Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does IFS Work in China? PIPL Cross-Border, Data Residency & Employee-Data Compliance

IFS's managed cloud is hosted on Microsoft Azure and offers no mainland-China region, so your China operation's financial records and employee personal information (payroll, HR — sensitive PI) rest offshore — a PIPL cross-border transfer and a data-localization problem. But IFS Cloud also deploys on-premises or self-managed in-country, a genuine residency lever. A compliance-first look at the residency, employee-data and cross-border exposure.

Does IFS work in China?

Your China operation's financial records and employee personal information (payroll, HR — sensitive PI) sit on IFS's offshore, Azure-hosted managed cloud with no mainland-China region, and the lever is deploying IFS Cloud on-premises or self-managed in-country — not making the offshore ERP reachable.

IFS Cloud holds your statutory financial ledgers, your employees' payroll, HR and national-ID data (sensitive personal information under PIPL Article 28), and your supplier, customer and asset records. On IFS's managed cloud, hosted on Microsoft Azure with no mainland-China region, those records rest offshore — so running a China operation on it is a PIPL cross-border transfer (Articles 38–40) and, for a CIIO or high-volume handler, a data-localization problem. Because IFS Cloud can equally be deployed on-premises or self-managed on infrastructure you control, the lawful lever is to keep the financial and employee data in-country on that deployment and ICP-file any China-facing surface — not to make the offshore ERP reachable.

Which obligations bite depends on your entity, data volumes and role, so treat this as a risk map to settle with counsel — then our China team can map your exposure →

What IFS's own documentation says about China

FactPrimary source
IFS Cloud is not cloud-only — it deploys on-premises or in the cloud. On IFS's own deployment-choice page: “Choose IFS Cloud and deploy on prem or in the cloud – with all the cloud innovation and functionality.” Because it can run on infrastructure you control, including in-country, IFS Cloud can keep your China financial and employee data on the mainland — the residency lever a cloud-only ERP lacks. IFS, “You have a choice” (ifs.com), retrieved 2026-10-10
IFS Cloud spans ERP, Enterprise Asset Management and Field Service Management, and its managed cloud runs on Microsoft Azure. One platform for asset- and service-intensive industries holds your statutory financial ledgers, employee payroll and HR records, and supplier, customer and asset data; IFS's own managed cloud is hosted on Microsoft Azure, whose footprint offers no mainland-China region, so on that path your China data rests offshore. IFS — IFS Cloud overview and Trust Center (ifs.com), retrieved 2026-10-10
Financial and employee data in an offshore ERP is a PIPL cross-border transfer — and payroll and national-ID data is sensitive personal information. Holding China-collected personal information on infrastructure outside the mainland triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Employee payroll, bank and national-ID data is sensitive PI under Article 28, requiring a separate consent (Article 29) and a prior impact assessment. Personal Information Protection Law of the PRC, Articles 28–29 and 38–40 (21YunBox gov-doc translation), retrieved 2026-10-10
For a CIIO or high-volume handler, China-generated personal information must be stored in China. The Cybersecurity Law's Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires personal information and important data collected or generated in China to be stored on the mainland — a duty IFS's offshore managed cloud cannot meet, but an on-premises or self-managed in-country IFS deployment can. Cybersecurity Law of the PRC, Article 39 (formerly Article 37) (21YunBox gov-doc translation), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a company running IFS in mainland China, the instinct is to ask whether staff can even open IFS Cloud from a Shanghai or Chengdu plant — and on the wire they can: it is browser-based, reached over the public internet, and not blocked at the border. So reachability is not where the China decision is made. What settles it is data residency — where the financial records, employee personal information and asset data your China operation enters into IFS come to rest, and whether the way you deploy IFS can keep them in the country. That is what makes IFS different from a cloud-only ERP: IFS Cloud runs either on IFS’s own managed cloud, hosted on Microsoft Azure with no mainland-China region — where the data sits offshore — or deployed on-premises or self-managed on infrastructure you control, including in-country, which keeps the financial and employee data on the mainland. The first path is a cross-border transfer (数据出境) of personal information under PIPL, with payroll and national-ID data treated as sensitive personal information under Article 28; the second is the residency lever.

IFS's own 'You have a choice' page stating that customers can choose IFS Cloud and deploy on premises or in the cloud, with the same cloud innovation and functionality either way — evidence that IFS Cloud supports a customer-controlled, in-country deployment, not only IFS's Azure-hosted managed cloud
“Choose IFS Cloud and deploy on prem or in the cloud – with all the cloud innovation and functionality.” Because IFS Cloud can run on infrastructure you control — including in-country — rather than only on IFS's Azure-hosted managed cloud, keeping your China operation's financial and employee data on the mainland is actually possible. Source: IFS — You have a choice

IFS in China at a glance

What decides it In IFS's own terms — and China's law
What it holds IFS Cloud is one platform spanning ERP (finance, supply chain, projects), Enterprise Asset Management and Field Service Management for asset- and service-intensive industries. For a China entity it holds the statutory financial ledgers, the personal information of employees (payroll, HR and national-ID / social-security data), suppliers and customers, and detailed asset and operational records.
Where it runs Two ways. On IFS's managed cloud it is hosted on Microsoft Azure, whose footprint offers no mainland-China region, so the data rests offshore. Alternatively it is deployed on-premises or self-managed on infrastructure you choose — which can be in-country. Running a China operation on the offshore managed path is a cross-border transfer (数据出境) under PIPL Articles 38–40, with your China entity as the handler.
The deployment lever Because IFS Cloud can be deployed on-premises or self-managed on infrastructure you control, an in-country deployment keeps the financial and employee data on the mainland — the strong form of the fix. A cloud-only ERP with no mainland-China region cannot do this; IFS can. This lever, not reachability, is what decides the China question for IFS.
Sensitive employee PI & residency Payroll, bank and national-ID data is sensitive personal information under PIPL Article 28 — separate consent (Article 29) and a prior impact assessment, and its cross-border transfer is heavily scrutinized. For a critical information infrastructure operator or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information generated in China to be stored in China — a duty an offshore region cannot meet.
What actually decides it Not reachability — IFS Cloud opens from the mainland. The decision is residency: keep the China financial and employee data in-country via an on-premises, self-managed or onshore deployment, minimize and protect the sensitive employee PI, and deliver any China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never moves personal information across the border by stealth.

What you actually hold — financials, employee data, and operational records

IFS Cloud is not an abstraction; it is the running record of an asset- and service-intensive business. On the ERP side that means the general ledger, payables and receivables, procurement and project accounting; on the Enterprise Asset Management side, asset registers, maintenance history and work orders; on the Field Service Management side, the records of jobs, parts and the technicians who perform them. For a China operation, that record is thick with personal information: employee payroll, HR files and national-ID or social-security numbers — sensitive personal information — alongside the contact and identity details of suppliers, customers and approvers.

Where that data lives depends on how you deploy. On IFS’s own managed cloud, the software is hosted on Microsoft Azure, and your tenant sits in whichever Azure region it was provisioned in; that footprint offers no mainland-China region, so a managed-cloud instance serving your China entity keeps its financial and personal records offshore. The alternative is the one a cloud-only ERP does not have: IFS Cloud can also be deployed on-premises or self-managed on infrastructure you choose — a private or sovereign-hosted environment, including one physically in the mainland. The functionality is the same; what changes is where the data sits. That single choice — managed cloud offshore, or an in-country deployment you control — is the hinge the whole China question turns on.

The doors: cross-border data, sensitive employee PI, and in-country storage

On the managed-cloud path, the financial and personal records your China operation posts into IFS come to rest in an offshore Azure region, and a separate body of law decides whether they were allowed to go there. The employee, supplier and customer information inside an ERP is personal information under China’s Personal Information Protection Law, so loading it into an IFS instance hosted outside the mainland is a cross-border transfer (数据出境). PIPL puts the duty on the handler — your China entity, not IFS the processor: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Employee data raises the bar. Payroll, bank and national-ID or social-security numbers are sensitive personal information under Article 28, which calls for a separate, specific consent (Article 29) and a prior personal information protection impact assessment before you process it — and the cross-border transfer of sensitive employee data is among the most heavily scrutinized. At volume, or where consolidated financial or operational data is treated as “important data,” a CAC data-export security assessment may apply before anything leaves. And on residency: if your organization is a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires personal information generated in China to be stored in China — a duty IFS’s offshore managed cloud cannot satisfy. Which of these bite your deployment turns on your sector, your data volumes and your role under Chinese law.

Logging in isn’t the question — a compliant in-country ERP is

Because IFS can be reached from the mainland, the temptation is to treat the China question as solved once people can log in — or to force a smoother connection to an offshore instance. Neither is the point, and 21YunBox neither uses nor suggests any network workaround of that kind. The decision is residency: where your China operation’s financial ledgers and employee data are allowed to sit, and how to keep any China-facing screen delivering lawfully from inside the mainland.

For IFS specifically, the lawful answer is the one a cloud-only ERP cannot offer. Deploy IFS Cloud on-premises or self-managed on in-country infrastructure you control, and the statutory financial records and the employee payroll, HR and national-ID data stay on the mainland by design — the strong form of the residency fix. Minimize and protect the sensitive employee fields, keep the consent and transfer basis documented for anything that does leave for group consolidation, and treat any China-facing surface IFS powers — a web ERP portal, an employee self-service page, a supplier or customer portal — as a public service in the mainland that carries an ICP filing (备案) duty and needs compliant, in-country delivery. Localizing means keeping the data on an in-country path — never shipping it offshore and reaching back for it.

None of this is a verdict that IFS is “blocked” or “illegal.” It is a risk map: whether you owe a separate consent, a transfer mechanism, an impact assessment, in-country storage, a data-export assessment, an ICP filing, or some combination depends on your entity, your data volumes, your role as handler and who your users are — settle the specifics with counsel before your China operation depends on them.

The lawful path — map, localize, deliver

There is a compliant way to run IFS for a China operation, and it has a shape.

First, map: our China team inventories what your IFS system holds and where it runs — the financial ledgers, the employee payroll, HR and national-ID data (sensitive personal information), the supplier, customer and asset records; which of them your China entity must keep in the country and what may lawfully leave; whether you are on IFS’s Azure-hosted managed cloud or an on-premises or self-managed deployment; and where your consent, impact-assessment and transfer basis stand. We build the technical picture; the legal conclusions are settled with counsel.

Then localize: we help you put the China financial and employee data on an in-country footing — deploying IFS Cloud on-premises or self-managed on mainland infrastructure where that is the right fit, or a China-resident instance where it is — so the records your mainland entity is obliged to keep in the country stop leaving it by default, with the sensitive employee fields minimized and protected, while IFS stays your global system of record for everywhere else. Localizing keeps the data on an in-country path; it never moves personal information out of China by stealth.

Then deliver: the China-facing access to that stack — the screens your mainland finance, maintenance, field-service and HR users open, and any supplier or customer portal — needs compliant, in-country delivery, and a public-facing service in the mainland carries an ICP filing (备案) duty. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform, so your China users reach the service reliably on ICP-filed infrastructure. The result is an ERP footprint that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind: we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and act as a compliance partner to the stack you already run — not a replacement for IFS.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does IFS work in China?
IFS Cloud opens from the mainland — it is browser-based and not blocked at the border, so reachability is not the obstacle. The real question is data residency: where the financial records, employee personal information and asset data your China operation enters into IFS come to rest, and whether your deployment can keep them in the country. On IFS's managed cloud, hosted on Microsoft Azure with no mainland-China region, that data sits offshore — a cross-border transfer under PIPL. But because IFS Cloud can also be deployed on-premises or self-managed on infrastructure you control, including in-country, you can keep the financial and employee data on the mainland. Treat the specifics as a risk to confirm with counsel.
Can IFS Cloud be hosted in mainland China?
Not on IFS's own managed cloud — its Azure-hosted footprint offers no mainland-China region, so a managed-cloud tenant's data rests offshore. But IFS Cloud is not cloud-only: IFS's own materials say you can “deploy on prem or in the cloud,” and the on-premises / self-managed option can run on in-country infrastructure you control. That is the residency lever — deploy IFS Cloud in-country and the statutory financial ledgers and the employee payroll, HR and national-ID data stay on the mainland. Any China-facing surface still needs compliant, ICP-filed, in-country delivery, which 21YunBox provides in front of the stack you already run.
Is employee payroll data in IFS a China compliance issue?
Yes. Payroll, bank and national-ID or social-security data is sensitive personal information under PIPL Article 28, which calls for a separate, specific consent (Article 29) and a prior personal information protection impact assessment, and its cross-border transfer is heavily scrutinized. If that employee data is held in an offshore IFS managed cloud, moving it there is a cross-border transfer under PIPL Articles 38–40, and for a CIIO or high-volume handler the Cybersecurity Law's Article 39 (formerly Article 37) requires China-generated personal information to be stored in China. Minimizing the sensitive fields and keeping the employee data on an in-country IFS deployment is the lawful path — confirm your exact duties with counsel.

ARTICLES RELATED TO IFS

CATEGORIES

ERP

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.