resolving an issue. Every sentence a worried customer types is, under China’s law, their personal information, collected from them in the mainland.

The widget adds a second flow that most teams never picture. A Crisp chat bubble is third-party JavaScript embedded in your pages; the moment one loads for a visitor in China, it opens a connection to Crisp’s infrastructure. Crisp is candid about what that touches: the relay servers it runs to cut latency, it says, keep “connection logs (IP address, date of connection, user-agent and source website)” and nothing else. In other words the visitor’s IP and context leave for Crisp’s servers on page load — before any consent dialog has been shown.

And Crisp now answers as well as records. It states that it relies on Mirage “for our AI features (eg. LiveTranslate, MagicReply, etc.),” and MagicReply can be trained to draft or auto-answer a conversation on its own. When software decides what a customer is told, you are no longer only storing data — you are making an automated decision about a person, which Chinese law treats as its own category.

Start with where the data rests. Crisp’s own GDPR compliance page is explicit: “Servers are hosted by DigitalOcean (with a subsidiary in the EU subject to EU law),” messaging data sits in the Netherlands and plugin data in Germany, and “We do not plan to store data outside the EU in the future.” None of that is in the mainland. Because your Chinese customers’ conversations and profiles are collected in China and come to rest in the EU, you are the handler of a cross-border transfer of personal information under the Personal Information Protection Law: you owe notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (Articles 38–40).

The widget opens a second door. Setting a third-party connection that ships a visitor’s IP and context to an offshore service on page load is non-essential processing: under PIPL Articles 13 and 23 it needs a lawful basis and informed consent before it fires, and the overseas transfer needs its own separate consent — not a single “by using this site” line. A chat bubble that phones home before the visitor has agreed to anything is the most common, and most overlooked, exposure on a China-facing support page.

The third door is the AI. Where MagicReply triages, routes or auto-answers a customer, PIPL Article 24 attaches: automated decision-making must be transparent and fair, and the person has a right not to be subject to a decision made solely by automation — which means a route to human review in the flow. Finally, residency. For a critical information infrastructure operator or a high-volume handler, personal information generated in China must be stored in China under Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged) and PIPL Article 40 — a duty an EU-only platform has no way to satisfy.

Loading the widget isn’t the question — a compliant in-country support path is

The instinct, once someone notices the chat can be slow or flaky from the mainland, is to find a way to make the offshore widget load faster. That solves the wrong problem. A widget that connects cleanly still ships the visitor’s IP on load, still stores every conversation in the EU, and still lets the AI answer without a human in the loop — reachability changes none of it. Making an offshore endpoint reach further does not create a lawful basis, a transfer mechanism, or an Article 24 opt-out; it only guarantees the unconsented export you were previously only risking.

The compliant direction is the opposite: reduce and localize what leaves. Keep the China-customer conversations and PII on an in-country path — an in-country support deployment, with what you collect minimized and pseudonymized. Gate and consent the chat widget so it does not fire for mainland visitors before a lawful basis exists, or replace it with an in-country path. Meet the Article 24 duties wherever MagicReply decides what a customer sees. And ICP-file the public support surface — the help center, the chat page, the host of the widget — because that is a public internet service in China’s sense. Keeping the data in-country is the lever; a tunnel that ships it offshore anyway is not.

This is a risk map, not a verdict — whether you owe a cross-border mechanism, in-country storage, widget consent, Article 24 controls, or all of them depends on your entity, your data volumes and who your users are, so settle the specifics with counsel before you build.

The lawful path — map, localize, deliver

21YunBox is a compliance overlay in front of the stack you already run — Crisp stays exactly where it is, your inbox and history don’t move, and you rewrite nothing.

  • Map — inventory the conversation content, the contacts and profiles, and the widget’s on-load data flow; confirm where each is processed and stored (Crisp’s EU regions, with no mainland-China option); identify where MagicReply scores or auto-answers a customer (Article 24); and establish your consent basis.
  • Localize / govern — keep the China-customer conversations and PII in-country, minimize and pseudonymize what you collect, gate and consent the chat widget so it does not export visitor data on load, and meet the Article 24 duties for the AI. Localize means keeping the data on an in-country path — never a tunnel that ships it offshore anyway.
  • Deliver — stand up compliant, ICP-filed, in-country delivery of the support surface with the 21YunBox Optimizer, in front of your existing origin, with no rebuild.

21YunBox never uses or suggests circumvention of any kind. The goal is simple: Crisp runs legally and compliantly for your users in China, on a path whose data stays where China’s law requires.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Where does Crisp store our Chinese customers' conversations?
Outside mainland China. Crisp's own GDPR page says all its data is held on EU servers — messaging data in the Netherlands, plugin data in Germany, on DigitalOcean — and that it does not plan to store data outside the EU. There is no mainland-China region, so every chat, contact and profile the widget collects from your Chinese customers is stored offshore, which is what turns running Crisp into a PIPL cross-border-transfer question.
Is the Crisp chat widget itself a compliance problem in China?
It can be. A live-chat widget is third-party JavaScript on your page: it opens a connection to Crisp's servers and, by Crisp's own account, logs the visitor's IP, user-agent and originating site, sending that abroad on page load — before any consent dialog. Under PIPL Articles 13 and 23 that non-essential data flow needs a lawful basis and consent before it fires, and the overseas transfer needs its own separate consent. The fix is to gate and consent the widget or move to an in-country path — not to make the offshore endpoint reach further.
Can 21YunBox make our Crisp setup work in China?
Yes — as a compliance overlay, not a migration. Our China team maps your PIPL cross-border and residency exposure for your entity, data volumes and users, helps keep the China-customer conversations and PII on an in-country path, gates and consents the widget, addresses the Article 24 duties for MagicReply, and stands up the ICP-filed, in-country delivery a compliant China support surface needs — in front of the Crisp stack you already run. Get in touch to work through your case.

ARTICLES RELATED TO CRISP

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.