Does Ivalua Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules
Ivalua is a source-to-pay procurement platform run as a managed, multi-instance SaaS with no mainland-China region, so your China operation's supplier master data, supplier and buyer contacts, contracts and spend data sit offshore — a PIPL cross-border transfer — while consolidated sourcing and supply-network data can be 'important data' requiring a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure, and the lawful in-country path.
Does Ivalua work in China?
Running Ivalua for a China operation is a data-residency question, not a speed one: its supplier master data, contacts, contracts and spend sit on an offshore cloud with no mainland-China region — a PIPL cross-border transfer — and consolidated sourcing and supply-network data can be "important data" (重要数据) that needs a CAC data-export security assessment before it leaves.
Ivalua is a managed, multi-instance source-to-pay SaaS that holds your supplier and vendor master data, the personal information of supplier and buyer contacts, your contracts, and your spend and sourcing data — stored in its offshore regions (the US, Europe and Asia-Pacific), none in mainland China. Holding a China operation's records there is a PIPL cross-border transfer of personal information, and the strategic supply-chain data itself can trigger a mandatory CAC data-export security assessment regardless of any personal information. The lawful lever is to keep the supplier and supply-chain data in-country — a dedicated, in-country data path, data classification and minimization — handle any important data, and ICP-file any China-facing supplier surface, not to make the offshore platform reachable.
Whether your supply-chain data is "important data" turns on your sector and the applicable catalogs — a risk map to settle with counsel, not a verdict. Our China team can map your exposure →
What Ivalua's own documentation says about China
| Fact | Primary source |
|---|---|
| Ivalua runs as a managed, multi-instance SaaS with no mainland-China region. Ivalua's own technology page describes a "multi-instance SaaS architecture" with AES-256 encryption and ISO 27001, SOC 2 and TISAX certifications; its hosting footprint spans the United States, Europe and Asia-Pacific (including an IRAP-assessed environment in Australia announced December 2025) — none in mainland China. So a China operation's supplier master data and contacts are held offshore. | Ivalua — Technology (platform & security), retrieved 2026-10-11 |
| Ivalua transfers personal data across borders by its own account. Its privacy policy states that "Ivalua operates at a global scale and may transfer Personal Data to (or access Personal Data from) countries outside" the EEA, UK or Switzerland, relying on Standard Contractual Clauses, and that its website is "provided and hosted in the United States." For a China entity, the supplier and buyer contacts it holds are personal information moving offshore. | Ivalua — Privacy Policy, retrieved 2026-10-11 |
| Supply-chain data can be "important data" needing a CAC assessment before it leaves. Beyond the PIPL Articles 38–40 cross-border transfer that supplier personal information triggers, consolidated sourcing, spend and supplier-network data can be classified as "important data" (重要数据) under the Data Security Law in strategic sectors — and transferring important data abroad requires a mandatory CAC data-export security assessment before anything leaves, regardless of whether personal information is involved. | 21YunBox — China data-export security assessment (CAC); cross-border data transfers under PIPL, retrieved 2026-10-11 |
| A CIIO or high-volume handler owes an in-country storage duty. Personal information collected in China must be stored in China for a critical information infrastructure operator or large-volume handler — Cybersecurity Law Article 39 (formerly Article 37), renumbered by the 2025 amendment in force January 1, 2026 with its substance unchanged, read with PIPL Article 40. An offshore Ivalua region cannot meet it; switching among offshore regions only relocates the transfer. | 21YunBox — China's Cybersecurity Law (data localization, Article 39), retrieved 2026-10-11 |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a company running Ivalua in mainland China, the instinct is to ask whether the procurement team can open it from Shanghai — and they can; it is browser-based source-to-pay software, not blocked at the border. So reachability is not the China decision. What settles it is residency: where the supplier master data, the supplier and buyer contacts, and the contract, spend and sourcing data your China operation enters come to rest — and whether any of it is “important data” that cannot lawfully leave. Ivalua is a source-to-pay platform — sourcing, supplier management, contracts, procure-to-pay and spend analytics — run as a managed, multi-instance SaaS across offshore regions, with no mainland-China region, so that data sits abroad. That opens several doors at once: a PIPL cross-border transfer of supplier personal information (Articles 38–40); the Data Security Law’s “important data” (重要数据) question, which can force a CAC data-export security assessment before the supply-chain data leaves; an in-country storage duty for a critical information infrastructure operator or high-volume handler; and an ICP filing for any China-facing supplier surface.
Ivalua in China at a glance
| What decides it | In Ivalua's own terms — and China's law |
|---|---|
| What it holds | Ivalua is a system of record for procurement. For a China entity that means supplier and vendor master data; the names, emails and phone numbers of supplier and buyer contacts and approvers (personal information); signed contracts; and spend, sourcing and supplier-network data — the commercial map of who you buy from and on what terms. |
| Where it runs | Offshore. Ivalua runs as a managed, “multi-instance SaaS architecture” across its global regions — the United States, Europe and Asia-Pacific — with no mainland-China region. So the supplier records and contacts your China operation enters rest outside the mainland, and loading them there is a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40). |
| The important-data door | The distinctive half. Consolidated sourcing, spend and supplier-network data can be classified as “important data” (重要数据) under the Data Security Law — especially in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy, food and logistics. Transferring important data abroad requires a mandatory CAC data-export security assessment before anything leaves, regardless of whether any personal information is involved. |
| Supplier PII & residency | Supplier, buyer and employee contacts are personal information: PIPL Articles 13 and 23 require a lawful basis and a separate consent for the overseas transfer. For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37 — the data-localization article was renumbered from 37 to 39 by the 2025 Cybersecurity Law amendment in force January 1, 2026, its substance unchanged) sets an in-country storage duty an offshore region cannot meet. |
| Reachability is not the axis | Ivalua opens from the mainland over the browser; cross-border access to an offshore instance can be inconsistent, but that is operational, not the decision. Because Ivalua runs as a multi-instance SaaS and is built for deployment flexibility, a dedicated, in-country data path is more attainable than with a pure multi-tenant cloud — the lever is to keep the China supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing supplier surface. |
What you actually hold — supplier data, spend, and the supply chain
Ivalua does not hold an abstraction; it holds the running record of how you buy. As a unified source-to-pay platform it carries sourcing events and bids, supplier management and onboarding, contracts, procure-to-pay transactions, and spend analytics — and underneath all of it, a supplier and vendor master that is the spine of the system. For a China operation, that master is dense with personal information: the names, work emails, phone numbers and bank details of supplier contacts, buyers and approvers, each one a data subject whose information Chinese law protects.
Around that PII sits the commercial record — what you source, from whom, on what terms, at what price, and in what volumes. Aggregated across a category or a region, that sourcing, spend and supplier-network data is not just contractual housekeeping: it is a map of your supply chain. Ivalua’s own technology page describes the platform as a “multi-instance SaaS architecture” with AES-256 encryption and certifications including ISO 27001, SOC 2 and TISAX; its published hosting footprint spans the United States, Europe and Asia-Pacific — including an IRAP-assessed environment in Australia announced in December 2025 — with no region in mainland China. A multi-instance model (each customer a dedicated instance) and Ivalua’s recognized deployment flexibility make a dedicated, in-country data path more feasible than a pure multi-tenant cloud would — but out of the box, a China entity’s supplier and supply-chain data lands in one of those offshore regions.
The doors: cross-border personal data, important data, and in-country storage
Once the data is offshore, a different body of law decides whether it was allowed to go there — and for a procurement platform, more than one door opens at once.
Cross-border transfer. The supplier, buyer and employee contacts in Ivalua are personal information, and loading them into a region outside the mainland is a cross-border transfer (数据出境) under China’s Personal Information Protection Law. PIPL puts the duty on the handler — your China entity, not Ivalua the processor: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), with the Article 13/23 consent underneath it.
Important data — the distinctive half. The exposure is not only PII. Consolidated sourcing, spend and supplier-network data can be classified as “important data” (重要数据) under the Data Security Law and the national and sectoral important-data catalogs, especially in strategic sectors. Where it is, transferring it abroad requires a mandatory CAC data-export security assessment before anything leaves — regardless of whether any personal information is involved, and regardless of volume. For a supply-chain-heavy procurement platform, that is the risk competitors miss: the strategic nature of the data itself, not just the names attached to it.
In-country storage. If your organization is a critical information infrastructure operator — or moves personal information at the volumes a large procurement platform routinely reaches — personal information generated in China must be stored in China. That duty rests on PIPL Article 40 and on Cybersecurity Law Article 39 (formerly Article 37). An offshore Ivalua region cannot meet it, and switching among offshore regions only relocates the transfer; it does not end it.
Logging in isn’t the question — a compliant in-country supply chain is
Notice what is not on that list: how fast Ivalua loads from Shanghai, or how to force a smoother connection to an offshore instance. Those are operational questions, and chasing them misses the decision. The decision is whether your China operation’s supplier personal information and supply-chain data are allowed to sit where Ivalua keeps them — and how to put them somewhere they are allowed to be.
For a cloud platform with no mainland-China region, the lawful move is not to make the offshore instance reachable — it is to keep the China supplier and supply-chain data on an in-country footing. Where Ivalua’s multi-instance model and deployment flexibility allow a dedicated or in-country deployment, that is the strong form of the fix: the regulated data stays on the mainland. Where it cannot, you keep Ivalua as your global source-to-pay system and localize the China entity’s regulated data onto a China-resident path, classify and handle any important data, send offshore only what may lawfully leave, minimize the supplier and employee PII, and carry the Article 13/23 consent. Any China-facing surface Ivalua powers — a supplier portal, an SRM self-service page — is a public service in the mainland and carries an ICP filing duty, delivered compliantly and in-country.
None of this is a verdict that Ivalua is “blocked” or “illegal.” It is a risk map: whether your supply-chain data is “important data” turns on your sector and the applicable catalogs, and whether you owe separate consent, a transfer mechanism, in-country storage, a data-export assessment, an ICP filing, or some combination depends on your entity, your data volumes and your role under Chinese law — specifics to settle with counsel before your China operation depends on them.
The lawful path — map, localize, deliver
There is a compliant way to run procurement for a China operation, and it has a shape.
First, map: our China team inventories what your Ivalua instance holds for the China entity — the supplier and vendor PII, the contracts and spend, and the sourcing and supplier-network data — where each is processed and stored (an offshore region, since Ivalua has no mainland-China region), whether any of it is “important data” (重要数据), the deployment options, and the consent, residency and assessment basis each one needs. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we help you keep the China supplier and supply-chain data in-country — a dedicated or in-country deployment where Ivalua’s multi-instance model allows it, or an in-country data path otherwise — classify the data and handle any important-data and data-export-assessment duty, and minimize and protect the supplier and employee PII with the Article 13/23 consent in place. Localizing means keeping the data on an in-country path — never moving it offshore by stealth.
Then deliver: the China-facing surfaces the platform powers — a supplier portal, an SRM self-service page — carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform, so the service runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment (CAC)
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
