Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does o9 Solutions Work in China? PIPL Cross-Border, Data Residency & Important-Data Rules

o9 Solutions runs its Digital Brain planning platform as cloud-native SaaS on global hyperscalers (Microsoft Azure, Google Cloud, AWS) with no mainland-China region, so your China operation's supplier contacts and supply-chain data sit offshore — a PIPL cross-border transfer, and supply-chain data that can be 'important data' needing a CAC data-export security assessment before it leaves. A compliance-first look at the residency, important-data and cross-border exposure.

Does o9 Solutions work in China?

Run your China operation on o9's Digital Brain and its supplier contacts and supply-chain data sit on an offshore hyperscaler cloud with no mainland-China region — a PIPL cross-border transfer — and the supply-chain data itself can be "important data" (重要数据) that cannot leave without a CAC data-export security assessment.

o9 is cloud-native planning SaaS, delivered from the global regions of Microsoft Azure, Google Cloud and AWS; it holds your demand, inventory, logistics and supply-network data plus the planner, supplier and partner contacts that are personal information. Holding that offshore for a China entity is a PIPL cross-border transfer (notice, separate consent, a transfer mechanism), and supply-chain data in a strategic sector can be important data needing a CAC data-export security assessment before it leaves. The lawful lever is to keep the supplier and supply-chain data in-country, classify and handle any important data, and ICP-file any China-facing surface — not to make the offshore platform reachable.

This is a risk map, not a verdict — whether your supply-chain data is important data turns on your sector, and it's worth settling with counsel. Our China team can map your exposure →

What o9 Solutions's own documentation says about China

FactPrimary source
o9 runs the Digital Brain as cloud-native SaaS on global hyperscalers — with no mainland-China region. In o9's own announcement, "Microsoft Azure customers worldwide now have access to the o9 Digital Brain," and "as a cloud native company, o9 can deploy both on its own Azure tenant and any client's Azure tenant"; the platform is equally offered on Google Cloud and AWS. All are offshore for a China operation, which makes holding supplier and supply-chain data in them a cross-border transfer under PIPL. o9 Solutions — "The o9 Digital Brain Now Available in the Microsoft Azure Marketplace," retrieved 2026-10-11
It holds exactly the data most exposed to the important-data rules: the multi-tier supply chain. o9 describes a platform for "matching demand and supply and driving collaboration across the multi-tier supply chain" — demand forecasts, inventory, logistics, production and supply-network data — and its own security page lists certifications including TISAX, the automotive-industry supply-chain security standard. Consolidated supply-chain data like this, in a strategic sector, is what the Data Security Law can treat as important data (重要数据). o9 Solutions — company platform description and Security page (certifications incl. TISAX), retrieved 2026-10-11
Exporting "important data" abroad requires a CAC security assessment first — no personal information needed to trigger it. Under the Data Security Law and the Measures for the Security Assessment of Outbound Data, transferring important data out of China requires a mandatory CAC data-export security assessment before anything leaves, regardless of whether personal information is involved or in what volume. Whether your supply-chain data is important data turns on your sector and the applicable catalogs. 21YunBox — China data-export security assessment (CAC), retrieved 2026-10-11
The cross-border and residency duties fall on you, the handler — not on o9. For supplier and employee personal information moved offshore, PIPL Articles 38–40 require notice, a separate consent and a transfer mechanism; a CIIO or high-volume handler must store China personal information in the mainland under Cybersecurity Law Article 39 (formerly Article 37); and any China-facing supplier portal carries an ICP filing duty bound to a mainland host. 21YunBox — cross-border data transfers under PIPL; Cybersecurity Law; ICP filing, retrieved 2026-10-11

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running o9 Solutions in mainland China, the question is not whether planners can open the Digital Brain from Shanghai — it is where the supplier and supply-chain data they feed it rests, and whether any of it is “important data” that cannot leave China without a government assessment. o9 is a cloud-native planning platform whose Digital Brain holds demand, inventory, logistics, production and multi-tier supply-network data, plus the planner, supplier and partner contacts that are personal information. It is delivered as SaaS from the global regions of Microsoft Azure, Google Cloud and AWS, with no mainland-China region named, so a China operation’s data rests offshore. That opens four doors: cross-border transfer of supplier and employee personal information; the “important data” (重要数据) door, where supply-chain data can need a CAC data-export security assessment before it leaves; in-country storage for a CIIO or high-volume handler; and ICP filing for any China-facing surface.

o9 Solutions press release, The o9 Digital Brain Now Available in the Microsoft Azure Marketplace, stating that Microsoft Azure customers worldwide now have access to the o9 Digital Brain and that, as a cloud native company, o9 can deploy on its own Azure tenant or any client's Azure tenant
"Microsoft Azure customers worldwide now have access to the o9 Digital Brain" — o9's own announcement describes a cloud-native SaaS it runs from a hyperscaler's global regions, deployed on its own or a client's Azure tenant and equally offered on Google Cloud and AWS, with no mainland-China region named; for a China operation that means the supplier and supply-chain data it holds rests offshore. Source: o9 Solutions — Azure Marketplace announcement

o9 Solutions in China at a glance

What decides it In o9's own terms — and China's law
What o9 holds An end-to-end planning system of record: demand forecasts, inventory and logistics, production and capacity plans, and the multi-tier supply-network map that ties your suppliers together, all unified in o9's Enterprise Knowledge Graph. Alongside it sits personal information — the planner, buyer, approver, supplier and partner contacts who use and populate the platform.
Where the data runs o9 is cloud-native SaaS. By its own account it deploys on its own or a client's Microsoft Azure tenant, and it is equally available on Google Cloud and AWS — delivered from those providers' global regions, with no mainland-China region named. For a China operation, supplier and supply-chain data held in those offshore regions is a cross-border transfer (数据出境) under PIPL Articles 38–40.
The important-data door Supply-chain data — supply-network maps, logistics and inventory, production and capacity, consolidated sourcing — can be classified as "important data" (重要数据) under the Data Security Law and the sectoral catalogs, especially in strategic sectors such as automotive, pharmaceuticals, energy, food and manufacturing. Exporting important data abroad requires a mandatory CAC data-export security assessment before anything leaves — regardless of whether any personal information is involved.
Supplier PII + residency The supplier, planner and employee contacts are personal information: PIPL Articles 13 and 23 require a lawful basis and a separate consent before they move abroad. And where your organization is a critical information infrastructure operator or a high-volume handler, China personal information must be stored in the mainland under the Cybersecurity Law's data-localization rule — a duty an offshore instance cannot meet.
Reachability is not the axis Whether the Digital Brain loads quickly from the mainland is an operational matter, not the compliance question. What decides it is which infrastructure holds the China supplier and supply-chain data — kept in-country on an in-country data path, classified and minimized — and whether any China-facing surface is ICP-filed and delivered compliantly. 21YunBox maps the exposure and stands up that in-country path in front of the o9 stack you already run.

What you actually hold — supplier data, spend, and the supply chain

o9 Solutions is the planning system of record for the operation that runs it. Its Digital Brain — an Enterprise Knowledge Graph spanning demand, supply and integrated business planning — holds the data your China operation plans on: demand forecasts and sell-through, inventory positions and logistics, production and capacity, procurement and sourcing signals, and the multi-tier supply-network map that links your suppliers, plants and distribution together. On top of that operational data sit the people: the planners, buyers, approvers, supplier and partner contacts whose names, work emails and roles are personal information under Chinese law.

Where does all of it run? o9 is cloud-native SaaS, not software you install in your own data center. By o9’s own announcements it deploys on its own or a client’s Microsoft Azure tenant, and the Digital Brain is equally offered on Google Cloud and AWS — delivered from those hyperscalers’ global regions. o9 names no mainland-China region, so for a China entity the supplier and supply-chain data lands offshore by default. Because the platform is cloud-native, the residency lever is not a traditional on-premises install but an in-country data path: keeping the China data on the mainland, classifying it, and minimizing what the global instance ever sees.

The doors: cross-border personal data, important data, and in-country storage

Once China supplier and supply-chain data comes to rest outside the mainland, a different body of law decides whether it was allowed to go there — and for a planning platform there are two distinct doors, not one.

The first is personal information. The supplier, planner, approver and employee contacts inside o9 are personal information under the Personal Information Protection Law, and holding them in an offshore instance is a cross-border transfer (数据出境). PIPL puts the duty on the handler — your China entity, not o9: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), with the Article 13/23 lawful basis underneath.

The second door is the distinctive one, and it has nothing to do with personal information. Supply-chain data — supply-network maps, logistics and inventory, production and capacity, consolidated sourcing — can itself be classified as “important data” (重要数据) under China’s Data Security Law and the national and sectoral important-data catalogs, especially in strategic sectors such as automotive, pharmaceuticals, energy, food, and manufacturing. Transferring important data abroad requires a mandatory CAC data-export security assessment before anything leaves — regardless of whether any personal information is involved, and regardless of volume. Whether your supply-chain data is important data turns on your sector and the applicable catalogs; it is a risk to classify, not a foregone conclusion.

On residency: if your organization is a critical information infrastructure operator or a large-volume handler, Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) requires personal information generated in China to be stored in China, an in-country duty an offshore o9 instance cannot satisfy. Which of these doors bite your specific deployment turns on your sector, your data volumes and your role under Chinese law.

Logging in isn’t the question — a compliant in-country supply chain is

The fix for o9 is not to make an offshore instance reachable — it is to put the China data where the law needs it. Because o9 is cloud-native rather than something you can simply install on a mainland server, the lever is an in-country data path: keeping the China supplier and supply-chain data on the mainland, classifying it so any “important data” is identified before it would ever move, minimizing what the global Digital Brain receives, and handling any cross-border transfer and data-export assessment lawfully. That is localization in the real sense — keeping the data on an in-country path — not a tunnel that ships it offshore anyway. On top of the platform, o9 exposes China-facing surfaces: a supplier collaboration portal, an SRM self-service page, partner logins. Any such service actually served to users in the mainland is an internet information service, so it carries an ICP filing (备案) duty bound to a mainland hosting resource, plus compliant in-country delivery. None of this is a verdict that o9 is “blocked” or “illegal” in China — it runs there lawfully when the pieces line up. It is a residency-and-exposure map, and which path fits turns on your entity, your data and your users — so settle the specifics with counsel before your China supply chain depends on it.

The lawful path — map, localize, deliver

There is a compliant way to run supply-chain planning for a China operation, and it has a shape. First, map: our China team inventories what your o9 instance holds — the supplier and partner PII, the demand, inventory, logistics, production and supply-network data — where each is processed and stored today (offshore hyperscaler regions, with no mainland-China region), whether any of it is “important data” (重要数据), the deployment options open to you, and the consent, residency and assessment basis each transfer would need. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we help you keep the China supplier and supply-chain data in-country — on an in-country data path, classified and minimized — so the data your mainland entity must keep in the country stops leaving it by default, while your global Digital Brain keeps serving your other markets. We handle any important-data classification and data-export-assessment duty, and help you obtain the Article 13/23 consent for supplier and employee PII. Localize means keeping the data on an in-country path, never moving it offshore by stealth.

Then deliver: any China-facing surface on top of the stack — a supplier portal, an SRM page — needs compliant, in-country delivery and carries an ICP filing duty. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a supply-chain footprint that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and never move personal information or important data across the border by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does o9 Solutions store your China supply-chain and supplier data in China?
Not by default. o9 is cloud-native SaaS delivered from the global regions of Microsoft Azure, Google Cloud and AWS, and it names no mainland-China region. The demand, inventory, logistics and supply-network data your China operation plans on, along with the supplier and planner contacts that are personal information, therefore rest offshore — which makes them a cross-border transfer under PIPL. The handler (you, not o9) owes notice, a separate consent and a transfer mechanism, and a CIIO or high-volume handler owes in-country storage.
Is our supply-chain data 'important data' (重要数据) under Chinese law?
It can be, and that is the distinctive risk for a planning platform. Supply-network maps, logistics and inventory, production and capacity, and consolidated sourcing data can be classified as important data under the Data Security Law and the sectoral catalogs, especially in strategic sectors such as automotive, pharmaceuticals, energy, food and manufacturing. If it is, exporting it abroad requires a mandatory CAC data-export security assessment before anything leaves — regardless of whether any personal information is involved. Whether it applies to you turns on your sector and the applicable catalogs, so it is a risk to classify with counsel, not a blanket rule.
Can 21YunBox help run o9 Solutions compliantly in China?
Yes. Our China team can map your exposure — what your o9 instance holds, where it runs, which data is personal information and which may be important data — and help you keep the China supplier and supply-chain data on an in-country path, classified and minimized, with any important-data and cross-border duties handled lawfully. We also stand up the ICP-filed, in-country delivery any China-facing supplier portal needs, in front of the o9 stack you already run. Get in touch to work through your specific case.

ARTICLES RELATED TO O9 SOLUTIONS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.