Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Linear Work in China? Data Residency, Cross-Border PII & ICP

Linear is a reachable cloud app, but that was never the China question. Linear stores each workspace in the United States or the European Union — never mainland China — and by its own documentation a defined subset of data (workspace and account info, API keys, usage and analytics, notification emails) is always stored in the US whichever region you pick. So the issues, project content, attachments and team-member identities a China-facing team keeps in Linear sit offshore — a cross-border transfer of personal information under PIPL, with an in-country storage duty for some handlers under the Cybersecurity Law's Article 39 (formerly Article 37), and an ICP filing for any public China-facing surface. A compliance-first look at the data-residency question and the lawful in-country path — with no circumvention of any kind.

Does Linear work in China?

Linear is a cloud app you can reach, but reachability was never the China question. What decides it is where your issues, project content, attachments and team-member identities live — and Linear stores them offshore. At workspace creation you pick one region, the "United States" or the "European Union," and neither is mainland China.

By Linear's own documentation a defined subset — workspace and account information, API keys, usage and analytics data, and notification emails — is "always stored in the United States" no matter which region you choose, and the region "isn't self-serve to change later." So the personal information your China users generate in Linear rests outside the mainland, which makes its collection a cross-border transfer under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–40), possibly subject to the data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) requires that data to stay in China — a duty no Linear region meets.

21YunBox maps your cross-border and residency exposure, localizes the China-resident data onto an in-country store (sending Linear only what may lawfully leave), and delivers any China-facing surface in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Linear's own documentation says about China

FactPrimary source
Linear stores each workspace in the US or the EU — and offers no mainland-China region. Under "Data regions," Linear's documentation says: "When creating a new workspace, you have the option to select the region where you want your data to be stored," and lists the available options as "United States" and "European Union." Neither is in mainland China, and Linear notes the setting "isn't self-serve to change later." Linear Documentation — Security, "Data regions" (linear.app), retrieved 2026-10-09
A defined subset of data is always stored in the United States, whichever region you choose. Linear's documentation states: "Regardless of the region you select for your workspace, the following data is always stored in the United States:" — naming workspace and account information, user-created API keys, usage and analytics data, and notification emails. So even the EU region does not keep all data out of the US, and none of it is in China. Linear Documentation — Security, "Data regions" (linear.app), retrieved 2026-10-09
Linear's own privacy terms and DPA place hosting and processing in the United States. Linear's Privacy Policy states that "The Services are hosted and operated in the United States ("U.S.") through Linear and its service providers," and that by using them "you authorize Linear to transfer, store and process your information to and in the U.S., and possibly other countries." Its Data Processing Agreement adds that Linear's "primary processing operations take place in the United States" and lists its sub-processors across the US and EU — none in mainland China. Linear Privacy Policy and Data Processing Agreement (linear.app), retrieved 2026-10-09
China-collected personal data sent to an offshore workspace is a PIPL cross-border transfer. Moving personal information collected from users in mainland China to a Linear workspace hosted in the US or EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty no Linear region can meet. Personal Information Protection Law of the PRC, Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

The first instinct with a tool like Linear is to ask whether it is fast enough from Shanghai or Shenzhen — whether the app loads, whether a board stays snappy. For a China-facing team that is the wrong first question. Linear is a cloud service reached over the public internet, and even on a day it loads perfectly, whether you may use it for your mainland users is settled somewhere else entirely: in where the issues, project content, attachments and the identities of the team members themselves are allowed to live.

That makes this a compliance question before it is a performance one. Linear stores each workspace’s data outside mainland China — you choose a United States or a European Union region when the workspace is created — and that single fact sets off the chain that actually governs a China-facing deployment: cross-border transfer of personal information, data-residency duties for certain handlers, and an ICP filing for any surface served to the public in the mainland. And to be unambiguous from the outset: where a cloud service is hard to reach from China, the only ways to force a connection are forms of circumvention, which are themselves non-compliant and which 21YunBox never uses or suggests.

Linear's own Security documentation under the heading 'Data regions', stating that when creating a new workspace you can select the region where your data is stored, with the available options listed as United States and European Union, and that regardless of the region selected a defined set of data is always stored in the United States — mainland China absent from the options
Linear's own Security documentation, under “Data regions”, states: “When creating a new workspace, you have the option to select the region where you want your data to be stored” — the available options being “United States” and “European Union” — and “Regardless of the region you select for your workspace, the following data is always stored in the United States:”. Mainland China is not among the regions Linear offers, and Linear notes the setting “isn't self-serve to change later.” Source: linear.app/docs/security — Data regions

Linear in China at a glance

What decides it In Linear's own terms — and China's law
What it is Linear is issue tracking and project management for product teams — issues, projects, documents, attachments, and the identities of the team members who use it. There is no Linear region or entity inside mainland China.
Where your workspace data lives Offshore. At workspace creation you pick one region — Linear's documentation names only “United States” and “European Union” — and neither is mainland China. Linear adds that the choice “isn't self-serve to change later.”
What stays in the US no matter what Even if you pick the EU region, Linear says “regardless of the region you select for your workspace, the following data is always stored in the United States” — workspace and account information, user-created API keys, usage and analytics data, and notification emails.
Putting China-collected data in that workspace A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. It may trigger China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore workspace cannot meet.
Sub-processors Linear's Data Processing Agreement lists its sub-processors across the US and EU — none in mainland China — and describes the database as “managed by Google Cloud Platform.” There is no in-country Linear processor to localize onto.
The lawful path Keep China-resident issues, attachments and team-member identities in-country, send Linear only what may lawfully leave, and serve any China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention.

Where your Linear data lives — a region you choose, but never mainland China

With Linear the data-location story is more detailed than a simple “US-hosted,” and it is worth getting right. Linear does offer a residency choice: in its own documentation, under “Data regions,” it says, “When creating a new workspace, you have the option to select the region where you want your data to be stored,” and the available options are “United States” and “European Union.” That is the whole menu — there is no mainland-China region, and Linear notes the choice “isn’t self-serve to change later.”

So far this reads like a genuine residency control, and for a US or EU team it is. For a China-facing team it is not, for two reasons. First, neither option is in China, so whichever you pick, the issues, documents and identities your mainland users generate come to rest offshore. Second — the part that is easy to miss — Linear states that “regardless of the region you select for your workspace, the following data is always stored in the United States,” and then lists workspace and account information, user-created API keys, usage and analytics data, and notification emails. Even the EU region, in other words, does not keep everything out of the United States. There is simply no configuration of Linear that holds a China team’s data in the mainland. Its own Data Processing Agreement is consistent with this: it lists Linear’s sub-processors across the US and EU — none in mainland China — and describes the database as “managed by Google Cloud Platform.”

China-collected issues and identities are a cross-border transfer

Here is the gate most teams miss. Everything a mainland colleague puts into Linear — an issue and its description, a comment, a document, an uploaded file, their own account identity — is stored in the workspace region you chose, and that region sits in the United States or the European Union. So the ordinary act of a China-based teammate filing a ticket places personal information collected in China onto storage outside the country. Under China’s Personal Information Protection Law that is a cross-border transfer (数据出境), and the duty falls on the handler — you, not Linear.

PIPL Articles 38–40 require notice, a separate consent distinct from a user’s agreement to use the product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Where the data crosses the regulator’s volume thresholds, or includes “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves the country.

And if your organization is a critical information infrastructure operator, the Cybersecurity Law adds a harder duty. Its Article 39 — formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, with the obligation itself unchanged — requires that personal information and important data collected and generated in the mainland be stored in the mainland. No Linear workspace region can satisfy that, because Linear offers only a US region and an EU region, and a defined subset of data stays in the US even when you pick the EU. None of this turns on how quickly a board loads; it turns on whether the data had a lawful basis to be outside the country at all. Which of these obligations bite on your specific workspace is a risk to confirm with counsel against what you actually collect and store.

A China-facing surface built around Linear still needs in-country footing

Issue tracking is often internal, and if Linear is only ever used by your own team, the pressing question is the data-residency one above. But the moment any surface tied to that workflow is exposed to mainland visitors — a public roadmap, a customer request or feedback board, a shared project view embedded in a China-facing site — you are serving the public in China, and that turns on an ICP filing (备案) bound to a hosting resource physically in the mainland. Linear names no mainland region to attach such a filing to, so the in-country footing has to come from somewhere Linear does not provide.

This is a risk map, not a verdict: whether an ICP duty, a transfer mechanism, in-country storage, or some combination applies to you depends on what you expose, your role as handler, and your data volumes — worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

Running Linear for a China-facing team has a lawful shape, and it is a sequence, not a switch.

Map. Our China team works through what your Linear workspace actually holds for people in the mainland — the issues and their text, project and document content, uploaded attachments, and the identities of the team members themselves — and sorts it against your PIPL cross-border duties and any data-residency obligation: which personal information must stay in-country, which may lawfully be transferred, and whether a data-export security assessment or an Article 39 storage duty is in reach. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.

Localize. For the data that has to stay, the answer is not a Linear region — there isn’t one in China — but an in-country, consented store that holds what must remain in the mainland, with only what may lawfully leave flowing on to the Linear workspace your global team already lives in. 21YunBox stands up and integrates that China-resident option in place of the storage that cannot sit inside Linear compliantly, so the team’s day-to-day workflow is preserved while the mainland data stops being carried out of the country by default.

Deliver. Any surface you actually expose to mainland users around that workflow — a customer portal, a public roadmap, an embedded status view — is a public service in China and carries an ICP filing (备案) duty with compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is an issue-tracking and project workflow that runs legally and compliantly for your users in China. What we never do, because no one lawfully can, is reach a service around a network block: we localize what must stay and deliver in-country, and a network workaround is never on the table.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Can I keep my China team's Linear data inside China?
No. Linear lets you choose only a United States or European Union region when a workspace is created — there is no mainland-China region, and Linear says the setting "isn't self-serve to change later." It also states that a defined subset of data (workspace and account information, API keys, usage and analytics, and notification emails) is "always stored in the United States" regardless of the region you pick. So there is no Linear setting that keeps China-collected data in the mainland; keeping it in-country means holding that data outside Linear. Treat the specifics as a risk to confirm with counsel.
Is putting China users' issues and data in Linear a cross-border transfer?
If your workspace is in the US or EU — anywhere outside the mainland — then the issues, project content, attachments, and team-member identities it holds for your China users rest offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and above the regulator's thresholds or for "important data" it may require China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty no Linear region can meet. Which obligations apply to your data is a question for counsel.
Can 21YunBox make Linear work compliantly for China?
Yes. Our China team maps the PIPL cross-border and data-residency obligations that attach to the China-collected issues, attachments, and identities in your Linear workspace, for your entity and data volumes; localizes the data that must stay in the mainland onto a consented, China-resident store while you keep Linear for everything that may lawfully leave; and delivers any China-facing surface in-country on ICP-filed infrastructure, in front of what you already run. Get in touch to work through your specific case — we never use or suggest circumvention of any kind.

ARTICLES RELATED TO LINEAR

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.