Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Demandbase Work in China? Visitor-IP Data Residency, PIPL Cross-Border & Automated Profiling

Demandbase works by de-anonymizing your site's visitors — reading each visitor's IP address, mapping it to a company, and building an intent and engagement profile — and it hosts that data on AWS and Google Cloud with no mainland-China region. For a China-facing site that turns visitor IPs and de-anonymized records into personal information crossing the border under PIPL, with automated-profiling duties (PIPL Article 24) on top. A compliance-first look at the data-residency, cross-border and consent exposure — and the lawful, consented, in-country path.

Does Demandbase work in China?

The question isn't whether the Demandbase tag loads from Shanghai — it's what Demandbase does with your Chinese visitors and where it keeps the result. Demandbase de-anonymizes site visitors: it reads each visitor's IP address, maps it to a company, and builds an intent and engagement profile — and it hosts that data on AWS and Google Cloud with no mainland-China region.

For a visitor in mainland China, the IP address and the de-anonymized record are personal information, and holding them offshore is a cross-border transfer (数据出境) under PIPL — notice, a separate consent, and a transfer mechanism (Articles 38–40) — which above thresholds may trigger China's data-export security assessment. De-anonymizing and profiling identifiable visitors is itself automated decision-making under PIPL Article 24, with a consent duty under Article 13, and it bites even on data that never leaves China. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires in-country storage no offshore region can meet.

21YunBox maps your cross-border, residency and profiling exposure, localizes the China visitor data onto a consented, in-country footing (sending Demandbase only what may lawfully leave), and delivers your China-facing site in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Demandbase's own documentation says about China

FactPrimary source
Demandbase hosts on AWS and Google Cloud, with no mainland-China region. Its Security Policy states that "Demandbase uses Amazon Web Services (AWS) and Google Cloud Platform (GCP) as the primary cloud platforms," across "multiple regions and multiple availability zones" — and neither cloud operates a commercial region inside mainland China. So the visitor records it builds from your Chinese traffic come to rest offshore, a cross-border transfer of personal information under PIPL. Demandbase Security Policy (demandbase.com), retrieved 2026-10-09
Demandbase's own Privacy Notice names the United States — not China — as a processing destination. Effective April 21, 2026, it says Demandbase may "transfer, store, or process your personal information in a country outside your jurisdiction," "including the United States," and relies on standard contractual clauses when moving data out of the EEA, Switzerland or the UK. No mainland-China location appears. Demandbase Privacy Notice (demandbase.com), effective 2026-04-21, retrieved 2026-10-09
Demandbase's core function reads a visitor's IP address — which is personal information under Chinese practice. Demandbase de-anonymizes web traffic by mapping visitor IPs to companies, drawing on what it describes as "around 3.7 billion IP addresses that are mapped to a company or otherwise classified," supplemented by over a billion cookies. Reading a mainland visitor's IP and attaching an account identity and intent score to it is processing of personal information that PIPL requires a lawful basis for (Article 13), and building and acting on the profile is automated decision-making under Article 24. Demandbase, "...Improved Target Account Identification with More IP and Cookie Data" (demandbase.com), 2024-11-07, retrieved 2026-10-09; PIPL Articles 13 and 24
For China visitors, the transfer, the profiling and the public site each carry a duty. Moving China-collected personal information to an offshore Demandbase triggers PIPL Articles 38–40 (notice, a separate consent, a transfer mechanism) and may require China's data-export security assessment; for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) requires in-country storage; and a public site served from inside the mainland needs an ICP filing bound to a mainland hosting resource Demandbase does not provide. PIPL Articles 24, 38–40 (cac.gov.cn); Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33, retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a company running Demandbase on a China-facing website, the first instinct is to ask whether the tag loads from Shanghai. That is not where the China decision is made. Demandbase’s entire purpose is to de-anonymize the people who land on your site — to read each visitor’s IP address, resolve it to a company, and build an intent and engagement profile around that account — and to keep the resulting records on its own cloud infrastructure. For a visitor in mainland China, the IP address Demandbase reads and the de-anonymized record it assembles are personal information, and Demandbase holds them outside the country. So two questions arrive before performance ever does: where that personal information is allowed to live, and whether you had a lawful basis to profile the person in the first place. Demandbase settles the first in its own security and privacy documentation.

Demandbase's own Security Policy page, Architecture section, stating that Demandbase uses Amazon Web Services (AWS) and Google Cloud Platform (GCP) as its primary cloud platforms, spanning multiple regions and availability zones — with no mainland-China region
Demandbase's own Security Policy: “Demandbase uses Amazon Web Services (AWS) and Google Cloud Platform (GCP) as the primary cloud platforms.” Neither of those clouds runs a commercial region inside mainland China — so the visitor IP addresses and de-anonymized records Demandbase builds from your Chinese traffic come to rest offshore. Source: demandbase.com — Security Policy

Demandbase in China at a glance

What decides it In Demandbase's own terms — and China's law
What it is Demandbase is a B2B account-based marketing platform. It de-anonymizes website visitors — reading each visitor's IP address, resolving it to a company, and building an intent and engagement profile — drawing on what it describes as a dataset of around 3.7 billion IP addresses mapped to companies, plus more than a billion cookies. So it holds an identifiable, account-level record of who visits your site.
Is it reachable from the mainland? The Demandbase tag and its APIs are served from its offshore commercial cloud, so for most sites the script will load. But load time is not what decides the China question, and this page publishes no China latency figure for it. Reachability is the delivery half; the legal half is below.
Where does the visitor data sit? Offshore. Demandbase's Security Policy names AWS and Google Cloud as its primary cloud platforms, across “multiple regions and multiple availability zones,” with no country named and no mainland-China region; its Privacy Notice names the United States as a processing destination and uses standard contractual clauses for EEA, Swiss and UK transfers. There is no China region to select.
Collecting China visitor data into it A visitor's IP address and the de-anonymized record built from it are personal information. Holding them in a US or EU Demandbase is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Above thresholds a data-export security assessment may apply, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
De-anonymizing and profiling visitors Reading a visitor's IP and attaching an account identity is processing of personal information needing a lawful basis — consent — under PIPL Article 13; building and acting on account profiles is automated decision-making under PIPL Article 24 (transparency, fairness, a right to refuse). These duties apply to identifiable visitors in China even for data that never leaves the country.
The lawful path Keep the China-collected IP-derived identifiers and account records on a consented, China-resident footing, send Demandbase only what may lawfully leave, keep Demandbase for your other markets, and deliver the China-facing site in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention.

Where the visitor data lives — offshore, in Demandbase’s own words

Demandbase’s position is set in its own documentation, not by a load-time test. Its Security Policy states that “Demandbase uses Amazon Web Services (AWS) and Google Cloud Platform (GCP) as the primary cloud platforms,” and that this infrastructure “spans multiple regions and multiple availability zones within each region.” Neither of those clouds runs a commercial region inside mainland China — Google Cloud operates none, and the AWS China partition is a separate, locally operated environment, not the global AWS Demandbase describes. Its Privacy Notice (effective April 21, 2026) is just as plain about destination: it says Demandbase may “transfer, store, or process your personal information in a country outside your jurisdiction,” “including the United States,” and relies on standard contractual clauses when moving data out of the EEA, Switzerland or the UK. No mainland-China location appears anywhere in either document.

So the visitor records Demandbase builds from your Chinese traffic come to rest in the United States or Europe. Under China’s Personal Information Protection Law that is a cross-border transfer (数据出境) of personal information, and the duty falls on the handler — you, the site operator, not Demandbase the processor. PIPL Articles 38–40 require notice, a separate consent for the overseas transfer distinct from any general agreement to use your site, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above certain volumes, or where the data counts as “important data,” the transfer may also need China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization clause was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in the mainland, which an AWS or GCP account outside the country cannot satisfy.

A visitor’s IP address is personal information — and de-anonymizing it is profiling

The residency question is only half of it, and Demandbase raises a second half that a plain analytics tool does not. Its core function is to de-anonymize web traffic: it reads a visitor’s IP address and resolves it to a company, drawing on what it describes as a dataset of “around 3.7 billion IP addresses that are mapped to a company or otherwise classified,” supplemented by more than a billion cookies (Demandbase, retrieved 2026-10-09). Under Chinese practice an IP address is itself personal information — so before any data crosses a border, reading a mainland visitor’s IP and attaching an account identity and an intent score to it is already processing of personal information, which PIPL requires a lawful basis for: in practice informed consent and clear notice before the tag begins collecting (PIPL Article 13).

It goes one step further. Because Demandbase then builds account-level profiles and uses them to target, personalize and prioritize outreach, that is automated decision-making under PIPL Article 24 — which layers on its own duties: transparency and fairness in the decision, a visitor’s right not to be subject to a decision made solely by automated means, and, for commercial messaging driven by those profiles, an option that is not targeted to the individual’s characteristics or an easy way to refuse. This duty bites on the profiling itself: it applies to the identifiable visitors you observe in China even for data that never leaves the country. Whether your identifiers count as personal information in a given flow, whether any field is sensitive, and exactly what your consent and notice must say are questions to settle with counsel.

Why pointing Demandbase at “a different region” isn’t the fix

The reflex is to flip Demandbase to an in-region setup and keep the data local — but the only places Demandbase runs are AWS and Google Cloud regions outside the mainland. Moving a China visitor’s record from a US environment to a European one relocates the cross-border transfer; it does not end it, because neither is in China. Keeping China-collected visitor data in the country means standing up a consented, China-resident footing for the IP-derived identifiers and account records, and sending Demandbase only what may lawfully leave. That split — what must stay, what may go — is the heart of the work, and it is a legal question before it is a technical one.

None of this is a verdict that Demandbase is “blocked” or “illegal.” It is a risk map: which obligations bite — a separate consent, a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination — turns on your entity, the data your tag actually collects, your role as handler, and who your visitors are. It is worth settling with counsel before your China-facing marketing depends on it.

The lawful path — map, localize, deliver

There is a lawful way to run account-based marketing for a China-facing site, and it has three moves.

First, map. Our China team works through the PIPL exposure on both fronts at once — the profiling and the transfer. We identify which visitor identifiers and de-anonymized records collected in China are personal information, what (if anything) may lawfully leave, where a data-export security assessment or an Article 39 storage duty applies, and what your consent and notice flow must tell a visitor before the tag starts reading their IP. The legal conclusions are yours to confirm with counsel; we build the technical and data-flow picture that feeds them.

Then localize. We stand up and integrate a consented, in-country footing for the China visitor data — the IP-derived identifiers, the engagement signals, the account records — so the de-anonymization and intent work you rely on keeps running while that personal information stops leaving the country by default. You keep Demandbase for the markets where it already serves you, and send it only what may lawfully cross the border. Where there is no clean domestic equivalent, the pattern is the point: consented collection, in-country processing and storage, and a minimized, lawful export — not a named product swap.

Then deliver. The China-facing site that carries the Demandbase tag is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the site you already run, with no rebuild and no re-platform. The outcome is account-based marketing that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Demandbase blocked in China?
Blocking is not the real issue. The Demandbase tag and APIs are served from its offshore commercial cloud, so for most sites the script loads — but reachability is not what decides compliance, and this page publishes no China latency figure. The decision turns on data residency and profiling: Demandbase maps your visitors' IP addresses to companies and keeps the records on AWS and Google Cloud outside mainland China, so for your Chinese visitors that is personal information crossing the border under PIPL, with automated-profiling duties on top. Confirm your exact obligations with counsel.
Is sending China visitor data to Demandbase a cross-border transfer?
If your Demandbase instance is hosted in the US or EU — anywhere outside the mainland — then the visitor IP addresses and de-anonymized account records it holds for your China visitors sit offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and above thresholds it may require China's data-export security assessment. De-anonymizing and profiling identifiable visitors also needs its own lawful basis under PIPL Articles 13 and 24. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet.
Can 21YunBox make our Demandbase setup work in China?
Yes. Our China team maps your exposure — the cross-border transfer, the residency duty, and the automated-profiling obligations that attach to the IP addresses and de-anonymized records Demandbase collects, for your entity, data volumes and visitors — then localizes the China visitor data onto a consented, in-country footing and delivers your China-facing site on ICP-filed infrastructure, in front of the Demandbase stack you keep running for your other markets. Get in touch to work through your specific case. We never use or suggest circumvention of any kind.

ARTICLES RELATED TO DEMANDBASE

CATEGORIES

CRM

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.