Does Oracle CX Work in China? Customer Data Residency, PIPL Cross-Border & ICP
Oracle CX — the Sales, Service, Marketing (Eloqua) and CPQ applications on Oracle Cloud Infrastructure — is reachable from mainland China, so speed is not the question; residency is. A standard instance runs in an offshore OCI region, and Oracle's own policy states it has no data centers in China, so your China customers' and agents' records rest abroad — a PIPL cross-border transfer. A compliance-first look at the residency, sensitive-PI and cross-border exposure, and the lawful in-country path.
Does Oracle CX work in China?
Yes — Oracle CX opens fine from mainland China, so reachability was never the question; data residency is.
Oracle CX is a system of record of people — the contacts, accounts, cases, service history, marketing profiles and agent logins behind Sales, Service, Marketing (Eloqua) and CPQ — so nearly everything in it is personal information. A standard instance runs in an offshore Oracle Cloud Infrastructure region, and Oracle's own Cloud Hosting and Delivery Policies state it has “no data centers in China,” so holding your China customers' and agents' records in it is a cross-border transfer under PIPL (Articles 38–40: notice, a separate consent, a transfer mechanism). For a critical information infrastructure operator, personal information collected in China must be stored in China under Cybersecurity Law Article 39 (formerly Article 37) — a duty an offshore region cannot meet, and larger or sensitive transfers can add a CAC data-export security assessment.
Which duties bite turns on your entity, data and users, so settle specifics with counsel. Our China team can map your exposure →
What Oracle CX's own documentation says about China
| Fact | Primary source |
|---|---|
| Oracle states it has no data centers in China. Oracle's Cloud Hosting and Delivery Policies define the Asia-Pacific region as “the Asia-Pacific geography, except China as Oracle has no data centers in China,” and say “Your Content will be stored in the Data Center Region applicable to such Services.” So a standard Oracle CX instance is provisioned in an offshore OCI region, not the mainland. | Oracle Cloud Hosting and Delivery Policies (Effective September 2026), retrieved 2026-10-10 |
| Oracle CX runs on Oracle Cloud Infrastructure, and OCI has no mainland-China commercial region. Oracle's public region documentation lists Asia-Pacific regions in Japan (Tokyo, Osaka), South Korea (Seoul, Chuncheon), Singapore, India (Mumbai, Hyderabad), Indonesia (Batam), Malaysia (Kulai) and Australia (Sydney, Melbourne) — none in mainland China. | Oracle — Regions and Availability Domains (OCI documentation), retrieved 2026-10-10 |
| Holding China customer data offshore is a cross-border transfer, and the duty is yours. Under PIPL Articles 38–40, exporting personal information collected in China requires notice, one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and — where consent is the basis — a separate consent; the obligation falls on the personal-information handler (you), not on Oracle as processor. | Personal Information Protection Law of the PRC, Articles 38–40 |
| A CIIO must store China personal information in China. Cybersecurity Law Article 39 (formerly Article 37) — renumbered by the 2025 amendment in force January 1, 2026, substance unchanged — with PIPL Article 40 requires a critical information infrastructure operator to store personal information collected in China on the mainland, a duty an offshore OCI region cannot satisfy. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); PIPL Article 40 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a customer-experience platform, “does Oracle CX work in China” is decided long before anyone times a page load. Oracle CX — Oracle’s suite of customer-experience applications, spanning Oracle Sales, Oracle Service, Oracle Marketing (including Eloqua) and CPQ, delivered on Oracle Cloud Infrastructure (OCI) — is browser-based software that reaches the mainland perfectly well. What the question really turns on is geography: where the customer records it holds come to rest, and whether they were permitted to leave China in the first place. A CX suite is, by design, a system of record of people — the contacts and accounts in your pipeline, the cases and conversations in Service, the profiles and consent state in Marketing, and the accounts of the agents who work it — so nearly everything in it is personal information. Oracle answers the geography half in its own contract policies, and for a standard Oracle CX instance the answer is offshore: Oracle states plainly that it has no data centers in China.
Oracle CX in China at a glance
| What decides it | In Oracle CX's own terms — and China's law |
|---|---|
| Where the records live | Offshore, by default. Oracle's Cloud Hosting and Delivery Policies define the Asia-Pacific region as “the Asia-Pacific geography, except China as Oracle has no data centers in China,” and say “Your Content will be stored in the Data Center Region applicable to such Services.” A standard Oracle CX instance therefore sits in an offshore OCI region — the nearest are Tokyo, Osaka, Seoul, Singapore, Mumbai and Sydney. |
| What it holds, and why it's personal information | Oracle CX — Sales, Service, Marketing (Eloqua) and CPQ — is a system of record of people: contacts, leads and accounts, cases and interaction history, marketing profiles and consent state, plus the accounts of the agents who operate it. Nearly all of it is personal information, and Service cases can hold sensitive personal information — payment-card, government-ID, health or financial detail — under PIPL Articles 28–29. |
| Your China customers' and agents' data = cross-border | Collecting personal information from customers or agents in mainland China into an offshore Oracle CX instance is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, one transfer mechanism, and — where consent is your basis — a separate consent for the overseas transfer. The duty sits with you as the personal-information handler, not with Oracle the processor. |
| In-country storage duty | For a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) — a duty an offshore OCI region cannot meet. High-volume or sensitive transfers can also require a CAC data-export security assessment before anything leaves. |
| Reachability is not the axis | Oracle CX opens from the mainland like any browser-based SaaS, so reachability is not the China question. But any China-facing surface — a customer support portal, a web-to-case or self-service form, a help center served to mainland users — is a public service there and carries an ICP filing (备案) duty bound to a mainland hosting resource. |
No mainland region, so your customer records leave the country
Oracle CX is delivered on Oracle Cloud Infrastructure, and your instance lives in whichever region it was provisioned in. Oracle’s Cloud Hosting and Delivery Policies — the contract document that governs where “Your Content” is stored — define the Asia-Pacific region as “the Asia-Pacific geography, except China as Oracle has no data centers in China,” and state that “Your Content will be stored in the Data Center Region applicable to such Services.” The OCI commercial realms bear this out: across the Asia-Pacific regions Oracle publishes — in Japan (Tokyo, Osaka), South Korea (Seoul, Chuncheon), Singapore, India (Mumbai, Hyderabad), Indonesia (Batam), Malaysia (Kulai) and Australia (Sydney, Melbourne) — none is in mainland China; the nearest to it are Tokyo, Seoul and Singapore.
So the conclusion is structural, not a tuning problem: a standard Oracle CX instance serving your China customers is hosted offshore because Oracle offers no mainland region to provision it in. The contacts, accounts, cases and service history your China operation enters into Sales, Service and Marketing all come to rest in another country. That same offshore OCI footing governs Oracle’s Fusion-suite siblings — Oracle Fusion Cloud ERP and Oracle HCM Cloud — and it is where every China compliance question about Oracle CX begins, settled before performance is ever discussed. For that reason this page publishes no first-party China latency figure for Oracle CX: a lawful in-country cloud is not what the decision turns on — residency is.
A CX record is personal information — and some of it is sensitive
Once the records are offshore, a different body of law decides whether they were allowed to go there. A CX suite makes that unusually stark: where a finance ledger mixes figures with some personal records, Oracle CX is personal information almost end to end. Every contact and lead is a named individual; every account carries the people who work there; every Service case records a conversation with a customer; Marketing holds consent state and behavioral history; and the agent and user accounts that operate it are themselves personal data. Collecting that from people in mainland China and holding it in an offshore Oracle CX instance is a cross-border transfer (数据出境) of personal information under the Personal Information Protection Law. PIPL puts the duty on the personal-information handler — you, not Oracle the processor: Articles 38–40 require notice, one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and, where consent is your basis, a separate consent for the overseas transfer. Where the CX stack also drives marketing automation, lead scoring or profiling, the automated-decision rules add their own consent and transparency duties on top.
Part of a CX record can also be sensitive personal information. Service cases routinely capture payment-card and bank details, government-ID numbers, and health or financial disclosures as customers explain a problem, and marketing or profiling data can infer sensitive attributes. Where that is so, PIPL (Articles 28–29) adds a specific-purpose, separate-consent and personal-information-protection-impact-assessment bar (Article 55). And moving sensitive or high-volume personal information across the border can trigger China’s data-export security assessment (数据出境安全评估) before anything leaves. The exposure is therefore sharper for a CX system than for an ordinary application, because of both what it holds and how much of it is identifiable.
Narrowing the exposure doesn’t close the door
There are real levers to reduce what crosses the border. You can provision the instance in the nearest APAC region, redact or tokenize fields, limit which modules hold China customer data, and keep only what you must. Oracle also offers in-country infrastructure — OCI Dedicated Region and Cloud@Customer can place Oracle-managed hardware inside a customer’s own facility. But each of these changes what crosses the border, or where the bytes sit; none changes that the processing is governed by Chinese law. A redacted record exported offshore is still an export. An in-country Dedicated Region settles residency for the data that lives on it, yet if any of that data still flows to a global, offshore Oracle CX instance for group reporting, that flow is a cross-border transfer in its own right — and the in-country hardware does not, by itself, discharge the notice, consent, assessment or filing duties.
Beneath all of it sits residency. For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in the mainland (Cybersecurity Law Article 39 (formerly Article 37 — the data-localization article renumbered by the 2025 Cybersecurity Law amendment that took effect on January 1, 2026, its substance unchanged); PIPL Article 40) — a duty an offshore OCI region cannot satisfy. And any China-facing surface of the system — a customer support portal, a web-to-case or self-service form, a help center actually served to people in the mainland — is a public service there, so it carries an ICP filing (备案) duty bound to a mainland hosting resource. Which of these bite your organization turns on your entity, your data volumes and who your users are, so treat each as a risk to settle with counsel against what you actually deploy — not a verdict that Oracle CX is “blocked” or “illegal.”
The lawful path — map, localize, deliver
There is a lawful way to run Oracle CX for a customer base that includes mainland China, and it has a shape. First, map: our China team works through your PIPL exposure — which customer and agent records collected in China must stay in the country, what may lawfully leave for a global CX instance, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty bites, and what your notice, consent and impact-assessment flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we stand up and integrate a consented, China-resident home for the China customer records that have to stay, while you keep Oracle CX as the system of record for the rest of your customer base, sending it only what may lawfully cross the border. Where an in-country Oracle deployment is the right fit, we help you weigh it for what it is — a residency footing, not a compliance shortcut.
Then deliver: the China-facing surfaces — the support portals, self-service pages, web-to-case and help-center forms your mainland customers actually open — need compliant, in-country delivery, and a public-facing service in the mainland carries an ICP filing duty. The 21YunBox Optimizer delivers them in-country, in front of what you already run, with no rebuild and no re-platform. 21YunBox is a compliant overlay, not a migration — and a partner to Oracle CX, not a competitor. The result is a customer-experience stack that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is move personal information out of China by stealth: we localize what must stay and deliver in-country. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment measures
- China’s Cybersecurity Law — Article 39 (formerly Article 37) and data localization
- How to get an ICP filing for China
