Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Jira Service Management Work in China? Data Residency, ICP & Cross-Border Rules

Jira Service Management is the system of record for your China IT estate. Atlassian Cloud hosts it in offshore regions with no mainland-China option, so your China IT staff's and requesters' personal information and your CMDB sit abroad — a PIPL cross-border and data-residency matter, with Data Center being retired. A compliance-first look at residency, ICP and keeping the regulated data in-country.

Does Jira Service Management work in China?

Whether you can run Jira Service Management for a mainland-China team is a data-residency and governance question, not a speed one. The service desk holds your China IT staff and ticket requesters' personal information and — the half a reachability check never sees — your CMDB and tickets: the hostnames, topology, asset inventory and configuration detail that map how your China operation is built and run.

Jira Service Management Cloud keeps all of it on Atlassian's offshore regions — its data-residency options name no mainland-China location — so data collected from people in China is a cross-border transfer under PIPL (notice, separate consent, a transfer mechanism), with an in-country storage duty for a CIIO or high-volume handler under the Cybersecurity Law's Article 39 (formerly Article 37). The self-managed Data Center edition could sit in-country, but Atlassian is retiring it — so the durable answer is the lawful in-country pattern, not the product.

This is a risk picture to settle with counsel, not a verdict. Our China compliance team can map your Jira Service Management exposure →

What Jira Service Management's own documentation says about China

FactPrimary source
In Atlassian's own words: "Data residency gives you control over where your in-scope app data for Jira, Jira Service Management, Jira Product Discovery, Confluence, and Loom is hosted." The locations you can pin that data to are Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a "Global" default — none in mainland China. Atlassian Support — Understand data residency, retrieved 2026-10-11
Atlassian's self-managed Data Center — the only edition you can host in-country — is being retired. Its own licensing states "On March 30, 2026 at 23:59 PST, new customers will no longer be able to purchase new Data Center subscriptions," and "End of life for impacted Data Center products … will take place on March 28, 2029," after which they become read-only; Jira Service Management Data Center is named among the impacted products. Atlassian — Data Center end of life, retrieved 2026-10-11
Because a Jira Service Management instance holds personal information — your China IT staff and every requester who files a ticket — storing it offshore is a cross-border transfer PIPL governs: the handler (you, not Atlassian) must give notice, obtain separate consent and meet a transfer mechanism, and for a CIIO or high-volume handler the Cybersecurity Law's Article 39 (formerly Article 37) requires China-collected personal information to be stored in the mainland. PIPL Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37)
A public self-service or ticket portal served to mainland visitors is an internet information service, so it carries an ICP filing duty bound to mainland hosting that an offshore tenant cannot meet; and auto-triage or AI that profiles or decides about individuals brings PIPL Article 24 automated-decision-making duties, including an opt-out. ICP filing (备案), State Council Order No. 292 / MIIT Order No. 33; PIPL Article 24

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a mainland-China IT team, the first instinct is to ask whether the service desk opens quickly from Shanghai or Shenzhen. That is the wrong gate. Jira Service Management is Atlassian’s IT service management platform — the service desk, incident, change and problem management, and the CMDB and asset management behind them — and what decides whether you can run it for China is not reachability or speed. It is where the personal information it holds comes to rest, and where the record of your entire China IT estate is kept. It ships two ways: Jira Service Management Cloud, a SaaS tenant Atlassian hosts in its own regions, and the self-managed Data Center edition you run yourself. By Atlassian’s own account, Cloud has no mainland-China region — and, as we will come to, the self-managed edition that could sit in-country is being retired. To be unambiguous from the outset: there is no lawful way around China’s network controls, and 21YunBox never uses or suggests circumvention of any kind.

Atlassian's own data-residency documentation, naming Jira Service Management among the products it covers and listing the locations you can pin Atlassian Cloud data to — Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a Global default — with mainland China absent from the list.
Atlassian's own data-residency documentation states: “Data residency gives you control over where your in-scope app data for Jira, Jira Service Management, Jira Product Discovery, Confluence, and Loom is hosted” — and the locations you can select from are Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a “Global” default. None is in mainland China. Source: Atlassian Support — Understand data residency

Jira Service Management in China at a glance

What decides it In Atlassian's own terms — and China's law
What it is Jira Service Management is Atlassian's ITSM platform — service desk, incident/change/problem management, and the CMDB and asset management behind them. It ships as Cloud (SaaS) and as the self-managed Data Center edition. There is no Atlassian region or operating entity inside mainland China.
Where Cloud data lives Atlassian Cloud lets you pin data to a region, but its data-residency options run across Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a “Global” default. None is inside mainland China.
The people it holds (PII) The directory of your China IT staff and every requester who files a ticket — names, work emails, phone numbers, org unit, sometimes device or location. Held offshore, that is a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, a transfer mechanism; for a CIIO or high-volume handler, in-country storage under the Cybersecurity Law's Article 39 (formerly Article 37).
The CMDB & tickets (the distinctive half) Your configuration management database — hostnames, network topology, asset inventory, service maps — plus incident/change tickets that routinely carry internal system detail, configuration and sometimes embedded credentials. Held offshore, this concentrated map of how your China estate is built and run is a cross-border data issue and, for sensitive operations, may implicate China's handling of sensitive or “important data” (重要数据). A risk to confirm with counsel, not a fixed classification.
Automated triage & AI Auto-triage, predictive routing or agentic workflows that profile or make decisions about individuals bring PIPL Article 24 automated-decision-making duties — transparency, fairness, and an opt-out of decisions made solely by automated means.
A China-facing portal A public self-service or ticket portal served to mainland visitors from inside China is an internet information service, so it carries an ICP filing (备案) duty bound to a mainland hosting resource — which Atlassian Cloud does not provide.
The self-managed option Data Center could sit in-country, but Atlassian is retiring it — new-customer sales closed March 30, 2026 and end of life is March 28, 2029, after which the products become read-only, with Jira Service Management Data Center named among them. A retiring product is not a durable in-country shape.
The lawful path Keep the China-collected PII and the CMDB and ticket data that must stay on a consented, China-resident store, move only what may lawfully leave, ICP-file any China-facing portal, and deliver it in-country. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention.

The data a service desk holds is personal information — and it sits offshore

A Jira Service Management instance is not just workflow — it is the system of record for your China IT estate, and two kinds of data inside it are what China’s law responds to. The first is personal information: the directory of your China IT staff, and every requester who files a ticket — names, work emails, phone numbers, org unit, and sometimes device or location detail. All of it lives in your Atlassian Cloud tenant, and by Atlassian’s own data-residency documentation that tenant sits outside mainland China. So the ordinary act of a Beijing-based employee raising a ticket places personal information collected in China onto storage outside the country. That is a cross-border transfer of personal information under the Personal Information Protection Law, and the duty lands on you, the handler — not on Atlassian. PIPL Articles 38–40 require notice, a separate consent distinct from a user’s agreement to use the tool, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. None of that turns on how fast the portal paints.

The CMDB and tickets — the half a reachability check never sees

Here is the exposure a speed test can never surface. Beyond the people, a Jira Service Management instance holds your configuration management database and your tickets — and together they are the concentrated, security-sensitive map of how your China operation is built and run. The CMDB carries hostnames, network topology, asset inventory and service maps; incident and change tickets routinely carry internal system detail, configuration, and sometimes embedded credentials or secrets. Held on an offshore tenant, that blueprint of your China IT estate is two things at once: a cross-border data transfer, and — for sensitive operations — a matter that may implicate China’s handling duties for sensitive or “important data” (重要数据) and its broader data-security obligations.

A reachability check confirms the portal loads; it says nothing about the fact that your estate’s operational secrets are being processed and stored abroad. We frame this as a risk to confirm with counsel, not a settled classification — but it is precisely the half of the question that decides whether an offshore service desk is safe to run for China, and it is the half a competitor who only measures speed can never answer.

No mainland-China region — residency, the portal, and automated triage

With some vendors the fix is to move onto a mainland instance the vendor runs. Atlassian Cloud is not one of them: as its own documentation shows, the locations you can pin data to are Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, with a “Global” default — and not one is in mainland China. That settles several questions before performance ever enters the picture.

First, residency. If your organization is a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 — formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, the obligation unchanged). An offshore Jira Service Management Cloud tenant cannot satisfy that, whichever residency region you pick. Second, licensing. A public self-service or ticket portal actually served to mainland visitors from inside China is an internet information service, so it carries an ICP filing (备案) duty bound to a mainland hosting resource — and Atlassian Cloud offers none of its own to file against. Third, automated handling. Where auto-triage, predictive routing or agentic workflows profile or decide about individuals, PIPL Article 24 adds automated-decision-making duties: transparency, fairness, and an opt-out of decisions made solely by automated means. Which of these actually bite on your data is a risk to confirm with counsel against what you collect, your volumes, and who your users are.

The self-managed in-country option is closing

It is fair to ask the obvious question: can’t you simply run the self-managed Data Center edition on a server inside China and keep the data in-country? In principle that is one lawful shape — but it is a shape that is closing, and it would be dishonest to point you at it as a durable answer. Atlassian’s own licensing states that “On March 30, 2026 at 23:59 PST, new customers will no longer be able to purchase new Data Center subscriptions,” and that “End of life for impacted Data Center products … will take place on March 28, 2029,” after which they become read-only — with Jira Service Management Data Center named among the impacted products.

So the right thing to build around is the pattern, not the product: consented, in-country storage for the China-collected personal information and the CMDB and ticket data that must stay, with only what may lawfully leave reaching your global service desk. That pattern outlives any one vendor’s product lifecycle, and it is what 21YunBox stands up and integrates — with the legal conclusions settled alongside your counsel.

The lawful path — map, localize, deliver

There is a compliant way to run IT service management for a China-facing team, and it has a clear shape — three moves, in order.

Map. Our China compliance team inventories what your Jira Service Management instance holds — the China IT staff directory and requester identities, the CMDB and asset data, the content of incident and change tickets, and any China-facing self-service portal — establishes where it is hosted today, the ICP status of any public surface, and the consent and residency basis each flow relies on. We build the technical picture; the legal conclusions are settled with your counsel.

Localize. Keep the China-collected personal information and the CMDB and ticket data that must stay on a consented, China-resident store, protect that security-sensitive estate record, obtain the Article 13/23 notice-and-consent and an Article 24 opt-out for automated handling, and let only what may lawfully leave reach the service desk your team already uses — so your queues, workflows and automations keep working, without the ITSM becoming the thing that carries your estate’s data out of China unlawfully. Localize means keeping the data on an in-country path — never a route that ships it offshore anyway.

Deliver. Any China-facing self-service or ticket portal served to users in the mainland is a public service there, so it carries an ICP filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is an IT service desk, and a China-facing portal, that run legally and compliantly for your users in China. What we do not do, and what no one lawfully can, is give you a way around China’s network controls: we keep in-country what must stay and deliver the rest compliantly from inside the mainland. 21YunBox is a compliance overlay and partner to the ITSM you already run, not a competitor to it.

Get a compliance assessment →

Tell us how your China team uses Jira Service Management and what your tickets and CMDB hold — we’ll map what may lawfully leave, localize what must stay in-country, and deliver your China-facing portal compliantly. Reach out and we’ll scope it with you and get you a quote.


Related reading:

Frequently Asked Questions

Does Jira Service Management store Chinese users' data in China?
No. By Atlassian's own data-residency documentation, the locations you can pin Jira Service Management data to are Australia, Canada, the EU, Germany, India, Japan, Singapore, South Korea, Switzerland, the United Kingdom and the USA, plus a "Global" default — none in mainland China. So the employee and requester personal information, and the CMDB and ticket records, that your instance collects in China are held offshore, which is what China's cross-border rules respond to.
The CMDB is just technical data — why does it matter for compliance?
It is the part a reachability test never sees. Your CMDB and tickets hold hostnames, network topology, asset inventory, service maps and configuration detail, and tickets routinely carry internal system detail and sometimes embedded credentials. Held offshore, that concentrated map of how your China IT estate is built and run is both a cross-border data issue and, for sensitive operations, may implicate China's data-security duties around sensitive or 'important data' (重要数据). Treat the specific classification as a risk to confirm with counsel.
Can't we just self-host Jira Service Management Data Center in China to fix this?
In principle a self-managed deployment inside the mainland is one lawful shape — but Atlassian is retiring Data Center: new-customer sales closed March 30, 2026 and end of life is March 28, 2029, after which the products become read-only. So the durable answer is the pattern, not the product: keep the China-collected personal information and the CMDB and ticket data that must stay on a consented, China-resident store, ICP-file any China-facing portal, and deliver it in-country. 21YunBox maps, localizes and delivers — and never uses or suggests circumvention of any kind.

ARTICLES RELATED TO JIRA SERVICE MANAGEMENT

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.