Does Kinaxis Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules
Kinaxis Maestro is a single-tenant SaaS supply-chain planning platform hosted in North America, Europe and Asia — with no mainland-China region. Your China operation's supplier contacts and its demand, inventory and supply-network data sit offshore: a PIPL cross-border transfer, and supply-chain data that can be 'important data' needing a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure.
Does Kinaxis work in China?
Kinaxis runs Maestro as a single-tenant SaaS hosted in North America, Europe and Asia with no mainland-China region, so your China operation's supplier contacts and supply-chain data sit offshore — a PIPL cross-border transfer — and that supply-chain data can be "important data" (重要数据) needing a CAC data-export security assessment before it leaves.
Maestro (formerly RapidResponse) holds demand, inventory, logistics and supply-network data plus the personal information of your planners and supplier contacts; on an offshore cloud with no mainland-China region, holding it for a China operation is a PIPL cross-border transfer (Articles 38–40), and the supply-chain data itself can be "important data" under the Data Security Law, triggering a mandatory CAC data-export security assessment before it leaves — regardless of any personal information. The lawful lever is to keep the supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing surface — not to make the offshore platform reachable.
Whether your supply-chain data is "important data" turns on your sector — a risk to map with counsel, not a verdict. Our China team can map your exposure →
What Kinaxis's own documentation says about China
| Fact | Primary source |
|---|---|
| Kinaxis hosts Maestro in North America, Europe and Asia — not in mainland China. Its Trust Center states Kinaxis "hosts customer data in secure data centers located in North America, Europe, and Asia," on private and public cloud via Equinix, Google Cloud Platform and Microsoft Azure; its listed public-cloud regions are the EEA, US, Canada, Japan and Australia. For a China operation, that places supplier and supply-chain data offshore. | Kinaxis Trust Center — Data hosting locations & subprocessor list (retrieved October 11, 2026) |
| Maestro is a single-tenant SaaS with no customer-run, in-country deployment. Kinaxis's Trust Center lists a "Single tenant SaaS model" and a "Cross-border data transfers" section; because you cannot self-host Maestro on the mainland, the residency lever is an in-country data path, data classification and minimization — not deploying it in China yourself. | Kinaxis Trust Center — Security key highlights (retrieved October 11, 2026) |
| Exporting "important data" (重要数据) requires a CAC data-export security assessment before it leaves — regardless of any personal information. Supply-chain data such as supply-network maps, logistics, inventory and production/capacity can be classified as important data in strategic sectors, triggering a mandatory data-export security assessment under the Data Security Law. | 21YunBox — China Data-Export Security Assessment Measures |
| Supplier and employee personal information held offshore is a PIPL cross-border transfer (Articles 38–40). It needs notice, a separate consent and a transfer mechanism; and for a CIIO or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China personal information to be stored in China. See cross-border data transfers under PIPL. | 21YunBox — Cross-Border Data Transfers under PIPL; China's Cybersecurity Law |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a company running Kinaxis Maestro in mainland China, the question is not whether planners can open the app from Shanghai — reachability is an operational detail. What settles it is where your supplier and supply-chain data comes to rest, and whether any of it is “important data” that cannot leave the country without a government security assessment. Kinaxis delivers Maestro (formerly RapidResponse) — its concurrent supply-chain planning platform for demand, supply, inventory and sales-and-operations planning — as a single-tenant SaaS, hosted in North America, Europe and Asia on private and public cloud, with no mainland-China region. So for a China operation three things are in play at once: the supplier and planner contacts in Maestro are personal information resting offshore, a cross-border transfer under PIPL; the demand, inventory and supply-network data can be “important data” under the Data Security Law; and a critical information infrastructure operator or high-volume handler owes an in-country storage duty. Any supplier-facing surface adds an ICP filing.
Kinaxis in China at a glance
| What decides it | In Kinaxis's own terms — and China's law |
|---|---|
| What Maestro holds | A concurrent supply-chain planning system of record: demand forecasts, inventory and logistics, production and capacity plans, and the end-to-end supply-network map, plus sourcing and order data. Alongside that operational data it holds personal information — the names, business emails and roles of your planners and approvers, and of the supplier and partner contacts who collaborate in it. |
| Where the data runs | Kinaxis delivers Maestro as a single-tenant SaaS from data centers in North America, Europe and Asia, on private and public cloud (Equinix, Google Cloud Platform, Microsoft Azure). Its listed public-cloud regions run in the EEA, the US, Canada, Japan and Australia — there is no mainland-China region. For a China operation, data held there is a cross-border transfer (数据出境) under PIPL Articles 38–40. |
| The "important data" door | Beyond personal information, the supply-chain data itself can be the exposure. Supply-network maps, logistics and inventory, production and capacity, and consolidated sourcing data can be classified as "important data" (重要数据) under the Data Security Law in strategic sectors. Exporting important data triggers a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves — regardless of whether any personal information is involved, or how much. |
| Supplier/employee PI + residency | Supplier and employee contacts are personal information: PIPL Articles 13 and 23 require notice and, for an overseas transfer, a separate consent. For a critical information infrastructure operator or high-volume handler, the Cybersecurity Law's data-localization rule — Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) — requires China-generated personal information to be stored in China, a duty an offshore instance cannot meet. |
| Reachability is not the axis | Whether Maestro loads quickly from Shanghai is an operational matter, not the compliance question. What decides it is where the supplier and supply-chain data lives and whether any of it may lawfully leave. The lever is an in-country data path, data classification and minimization, and an ICP filing for any China-facing surface such as a supplier portal — delivered in-country in front of the stack you already run. |
What you actually hold — supplier data, spend, and the supply chain
Kinaxis Maestro is where your supply chain is planned and, increasingly, executed. It holds the demand forecasts, inventory positions, logistics and transportation data, production and capacity plans, and the end-to-end supply-network map that ties your sites, suppliers and parts together — much of it commercially sensitive, and some of it a window onto national supply for a whole sector. Unlike a source-to-pay procurement suite, Maestro’s core is planning and execution data rather than spend and contract records — but the residency question is identical, and the supply-network data raises a second one. On top of that operational core sits personal information: the names, business emails and roles of the planners and approvers who use Maestro, and of the supplier and partner contacts who collaborate through it.
Where does all of that live? Kinaxis runs Maestro as a single-tenant SaaS from private and public-cloud data centers in North America, Europe and Asia — its listed public-cloud footprint sits in the EEA, the US, Canada, Japan and Australia, with no mainland-China region. Maestro is not a suite you install on infrastructure you choose; there is no customer-run, in-country deployment. For a China operation that means the data is, by default, processed and stored outside the mainland — which is precisely where Chinese law starts asking questions.
The doors: cross-border personal data, important data, and in-country storage
Once Maestro holds your China operation’s data offshore, three bodies of law decide whether that was allowed.
First, personal information. The planner, approver and supplier contacts in Maestro are personal information under China’s PIPL, and holding them in an offshore instance is a cross-border transfer (数据出境). PIPL puts the duty on you, the handler — not on Kinaxis: Articles 38–40 require notice, a separate consent for the overseas transfer, and one lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), while Articles 13 and 23 govern the consent itself.
Second — and this is the half a pure personal-data analysis misses — the supply-chain data itself. Supply-network maps, logistics and inventory, production and capacity, and consolidated sourcing data can be classified as “important data” (重要数据) under the Data Security Law, especially in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy, food and logistics. Exporting important data triggers a mandatory CAC data-export security assessment before anything leaves the country — regardless of whether personal information is involved, or how much. Whether your supply-chain data is important data turns on your sector and the applicable national and sectoral catalogs, so it is a risk to assess, not a blanket rule.
Third, residency. If your organization is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information generated in China to be stored in China — an in-country duty an offshore Maestro instance cannot satisfy. Which of these doors bite your specific deployment turns on your sector, your data volumes and your role under Chinese law.
Logging in isn’t the question — a compliant in-country supply chain is
The fix is not to make an offshore Maestro instance load faster from the mainland — it is to put the China supply-chain and supplier data where the law needs it and to handle what leaves lawfully. Because Maestro is cloud-only, the lever is not self-hosting it in China; it is keeping the China data on an in-country path, classifying it so you know what is “important data,” minimizing what crosses the border, and completing the CAC data-export security assessment or other mechanism for anything that does. That is localization in the real sense — keeping the data on an in-country footing — not a tunnel that ships it offshore anyway. Any supplier- or partner-facing surface you publish in the mainland — a supplier collaboration portal, an onboarding page — is an internet information service and carries an ICP filing (备案) duty bound to a mainland hosting resource, plus compliant in-country delivery. None of this is a verdict that Kinaxis is “blocked” or “illegal” in China — Maestro can run there lawfully when the pieces line up. It is a residency-and-exposure map, and which path fits turns on your entity, your sector and your data — worth settling the specifics with counsel before your China supply chain depends on it.
The lawful path — map, localize, deliver
There is a compliant way to run supply-chain planning for a China operation, and it has a shape. First, map: our China team inventories what your Maestro environment holds — the supplier and planner personal information, and the demand, inventory, logistics and supply-network data — where each is processed and stored today, whether any of it is “important data” (重要数据), the data-path options open to you, and the consent, residency and assessment basis each transfer would need. We build the technical picture; the legal conclusions are settled with counsel.
Then localize: we help you keep the China supplier and supply-chain data in-country — on an in-country data path — classify it, handle any important-data and data-export-assessment duty, and minimize and obtain the Article 13/23 consent for the supplier and employee personal information. Localize means keeping the data on an in-country path, never moving it across the border by stealth.
Then deliver: any China-facing surface on top of the stack — a supplier portal, an SRM page — needs compliant, in-country delivery and carries an ICP filing duty. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and classify and assess the supply-chain data that may be important data before any of it moves.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment (CAC)
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
