Does Crowdin Work in China? PIPL Cross-Border Data Transfer & Content Residency
Crowdin is a cloud translation-management platform that stores your source strings, translations, translation memory, glossaries, screenshots, and translator accounts on AWS in the US or EU — no mainland-China region. Sending that content offshore to translate is a PIPL cross-border transfer of the personal and sensitive information inside it. A compliance-first look at where your localization content may rest.
Does Crowdin work in China?
Crowdin's app loads fine from China — what decides the China question is that the content you send it to translate is copied to Crowdin's offshore servers, carrying the personal and sensitive information inside it.
Crowdin is a cloud translation-management platform hosted on AWS in the US by default (a US-or-EU choice for Crowdin Enterprise), with no mainland-China region. Your source strings, translations, translation memory, glossaries, screenshots, and translator accounts persist there and grow with every job, and every upload or repo/CMS sync is a PIPL cross-border transfer of whatever personal or sensitive data your strings contain. Crowdin offers no customer-hosted or on-premises deployment, so the lawful lever is to keep China-origin content's translation in-country — a licensed in-country path with personal information minimized and offshore AI/MT features off for China content — not to make the offshore platform reachable.
This is a risk map to settle with counsel, not a verdict. Our China team can map your exposure →
What Crowdin's own documentation says about China
| Fact | Primary source |
|---|---|
| Crowdin stores your whole localization corpus on AWS in the US or EU — never in mainland China. Crowdin's data-residency page states that “customer data is stored in the US Data Center by default,” that Crowdin Enterprise can choose a US (AWS us-east-1, N. Virginia) or EU (AWS eu-west-1, Ireland) data center at setup, and that the chosen region holds your source files and translations, strings and their metadata, translation memories and glossaries, screenshots and visual context, and user profiles and team membership info, with backups in the same region. No mainland-China region is offered. | Crowdin — Data residency (support.crowdin.com), retrieved 2026-10-10 |
| Using Crowdin's AI and machine-translation features sends your strings on to further offshore providers. Crowdin's sub-processor list names Amazon Web Services (United States) for hosting, file storage and backups, and — for opt-in AI/ML features — DeepL (Germany), OpenAI (Ireland), Anthropic and Microsoft Azure (United States), and Mistral AI (France); none is in mainland China. Crowdin offers no customer-hosted or on-premises deployment of the platform — its “self-hosted” support refers to connecting self-hosted Git servers (GitHub Enterprise, GitLab Self-Managed, Bitbucket Server), not to running Crowdin on your own infrastructure. | Crowdin — Sub-processors (effective July 7, 2026) and Comparing Crowdin and Crowdin Enterprise (support.crowdin.com), retrieved 2026-10-10 |
| Sending China-origin content abroad to be translated is a cross-border transfer under PIPL. Shipping source strings, documents, or screenshots that contain the personal information of people in China to Crowdin's offshore servers triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Sensitive content adds Article 28 — separate consent plus a prior personal-information protection impact assessment. | Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| A CIIO or high-volume handler owes an in-country storage duty an offshore corpus cannot meet. A persistent translation memory and project store that keeps China-collected personal information offshore conflicts with Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — which requires such data to be stored in the mainland, and a large or sensitive export may first require a data-export security assessment. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); Measures for the Security Assessment of Data Exports, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
The question about Crowdin for mainland China was never whether the platform loads or whether your localization team can sign in. They can. Crowdin is a cloud translation-management platform, and the compliance question is about the content you hand it. Every source string, document, and screenshot you upload — and everything your Git and CMS integrations sync on each push — is copied to Crowdin’s offshore servers to be translated, carrying whatever personal, sensitive, or confidential information is inside it. A translation-management system does not translate-and-forget: the content accumulates permanently as a translation memory, glossary, and project store, alongside the translator and member accounts that work on it. Crowdin runs on Amazon Web Services in the United States by default, with a US-or-EU choice for Crowdin Enterprise and no mainland-China region. So the real question is cross-border and residency: strings describing people in China are a transfer under PIPL (Articles 38–40), sensitive content triggers Article 28, and the permanent corpus raises a content-residency and in-country-storage duty for a critical information infrastructure operator or high-volume handler.
Crowdin in China at a glance
| What decides it | In Crowdin's own terms — and China's law |
|---|---|
| What content you send, and why it is personal information | Crowdin holds the content itself: source strings and documents, their translations, translation memories and glossaries, and the screenshots and visual context you upload — plus support articles, product copy, and user-generated text you route through it. The content you most need translated is the content most likely to carry names, emails, addresses, and account details, and often Article 28 sensitive data (health, financial, legal, ID). Once a string identifies a person in China, it is personal information under PIPL. |
| It leaves China to be translated | Uploading or syncing that content to Crowdin copies it to Crowdin's offshore servers — on AWS in the US by default, or a US-or-EU data center for Crowdin Enterprise, with no mainland-China region. Sending China-origin content abroad to be translated is a cross-border transfer (数据出境) PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). It happens on every push from your Git or CMS integration, not once. |
| The permanent offshore corpus + residency | A translation-management system does not translate-and-forget. Crowdin's own data-residency page says the chosen region stores your files, source strings and translations, translation memories and glossaries, screenshots and visual context, and user profiles and team membership info — a corpus that grows with every job and persists offshore, with backups in the same region. For a critical information infrastructure operator or high-volume handler, China-collected personal information must be stored in the mainland (Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — a duty an offshore corpus cannot meet. |
| Retention and model-training | Crowdin's AI and machine-translation features are opt-in and, when used, route your strings on to further offshore sub-processors Crowdin names — among them DeepL (Germany), OpenAI (Ireland), Anthropic and Microsoft Azure (US), and Mistral AI (France) — none in mainland China. Whether inputs are retained or used to improve models turns on those providers' terms and your configuration. Crowdin offers a US-or-EU residency choice (Enterprise) but no customer-hosted or on-premises deployment; "self-hosted" here means connecting self-hosted Git servers, not running Crowdin on your own infrastructure. |
| Is it reachable? (not the axis) | Treat reachability as the delivery half, not the question — the app, API, and integrations connect from the mainland. The lawful lever is to keep China-origin content's translation in-country: a licensed in-country machine-translation / localization path that holds the data in China, with personal information minimized or pseudonymized in strings before any offshore call and offshore AI/MT features off for China content. Any China-facing site or app that consumes the translations needs an ICP filing tied to mainland hosting (State Council Order No. 292; MIIT Order No. 33). |
What you actually send — and where it goes
Crowdin is the system of record for your localization: it holds the source strings and documents you upload, their translations, the translation memory and glossaries that accumulate across projects, and the screenshots and visual context translators use to do the work — plus the accounts of the translators, vendors, and members who touch it. It holds the actual content, not a pointer to it. And a localization pipeline pulls from the places your content already lives: Crowdin connects to GitHub, GitLab, and Bitbucket, to CMSes and design tools, and to your own code through its CLI and API — so content flows in continuously, and each sync is another copy leaving your systems for Crowdin’s.
Where does it land? Crowdin’s own data-residency page is explicit: “customer data is stored in the US Data Center by default,” and “Data center selection is not available in Crowdin.” Crowdin Enterprise lets an organization choose, at creation, a US data center (“hosted on AWS in the US-east-1 region (N. Virginia)”) or an EU one (“hosted on AWS in the EU-west-1 region (Ireland)”); the choice is fixed once set, migration between regions is not supported, and — critically — there is no mainland-China region to select. The chosen region stores your files, strings and their metadata, translation memories and glossaries, screenshots and visual context, and user profiles and team membership info, with backups in the same region. Crowdin also notes that some operational data — authentication data, the Global Translation Memory, store-app and integration data — may be processed outside your selected region, so even the EU choice does not keep everything in one jurisdiction. None of these jurisdictions is China.
It’s a cross-border data transfer — under PIPL
The moment your source content describes people in China — names and emails in support tickets, HR or customer records in documents, ID or financial details in legal and compliance text, unreleased product copy, user-generated strings — sending it to Crowdin to be translated is a cross-border transfer of personal information (数据出境). Under China’s Personal Information Protection Law, that transfer needs three things before it is lawful: clear notice to the individuals, a separate consent for the cross-border leg specifically, and one statutory transfer mechanism — a CAC-led security assessment, the CAC standard contract with filing, or certification (PIPL Articles 38–40). Because a translation-management system syncs, the transfer is not a one-time event: every push from your Git or CMS integration re-exports whatever changed.
Sensitive personal information raises the bar. Translated content frequently includes health, financial, legal, biometric, religious, or government-ID data — and you cannot anonymize a document you need rendered in full. Processing sensitive personal information under PIPL Article 28 requires its own separate consent and a prior personal-information protection impact assessment (PIPIA).
Residency is the second duty. Crowdin’s corpus — translation memory, glossaries, project store, screenshots, and member accounts — persists on its offshore AWS region and grows with every job. For a critical information infrastructure operator or a handler whose volumes cross the regulators’ thresholds, China-collected personal information and important data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and where an export is permitted at all, crossing a volume or sensitivity threshold can trigger a CAC data-export security assessment before anything lawfully leaves.
Reaching the platform isn’t the question — keeping the content in-country is
Nothing about Crowdin is blocked in the mainland — the web app, the API, the CLI, and the Git, CMS, and design integrations all connect. So reachability is the delivery half, not the compliance question. The exposure is that your localization content, and the personal and sensitive information inside it, rests on an offshore service with no mainland-China region.
Here the honest lever is narrower than it is for some vendors. Crowdin does offer a residency choice — a US or EU data center for Crowdin Enterprise — but neither is in China, and Crowdin offers no customer-hosted, on-premises, or private-cloud deployment of the platform itself. Its “self-hosted” support refers to connecting self-hosted Git servers — GitHub Enterprise, GitLab Self-Managed, Bitbucket Server — which changes where your source repository lives, not where Crowdin stores the strings, translation memory, glossaries, and screenshots it extracts; those still rest in Crowdin’s US or EU region. So you cannot keep the corpus in China by configuring Crowdin.
What you can do is keep China-origin content’s translation off the offshore path in the first place: route it through a licensed in-country machine-translation / localization service that holds the data in China, minimize or pseudonymize the personal information in strings before any string that must go abroad does, and keep Crowdin’s AI and machine-translation features — which call further offshore providers — turned off for China content. That is localization, not a tunnel that ships the content offshore anyway; you keep Crowdin for your other markets, and only the minimized, lawfully transferable subset ever crosses the border.
This is a risk map, not a verdict: whether you owe a transfer mechanism, a separate consent, an Article 28 impact assessment, a data-export security assessment, in-country storage, or an ICP filing turns on your entity, your volumes, how much of your content is personal or sensitive, and whose data it is — settle the specifics with counsel before you route a single project through an offshore region.
The lawful path — map, localize, deliver
You do not have to drop Crowdin to run localization lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner alongside your stack, not a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team inventories what content flows to Crowdin — which projects, which strings, which uploaded documents and screenshots — what personal, sensitive, or confidential information it carries, where Crowdin stores it, whether your AI and machine-translation features route it on to further offshore providers, and where you lack a lawful basis for the cross-border leg, so the exposure is written down before anything else moves.
Localize. Because Crowdin offers no mainland-China region and no customer-hosted deployment, we keep China-origin content’s translation in-country on a licensed in-country machine-translation / localization path that holds the data in China — with personal information minimized or pseudonymized in strings before any offshore call, and offshore AI/MT features kept off for China content. Localize means keeping that content’s translation on an in-country path, never a tunnel that ships the content offshore anyway; you keep Crowdin for your other markets, and only the minimized, lawfully transferable subset ever crosses.
Deliver. The China-facing site or app that consumes the translations is a public internet service with an ICP filing duty; the 21YunBox Optimizer provides ICP-filed, in-country delivery in front of the stack you already run — no rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your localization runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization (Article 39)
- China’s data-export security assessment measures
- How to get an ICP filing for China
