Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Informatica Work in China? Data Residency, PIPL Cross-Border Transfer & IDMC Hosting

Informatica's Intelligent Data Management Cloud hosts its control plane and managed runtime in the Informatica Cloud hosting facility, with points of delivery across the Americas, EMEA and Asia-Pacific but none in mainland China. A platform that moves your whole data estate makes that a PIPL cross-border transfer — a compliance-first look at the data-residency, sensitive-PI and ICP questions.

Does Informatica work in China?

Whether you can use Informatica in China is a data-residency question, not a connectivity one. The decision does not turn on reaching the IDMC console — it turns on where the records your pipelines move are allowed to come to rest.

By Informatica's own documentation, the managed Hosted Agent runs “within the Informatica Cloud hosting facility,” and its points of delivery span the Americas, EMEA and Asia-Pacific with none in mainland China. Because a data-integration platform moves and reconciles records across your whole estate — CRM, ERP, HR, finance, logs — the personal information it carries out of China, plus the metadata and job logs IDMC keeps, is a cross-border transfer PIPL governs, and a single pipeline can carry the sensitive fields Article 28 singles out. A self-managed Secure Agent can keep the data in your own network, but the control plane still reaches the offshore SaaS — so in-country runtime is not automatic compliance.

This is a risk map, not a verdict — your duties turn on your entity, data volumes and who your users are. Our China team can map your Informatica exposure →

What Informatica's own documentation says about China

FactPrimary source
In Informatica's own words: with the Hosted Agent “you run tasks within the Informatica Cloud hosting facility,” while a Secure Agent can be installed “to run within your network or in a cloud computing services environment such as AWS, Google Cloud, Microsoft Azure, or Oracle Cloud Infrastructure.” The managed runtime and the IDMC control plane are Informatica's cloud, and a Secure Agent “enables secure communication across the firewall between your organization and IDMC” — so even a self-hosted agent keeps reporting to the offshore SaaS. Informatica IDMC Documentation — Runtime environments, retrieved 2026-10-10
Informatica's own “POD Availability and Networking” documentation lists its Asia-Pacific points of delivery as “AP East,” “AP NorthEast,” “AP SouthEast” and Australia, on AWS and Microsoft Azure. None is in mainland China — so for the managed service, China-sourced records a pipeline handles rest in an offshore region, not on the mainland. (Informatica has been part of Salesforce since November 2025; the IDMC hosting model is unchanged.) Informatica IDMC Documentation — APJ PODs (POD Availability and Networking), retrieved 2026-10-10
Because Informatica's pipelines move personal information your systems hold — customer and employee records, account and transaction data — out of China to an offshore region, PIPL governs the transfer. Articles 38–40 put the duty on you, the personal-information handler (not on Informatica the processor): give notice, obtain separate consent, and satisfy one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. A single pipeline can also move the categories Article 28 treats as sensitive, which raise the consent-and-necessity bar. PIPL (Personal Information Protection Law), Articles 28 and 38–40
For a critical information infrastructure operator or large-volume handler, personal information generated in mainland China must be stored in China (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37 — the 2025 amendment in force January 1, 2026 renumbered the data-localization article, substance unchanged). An offshore point of delivery cannot meet that duty, and any China-facing surface these pipelines feed is an internet service that also carries an ICP filing (备案) obligation. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); ICP filing (备案), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

Whether Informatica “works” in mainland China is a data-residency question long before it is a connectivity one. Informatica’s Intelligent Data Management Cloud (IDMC) — the platform behind its data integration, ETL/ELT, iPaaS, master data management, data quality and governance — exists to move and reconcile records across your whole estate: CRM, ERP, HR and payroll, databases, warehouses and the event logs it connects. Much of that payload is personal information, and a single pipeline can carry the sensitive fields PIPL singles out. So the decision does not turn on whether you can open the IDMC console from Shanghai; it turns on where those records — and the metadata and job logs the platform keeps about them — are allowed to come to rest. In its own documentation, Informatica runs the managed runtime and control plane in the Informatica Cloud hosting facility and lists no point of delivery inside mainland China. (Informatica has been part of Salesforce since November 2025; its IDMC hosting model is unchanged.)

Informatica's own IDMC documentation, the 'Runtime environments' page, stating that with the Hosted Agent you run tasks within the Informatica Cloud hosting facility, and that a Secure Agent can be installed to run within your own network or in an AWS, Google Cloud, Microsoft Azure or Oracle Cloud Infrastructure environment — naming no mainland-China hosting facility
Informatica's own IDMC documentation, under “Runtime environments”: “When you use the Hosted Agent, you run tasks within the Informatica Cloud hosting facility,” while a Secure Agent can be installed “to run within your network or in a cloud computing services environment such as AWS, Google Cloud, Microsoft Azure, or Oracle Cloud Infrastructure.” The managed runtime and the IDMC control plane sit in Informatica's cloud — no mainland-China point of delivery is offered — so keeping China data in-country rests on the self-managed agent, not the SaaS. Source: docs.informatica.com — Runtime environments

Informatica in China at a glance

What decides it In Informatica's own terms — and China's law
Where the records live Informatica runs the IDMC control plane and the managed Hosted Agent runtime in the “Informatica Cloud hosting facility,” across points of delivery in the Americas, EMEA and Asia-Pacific — its Asia-Pacific list names “AP East,” “AP NorthEast,” “AP SouthEast” and Australia. None is in mainland China. A self-managed Secure Agent can instead run “within your network” or in your own AWS, Google Cloud, Microsoft Azure or Oracle Cloud Infrastructure.
What it holds, and why it's personal information IDMC's job is to move and reconcile records between systems, so the China surface is the data in every pipeline plus the control-plane metadata and logs. That payload is personal information — names, contact details, account, order and transaction history, employee and payroll records, device and user identifiers — and because the platform spans the whole estate, a single mapping can include the categories PIPL Article 28 treats as sensitive.
Your China users' and employees' data crossing the border When a source or destination is on the mainland and the pipeline's runtime or control plane is offshore, the personal information those records carry out of China is a cross-border transfer under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. Because IDMC touches the whole estate, the exposure is unusually broad.
In-country storage duty For a critical information infrastructure operator or large-volume handler, personal information generated in China must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore point of delivery cannot meet that duty; switching PODs only relocates the transfer.
Reachability is not the axis Opening the IDMC console from inside China proves nothing about residency — a tool can load and still be unlawful to use for the data it moves. And any China-facing surface these pipelines feed is an internet service in China, so it carries an ICP filing (备案) duty on top.

No mainland region, so the records leave the country

IDMC is built as a cloud control plane plus a runtime, and China’s law reaches both. The control plane — where you design, schedule and monitor pipelines — and the managed Hosted Agent runtime run, in Informatica’s words, within the Informatica Cloud hosting facility. Its published points of delivery span the Americas, EMEA and Asia-Pacific; the Asia-Pacific list names “AP East,” “AP NorthEast,” “AP SouthEast” and Australia, and Informatica has added sovereignty-driven points of delivery in Switzerland (2026), the United Kingdom and the United Arab Emirates for customers with residency rules in those markets. Not one point of delivery sits in mainland China. So “we already run Informatica” does not carry into the country on the platform’s own terms: when a pipeline’s source or destination is on the mainland and its runtime or control plane is offshore, the records it moves leave China by design, and the control-plane metadata and job logs Informatica retains are held offshore as well.

What a pipeline carries is personal information — often sensitive

This is the part most teams underestimate. A data-management platform exists to move and reconcile records between systems — a CRM, an ERP, HR and payroll, a data warehouse, a payment or messaging service — and much of that payload is personal information: names, contact details, account and order history, employee records, device and user identifiers. Because IDMC sits across the whole estate rather than a single app, the exposure is unusually broad: one mapping can pull a table whose columns include the categories PIPL Article 28 treats as sensitive — financial accounts, national ID numbers, biometric or health data, precise location — whose export carries a higher bar of separate consent and demonstrated necessity. Under China’s Personal Information Protection Law the transfer obligation lands on you, the personal-information handler, not on Informatica the processor: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where the data is “important data,” China’s data-export security assessment (数据出境安全评估) may have to clear before anything leaves.

Narrowing the exposure doesn’t close the door

Informatica’s architecture does offer a genuine lever, and it is worth using. You can install a self-managed Secure Agent to run within your network or in a cloud computing services environment such as AWS, Google Cloud, Microsoft Azure, or Oracle Cloud Infrastructure, so the data a pipeline processes can stay on infrastructure you control inside the mainland, with only what may lawfully leave flowing out. Field-level masking, filtering and choosing where a job runs narrow what crosses the border further still. None of that, on its own, changes that a transfer happens: the Secure Agent still fetches its instructions from the IDMC control plane, and the metadata, operational logs and monitoring data that describe your China data keep reaching the Informatica Cloud hosting facility offshore — so an in-country runtime is not automatic compliance. Pointing a job at a “different region” only relocates the transfer among offshore points of delivery; it does not end it. Which obligations actually bite — a transfer mechanism, a data-export security assessment, in-country storage under Article 39 (formerly Article 37), an ICP filing, or some combination — turns on your entity, your data volumes and who your users are. This is a risk map, not a verdict: settle the specifics with your counsel before your pipelines depend on the answer.

The lawful path — map, localize, deliver

There is a compliant way to run Informatica for a China-facing business, and it has a shape. First, map: our China compliance team works through your PIPL exposure pipeline by pipeline — which flows carry personal information out of China, which touch the sensitive categories, what may lawfully leave, where a data-export security assessment or an Article 40 storage duty applies, and what your notice and consent must cover. We build the technical picture; the legal conclusions are settled with your counsel.

Then localize: we stand up consented, in-country processing and storage for the records that must stay on mainland soil — running a self-managed Secure Agent on infrastructure inside the mainland where IDMC supports it — so China data stays resident, and only what may lawfully leave flows out to the rest of your estate, with your IDMC control plane left exactly where it already serves your other markets.

Then deliver: any China-facing surface these pipelines feed — a dashboard, a customer portal, an intake form — is an internet service in China, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no second codebase. 21YunBox is a compliant overlay, not a migration, and a partner to the platforms you already license, not a competitor. 21YunBox never uses or suggests circumvention of any kind. The result is an Informatica estate that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Informatica store Chinese users' and employees' data in China?
Not on its managed service. By Informatica's own documentation, the Hosted Agent runs within the Informatica Cloud hosting facility, and its points of delivery span the Americas, EMEA and Asia-Pacific with none in mainland China. A pipeline's records therefore rest offshore unless you run a self-managed Secure Agent on infrastructure inside the mainland — and even then the control plane, metadata and logs still reach the offshore SaaS.
Is it against the law to use Informatica in China?
Not inherently. The issue is the cross-border transfer of personal information, which PIPL permits if you give notice, obtain separate consent and meet one transfer mechanism. Because an integration platform touches your whole data estate, watch for sensitive fields under Article 28 and, for a CIIO or large-volume handler, the in-country storage duty (PIPL Article 40; CSL Article 39, formerly 37). Treat it as a risk to assess with counsel, not a blanket prohibition.
Can 21YunBox make our Informatica stack compliant in China?
Yes. Our China team maps your cross-border and residency exposure for your data volumes and role, localizes the records that must stay on the mainland — running a Secure Agent in-country where IDMC supports it — and stands up the compliant, ICP-filed in-country delivery for any China-facing surface. Get in touch to work through your specific case.

ARTICLES RELATED TO INFORMATICA

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.