Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Osano Work in China? Consent Data, PIPL Cross-Border & Data Residency

Osano is a consent-management and data-privacy platform — yet its own FAQ says it is "built entirely on top of Amazon Web Services," storing data in its "Dublin, Ireland data center" and "Virginia, USA data center," with no mainland-China region. For China that turns the IP addresses and consent signals it collects from your visitors into a cross-border transfer under PIPL — with no ICP-filing footing, no in-country storage, and a GDPR-shaped consent flow that does not by itself meet China's separate-consent regime. A compliance-first look at the exposure, and the lawful in-country path.

Does Osano work in China?

The irony is the answer: Osano is a consent-management and data-privacy platform that, run as-is for mainland China, can become a compliance exposure of its own. Reaching the banner isn't the problem — where it processes your Chinese users' consent signals, and how it takes their consent, is.

Osano's own FAQ says it is "built entirely on top of Amazon Web Services," storing data in its "Dublin, Ireland data center" and "Virginia, USA data center," with no mainland-China region. So the IP addresses, consent choices and cookie-scan records it collects from Chinese visitors are personal information processed offshore — a cross-border transfer PIPL governs (notice, separate consent and a transfer mechanism, Articles 38–40), with an in-country storage duty for a CIIO or large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). And because Osano is built for GDPR, its banner does not by itself meet PIPL's separate, specific consent for a cross-border transfer. The table below is Osano's own wording and the rule each line triggers.

This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →

What Osano's own documentation says about China

FactPrimary source
Osano's own FAQ places its data centers in Europe and the US — none in mainland China. Osano says it "stores de-identified data in our Dublin, Ireland data center," keeps administrator data "in our Virginia, USA data center," is "built entirely on top of Amazon Web Services," and fails over between Berlin and Frankfurt. For a consent platform that is the point in reverse: the record proving a Chinese user consented is held offshore — a cross-border transfer of personal information under PIPL (notice, separate consent and a transfer mechanism, Articles 38–40). Osano — FAQ ("Does Osano store visitor data?" / "Is Osano reliable?"), retrieved 2026-10-09; PIPL Articles 38–40
Osano itself treats the IP address it collects as personal information. Its FAQ says Osano "does not collect data about your users other than IP addresses, which are stored for 30 days," and advises that "in some jurisdictions, IP addresses are considered PII, so we do recommend adding Osano to your GDPR statement as a sub-processor." China is such a jurisdiction: under PIPL an IP address and online identifiers are personal information, and PIPL treats de-identified data as personal information still — only truly anonymized data falls outside the law. Osano — FAQ ("Does Osano collect PII on my users?"), retrieved 2026-10-09; PIPL Articles 4 and 73 (definitions)
A consent flow built for GDPR does not automatically satisfy China's consent regime. Osano is architected around Europe — it offers to act as a customer's EU GDPR representative and says it does not "transfer personal data outside of the European Economic Area." But PIPL runs a distinct regime: sensitive processing and any cross-border transfer each require a separate, specific consent that names the overseas recipient, purpose and data categories — not a bundled "accept all." A banner tuned to GDPR categories can leave you collecting consent in a shape China's law does not recognize. Osano — FAQ and GDPR Representative product page, retrieved 2026-10-09; PIPL Articles 29 and 39 (separate consent)
For some handlers the data must stay in China, and serving the banner from inside China triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore store cannot do. Any public site actually served from inside China must also carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Osano does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-09.

For an audience in mainland China, Osano carries the same awkward paradox any consent platform does: it is the product a company buys in order to show it handled personal information properly — cookie consent, consent records, cookie scanning, data-subject requests — yet aimed at China as it ships, it can quietly become an exposure of its own. The question is not whether the banner loads. It is that the IP addresses and consent signals Osano collects from your Chinese visitors are processed on infrastructure sitting in Europe and the United States, that the records of those choices are kept there, and that the consent flow itself is shaped for Europe’s law rather than China’s. The first is a data-residency and cross-border question under Chinese law; the second is a consent-regime question; neither is about speed. Osano settles the first in its own FAQ.

Osano's own FAQ, 'Does Osano store visitor data?', stating that Osano stores de-identified data in its Dublin, Ireland data center and keeps administrator data in its Virginia, USA data center — naming no mainland-China region
Osano's own FAQ states: “Osano stores de-identified data in our Dublin, Ireland data center and does not store identifiable information about your visitors, nor do we transfer personal data outside of the European Economic Area.” Administrator data it keeps “in our Virginia, USA data center.” Every region it names is European or US — none inside mainland China, so the record of a Chinese user's consent is itself held offshore. Source: Osano — FAQ (“Does Osano store visitor data?”)

Osano in China at a glance

What decides it In Osano's own terms — and China's law
What Osano collects Osano's FAQ says it collects visitors' IP addresses — held 30 days — and records their consent choices and cookie-scan results. Osano itself flags that “in some jurisdictions, IP addresses are considered PII” and asks to be named a sub-processor. Under PIPL, an IP address and online identifiers are personal information.
Where the records live Osano is “built entirely on top of Amazon Web Services,” storing data in its “Dublin, Ireland data center” and administrator data “in our Virginia, USA data center,” with failover between Berlin and Frankfurt. None of these is inside mainland China.
Your China users' data IP addresses and consent records collected from people in China and processed offshore are a cross-border transfer of personal information PIPL governs (Articles 38–40): notice, a separate consent, and one cleared transfer mechanism.
How consent is taken Osano's flow is built for GDPR — it even offers to act as your EU representative. China's PIPL requires separate, specific consent, and a further separate consent naming the overseas recipient before any cross-border transfer — which a GDPR-style banner does not automatically provide.
Residency & serving the public For a critical information infrastructure operator or a large-volume handler, personal information collected in China must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore store cannot do. A site served from inside China also needs an ICP filing bound to a mainland hosting resource Osano does not provide.

The uncomfortable part is structural, not incidental. Osano exists to collect and keep the proof that you handled personal information lawfully — who consented, to which cookie categories, when, and the trail behind a data-subject request. Yet its own FAQ says Osano is “built entirely on top of Amazon Web Services,” that it “stores de-identified data in our Dublin, Ireland data center,” and that administrator data lives “in our Virginia, USA data center,” with failover routing “requests to Frankfurt” when Berlin is down. Every location it names is European or American. So the proof that a Chinese visitor made a choice is itself kept outside the mainland — the privacy tool has produced the very cross-border record it is meant to help you govern.

Osano is candid about what it collects, too. Its FAQ says Osano “does not collect data about your users other than IP addresses, which are stored for 30 days,” and adds that “in some jurisdictions, IP addresses are considered PII, so we do recommend adding Osano to your GDPR statement as a sub-processor.” China is one of those jurisdictions: under the Personal Information Protection Law an IP address and other online identifiers are personal information. And PIPL draws a line Osano’s wording quietly crosses — de-identified data is still personal information under the law; only data that has been truly anonymized falls outside it. So “de-identified in Dublin” does not lift a Chinese visitor’s record out of PIPL’s scope; it simply places that record in Europe.

Processed offshore, that personal information is a cross-border transfer, and the duty lands on the personal-information handler — you, not Osano. You owe notice, a separate consent for the overseas transfer, and one cleared transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Above certain volumes, or where the records count as important data, the move may also require China’s data-export security assessment before anything leaves. The platform that gathers the consent does not absorb the obligation attached to wherever that consent is then stored.

This is where a consent manager differs from an ordinary offshore script — and where Osano’s design shows its origin. Osano is built around Europe’s regime: it offers to act as a customer’s EU GDPR representative, advises customers to update their “GDPR statement,” and says it does not “transfer personal data outside of the European Economic Area.” That is a genuine strength for Europe, and precisely the mismatch for China. PIPL’s consent regime is not GDPR’s with a translated banner. For sensitive processing, and for any cross-border transfer, PIPL requires a separate, specific consent — a distinct, affirmative act rather than a bundled “accept all” — and the cross-border consent must name the overseas recipient, the purpose, and the categories of data leaving the country. A cookie banner tuned to GDPR lawful bases and categories does not automatically produce any of that. Run Osano’s European consent experience for Chinese users and you can end up collecting consent in a shape China’s law does not recognize, while the record of it sits in Dublin.

No mainland region — so no in-country storage, and no ICP footing

Osano names AWS as its host and points to data centers in Ireland, Virginia and Germany; it publishes no mainland-China region. That single fact settles two more questions before performance is ever in frame.

First, residency. If you are a critical information infrastructure operator or a large-volume handler, personal information collected in China has to be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 — the data-localization provision renumbered from Article 37 by the 2025 Cybersecurity Law amendment that took effect on January 1, 2026, its substance unchanged). An offshore consent-and-log store cannot meet that duty however it is configured. Second, licensing. A public-facing site actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and the filing has to attach to a hosting resource physically in the mainland. Osano offers none, so there is nothing of Osano’s to file against. “We already run Osano for privacy” does not travel across the border; the clean data-handling story the platform promises is the very thing it leaves open here.

There is a reachability footnote, and for a consent gate it bites harder than for most scripts: a cookie-consent experience is loaded client-side and is often wired to hold the page until the visitor chooses. Delivered from Osano’s offshore AWS regions, that script makes the same cross-border hop every offshore asset makes into China, so it can load slowly or fail — and a gate that cannot load can stall the content it is meant to guard. That is a delivery problem, not a legal one, but on a China-facing site the two compound. We publish no first-party China latency figure for Osano here: speed is not the axis this turns on, and a number without a method, a sample and a date would only mislead. And one thing 21YunBox never does — and that no lawful provider can offer — is route around China’s data-export rules or any network restriction; we never use or suggest circumvention of any kind.

This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, in-country storage, a data-export assessment, an ICP filing, or some combination depends on your data volumes, your role as handler, and who your users are — worth settling with counsel before you depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run consent management for a China-facing audience, and it has a defined shape. First, map: our China team works through the PIPL cross-border and residency obligations that attach to the IP addresses, consent choices and request records a consent platform collects — against your entity, your data volumes and who your users are — and marks where a separate cross-border consent, a data-export assessment or an Article 39 storage duty applies. The legal calls are made with counsel; we build the technical picture those calls rest on.

Then localize: for the records that must stay in the country, we stand up and integrate a China-resident consent store and a PIPL-aligned consent flow — the lawful in-country pattern of consented, in-country processing and storage, with separate consent captured the way China’s regime expects — so what cannot lawfully leave the mainland no longer does, while you keep Osano for the markets where it already serves you.

Then deliver: the China-facing site or app that presents the consent gate is itself a public service in the mainland, so it carries an ICP-filing duty and needs compliant, in-country delivery. 21YunBox delivers it from inside the mainland — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The outcome is a consent and privacy setup that runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Osano store Chinese users' consent data in China?
No. By Osano's own FAQ it is "built entirely on top of Amazon Web Services," storing data in its "Dublin, Ireland data center" and "Virginia, USA data center," with failover to Frankfurt — every region outside the mainland. The IP addresses, consent choices and cookie-scan records it collects from Chinese visitors are processed offshore, which makes them a cross-border transfer of personal information under PIPL: the handler (you, not Osano) owes notice, a separate consent and a transfer mechanism.
If Osano is a privacy tool, how can it be a compliance risk in China?
Because compliance in China turns on where the data lives and how consent is taken, not on what the tool is for. A consent platform exists to prove you handled personal information lawfully — but if the proof is kept in Ireland or the US, you have created the exact cross-border transfer PIPL regulates, and for a CIIO or large-volume handler a residency duty an offshore store cannot meet. Osano even notes that an IP address is PII in some jurisdictions and asks to be listed as a sub-processor. Treat it as a risk to work through with counsel: using a privacy tool does not exempt the personal information it collects from China's transfer, residency and consent rules.
Can 21YunBox help make our Osano setup work in China?
Yes. Our China team can map your exposure — the PIPL cross-border, consent and data-residency obligations that attach to the IP addresses and consent records Osano collects, for your entity, data volumes and users — and stand up the ICP-filed, in-country delivery and a China-resident consent store a compliant presence requires, in front of the Osano stack you already run. Get in touch to work through your specific case.

ARTICLES RELATED TO OSANO

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.