Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does mParticle Work in China? PIPL Cross-Border, Automated Decisions & Data Residency

mParticle (now mParticle by Rokt) is a customer data platform: the events and identities you send it are resolved into unified profiles on offshore US, EU or Australia infrastructure — no mainland-China region — then used to build audiences. For your China users that is a PIPL cross-border transfer and Article 24 automated decision-making, plus a compliance-first look at data residency.

Does mParticle work in China?

The SDK reaching the mainland is not the issue — mParticle (now mParticle by Rokt) is a customer data platform that resolves your China users' events and identities into unified, persistent profiles on offshore US, EU and Australia infrastructure with no mainland-China region, then builds audiences and decides what each person sees.

You send mParticle behavioral events, identities, device signals and the user's IP; it resolves them into one continuously updated profile per person, builds machine-learning audiences, and routes the result to downstream tools. For a mainland user that is a PIPL cross-border transfer (Articles 38–40) — and because the profile is used to decide each person's experience, it is also Article 24 automated decision-making and profiling, which requires transparency, a way to refuse, and a non-profiled option. The lawful lever is to keep the profile-building and user data on an in-country path — a licensed domestic alternative, the context minimized, and the Article 24 opt-out honored — not to make the offshore endpoint reachable.

A risk map, not a verdict — your exposure turns on what you send, your role and data volumes, and who your users are. Our China team can map your exposure →

What mParticle's own documentation says about China

FactPrimary source
mParticle (now mParticle by Rokt) hosts its data offshore, with no mainland-China region. Its sub-processor list places cloud hosting on AWS in North Virginia, Frankfurt and Sydney, with Snowflake as the "store for customer data" in the USA, Germany and Australia — none in mainland China. Rokt / mParticle by Rokt — Subprocessors list (retrieved 2026-10-10)
mParticle resolves events and identities into one persistent profile per person, then decides what each sees. Its docs describe a profile "continuously updated and maintained in real time," holding all identities, every audience membership and "the most recently seen IP address," used to "offer personalized experiences at any touchpoint." mParticle Docs — User Profiles Overview (retrieved 2026-10-10)
Personalizing or segmenting China users from a profile is automated decision-making under PIPL Article 24. It requires transparency and fairness, a way to refuse, and — where a decision rests on profiling — an option not to be targeted by personal characteristics. See cross-border transfers under PIPL. PIPL Article 24 (automated decision-making and profiling)
A high-volume handler or CIIO must keep China personal information in the mainland. Cybersecurity Law Article 39 (formerly Article 37) carries the data-localization duty — the 2025 amendment, in force January 1, 2026, renumbered it from 37 to 39, substance unchanged — which offshore US, EU or Australia pods cannot satisfy. Cybersecurity Law of the PRC, Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

With mParticle, the question for a mainland-China audience is not whether the SDK loads or the ingestion endpoint can be reached — it is what happens to the user data you send it. mParticle (now mParticle by Rokt) is a customer data platform: it ingests the behavioral events and identities you capture, resolves them into a single, continuously updated user profile, builds audiences from it, and routes the result to downstream tools. By its own documentation that profile lives on offshore infrastructure — in the United States, Frankfurt and Sydney — with no region inside mainland China. So the instant mParticle ingests a user in Shanghai, their personal information has entered a growing offshore profile store, and automated decisions about what they see are made from it. Three of China’s rules bite at once: a cross-border transfer (PIPL Articles 38–40), automated decision-making and profiling (Article 24), and consent for behavioral tracking (Articles 13 and 23) — with an in-country storage duty for a high-volume handler on top.

mParticle by Rokt sub-processor list showing Amazon Web Services hosting mParticle data in North Virginia, Frankfurt and Sydney and Snowflake as the store for customer data, with no mainland-China location
mParticle by Rokt's own sub-processor list says the service uses its listed sub-processors "to process personal information in the corresponding locations" — AWS in North Virginia, Frankfurt and Sydney, with Snowflake as the customer-data store, and no mainland-China location. Source: Rokt / mParticle by Rokt sub-processors

mParticle in China at a glance

What decides it In mParticle's own terms — and China's law
What you send it mParticle ingests the behavioral events and identities you capture — user and device IDs, emails, custom attributes, and, in its own schema, "the most recently seen IP address associated with the user." It resolves them into one profile per person. All of that is personal information.
Where it is stored and resolved By its own sub-processor list, mParticle processes and stores that data on offshore infrastructure in the United States, Frankfurt and Sydney — no mainland-China region. Ingesting a China user moves their personal information out of the mainland: a cross-border transfer (数据出境) under PIPL Articles 38–40.
What it does with the profile mParticle builds audiences and can "offer personalized experiences at any touchpoint via the Profile API," its "machine learning engine" segmenting users by behavior. Deciding what each person sees from their profile is automated decision-making and profiling — PIPL Article 24 requires transparency, a way to refuse, and an option not to be targeted by personal characteristics.
Consent and residency Capturing behavioral events needs genuine consent, not a buried "by using this product…" (PIPL Articles 13 and 23). And because the profile store is permanent and growing, a mainland-storage duty can apply for a CIIO or high-volume handler — Cybersecurity Law Article 39 (formerly Article 37); the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Why "can the SDK be reached?" misses it Whether the SDK and ingestion endpoint load from the mainland is the smaller half. The real question is lawful collection, profiling and onward routing — the lever is to keep the profile-building and user data on an in-country path (a licensed domestic alternative, the context minimized, the Article 24 opt-out honored), while the app consuming the decisions carries an ICP filing and needs in-country delivery.

What you actually send — your users’ attributes and behavior

mParticle is built to collect, not to meter. In its own words, it “receives data as batches from native SDKs, our HTTP API and third-party data feeds,” where “each batch is a JSON object containing an array of events and contextual information about the user, such as identities, user attributes, and device information.” IDSync then “resolves identities like email, customer ID and device IDs to a single mParticle ID,” and each mParticle ID “maps to a single user profile.”

What accumulates is not a handful of metrics but “a complete picture of what you’ve learned about a given user over time, across all of your channels, continuously updated and maintained in real time.” The profile holds all known identities, every audience membership, and “the most recently seen IP address associated with the user.” For a mainland-China user, all of that is personal information — and some of it (precise behavior, contact identifiers) can rise to sensitive personal information, which PIPL guards more tightly still. This is close to the maximal case the cross-border rules were written for: a permanent, growing offshore store of who your China users are and what they do.

It’s a cross-border transfer — and an automated decision — under PIPL

Where that profile lives is what turns a marketing tool into a compliance exposure. mParticle by Rokt’s sub-processor list places its hosting on AWS in the United States, Frankfurt and Sydney, with no mainland-China region — so a user captured in the mainland is written to servers offshore. Under the Personal Information Protection Law that is a cross-border transfer (数据出境), and the handler — you, the company whose app embeds mParticle, not mParticle itself — must give notice, obtain a separate consent for the transfer, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (Articles 38–40).

But a CDP adds a second, sharper duty most teams miss. mParticle does not merely store the profile; it uses it to decide what each person sees — it can “offer personalized experiences at any touchpoint via the Profile API,” and its audiences “define sophisticated, intelligent segments” with a “machine learning engine” that “analyzes user behavior patterns.” Segmenting and personalizing from a profile is automated decision-making and profiling, which PIPL Article 24 governs directly: the individual is owed transparency and fairness, a way to refuse, and — where a push or decision rests on profiling — an option not to be targeted by their personal characteristics. A feature that quietly sorts your China users into cohorts and tailors their experience sits squarely inside Article 24.

Two more duties run alongside. Capturing behavioral events requires genuine consent for the tracking, not a buried “by using this product…” clause (PIPL Articles 13 and 23). And because the profile store is permanent and growing, an in-country storage duty can apply: Cybersecurity Law Article 39 (formerly Article 37) requires a critical information infrastructure operator or a high-volume handler to keep China personal information in the mainland — which offshore pods in the United States, Frankfurt or Sydney cannot satisfy. Every destination mParticle routes the profile onward to is, in turn, its own cross-border transfer to account for.

Reaching the SDK isn’t the question — keeping the decisioning in-country is

mParticle’s collection point is an SDK and an ingestion endpoint fronted by a content-delivery sub-processor, so from the mainland it can be slow or unreliable — a real delivery question, but the smaller half. The larger half is that mParticle is a managed, proprietary service: it publishes data-localization pods in the United States, Europe and Australia, but there is no open-source or self-hostable edition you could stand up inside China, and no mainland-China pod to select. So the lawful lever is not to make the offshore endpoint reachable — it is to keep the profile-building and the user data on an in-country path. In practice that means routing China users through a licensed in-country customer-data or experimentation alternative so the profile is resolved and stored in the mainland; minimizing and pseudonymizing whatever context still has to leave (resolve and decide with the least identifying data, ideally no raw identifiers); securing the Article 13/23 consent for the tracking; and honoring the Article 24 right to refuse profiling and to receive a non-profiled experience. What this is not is a tunnel that ships the same personal information offshore anyway — relocating the wire does not relocate the data, and the transfer and the automated decision both remain.

This is a risk map, not a verdict: how much exposure you carry turns on what you send mParticle, what you do with the profile, your role and data volumes, and who your users are — worth settling the specifics with counsel before you collect and personalize at scale.

The lawful path — map, localize, deliver

mParticle stays your customer data platform; nothing migrates. What 21YunBox adds is the compliance layer the CDP itself does not provide, in three moves.

Map. Our China team inventories what your mParticle implementation ingests from mainland users — the identities, events, device signals and IP-derived data — where it is resolved and stored, how the profile is used to decide what each user sees, and the consent basis behind it, then weighs the PIPL cross-border and Article 24 exposure against your entity, your role and your data volumes.

Localize. We keep the profile-building and the user data on an in-country path — a licensed domestic customer-data or experimentation alternative for China users, the targeting context minimized and pseudonymized, and the Article 24 opt-out honored — rather than shipping your China users’ profiles offshore. 21YunBox never uses or suggests circumvention of any kind.

Deliver. The app or site that runs on these decisions carries an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer, placed in front of the stack you already run, no rebuild and no second codebase.

The result is mParticle that runs legally and compliantly for your users in China: the profile and the decisioning stay on a lawful in-country footing, and the cross-border, consent and residency gaps become ours to map and close with you.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does mParticle have a data center or region in mainland China?
No. Per its sub-processor list, mParticle (now mParticle by Rokt) hosts on AWS in North Virginia, Frankfurt and Sydney, with data-localization pods in the US, EU and Australia only — there is no mainland-China region. Events and profiles for your China users are therefore resolved and stored offshore, which is a PIPL cross-border transfer by you, the handler who embeds mParticle.
Why is a CDP like mParticle an "automated decision" under PIPL Article 24?
Because it does not just store data — it builds audiences and personalizes what each user sees from their profile. PIPL Article 24 governs automated decision-making and profiling: China users are owed transparency, a way to refuse, and, where a decision rests on profiling, an option not to be targeted by their personal characteristics. Sorting your China users into cohorts or tailoring their experience falls inside it.
Can I self-host mParticle inside China to stay compliant?
No — mParticle is a managed, proprietary service with no open-source or self-hostable edition and no mainland-China pod. The lawful in-country path is to route China users through a licensed domestic customer-data or experimentation alternative, minimize and pseudonymize any context that still leaves, honor the Article 24 opt-out, and run the consuming app on ICP-filed, in-country delivery. This is a risk map to settle with counsel, not a verdict — 21YunBox maps it with you.

ARTICLES RELATED TO MPARTICLE

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.