Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does LivePerson Work in China? PIPL Cross-Border, Data Residency & Consent

LivePerson's Conversational Cloud is enterprise conversational AI hosted offshore in US and European data centers, with no mainland-China region — so your China customers' chats and profiles rest abroad as a PIPL cross-border transfer, the embedded web-messaging tag ships visitor data offshore before consent, and its AI auto-answers and routes customers as an automated decision. A compliance-first look at the residency, consent and automated-decision exposure.

Does LivePerson work in China?

What decides LivePerson in mainland China isn't whether the chat window loads — it's that your China customers' conversations and profiles sit on an offshore conversational-AI platform with no mainland-China region, the embedded web-messaging tag ships visitor data offshore before consent, and its AI auto-answers and routes customers as an automated decision, so the support surface needs an ICP filing and a lawful in-country path.

LivePerson's Conversational Cloud stores the transcripts, identifiers and profiles its bots, Routing AI Agents, KnowledgeAI answers and Conversation Copilot handle on US and European data centers — never the mainland — and its own privacy notice says it may “transfer your personal data outside of your country of origin,” on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. That makes serving Chinese customers a PIPL cross-border transfer (Articles 38–40), the embedded tag a PIPL Article 13/23 consent problem because it fires on page load, and the AI an Article 24 automated decision; for a CIIO or high-volume handler, in-country storage is owed (Cybersecurity Law Article 39 (formerly Article 37)). The lawful lever is to keep the conversations and PII in-country, gate and consent the tag, meet the Article 24 duties, and ICP-file the surface — not to make the offshore widget reachable.

This is a risk map, not a verdict — settle the specifics with counsel against what you actually run. Our China team can map your exposure →

What LivePerson's own documentation says about China

FactPrimary source
LivePerson transfers your personal data across borders and runs no mainland-China region. Its own privacy notice states that, “as a company that operates globally,” it may “transfer your personal data outside of your country of origin,” and that “by providing or making available your personal data, you consent to that transfer.” Those transfers run on the “Standard Contractual Clauses (“SCCs”)” and the EU-U.S. Data Privacy Framework, under which LivePerson “is subject to the investigatory and enforcement powers of the United States Federal Trade Commission” — a US-anchored model with no option to keep China-collected conversations on mainland soil. LivePerson — Privacy Notice (policies.liveperson.com), retrieved 2026-10-10
LivePerson's AI makes automated decisions about customers — a PIPL Article 24 matter. Conversational Cloud ships “Routing AI Agents” that “Route Consumers Conversationally,” “KnowledgeAI Agents” to “Automate Enriched Answers,” Conversational AI bots, and Conversation Copilot, whose automated conversation summaries are “LLM-powered” and, once generated, “aren't editable.” Where that AI auto-answers, routes or scores a customer, PIPL Article 24 requires transparency, fairness, and a route to a human decision. LivePerson Developers — Conversational AI capabilities; LivePerson Customer Success Center — Overview of Conversation Summaries, retrieved 2026-10-10
Serving China customers on LivePerson is a PIPL cross-border transfer by you, the handler. Because the conversations, transcripts and profiles are collected from mainland users and stored offshore, the flow is governed by PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). The embedded web-messaging tag that sends visitor data on page load adds a PIPL Article 13/23 consent duty, since it fires before the visitor agrees. PIPL Articles 38–40 (cross-border) and 13 & 23 (consent)
A CIIO or high-volume handler owes in-country storage LivePerson cannot provide. China-collected personal information must stay in the mainland for a critical information infrastructure operator or a large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). A managed SaaS hosted only on US and European data centers, with no self-host and no mainland-China region, has no way to meet that duty. Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a China-facing support operation, the question about LivePerson is not whether the chat window paints or the Conversational Cloud workspace opens — it is where your customers’ conversations are allowed to live, what the embedded web-messaging tag sends the moment a mainland visitor loads the page, whether the platform’s AI is deciding things about those customers, and whether the public support surface is filed. LivePerson is an enterprise conversational-AI platform — bots, Routing AI Agents, KnowledgeAI answers, and Conversation Copilot — on a managed cloud in US and European data centers, with no mainland-China region and no self-host. So a rollout meets four doors at once: a cross-border transfer of the conversations and profiles it stores, an embedded tag that ships visitor data offshore before consent, AI that auto-answers and routes customers, and an ICP filing for the support surface. Not one of them turns on latency.

LivePerson's privacy notice stating that it operates globally and may transfer your personal data outside your country of origin, on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework, with no mainland-China region
"we may transfer your personal data outside of your country of origin. By providing or making available your personal data, you consent to that transfer." LivePerson's own privacy notice, whose transfers run on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework — a US-anchored model with no mainland-China region to keep your China customers' conversations in. Source: LivePerson — Privacy Notice

LivePerson in China at a glance

What decides it In LivePerson's own terms — and China's law
What it holds LivePerson Conversational Cloud — enterprise conversational AI across web, app and messaging channels: bots and Conversational AI, Routing AI Agents, KnowledgeAI answers, Conversation Copilot, and automated conversation summaries. It stores the chat transcripts, the customer's identifiers and profile, the engagement signals its tag collects, and whatever a customer discloses mid-conversation — personal information under China's law, not anonymous telemetry.
Where those conversations live A managed SaaS hosted on offshore US and European data centers, with no mainland-China region and no self-host. Its own privacy notice says LivePerson may "transfer your personal data outside of your country of origin," on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. For your China customers that is a cross-border transfer under PIPL Articles 38–40 (数据出境): notice, a separate consent, and one transfer mechanism.
AI that decides about customers (Article 24) LivePerson ships AI that auto-answers, routes and scores conversations — Conversational AI bots, Routing AI Agents that "Route Consumers Conversationally," KnowledgeAI that automates answers, and Conversation Copilot with automated, "LLM-powered" summaries that "aren't editable." Where that AI makes or materially drives a decision about a customer, PIPL Article 24 adds transparency, fairness, and a route to a human.
The embedded tag, consent, and residency The web-messaging window loads as embedded third-party JavaScript on your China-facing pages and sends the visitor's page activity and engagement signals to LivePerson's offshore platform as the page loads — a transfer plus a PIPL Article 13/23 consent problem, because it fires before the visitor agrees. In-country storage can also bite for a CII or high-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged).
The lawful path Reachability is not the axis. Map the conversation, profile, widget and AI exposure; keep China-customer conversations and PII in-country and minimize what is collected; gate and consent the embedded tag; meet the Article 24 duties for the AI; and deliver any China-facing support surface over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the LivePerson stack you already run — never a tunnel that ships the same data offshore under another name.

What you actually hold — conversations, customer profiles, and a widget that phones home

A support conversation is built from exactly the data China’s law protects. Every LivePerson interaction carries the customer’s identifiers and profile and the full transcript of what they say — an order reference, an address, an account dispute, a health or payment detail volunteered to resolve a ticket — stored on the Conversational Cloud along with the enrichments the platform layers on top: the intent it infers, the routing decision, the automated summary, the conversation score. None of that is anonymous telemetry; it names, contacts and profiles individual people, which is personal information under China’s Personal Information Protection Law. LivePerson is a managed SaaS: there is no self-host build and no mainland-China region to point an in-country install at, so the records of your China conversations are written offshore the moment they are captured.

Two of those facts are distinctive, and both matter more than whether the chat connects. First, LivePerson’s web-messaging window is embedded third-party JavaScript — its tag loads on your China-facing page and begins sending the visitor’s page activity and engagement signals to LivePerson’s offshore platform as the page renders, before the visitor has agreed to anything. Second, LivePerson is, in its own words, AI that decides: Routing AI Agents that “Route Consumers Conversationally,” KnowledgeAI that automates answers, Conversational AI bots that deflect and resolve, and Conversation Copilot, whose automated conversation summaries are “LLM-powered” and, once generated, “aren’t editable.” Each of those is the platform acting on a customer’s data without a person in the loop — the material that PIPL Article 24 governs.

The lead door is cross-border transfer. Sent from or about a person in China to a platform operated offshore, the transcript, the customer profile, and the engagement record are a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境): the handler — the business running the support desk, not only LivePerson — owes notice, a distinct cross-border consent, and one approved transfer mechanism, which for a CII or high-volume handler can mean a CAC security assessment. LivePerson’s own privacy notice confirms the shape of the flow: it “operates globally,” “may transfer your personal data outside of your country of origin,” and does so on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework — safeguards built for export, not for keeping China data on mainland soil.

The second door is the embedded tag. A live chat widget on your China site is not a passive button: it is third-party JavaScript that ships the visitor’s page activity, device and engagement signals, and the messages they type to LivePerson’s offshore infrastructure on page load — a transfer that fires before any consent banner is answered, which is both a cross-border movement and a PIPL Article 13/23 consent problem. It cannot be fixed by making the offshore endpoint reachable; it has to be gated and consented, minimized, or replaced with an in-country path.

The third door is automated decisions. Wherever LivePerson’s AI auto-answers, routes, deflects or scores a customer — the Conversational AI bots, the Routing AI Agents, the KnowledgeAI answers, the Copilot summaries that feed a hand-off — PIPL Article 24 attaches its own duties: transparency about the automated processing, fairness in the outcome, and a route for the customer to a human decision. And in-country storage can be required outright for a CII or high-volume handler under Cybersecurity Law Article 39 (formerly Article 37). None of this is softened by how quickly the chat window opens.

Loading the widget isn’t the question — a compliant in-country support path is

It is tempting to treat a China rollout as a connectivity problem, but reachability was never the deciding variable here. LivePerson can mask a field, redact a segment, or shorten retention — each narrows what is kept, and none changes that it crosses, because the region on offer is always offshore and there is no mainland-China deployment to anchor an in-country install to. The lawful shape is different in kind: keep the China-customer conversations, transcripts and profiles that must stay on mainland soil in-country and minimize what is collected; gate and consent the embedded web-messaging tag so it does not ship a visitor’s data on load without a basis; meet the Article 24 duties for any AI that answers, routes or scores a customer; and file the public support surface — a lawful, in-country path for the data and the AI, never a tunnel that ships the same records offshore under another name. Because the specifics — whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, and how the renumbered Cybersecurity Law Article 39 (formerly Article 37) bears on you — turn on facts only your team and your counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.

The lawful path — map, localize, deliver

Running customer support for Chinese users the lawful way has a shape, and it keeps LivePerson where it already runs. 21YunBox is a compliant overlay, not a migration, and for an enterprise platform like LivePerson we are a partner to it, not a competitor. We map your exposure first — reading the PIPL cross-border, data-residency, embedded-tag consent, and Article 24 automated-decision obligations against your entity, your conversation and profile volumes, and who your customers actually are, so you know exactly what counsel needs to confirm. We localize what must stay on mainland soil — standing up consented, in-country processing and storage for the conversations, transcripts and profiles that cannot lawfully sit offshore, minimizing what the embedded tag collects and gating it behind a lawful basis, and meeting the Article 24 duties for the AI that answers and routes. And we deliver every China-facing support surface — the help center, the chat page, the widget host — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the LivePerson stack you already run, with no rebuild and no second codebase. The result is a support stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Where does LivePerson store our Chinese customers' conversations?
Outside mainland China. LivePerson's Conversational Cloud is a managed SaaS hosted on US and European data centers, with no mainland-China region and no self-host, and its own privacy notice says it may “transfer your personal data outside of your country of origin,” on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. So the transcripts, identifiers and profiles your China customers generate are stored offshore — which is what turns a routine integration into a cross-border-transfer question under PIPL.
Is LivePerson's AI a problem under China's law?
It is a specific duty to meet, not a flat yes or no. LivePerson ships AI that auto-answers, routes and scores conversations — Conversational AI bots, Routing AI Agents, KnowledgeAI answers, and Conversation Copilot summaries. Where that AI makes or materially drives a decision about a customer, PIPL Article 24 requires transparency about the automated processing, a fair outcome, and a route for the customer to a human decision. That sits on top of the cross-border-transfer and consent duties for the conversation data itself.
Can 21YunBox help run LivePerson compliantly in China?
Yes. Our China team can map your PIPL cross-border, consent and Article 24 exposure for your entity, your conversation and profile volumes, and your customers, then keep the China conversation data and profiles on a consented in-country path, gate and consent the embedded web-messaging tag, and stand up the ICP-filed, in-country delivery a compliant China support surface needs — in front of the LivePerson stack you already run, with no rebuild. Get in touch to work through your specific case.

ARTICLES RELATED TO LIVEPERSON

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.