Does Diligent Work in China? Board, Governance & Whistleblower Data, PIPL & Data Residency
Diligent's own trust page lets you store Diligent One Platform data in the AWS region you choose — and lists none in mainland China. So the board books, director PII, audit evidence and whistleblower case files it holds for your China people come to rest offshore: a PIPL cross-border transfer, some of it sensitive. A compliance-first look at the data-residency and sensitive-PI exposure.
Does Diligent work in China?
Diligent is reachable from China — but it offers no mainland-China region, so the governance records it holds for your China people come to rest offshore, a PIPL cross-border transfer.
Diligent Boards holds board books, minutes and director/officer PII; the Diligent One GRC platform holds audit evidence, risk registers and third-party due-diligence records; and Speak Up holds whistleblower and ethics-hotline reports that name identifiable people — sensitive personal information under PIPL Article 28. Diligent's trust page lets you pick among AWS regions (U.S., Canada, Frankfurt, London, Tokyo, Singapore, Sydney, Brazil, South Africa, plus GovCloud), none in mainland China, so China-origin records are held abroad. 21YunBox maps the exposure, localizes what must stay on mainland soil, and delivers any China-facing surface on ICP-filed, in-country infrastructure.
What Diligent's own documentation says about China
| Fact | Primary source |
|---|---|
| Diligent's trust page states the Diligent One Platform is 'available in multiple regions to give customers options for where their data is stored,' and lists its supported AWS regions as the U.S., Canada, Frankfurt, London, Tokyo, Singapore, Sydney, Brazil, South Africa and two GovCloud options — none in mainland China. | Diligent One Platform Trust and Compliance |
| Diligent states that 'Upon system setup, your platform data is stored in the data center region associated with the address listed in your Order Form,' and that customer data is 'stored exclusively in the single hosting region' — a chosen region, all of them offshore to China. | Diligent One Platform Trust and Compliance |
| Transferring personal information collected in China to an offshore region is a cross-border transfer requiring notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Whistleblower and investigation records are sensitive personal information under PIPL Article 28. | Personal Information Protection Law (cross-border transfer; Art 28 sensitive PI) |
| For a critical information infrastructure operator, personal information generated in China must be stored in China under Cybersecurity Law Article 39 (formerly Article 37), renumbered by the 2025 amendment in force January 1, 2026 — a residency duty no offshore region can meet. | Cybersecurity Law Article 39 (formerly Article 37) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a company that runs Diligent to govern its board and manage risk, the mainland-China question is almost never whether the dashboard opens. Diligent’s board portal and its GRC and ethics tools are reachable from inside China, so reachability is not where the decision is made. What settles it is residency — where the records these tools hold come to rest, and whether it was lawful to move them there. Diligent Boards holds board and committee books, minutes and resolutions, the personal details of the directors and officers on them, and material non-public information; the Diligent One GRC platform (built on the technology Diligent acquired as Galvanize/HighBond) holds audit evidence, risk registers and third-party due-diligence records; and its Speak Up tool holds whistleblower and ethics-hotline reports that name identifiable people. For your China directors, employees and counterparties, all of that is personal information — and the regions Diligent offers to store it in include none inside mainland China, as its own trust documentation sets out.
Diligent in China at a glance
| What decides it | In Diligent's own terms — and China's law |
|---|---|
| Where the records live | Offshore. Diligent's trust page states the “Diligent One Platform is available in multiple regions,” that “Upon system setup, your platform data is stored in the data center region associated with the address listed in your Order Form,” and that customer data is “stored exclusively in the single hosting region.” The supported regions — U.S., Canada, Frankfurt, London, Tokyo, Singapore, Sydney, Brazil, South Africa, plus two GovCloud options — include none in mainland China. |
| What it holds, and why it's personal (and sensitive) | Board and committee books, minutes and resolutions, director and officer PII, audit workpapers and evidence, risk registers, third-party due-diligence records with counterparty and signatory details, and — in Speak Up — whistleblower and ethics-hotline reports that name identifiable people. Those reports are allegations about individuals, sometimes touching health or finances, which makes them sensitive personal information under PIPL Article 28. |
| Your China people's data = cross-border | The directors, employees, whistleblowers and counterparties these records describe include people in China. Holding their data in an offshore Diligent region is a cross-border transfer (数据出境) governed by PIPL — notice, a separate consent, and one transfer mechanism (Articles 38–40). |
| In-country storage duty | For a critical information infrastructure operator or large-volume handler, personal information collected in China must be stored in China — PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37). The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged). No offshore Diligent region meets it. |
| Reachability is not the axis | The portal loads from China, so speed is not the question. A China-facing surface actually served to mainland users — a director or whistleblower intake portal — additionally turns on an ICP filing tied to a mainland hosting resource, which an offshore platform has nothing to file against. |
No mainland region, so the board books and case files leave the country
Diligent’s position is set in its own documentation, not by a load-time test. Its trust page describes the Diligent One Platform running on Amazon Web Services and states that it is “available in multiple regions to give customers options for where their data is stored” — then names them: the United States, Canada, Frankfurt, London, Tokyo, Singapore, Sydney, Brazil, South Africa, and two AWS GovCloud options for U.S. public-sector customers. Not one of those regions is inside mainland China, and the nearest — Tokyo, Singapore, Sydney — are all outside it. The page is explicit that “Upon system setup, your platform data is stored in the data center region associated with the address listed in your Order Form,” and that a tenant’s data is “stored exclusively in the single hosting region.”
So the only lever Diligent itself offers is a choice among offshore regions. Wherever you set the tenant, the board books, minutes, audit evidence and case files your China people generate come to rest outside the mainland — and that is a data-residency and cross-border transfer question under China’s law before performance ever enters the picture. “Can the Diligent console be reached from Shanghai?” is the wrong test; it can. The real question is where the China-collected records are allowed to live, and whether it was lawful to move them there.
What Diligent holds is personal information — and some of it is sensitive
Here is the structural point. Diligent exists to hold an organization’s most sensitive governance records: Diligent Boards keeps board and committee deliberations, resolutions and the personal details of the directors and officers who sit on them; the Diligent One GRC platform keeps audit workpapers and evidence, risk registers, and third-party due-diligence records carrying counterparty and signatory details; and Speak Up keeps whistleblower and ethics-hotline reports and the investigation files behind them. For your people in China, every one of those is personal information — and the whistleblower and investigation records are sensitive personal information under PIPL Article 28, because they are allegations about identifiable people and can carry health or financial detail. That category raises the bar: separate consent, a demonstrated necessity, and a personal-information protection impact assessment. The irony is hard to miss — the very tool you deployed to run governance and compliance creates a PIPL cross-border exposure of its own.
PIPL puts that duty on the handler — you, the organization, not Diligent the processor. Articles 38–40 require notice, a separate consent distinct from any general employment or board-service agreement, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the records count as “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, Cybersecurity Law Article 39 (formerly Article 37) requires that personal information generated in China be stored in China — an in-country duty no offshore Diligent region can satisfy. None of this turns on how quickly a board book renders; it turns on whether the data had a lawful basis to be where it is.
Narrowing the exposure doesn’t close the door
The obvious moves reduce the exposure without ending it. You can pick the nearest region Diligent offers — Tokyo or Singapore — but that relocates the cross-border transfer; it does not stop it, and none of Diligent’s regions is in mainland China, so none resolves a China residency duty. You can minimize or redact what gets uploaded, and restrict who may open a case file; that shrinks what crosses the border and who can read it, not that it crosses. Even where a tool supports a more isolated or dedicated footing, that changes the deployment, not the legal position, so long as the China-origin records still come to rest offshore. A board or whistleblower intake portal actually served to users inside China is a further question: a public-facing service reached from the mainland turns on an ICP filing (备案) tied to in-country hosting, which an offshore platform has nothing to file against.
This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination depends on your entity, your data volumes, your role as handler, and whose records you hold — worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
There is a lawful way to run governance, risk and ethics tooling for a China presence, and it has a shape. First, map: our China compliance team works through your PIPL exposure for the records Diligent holds — which board materials, director PII, audit evidence, due-diligence files and especially whistleblower and ethics reports collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your consent and notice flow has to cover for sensitive personal information. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we stand up consented, in-country processing and storage for the records that must stay on mainland soil — and a self-hosted or dedicated footing where the tool supports it — so the governance you depend on keeps working while that data stops leaving the country by default, and you keep the global Diligent tenant for the markets where it already serves you.
Then deliver: any China-facing surface — a director portal, an ethics-hotline intake form, a board or audit dashboard reached from the mainland — runs over ICP-filed, in-country delivery (the 21YunBox Optimizer), set in front of the stack you already run, with no rebuild and no second codebase. The result is governance and compliance tooling that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We are a compliant overlay, not a migration — and for an enterprise platform like Diligent, a partner and overlay, not a competitor.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
