Does Hyland OnBase Work in China? Data Residency, Localization & PIPL Cross-Border
Hyland OnBase installs and is reachable from the mainland — the real question is where the documents it holds come to rest. Hyland Cloud runs region-by-region on AWS (US, Frankfurt, Sydney, Tokyo, São Paulo) with no mainland-China region, so the content rests offshore. A compliance-first look at residency, PIPL cross-border transfer, and the on-premises in-country lever.
Does Hyland OnBase work in China?
Whether Hyland OnBase works in China is a data-residency question, not a reachability one. OnBase installs and its clients reach the mainland fine — the exposure is legal, and it turns on where the documents it holds come to rest.
OnBase is the system of record for an organization's most sensitive content — patient and clinical records, insurance claims, account and loan files, case files, contracts and HR files — much of it Article 28 sensitive personal information and often legally privileged. Hyland delivers its hosted Content Innovation Cloud (formerly Hyland Cloud) region by region on AWS — the US, Frankfurt, Sydney, Tokyo and São Paulo — with no mainland-China region, so that content rests offshore: a PIPL cross-border transfer, and for a CIIO or high-volume handler an in-country storage duty an offshore repository cannot meet. OnBase does still ship on-premises, which is the lawful in-country lever.
This is a risk map, not a verdict — your obligations turn on your entity, your volumes and whose data the documents hold. Our China team can map your OnBase residency exposure with you →
What Hyland OnBase's own documentation says about China
| Fact | Primary source |
|---|---|
| Hyland Cloud has no mainland-China region. Hyland provisions its Content Innovation Cloud (formerly Hyland Cloud) region by region on AWS — the newest being the AWS Frankfurt Region for Europe, announced October 2025 "while meeting regional data residency requirements," alongside US, Sydney, Tokyo and São Paulo locations. None is in mainland China, so OnBase documents stored on Hyland Cloud come to rest offshore. | Hyland newsroom — Hyland expands European cloud presence (Oct 14, 2025), retrieved 2026-10-10 |
| OnBase still offers an on-premises deployment — the lawful in-country lever. Hyland's own trust center organizes its product documentation by deployment model — "Hosted," "On-premises" and "Content Innovation Cloud" — confirming on-premises is a current option. Deployed on mainland infrastructure, OnBase keeps the documents and records in-country, which a no-China-region hosted cloud cannot. Hyland's listed compliance frameworks (GDPR, CCPA, EU-US DPF, NHS DSPT) name no Chinese data-localization regime. | Hyland Trust Center (security.hyland.com), retrieved 2026-10-10 |
| Moving the documents offshore is a PIPL cross-border transfer with an in-country storage duty on top. Personal information drawn from people in China and stored on an offshore repository needs notice, a separate consent and a transfer mechanism (PIPL Articles 38–40); a CIIO or high-volume handler must additionally store mainland personal information and important data in the mainland (PIPL Article 40). OnBase content is routinely Article 28 sensitive, raising the bar further. | Personal Information Protection Law, Articles 28 and 38–40, retrieved 2026-10-10 |
| The data-localization duty lives in Cybersecurity Law Article 39 (formerly Article 37). The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged); it requires CIIOs to store in-country the personal information and important data they collect in the mainland. Any China-facing OnBase surface — web client, admin console, portal — additionally needs an ICP filing tied to a mainland hosting resource. | Cybersecurity Law Article 39 (formerly Article 37); ICP filing (State Council Order No. 292), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For an organization serving mainland China, the question about Hyland OnBase was never whether it installs or whether users can reach it. It does, and they can. OnBase is a content-services and workflow platform — in Hyland’s own words it “orchestrates the capture and governance of enterprise documents” — and the system of record for an organization’s most sensitive material: patient and clinical records, insurance claims, account and loan files, government case files, contracts and HR files. It does not touch a thin slice of data; it holds the actual content — the files themselves, versioned, with access-control lists and audit trails — content that is routinely Article 28 sensitive (health, financial, government-ID) and often legally privileged. So the real question is a residency one: where are those documents allowed to come to rest? Hyland Cloud has no mainland-China region; OnBase, however, still ships on-premises — the lawful in-country lever.
Hyland OnBase in China at a glance
| What decides it | In OnBase's own terms — and China's law |
|---|---|
| Where the documents physically rest | Hyland runs its hosted offering — the Content Innovation Cloud (formerly Hyland Cloud) — region by region on AWS: the US, the AWS Frankfurt Region for Europe, Sydney for Asia-Pacific, Tokyo, and São Paulo, a footprint Hyland put at "19 geographically diverse locations" in 2021. None is in mainland China. Point an OnBase tenant at any of them and the documents, versions, metadata and audit trails come to rest offshore. |
| What the repository holds, and why it is personal information | OnBase is the system of record: it covers a case "from documents, emails and tasks to approvals, compliance and verifications," and automates "the secure retention and destruction of your documents and records." In healthcare, insurance, finance and government that content is patient records, claims, account files and citizen records — personal information under PIPL, much of it Article 28 sensitive (health, financial, government-ID) and often legally privileged. |
| Your mainland documents in the repository | Documents, metadata and audit trails drawn from people in China and held on an offshore cloud are a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the operator — not Hyland, the processor. |
| In-country storage duty | A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore repository cannot meet — mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. |
| Is it reachable? | Treat reachability as the delivery half, not the question — the OnBase clients and portals connect. The lawful lever is that OnBase still deploys on-premises: run it on mainland infrastructure (or a licensed sovereign equivalent) so the documents stay in-country, and give any China-facing surface in front of it an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33). |
Where the documents actually rest
Hyland does not operate a region inside mainland China. It delivers its hosted offering — the Content Innovation Cloud, formerly the Hyland Cloud — on AWS, adding capacity one region at a time: the US West (Oregon) region, the AWS Frankfurt Region for Europe (announced October 2025, “while meeting regional data residency requirements”), Sydney for Asia-Pacific, Tokyo for Japan, and São Paulo for Latin America. In its own 2021 count the network reached “19 geographically diverse locations.” Not one of them is in mainland China. Select any region for your OnBase tenant and the content it holds — the files themselves, their versions, the metadata and the audit trail — comes to rest outside China.
This matters because OnBase is one of several Hyland content products (OnBase, Alfresco, Nuxeo, Perceptive Content, Saperion ECM and more), and the residency question is specific to where your OnBase repository lives. The honest counterweight is that OnBase has not gone cloud-only: Hyland still documents an on-premises deployment model alongside its hosted and Content Innovation Cloud options, so OnBase can run on infrastructure you place on mainland soil. Hyland markets the cloud first, but the on-premises product is a genuine, current lever — and it is the one that keeps the documents in-country.
What it holds is personal information — and often privileged
OnBase earns this scrutiny because of what it holds. This is not telemetry or a thin index; it is the content itself. A hospital’s OnBase holds clinical and patient records; an insurer’s holds policy, claims and medical-underwriting files; a bank’s holds account, loan and KYC files; a government agency’s holds case files and citizen records. Each of those is personal information under China’s Personal Information Protection Law the moment it identifies a person, and most of it is Article 28 sensitive personal information — health, financial and government-ID data — which carries a higher bar of specific purpose, strict necessity and separate consent. Much of the same content is legally privileged or confidential: contracts, legal matters, board materials and HR files whose confidentiality is itself a reason not to let them come to rest in the wrong jurisdiction.
So what an offshore OnBase cloud concentrates abroad is the organization’s actual record of its most sensitive dealings in China. For a critical information infrastructure operator, and for a handler whose volumes cross the regulators’ thresholds, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore repository structurally cannot satisfy that duty — the documents are, by definition, in the wrong country — and where an export is permitted at all, crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment before any of it lawfully leaves.
Running it on a no-China-region cloud doesn’t meet the residency duty — and what does
The honest summary is narrow and important: nothing about OnBase is “blocked” in China, and the exposure is not the software. The exposure is a hosted deployment that parks your mainland’s most sensitive documents and records — the contracts, the case files, the health and financial records — outside the mainland, on a cloud with no in-country region to select.
Because OnBase still ships on-premises, the lawful lever is real and does not require abandoning the product. You run OnBase in-country — on mainland infrastructure you control, or on a licensed sovereign-cloud equivalent — so the documents, versions and audit trails China requires to stay on mainland soil do. Pointing a mainland OnBase client back at an offshore Hyland Cloud tenant is not localization and does not meet the storage duty; standing the repository up in-country is. Where a minimized subset of content may lawfully cross the border, you keep that transfer consented and backed by a transfer mechanism, while any China-facing surface in front of the repository — the web client, the admin console, the self-service portal your mainland users hit — earns its own ICP filing. No rebuild and no migration to a different product are needed to put the content in the right country.
This is a risk map, not a verdict. Whether you owe in-country storage, a transfer mechanism, a separate consent, a data-export security assessment, an ICP filing, or some combination turns on your entity, your data volumes, how much of what your OnBase repository holds is personal or sensitive, and whose data it is — and it is worth settling with counsel before you decide where a single case file lives.
The lawful path — map, localize, deliver
You do not have to drop Hyland OnBase to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner that sits alongside your stack, not a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information your OnBase repository holds — the patient records, the claims files, the contracts, the HR files — so the exposure is written down before anything moves.
Localize. Because the risk is where those documents rest, we keep the repository in-country — OnBase on-premises on mainland infrastructure where you deploy it, or a licensed in-country / sovereign-cloud equivalent — so the content China requires to stay on mainland soil does. Localize means a lawful in-country deployment of the repository, never a tunnel back to an offshore endpoint; only the minimized, lawfully transferable subset ever crosses.
Deliver. For any China-facing surface in front of the repository — the OnBase web client, the admin console, the portal or self-service page your mainland users hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your Hyland OnBase deployment runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization (Article 39)
- China’s data-export security assessment measures
- How to get an ICP filing for China
