Does JAGGAER Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules
JAGGAER One is a cloud source-to-pay platform hosted on AWS in the US, EU, UK and UAE with no mainland-China region, so the supplier contacts, contracts, spend and supply-chain data your China operation enters sit offshore — a PIPL cross-border transfer, and supply-chain data can itself be “important data” needing a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure.
Does JAGGAER work in China?
Not on its own terms. JAGGAER One holds your China operation's supplier master, contracts, spend and supply-chain data on AWS in the US, EU, UK and UAE — no mainland-China region, APAC data processed in the UK — so storing it there is a PIPL cross-border transfer, and consolidated supply-chain data can itself be “important data” that needs a CAC data-export security assessment before it leaves.
JAGGAER is a source-to-pay suite — sourcing, supplier management, contracts, procure-to-pay and, for manufacturers, supply-chain collaboration — so it continuously holds supplier and buyer contacts (personal information), contracts and consolidated spend, plus supplier-network, inventory and logistics data. On an offshore cloud with no mainland-China region, putting China-collected personal information there is a PIPL cross-border transfer (Articles 38–40), while the supply-chain data itself can be “important data” under the Data Security Law that triggers a mandatory CAC data-export security assessment regardless of any PII. The lawful lever is to keep the China supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing surface — not to make the offshore platform reachable.
This is a risk map, not a verdict — whether your supply-chain data is “important data” turns on your sector, so settle the specifics with counsel. Our China team can map your exposure →
What JAGGAER's own documentation says about China
| Fact | Primary source |
|---|---|
| JAGGAER One is hosted on AWS with no mainland-China region. JAGGAER's own sub-processor list names Amazon Web Services for infrastructure (IaaS) and platform (PaaS) services, with Location of Processing in the United States, Germany, Ireland, the UK and the UAE — none in mainland China. It states that “For UK and APAC based Clients, data is processed in UK,” so a mainland-China operation is an APAC client whose supplier and supply-chain data rests in an offshore AWS region. | JAGGAER — Trust Center, Sub-Processors List (jaggaer.com), retrieved 2026-10-11 |
| JAGGAER One is a cloud source-to-pay platform holding supplier PII, contracts, spend and supply-chain data. JAGGAER describes JAGGAER One as one connected source-to-pay platform spanning sourcing, supplier management, contracts, eProcurement, invoicing and payments, with supply-chain collaboration for manufacturers — so it continuously stores supplier and buyer contacts (personal information), contracts and consolidated spend, and, where the supply-chain modules run, inventory, shipping-notice and shortage data about your China supply network. | JAGGAER — JAGGAER One platform overview (jaggaer.com), retrieved 2026-10-11 |
| Exporting “important data” requires a CAC security assessment before it leaves — regardless of PII. Under China's Data Security Law and the national and sectoral catalogs, consolidated supply-chain data — supplier-network maps, sourcing, production and logistics — can be “important data” (重要数据), and transferring it abroad triggers a mandatory CAC data-export security assessment (数据出境安全评估). Whether your data qualifies turns on your sector. | 21YunBox — Measures for the Security Assessment of Data Exports, retrieved 2026-10-11 |
| Storing China supplier PII offshore is a PIPL cross-border transfer, with an in-country storage duty for a CIIO. Supplier and employee personal information held in an offshore region is a cross-border transfer under PIPL (Articles 38–40, with a separate consent under Articles 13 and 23). A critical information infrastructure operator or high-volume handler also owes in-country storage under Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered it, substance unchanged. | 21YunBox — China Cybersecurity Law; cross-border data transfers, retrieved 2026-10-11 |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a company running sourcing, supplier management, contracts and procure-to-pay through JAGGAER for its China operation, the instinct is to ask whether the platform is quick, or even reachable, from the mainland. That is the wrong place to start. JAGGAER One is a cloud source-to-pay suite, and what decides whether you can use it in China is where the supplier master data, the buyer and supplier contacts, the contracts and the spend and supply-chain data it holds come to rest — and whether any of that information had a lawful basis to leave the country. Under China’s law that is a data-residency and cross-border question, with a second door most procurement teams miss: consolidated sourcing and supply-chain data can itself be “important data” that cannot leave without a state security assessment, regardless of whether any personal information is involved. JAGGAER settles the factual half in its own trust documentation.
JAGGAER in China at a glance
| What decides it | In JAGGAER's own terms — and China's law |
|---|---|
| What it holds | JAGGAER One is a source-to-pay suite — sourcing, supplier management, contracts, eProcurement, invoicing and payments, with supply-chain collaboration for manufacturers. It is a continuous store of your supplier master data, buyer and supplier contacts (personal information), contracts and consolidated spend, and — where you run the supply-chain modules — inventory, shipping-notice and shortage data about your China supply network. |
| Where the data sits | Offshore. JAGGAER's own sub-processor list hosts the platform on Amazon Web Services in the United States, Germany, Ireland, the UK and the UAE, and states that “For UK and APAC based Clients, data is processed in UK.” There is no mainland-China region; a mainland-China operation is an APAC client whose data rests in the UK. Putting China-collected personal information there is a cross-border transfer (数据出境) under PIPL Articles 38–40 — notice, a separate consent and one transfer mechanism. |
| The important-data door | Supplier-network maps, consolidated sourcing and spend, and — for manufacturing clients — production, inventory and logistics data can be classified as “important data” (重要数据) under the Data Security Law and China's sectoral catalogs, most readily in manufacturing, automotive, pharmaceuticals, energy, food and logistics. Exporting important data abroad requires a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves — regardless of whether any personal information is involved. Whether your data qualifies turns on your sector. |
| Supplier PII and in-country storage | Supplier and buyer contacts, approver identities and any employee data are personal information: PIPL Articles 13 and 23 require a lawful basis and, for the transfer, a separate consent, and bank or tax identifiers in the supplier master can rise to sensitive personal information with a necessity test and an impact assessment on top. If your China entity is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires that personal information generated in China be stored in China — a duty an offshore AWS region cannot meet. |
| The lawful path | Whether a buyer in Shenzhen can open a requisition screen is not the question; where the supplier and supply-chain data behind it lives is. Keep the China supplier and supply-chain data in-country — an in-country data path, data classification and minimization — handle any important-data and cross-border duties lawfully, and deliver any China-facing surface, such as a supplier portal, on ICP-filed, in-country infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind. |
What you actually hold — supplier data, spend, and the supply chain
JAGGAER One is a connected source-to-pay platform: sourcing and contract management upstream, eProcurement, invoicing and payments downstream, supplier intelligence and onboarding across the middle, and — for manufacturers — supply-chain collaboration covering inventory, advance shipping notices and shortage alerts. Everything it does produces data about the people and companies in your China supply base.
Three kinds of data matter here. First, personal information: the supplier master carries supplier and buyer contacts — names, work emails, phone numbers, sometimes bank and tax identifiers — and your approvers and procurement staff are identifiable too. Second, commercial records: contracts, sourcing events, catalogs, purchase orders, invoices and consolidated spend. Third, where you run the supply-chain modules, supply-network data: who supplies what, from where, in what volume, and with what lead times and shortages.
JAGGAER’s own trust documentation settles where this sits. Its sub-processor list hosts the platform on Amazon Web Services in the United States, Germany, Ireland, the UK and the UAE, and notes that “For UK and APAC based Clients, data is processed in UK.” There is no mainland-China region in the list, and no mainland-China entity among its affiliates — the nearest APAC footing processes in the UK. JAGGAER One is delivered as cloud software, and while JAGGAER has extended in-country AWS hosting in select markets elsewhere, it publishes no mainland-China region, so for a China operation the practical lever is an in-country data path, data classification and minimization — not a region you can switch on.
The doors: cross-border personal data, important data, and in-country storage
Cross-border transfer of personal information. The moment supplier, buyer or employee personal information collected in China lands in JAGGAER’s US, EU, UK or UAE AWS region, you — the handler, not JAGGAER the processor — have made a cross-border transfer of personal information (数据出境) under PIPL. Articles 38–40 require one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification); Articles 13 and 23 require a lawful basis and a separate consent distinct from general agreement to use the platform; and bank or tax identifiers in the supplier master can rise to sensitive personal information, adding a necessity test and an impact assessment.
Important data — the door procurement teams miss. For a supply-chain platform the exposure is not only personal information. Consolidated supplier-network maps, sourcing and spend, and — for manufacturers — production, inventory and logistics data can be classified as “important data” (重要数据) under the Data Security Law and China’s national and sectoral important-data catalogs, most readily in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy, food and logistics. Exporting important data abroad triggers a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves the country — regardless of whether any personal information is involved, and regardless of volume. Whether your sourcing and supply-chain data qualifies turns on your sector and the applicable catalog, which is why this is a risk to map, not a verdict to assume.
In-country storage. If your China entity is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires that personal information generated in China be stored in China. An offshore AWS region cannot satisfy that duty. Which of these obligations bite — a transfer mechanism, an assessment, in-country storage, or several at once — is a question for counsel against what you actually collect and where your suppliers and staff sit.
Logging in isn’t the question — a compliant in-country supply chain is
JAGGAER is software your buyers and suppliers open over the public internet, so a mainland user can usually reach it; cross-border access to an offshore region can simply be inconsistent. That is an operational matter, not the decision, and this page publishes no first-party China latency figure for JAGGAER because speed is not the axis for a question that turns on residency, consent and data classification. The temptation is to force a shaky connection through a network workaround; that is both a compliance risk and beside the point, and 21YunBox neither uses nor suggests any form of circumvention.
The productive work is to keep the China supplier and supply-chain data on a lawful, in-country footing: an in-country data path for what must stay, data classification to find any important data before it moves, minimization and the Article 13/23 consent for supplier and employee personal information, and compliant in-country delivery for any China-facing surface — a supplier-onboarding or SRM self-service page carries an ICP filing (备案) duty. Localizing means keeping the data on an in-country path — never a tunnel that ships it offshore anyway. Whether your supply-chain data is important data, and which transfer and storage duties apply, turns on your sector and your entity: settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a compliant way to run source-to-pay for a China operation, and it has three moves. First, map: our China team inventories the supplier and buyer personal information, the contracts and spend, and the demand, inventory, logistics and supplier-network data JAGGAER holds; where each is processed and stored (an offshore AWS region, with APAC data in the UK); whether any of it is “important data” (重要数据); and what your consent, transfer-mechanism and assessment basis must cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we help stand up a China-resident footing for the China supplier and supply-chain data — a consented, in-country pattern of processing and storage, with the data classified so that anything qualifying as important data is handled under the data-export rules before it would ever move — while you keep JAGGAER for the markets where it already serves you. Localizing keeps the data on an in-country path; it is never a tunnel that ships it offshore anyway.
Then deliver: the China-facing surfaces around your procurement stack — a supplier-onboarding or SRM portal, an approval page, the integration edge your mainland users and suppliers reach — are public services in the mainland, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. What we never do, and what no one lawfully can, is hand you a way around China’s data-export rules. 21YunBox never uses or suggests circumvention of any kind. The result is a source-to-pay stack that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
