Does Mural Work in China? PIPL Cross-Border, Data Residency & Employee-Data Rules
Mural is a collaborative whiteboard whose data is stored by default in the United States on Microsoft Azure, with Enterprise data residency only in North America, Europe, or Asia-Pacific — no mainland-China region. Running it for a China team puts your internal collaboration content and your collaborators' personal information offshore: a PIPL cross-border transfer, with Mural's usage analytics raising an Article 24 question — a compliance-first look at the residency, personal-data and automated-decision exposure.
Does Mural work in China?
Your internal collaboration content and your collaborators' personal information sit on Mural's offshore cloud — stored by default in the United States on Microsoft Azure, with no mainland-China region — a PIPL cross-border transfer, and Mural's usage analytics can profile your China collaborators under Article 24.
Mural is a collaborative whiteboard: it holds the murals, workshops and sticky notes your teams create (internal company content, sometimes confidential or carrying customer data), plus your collaborators' identities and activity, and the admin usage and engagement analytics that profile participants. Because that data is resident in the United States — Enterprise data residency reaches only North America, Europe, or Asia-Pacific — running Mural for a China team is a PIPL cross-border transfer of personal information, and wherever those analytics inform a decision about an individual it is Article 24 automated decision-making. The lawful lever is to keep the collaboration content and collaborator data in-country, handle the profiling duty, and ICP-file any China-facing surface — not to make the offshore platform reachable.
Whether your content is 'important data' and which duties bite turns on your sector and workforce — settle the specifics with counsel. Our China team can map your exposure →
What Mural's own documentation says about China
| Fact | Primary source |
|---|---|
| Mural stores customer data in the United States by default, with no mainland-China region. Mural's Trust & Security page states: “By default, Mural customer data is stored in the United States and hosted on Microsoft Azure,” and names no mainland-China location. | Mural, “Trust & Security” (mural.co), retrieved 2026-10-11 |
| Mural's data residency reaches only North America, Europe, or Asia-Pacific — never mainland China. Mural's data-residency announcement says Enterprise customers can designate where a mural's data is stored, “selecting from North America, Europe, or Asia-Pacific regions,” and its Trust & Security page confirms you can “designate the region where data is stored”; none of the options is in the mainland. | Mural, “Introducing data residency for Mural” (mural.co), retrieved 2026-10-11 |
| Keeping China collaborators' personal information on Mural's offshore cloud is a PIPL cross-border transfer. Under PIPL Articles 38–40, transferring personal information collected in mainland China to an offshore platform requires notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — on top of the Articles 13/23 notice-and-consent to collect it. | 21YunBox — Cross-border data transfers under PIPL, retrieved 2026-10-11 |
| Where Mural's analytics profile your China collaborators, PIPL Article 24 applies. When usage, engagement or activity analytics inform a decision about an individual made solely by automation, PIPL Article 24 lets that person refuse the solely-automated decision and requires an option not targeted at their personal characteristics. For a critical information infrastructure operator or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. | 21YunBox — China's Personal Information Protection Law, retrieved 2026-10-11 |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a team running Mural across a China operation, the instinct is to ask whether the whiteboard loads from Shanghai. It does — Mural is not blocked — so reachability is not the question. What settles it is where the work you keep in Mural lives: the murals, workshops and sticky notes your teams build are internal company content — sometimes confidential, sometimes carrying customer personal information — and alongside them Mural holds your collaborators’ identities and their activity. Mural’s Trust & Security page states that, by default, customer data is stored in the United States and hosted on Microsoft Azure, with Enterprise data residency reaching only North America, Europe, or Asia-Pacific and no mainland-China region. So that content and those records rest offshore: a PIPL cross-border transfer of personal information (Articles 38–40, 数据出境) with an Articles 13/23 consent duty, an Article 24 question wherever Mural’s analytics profile your China collaborators, an internal-content and important-data residency question, a CIIO or high-volume in-country storage duty, and an ICP filing for any China-facing surface.
Mural in China at a glance
| What decides it | In Mural's own terms — and China's law |
|---|---|
| What it holds | Mural holds your visual collaboration content — murals, workshops, sticky notes, diagrams, uploaded documents and images your teams create — which is internal company material, sometimes confidential and sometimes carrying customer personal information. It also holds your collaborators' identities (the member directory) and their activity: audit logs, and the usage and engagement analytics an administrator can see. |
| Where it runs | Offshore. Mural's Trust & Security page states that "By default, Mural customer data is stored in the United States and hosted on Microsoft Azure," and its Enterprise data residency lets you designate only North America, Europe, or Asia-Pacific — there is no mainland-China region. So the content and the collaborator records come to rest outside China: a cross-border transfer (数据出境) of personal information under PIPL Articles 38–40, with the Articles 13/23 notice-and-consent duty for collecting it. |
| The automated-decision door | Mural does not only store your people's data; its usage, engagement and activity analytics can profile the individuals who collaborate. Wherever that profiling informs a decision about a person made solely by automation — an engagement ranking, a nudge, flagging the inactive — it is automated decision-making under PIPL Article 24: the individual may refuse a decision made solely by automated means, and profiling must offer an option not targeted at their personal characteristics. This is the half a reachability check misses. |
| Residency of content and personal data | The collaborator directory and activity data is ordinary personal information — not "sensitive" under Article 28 unless your people paste identity or financial-account numbers onto a board. Collecting it needs the Article 13/23 notice-and-consent. A critical information infrastructure operator or high-volume handler must store China-generated personal information in the mainland under the Cybersecurity Law's Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). Collaboration content at volume or in a sensitive sector can also raise the "important data" (重要数据) question. |
| Reachability is not the axis | Whether the Mural board opens from the mainland is not the decision; where your collaboration content and your collaborators' personal information live, on what legal basis, and whether the platform profiles those people, is. The lawful path keeps the China content and collaborator data in-country — a China-resident path or a China-legal domestic alternative, with minimization — handles any Article 24 duty, and delivers any China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never moves personal information offshore by stealth. |
What it actually holds — your internal content and your people’s data
Mural does not hold an abstraction; it holds the work your teams make and a record of the people who make it. The visual collaboration content — the murals, the workshop boards, the sticky notes, the diagrams, the uploaded documents and images — is internal company material. Some of it is confidential (a product roadmap, an org design, a reorganization plan sketched on a board), and some of it carries other people’s personal information (customer names on a journey map, interview notes, research participants on a research wall). Mural’s own governance features acknowledge this: its Trust & Security page lists audit logs, SIEM support and eDiscovery, because the platform is a system of record for that content and for who touched it.
Alongside the content, Mural holds your collaborators — the member directory of identities, and their activity. For an administrator, that activity is not just a log: Mural surfaces usage and engagement reporting about who is active, who is collaborating, how the platform is adopted. That reporting profiles the individuals behind it.
Where does all of it live? Offshore. Mural’s Trust & Security page states plainly that “By default, Mural customer data is stored in the United States and hosted on Microsoft Azure.” Its Enterprise data residency, as Mural describes it, lets customers “designate the region where data is stored,” selecting from North America, Europe, or Asia-Pacific regions — none of which is in mainland China. So the moment your China team opens a board, the content they create and the record of them creating it rest outside the country.
The doors: personal data, cross-border transfer, and automated decisions
Once the content and the collaborator records are offshore, a different body of law decides whether they were allowed to go. The collaborator identities and activity Mural holds for your China team are personal information under China’s Personal Information Protection Law, and keeping them on a platform stored in the United States is a cross-border transfer (数据出境). PIPL puts the duty on the handler — your China entity, not Mural the processor: Articles 38–40 require notice, a separate consent distinct from general terms of use, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — with the minimization duties of Articles 13 and 23. The collaborator directory is ordinary personal information; it does not become “sensitive” under Article 28 unless your people put identity or financial-account numbers onto a board, which is a content-governance question of its own.
The distinctive door for a collaboration platform is the automated-decision one. Mural does not only store your people’s data; its usage and engagement analytics profile the individuals who collaborate. The moment that profiling drives or informs a decision about a person made solely by automated means — ranking engagement, flagging the inactive, nudging a user — that is automated decision-making under PIPL Article 24, which lets the individual refuse a decision made solely by automation and requires that profiling offer an option not targeted at their personal characteristics. Analytics over a China workforce also sit against China’s employee-monitoring and labor norms — a separate matter to settle with counsel.
Residency sits underneath all of it. If your organization is a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37) requires personal information generated in China to be stored in the mainland — a duty no offshore Mural region can meet. And collaboration content at volume, or in a sensitive sector, can raise the “important data” (重要数据) question under the Data Security Law, which can make a CAC data-export security assessment (数据出境安全评估) mandatory before anything leaves. Which doors apply, and in what combination, depends on your sector, your data volumes and your role as handler.
Logging in isn’t the question — compliant in-country data is
Because Mural is a cloud collaboration service stored by default in the United States, with Enterprise data residency reaching only North America, Europe, or Asia-Pacific and no mainland-China region, you cannot localize the data by relocating the product: there is nothing in the mainland to provision, and moving between offshore regions only relocates the transfer, it does not end it. The lawful shape is therefore to keep the China collaboration content and the China collaborators’ personal information on an in-country footing — a China-resident path or a China-legal domestic alternative — send out of the country only what may lawfully leave, obtain the Article 13/23 notice-and-consent, handle any Article 24 automated-decision and important-data duty, and treat any China-facing surface the platform serves — a public knowledge base, an external microsite, an embedded board on a customer-facing page — as a public service that carries an ICP filing duty and needs compliant, in-country delivery. That is a residency-and-delivery design, not a matter of making an offshore board load faster, and never a hidden path that ships the data offshore anyway.
None of this is a verdict that Mural is “blocked” or “illegal.” Whether your collaboration content is “important data,” whether you owe a transfer mechanism, in-country storage, an Article 24 explanation, or an ICP filing, and which duties bite, turns on your sector and workforce — a brainstorming board of sticky notes is not a wall of customer records. Settle the specifics with counsel before your China team depends on it.
The lawful path — map, localize, deliver
There is a compliant way to run visual collaboration for a China operation, and it has a shape. First, map: our China team inventories what you keep in Mural — which boards and content your China team creates, which of it is confidential or carries customer personal information, the collaborator directory and activity it holds, whether Mural’s usage and engagement analytics profile individuals (Article 24), where each is stored (a United States region by default, with residency only in North America, Europe, or Asia-Pacific), the cross-border and consent basis, and whether any content is “important data.” The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: because Mural offers no mainland region to localize onto, we help you keep the China collaboration content and collaborator data on a China-resident footing — a consented, in-country path, or a China-legal domestic alternative where that is the right fit — with minimization, so the China content and personal data stay resident and stop leaving the country by default, while you keep Mural for your other markets. We obtain the Article 13/23 notice-and-consent and handle any Article 24 profiling duty and its opt-out. Localize means keeping the data on an in-country path — never a tunnel that ships it offshore anyway.
Then deliver: any China-facing surface Mural serves — a public knowledge base, an external microsite, an embedded board — is a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no re-platform, so your mainland users reach it reliably on ICP-filed infrastructure. The result is a collaboration stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We localize what must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth. 21YunBox is a compliance partner that sits in front of Mural, not a competitor to it.
Related reading:
- China’s Personal Information Protection Law (Articles 13/23, 24, 38–40)
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law (data localization, Article 39 formerly 37)
- How to get an ICP filing for China
