Does PagerDuty Work in China? Data Residency, PIPL & Your Responder Data
PagerDuty runs only two service regions — the US and the EU — with no site inside mainland China, so the responder contact details and incident payloads it holds for your China team rest offshore, a cross-border transfer of personal information under PIPL. A compliance-first look at the data-residency door, not a speed test.
Does PagerDuty work in China?
Yes — alerts reach on-call responders inside mainland China, but that is the easy half. PagerDuty runs only two service regions, the United States and Europe, with no site in the mainland, so the responder contact details and incident payloads it holds for your China team rest on AWS facilities offshore — a cross-border transfer of personal information, not a speed problem.
PagerDuty's own "Service Regions" documentation lists just two choices — the US (AWS US West in Northern California and Oregon, and US East in Ohio) and the EU (AWS EU Central in Frankfurt and EU West in Ireland) — and states that "We may process and store some types of data outside of your account's chosen service region." Its privacy policy says PagerDuty collects "identifiers and customer records (e.g., name, email address, phone number)" — your on-call engineers — while the alert and event payloads routed through it can carry user IDs, client IPs and request context from the systems it monitors. Gathered from mainland people and systems and stored offshore, that personal information is a cross-border transfer PIPL governs (notice, separate consent and a transfer mechanism, Articles 38–40), and for a CIIO or large-volume handler it must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). The table below is PagerDuty's own wording and the rule each line triggers.
This is a risk map, not a verdict — what applies turns on what your payloads carry, how much is personal, and who your users are. Our China team can map your exposure with you →
What PagerDuty's own documentation says about China
| Fact | Primary source |
|---|---|
| PagerDuty runs only two service regions — the US and the EU — with none in mainland China. PagerDuty's own "Service Regions" documentation says that at sign-up you "choose one of the following service regions" and lists only the United States and Europe, then notes that "Depending on your service region, PagerDuty could be running from any of the following data centers at any point in time" — AWS US West (Northern California), US West (Oregon) and US East (Ohio) for the US, and AWS EU Central (Frankfurt) and EU West (Ireland) for the EU. There is no mainland-China region to pick, so the responder and incident data PagerDuty holds for your China team rests offshore. | PagerDuty — Service Regions (support.pagerduty.com), retrieved 2026-10-09 |
| Even your chosen region is not absolute. PagerDuty states that "We may process and store some types of data outside of your account's chosen service region," and that your service region "may also determine the primary location of some service providers for your account, such as phone, SMS and email service." So selecting the EU pins neither every category of data nor, in any case, the mainland — the phone, SMS and email vendors that carry your responders' numbers follow the region, and some data sits outside it. | PagerDuty — Service Regions (support.pagerduty.com), retrieved 2026-10-09 |
| What PagerDuty stores is personal information — your responders and your incidents. PagerDuty's privacy policy says "If you interact with our Services, PagerDuty may collect the following categories of PII from you" and lists "identifiers and customer records (e.g., name, email address, phone number)" — the on-call engineers it pages. The alert and event payloads routed through it can also carry user IDs, client IPs and request context from your monitored systems. Collected in the mainland and stored in the US or EU, that is a cross-border transfer of personal information under PIPL — notice, separate consent and a transfer mechanism (Articles 38–40), which for larger volumes can mean a data-export security assessment. | PagerDuty — Privacy Policy, effective September 1, 2025 (pagerduty.com), retrieved 2026-10-09; PIPL Articles 38–40 |
| No mainland region means no in-country storage, and ICP is a separate door. For a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty PagerDuty's US- and EU-only regions cannot meet. The ICP filing (State Council Order No. 292; MIIT Order No. 33) attaches to the public mainland site or app you operate, not to PagerDuty as a backend alerting service. | PagerDuty — Service Regions (support.pagerduty.com), retrieved 2026-10-09; PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a mainland-China audience, the question about PagerDuty is rarely whether an alert can reach an on-call phone — it usually can. The question is where the data PagerDuty keeps is allowed to live. PagerDuty answers that in its own documentation: it offers two service regions, the United States and Europe, and runs no site inside mainland China. So the responder records it holds — the names, phone numbers and email addresses it rings, texts and emails when something breaks — and the alert and event payloads routed through it sit on AWS facilities in the US or the EU. Because those records are personal information, and the payloads can carry user IDs, client IP addresses and request context pulled from the systems it monitors, keeping them offshore is a cross-border transfer China’s law governs. Whether the pager buzzes is the delivery half; where the responder and incident data rests is the exposure.
PagerDuty in China at a glance
| What decides it | In PagerDuty's own terms — and China's law |
|---|---|
| Where it runs | Two service regions only: the United States and Europe. US accounts run from AWS US West (Northern California), US West (Oregon) and US East (Ohio); EU accounts from AWS EU Central (Frankfurt) and EU West (Ireland). None is in mainland China. |
| Can you keep it in region | “We may process and store some types of data outside of your account's chosen service region,” and your region “may also determine the primary location of some service providers for your account, such as phone, SMS and email service.” Even the EU choice pins neither every category nor the mainland. |
| What it holds | Responder identity and contact details — “name, email address, phone number” in PagerDuty's own words — plus alert and event payloads that can carry user IDs, client IPs and request context from your monitored systems. |
| Your China users' data | Responder records and mainland event data stored in the US or EU is a cross-border transfer of personal information PIPL governs; CIIOs and large-volume handlers owe an in-country storage duty PagerDuty's offshore regions cannot meet. |
| Is it reachable? | Yes — alerts page from inside China. This is not a speed question; the exposure is where the responder and incident data rests, not whether the alert arrives. |
Two service regions — and neither is in the mainland
PagerDuty’s Service Regions documentation says that when you sign up you “choose one of the following service regions,” and lists only two: the United States and Europe. It then states that “Depending on your service region, PagerDuty could be running from any of the following data centers at any point in time,” naming AWS US West (Northern California), US West (Oregon) and US East (Ohio) for the US, and AWS EU Central (Frankfurt) and EU West (Ireland) for the EU. Not one of those sits in mainland China, and there is no mainland region to pick. PagerDuty also cautions that “We may process and store some types of data outside of your account’s chosen service region,” and that your region “may also determine the primary location of some service providers for your account, such as phone, SMS and email service” — so even the EU choice does not pin every category in one place, and neither place is the mainland. Reaching PagerDuty was never the hard part; keeping the data it holds inside the country is.
What PagerDuty holds is personal information — your responders and your incidents
PagerDuty’s job is to reach the right human fast, which means it stores the people it reaches. Its privacy policy says that “If you interact with our Services, PagerDuty may collect the following categories of PII from you,” and lists “identifiers and customer records (e.g., name, email address, phone number).” Those are your on-call engineers — their names, their mobile numbers, their email addresses — held so the platform can ring, text and email them. On top of that, the alert and event payloads you route into PagerDuty can carry user IDs, client IP addresses and request context lifted from the systems it monitors; the sending system decides how much. A single responder’s phone number is already personal information, and so is a mainland user’s IP address riding along in an event. Under China’s Personal Information Protection Law, moving any of it to a US or EU region is a cross-border transfer — the handler (you, not PagerDuty) must give notice, obtain separate consent, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). Depending on your volumes, that mechanism may be a data-export security assessment. PagerDuty’s own GDPR terms concede the direction of travel, warning that it “may transmit some of your personal data to a country where the data protection laws may not provide” the same protection, “including the United States.”
No mainland region, so no in-country storage — and ICP is a separate door
The geography settles two questions before performance ever enters the picture. First, residency: if you are a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force 2026-01-01, renumbered the data-localization clause from Article 37 to Article 39) — a duty PagerDuty’s US- and EU-only regions cannot satisfy, however you tune them. Second, licensing: a public-facing site actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing must attach to a hosting resource physically in the mainland. PagerDuty provides none, so there is nothing on PagerDuty to file against — the ICP question attaches to the public mainland site or app you operate, not to PagerDuty as a backend alerting service.
This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, in-country storage, an ICP filing, or some combination turns on what your payloads carry, how much of it is personal, your role as handler, and who your users are — worth settling with counsel before you wire anything through PagerDuty.
The lawful path — map, localize, deliver
You keep running PagerDuty. What an alerting platform with only US and EU regions cannot give you is a lawful place inside China for the responder and incident personal data it handles there. That is where our China team comes in, across three steps. We map your exposure first — which PagerDuty data is personal information, which of it crosses the border, and whether your entity and volumes trigger a transfer mechanism, in-country storage, or an ICP filing. We localize what cannot lawfully leave, moving the in-country processing and storage onto a China-legal, consented footing rather than an offshore region. We deliver it with ICP-filed, in-country delivery — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no second codebase. 21YunBox never uses or suggests circumvention of any kind; every node we run is lawful and ICP-filed. The result is a PagerDuty setup that keeps paging your responders while the personal data behind it runs legally and compliantly for your users in China.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s data-export security assessment measures
- China’s Cybersecurity Law and data localization
