Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does M-Files Work in China? Data Residency, Localization & PIPL Cross-Border

M-Files is a metadata-driven document management platform that holds the actual files — contracts, case files, HR and regulatory records, often sensitive or privileged. M-Files Cloud runs on Microsoft Azure with no mainland-China region, so those documents rest offshore: a PIPL cross-border transfer. A compliance-first look at where your records may rest.

Does M-Files work in China?

Whether M-Files works in China is first a data-residency question — where your documents come to rest — not a speed or reachability one.

M-Files is a metadata-driven document management platform that holds the actual files — contracts, case files, HR and regulatory records, board materials — full-text-indexed and versioned, routinely carrying the personal information of people in China and often Article 28 sensitive or legally privileged material. M-Files’s own Cloud Vault page says "M-Files Cloud is hosted in Microsoft Azure" and geo-replicates it across a primary and a secondary Azure region, with no mainland-China region, so those documents rest offshore — a PIPL cross-border transfer, and for a CIIO or high-volume handler a data-localization duty an offshore repository cannot meet. The lawful lever is M-Files’s own robust on-premises / self-managed product (or a licensed sovereign equivalent) run on mainland infrastructure, which keeps the records in-country.

This is a risk map, not a verdict — what applies turns on your entity, data volumes and whose information the documents hold. Our China team can map your exposure →

What M-Files's own documentation says about China

FactPrimary source
M-Files Cloud is hosted on Microsoft Azure with no mainland-China region. M-Files’s own Cloud Vault page states "M-Files Cloud is hosted in Microsoft Azure," with data "geo-replicated, and six copies of your data are always maintained" across a primary and a secondary Azure region. Those are Microsoft’s commercial Azure regions; the page names no mainland-China region, so documents, versions and metadata come to rest offshore. Azure’s mainland-China regions are a separate cloud operated by 21Vianet that M-Files Cloud is not built on. M-Files — Cloud Vault hosting (retrieved October 2026)
M-Files still ships a robust on-premises / self-managed product — the in-country lever. M-Files’s deployment guidance says on-premises "is best suited for organizations that ... are required to use an on-premises solution deployed behind the organization’s own firewall for regulatory reasons," and that a self-managed "Windows Server virtual machine running on a cloud platform such as Microsoft Azure, Amazon Web Services, or Google Cloud" is "self-managed in the same way as M-Files on-premises deployments." Run that server on mainland infrastructure and the vault stays in-country. M-Files User Guide — Deployment options (retrieved October 2026)
Storing China documents on an offshore repository is a PIPL cross-border transfer. Contracts, case files and records drawn from people and matters in China, together with their metadata and audit trails, held on an offshore M-Files Cloud tenant trigger PIPL’s cross-border transfer rules — notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is the operating company, not M-Files the processor. PIPL Articles 38–40
A CIIO or high-volume handler owes an in-country storage duty an offshore SaaS cannot meet. Mainland personal information and important data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. Crossing a volume or sensitivity threshold can require a CAC-led data-export security assessment. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a team serving mainland China, the question about M-Files was never whether the software installs or whether its clients can reach the vault. They do. M-Files is a metadata-driven document management platform: instead of folders, it classifies and finds every object — a contract, a case file, an invoice, an HR record, a quality or regulatory document — by metadata, and it holds the actual files, full-text-indexed and versioned, wrapped in permissions, workflows and audit trails. That content is the crux, because it routinely carries the personal information of people in China, frequently Article 28 sensitive personal information — health, financial, government-ID — and legally privileged or confidential material. M-Files’s own posture is honest and specific: M-Files Cloud is a fully managed service hosted on Microsoft Azure with no mainland-China region, while the company still ships a robust on-premises / self-managed product. So the real question is the most literal residency question on the site: where are your contracts and records allowed to come to rest?

M-Files's own Cloud Vault page stating that M-Files Cloud is hosted in Microsoft Azure, with data geo-replicated across a primary and a secondary Azure region and none in mainland China
"M-Files Cloud is hosted in Microsoft Azure." M-Files geo-replicates six copies of your data across a primary and a secondary Azure region, and its own Cloud Vault documentation names no mainland-China region — so the documents you store come to rest offshore. Source: M-Files — Cloud Vault hosting

M-Files in China at a glance

What decides it In M-Files's own terms — and China's law
Where the documents physically rest M-Files Cloud is a fully managed service that, in M-Files's own words, "is hosted in Microsoft Azure." Data is "geo-replicated, and six copies of your data are always maintained" — "three times within the primary region and three times within a secondary region" — but those are M-Files's commercial Azure regions (the US, Europe, the UK, Australia and the like). There is no mainland-China region to provision, so the documents, versions, metadata and audit trails come to rest offshore. Azure's own mainland-China regions are a separate cloud operated by 21Vianet that M-Files Cloud is not built on.
What it holds, and why it is personal information M-Files is metadata-driven: every object — contract, case file, invoice, HR record, quality or regulatory document — is classified and found by metadata, and the repository holds the actual files, full-text-indexed and versioned, with permissions, workflows and audit trails. That content routinely carries the personal information of people in China, frequently Article 28 sensitive personal information (health, financial, government-ID) and legally privileged or confidential material. This is the most literal residency question there is.
Your mainland documents in the repository Documents, metadata and audit trails drawn from people and matters in China and stored on an offshore M-Files Cloud tenant are a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the operator — M-Files is the processor.
In-country storage duty A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore SaaS cannot meet — mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Is it reachable? Treat reachability as the delivery half, not the question — clients and web access connect fine. M-Files still ships a robust on-premises / self-managed product, and it counts a self-managed Azure, AWS or Google Cloud VM the same as on-premises, so you can run the vault on mainland infrastructure and keep the documents in-country (the lawful lever). Any China-facing surface in front of it — the web client, the admin console, a self-service portal — needs an ICP filing tied to a mainland hosting resource.

Where the documents actually rest

M-Files does not place a region inside mainland China. M-Files Cloud is cloud-native on Microsoft Azure — in the company’s own Cloud Vault documentation, “M-Files Cloud is hosted in Microsoft Azure,” where “six copies of your data are always maintained,” replicated “three times within the primary region and three times within a secondary region” hundreds of miles away. Those are Microsoft’s commercial Azure regions — the United States, Europe, the United Kingdom, Australia and the like — and that hosting documentation names no mainland-China region to provision. Point a tenant at any of them and the documents M-Files holds for your China operations come to rest outside China.

It is worth being precise about why “it runs on Azure” does not quietly solve this. Azure’s mainland-China regions are a separate cloud, operated under local license by 21Vianet, that a vendor must build on deliberately; M-Files Cloud is not built on it. M-Files’s own roadmap confirms the pattern: the company has described a FedRAMP-authorized edition hosted on Azure Government for US federal use, targeted for authorization in 2027 — evidence that sovereign Azure partitions are separate builds M-Files takes on one at a time, and it has not taken on a mainland-China one.

The one deployment that keeps everything on mainland soil is the one M-Files endorses for exactly this reason. Its deployment guidance says an on-premises deployment “is best suited for organizations that have already invested in IT infrastructure” or “are required to use an on-premises solution deployed behind the organization’s own firewall for regulatory reasons,” and it adds that you “can set up M-Files in a Windows Server virtual machine running on a cloud platform such as Microsoft Azure, Amazon Web Services, or Google Cloud,” which “are self-managed in the same way as M-Files on-premises deployments.” Run that self-managed server on mainland infrastructure and the vault — documents and all — stays in the mainland. That on-premises product is current and robust, not a deprecated afterthought.

What it holds is personal information — and often privileged

M-Files earns this scrutiny because of what the repository holds. This is not a tool that touches one slice of data; it is the system of record for the files themselves — the signed contracts, the legal matters (often privileged), the HR files, the quality and regulatory dossiers, the financial records and the board materials — each one classified by metadata, full-text-indexed, versioned, and surrounded by the access-control lists and audit trails that record who opened or changed what. Every one of those is personal information under China’s Personal Information Protection Law the moment it identifies a person, and a great deal of it is Article 28 sensitive personal information — health, financial and government-ID fields — which carries a higher bar of specific purpose, strict necessity and separate consent. Where the matters are legal or regulated, the confidentiality and privilege of the content raise the stakes again.

So the thing an offshore M-Files Cloud tenant concentrates outside China is not an incidental cache; it is your organization’s most sensitive documents and the metadata map around them. For a critical information infrastructure operator, and for a handler whose volumes cross the regulators’ thresholds, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore repository structurally cannot satisfy that duty — the records are, by definition, in the wrong country — and where an export is permitted at all, crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment before any of it lawfully leaves.

Running it on a no-China-region cloud doesn’t meet the residency duty — and what does

The honest summary is narrow and important: nothing about M-Files is “blocked” in China, and the exposure is not the software. The exposure is a SaaS deployment that parks your mainland’s contracts, case files and records — and the metadata and audit trails around them — outside the mainland, on a cloud with no in-country region to provision.

The lawful lever here is genuinely strong, because M-Files still offers it: run the vault in-country. Its on-premises / self-managed product, including a self-managed server on mainland cloud infrastructure, keeps the documents on mainland soil; where that is not the fit, a licensed in-country or sovereign-cloud equivalent holds the repository in-country, with consented in-country storage for what must stay. Pointing a mainland client back at the offshore M-Files Cloud endpoint is not localization and does not meet the storage duty; standing up the repository in-country is. Where a minimized subset of content may lawfully cross the border, you keep that transfer consented and backed by a transfer mechanism, while any China-facing surface in front of the vault — the web client, the admin console, the self-service portal your mainland users hit — earns its own ICP filing.

This is a risk map, not a verdict. Whether you owe in-country storage, a transfer mechanism, a separate consent, a data-export security assessment, an ICP filing, or some combination turns on your entity, your data volumes, how much of what your documents hold is personal or sensitive, and whose data it is — and it is worth settling the specifics with counsel before you decide where a single contract or case file lives.

The lawful path — map, localize, deliver

You do not have to drop M-Files to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner that sits alongside your stack, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information your M-Files repository holds — the contracts, the case files, the HR and regulatory records, the sensitive and privileged material — so the exposure is written down before anything moves.

Localize. Because the risk is where those documents rest, we keep the repository in-country — on M-Files’s own on-premises / self-managed product run on mainland infrastructure, or a licensed in-country or sovereign-cloud equivalent — so the records China requires to stay on mainland soil do. Localize means a lawful in-country deployment of the repository, never a tunnel back to the offshore endpoint; only the minimized, lawfully transferable subset ever crosses.

Deliver. For any China-facing surface in front of the vault — the web client, the admin console, the self-service portal your mainland users hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind. The entire point is a lawful, filed, in-country path.

The goal is plain: your M-Files deployment runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is M-Files blocked in China?
No — M-Files installs and its clients and web access reach the vault from the mainland; reachability is not the issue. The compliance question is residency: M-Files Cloud is hosted on Microsoft Azure with no mainland-China region, so documents, versions and metadata come to rest offshore, which is a PIPL cross-border transfer once they hold the personal information of people in China.
Does M-Files Cloud have a mainland-China region or data-residency option?
No mainland-China region. M-Files Cloud runs on Microsoft Azure’s commercial regions (the US, Europe, the UK, Australia and the like) and names no China region in its hosting documentation; Azure’s mainland-China regions are a separate cloud operated by 21Vianet that M-Files Cloud is not built on. M-Files’s FedRAMP / Azure Government edition is only planned (authorization targeted 2027), which underlines that sovereign partitions are separate builds it does not yet offer.
How do we run M-Files compliantly for mainland-China users?
Keep the records in-country. M-Files still ships a robust on-premises / self-managed product and counts a self-managed mainland-cloud VM the same as on-premises, so you can run the vault on mainland infrastructure (or a licensed sovereign equivalent) and keep the documents on mainland soil. 21YunBox maps your PIPL, data-residency and ICP exposure, localizes the repository in-country, and delivers any China-facing client or portal over ICP-filed infrastructure — no rebuild, no migration. 21YunBox never uses or suggests circumvention of any kind.

ARTICLES RELATED TO M-FILES

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.