Does Criteo Work in China? PIPL Cross-Border, Profiling Consent & Data Transfer
Criteo's commerce-media retargeting tag generally loads in mainland China — and that is the exposure: on every China visitor the OneTag ships behavioral personal information (cookie and device IDs, IP, products viewed and purchased) to Criteo's EU and US servers in real time, a PIPL cross-border transfer and an Article 24 profiling mechanism needing separate consent. A compliance-first look at the data-export, profiling and consent exposure, and the lawful in-country path.
Does Criteo work in China?
Yes — Criteo's tag generally loads from mainland China, which is the problem, not the comfort: the moment it fires on a visitor in China it ships that person's behavioral data to Criteo's offshore ad servers in real time. The China question is compliance, not reachability.
Criteo's own Ads Privacy Notice says its technologies collect a cookie UID, device advertising IDs, advertiser-supplied hashed emails, IP-derived location and commerce events — "Products viewed, put in a shopping cart or purchased" — and process them in the EU and the US, with no mainland-China region. Firing that pixel on a China visitor is a PIPL cross-border transfer of personal information (Articles 38–40) and an Article 24 profiling mechanism, and setting the tracking cookie and sharing events for cross-context advertising needs a separate, informed consent (Articles 13/23) that a buried banner does not give. The lawful lever is to gate or suppress the offshore pixel for mainland visitors and move any needed measurement onto a licensed in-country alternative — not to make the offshore pixel load.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Criteo's own documentation says about China
| Fact | Primary source |
|---|---|
| Criteo's OneTag collects behavioral personal information and sends it to Criteo. Criteo's Ads Privacy Notice says it processes, via sites and apps that incorporate its technologies, a cookie-based UID, device advertising IDs (Apple IDFA, Google AAID, Samsung IFA), advertiser-supplied hashed email addresses, IP-derived coarse location, and commerce events — "Products viewed, put in a shopping cart or purchased." | Criteo, "Ads Privacy Notice" (criteo.com/privacy), effective July 17, 2026, retrieved 2026-10-10 |
| Criteo processes this data offshore — in the EU and the US, with no mainland-China region. The same notice says recipients "may be in countries outside of Europe" including "the USA," protected by the EU-US Data Protection Framework and EU Standard Data Protection Clauses, and that Criteo discloses or sells these categories for "cross-context behavioral advertising." No China data-residency option is offered. | Criteo, "Ads Privacy Notice" — international transfers and US disclosures (criteo.com/privacy), retrieved 2026-10-10 |
| Firing the pixel on a China visitor is a PIPL cross-border transfer. Sending the identifiers, commerce events and IP-derived location of a user in mainland China to Criteo's offshore servers triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| Retargeting needs a separate consent and carries Article 24 profiling duties. Setting the tracking cookie and building cross-site profiles for targeted ads needs a lawful basis — consent (Article 13) — with a separate consent to share and to export (Article 23), while automated decision-making for marketing must be transparent and offer a way to refuse (Article 24). | Personal Information Protection Law of the PRC, Articles 13, 23 and 24 (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
The question teams ask about Criteo in China is whether the tag fires — whether the OneTag loads and campaigns keep optimizing. For a mainland audience that is the wrong test. Criteo is a French commerce-media and retargeting network, and because it is a global advertising platform rather than a consumer service China blocks outright, its tag generally resolves from the mainland — which is precisely the exposure. The moment the OneTag fires on a visitor in China it collects that person’s behavioral personal information — the products they viewed, added to a cart or purchased, a cookie identifier, their device’s advertising ID, an IP-derived location, sometimes a hashed email — and sends it, in real time, to Criteo’s servers offshore to build a cross-site profile for ad targeting. That triggers three China duties at once: a cross-border transfer of personal information, automated-decision profiling, and a separate consent to track and to export. Criteo describes the data it collects in its own notice.
Criteo in China at a glance
| What decides it | In Criteo's own terms — and China's law |
|---|---|
| What the tag collects | Criteo's Ads Privacy Notice says its technologies collect a Criteo cookie "UID", device advertising IDs ("Apple IDFA, Google AAID or Samsung IFA"), advertiser-supplied "hashed email addresses, hashed phone numbers, and membership or loyalty card numbers", IP-derived "coarse location", and commerce events — "Products viewed, put in a shopping cart or purchased." Under PIPL those online identifiers and behavioral records are personal information, whatever Criteo's "pseudonymized" label. |
| Where it goes | Criteo processes this in the EU and the US — its notice says recipients "may be in countries outside of Europe" including "the USA," under the EU-US Data Protection Framework and EU Standard Data Protection Clauses. There is no mainland-China region. Collecting a China visitor's data into it is a cross-border transfer (数据出境) under PIPL Articles 38–40: notice, a separate consent, one transfer mechanism. |
| Profiling for ads | Retargeting builds a cross-site, cross-device profile to decide which ad chases which user — automated decision-making for commercial marketing. PIPL Article 24 adds transparency and fairness duties and requires a way to refuse, plus an option not based on the individual's personal characteristics. |
| Consent to track and share | Setting the Criteo cookie and sharing events with demand-side platforms and match partners for "cross-context behavioral advertising" needs a lawful basis — for non-essential tracking, consent (Article 13) — with a separate consent before the data is shared and before it leaves China (Article 23; Articles 38–40). A buried "by using this site" line does not carry it. |
| Reachability is not the axis | Criteo generally resolves from the mainland, so this is not about whether the tag loads — that is the delivery half. The lawful move is to gate or suppress the offshore pixel for mainland visitors and route any measurement you still need through a licensed in-country alternative, while the China-facing site that carries the tag takes an ICP filing and in-country delivery. |
What the pixel actually sends — and where
Start with what the OneTag is for. Criteo is a commerce-media and retargeting network: its notice says it displays ads “based on products and services they have previously viewed, put in their digital shopping carts or purchased.” To do that, the tag you embed collects a defined set of signals on each visitor. Criteo’s Ads Privacy Notice lists them: a Criteo-generated “UID” tied to the cookie it sets on the browser (“cross-device where relevant”); the device’s advertising identifier (“Apple IDFA, Google AAID or Samsung IFA”); advertiser-supplied “CRM identifiers like hashed email addresses, hashed phone numbers, and membership or loyalty card numbers”; “coarse location (country, region, or city) derived from your IP address”; and the commerce events themselves — “Products viewed, put in a shopping cart or purchased,” with the date, time and page URL. Criteo is careful to call this “pseudonymized, technical information” that does not directly name you. Under China’s privacy law that label does not change the category: a persistent cookie ID, a device advertising ID, an IP address and a behavioral event history are personal information when they can be tied to a person, and the law reaches them.
Where does it go? Criteo is a French company — its Data Protection Office sits at “32 rue Blanche 75009 Paris France” — and it processes this data in the European Union and the United States. Its notice tells users that recipients “may be in countries outside of Europe,” including “the USA,” and that such transfers rely on the EU-US Data Protection Framework and the “EU Standard Data Protection Clauses.” Nowhere does it offer a mainland-China region or a China data-residency option. So this is the case that bites hardest: the tag is not dead weight that quietly fails — it resolves from the mainland and actively exports. On every Chinese visitor it fires on, it ships that behavioral record offshore in real time and feeds it into a cross-site, cross-device profile that Criteo then shares with demand-side platforms and audience partners for “cross-context behavioral advertising.”
It’s a cross-border transfer and a profiling mechanism — under PIPL
Three duties attach the instant that pixel fires on a user in China, and they are independent of one another.
First, a cross-border transfer. Moving the identifiers, commerce events and IP-derived location of a mainland visitor to Criteo’s servers in the EU or the US is a cross-border transfer of personal information (数据出境) under the Personal Information Protection Law. The handler on the hook is you — the site or app that embeds the tag — not Criteo. PIPL Articles 38–40 require notice, a separate consent for the overseas transfer specifically, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. The mechanisms Criteo actually names — the EU-US Data Protection Framework and the EU Standard Data Protection Clauses — are GDPR instruments; they do nothing for a transfer out of mainland China. And above the regulators’ volume or sensitivity thresholds, a data-export security assessment (数据出境安全评估) can be required before anything leaves.
Second, profiling. Retargeting is the textbook case of what PIPL Article 24 governs — automated decision-making used for commercial marketing. The article demands that the process be transparent and its outcomes fair, and, for marketing aimed at individuals, that you offer an option not based on their personal characteristics, or a convenient way to refuse. A campaign that only knows how to target by profile does not meet that on its own; the opt-out and the non-profiled path have to be built into the flow.
Third, consent. Setting Criteo’s cookie and reading a device identifier is non-essential tracking, so it needs a lawful basis — in practice, informed consent obtained before the tag fires (Article 13). Criteo’s own notice acknowledges this, conditioning its identifiers on the consent that advertisers and publishers collect on their own sites. Handing the events to Criteo and onward to DSPs and match partners is a provision of personal information to third parties, which carries its own notice and a separate consent under Article 23 — and the overseas leg needs a further separate consent of its own. A single buried “by using this site” line does not discharge all three.
One further door opens only for some handlers: a critical information infrastructure operator, or a handler whose data volumes cross the regulators’ thresholds, owes an in-country storage duty — mainland personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore ad network cannot satisfy that no matter how its regions are tuned.
Making the offshore pixel reachable is the wrong fix — what actually works
It is tempting to treat this as a delivery problem — to make sure the tag loads crisply for mainland users so the campaign keeps optimizing. For Criteo that is exactly the wrong instinct. The tag already loads; the harm is that it loads and exports. Improving its reach only increases the volume of unconsented behavioral data leaving the country. The compliant direction is the opposite.
The lever is governance at the edge, not reachability. For mainland visitors, you gate, suppress or defer the Criteo tag so it does not fire unless and until you hold the separate, informed consent PIPL requires — serving it only to consented, out-of-scope audiences. You honor the Article 24 right to refuse profiled advertising, with a genuine non-profiled path. And where you still need measurement or advertising to reach Chinese users, you route it through a lawful, licensed in-country advertising-and-analytics alternative whose data stays on mainland infrastructure — rather than the offshore pixel. Localizing here means stopping the unconsented offshore export and replacing it with a compliant in-country path; it never means tunneling the offshore pixel in so it fires anyway. You cannot self-host Criteo — it is a third-party network — and forcing its endpoint to be reachable is the wrong goal; you replace what it does for your China audience with something lawful.
None of this is a ruling that Criteo is banned in China. It is a risk map: which duties actually bite depends on what your tag collects, your data volumes, your role under Chinese law, and who your users are — settle the specifics with counsel before a China campaign relies on it.
The lawful path — map, localize, deliver
You do not have to abandon Criteo to run advertising lawfully for a mainland-China audience. 21YunBox is a compliant overlay, not a migration — and for a network you already run, a partner alongside your stack, not a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team inventories which advertising and tracking pixels fire on your mainland-facing pages — Criteo’s OneTag and whatever rides alongside it — and writes down, for each, what behavioral personal information it sends offshore and where you lack a lawful basis: the consent and notice you owe before a tag fires, the separate consent that sharing with ad partners and the cross-border transfer each require, the Article 24 options you owe on profiled marketing, and whether a data-export assessment or an in-country storage duty bites. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.
Localize. Because the exposure is behavioral data leaving China without a basis, we gate or suppress the offshore pixels for mainland visitors — honoring consent and the right to refuse — and, where you still need to measure or advertise to Chinese users, stand up a lawful, licensed in-country advertising-and-analytics path whose data rests on mainland infrastructure. You keep Criteo for the markets where it already serves you. Localizing means ending the unconsented offshore export and replacing it with a compliant in-country path — never a tunnel that makes the offshore pixel fire regardless.
Deliver. The China-facing site or app that carries the tag is a public internet service in the mainland, so it needs an ICP filing and compliant, in-country delivery. 21YunBox provides it — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your site and your advertising run legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization
- China’s data-export security assessment measures
- How to get an ICP filing for China
