Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Kinaxis Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules

Kinaxis Maestro is a single-tenant SaaS supply-chain planning platform hosted in North America, Europe and Asia — with no mainland-China region. Your China operation's supplier contacts and its demand, inventory and supply-network data sit offshore: a PIPL cross-border transfer, and supply-chain data that can be 'important data' needing a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure.

Does Kinaxis work in China?

Kinaxis runs Maestro as a single-tenant SaaS hosted in North America, Europe and Asia with no mainland-China region, so your China operation's supplier contacts and supply-chain data sit offshore — a PIPL cross-border transfer — and that supply-chain data can be "important data" (重要数据) needing a CAC data-export security assessment before it leaves.

Maestro (formerly RapidResponse) holds demand, inventory, logistics and supply-network data plus the personal information of your planners and supplier contacts; on an offshore cloud with no mainland-China region, holding it for a China operation is a PIPL cross-border transfer (Articles 38–40), and the supply-chain data itself can be "important data" under the Data Security Law, triggering a mandatory CAC data-export security assessment before it leaves — regardless of any personal information. The lawful lever is to keep the supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing surface — not to make the offshore platform reachable.

Whether your supply-chain data is "important data" turns on your sector — a risk to map with counsel, not a verdict. Our China team can map your exposure →

What Kinaxis's own documentation says about China

FactPrimary source
Kinaxis hosts Maestro in North America, Europe and Asia — not in mainland China. Its Trust Center states Kinaxis "hosts customer data in secure data centers located in North America, Europe, and Asia," on private and public cloud via Equinix, Google Cloud Platform and Microsoft Azure; its listed public-cloud regions are the EEA, US, Canada, Japan and Australia. For a China operation, that places supplier and supply-chain data offshore. Kinaxis Trust Center — Data hosting locations & subprocessor list (retrieved October 11, 2026)
Maestro is a single-tenant SaaS with no customer-run, in-country deployment. Kinaxis's Trust Center lists a "Single tenant SaaS model" and a "Cross-border data transfers" section; because you cannot self-host Maestro on the mainland, the residency lever is an in-country data path, data classification and minimization — not deploying it in China yourself. Kinaxis Trust Center — Security key highlights (retrieved October 11, 2026)
Exporting "important data" (重要数据) requires a CAC data-export security assessment before it leaves — regardless of any personal information. Supply-chain data such as supply-network maps, logistics, inventory and production/capacity can be classified as important data in strategic sectors, triggering a mandatory data-export security assessment under the Data Security Law. 21YunBox — China Data-Export Security Assessment Measures
Supplier and employee personal information held offshore is a PIPL cross-border transfer (Articles 38–40). It needs notice, a separate consent and a transfer mechanism; and for a CIIO or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China personal information to be stored in China. See cross-border data transfers under PIPL. 21YunBox — Cross-Border Data Transfers under PIPL; China's Cybersecurity Law

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running Kinaxis Maestro in mainland China, the question is not whether planners can open the app from Shanghai — reachability is an operational detail. What settles it is where your supplier and supply-chain data comes to rest, and whether any of it is “important data” that cannot leave the country without a government security assessment. Kinaxis delivers Maestro (formerly RapidResponse) — its concurrent supply-chain planning platform for demand, supply, inventory and sales-and-operations planning — as a single-tenant SaaS, hosted in North America, Europe and Asia on private and public cloud, with no mainland-China region. So for a China operation three things are in play at once: the supplier and planner contacts in Maestro are personal information resting offshore, a cross-border transfer under PIPL; the demand, inventory and supply-network data can be “important data” under the Data Security Law; and a critical information infrastructure operator or high-volume handler owes an in-country storage duty. Any supplier-facing surface adds an ICP filing.

Kinaxis Trust Center, Data hosting locations section, stating that Kinaxis hosts customer data in secure data centers located in North America, Europe, and Asia on private and public cloud via Equinix, Google Cloud Platform and Microsoft Azure, with no mainland-China region
"Kinaxis hosts customer data in secure data centers located in North America, Europe, and Asia." On private and public cloud (Equinix, Google Cloud Platform, Microsoft Azure), Kinaxis names no mainland-China region — its listed public-cloud regions are the EEA, US, Canada, Japan and Australia — so a China operation's supplier and supply-chain data is stored offshore. Source: Kinaxis Trust Center — Data hosting locations

Kinaxis in China at a glance

What decides it In Kinaxis's own terms — and China's law
What Maestro holds A concurrent supply-chain planning system of record: demand forecasts, inventory and logistics, production and capacity plans, and the end-to-end supply-network map, plus sourcing and order data. Alongside that operational data it holds personal information — the names, business emails and roles of your planners and approvers, and of the supplier and partner contacts who collaborate in it.
Where the data runs Kinaxis delivers Maestro as a single-tenant SaaS from data centers in North America, Europe and Asia, on private and public cloud (Equinix, Google Cloud Platform, Microsoft Azure). Its listed public-cloud regions run in the EEA, the US, Canada, Japan and Australia — there is no mainland-China region. For a China operation, data held there is a cross-border transfer (数据出境) under PIPL Articles 38–40.
The "important data" door Beyond personal information, the supply-chain data itself can be the exposure. Supply-network maps, logistics and inventory, production and capacity, and consolidated sourcing data can be classified as "important data" (重要数据) under the Data Security Law in strategic sectors. Exporting important data triggers a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves — regardless of whether any personal information is involved, or how much.
Supplier/employee PI + residency Supplier and employee contacts are personal information: PIPL Articles 13 and 23 require notice and, for an overseas transfer, a separate consent. For a critical information infrastructure operator or high-volume handler, the Cybersecurity Law's data-localization rule — Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) — requires China-generated personal information to be stored in China, a duty an offshore instance cannot meet.
Reachability is not the axis Whether Maestro loads quickly from Shanghai is an operational matter, not the compliance question. What decides it is where the supplier and supply-chain data lives and whether any of it may lawfully leave. The lever is an in-country data path, data classification and minimization, and an ICP filing for any China-facing surface such as a supplier portal — delivered in-country in front of the stack you already run.

What you actually hold — supplier data, spend, and the supply chain

Kinaxis Maestro is where your supply chain is planned and, increasingly, executed. It holds the demand forecasts, inventory positions, logistics and transportation data, production and capacity plans, and the end-to-end supply-network map that ties your sites, suppliers and parts together — much of it commercially sensitive, and some of it a window onto national supply for a whole sector. Unlike a source-to-pay procurement suite, Maestro’s core is planning and execution data rather than spend and contract records — but the residency question is identical, and the supply-network data raises a second one. On top of that operational core sits personal information: the names, business emails and roles of the planners and approvers who use Maestro, and of the supplier and partner contacts who collaborate through it.

Where does all of that live? Kinaxis runs Maestro as a single-tenant SaaS from private and public-cloud data centers in North America, Europe and Asia — its listed public-cloud footprint sits in the EEA, the US, Canada, Japan and Australia, with no mainland-China region. Maestro is not a suite you install on infrastructure you choose; there is no customer-run, in-country deployment. For a China operation that means the data is, by default, processed and stored outside the mainland — which is precisely where Chinese law starts asking questions.

The doors: cross-border personal data, important data, and in-country storage

Once Maestro holds your China operation’s data offshore, three bodies of law decide whether that was allowed.

First, personal information. The planner, approver and supplier contacts in Maestro are personal information under China’s PIPL, and holding them in an offshore instance is a cross-border transfer (数据出境). PIPL puts the duty on you, the handler — not on Kinaxis: Articles 38–40 require notice, a separate consent for the overseas transfer, and one lawful transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), while Articles 13 and 23 govern the consent itself.

Second — and this is the half a pure personal-data analysis misses — the supply-chain data itself. Supply-network maps, logistics and inventory, production and capacity, and consolidated sourcing data can be classified as “important data” (重要数据) under the Data Security Law, especially in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy, food and logistics. Exporting important data triggers a mandatory CAC data-export security assessment before anything leaves the country — regardless of whether personal information is involved, or how much. Whether your supply-chain data is important data turns on your sector and the applicable national and sectoral catalogs, so it is a risk to assess, not a blanket rule.

Third, residency. If your organization is a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information generated in China to be stored in China — an in-country duty an offshore Maestro instance cannot satisfy. Which of these doors bite your specific deployment turns on your sector, your data volumes and your role under Chinese law.

Logging in isn’t the question — a compliant in-country supply chain is

The fix is not to make an offshore Maestro instance load faster from the mainland — it is to put the China supply-chain and supplier data where the law needs it and to handle what leaves lawfully. Because Maestro is cloud-only, the lever is not self-hosting it in China; it is keeping the China data on an in-country path, classifying it so you know what is “important data,” minimizing what crosses the border, and completing the CAC data-export security assessment or other mechanism for anything that does. That is localization in the real sense — keeping the data on an in-country footing — not a tunnel that ships it offshore anyway. Any supplier- or partner-facing surface you publish in the mainland — a supplier collaboration portal, an onboarding page — is an internet information service and carries an ICP filing (备案) duty bound to a mainland hosting resource, plus compliant in-country delivery. None of this is a verdict that Kinaxis is “blocked” or “illegal” in China — Maestro can run there lawfully when the pieces line up. It is a residency-and-exposure map, and which path fits turns on your entity, your sector and your data — worth settling the specifics with counsel before your China supply chain depends on it.

The lawful path — map, localize, deliver

There is a compliant way to run supply-chain planning for a China operation, and it has a shape. First, map: our China team inventories what your Maestro environment holds — the supplier and planner personal information, and the demand, inventory, logistics and supply-network data — where each is processed and stored today, whether any of it is “important data” (重要数据), the data-path options open to you, and the consent, residency and assessment basis each transfer would need. We build the technical picture; the legal conclusions are settled with counsel.

Then localize: we help you keep the China supplier and supply-chain data in-country — on an in-country data path — classify it, handle any important-data and data-export-assessment duty, and minimize and obtain the Article 13/23 consent for the supplier and employee personal information. Localize means keeping the data on an in-country path, never moving it across the border by stealth.

Then deliver: any China-facing surface on top of the stack — a supplier portal, an SRM page — needs compliant, in-country delivery and carries an ICP filing duty. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and classify and assess the supply-chain data that may be important data before any of it moves.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Kinaxis have a data center in mainland China?
No. Per its Trust Center, Kinaxis hosts customer data in North America, Europe and Asia, and its listed public-cloud regions are the EEA, US, Canada, Japan and Australia — none in mainland China. So a China operation's supplier and supply-chain data held in Maestro is stored offshore, which is where PIPL's cross-border rules and the Data Security Law begin to apply.
Is our supply-chain data really "important data" under Chinese law?
It can be — it is not automatic. Whether your supply-network maps, logistics, inventory, production/capacity and consolidated sourcing data count as "important data" (重要数据) turns on your sector and the applicable national and sectoral catalogs; manufacturing, automotive, pharmaceuticals, energy, food and logistics are higher-risk. If it is classified as important data, a CAC data-export security assessment is mandatory before it leaves the country — a point to settle with counsel.
Can 21YunBox just make Kinaxis faster or reachable in China?
That is not the question that decides this. The exposure is residency and cross-border transfer, not reachability. We map what Maestro holds and where it runs, keep your China supplier and supply-chain data on an in-country path, help classify and handle any important data, and ICP-file any China-facing surface such as a supplier portal — a compliant overlay in front of your stack, delivered in-country, never moving data across the border by stealth.

ARTICLES RELATED TO KINAXIS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.