Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Guru Work in China? PIPL Cross-Border, Data Residency & Employee-Data Rules

Guru is a United States knowledge and sales-enablement platform, run on AWS with no mainland-China region. Your China workforce's employee personal information and internal content sit on its offshore cloud — a PIPL cross-border transfer — and Guru profiles your China employees through usage analytics under Article 24: a compliance-first look at the residency, employee-data and automated-decision exposure.

Does Guru work in China?

Guru loads in China, but your China workforce's employee personal information and your internal content sit on its offshore AWS cloud with no mainland-China region — a PIPL cross-border transfer — and Guru profiles your China employees through engagement and usage analytics under Article 24.

Guru is a United States enterprise AI knowledge and sales-enablement platform; by its own security page your content is "stored and managed in a highly secure AWS database," with no mainland-China region. The China employee directory, profiles and the who-reads-and-verifies-what analytics it holds are personal information, so running it for your China workforce is a PIPL cross-border transfer — and because the platform scores and profiles those employees, a PIPL Article 24 automated-decision door opens. The lawful lever is to keep the employee data and internal content in-country, handle the profiling duty, and ICP-file any China-facing surface — not to make the offshore platform reachable.

This is a risk map, not a verdict — which duties bite turns on your sector and workforce; settle the specifics with counsel. Our China team can map your exposure →

What Guru's own documentation says about China

FactPrimary source
Guru stores your content on AWS, with no mainland-China region. Its security page states content is "stored and managed in a highly secure AWS database," copied daily "to a disaster recovery site in an entirely separate region" — and names no mainland-China region anywhere, so a China operation's employee directory, profiles and internal content are held offshore. Guru — Security (getguru.com), retrieved 2026-10-11
Guru is a US-operated SaaS; EU data moves to the United States under Privacy-Framework and standard contractual clauses. Its security page says Guru "complies with the EU-U.S., the EU (United Kingdom Extension)-U.S., and the Swiss-U.S. Data Privacy Framework" and abides by "EU standard contractual clauses," and that "In addition to AWS, Guru uses some third parties" — confirming an offshore, US-centric footing with no China-resident path. Guru — Security (getguru.com), retrieved 2026-10-11
Running Guru for a China workforce is a cross-border transfer under PIPL. Holding your China employees' directory, profiles and usage analytics offshore puts the handler's duties in PIPL Articles 38–40 in play — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) — on top of the Articles 13/23 consent to collect employee data. 21YunBox — Cross-border data transfers under PIPL; PIPL Articles 13, 23, 38–40
Profiling China employees triggers PIPL Article 24; a CIIO or high-volume handler owes in-country storage. Guru's engagement and usage analytics profile individuals, so an Article 24 automated-decision duty can apply, and for a critical information infrastructure operator or high-volume handler Cybersecurity Law Article 39 (formerly Article 37) requires mainland-generated personal information to be stored in-country. 21YunBox — PIPL (Article 24) and Cybersecurity Law (Article 39, formerly 37)

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running Guru across a China operation, the instinct is to ask whether the knowledge base answers from Shanghai. It does — Guru is cloud software China does not block — so reachability is not the question. What settles it is where two things live: your internal company content (the cards, playbooks, collateral and answers your teams author and verify) and your China workforce’s employee personal information — the user directory and profiles, plus the engagement and usage analytics Guru builds about who reads, searches and verifies which knowledge. Guru is a United States enterprise AI knowledge and sales-enablement platform, run as cloud SaaS on Amazon Web Services; by its own security page your content is stored in an AWS database, with no mainland-China region and no in-country build. So that employee data and content sit offshore: a PIPL cross-border transfer (Articles 38–40), an Article 24 automated-decision door because Guru profiles your China employees, an internal-content and important-data residency question, a Cybersecurity Law storage duty for a CIIO or high-volume handler, and an ICP filing for any China-facing surface Guru serves.

Guru's security page stating that customer content is stored and managed in a highly secure AWS database, with no mainland-China region named anywhere.
"Your content is stored and managed in a highly secure AWS database, separated and protected from other client content" — Guru's security page names only AWS as its host and offers no mainland-China region anywhere. Source: Guru Security

Guru in China at a glance

What decides itIn Guru's own terms — and China's law
What Guru holdsYour internal company content — cards, playbooks, collateral and answers your teams author and verify — plus your China workforce's employee personal information: the user directory and profiles, and the engagement and usage analytics Guru builds about who reads, searches and verifies which knowledge (user- and team-level views, and a record of verification activity).
Where it runsBy Guru's own security page, content is "stored and managed in a highly secure AWS database," copied daily "to a disaster recovery site in an entirely separate region" — no mainland-China region, no in-country build. Holding your China employees' personal information there is a cross-border transfer (数据出境) governed by PIPL Articles 38–40, on top of the Articles 13/23 notice-and-consent for collecting it.
The automated-decision doorGuru does not just store employee data — it profiles it: engagement, adoption and verification analytics over who reads and verifies what. Where that profiling drives or informs a decision about an individual, it is automated decision-making under PIPL Article 24; the individual may refuse a decision made solely by automated means and ask for an explanation, and profiling must not apply unreasonable differential treatment.
ResidencyConsent is required to collect China employees' personal information; for a critical information infrastructure operator or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information generated in the mainland to be stored there — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. Internal content at volume or in a sensitive sector can raise the "important data" (重要数据) question.
Reachability is not the axisWhether Guru loads quickly in China decides nothing. The lawful lever is to keep the China employee data and internal content on an in-country, China-resident path (or a China-legal domestic alternative), handle the Article 24 profiling duty, and give any China-facing surface Guru serves a compliant, ICP-filed, in-country delivery — not to make the offshore platform reachable.

What it actually holds — your internal content and your people’s data

Guru is a knowledge and sales-enablement platform, so it concentrates two categories of data that China law treats very differently. The first is your internal company content: the cards, playbooks, product and sales collateral, onboarding material and verified answers your teams write and keep current. Some of it is confidential; some of it carries other people’s personal information — a customer named in a sales play, a contact in an account note — and at volume or in a regulated sector it can edge toward “important data” (重要数据).

The second is your China workforce’s employee personal information. Guru holds the user directory and profiles, and — because it is built to measure knowledge adoption — it continuously generates analytics about individuals: user- and team-level engagement with content, views by user, search behavior, and who verifies and maintains which cards. Guru’s own analytics describe “team- and user-level engagement” and dashboards that filter by user and group, and present this as data that can support onboarding and performance. This is ordinary personal information — not the “sensitive” category of PIPL Article 28, since Guru is not built to hold national-ID or financial-account numbers — but it is still personal information, and it is still your China employees’.

Where does all of it run? Offshore. Guru’s security page states content is “stored and managed in a highly secure AWS database,” copied “to a disaster recovery site in an entirely separate region”; it certifies to the EU-U.S. Data Privacy Framework and relies on EU standard contractual clauses for transfers, and notes that “In addition to AWS, Guru uses some third parties.” There is no mainland-China region and no China sovereign-cloud partition on offer — so for a China operation, both the content and the employee data live outside the mainland.

The doors: employee personal data, cross-border transfer, and automated decisions

Because the employee directory, profiles and usage analytics are personal information under China’s Personal Information Protection Law, running Guru for a China workforce is a cross-border transfer (数据出境) — and PIPL puts the duty on the handler, your China entity, not on Guru the processor. Articles 38–40 require notice, a separate consent distinct from any general terms, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — alongside the Articles 13 and 23 notice-and-consent and minimization duties for collecting employee data in the first place.

The distinctive door here is Article 24. Guru does not merely store employee data; it profiles it. Engagement scores, adoption dashboards, verification activity and who-read-what analytics are exactly the kind of profiling PIPL Article 24 governs: where an automated decision made with that profile has a significant effect on an individual, the person may ask for an explanation and refuse a decision made solely by automated means, and profiling may not impose unreasonable differential treatment. Scoring and ranking a China workforce also sits against China’s employee-data and workplace-monitoring norms. This is the half a reachability test never sees — the platform is watching and scoring your China employees, offshore.

Residency sits underneath both. If your organization is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information generated in the mainland to be stored there — a duty no offshore knowledge platform can meet. And internal content at volume or in a sensitive sector can raise the “important data” question, which carries its own export controls. Which doors apply, and in what combination, turns on your sector, your workforce and your role as handler.

Logging in isn’t the question — compliant in-country employee data is

Guru loads in China, so the temptation is to treat the job as done. It is not, because the exposure is not reachability — it is that your China employees’ personal information and your internal content are held and profiled on a platform with no mainland-China region. You cannot localize that by making the offshore service load faster, and moving between offshore regions only relocates the transfer rather than ending it.

The lawful shape is to keep the China employee data and internal content on an in-country footing — a China-resident processing path or a China-legal domestic alternative — send across the border only what may lawfully leave, minimize what you collect, obtain the Article 13/23 notice-and-consent, and handle any Article 24 automated-decision and profiling duty with a route for the employee that is not driven solely by automation. Any China-facing surface Guru serves — an external help center, a public knowledge base, a customer-facing microsite — is a public service in the mainland and carries an ICP filing duty with compliant, in-country delivery. That is a residency-and-delivery design, never a hidden path that ships the employee data offshore anyway. This is a risk map, not a verdict — whether your internal content is “important data”, and which duties bite, turns on your sector and workforce, so settle the specifics with counsel.

The lawful path — map, localize, deliver

Map: inventory the employee personal information Guru holds for your China workforce — the directory, the profiles, and the engagement, usage and verification analytics that profile individuals — and the internal content alongside it; record where each is processed and stored (the offshore region), whether the platform profiles individuals in a way that engages Article 24, the consent and residency basis, and whether any content reaches “important data”.

Localize / govern: keep the China employee data and internal content in-country — a China-resident path or a China-legal domestic alternative, with data minimization; obtain the Article 13/23 notice-and-consent; and discharge the Article 24 duty, including a means for employees to decline a decision made solely by automated profiling. Localize means keeping the data on an in-country path — never a tunnel that ships it offshore anyway.

Deliver: any China-facing surface Guru serves is a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery — the 21YunBox Optimizer, set in front of the stack you already run, with no rebuild and no re-platform. The result is a knowledge and enablement stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth. 21YunBox is a compliance overlay and partner, not a competitor to Guru.

Get a compliance assessment →

Frequently Asked Questions

Does Guru have a mainland-China region we can host our China workforce's data in?
No. By Guru's own security page, content is stored and managed in an AWS database with a daily disaster-recovery copy in a separate region, and Guru names no mainland-China region; it certifies to the EU-U.S. Data Privacy Framework and uses EU standard contractual clauses, which confirm a US-operated, offshore footing. Holding your China employees' directory, profiles and usage analytics there is a PIPL cross-border transfer, so the lawful path is to keep that data on an in-country, China-resident path (or a China-legal domestic alternative) with the required notice and consent — not to relocate it between offshore regions.
Guru's analytics just show who reads and verifies content — is that really a PIPL Article 24 issue?
It can be. Engagement, adoption and verification analytics profile individual employees, and when that profiling drives or informs a decision about a person — a readiness or engagement ranking, a nudge, an onboarding or performance signal — PIPL Article 24 treats it as automated decision-making: the individual may ask for an explanation and refuse a decision made solely by automated means, and profiling must not apply unreasonable differential treatment. Analytics over a China workforce also sit against China's employee-data and monitoring norms. This is the exposure a pure reachability review misses — the platform is scoring your China employees, offshore.
Can 21YunBox help make our Guru setup work in China?
Yes — as a compliance overlay in front of the stack you already run, with no rebuild. We map the employee personal information and internal content Guru holds and where each is processed, keep the China employee data and content on an in-country, China-resident path (or a China-legal domestic alternative) with the Article 13/23 notice-and-consent, handle any Article 24 automated-decision and profiling duty, and stand up ICP-filed, in-country delivery (the 21YunBox Optimizer) for any China-facing surface Guru serves. 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO GURU

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.