Does Matomo Work in China? Self-Hosted vs Cloud, PIPL & Data Residency
Matomo ships two ways. On-Premise (self-hosted) you can run on licensed, in-country infrastructure and keep your China analytics data in the mainland — a genuinely compliant path — while Matomo Cloud hosts that data in Frankfurt, Germany, making a mainland visitor's analytics a cross-border transfer under PIPL. A compliance-first look at the data-residency door.
Does Matomo work in China?
It depends which Matomo. Matomo On-Premise is open-source software you install on your own servers, so you can run it on licensed, in-country infrastructure and keep your China analytics data in the mainland — a genuinely compliant path. Matomo Cloud hosts that same data in Frankfurt, Germany — offshore for a China audience, and a cross-border transfer of personal information.
Matomo's own documentation draws the line. Self-hosting, it says, "provides you with full control and allows you to choose the country and location to store analytics data" — "Once downloaded, you have 100% data ownership as Matomo is hosted on your own servers," and "We have absolutely no way of gaining access to your data." The managed edition is different: "Matomo data stored in the cloud edition is hosted in Frankfurt, Germany," with no mainland-China region. Analytics records visitor personal information — IP address, pages, behavior — so sending a mainland visitor's data to Frankfurt is a cross-border transfer under PIPL (Articles 38–43), and for a CIIO or large-volume handler that data must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). Matomo is a backend analytics tool, so it carries no ICP filing of its own — that falls on the site it sits inside. The table below is Matomo's own wording and the rule each path triggers.
This is a risk map, not a verdict — which path fits turns on your entity, your data volumes and who your users are. Our China team can map your exposure with you →
What Matomo's own documentation says about China
| Fact | Primary source |
|---|---|
| Matomo On-Premise lets you put the data in-country — that is the compliant path. It is open-source software you host yourself, and in Matomo's words self-hosting "provides you with full control and allows you to choose the country and location to store analytics data," so "Once downloaded, you have 100% data ownership as Matomo is hosted on your own servers." Run it on licensed infrastructure inside the mainland and your visitors' analytics data can stay in China — directly addressing the data-residency expectation under PIPL (Article 40; Cybersecurity Law Article 39 (formerly Article 37)). | Matomo — Data sovereignty FAQ & 100% Data Ownership (matomo.org), retrieved 2026-10-07; PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) |
| Matomo Cloud keeps your data in Frankfurt, Germany — there is no mainland-China region. Matomo states "Matomo data stored in the cloud edition is hosted in Frankfurt, Germany," and that its "secure server is based in Germany and follows EU laws for the Cloud." Analytics gathered from a mainland user on the Cloud edition is therefore written to the EU — a cross-border transfer of personal information PIPL governs (notice, separate consent and a transfer mechanism, Articles 38–43). | Matomo — Data sovereignty FAQ & 'Manage your data your way' (matomo.org), retrieved 2026-10-07; PIPL Articles 38–43 |
| Owning your data is not the same as locating it in China. Matomo's whole pitch is ownership: it says your "data is 100% yours to own, with no external parties looking in," and for On-Premise "We have absolutely no way of gaining access to your data." That settles who controls the data — not where it sits. On the Cloud edition it still lives in Germany, so the cross-border and residency questions under PIPL remain open. Ownership and data location are two different tests, and the edition you choose decides the second one. | Matomo — 100% Data Ownership (matomo.org), retrieved 2026-10-07 |
| Matomo carries no ICP filing of its own — that duty falls on the site it sits inside. Matomo is a backend analytics tool embedded in a website you operate, not a public site you file for separately, so it adds a data-residency and cross-border question rather than its own ICP filing (the regime under State Council Order No. 292 and MIIT Order No. 33). The handler running the tracker — you, not Matomo — carries the PIPL duties, and for a CIIO or large-volume handler the collected data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). | Matomo (matomo.org), retrieved 2026-10-07; State Council Order No. 292; MIIT Order No. 33; PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) |
Sources verified by the 21YunBox compliance team on 2026-10-07.
“Does Matomo work in China?” has two answers, because Matomo ships in two forms and they land on opposite sides of China’s data rules. Matomo On-Premise is open-source software you install on your own servers, so you can run it on licensed infrastructure inside the mainland and keep your China visitors’ analytics data in China; that is a genuinely compliant path, and the data-ownership promise Matomo is built on is exactly what makes it possible. Matomo Cloud is the managed edition, and by Matomo’s own account the data sits in Frankfurt, Germany — offshore for a China audience, which turns every mainland visitor’s analytics into a cross-border transfer of personal information China’s law governs. So the honest answer is: it depends which Matomo, and this page walks both.
Matomo in China at a glance
| What decides it | In Matomo's own terms |
|---|---|
| Two editions | On-Premise (self-hosted) versus Cloud (managed). Matomo says self-hosting “allows you to choose the country and location to store analytics data,” while the Cloud edition is “hosted in Frankfurt, Germany.” |
| Where your data lives | On-Premise: wherever you put the server — including licensed infrastructure inside the mainland. Cloud: Frankfurt, Germany, which Matomo says “follows EU laws” — offshore for China, with no mainland-China region. |
| What it collects | Web analytics — a visitor's IP address, the pages they view and how they behave. That is personal information under China's law, wherever it is stored. |
| The cross-border trigger | Recording a mainland user on Matomo Cloud ships their personal information to the EU — a cross-border transfer PIPL governs, calling for notice, separate consent and a transfer mechanism. |
| Who carries the duty | You, the handler embedding the tracker — not Matomo. Matomo carries no ICP of its own; ICP falls on the site it sits inside, and any residency duty is yours. |
Door one — Matomo On-Premise can keep your China data in-country
Matomo’s self-hosted edition is the honest yes. It is open-source software you download and run on infrastructure you control; in Matomo’s words, self-hosting “provides you with full control and allows you to choose the country and location to store analytics data,” and “Once downloaded, you have 100% data ownership as Matomo is hosted on your own servers.” Put that server on licensed infrastructure inside the mainland and your China visitors’ analytics never leave the country — which is exactly what a data-residency obligation under the Personal Information Protection Law asks for (Article 40; Cybersecurity Law Article 39 (formerly Article 37)). The ownership pitch Matomo is built on — “We have absolutely no way of gaining access to your data” — works in your favor here: nothing about the software forces your data offshore. Self-hosting in-country also means the tracker script loads from inside the mainland rather than from an offshore endpoint, but that is the delivery half; the reason to self-host in-country is where the data lands, not how fast it paints. This is the path that can be made compliant, and it is Matomo’s own differentiator rather than a workaround.
Door two — Matomo Cloud keeps your data in Frankfurt
The managed edition is where the exposure lives. Matomo states plainly that “Matomo data stored in the cloud edition is hosted in Frankfurt, Germany,” and that its “secure server is based in Germany and follows EU laws for the Cloud.” There is no mainland-China region on offer. So the moment Matomo Cloud records a visitor in Shanghai or Shenzhen, their IP address, the pages they viewed and how they behaved are written to servers in the EU. Under the Personal Information Protection Law that is a cross-border transfer, and the handler — you, the site embedding the tracker, not Matomo — must give notice, obtain separate consent for the transfer, and satisfy one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (Articles 38–43). EU hosting earns Matomo strong standing under European privacy law; it does nothing for China residency, because Frankfurt is still outside the mainland.
Owning your data and locating your data are two different tests
It is worth separating the two claims Matomo makes, because they are easy to run together. Ownership is about control: Matomo says your “data is 100% yours to own, with no external parties looking in,” and that holds on either edition. Location is about geography — where the bytes physically sit. China’s cross-border rules turn on location, not ownership, so you can own your data completely and still trigger a transfer the instant it is stored in Germany. That is why the edition you choose matters more than the privacy branding on the box. And because Matomo is a backend analytics tool embedded in a site you operate — not a public website you file for separately — what it adds to your China footprint is not an ICP question of its own but a data-residency and cross-border one. Whether the tracker reaches a mainland user cleanly is the smaller, delivery half; whether you were allowed to collect and store that data where you did is the half PIPL decides.
This is a risk map, not a verdict: how much exposure you carry turns on which edition you run, what you collect and anonymize, your role and data volumes, and who your users are — worth settling with counsel before you record at scale.
Where 21YunBox fits — a compliant overlay, not a migration
You keep Matomo as your analytics platform. What we add is the piece that makes the China side lawful. Our China team weighs the two editions against your real exposure — self-hosted Matomo on in-country infrastructure that keeps the data in the mainland, versus the EU-hosted Cloud and the PIPL cross-border and consent duties it creates — and then stands up the compliant, ICP-filed delivery from inside the mainland, placed in front of your existing origin, with no rebuild, no second codebase and no move off the stack you run today. Matomo stays where it is; the residency and cross-border gaps become ours to map and close with you.
Related reading:
