Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Looker Work in China? Data Residency, Localization & PIPL Cross-Border

Looker is Google Cloud's enterprise BI and data-modeling platform (the LookML semantic layer). Looker (Google Cloud core) runs only on Google Cloud, which has no mainland-China region — the nearest are Taiwan and Hong Kong — so an instance and its caches and result sets rest offshore. A compliance-first look at Looker data residency, localization and PIPL cross-border transfer.

Does Looker work in China?

Whether Looker "works" in China is first a data-residency question — where the data it models, caches and reports on is allowed to rest, not whether a dashboard loads.

Looker is Google Cloud's enterprise BI and data-modeling platform (the LookML semantic layer), distinct from the self-service Looker Studio. The flagship Looker (Google Cloud core) is Google-managed and runs only on Google Cloud, which has no mainland-China region — the nearest are asia-east1 (Taiwan) and asia-east2 (Hong Kong) — so the instance and the result caches, saved dashboards and scheduled-delivery extracts it holds come to rest offshore, and China personal information in it is a cross-border transfer PIPL governs. The older Looker (original) does offer a customer-hosted deployment you can run on mainland infrastructure — the in-country lever. For a CIIO or high-volume handler, China personal information must stay on the mainland (PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37) localization duty), which an offshore Looker instance cannot do.

This is a risk map, not a ruling — your obligations turn on your entity, data volumes and whose data Looker holds. Our China team can map your Looker data-residency exposure →

What Looker's own documentation says about China

FactPrimary source
Looker (Google Cloud core) runs on Google Cloud regions, and none are inside mainland China. Google's "Looker (Google Cloud core) locations" documentation says the listed locations "represent the geographical regions where a Looker (Google Cloud core) instance is hosted," and its Asia Pacific list places the nearest at asia-east1 (Taiwan) and asia-east2 (Hong Kong) — none on the mainland. An instance, and the query caches, saved dashboards and scheduled-delivery extracts it holds, therefore rest offshore. Google Cloud — Looker (Google Cloud core) locations, retrieved 2026-10-10
Core is fully Google-managed; a customer-hosted deployment exists only on Looker (original). Google's hosting-options documentation states that "A customer-hosted option is offered only for Looker (original) instances" and that this option "is not available for Looker (Google Cloud core) instances." Looker (original) is designed to be multi-cloud and can be hosted on-premises — a residency-flexible path you can run on mainland-China infrastructure to keep the analytics layer in-country. Google Cloud — Looker: choosing a hosting option, retrieved 2026-10-10
China personal information held in an offshore Looker instance is a cross-border transfer under PIPL. Where Looker (or the warehouse it caches from) holds the personal information of people in China and sits in an offshore region, the handler — you, the customer, not Google — must give notice, obtain separate consent and satisfy one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. PIPL Articles 38–40 govern that transfer, and the security-assessment measures set when the assessment is mandatory. PIPL Articles 38–40; CAC cross-border data measures
CIIOs and high-volume handlers must store China personal information on the mainland. PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) impose an in-country storage duty on critical-information-infrastructure operators and large-volume handlers; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged). Because a BI platform concentrates data from across the business, a Looker deployment can itself push a handler over the large-volume threshold — and an offshore instance structurally cannot meet the duty. The lawful levers are a licensed in-country deployment with the China-facing surface on ICP-filed delivery. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a team serving mainland China, the deciding question about Looker is not whether a dashboard renders or whether it can reach your data warehouse — both are routine. It is where the data Looker works with is allowed to come to rest. Looker is Google Cloud’s enterprise business-intelligence and data-modeling platform — the LookML semantic layer that queries your warehouse and builds the saved Looks, dashboards, scheduled deliveries and result caches your teams read from — and that content is, overwhelmingly, your customers’, users’ and employees’ personal information. The flagship, Looker (Google Cloud core), is Google-managed and runs only on Google Cloud, and Google Cloud has no mainland-China region: the nearest are asia-east1 (Taiwan) and asia-east2 (Hong Kong). So the instance, and the caches and result sets it holds, come to rest offshore. The older Looker (original) does offer a customer-hosted deployment — the in-country lever we return to below.

Google Cloud's Looker (Google Cloud core) locations documentation listing the Asia Pacific regions where a Looker instance can be hosted — asia-east1 in Taiwan and asia-east2 in Hong Kong — with no region inside mainland China
"These represent the geographical regions where a Looker (Google Cloud core) instance is hosted." Google Cloud's own locations list for Looker shows the nearest Asia Pacific regions as asia-east1 (Taiwan) and asia-east2 (Hong Kong), with no region inside mainland China. Source: cloud.google.com/looker/docs/looker-core-locations

Looker in China at a glance

What decides itIn Looker's own terms — and China's law
Where the data physically rests (the region reality)Looker (Google Cloud core) runs only on Google Cloud, and Google's locations list has no mainland-China region. The nearest Asia Pacific regions are asia-east1 (Taiwan) and asia-east2 (Hong Kong), both outside the mainland — so the instance and its query caches, result sets and saved content rest offshore.
What Looker holds, and why it is personal informationLooker models and reports on data pulled from across your business — customer records, user accounts, transactions, employee data. The result caches, saved Looks and dashboards, and scheduled-delivery extracts it builds are personal information under PIPL, some of it sensitive. Where they rest is a legal question, not a performance one.
Your China users' records when the instance is offshoreHold the personal information of people in China in an offshore Looker instance and you are making a cross-border transfer under PIPL (Articles 38–40): notice, separate consent, and one transfer mechanism — a CAC security assessment, the standard contract, or certification.
The in-country storage duty (CIIO / high-volume handler)A critical-information-infrastructure operator or high-volume handler must keep China personal information on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). A BI platform concentrates data, which can itself push a handler over the large-volume threshold; an offshore Looker instance structurally cannot meet the duty.
Reachability is not the axis (and the China-facing surface)Whether a dashboard loads from China is a delivery matter, not the legal test; data-at-rest residency is. The lawful levers are to run analytics in-country — a customer-hosted Looker (original) deployment on mainland infrastructure, or a licensed in-country equivalent — and to put any China-facing reporting surface on ICP-filed delivery.

Where the data actually rests

Looker comes in two shapes, and they answer the residency question differently. The flagship, Looker (Google Cloud core), is the fully Google-managed service: Google runs the instance within Google Cloud, and you pick its location from Google Cloud’s list when you create it. That list has no mainland-China region. The nearest Asia Pacific locations are asia-east1 (Taiwan) and asia-east2 (Hong Kong), both outside the mainland. (Hong Kong is Chinese territory, but it is treated separately from the mainland for data-localization purposes.) There is no China-region option to select — so a Core instance, by construction, sits offshore.

Looker is known for querying your warehouse in place rather than copying it wholesale, and that genuinely limits how much raw data lands in the platform. But it does not move the residency question off the table. The instance still holds a query result cache, your saved Looks and dashboards, the result sets of scheduled deliveries it emails or writes to storage, the LookML model and your user accounts — all in its Google Cloud region. And where you enable persistent derived tables, Looker materializes them into a scratch schema in the warehouse you connect, so that warehouse’s residency matters too. Either way, result sets that contain personal information come to rest somewhere — in the instance’s offshore region, or in whatever warehouse you point it at.

One clarification worth making: this page is about Looker, the enterprise BI and data-modeling platform Google acquired in 2020 — not the separate, self-service Looker Studio (formerly Google Data Studio). They share a brand, not an architecture, and the residency analysis here is Looker’s.

What it holds is personal information

A BI platform is a concentrator. It pulls from every source system — your warehouse, your transactional databases, your event streams — into one modeling and reporting layer, then builds extracts, in-memory models, result caches and scheduled-delivery outputs on top. That makes a Looker deployment one of the largest single concentrations of personal information a company holds: customer records, user accounts, transactions, support history, employee data. Most of it is personal information under PIPL, and some — contact, financial and identity data — is sensitive personal information that draws heightened duties.

That is why residency, not reachability, is the test. When the personal information of people in China rests in an offshore Looker instance — or in an offshore warehouse it caches from — you are making a cross-border transfer, and PIPL Articles 38–40 govern it: notice, separate consent, and one lawful transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The security-assessment measures set when that assessment is mandatory rather than optional.

On top of the transfer rules sits a harder duty. A critical-information-infrastructure operator or a high-volume handler must store China personal information inside the mainland — PIPL Article 40 and the data-localization rule in Cybersecurity Law Article 39 (formerly Article 37). Because BI concentrates data, a single Looker deployment can itself tip a handler over the large-volume threshold that triggers that duty. An offshore instance cannot satisfy it, because the data is, by definition, not in the country.

Running it on a no-China-region managed service doesn’t meet the residency duty — and what does

The fix is not to make an offshore Looker endpoint reachable from China. Reachability was never the problem; residency is. If your obligations require China personal information to stay on the mainland, the lawful lever is to run the analytics layer in-country.

Here the two Looker products diverge. Looker (Google Cloud core) offers no mainland-China region and no customer-hosting — Google’s own hosting documentation states that a customer-hosted option is offered only for Looker (original) — so for Core the in-country route means standing up a lawful in-country equivalent. Looker (original), by contrast, supports a customer-hosted deployment: software you operate on infrastructure you control, which you can place on mainland-China infrastructure so the modeling and result layer stays in-country, with the warehouse it reads from in-country too. Customer-hosted Looker (original) carries its own feature gaps versus the managed Core service, so weigh those — but the point stands: the engine runs where you deploy it, and nothing here is blocked.

Either way this is not a re-platforming project. You keep the stack you already run and place a compliant, in-country analytics layer where the data must live, then put the China-facing reporting surfaces — the dashboards and portals your mainland users open — on ICP-filed, in-country delivery in front of it. Localize means an in-country deployment, not a tunnel back to an offshore endpoint.

This page maps exposure; it is not a legal ruling. Your actual duties turn on your entity, how you classify the data, your transfer volumes and whether you are a critical-information-infrastructure operator — so settle those specifics with qualified China counsel before you rely on any single path.

The lawful path — map, localize, deliver

21YunBox is a compliant overlay, not a migration — and a partner to Google Cloud and to your analytics team, not a competitor to them.

  • Map. We read the PIPL cross-border, data-residency, data-localization (CII) and ICP obligations against your entity, your data volumes and whose personal information actually flows into Looker — so you know which duties bite before you move anything.
  • Localize. We run the analytics layer in-country so the personal information stays on mainland soil — a customer-hosted Looker (original) deployment on mainland infrastructure where that fits, or a licensed in-country equivalent, with the connected warehouse in-country — and keep consented, in-country storage for what must stay. For Looker (Google Cloud core), which has no China region, localize means standing up a lawful in-country equivalent, not a tunnel to the offshore endpoint.
  • Deliver. Any China-facing surface in front of the analytics layer — the dashboards, the embedded reporting, the admin and reporting portals your mainland users hit — runs over ICP-filed, in-country delivery (the 21YunBox Optimizer), in front of the stack you already run. No rebuild, no second codebase.

The result is an analytics layer that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →

Frequently Asked Questions

Does Looker have a mainland-China region?
Not in Looker (Google Cloud core). It is Google-managed and runs only on Google Cloud, whose regions include none inside mainland China — the nearest are asia-east1 (Taiwan) and asia-east2 (Hong Kong). So a Core instance, and the result caches, saved dashboards and scheduled-delivery extracts it holds, rest offshore. The older Looker (original) has no China region either, but it does offer a customer-hosted deployment you can place on mainland-China infrastructure.
Isn't Looker fine for China because it queries our warehouse in place instead of copying the data?
Querying in place reduces how much data Looker ingests, but it does not remove the residency question. The instance still holds a query result cache, saved Looks and dashboards, scheduled-delivery result sets, the LookML model and user accounts in its Google Cloud region, and persistent derived tables are materialized in the warehouse you connect. Wherever those result sets hold the personal information of people in China, they still have to rest somewhere lawful — so the region of the instance and of the connected warehouse both matter.
Can 21YunBox make our Looker setup compliant for China?
Yes. Our China team maps your cross-border and data-residency exposure for your entity and data volumes, and — where the law requires your China users' data to stay on the mainland — stands up a lawful in-country analytics layer (a customer-hosted Looker (original) deployment on mainland infrastructure, or a licensed in-country equivalent, with the connected warehouse in-country) and puts the China-facing reporting surfaces on ICP-filed delivery in front of the stack you already run. It is a compliant overlay, not a migration off Looker or Google Cloud, and 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO LOOKER

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.