Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Atlassian Jira Work in China? Data Residency, PIPL Cross-Border & ICP

Whether you can run Atlassian Jira for a mainland-China team is first a data-residency and cross-border question under PIPL — not a question of whether it loads. Jira Cloud keeps your issues, project data, attachments and the team's identities on Atlassian's offshore AWS regions — its data-residency options cover Australia, Canada, the EU, Japan, Singapore and more, but not mainland China — so China-collected data kept there is a cross-border transfer of personal information under PIPL (notice, a separate consent, a transfer mechanism), with an in-country storage duty for some handlers under the Cybersecurity Law's Article 39 (formerly Article 37) and an ICP filing for any public Jira surface served from inside China. Atlassian's self-managed Data Center is itself being retired, so the durable answer is the lawful in-country pattern — consented, China-resident storage for data that must stay, delivered in-country on ICP-filed infrastructure. A compliance-first look, with no circumvention of any kind.

Does Atlassian Jira work in China?

Whether you can run Atlassian Jira for a mainland-China team is first a data-residency and cross-border question under PIPL — not a question of whether it loads. Jira holds your issues, project data, attachments and the identities of the people using it, and where that personal information is kept is what China's law responds to.

Atlassian Cloud lets you pin data to a region, but its own data-residency documentation lists Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA — plus a "Global" default — and mainland China is not among them. So the issues, attachments and user identities collected from your China team sit on Atlassian's offshore AWS regions: a cross-border transfer of personal information PIPL governs (notice, a separate consent and a transfer mechanism, Articles 38–43), with an in-country storage duty for a CIIO or large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and an ICP filing for any public Jira surface served from inside China. Atlassian's self-managed Data Center could sit in-country, but it is itself being retired, so it is not a durable answer.

This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it is worth settling with counsel. Our China team can map your exposure with you →

What Atlassian Jira's own documentation says about China

FactPrimary source
Atlassian's own data-residency documentation lists no mainland-China location. It states that "Data residency gives you control over where your in-scope app data for Jira, Jira Service Management, Jira Product Discovery, Confluence, and Loom is hosted," and under "The following locations are available for you to select from:" it names Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a "Global" default — mainland China among none of them. So the issues, attachments and user identities a China team keeps in Jira Cloud are held on Atlassian's offshore AWS regions — a cross-border transfer of personal information under PIPL. Atlassian Support — Understand data residency, retrieved 2026-10-09
What Jira holds is personal information, and the transfer duty is yours — not Atlassian's. Issue descriptions and comments, attachments, and the reporter, assignee and account identities (names and email addresses) of the people using Jira are personal information. Collecting that from people in mainland China and keeping it in an offshore Jira Cloud tenant is a cross-border transfer PIPL governs: the personal-information handler — you, Atlassian's customer — must give notice, obtain a separate consent for the transfer, and satisfy one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Above thresholds a data-export security assessment may apply before anything leaves. PIPL Articles 38–43; China data-export security assessment measures
For some handlers the data must stay in China — and a public Jira surface served from inside the mainland needs an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty an offshore Jira Cloud tenant cannot meet. And a public Jira surface, such as a Jira Service Management customer portal or help center, served to mainland visitors from inside China carries an ICP filing duty (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Atlassian Cloud does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33
The self-managed in-country option is closing. Running Jira's self-managed edition inside China could, in principle, keep data in-country — but Atlassian's own licensing page states that "On March 30, 2026 at 23:59 PST, new customers will no longer be able to purchase new Data Center subscriptions," and that "End of life for impacted Data Center products will take place on March 28, 2029 at 23:59 PST," with "Jira Software Data Center" and "Jira Service Management Data Center" on the affected list — and Jira Server support has already ended. A retiring product is not a durable go-forward shape, so the lawful in-country answer is the pattern (consented, China-resident storage), not the specific product. Confirm the path with counsel. Atlassian — Data Center end of life, retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a mainland-China team the first instinct is to ask whether Jira loads from Shanghai or Shenzhen. That is the wrong gate. Atlassian Jira is project and issue tracking, and what decides whether you can use it for China is not reachability or speed — it is where the personal information it holds is kept. Every issue description, comment and attachment, and the names and email addresses of the people working the board, live in your Atlassian Cloud tenant, and by Atlassian’s own account that tenant sits outside mainland China. The moment data collected from people in China lands there, a different body of law decides whether that was lawful — and that question stands even if the page loads instantly. To be unambiguous from the outset: there is no lawful way around China’s network controls, and 21YunBox never uses or suggests circumvention of any kind.

Atlassian's own data residency documentation listing the locations you can pin Atlassian Cloud data to — Australia, Canada, EU, Germany, India, Japan, Singapore, South Korea, Switzerland, United Kingdom and USA, plus a Global default — with mainland China absent from the list
Atlassian's own data-residency documentation states: “Data residency gives you control over where your in-scope app data for Jira, Jira Service Management, Jira Product Discovery, Confluence, and Loom is hosted,” and under “The following locations are available for you to select from:” it lists Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a “Global” default — mainland China among none of them. Source: Atlassian Support — Understand data residency

Atlassian Jira in China at a glance

What decides it In Atlassian's own terms — and China's law
What it is Jira is Atlassian's project and issue tracking (Atlassian Cloud): issues, project data, attachments, and the identities of the team members using it. There is no Atlassian region or operating entity inside mainland China.
Where the data lives Atlassian Cloud lets you pin data to a region, but its data-residency options run across Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a “Global” default. None is inside mainland China; the nearest is still offshore.
Putting China-collected issues & attachments in Jira Cloud A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–43): notice, a separate consent, and one transfer mechanism. Above thresholds it may trigger China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore tenant cannot meet.
Serving the public A public Jira surface — such as a Jira Service Management customer portal or help center — served to mainland visitors from inside China carries an ICP filing duty, bound to a mainland hosting resource Atlassian Cloud does not provide.
The self-managed option Atlassian's self-managed Data Center could sit in-country, but Atlassian is retiring it — new-customer sales closed March 30, 2026 and end of life is March 28, 2029 — and Jira Server support has already ended. A retiring product is not a durable in-country shape.
The lawful path Keep the China-collected data that must stay in-country on a consented, China-resident store, move only what may lawfully leave, and deliver the China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention.

The data Jira holds is personal information — and it sits offshore

Here is the gate most teams miss. A Jira board is not just workflow — it is a store of personal information. Issue descriptions and comments routinely carry the names, contact details and account data of customers, candidates or employees; attachments carry whatever files people drop in; and the reporter, assignee and account identities are themselves the names and email addresses of your team. All of it is held in your Atlassian Cloud tenant, and that tenant is hosted outside the mainland. So the ordinary act of a Beijing-based colleague logging a ticket places personal information collected in China onto storage outside the country. That is a cross-border transfer of personal information under China’s Personal Information Protection Law.

PIPL puts the duty on the handler — you, not the tool vendor. Articles 38–43 require notice, a separate consent distinct from a user’s agreement to use the product, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the records include “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. None of this turns on how quickly a board renders; it turns on whether the data had a lawful basis to be outside the country at all.

No mainland-China region to pin to — residency and the ICP question

With some vendors the fix is to move onto a mainland instance the vendor itself runs. Atlassian Cloud is not one of them for data residency: as its own documentation shows, the locations you can pin data to are Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, with a “Global” default — and not one of them is in mainland China. That single fact settles two questions before performance ever enters the picture.

First, residency. If your organization is a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 — formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, the obligation unchanged). An offshore Jira Cloud tenant cannot satisfy that, whichever residency region you pick, because none of the regions is in China. Second, licensing. A public-facing Jira surface actually served to mainland visitors from inside China — a Jira Service Management customer portal or help center, for instance — turns on an ICP filing (备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing must attach to a hosting resource physically in the mainland. Atlassian Cloud offers none, so there is nothing of its own to file against. Which of these obligations actually bite on your data is a risk to confirm with counsel against what you collect, your volumes, and who your users are.

The self-managed in-country option is closing

It is fair to ask the obvious question: can’t you simply run Jira’s self-managed edition on a server inside China and keep the data in-country? In principle a self-managed deployment is one lawful shape — but it is a shape that is closing, and it would be dishonest to point you at it as a durable answer. Atlassian’s own licensing page states that on March 30, 2026 new customers can no longer purchase Data Center subscriptions, and that end of life for impacted Data Center products — Jira Software Data Center and Jira Service Management Data Center among them — falls on March 28, 2029, after which they become read-only. Jira Server support ended earlier still.

So the right thing to build around is the pattern, not the product: consented, in-country storage for the China-collected data that must stay, with only what may lawfully leave reaching your global Jira. That pattern outlives any one vendor’s product lifecycle, and it is what 21YunBox stands up and integrates — settled with counsel on the legal conclusions.

The lawful path — map, localize, deliver

There is a lawful way to run project and issue tracking for a China-facing team, and it has a clear shape — three moves, in order.

Map. Our China team works through your PIPL cross-border exposure and your data-residency duties: classifying which Jira-held records carry personal or important information that must stay in-country, which may lawfully be transferred, and where a data-export security assessment, an Article 39 storage duty, or an ICP filing applies to a public Jira surface. We frame the technical picture; the legal conclusions are settled with your counsel.

Localize. Keep the China-collected issues, attachments and identities that must stay on a consented, China-resident store, and let only what may lawfully leave reach the Jira Cloud your team already uses — so the boards, workflows and automations your team depends on keep working, without the tracker becoming the thing that carries data out of China unlawfully. 21YunBox stands up and integrates that China-legal in-country option in place of what cannot run compliantly in the mainland.

Deliver. Any China-facing surface that serves those boards or portals to users in the mainland is itself a public service there, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is project and issue tracking, and a China-facing surface, that run legally and compliantly for your users in China. What we do not do, and what no one lawfully can, is give you a way around China’s network controls: we localize what must stay and deliver in-country, and circumvention is never on the table.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Atlassian Jira store a China team's data in mainland China?
No. By Atlassian's own data-residency documentation, the locations you can pin Jira Cloud data to are Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a "Global" default — none in mainland China. So the issues, attachments and user identities collected from your China team are held offshore, which makes them a cross-border transfer of personal information under PIPL: the handler (you, not Atlassian) owes notice, a separate consent and a transfer mechanism. Treat the specifics as a risk to settle with counsel.
Can't we just run Jira Data Center in China to keep the data in-country?
It is a shape some teams have used, but it is closing. Atlassian's own licensing page says new customers can no longer purchase Data Center as of March 30, 2026, and that impacted Data Center products — including Jira Software Data Center and Jira Service Management Data Center — reach end of life on March 28, 2029; Jira Server support ended earlier still. So a self-managed in-country deployment is not a durable go-forward answer. The durable path is the lawful in-country pattern: keep the China-collected data that must stay on a consented, China-resident store, and move only what may lawfully leave — confirmed with counsel.
Can 21YunBox help make our Jira setup work in China?
Yes. Our China team maps the PIPL cross-border, data-residency and ICP obligations that attach to the issues, attachments and user identities Jira holds — for your entity, data volumes and users — then localizes the China-collected data that must stay onto a consented, in-country store and delivers your China-facing Jira surface in-country on ICP-filed infrastructure, in front of the Jira you already run, with no rebuild. We never use or suggest circumvention of any kind. Get in touch to work through your specific case.

ARTICLES RELATED TO ATLASSIAN JIRA

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.