Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does JAGGAER Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules

JAGGAER One is a cloud source-to-pay platform hosted on AWS in the US, EU, UK and UAE with no mainland-China region, so the supplier contacts, contracts, spend and supply-chain data your China operation enters sit offshore — a PIPL cross-border transfer, and supply-chain data can itself be “important data” needing a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure.

Does JAGGAER work in China?

Not on its own terms. JAGGAER One holds your China operation's supplier master, contracts, spend and supply-chain data on AWS in the US, EU, UK and UAE — no mainland-China region, APAC data processed in the UK — so storing it there is a PIPL cross-border transfer, and consolidated supply-chain data can itself be “important data” that needs a CAC data-export security assessment before it leaves.

JAGGAER is a source-to-pay suite — sourcing, supplier management, contracts, procure-to-pay and, for manufacturers, supply-chain collaboration — so it continuously holds supplier and buyer contacts (personal information), contracts and consolidated spend, plus supplier-network, inventory and logistics data. On an offshore cloud with no mainland-China region, putting China-collected personal information there is a PIPL cross-border transfer (Articles 38–40), while the supply-chain data itself can be “important data” under the Data Security Law that triggers a mandatory CAC data-export security assessment regardless of any PII. The lawful lever is to keep the China supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing surface — not to make the offshore platform reachable.

This is a risk map, not a verdict — whether your supply-chain data is “important data” turns on your sector, so settle the specifics with counsel. Our China team can map your exposure →

What JAGGAER's own documentation says about China

FactPrimary source
JAGGAER One is hosted on AWS with no mainland-China region. JAGGAER's own sub-processor list names Amazon Web Services for infrastructure (IaaS) and platform (PaaS) services, with Location of Processing in the United States, Germany, Ireland, the UK and the UAE — none in mainland China. It states that “For UK and APAC based Clients, data is processed in UK,” so a mainland-China operation is an APAC client whose supplier and supply-chain data rests in an offshore AWS region. JAGGAER — Trust Center, Sub-Processors List (jaggaer.com), retrieved 2026-10-11
JAGGAER One is a cloud source-to-pay platform holding supplier PII, contracts, spend and supply-chain data. JAGGAER describes JAGGAER One as one connected source-to-pay platform spanning sourcing, supplier management, contracts, eProcurement, invoicing and payments, with supply-chain collaboration for manufacturers — so it continuously stores supplier and buyer contacts (personal information), contracts and consolidated spend, and, where the supply-chain modules run, inventory, shipping-notice and shortage data about your China supply network. JAGGAER — JAGGAER One platform overview (jaggaer.com), retrieved 2026-10-11
Exporting “important data” requires a CAC security assessment before it leaves — regardless of PII. Under China's Data Security Law and the national and sectoral catalogs, consolidated supply-chain data — supplier-network maps, sourcing, production and logistics — can be “important data” (重要数据), and transferring it abroad triggers a mandatory CAC data-export security assessment (数据出境安全评估). Whether your data qualifies turns on your sector. 21YunBox — Measures for the Security Assessment of Data Exports, retrieved 2026-10-11
Storing China supplier PII offshore is a PIPL cross-border transfer, with an in-country storage duty for a CIIO. Supplier and employee personal information held in an offshore region is a cross-border transfer under PIPL (Articles 38–40, with a separate consent under Articles 13 and 23). A critical information infrastructure operator or high-volume handler also owes in-country storage under Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered it, substance unchanged. 21YunBox — China Cybersecurity Law; cross-border data transfers, retrieved 2026-10-11

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running sourcing, supplier management, contracts and procure-to-pay through JAGGAER for its China operation, the instinct is to ask whether the platform is quick, or even reachable, from the mainland. That is the wrong place to start. JAGGAER One is a cloud source-to-pay suite, and what decides whether you can use it in China is where the supplier master data, the buyer and supplier contacts, the contracts and the spend and supply-chain data it holds come to rest — and whether any of that information had a lawful basis to leave the country. Under China’s law that is a data-residency and cross-border question, with a second door most procurement teams miss: consolidated sourcing and supply-chain data can itself be “important data” that cannot leave without a state security assessment, regardless of whether any personal information is involved. JAGGAER settles the factual half in its own trust documentation.

JAGGAER's Trust Center sub-processor list, Amazon Web Services (AWS) row, showing Location of Processing as United States, Germany, Ireland, UK and UAE, with a note that for UK and APAC based clients data is processed in the UK, and no mainland-China location
JAGGAER's own sub-processor list, Amazon Web Services row: “For UK and APAC based Clients, data is processed in UK.” Its Location of Processing column lists the United States, Germany, Ireland, the UK and the UAE — none in mainland China — so a mainland-China operation's supplier and supply-chain data rests in an offshore AWS region. Source: JAGGAER Sub-Processors List

JAGGAER in China at a glance

What decides it In JAGGAER's own terms — and China's law
What it holds JAGGAER One is a source-to-pay suite — sourcing, supplier management, contracts, eProcurement, invoicing and payments, with supply-chain collaboration for manufacturers. It is a continuous store of your supplier master data, buyer and supplier contacts (personal information), contracts and consolidated spend, and — where you run the supply-chain modules — inventory, shipping-notice and shortage data about your China supply network.
Where the data sits Offshore. JAGGAER's own sub-processor list hosts the platform on Amazon Web Services in the United States, Germany, Ireland, the UK and the UAE, and states that “For UK and APAC based Clients, data is processed in UK.” There is no mainland-China region; a mainland-China operation is an APAC client whose data rests in the UK. Putting China-collected personal information there is a cross-border transfer (数据出境) under PIPL Articles 38–40 — notice, a separate consent and one transfer mechanism.
The important-data door Supplier-network maps, consolidated sourcing and spend, and — for manufacturing clients — production, inventory and logistics data can be classified as “important data” (重要数据) under the Data Security Law and China's sectoral catalogs, most readily in manufacturing, automotive, pharmaceuticals, energy, food and logistics. Exporting important data abroad requires a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves — regardless of whether any personal information is involved. Whether your data qualifies turns on your sector.
Supplier PII and in-country storage Supplier and buyer contacts, approver identities and any employee data are personal information: PIPL Articles 13 and 23 require a lawful basis and, for the transfer, a separate consent, and bank or tax identifiers in the supplier master can rise to sensitive personal information with a necessity test and an impact assessment on top. If your China entity is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires that personal information generated in China be stored in China — a duty an offshore AWS region cannot meet.
The lawful path Whether a buyer in Shenzhen can open a requisition screen is not the question; where the supplier and supply-chain data behind it lives is. Keep the China supplier and supply-chain data in-country — an in-country data path, data classification and minimization — handle any important-data and cross-border duties lawfully, and deliver any China-facing surface, such as a supplier portal, on ICP-filed, in-country infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

What you actually hold — supplier data, spend, and the supply chain

JAGGAER One is a connected source-to-pay platform: sourcing and contract management upstream, eProcurement, invoicing and payments downstream, supplier intelligence and onboarding across the middle, and — for manufacturers — supply-chain collaboration covering inventory, advance shipping notices and shortage alerts. Everything it does produces data about the people and companies in your China supply base.

Three kinds of data matter here. First, personal information: the supplier master carries supplier and buyer contacts — names, work emails, phone numbers, sometimes bank and tax identifiers — and your approvers and procurement staff are identifiable too. Second, commercial records: contracts, sourcing events, catalogs, purchase orders, invoices and consolidated spend. Third, where you run the supply-chain modules, supply-network data: who supplies what, from where, in what volume, and with what lead times and shortages.

JAGGAER’s own trust documentation settles where this sits. Its sub-processor list hosts the platform on Amazon Web Services in the United States, Germany, Ireland, the UK and the UAE, and notes that “For UK and APAC based Clients, data is processed in UK.” There is no mainland-China region in the list, and no mainland-China entity among its affiliates — the nearest APAC footing processes in the UK. JAGGAER One is delivered as cloud software, and while JAGGAER has extended in-country AWS hosting in select markets elsewhere, it publishes no mainland-China region, so for a China operation the practical lever is an in-country data path, data classification and minimization — not a region you can switch on.

The doors: cross-border personal data, important data, and in-country storage

Cross-border transfer of personal information. The moment supplier, buyer or employee personal information collected in China lands in JAGGAER’s US, EU, UK or UAE AWS region, you — the handler, not JAGGAER the processor — have made a cross-border transfer of personal information (数据出境) under PIPL. Articles 38–40 require one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification); Articles 13 and 23 require a lawful basis and a separate consent distinct from general agreement to use the platform; and bank or tax identifiers in the supplier master can rise to sensitive personal information, adding a necessity test and an impact assessment.

Important data — the door procurement teams miss. For a supply-chain platform the exposure is not only personal information. Consolidated supplier-network maps, sourcing and spend, and — for manufacturers — production, inventory and logistics data can be classified as “important data” (重要数据) under the Data Security Law and China’s national and sectoral important-data catalogs, most readily in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy, food and logistics. Exporting important data abroad triggers a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves the country — regardless of whether any personal information is involved, and regardless of volume. Whether your sourcing and supply-chain data qualifies turns on your sector and the applicable catalog, which is why this is a risk to map, not a verdict to assume.

In-country storage. If your China entity is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires that personal information generated in China be stored in China. An offshore AWS region cannot satisfy that duty. Which of these obligations bite — a transfer mechanism, an assessment, in-country storage, or several at once — is a question for counsel against what you actually collect and where your suppliers and staff sit.

Logging in isn’t the question — a compliant in-country supply chain is

JAGGAER is software your buyers and suppliers open over the public internet, so a mainland user can usually reach it; cross-border access to an offshore region can simply be inconsistent. That is an operational matter, not the decision, and this page publishes no first-party China latency figure for JAGGAER because speed is not the axis for a question that turns on residency, consent and data classification. The temptation is to force a shaky connection through a network workaround; that is both a compliance risk and beside the point, and 21YunBox neither uses nor suggests any form of circumvention.

The productive work is to keep the China supplier and supply-chain data on a lawful, in-country footing: an in-country data path for what must stay, data classification to find any important data before it moves, minimization and the Article 13/23 consent for supplier and employee personal information, and compliant in-country delivery for any China-facing surface — a supplier-onboarding or SRM self-service page carries an ICP filing (备案) duty. Localizing means keeping the data on an in-country path — never a tunnel that ships it offshore anyway. Whether your supply-chain data is important data, and which transfer and storage duties apply, turns on your sector and your entity: settle the specifics with counsel.

The lawful path — map, localize, deliver

There is a compliant way to run source-to-pay for a China operation, and it has three moves. First, map: our China team inventories the supplier and buyer personal information, the contracts and spend, and the demand, inventory, logistics and supplier-network data JAGGAER holds; where each is processed and stored (an offshore AWS region, with APAC data in the UK); whether any of it is “important data” (重要数据); and what your consent, transfer-mechanism and assessment basis must cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we help stand up a China-resident footing for the China supplier and supply-chain data — a consented, in-country pattern of processing and storage, with the data classified so that anything qualifying as important data is handled under the data-export rules before it would ever move — while you keep JAGGAER for the markets where it already serves you. Localizing keeps the data on an in-country path; it is never a tunnel that ships it offshore anyway.

Then deliver: the China-facing surfaces around your procurement stack — a supplier-onboarding or SRM portal, an approval page, the integration edge your mainland users and suppliers reach — are public services in the mainland, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. What we never do, and what no one lawfully can, is hand you a way around China’s data-export rules. 21YunBox never uses or suggests circumvention of any kind. The result is a source-to-pay stack that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does JAGGAER have a data center in mainland China?
No. JAGGAER's own sub-processor list hosts JAGGAER One on Amazon Web Services in the United States, Germany, Ireland, the UK and the UAE, and states that for UK and APAC based clients data is processed in the UK. There is no mainland-China region, and no mainland-China entity among JAGGAER's affiliates, so a China operation's supplier and supply-chain data rests in an offshore AWS region — making its collection a PIPL cross-border transfer that you, the handler, are responsible for.
Is our supply-chain data in JAGGAER “important data” under Chinese law?
It can be. Consolidated supplier-network maps, sourcing and spend, and production, inventory and logistics data can be classified as “important data” (重要数据) under the Data Security Law and China's sectoral catalogs, most readily in manufacturing, automotive, pharmaceuticals, energy, food and logistics. If it qualifies, exporting it abroad requires a mandatory CAC data-export security assessment before anything leaves — independent of whether any personal information is involved. Whether your data qualifies turns on your sector and the applicable catalog, so confirm it with counsel.
Can 21YunBox make JAGGAER faster or reachable from China?
That is not the question, and not what we do. Reachability and speed are not the axis; residency, consent and data classification are. 21YunBox keeps your China supplier and supply-chain data on a lawful in-country path, helps classify and handle any important data under the data-export rules, obtains the PIPL consent for supplier and employee personal information, and delivers any China-facing surface — such as a supplier portal — on ICP-filed, in-country infrastructure, in front of the JAGGAER stack you already run. 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO JAGGAER

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.