Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does LogicGate Risk Cloud Work in China? GRC Data, PIPL & Data Residency

LogicGate Risk Cloud is the GRC platform you run to govern risk — and its own sub-processor list hosts that data on AWS in the US, EU, UK or Australia, with no mainland-China region. For China users that turns your risk registers, audit evidence and third-party and owner PII into a PIPL cross-border transfer. A compliance-first look at the exposure, and the lawful in-country path.

Does LogicGate work in China?

Risk Cloud is reachable from China, but LogicGate hosts your GRC records on AWS in the US, EU, UK or Australia — never the mainland — so running it for people in China is a PIPL cross-border transfer, not a speed problem.

Risk Cloud holds risk registers, third-party and audit records, and the PII of control owners, risk owners, auditors and counterparties; some incident, investigation or privacy records can be sensitive personal information under PIPL Article 28. Because none of LogicGate's four AWS regions is in China, that data comes to rest offshore, triggering PIPL cross-border obligations (Articles 38–40) and, for CII or large-volume handlers, an in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). 21YunBox maps the exposure with your counsel and stands up consented, ICP-filed, in-country storage and delivery for the records that must stay on the mainland.

What LogicGate Risk Cloud's own documentation says about China

FactPrimary source
LogicGate's sub-processor list names Amazon Web Services (AWS) as its hosting platform and gives the Risk Cloud data location as a customer's choice of "US, EU, UK, AU" — no mainland-China region is listed. LogicGate Subprocessors & Affiliates (Effective: August 2024)
LogicGate's Trust Center tells customers to "Choose from these four data centers to host your Risk Cloud Data," offering "greater control over data residency and compliance needs" — the four being US, EU, UK and Australia, none on the mainland. LogicGate Risk Cloud Trust Center
Personal information on people in China that is processed on offshore infrastructure is a cross-border transfer under PIPL Articles 38–40, requiring notice, a separate consent, and a cleared mechanism (a CAC security assessment, the CAC standard contract, or certification). Personal Information Protection Law (PIPL), Arts. 38–40
For critical information infrastructure operators, personal information and important data collected in China must be stored in the mainland under Cybersecurity Law Article 39 (formerly Article 37); the 2025 amendment, in force January 1, 2026, renumbered the provision with its substance unchanged. Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a team in mainland China, the question about LogicGate Risk Cloud is not whether the dashboard opens — it loads over the public internet like any SaaS. The question is where the records it keeps are allowed to come to rest. Risk Cloud is the system a company runs to govern risk itself: enterprise and operational risk registers, third-party and vendor-risk assessments, control libraries and audit evidence, regulatory-compliance mappings, policies, and the contact details of the control owners, risk owners, auditors and third-party counterparties behind every workflow. All of that is personal information once it names identifiable people, and some of it is sensitive. LogicGate hosts it on Amazon Web Services, and its own sub-processor list gives the location as a customer’s choice of US, EU, UK or Australia — four offshore regions, none inside mainland China. That is a data-residency and cross-border question under Chinese law, not a speed one, and LogicGate answers it in its own documents.

LogicGate's public sub-processor list naming Amazon Web Services (AWS) as the hosting platform, with the data location given as a customer's choice of US, EU, UK, AU — naming no mainland-China region
On its public sub-processor list, LogicGate names "Amazon Web Services (AWS)" as the platform host and gives the data location as a customer's choice of "US, EU, UK, AU" — four offshore regions, none inside mainland China, so a Chinese user's Risk Cloud records come to rest outside the country. Source: logicgate.ai/subprocessors

LogicGate Risk Cloud in China at a glance

What decides it In LogicGate's own terms — and China's law
Where the records live LogicGate's sub-processor list names Amazon Web Services (AWS) as its hosting platform and gives the location as a customer's choice of "US, EU, UK, AU." Its Trust Center frames this as four data centers to "Choose from." Every option is offshore relative to China; none is inside the mainland.
What it holds & why it's PI Risk registers, third-party and vendor-risk assessments, controls and audit evidence, regulatory mappings and policies — plus the names and contact details of control owners, risk owners, auditors and third-party counterparties and signatories. Under PIPL those identifiers are personal information, and incident, investigation or privacy records that name people can be sensitive.
Your China users' data Personal information on people in China that is processed in an offshore AWS region is a cross-border transfer PIPL governs (Articles 38–40): notice, a separate consent naming the overseas recipient, and one cleared transfer mechanism before it leaves.
In-country storage duty For a critical information infrastructure operator or a large-volume handler, personal information collected in China must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). A customer's choice of US, EU, UK or AU cannot meet that duty.
Reachability is not the axis That the dashboard loads settles nothing. A China-facing surface — a Risk Cloud dashboard, attestation portal or third-party intake form shown to mainland users — is a public service that needs an ICP filing bound to mainland hosting LogicGate does not provide.

No mainland region, so your GRC records leave the country

LogicGate is unusually clear about where Risk Cloud lives. Its sub-processor list names Amazon Web Services as the hosting platform and gives the data location as a customer’s choice of “US, EU, UK, AU,” and its Trust Center invites customers to “Choose from these four data centers to host your Risk Cloud Data,” describing this as “greater control over data residency and compliance needs.” That control is real — and for most multinationals it is a genuine strength. It is also precisely the mismatch for China: all four regions are offshore relative to the mainland, and LogicGate publishes no Chinese region at all. So for a user or an employee in China, the risk, audit and third-party records tied to them come to rest in the United States, Europe, the United Kingdom or Australia — outside the country.

Processed offshore, that personal information is a cross-border transfer, and the obligation lands on the personal-information handler — you, the customer, not LogicGate. You owe notice, a separate consent for the overseas transfer, and one cleared mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Above certain volumes, or where the records count as important data, the move can also require China’s data-export security assessment before anything leaves. Choosing the AWS region closest to your governance footprint does not change any of this; it only picks which offshore country the data sits in.

Risk, audit and third-party records are personal information — and some are sensitive

The uncomfortable part is structural. Risk Cloud is the tool you deploy to run compliance — and in doing so it accumulates a dense store of personal information. Third-party and vendor-risk assessments carry counterparty contacts and signatory details; control and audit workflows carry the names of the control owners, risk owners and auditors accountable for each item; LogicGate’s own “Automated Evidence Monitoring” pulls in the artifacts behind an attestation. Under PIPL, those names, roles, email addresses and online identifiers are personal information the moment they describe an identifiable person — and exporting them to an offshore region is the transfer the previous section describes.

Some of it goes further. Where a customer uses Risk Cloud to track incidents, investigations, data-subject or data-privacy requests, or assessments that name identifiable individuals or hold financial or identity data, those records can be sensitive personal information under PIPL Article 28 — which demands a specific purpose, strict necessity, a heightened separate consent, and a personal-information protection impact assessment before processing. LogicGate’s opt-in generative-AI features add one more offshore flow: its sub-processor list places OpenAI, L.L.C. in the United States for “data analysis, automated reporting, insights generation, and personalized recommendations,” so turning those on routes GRC content to another US recipient. And at a critical information infrastructure operator — in finance, energy, telecoms or similar — some risk and control records can themselves describe critical systems. The irony is plain: the platform you bought to govern compliance becomes a PIPL exposure of its own.

Narrowing the exposure doesn’t close the door

There are levers that reduce what crosses. You can select the EU, UK or AU data center nearest your governance footprint, minimize and redact fields, confine identifiable data to a subset of applications, and switch off the opt-in AI and analytics sub-processors so fewer recipients touch the data. Each of these is worth doing, and each shrinks the payload and the number of hands it passes through.

But they change what crosses, not that it crosses. None of LogicGate’s four AWS regions is in mainland China, so a Chinese user’s records still leave the country, and the residency duty is unaffected: for a CII operator or large-volume handler, personal information collected in China must be stored on the mainland under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) — the data-localization provision; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered it from 37 to 39, its substance unchanged. Reachability is a separate matter, and for a China-facing surface it bites independently: if you expose a Risk Cloud dashboard, an attestation portal or a third-party intake form to users inside the mainland, that surface is a public service that carries an ICP filing duty (ICP 备案, under State Council Order No. 292 and MIIT Order No. 33) bound to a mainland hosting resource LogicGate does not offer. Whether the page loads quickly is not the question, and we publish no first-party China latency figure here, because speed is not the axis this turns on. This is a risk map, not a ruling: whether you owe a separate consent, a transfer mechanism, in-country storage, a data-export assessment, an ICP filing, or some combination turns on your entity, your data volumes and who your users are — settle the specifics with counsel before you rely on it.

The lawful path — map, localize, deliver

There is a compliant way to run a GRC platform for a China-facing audience, and it has a defined shape. First, map: our China team works through the PIPL cross-border, sensitive-PI and residency obligations that attach to the risk, audit, third-party and owner records Risk Cloud holds — against your entity, your data volumes and who your users are — and marks where a separate cross-border consent, a data-export assessment, an Article 28 impact assessment or an Article 39 storage duty applies. The legal calls are made with counsel; we build the technical picture those calls rest on.

Then localize: for the records that must stay in the country, we stand up and integrate consented, in-country processing and storage — the lawful pattern of on-mainland storage with separate consent captured the way China’s regime expects — so what cannot lawfully leave no longer does, while you keep Risk Cloud for the markets where it already serves you.

Then deliver: any China-facing surface — the dashboard, attestation portal or intake form your mainland users touch — is a public service in the mainland, so it carries an ICP-filing duty and needs compliant, in-country delivery. 21YunBox delivers it from inside the mainland over ICP-filed, in-country infrastructure — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no second codebase. 21YunBox is a compliant overlay, not a migration, and a partner to LogicGate, not a competitor. One thing 21YunBox never does, and that no lawful provider can offer, is route around China’s data-export rules or any network restriction: 21YunBox never uses or suggests circumvention of any kind. The outcome is a GRC setup that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is LogicGate Risk Cloud blocked in China?
Reachability is not the compliance question. Risk Cloud is cloud SaaS reached over the public internet; the issue is that LogicGate hosts the records it holds on AWS in the US, EU, UK or Australia, with no mainland-China region. For people in China, storing and processing their personal information in those offshore regions is a cross-border transfer governed by PIPL, whatever the page-load speed.
Where is LogicGate Risk Cloud data stored, and is there a China region?
LogicGate's sub-processor list hosts Risk Cloud on Amazon Web Services and gives the data location as a customer's choice of US, EU, UK or AU; its Trust Center frames this as four data centers to choose from. None of the four is in mainland China, so there is no in-country option to select.
Does running LogicGate for a China team trigger PIPL cross-border rules?
If Risk Cloud holds personal information about people in China — control and risk owners, auditors, third-party counterparties and signatories — then exporting it to an offshore AWS region is a cross-border transfer under PIPL Articles 38–40, needing notice, separate consent and a cleared transfer mechanism, and possibly a data-export security assessment above certain volumes. Some incident, investigation or privacy records may also be sensitive personal information under Article 28. 21YunBox can map the exposure with your counsel and stand up consented, in-country storage for the records that must stay on the mainland.

ARTICLES RELATED TO LOGICGATE RISK CLOUD

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.