Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does DataDome Work in China? Bot-Detection Data, PIPL Cross-Border Transfer & Consent

DataDome inspects every request — IP address, device and browser fingerprint, and behavioral signals — to tell bots from humans, and its own docs list the fixed endpoints its detection connects through in Singapore, Canada, the US, Ireland, the UK, Germany, France and Italy, with none in mainland China. So scoring your China visitors sends their personal information to an offshore endpoint — a cross-border transfer (数据出境) under PIPL, with a separate consent duty on top and no ICP-filing footing. A compliance-first look at the cross-border, consent and data-residency exposure, and the lawful in-country path.

Does DataDome work in China?

DataDome is a security tool whose raw material is your visitors' personal data: to tell a bot from a human it inspects every request — IP address, device and browser fingerprint, and behavioral signals — so the China question is not whether the tag loads, but where those signals are scored and whether you had a lawful basis to collect and move them.

DataDome scores each request on its own infrastructure, and its documentation lists the fixed endpoints its detection connects through in Singapore, Canada, the United States, Ireland, the United Kingdom, Germany, France and Italy — none in mainland China, the nearest being Singapore. So routing your China visitors' request, device and behavioral data to an offshore DataDome endpoint is a cross-border transfer (数据出境) of personal information under PIPL (notice, a separate consent, and one transfer mechanism, Articles 38–40), and it may trigger China's data-export security assessment. Inspecting each visitor carries its own PIPL consent duty on top, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore endpoint cannot meet.

This is a risk map, not a verdict — what you owe turns on what you collect, your data volumes, your role as handler and who your users are, and it is worth settling with counsel. 21YunBox maps your exposure, localizes the China signals onto a consented, in-country footing, and delivers your China-facing site in-country on ICP-filed infrastructure — never any form of circumvention. Our China team can map your exposure with you →

What DataDome's own documentation says about China

FactPrimary source
DataDome's detection feeds on each visitor's device and behavioral data. Its own JavaScript Tag documentation states the tag "collects behavioral data from the client (i.e. the web browser in most cases) such as mouse movements or key strokes," that "Generic information is also collected about the OS, the browser itself, the GPU, etc.," and that it is built to "send the fingerprint back to our API." Together with the IP address and request signals DataDome reads server-side, that is a continuous stream of personal information about people in China. DataDome Developer Docs — JavaScript Tag (docs.datadome.co), retrieved 2026-10-09
DataDome lists its fixed endpoints in eight countries — none in mainland China. Its documentation names fixed regional endpoints in Singapore, Canada, the United States, Ireland, the United Kingdom, Germany, France and Italy, and adds: "If you need a fixed endpoint in another region not listed below, please don't hesitate to contact us." The nearest to the mainland is Singapore; there is no in-country endpoint, so China visitors' request data is scored offshore. DataDome Developer Docs — Static IP endpoints (docs.datadome.co), retrieved 2026-10-09
Sending China visitors' signals to an offshore DataDome endpoint is a PIPL cross-border transfer. Moving personal information collected from people in mainland China — IP address, device fingerprint and behavioral signals — to a DataDome endpoint outside the mainland triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and above thresholds it may require China's data-export security assessment. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09
For some handlers the data must stay in China — and the site carrying the tag needs an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, China-collected personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore detection endpoint cannot satisfy. And any public-facing site served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33) bound to a mainland hosting resource DataDome's detection layer does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33, retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a site running DataDome against mainland China, the instinct is to ask whether the tag even loads. That is the wrong place to start. DataDome is a bot- and online-fraud-protection service, and the way it tells a bot from a human is by inspecting every request — the IP address, the device and browser fingerprint, the headers, and behavioral signals such as mouse movements and key strokes. Its raw material, in other words, is a continuous stream of personal information about each of your visitors. Whether that inspection may lawfully happen for people in China — and where their data is scored — is a compliance question, and China’s personal-information law decides it, not latency.

DataDome answers the location half in its own documentation. It scores each request on its own infrastructure, and the fixed endpoints its detection connects through are in Singapore, Canada, the United States, Ireland, the United Kingdom, Germany, France and Italy. None is in mainland China. So the moment a China visitor’s request is handed to DataDome to score, that visitor’s personal information has already left the country.

DataDome's documentation page 'Static IP endpoints', listing DataDome's fixed regional endpoints in Singapore, Canada (Central), Ireland, England, Germany, France, the United Kingdom, Italy and four US regions — with no mainland-China endpoint
DataDome's own documentation lists the fixed endpoints its service connects through — the regional addresses a firewalled integration must allow — in Singapore, Canada (Central), Ireland, England, Germany, France, the United Kingdom, Italy and four US regions, adding: “If you need a fixed endpoint in another region not listed below, please don't hesitate to contact us.” None of the listed endpoints is in mainland China — so a China visitor's request is scored offshore. Source: DataDome Developer Docs — Static IP endpoints

DataDome in China at a glance

What decides it In DataDome's own terms — and China's law
What it is A bot- and online-fraud-protection service. To tell a bot from a human it inspects every request — the IP address, the device and browser fingerprint, the headers, and behavioral signals such as “mouse movements or key strokes” — so its raw material is a continuous stream of personal information about each visitor.
Is reachability the question? No. DataDome's tag and API are offshore endpoints; whether they load from a given mainland network is a delivery matter. This page publishes no China latency figure — speed is not the axis, and the answer is never a network workaround.
Where the scoring happens On DataDome's own infrastructure, offshore. Its docs list fixed endpoints in Singapore, Canada, the US, Ireland, the UK, Germany, France and Italy — none in mainland China, the nearest being Singapore — and the tag is built to “send the fingerprint back to our API.”
Collecting China signals into it IP address, device fingerprint and behavioral records are personal information. Sending them from mainland visitors to an offshore DataDome endpoint is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Inspecting each visitor carries its own PIPL consent duty, and a data-export security assessment may apply above thresholds.
Residency & serving the public For a CIIO or large-volume handler, China-collected personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore endpoint cannot meet. The China-facing site carrying the tag needs an ICP filing bound to a mainland hosting resource DataDome's detection layer does not provide.

The signals it inspects are personal information — and they are scored offshore

This is not a “does it load” test. DataDome’s JavaScript tag, in its own docs, “collects behavioral data from the client (i.e. the web browser in most cases) such as mouse movements or key strokes,” and “Generic information is also collected about the OS, the browser itself, the GPU, etc.” The tag is then built to “send the fingerprint back to our API,” where — together with the IP address and the request signals DataDome reads server-side — it is scored to reach a bot-or-human verdict. Under China’s Personal Information Protection Law, an IP address, a device fingerprint and a record of how someone moved through a page are personal information, whether or not DataDome resolves them to a named person. Whether the tag loads quickly from a given mainland network is a delivery matter this page does not score with a latency figure — and the answer is never a network workaround.

DataDome is plain about where that scoring happens. Its documentation lists the fixed endpoints its service connects through — Singapore, Canada (Central), the United States, Ireland, the United Kingdom, Germany, France and Italy — and invites you to “contact us” for any region “not listed.” The nearest endpoint to the mainland is Singapore; there is none inside China. So when your deployment captures those signals from a visitor in Shanghai and hands them to a DataDome endpoint to be scored, you have made a cross-border transfer (数据出境) of personal information. PIPL puts the duty on the handler — you, not DataDome the processor: Articles 38–40 require notice, a separate consent distinct from any general site agreement, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the data is “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves.

DataDome notes that its cookie “is encrypted for security and does not contain any personally identifiable information (PII),” and that the tag is “focused on bot detection and not tracking.” Both can be true and beside the point. The cross-border and consent duties do not attach to what the cookie stores; they attach to the raw signals DataDome processes to reach its verdict — the IP address, the device and browser fingerprint, and the behavioral stream — which are personal information under PIPL regardless of whether the resulting cookie is anonymous. A privacy-respecting design can genuinely reduce exposure; it does not move the processing back inside China or discharge the handler’s duties. Whether your specific signals count as personal or sensitive information is a question to settle with counsel.

Inspecting every visitor is its own PIPL duty

Residency is only half of it. Bot detection works by observing what identifiable clients do — how a pointer moves, how keys are struck, how a device and browser are configured, how a session behaves over time — and scoring it. Under PIPL, that observation is itself processing of personal information, and it needs its own lawful basis: in practice, informed notice, and consent where required, before the tag begins collecting. The cross-border transfer to an offshore endpoint then needs a further, separate consent on top of that. A consent flow written for your analytics does not automatically cover a security layer that inspects every visitor; what your notice must say, and whether consent or another basis applies, is a question for counsel against what you actually collect.

Residency and ICP: no mainland endpoint to store on or serve from

Two further obligations turn on the same missing region. First, residency: if you are a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged)). An offshore detection endpoint cannot meet that duty. Second, licensing: the China-facing site or app that carries the DataDome tag — the pages your users actually load — is a public internet service in the mainland, so serving it compliantly from inside China turns on an ICP filing (备案) bound to a mainland hosting resource. DataDome’s detection layer provides none, so there is nothing of its own to file against.

This is not a ruling that DataDome is “blocked” or “illegal” in China. It is a map of risk: which duties actually bite depends on your entity, the signals your deployment collects, your role under Chinese law, and who your visitors are — and that is worth settling with counsel before your security layer leans on it.

The lawful path — map, localize, deliver

There is a lawful way to run bot and fraud protection for a China-facing property, and it has a shape. First, map: our China team works through your PIPL exposure on every front — the behavioral profiling, the cross-border transfer, and the residency question — pinning down which signals collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your notice and consent flow has to cover. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a consented, in-country footing for the China traffic — a domestic bot- and fraud-protection pattern, or in-country processing for the China property — so the signals your mainland visitors generate are inspected and held on a China-resident basis, while you keep DataDome for the markets where it already serves you, fed only by what may lawfully leave. Where there is no clean domestic equivalent, it is that lawful in-country pattern — consented collection, in-country processing and storage — that we build to, rather than a like-for-like swap.

Then deliver: the page a mainland visitor actually opens is a public internet service in China in its own right, and that is where the ICP-filing duty and the need for compliant in-country delivery land. We provide that layer — the 21YunBox Optimizer — standing in front of the stack you already run, so nothing gets rebuilt or re-platformed. The outcome is bot and fraud protection that runs legally and compliantly for your users in China. The one thing we will not do — because no one lawfully can — is engineer a route around China’s data-export rules or around any network restriction: 21YunBox never uses or suggests circumvention of any kind. We keep in-country what must stay, inspect it on a consented domestic footing, and deliver the site from inside the mainland — nothing is moved across the border by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is DataDome blocked in China?
This is the wrong first question. DataDome is a bot- and fraud-protection service, and whether its tag or API loads from a given mainland network is a delivery matter — this page publishes no China latency figure, and the answer is never a network workaround. What actually decides DataDome's use in China is compliance: it inspects every request's IP address, device fingerprint and behavioral signals, and it scores them on infrastructure outside the mainland, which raises cross-border-transfer, consent and data-residency duties. Treat the specifics as a risk to confirm with counsel.
Is sending China visitors' signals to DataDome a cross-border transfer?
If the DataDome endpoint scoring your traffic is outside the mainland — and every endpoint DataDome lists is — then the IP address, device fingerprint and behavioral signals it processes for your China visitors leave the country, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and it may be subject to China's data-export security assessment. Inspecting identifiable visitors also needs its own PIPL basis on top. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore endpoint cannot meet. Confirm your exact obligations with counsel.
DataDome says its cookie contains no personal data — isn't that enough?
Not by itself. DataDome states its cookie "is encrypted for security and does not contain any personally identifiable information (PII)," and that the tag is "focused on bot detection and not tracking." Both can be true while the duties still apply, because the cross-border and consent obligations attach to the raw signals DataDome processes to reach its verdict — the IP address, the device and browser fingerprint, and the behavioral stream — not to what the resulting cookie stores. 21YunBox maps that exposure, localizes the China signals onto a consented in-country footing, and delivers your China-facing site on ICP-filed infrastructure — never a route around China's data-export rules.

ARTICLES RELATED TO DATADOME

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.