Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Icertis Work in China? Contract Data, PIPL & Data Residency

Icertis Contract Intelligence is hosted entirely on Microsoft Azure, and Icertis's own privacy statement says personal data may be 'stored anywhere in the world' — the United States, India or other third countries, never a mainland-China region. So your third-party contracts and the counterparty PII inside them come to rest offshore, a PIPL cross-border transfer. A compliance-first look at where your contract data is allowed to live.

Does Icertis work in China?

Yes — Icertis loads from China, but that is the easy half: its contract repository and the counterparty PII inside it come to rest offshore, which is a PIPL cross-border transfer, not a speed problem.

Icertis Contract Intelligence is hosted entirely on Microsoft Azure, and Icertis's own privacy statement says the personal information it processes may be 'stored anywhere in the world, including but not limited to, the United States, India or other third countries' — none in mainland China — while its transfers rest on EU standard contractual clauses, a European mechanism rather than one of China's PIPL routes. A repository of executed contracts carries counterparty and signatory identities, contact details and account terms — personal information, some of it PIPL Article 28 sensitive — so moving contracts collected in or relating to China to an offshore Azure region needs notice, a separate consent and a transfer mechanism (Articles 38–40), and a CIIO or large-volume handler owes in-country storage (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). This is a risk map, not a verdict — settle specifics with counsel.

What Icertis's own documentation says about China

FactPrimary source
Icertis's Privacy Statement states that 'All personal information processed by us may be transferred, processed, and stored anywhere in the world, including but not limited to, the United States, India or other third countries,' and that 'Transfer of personal information to third countries is based on the appropriate standard contractual clauses issued by the European Commission.' It names no mainland-China region, and EU standard contractual clauses are not a PIPL transfer mechanism. Icertis Privacy Statement — International Data Transfers (last updated November 25, 2025)
The Icertis Contract Intelligence (ICI) platform is 'hosted entirely on Azure.' Microsoft Azure's global regions do not include mainland China; standard Azure China is a physically separate sovereign cloud operated by 21Vianet that a customer must be explicitly provisioned into, and Icertis's public materials describe a global-Azure footprint rather than that cloud. So contracts loaded into ICI come to rest in an offshore Azure region. Microsoft Azure Blog — 'Icertis boosts performance over 80 percent and lowers costs on Azure SQL' (February 8, 2021)
Sending personal information collected in China to an offshore region is a cross-border transfer under China's PIPL: the handler must give notice, obtain a separate consent for the export, and clear one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). Financial-account data in contracts is sensitive personal information under Article 28, carrying heightened duties. Personal Information Protection Law (PIPL), Articles 28 and 38–40
A critical information infrastructure operator or a large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty an offshore Azure region cannot meet. A mainland-served surface (a supplier or counterparty portal, an intake or signing page) additionally requires an ICP filing (State Council Order No. 292; MIIT Order No. 33). Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40; State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a legal, procurement or compliance team serving mainland China, the deciding question about Icertis is not whether the contract workspace opens — it usually does. It is where the agreements inside it, and the people named in them, are allowed to come to rest. Icertis Contract Intelligence (ICI) is a cloud platform hosted entirely on Microsoft Azure, and it holds some of the most sensitive paper a company owns: the full body of its third-party contracts, together with the counterparties and signatories named in them — identities, titles, contact details and signatures — and the commercial, payment and obligation terms written into every clause. Those details are personal information, and a repository of executed contracts can also carry financial-account and other sensitive data. Icertis’s own privacy statement says the personal information it processes may be “stored anywhere in the world,” naming the United States and India — not one mainland-China region among them. Reaching the dashboard is the easy half; where the contract data lands is the exposure.

Icertis Privacy Statement, International Data Transfers section, stating that all personal information processed by Icertis may be transferred, processed, and stored anywhere in the world, including the United States, India or other third countries, with no mainland-China region
Icertis's own Privacy Statement: “All personal information processed by us may be transferred, processed, and stored anywhere in the world, including but not limited to, the United States, India or other third countries.” Its cross-border transfers rest on EU standard contractual clauses — a European mechanism, not one of China's PIPL routes — and no mainland-China region appears. Source: icertis.com/information/icertis-privacy-statement

Icertis in China at a glance

What decides it In Icertis's own terms — and China's law
Where the contract data lives ICI is "hosted entirely on Azure," and Icertis's privacy statement says the personal information it processes "may be transferred, processed, and stored anywhere in the world, including but not limited to, the United States, India or other third countries." None is in mainland China; standard Azure China (operated by 21Vianet) is a separate sovereign cloud a tenant would have to be explicitly provisioned into.
What it holds, and why it is personal A repository of executed third-party contracts plus the counterparties and signatories named in them — identities, titles, contact details and signatures — and the payment and account terms inside the clauses. Those details are personal information; financial-account data is PIPL Article 28 sensitive personal information.
Your China counterparties' and employees' data Contracts and counterparty PII collected in or relating to the mainland, then stored in an offshore Azure region, are a cross-border transfer PIPL governs — notice, a separate consent, and one transfer mechanism (Articles 38–40).
In-country storage duty A CIIO or large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty ICI's offshore Azure footprint cannot meet.
Is it reachable? Treat reachability as the delivery half, not the question. The exposure is where the contracts are stored, not whether the workspace loads — and any China-facing surface (a supplier or counterparty portal, an intake or signing page) also needs an ICP filing.

No mainland region, so your contracts leave the country

Icertis Contract Intelligence is software-as-a-service, hosted — in Microsoft’s own words — “entirely on Azure.” That makes where your contracts rest a function of the Azure region your tenant is provisioned into, and Icertis’s public materials describe a global-Azure footprint, not a mainland-China one. Its privacy statement is explicit about the personal information it handles as a controller: that data “may be transferred, processed, and stored anywhere in the world, including but not limited to, the United States, India or other third countries.” The contract content you load is treated separately — the statement notes it “does not apply to personal information that the Platform processes on behalf of an Icertis subscriber (‘Subscriber Data’),” which “the Platform will process … only in accordance with the documented instructions of the Icertis’ subscriber as set forth in the applicable contract.” Either way, the destination sits outside the mainland: standard Azure China is a physically separate sovereign cloud operated by 21Vianet, with its own accounts and portal, that a customer must be explicitly provisioned into — and nothing public indicates Icertis offers it. For a CIIO or a large-volume handler, personal information collected in China must be stored inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment that took effect on January 1, 2026, with the substance unchanged)) — a floor an offshore Azure region cannot satisfy, and the point at which any mainland-served surface also turns on an ICP filing (State Council Order No. 292; MIIT Order No. 33).

A contract repository is personal information — and some of it is sensitive

A contract lifecycle platform is not a filing cabinet of anonymous documents. Every executed agreement carries the counterparty’s and signatory’s identity, title, contact details and signature; the negotiation history records who said what and when; and the clauses themselves hold pricing, bank and account terms, and the obligations each side owes. Those identifiers are personal information, and bank-account and payment details are Article 28 sensitive personal information under China’s law — with employment, settlement or dispute contracts able to sweep in more sensitive content still. Because that personal information is collected in or relates to the mainland and comes to rest in an offshore Azure region, the Personal Information Protection Law treats the move as a cross-border transfer: the handler — you, the Icertis subscriber, not Icertis — must give notice, obtain a separate consent for the export, and clear one lawful mechanism, whether the CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Icertis bases its own transfers on “the appropriate standard contractual clauses issued by the European Commission” — a European route that does nothing to satisfy China’s PIPL mechanisms.

Narrowing the exposure doesn’t close the door

Icertis gives you real levers to shrink what crosses the border — but none of them moves the border. Because ICI is SaaS on Azure, there is no customer-run, on-premises mainland deployment to fall back on; what you can do is pin your tenant to a particular Azure region, mask or redact fields, and minimize what you load. Each of those changes what crosses and how much, not that it crosses: region choice is a pick among offshore Azure regions, every one of which is still offshore of China, so data residency is unaffected and the cross-border transfer still happens. Scrubbing a sensitive field narrows the Article 28 exposure inside a given contract; it does not keep the contract in the mainland. This is a risk map, not a verdict: whether you owe a transfer mechanism, a separate consent, in-country storage, an ICP filing, or some combination turns on what your contracts actually contain, how much of it is personal, your role as handler, and whose data it is — worth settling with counsel before you route mainland contracts into an offshore tenant.

The lawful path — map, localize, deliver

You do not have to pull Icertis out to run it compliantly for mainland China. 21YunBox is a compliant overlay, not a migration — and a partner to the platform you already run, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads the PIPL cross-border, data-residency, sensitive-PI and ICP obligations against your entity, your contract volumes, and whose data those contracts carry — so your exposure is written down before anything is rewired.

Localize. Where contracts or counterparty records must stay on mainland soil, we stand up consented, in-country processing and storage for them, so the data that has to remain in China remains in China — while the Icertis your team already uses stays exactly where it runs.

Deliver. For any China-facing surface — a supplier or counterparty portal, an intake form, a signing or approval page — the 21YunBox Optimizer provides ICP-filed, in-country delivery in front of the stack you already run, with no rebuild and no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.

The goal is plain: your contract operations run legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Icertis have a data center or region in mainland China?
No mainland-China region appears in Icertis's public materials. Icertis Contract Intelligence is hosted entirely on Microsoft Azure, and Icertis's privacy statement says the personal information it processes may be stored 'anywhere in the world,' naming the United States and India. Standard Azure China is a physically separate sovereign cloud operated by 21Vianet, with its own accounts and portal, that a customer would have to be explicitly provisioned into — nothing public indicates Icertis offers it. So the contracts and counterparty data you load come to rest in an offshore Azure region.
Is it a compliance problem that our contracts and counterparty data leave China in Icertis?
Treat it as a risk to assess with counsel, not a flat yes or no. A contract repository holds counterparty and signatory identities, contact details and signatures — personal information — plus account and payment terms that can be PIPL Article 28 sensitive personal information. Moving data collected in or relating to China to an offshore Azure region is a cross-border transfer under PIPL, requiring notice, a separate consent and a transfer mechanism, and a CIIO or large-volume handler must also store that data in the mainland. Icertis bases its own transfers on EU standard contractual clauses, which do not satisfy China's PIPL mechanisms.
Can 21YunBox make our Icertis setup compliant for China?
Yes. Our China compliance team maps your PIPL cross-border and data-residency exposure for your entity, your contract volumes and whose data those contracts carry, then stands up consented, in-country storage for the records that must stay on mainland soil and ICP-filed, in-country delivery for any China-facing surface — a supplier or counterparty portal, an intake or signing page — in front of the Icertis you already run. We do not migrate Icertis; we add the lawful in-country layer the hosted platform cannot provide. 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO ICERTIS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.