Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does iManage Work in China? Data Residency, Localization & PIPL Cross-Border

iManage is the document and email system of record for law firms and corporate legal — contracts, matters, case files and filed email, often privileged and Article 28 sensitive. iManage Cloud runs on Microsoft Azure in customer-chosen regions (US, UK, EU, Canada, Australia, Switzerland, UAE), with no mainland-China region, so that content rests offshore. A compliance-first look at where your documents are allowed to rest.

Does iManage work in China?

iManage runs in China — the compliance question is where the documents and email it holds are allowed to rest, and iManage Cloud has no mainland-China region.

iManage is the document and email system of record for law firms and corporate legal: contracts, matters, case files and filed email, holding the actual content — routinely privileged and often Article 28 sensitive personal information. iManage Cloud is built on Microsoft Azure and provisioned into a customer-chosen regional data center (the US, UK, EU, Canada, Australia, Switzerland and the UAE among them), none in mainland China, so that content comes to rest offshore — a PIPL cross-border transfer, and for a CIIO or high-volume handler an in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) an offshore repository cannot meet. The lawful lever is to run the repository in-country — a self-managed iManage Work deployment on mainland infrastructure, still offered, or a licensed sovereign equivalent — not a connection back to the offshore endpoint.

This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →

What iManage's own documentation says about China

FactPrimary source
iManage Cloud is built on Microsoft Azure and provisioned into a customer-chosen regional data center — and the published footprint has no mainland-China region. iManage's newsroom describes expanding its footprint by adding "new data centres in Switzerland and the United Arab Emirates (UAE) built on Microsoft Azure," part of a global network that also spans the US, UK, EU, Canada and Australia; none is in mainland China, so documents and email provisioned on iManage Cloud come to rest offshore relative to China. Azure itself runs mainland-China regions via 21Vianet, but iManage has not stood up an iManage Cloud Region on them. iManage, "iManage Addresses Data Sovereignty Needs with New EMEA Data Centres" (imanage.com), retrieved 2026-10-10
iManage still ships a self-managed, on-premises deployment alongside iManage Cloud — the in-country lever. iManage's own cloud-vs-on-premises materials compare "iManage Work 10 in the Cloud vs. On Premises" across document and email management, AI, and the Security Policy Manager, Threat Manager and Records Manager governance layer, confirming on-premises remains a supported shape you can run on mainland-China infrastructure to keep documents in-country — even as iManage pushes cloud-first. iManage, "Cloud vs. on premises feature comparison" (imanage.com), retrieved 2026-10-10
China personal information in your documents and email, stored offshore, is a PIPL cross-border transfer — and legal content is often Article 28 sensitive and privileged. Contracts, matters, case files and filed email routinely carry the personal information of people in China, frequently sensitive personal information (financial, health, government-ID) and privileged material; moving it out of the mainland triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10
A CIIO or high-volume handler owes an in-country storage duty an offshore repository cannot meet. Personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged; crossing a volume or sensitivity threshold can require a CAC data-export security assessment before anything lawfully leaves. Cybersecurity Law of the PRC, Article 39 (formerly Article 37); PIPL Article 40 — 21YunBox summary, retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a law firm, corporate legal team or professional-services firm serving mainland China, the question about iManage was never whether the software installs or whether partners and staff can reach it. They can. iManage is the document and email management system of record for the legal and professional world — it holds the contracts, legal matters, litigation and case files, deal and due-diligence rooms, board materials, and the email filed against each matter, full-text-indexed, versioned, and walled by need-to-know access controls and audit trails. It holds the actual content, not a pointer to it — material that is routinely attorney work product or otherwise privileged, and often Article 28 sensitive personal information: client financial records, the health and government-ID data that surface in disputes, HR files. iManage Cloud is a SaaS built on Microsoft Azure, provisioned into a customer-chosen regional data center — the US, UK, EU, Canada, Australia, Switzerland and the UAE among them, with no mainland-China region — while a self-managed, on-premises iManage Work deployment is still offered. So the real question is a residency one: where are your China documents allowed to come to rest?

iManage's newsroom statement that it expanded its iManage Cloud footprint with new data centres in Switzerland and the United Arab Emirates built on Microsoft Azure, part of a global network of regional data centres with no mainland-China region
iManage describes expanding its cloud footprint by adding "new data centres in Switzerland and the United Arab Emirates (UAE) built on Microsoft Azure" — one more set of regions in a global network that already spans the US, UK, EU, Canada and Australia, with no mainland-China region to select. Source: iManage — data sovereignty & EMEA data centres

iManage in China at a glance

What decides it In iManage's own terms — and China's law
Where the documents physically rest iManage Cloud is built on Microsoft Azure and provisioned into a customer-chosen regional data center. Users hitting the cloudimanage.com endpoint are routed to the nearest data center, but the regions on offer are the US, UK, EU, Canada, Australia, Switzerland and the UAE — there is no mainland-China iManage Cloud Region to select, so the documents, email, versions and metadata come to rest offshore. A self-managed, on-premises iManage Work deployment is still offered and can run on mainland infrastructure.
What it holds, and why it is personal information iManage is the system of record for documents and email: contracts, legal matters, case files, deal and due-diligence material, board papers and the email filed against each matter — full-text-indexed and versioned. This is the actual content, routinely attorney work product or otherwise privileged, and it frequently contains Article 28 sensitive personal information: client financial records, health and government-ID data surfacing in litigation, HR files. Once it identifies a person in China, it is personal information under PIPL.
Your mainland documents in the store Documents, email and metadata drawn from people and matters in China and held in an offshore iManage Cloud region are a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the firm or operator — not iManage, the processor. Privileged and sensitive content raises the stakes of getting it wrong.
In-country storage duty A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore SaaS cannot meet — mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Is it reachable? Treat reachability as the delivery half, not the question — the web client, desktop and email integrations connect. The lawful lever is to keep the repository in-country: a self-managed iManage Work deployment on mainland infrastructure, or a licensed in-country / sovereign-cloud equivalent. Any China-facing surface in front of it — the web client, the admin console — needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33).

Where the documents actually rest

iManage runs iManage Cloud as a cloud-native SaaS on Microsoft Azure, which it adopted as its global cloud platform, and provisions each customer into a regional iManage Cloud Region — a set of data centers in one jurisdiction. The footprint has grown to roughly ten global regions: the United States and the United Kingdom from the start, then the European Union, Canada, Australia, and most recently Switzerland and the United Arab Emirates, which iManage added, in its own words, as “new data centres … built on Microsoft Azure” to answer “data sovereignty” demands. Users who sign in at the cloudimanage.com endpoint are routed to the nearest data center. None of those regions is in mainland China.

The nuance matters: Azure itself operates mainland-China regions in Beijing and Shanghai, run by 21Vianet under a separate license — but iManage runs iManage Cloud on commercial Azure, not that mainland partition, and has not stood up an iManage Cloud Region there. So “nearest data center” for a Shanghai user resolves to an offshore region, and there is simply no China region to select. Point a tenant anywhere in the published footprint and the documents, email, versions, metadata and audit trails iManage holds for your China matters come to rest outside the mainland.

The deployment that can keep everything on mainland soil is the one iManage has had all along and still offers: a self-managed, on-premises iManage Work deployment, which its own cloud-vs-on-premises materials still compare feature-by-feature against the cloud — document and email management, AI, and the Security Policy Manager, Threat Manager and Records Manager governance layer. iManage is pushing cloud-first — AI features land in the cloud first, and cloud adoption is its growth story — but on-premises remains a supported, robust shape you can run on infrastructure you place inside China.

What it holds is personal information — and often privileged

iManage earns this scrutiny because of what the repository is. It is not a tool that touches one slice of data; it is the system of record that holds the documents and the email themselves — contracts, legal matters, litigation and case files, M&A and due-diligence rooms, board and committee materials, policies, and the correspondence filed against each matter — full-text-indexed (in iManage’s own description of its cloud, down to “OCR and full text indexing”), versioned, and governed by need-to-know access controls and audit trails. That content is routinely attorney work product or otherwise privileged, and it frequently carries Article 28 sensitive personal information under China’s Personal Information Protection Law: client financial records, the health and government-ID data that surface in disputes and investigations, HR files on employees in China.

So an offshore iManage Cloud region does not hold an incidental log — it holds your clients’ and employees’ most confidential files, in full, in a country other than the one whose law governs them. For a critical information infrastructure operator, and for a handler whose volumes cross the regulators’ thresholds, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore repository structurally cannot satisfy that duty, and where an export is permitted at all, crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment before anything lawfully leaves. Privileged material carries its own confidentiality exposure on top of the statutory one.

Running it on a no-China-region cloud doesn’t meet the residency duty — and what does

The honest summary is narrow and important: nothing about iManage is “blocked” in China, and the exposure is not the software. The exposure is a cloud deployment that parks your most confidential, often privileged China documents — and the personal and sensitive information inside them — in a region outside the mainland, with no in-country region to select.

Because iManage still ships a self-managed, on-premises iManage Work, the lawful lever is real and does not require leaving iManage: run the repository in-country, on mainland infrastructure, so the documents and email stay on mainland soil — or, where self-hosting is impractical, on a licensed in-country / sovereign-cloud equivalent that holds the content locally, with consented in-country storage for what must stay. Pointing a mainland iManage client back at an offshore iManage Cloud region is not localization and does not meet the storage duty; standing up the repository in-country is. You do not have to migrate off iManage to do it — you change where the content rests, not the stack your users know. Where a minimized subset may lawfully cross the border, you keep that transfer consented and backed by a transfer mechanism, while any China-facing surface in front of the repository — the web client, the admin console, the self-service portal your mainland users hit — earns its own ICP filing.

This is a risk map, not a verdict. Whether you owe in-country storage, a transfer mechanism, a separate consent, a data-export security assessment, an ICP filing, or some combination turns on your entity, your data volumes, how much of what your documents hold is personal, sensitive or privileged, and whose data it is — and it is worth settling with counsel before you decide where a single matter’s files live.

The lawful path — map, localize, deliver

You do not have to drop iManage to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner that sits alongside your stack, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information your iManage documents and email contain — the clients, the employees, the counterparties in China, and how much of it is sensitive or privileged — so the exposure is written down before anything moves.

Localize. Because the risk is where the documents rest, we keep the repository in-country — a self-managed iManage Work deployment on mainland infrastructure, or a licensed in-country / sovereign-cloud equivalent — so the contracts, matters, email and metadata China requires to stay on mainland soil do. Localize means a lawful in-country deployment of the content repository, never a tunnel back to an offshore endpoint; only the minimized, lawfully transferable subset ever crosses.

Deliver. For any China-facing surface in front of the repository — the web client, the admin console, the self-service portal your mainland users and operators hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.

The goal is plain: your iManage deployment runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is iManage available in mainland China?
Yes. iManage installs and runs, and your mainland users can reach it — the web client, desktop apps and email integrations connect. Availability is not the issue. The compliance question is a residency one: iManage holds your actual documents and email — contracts, matters, case files, often privileged and Article 28 sensitive — and on iManage Cloud those come to rest in an offshore region, because there is no mainland-China iManage Cloud Region to select. Treat reachability as the delivery half and confirm the residency specifics with counsel.
Does running iManage Cloud keep my documents in China?
No. iManage Cloud is built on Microsoft Azure and provisioned into a customer-chosen region — the US, UK, EU, Canada, Australia, Switzerland and the UAE among them — and none is in mainland China, so documents, email, versions and metadata rest offshore. Azure does operate mainland-China regions via 21Vianet, but iManage has not stood up an iManage Cloud Region there. To keep the content in-country, the lawful lever is a self-managed, on-premises iManage Work deployment on mainland infrastructure, or a licensed in-country / sovereign-cloud equivalent — not a connection back to the offshore cloud.
Is storing privileged legal documents from China matters in iManage a PIPL problem?
It can be. The contracts, case files and filed email in iManage routinely contain the personal information of people in China — frequently Article 28 sensitive information (financial, health, government-ID) and privileged material — so holding them in an offshore region is a cross-border transfer under PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism. For a critical information infrastructure operator or high-volume handler, PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) add an in-country storage duty an offshore repository cannot meet, and large or sensitive exports can require a CAC data-export security assessment. Settle the specifics with counsel.

ARTICLES RELATED TO IMANAGE

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.