Does monday.com Work in China? Data Residency, PIPL Cross-Border Transfer & ICP
monday.com isn't blocked in mainland China — but reachability is not the decision. By monday.com's own white paper the platform runs on AWS, "primarily Northern Virginia (US), Frankfurt (Germany), and Sydney (Australia)," with every account "bound to a single region" and none in the mainland. So the boards, items, files and user identities a China-facing team keeps in monday.com sit offshore — a cross-border transfer of personal information under PIPL, with an in-country storage duty for some handlers and an ICP filing for any public China-facing surface. A compliance-first look at the data-residency and cross-border exposure, and the lawful in-country path — with no circumvention of any kind.
Does monday.com work in China?
The question isn't speed, and it isn't whether the page loads — monday.com runs on global cloud infrastructure and can usually be opened from the mainland. It's that every board, item, file and team member's profile it holds is stored offshore, and never in China.
By monday.com's own Security and Privacy white paper, the service is "hosted on Amazon Web Services (AWS) ... primarily Northern Virginia (US), Frankfurt (Germany), and Sydney (Australia)," and "Customer accounts are bound to a single region" — none of them the mainland. So the moment data collected from your China users lands in a monday.com account, you have made a cross-border transfer of personal information under PIPL (notice, a separate consent and one transfer mechanism, Articles 38–40), possibly a data-export security assessment, and for a critical information infrastructure operator an in-country storage duty under Cybersecurity Law Article 39 (formerly Article 37) that no offshore region can meet. A China-facing board or portal served to the public also needs an ICP filing monday.com gives nothing to attach to.
This is a risk map, not a verdict — which duties bite turns on what you collect, your data volumes, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →
What monday.com's own documentation says about China
| Fact | Primary source |
|---|---|
| monday.com's own white paper puts every account in the US, EU or Australia — never the mainland. Its Security and Privacy white paper states the service is "hosted on Amazon Web Services (AWS) which is a best in class secure infrastructure, hosted in multiple regions, primarily Northern Virginia (US), Frankfurt (Germany), and Sydney (Australia) across several Availability Zones," and that "Customer accounts are bound to a single region." Mainland China is not one of those regions, and the document names no China data region or entity — so a board created for a China-facing team is bound to an offshore region from the start. | monday.com Security and Privacy white paper (Trust Center), V2.0, retrieved 2026-10-09 |
| monday.com's own sub-processor list places full account data in the US region on AWS — with no China entry. Its US Data Region sub-processor page records Amazon Web Services with a hosting location of "US region" and data processed of "Full account data," lists Cloudflare as a global CDN, and names no mainland-China sub-processor or region at all. The infrastructure that stores and moves your monday.com data is, by monday.com's own disclosure, entirely outside the mainland. | monday.com — Sub-processors for US Data Region (In-depth information), retrieved 2026-10-09 |
| Loading data collected in China into monday.com is a cross-border transfer the law puts on you. Because the boards, items, files and user profiles sit offshore, personal information your China users generate crosses the border the moment it is saved — a transfer governed by China's Personal Information Protection Law. The duty falls on the handler (you, not monday.com): notice, a separate consent distinct from the terms of use, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Above certain volumes or where "important data" is involved, a data-export security assessment may be required before anything leaves. | PIPL Articles 38–40; Measures for the Security Assessment of Outbound Data Transfers |
| Some data must stay in China — and a public China-facing board needs an ICP filing monday.com can't anchor. Where the handler is a critical information infrastructure operator or moves personal information at scale, personal information collected in the mainland must be stored there (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty an offshore monday.com account cannot satisfy. And any site or portal actually served to the public from inside China carries an ICP filing duty (State Council Order No. 292; MIIT Order No. 33) tied to a mainland hosting resource — of which monday.com offers none. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
The first thing most teams want to know about monday.com and China is whether it even works there — and, unlike a hard-blocked service, it usually does. monday.com is a work-OS running on global cloud infrastructure, not a mainland-blocked site, so colleagues in China can typically open a board. But reachability is not where this decision is made, and neither is speed. The question that actually decides whether you can use monday.com for a China-facing team is where the boards, items, files and the identities of the people working on them are allowed to live.
And by monday.com’s own account, they live outside the mainland. Everything a team puts into monday.com — every item, every uploaded file, every member’s profile — is stored in whichever AWS region the account is bound to, and those regions are the United States, the EU, and Australia. The moment data collected from users in China lands in that account, you have made a cross-border transfer (数据出境), and a separate body of law decides whether that was lawful. Even if a board loaded instantly from Shanghai, that question would still stand — which is why this is a compliance decision, not a performance one. And to be plain from the outset: the only ways to reach a service you cannot lawfully reach across the border are forms of circumvention, which are themselves non-compliant and which 21YunBox never uses or suggests.
monday.com in China at a glance
| What decides it | In monday.com's own terms — and China's law |
|---|---|
| What it is | monday.com is a work-OS (work-management) platform: boards, items, uploaded files and the profiles of the team members who use them, all held in a cloud account. There is no monday.com region or operating entity inside mainland China. |
| Is it reachable from the mainland? | Usually, yes — it is a public cloud service, not a mainland-blocked one, so a board can typically be opened. But reachability and speed are not the China question, and the only ways to force a connection to something you cannot reach lawfully are circumvention, which 21YunBox never uses or suggests. |
| Where does your data actually sit? | Offshore. monday.com's white paper puts the service on AWS, “primarily Northern Virginia (US), Frankfurt (Germany), and Sydney (Australia),” with each account “bound to a single region.” File attachments sit on AWS S3. None of those regions is in the mainland. |
| Putting China-collected data into monday.com | A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. It may trigger China's data-export security assessment, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore account cannot meet. |
| Serving a China-facing board or portal to the public | A public surface served to mainland visitors needs an ICP filing tied to a mainland hosting resource. monday.com names no mainland region, so there is nothing of its own to file against. |
| The lawful path | Keep China-resident data in-country on a compliant in-country store, move only what may lawfully leave, and deliver the China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention. |
Your boards, items and files sit offshore — the residency question
Here is the gate most teams miss. A monday.com account does not keep your data on some neutral middle ground; it keeps it in one specific AWS region, chosen when the account is created and fixed thereafter. monday.com’s own Security and Privacy white paper is unambiguous about where those regions are: the service is hosted on AWS “primarily Northern Virginia (US), Frankfurt (Germany), and Sydney (Australia),” the EU region opened in 2021 and the Sydney region in 2023, and “Customer accounts are bound to a single region.” The files behind your items are no exception — the white paper notes that “File storage is hosted on Simple Storage Service (S3) by AWS.” Not one of those regions is in mainland China.
So the ordinary act of a Shanghai-based colleague adding a client’s details to a board, or uploading a contract to an item, puts personal information collected in China onto storage outside the country. For a handler with a data-localization duty, that is the problem in a sentence. If your organization is a critical information infrastructure operator or moves personal information at scale, the Cybersecurity Law requires that personal information and important data collected and generated in the mainland be stored in the mainland — its Article 39, formerly Article 37 in the 2016 text, renumbered by the amendment in force January 1, 2026, with the obligation itself unchanged (PIPL Article 40 carries the parallel residency duty). An offshore monday.com account cannot satisfy that, whichever of the US, EU, or Australia regions it is bound to, because none of them is China. Which of these duties actually bites on your data is a risk to confirm with counsel against what you truly collect and store.
Loading China users into monday.com is a cross-border transfer
Residency is the duty for some handlers; the cross-border transfer is the duty for nearly all of them. Because the account lives offshore, personal information your China users generate — a teammate’s profile, a customer record on a CRM board, a file with someone’s details — crosses the border the instant it is saved. That transfer is governed by China’s Personal Information Protection Law, and the obligation lands on the personal-information handler, which is you, not monday.com.
PIPL Articles 38–40 require three things before that data may lawfully leave: notice to the individuals, a separate consent distinct from their agreement to use the product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above certain volume thresholds, or where the data counts as “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) to clear before anything crosses. None of this turns on how quickly a board syncs; it turns on whether the data had a lawful basis to be outside the country at all. The platform collecting the data does not discharge the duty attached to where that data then sits.
Why there is no monday.com “China region” to switch on
With some vendors the fix is to move onto a mainland instance the vendor itself runs. monday.com is not one of them. Its region choices top out at the US, the EU, and Australia; an account is bound to one of them, and changing regions is not a setting you flip but a matter of standing up a fresh account in the target location. There is simply no China region to enable, and no in-country monday.com entity behind one.
That has a second consequence beyond storage. If the board or portal you build on monday.com is served to the public inside China — a customer form, a partner workspace, a status page — that public surface carries an ICP filing (备案) duty under State Council Order No. 292 and MIIT Order No. 33, and the filing has to attach to a hosting resource physically in the mainland. monday.com provides none, so there is nothing on monday.com to file against. “We already run monday.com” does not carry into China on its own; the in-country footing a lawful China presence needs is exactly what an offshore work-OS leaves open.
The lawful path — map, localize, deliver
There is a lawful way to run work management for a China-facing team, and it has a clear shape — three moves, in order.
Map. Our China team works through the PIPL cross-border exposure and the data-residency duties that attach to what you keep in monday.com: sorting which China-collected data carries personal or important information that must stay in-country, which may lawfully be transferred to your monday.com region, and where a data-export security assessment or an Article 39 storage duty applies. The legal conclusions are settled with counsel; we frame the technical picture that feeds them.
Localize. Hold the China-resident data in-country, on a compliant in-country store, and let only what may lawfully leave reach the monday.com account your team already works in — so the boards, automations and workflows people depend on keep running, without the work-OS becoming the thing that carries data out of China unlawfully. 21YunBox stands up and integrates that China-legal in-country option in place of whatever cannot run compliantly in the mainland.
Deliver. The China-facing board, form, or portal that serves and receives that data is itself a public service in the mainland, so it carries an ICP-filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is work management that runs legally and compliantly for your users in China. What we do not do, and what no one lawfully can, is hand you a way around the rules that decide where your data may live: we localize what must stay and deliver in-country, and circumvention is never on the table.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
