Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Esker Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules

Esker is a French-origin cloud SaaS for accounts-payable, accounts-receivable and procure-to-pay document automation, run on Microsoft Azure and AWS with no mainland-China region — so the invoices, supplier and customer master data and personal information your China operation keeps in it sit offshore. A compliance-first look at the PIPL cross-border, important-data and residency exposure, and the lawful in-country path.

Does Esker work in China?

Esker is reachable from mainland China, so reachability is not the question — what decides it is that your China operation's invoices, supplier and customer master data and the personal information tied to them sit on an offshore cloud with no mainland-China region, which makes running a China operation on it a PIPL cross-border transfer. And the procurement and spend data can, in some sectors, be “important data” that needs a CAC data-export security assessment before it leaves.

Esker is a French-origin, multi-tenant cloud platform for source-to-pay and order-to-cash document automation, run on Microsoft Azure and AWS with data centers in Europe, North America, Australia and Singapore — none in the mainland. Loading China supplier, customer and employee personal information into it is a PIPL cross-border transfer (Articles 38–40: notice, a separate consent, and one transfer mechanism), and consolidated spend, sourcing and supplier-network data can be “important data” (重要数据) under the Data Security Law that requires a CAC data-export security assessment before it leaves — regardless of any PII. For a critical or high-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty. The lawful lever is to keep the supplier and supply-chain data in-country, classify and handle any important data, obtain supplier and employee consent, and ICP-file any China-facing supplier surface — not to make the offshore platform reachable.

Whether your supply-chain data is important data turns on your sector, so treat the specifics as a risk to confirm with counsel. Our China team can map your exposure →

What Esker's own documentation says about China

FactPrimary source
Esker runs multi-tenant on Microsoft Azure and AWS, with no mainland-China region. Esker's own Cloud Platform page lists 11 data centers — “on-premises data centers in France, Germany and the U.S., Microsoft Azure data centers in Australia, Canada, Ireland, the Netherlands and Singapore, and data centers hosted in AWS in France, the U.K. and the U.S.” — none in mainland China, and describes a “Multi-tenant platform operating on MS Azure, AWS & more.” Esker, “Cloud Platform” (esker.com), retrieved 2026-10-11
Esker is a source-to-pay and order-to-cash document-automation platform. Esker's own site describes a cloud platform spanning Source-to-Pay (procurement, purchasing, supplier management and accounts payable) and Order-to-Cash (order management, accounts receivable and collections management) — so for a China entity it holds invoices, supplier and customer master data, spend and contract data, and the personal information of suppliers, customers and approvers. Esker, “Cloud Platform” / solutions pages (esker.com), retrieved 2026-10-11
Supplier PII and supply-chain data on an offshore cloud trigger PIPL cross-border rules — and may need a CAC data-export assessment. Loading China supplier, customer and employee personal information into an offshore Esker instance is a cross-border transfer under PIPL (Articles 38–40: notice, a separate consent, one transfer mechanism), and consolidated spend, sourcing and supplier-network data can be “important data” (重要数据) whose export requires a mandatory CAC data-export security assessment before it leaves, regardless of PII. 21YunBox — Cross-border data transfers under PIPL; China data-export security assessment measures, retrieved 2026-10-11
A critical or high-volume handler must store China personal information in the mainland. Under the Cybersecurity Law's Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged), a critical information infrastructure operator or high-volume handler must store personal information generated in China inside the mainland — a duty an offshore, multi-tenant Esker cloud cannot meet. 21YunBox — China's Cybersecurity Law (data localization, Article 39), retrieved 2026-10-11

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running Esker across a China operation, the instinct is to ask whether it opens from Shanghai — and it does: Esker is multi-tenant cloud software China does not block at the border. So reachability is not where the China decision is settled. What settles it is where the invoices, supplier and customer master data, and AP/AR records your China entity enters come to rest — and whether any of that spend and sourcing data is “important data” that cannot leave without a government assessment. Esker is a French-origin cloud platform for source-to-pay and order-to-cash document automation, run on Microsoft Azure and AWS with no mainland-China region; the sites it calls “on-premises” are its own, in France, Germany and the U.S. So those records sit offshore — a PIPL cross-border transfer, not a speed question, with a sector-dependent “important data” door, consent and residency duties, and an ICP filing for any China-facing supplier surface.

Esker's own Cloud Platform page listing its 11 data centers — on-premises in France, Germany and the U.S., Microsoft Azure in Australia, Canada, Ireland, the Netherlands and Singapore, and AWS in France, the U.K. and the U.S. — with no mainland-China region
"Esker has on-premises data centers in France, Germany and the U.S., Microsoft Azure data centers in Australia, Canada, Ireland, the Netherlands and Singapore, and data centers hosted in AWS in France, the U.K. and the U.S." — Esker's own cloud-platform page lists all 11 hosting locations, and none is in mainland China. Source: Esker — Cloud Platform

Esker in China at a glance

What decides it In Esker's own terms — and China's law
What it holds A cloud platform for source-to-pay and order-to-cash document automation — accounts payable, accounts receivable and collections, procurement, order management and supplier management. For a China entity it holds the invoices and AP/AR records, the supplier, vendor and customer master data, the spend and contract data, and the personal information tied to them: supplier and customer contacts, and the buyer and approver identities in every workflow.
Where it runs Offshore. Esker's own Cloud Platform page lists 11 data centers — its own sites in France, Germany and the U.S., Microsoft Azure in Australia, Canada, Ireland, the Netherlands and Singapore, and AWS in France, the U.K. and the U.S. There is no mainland-China region, so the records your China operation enters come to rest in another country — a cross-border transfer (数据出境) under PIPL (Articles 38–40).
The important-data door Beyond personal information, consolidated spend, sourcing and supplier-network data can be classified as "important data" (重要数据) under the Data Security Law in strategic sectors (manufacturing, automotive, pharmaceuticals, energy, logistics). Where it is, transferring it abroad requires a CAC data-export security assessment (数据出境安全评估) before anything leaves — regardless of whether personal information is involved. Whether your data qualifies turns on your sector and the applicable catalogs.
Supplier PII + residency Supplier, customer and employee-approver details are personal information: PIPL requires notice and a separate, specific consent for the cross-border transfer (Articles 13 and 23), with minimization. For a critical information infrastructure operator or high-volume handler, personal information generated in China must be stored in the mainland under the Cybersecurity Law's Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) — a duty an offshore cloud cannot meet.
Reachability is not the axis Whether Esker opens from the mainland is not the decision; where its invoices, supplier data and spend records are allowed to sit is. The lawful path keeps the China supplier and AP/AR data on an in-country footing, classifies and handles any important data, obtains the supplier and employee consent, and delivers any China-facing supplier surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never moves personal information offshore by stealth.

What you actually hold — supplier data, spend, and the AP/AR record

Esker does not hold an abstraction; it holds the paperwork that runs your purchasing and billing. On the source-to-pay side sit purchase requisitions and orders, supplier master data, and the accounts-payable invoices Esker captures, codes and routes for approval and payment. On the order-to-cash side sit customer master data, sales orders, the accounts-receivable ledger, and collections and dispute records. Around all of it are the people: supplier and customer contacts, the buyers and approvers in each workflow, and the employees whose identities move through it. For a China operation that record is thick with the personal information of Chinese suppliers, customers and staff — and with the spend, pricing and sourcing data that describes how your China supply chain actually runs.

Where does it live? Offshore. Esker’s own Cloud Platform page places the service on its network of 11 data centers — Esker-operated sites in France, Germany and the U.S., Microsoft Azure regions in Australia, Canada, Ireland, the Netherlands and Singapore, and AWS in France, the U.K. and the U.S. — and describes Esker as a “Multi-tenant platform operating on MS Azure, AWS & more.” None of those locations is in the mainland, and there is no customer-run, in-country build to deploy there. So the moment your China staff and counterparties raise invoices, onboard suppliers and post AR entries, those records come to rest outside China.

The doors: cross-border personal data, important data, and in-country storage

Once the data is offshore, a different body of law decides whether it was allowed to go there. The supplier, customer and employee details inside Esker are personal information under China’s Personal Information Protection Law, and loading them into an Azure- or AWS-hosted instance outside China is a cross-border transfer (数据出境). PIPL puts the duty on the handler — your China entity, not Esker the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your systems, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — with the minimization and consent duties of Articles 13 and 23 on top.

The distinctive half for a procurement platform is not the personal data at all. Consolidated spend, sourcing, supplier-network and logistics data can be treated as “important data” (重要数据) under the Data Security Law and the national and sectoral important-data catalogs — most readily in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy and logistics. Where your data falls into that class, moving it abroad requires a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves, regardless of whether any personal information is involved or how much. For an AP/AR and procurement platform this is sector-dependent rather than automatic — but it is the door that gets missed, because the exposure is the strategic nature of the data itself, not only the PII attached to it.

Residency is the third door. If your organization is a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37) requires personal information generated in China to be stored in the mainland — an in-country duty no offshore Esker region can satisfy. Which doors apply, and in what combination, depends on your sector, your data volumes and your role as handler; the law pages set out the tests.

Logging in isn’t the question — a compliant in-country supply chain is

Because Esker is multi-tenant cloud software with no mainland-China region and no customer-run, in-country build, you cannot localize the data by relocating the product: there is nothing in the mainland to provision, and switching among its offshore Azure and AWS regions merely moves the transfer, it does not end it. The lawful shape is therefore to keep the China supplier, customer and AP/AR data on an in-country footing, send Esker only what may lawfully leave for the group process, classify the spend and supplier-network data and handle any important-data and data-export-assessment duty, minimize and obtain consent for the supplier and employee personal information, and treat any China-facing surface — a supplier portal, an onboarding or self-service page served to mainland suppliers — as a public service that carries an ICP filing duty and needs compliant, in-country delivery. That is a residency-and-delivery design, not a matter of making the offshore cloud load faster, and never a hidden path that ships the data offshore anyway. None of this is a verdict that Esker is “blocked” or “illegal”: whether your supply-chain data is important data turns on your sector, and whether you owe a separate consent, a transfer mechanism, in-country storage, a data-export assessment, an ICP filing, or some combination depends on your entity, your data volumes and who your users are — worth settling the specifics with counsel before your China operation depends on it.

The lawful path — map, localize, deliver

There is a compliant way to run procurement and billing for a China operation, and it has a shape. First, map: our China team inventories what your Esker holds — which supplier, customer and employee personal information, which spend, contract and sourcing records, and which supplier-network and logistics data your China entity generates — where each is processed and stored (an Azure or AWS region, with no mainland-China option), and whether any of it is “important data.” The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: because Esker offers no mainland region or customer-run build to localize onto, we help you put the China supplier and AP/AR data on a China-resident footing — a consented, in-country processing-and-storage pattern — so the China records and China personal data stay resident and stop leaving the country by default, while you keep Esker for your other markets and the group process. We classify the spend and supplier-network data, handle any important-data and data-export-assessment duty, and minimize and protect the supplier and employee personal information, so that what crosses the border afterward is only what may lawfully cross it. Localize means keeping the data on an in-country path — never a tunnel that ships it offshore anyway.

Then deliver: the China-facing surfaces — a supplier portal, an onboarding or SRM self-service page served to mainland suppliers — are a public service in the mainland, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform, so your mainland suppliers and staff reach the service reliably on ICP-filed infrastructure. The result is a procurement and billing stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we localize what must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Esker available in mainland China?
Yes. Esker is multi-tenant cloud software and is reachable from the mainland, so availability is not the obstacle. The real question for a China operation is data residency and consent. Esker's own Cloud Platform page lists data centers in Europe, North America, Australia and Singapore, with no mainland-China region, so the invoices, supplier and customer master data and the personal information your China entity enters come to rest offshore — a cross-border transfer under PIPL. Treat the specifics as a risk to confirm with counsel.
Does running Esker in China require a CAC data-export security assessment?
It can, and the answer is sector-dependent. Transferring the supplier, customer and employee personal information in Esker offshore is a PIPL cross-border transfer that needs notice, a separate consent and a transfer mechanism (Articles 38–40). Separately, if your consolidated spend, sourcing or supplier-network data is classified as “important data” (重要数据) under the Data Security Law and the applicable catalogs — most readily in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy and logistics — its export requires a mandatory CAC data-export security assessment before anything leaves, regardless of any personal information. Whether your data qualifies turns on your sector; confirm it with counsel.
Can 21YunBox make Esker compliant in China?
Not by making the offshore platform “reachable” — that is not the axis. We map what your Esker holds and where it runs, help you keep the China supplier, customer and AP/AR data on an in-country footing (an in-country data path, data classification and minimization), handle any important-data, data-export-assessment and consent duties, and ICP-file and deliver any China-facing supplier surface in-country — set in front of what you already run, with no rebuild, and never a hidden path that ships data offshore. The legal conclusions are settled with your counsel; we build and run the compliant in-country path.

ARTICLES RELATED TO ESKER

CATEGORIES

Procurement

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.