Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does NAVEX Work in China? Whistleblower Reports, PIPL Sensitive-PI & Data Residency

NAVEX (formerly NAVEX Global) hosts customer data only in the US or the EU, with no mainland-China region, so the whistleblower reports, case files and contracts its EthicsPoint and NAVEX One tools hold come to rest offshore — a PIPL cross-border transfer of often-sensitive personal information. A compliance-first look at the residency, consent and ICP exposure, and the lawful in-country path.

Does NAVEX work in China?

Whether NAVEX "works" in mainland China is a data-residency question, not a speed one — the hotline reports and case files it holds are the most sensitive data you own.

NAVEX (formerly NAVEX Global) hosts customer data only in the US or the EU — stored in Frankfurt, backed up in Amsterdam — with no mainland-China region. So the whistleblower reports, investigation files and third-party contracts it collects from your China operations come to rest offshore: a PIPL cross-border transfer of often-sensitive (Article 28) personal information needing a separate consent, a transfer mechanism and a prior impact assessment. The lawful path keeps the records that must stay inside China on a consented, ICP-filed in-country footing.

What NAVEX's own documentation says about China

FactPrimary source
In NAVEX's own words, customer data is hosted in one of two regions — the US or the EU: "If your data is hosted in the EU, your data is safely stored and protected in Frankfurt, Germany, and backed up in Amsterdam, the Netherlands," and if hosted in the US it is "held in compliance with the requirements of the EU General Data Protection Regulation (GDPR)." No mainland-China region is offered. NAVEX — Data Privacy
NAVEX One's sub-processor list names Okta, Fivetran, Snowflake and Microsoft Azure, each operating in "Hosting and cloud infrastructure regions in the USA" and "in the European Union," with Microsoft providing "Azure for hosting." Every region listed is in the US or the EU — none in mainland China. NAVEX — NAVEX One sub-processors
A whistleblower or ethics-hotline report pairs a reporter's identity with allegations about identifiable people and often touches financial, health or alleged-criminal conduct — PIPL Article 28 sensitive personal information. Exporting it from China is a cross-border transfer requiring notice, a separate and specific consent, one transfer mechanism, and a prior personal-information protection impact assessment (PIPL Articles 38–40 and 55). Personal Information Protection Law (PIPL), Articles 28, 38–40, 55
For a critical information infrastructure operator or a large-volume handler, personal information generated in mainland China must be stored inside the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37 — renumbered by the 2025 amendment in force January 1, 2026, substance unchanged). No offshore NAVEX region can discharge that duty. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a whistleblower hotline and GRC platform like NAVEX — the ethics-and-compliance suite formerly branded NAVEX Global, with EthicsPoint at its core — whether it “works” in mainland China is not settled by whether an intake form loads. It is settled by where the records it holds are allowed to come to rest. NAVEX is the book of record for your most sensitive governance data: whistleblower and ethics-hotline reports that pair a reporter’s identity with allegations about named, identifiable people; investigation case files; third-party contracts and their signatories; risk registers; and board and policy materials. All of it is personal information, and the hotline reports are among the most sensitive a company ever holds. By NAVEX’s own data-privacy page, customer data is hosted in the US or the EU — stored in Frankfurt and backed up in Amsterdam — with no mainland-China region. Geography, not latency, is what China’s law responds to.

NAVEX's Data Privacy page stating that if your data is hosted in the US it meets the EU GDPR, and if hosted in the EU it is stored in Frankfurt, Germany and backed up in Amsterdam, the Netherlands — naming no mainland-China region
NAVEX's own Data Privacy page: “If your data is hosted in the EU, your data is safely stored and protected in Frankfurt, Germany, and backed up in Amsterdam, the Netherlands” — and the only other option it names is the US. Neither is mainland China, so the whistleblower reports, case files and contracts NAVEX holds for your China operations come to rest offshore. Source: navex.com/en-us/data-privacy
What decides it In NAVEX's own terms — and China's law
Where the records live NAVEX hosts customer data in one of two regions — the US or the EU. In its own words, “If your data is hosted in the EU, your data is safely stored and protected in Frankfurt, Germany, and backed up in Amsterdam, the Netherlands.” Its NAVEX One sub-processors (Okta, Fivetran, Snowflake and Microsoft Azure) run in “Hosting and cloud infrastructure regions in the USA” and “in the European Union.” No mainland-China region is named.
What it holds & why it's sensitive Whistleblower and ethics-hotline reports (EthicsPoint), investigation case files, third-party contracts and signatory details, risk registers, and board and policy records. A report pairs a reporter's identity with allegations about identifiable people and often touches financial, health or alleged-criminal conduct — PIPL Article 28 sensitive personal information.
Your China data crossing the border A report filed from your China operations, or a contract naming a China-based counterparty, is personal information collected in China. Holding it in a US or EU NAVEX environment is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, one transfer mechanism, and — for sensitive data — a separate, specific consent and a prior impact assessment.
In-country storage duty For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and a data-export security assessment may apply before anything leaves. No offshore NAVEX region can discharge that duty.
Reachability is not the axis Whether the intake form opens in China is the delivery half, not the decision. Any China-facing reporting surface actually served from inside the mainland also owes an ICP filing (备案). The exposure is where the reports rest, not whether the page paints.

No mainland region, so the reports leave the country

NAVEX publishes its hosting geography plainly. Its data-privacy page tells customers that “If your data is hosted in the US, your data is held in compliance with the requirements of the EU General Data Protection Regulation (GDPR),” and that “If your data is hosted in the EU, your data is safely stored and protected in Frankfurt, Germany, and backed up in Amsterdam, the Netherlands.” Two regions, both offshore. The NAVEX One sub-processor list says the same in operational terms — Okta, Fivetran, Snowflake and Microsoft Azure each run in “Hosting and cloud infrastructure regions in the USA” and “in the European Union” — and the WhistleB whistleblowing product states, “Our data centers are located within the EU.” Mainland China appears on none of these maps. So unless and until NAVEX opens an in-country region, every ethics report, case file, contract and risk record it collects from your China operations comes to rest in a US or EU NAVEX environment — a cross-border transfer of personal information from the moment it leaves the mainland.

A whistleblower report is sensitive personal information

What makes NAVEX’s exposure sharper than an ordinary application’s is the nature of what it holds. An ethics-hotline report is not a neutral record: it pairs a reporter — sometimes named, sometimes anonymous — with detailed allegations about identifiable colleagues, and it routinely touches financial wrongdoing, harassment, safety and health matters, or alleged criminal conduct. Under China’s Personal Information Protection Law (Article 28), that is sensitive personal information — information whose leak or misuse could readily harm a person’s dignity or safety. Processing it demands a specific purpose and demonstrated necessity, a separately obtained consent, and a prior personal-information protection impact assessment (Article 55) before the data is handled at all — and a second, specific consent again before it is sent abroad.

Here the irony sharpens into a genuine legal knot. The very tool a company deploys to run its ethics and compliance program is the one that carries the most sensitive reports it holds out of China. And the people in those reports are precisely the people who cannot freely consent to the export: a whistleblower who files anonymously has given consent to nothing, and the employee named in an allegation is hardly going to authorize shipping the accusation against them offshore. Moving sensitive reports across the border at volume can also pull in China’s data-export security assessment (数据出境安全评估) before anything leaves.

Narrowing the exposure doesn’t close the door

The reflex is to reach for the levers NAVEX and its peers offer — redact names from a report, pick the EU region over the US, restrict who can open a case, or ask about a self-managed deployment. Each of these is worth doing, and each reduces what crosses the border. None of them changes that it crosses. Choosing Frankfurt over a US data center moves sensitive reports from one offshore jurisdiction to another; it does not bring them inside mainland China. And China does not recognize EU Standard Contractual Clauses or the EU–US Data Privacy Framework — the GDPR-era safeguards NAVEX documents — as a lawful basis to export personal information out of the mainland; the recognized routes are a CAC security assessment, the CAC standard contract, or CAC-accredited certification. Redaction narrows the payload but leaves a residency question for whatever remains, and in-country storage duties (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) attach to the records themselves, not to how few of them travel.

This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, in-country storage, an ICP filing, or some combination of them turns on your entity, your data volumes, how much of what NAVEX holds is personal and sensitive, and who your reporters and subjects are — all of it worth settling with counsel before you route a single report through NAVEX.

The lawful path — map, localize, deliver

There is a lawful way to run NAVEX for an organization with people and operations in mainland China, and it has a definite shape. First, map: our China compliance team reads your PIPL cross-border, data-residency and sensitive-PI obligations against your actual entity, your data volumes, and who your reporters and data subjects are — which NAVEX records must stay on Chinese soil, which may lawfully cross the border, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty applies, and what your notice, consent and impact-assessment flow has to cover. The legal conclusions are reached with your counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a consented, in-country home for the records that must remain on the mainland — the sensitive reports and case data China law keeps in the country — including a self-managed deployment where NAVEX supports one, while you keep NAVEX as the system of record for everything that may lawfully travel.

Then deliver: any China-facing surface — an employee reporting portal, an intake or disclosure form actually served to people inside the mainland — is a public-facing service there, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. The 21YunBox Optimizer serves it from inside China, over ICP-filed infrastructure, in front of the NAVEX stack you already run — no rebuild, no second codebase, no migration. For your NAVEX investment we are a compliant overlay and a partner, not a replacement. The result is an ethics-and-compliance program that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does NAVEX store whistleblower and ethics-hotline data in China?
No. By NAVEX's own data-privacy page, customer data is hosted in the US or the EU — stored in Frankfurt, Germany and backed up in Amsterdam, the Netherlands — and none of its regions is in mainland China. So the reports, case files and contracts it collects from your China operations are stored offshore, which is what makes this a data-residency question rather than a speed one.
Is it against the law to use NAVEX in China?
Not inherently. The issue is the cross-border transfer of personal information, which PIPL permits if you give notice, obtain a separate consent and meet one transfer mechanism. The difficulty is that ethics-hotline reports are Article 28 sensitive personal information, and the people in them — an anonymous whistleblower, or an employee named in an allegation — often cannot freely consent to the export. Whether you also face in-country storage turns on your role and data volumes. Treat it as a risk to assess with counsel, not a blanket prohibition.
Can 21YunBox make our NAVEX setup compliant in China?
Yes. Our China team maps your PIPL cross-border, residency and sensitive-PI exposure for your entity and data volumes, then stands up a consented, ICP-filed in-country home for the records that must stay on the mainland — including a self-managed deployment where NAVEX supports one — while you keep NAVEX for everything that may lawfully travel. Get in touch to work through your specific case.

ARTICLES RELATED TO NAVEX

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.