Does Manhattan Associates Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules
Manhattan Associates runs its Manhattan Active warehouse, transportation and omnichannel platform cloud-native on Google Cloud, which has no mainland-China region — so the inventory, logistics, order and supplier, carrier and worker data your China operation keeps in it sit offshore: a PIPL cross-border transfer, and supply-chain data can be 'important data' needing a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure, and the lawful in-country path.
Does Manhattan Associates work in China?
Reaching Manhattan Active from Shanghai isn't the question — residency is: it runs cloud-native on Google Cloud, which has no mainland-China region, so your China operation's supplier, carrier and worker personal data and its supply-chain data sit offshore, a PIPL cross-border transfer — and the supply-chain data itself can be "important data" (重要数据) that needs a CAC data-export security assessment before it leaves.
Manhattan Active is the execution and planning record of a supply chain — warehouse management, transportation, order management and demand and inventory planning — holding inventory, logistics, order and fulfillment data plus the personal information of customers, carriers and warehouse workers. On an offshore cloud with no mainland-China region that is a PIPL cross-border transfer (notice, separate consent and a transfer mechanism, Articles 38–40), and because supply-network, logistics and planning data can be classified important data under the Data Security Law, transferring it abroad can require a CAC data-export security assessment first — regardless of any personal information. The lawful lever is to keep the supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing surface — not to make the offshore platform reachable.
This is a risk map, not a verdict — whether your supply-chain data is important data turns on your sector and the catalogs, and it's worth settling with counsel. Our China team can map your exposure →
What Manhattan Associates's own documentation says about China
| Fact | Primary source |
|---|---|
| Manhattan Active runs cloud-native on Google Cloud — and says so on its own platform page. Under the heading "Runs on Google Cloud," Manhattan states that ActivePlatform "leverages Google Cloud for its cloud infrastructure, taking advantage of many of Google's advanced capabilities to enhance agility, scalability, and resiliency." Google Cloud operates no region in mainland China, so a Manhattan Active instance serving your China operation is hosted offshore — and the supply-chain and personal data you load into it leaves the mainland, a cross-border transfer under PIPL. | Manhattan Associates — ActivePlatform (Manhattan Active Platform), retrieved 2026-10-11 |
| It is a supply-chain execution and planning platform, so it holds far more than contact details. Manhattan Active spans warehouse management (ActiveWarehouse), transportation (ActiveTransportation), order management (ActiveOrder) and demand and inventory planning (ActivePlanning). For a China operation that means inventory positions, logistics and transportation flows, demand forecasts and order and fulfillment records — alongside the personal information of customers, drivers and carriers and the warehouse workers tracked through labor management. | Manhattan Associates — Solutions / ActivePlatform, retrieved 2026-10-11 |
| Supply-chain data can be "important data" that cannot leave without a CAC assessment — regardless of any PII. Under the Data Security Law and China's national and sectoral catalogs, supply-network maps, logistics, inventory, production and consolidated planning data can be classified important data (重要数据) — a real risk in strategic sectors. Where it applies, transferring the data abroad requires a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves. Whether your data qualifies turns on your sector and the catalogs. | 21YunBox — China data-export security assessment measures (DSL; CAC Measures), retrieved 2026-10-11 |
| PIPL puts the cross-border duty on you, and some handlers must keep the data in China. Because the customer, carrier and worker records cross the border, the handler — you, Manhattan's customer, not Manhattan — must give notice, obtain separate consent, and satisfy one transfer mechanism (Articles 38–40). Where you are a critical information infrastructure operator or move personal information at volume, personal information collected in China must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), which an offshore region cannot satisfy. | 21YunBox — China's Cybersecurity Law (data localization, Article 39 formerly 37); PIPL Articles 38–40 |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a company running Manhattan Associates in mainland China, the reflex is to ask whether the warehouse and order screens open from Shanghai — and they do: Manhattan Active is browser-based SaaS, not blocked at the border. So reachability is not the China decision; where your supply-chain data comes to rest is. Manhattan Active is a cloud-native platform — warehouse management (ActiveWarehouse), transportation (ActiveTransportation), order management (ActiveOrder) and planning (ActivePlanning) — that, in Manhattan’s own words, “leverages Google Cloud for its cloud infrastructure.” Google Cloud operates no region in mainland China, so the inventory, logistics, order and fulfillment data — and the personal information of your customers, carriers and warehouse workers — sit offshore. Holding a China operation’s data there is a PIPL cross-border transfer (Articles 38–40); and supply-chain data can be classified “important data” (重要数据) that may not leave without a CAC data-export security assessment, regardless of any personal information, while a critical information infrastructure operator or high-volume handler owes in-country storage. Any China-facing surface adds an ICP filing.
Manhattan Associates in China at a glance
| What decides it | In Manhattan Associates' own terms — and China's law |
|---|---|
| What it holds | Manhattan Active is the execution and planning record of a supply chain: warehouse management (ActiveWarehouse), transportation (ActiveTransportation), order management (ActiveOrder) and demand and inventory planning (ActivePlanning). For a China operation that means inventory positions, logistics and transportation flows, demand forecasts and order and fulfillment records — plus the personal information of customers, drivers and carriers, and the warehouse workers tracked through labor management. |
| Where it runs | Offshore. ActivePlatform "leverages Google Cloud for its cloud infrastructure," and Google Cloud operates no region in mainland China. So the supply-chain and personal data your China operation enters rest outside the mainland, and loading them there is a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40). Manhattan Active is cloud-native SaaS, so there is no customer-run, in-country deployment to change that by itself. |
| The important-data door | This is the half most reviews miss. Supply-network maps, logistics and inventory, transportation lanes and consolidated planning data can be classified "important data" (重要数据) under the Data Security Law and the national and sectoral catalogs — a real risk in strategic sectors such as manufacturing, automotive, pharmaceuticals, energy, food and logistics. Transferring important data abroad requires a mandatory CAC data-export security assessment before anything leaves — regardless of whether personal information is involved, or how much. |
| Supplier PII & residency | Customer, carrier and workforce records are personal information: PIPL Articles 13 and 23 require notice and a specific consent, and Article 28 raises the bar for any sensitive identifiers. For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) sets an in-country storage duty an offshore region cannot meet. |
| Reachability is not the axis | Manhattan Active opens from the mainland over the browser; cross-border access to an offshore instance can be uneven, but that is an operational matter, not the decision. The lawful path is to keep the China supply-chain and supplier data in-country — an in-country data path, data classification and minimization — handle any important-data duty, and deliver any China-facing surface (a supplier portal, a self-service order page) in-country under an ICP filing. 21YunBox maps the exposure, localizes the regulated data onto an in-country path, and delivers in-country. |
What you actually hold — orders, inventory, and the supply chain
Manhattan Active does not hold an abstraction; it holds the running record of a supply chain. It is a cloud-native, microservices platform spanning warehouse management (ActiveWarehouse), transportation management (ActiveTransportation), order management (ActiveOrder) and supply-chain planning (ActivePlanning). For a China operation, that single platform carries your inventory positions and stock movements, your logistics and transportation lanes, your demand forecasts and replenishment plans, and your order and fulfillment history — the operational heartbeat of how goods move through the country.
Two kinds of regulated data sit inside that. The first is personal information: the customers an order is shipped to, the drivers and carriers a transportation plan routes, and the warehouse workers whose shifts, tasks and productivity labor management tracks — all of it personal information under Chinese law, and some of it potentially sensitive under PIPL Article 28. The second, and the sharper edge for a supply-chain platform, is the supply-chain data itself: where product is stored and in what quantity, how it moves, who supplies it, and the consolidated demand and capacity picture across your network. Where does all of it sit? In the Google Cloud region your instance was provisioned in — and because Google Cloud operates no region in mainland China, the answer is always offshore. Manhattan Active is delivered as cloud-native SaaS, so unlike a self-managed platform you could stand up on in-country infrastructure, it offers no customer-run, in-country deployment to keep that data onshore on its own.
The doors: cross-border personal data, important data, and in-country storage
Once the data is offshore, a different body of law decides whether it was allowed to go there — and for a supply-chain platform three doors open at once.
Cross-border transfer of personal information. The customer, carrier and worker records in Manhattan Active are personal information, and loading them into a Google Cloud region outside the mainland is a cross-border transfer (数据出境) under China’s Personal Information Protection Law. PIPL puts the duty on the handler — your China entity, not Manhattan the processor: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), with Articles 13 and 23 setting the consent basis for collecting and sharing the data in the first place.
Important data — the distinctive door. This is where a supply-chain platform differs from an ordinary SaaS tool. Supply-network maps, logistics and inventory data, transportation lanes, production and capacity, and consolidated sourcing data can be classified “important data” (重要数据) under the Data Security Law and China’s national and sectoral important-data catalogs — most plausibly in strategic sectors like manufacturing, automotive, pharmaceuticals, energy, food and logistics. Where that classification applies, transferring the data abroad requires a mandatory CAC data-export security assessment (数据出境安全评估) before anything leaves — and that duty attaches to the strategic nature of the data, regardless of whether any personal information is involved or how much. Whether your particular supply-chain data is important data turns on your sector and the applicable catalogs; it is a risk to assess, not a foregone conclusion.
In-country storage. If your organization is a critical information infrastructure operator — or moves personal information at the volumes a large supply-chain platform routinely reaches — personal information generated in China must be stored in China. That duty rests on PIPL Article 40 and on Cybersecurity Law Article 39 (formerly Article 37). An offshore Google Cloud region cannot meet it, and moving an instance between Manhattan’s offshore regions only relocates the transfer; it does not end it.
Logging in isn’t the question — a compliant in-country supply chain is
Notice what is not on that list: how quickly Manhattan Active paints a screen in Shanghai, or how to force a smoother connection to an offshore instance. Those are operational questions, and chasing them misses the decision. The decision is whether your China operation’s supplier, carrier and worker personal information and its supply-chain data are allowed to sit where Manhattan Active keeps them — and, if any of that is important data, whether it may cross the border at all without a CAC assessment first.
For a cloud-only platform with no mainland-China region, the lawful move is not to make the offshore instance reachable — it is to keep the China supply-chain and supplier data on an in-country footing. You keep Manhattan Active as your global execution and planning system, and for the China entity you localize the regulated data onto a China-resident path, classify the supply-chain data and handle any important-data and data-export-assessment duty, send offshore only what may lawfully leave, and carry the Article 13/23 and Article 28 consent for the personal information. Localizing means keeping the data on an in-country path — never quietly routing it offshore anyway. Any China-facing surface the platform powers — a supplier portal, a self-service order or returns page — is a public service in the mainland and carries an ICP filing duty, delivered compliantly and in-country.
None of this is a verdict that Manhattan Associates is “blocked” or “illegal.” It is a risk map: whether you owe separate consent, a transfer mechanism, in-country storage, an important-data classification and data-export assessment, an ICP filing, or some combination depends on your entity, your sector, your data volumes and your role under Chinese law — specifics to settle with counsel before your China operation depends on them.
The lawful path — map, localize, deliver
There is a compliant way to run a supply-chain platform for a China operation, and it has a shape.
First, map: our China team inventories what your Manhattan Active instance holds for the China entity — the inventory, logistics and transportation data, the demand and capacity picture, the order and fulfillment records, and the customer, carrier and worker personal information — and where each is processed and stored (an offshore Google Cloud region, since Manhattan Active has no mainland-China region), which of it may be important data, the deployment options, and the consent, residency and assessment basis each one needs. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we help you keep the China supply-chain and supplier data in-country — an in-country data path for the mainland entity, with the supply-chain data classified and any important-data or data-export-assessment duty handled, the supplier, carrier and worker personal information minimized and protected, and the Article 13/23 and Article 28 consent in place — while Manhattan Active stays your global system for everywhere else. Localizing means keeping the data on an in-country path, never moving it offshore by stealth.
Then deliver: the China-facing surfaces the platform powers — a supplier portal, a self-service order or returns page, the screens your mainland operations teams open — carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform, so the service runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We are a compliance overlay and partner to the stack you already run, not a competitor to it.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment (CAC)
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
