Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Pega Work in China? Customer Data, PIPL & Data Residency

Pega Cloud is a Pegasystems-managed service on Amazon Web Services and Google Cloud, with no mainland-China region — so the customer master records, case and interaction history, decisioning profiles and agent PII it holds come to rest offshore, a cross-border transfer under PIPL. Pega's own client-managed cloud and on-premises options are the lawful in-country lever. A compliance-first look at where your customer data is allowed to live.

Does Pega work in China?

Not as a managed Pega Cloud service — Pega Cloud runs on Amazon Web Services and Google Cloud with no mainland-China region, so the customer master records, case history, decisioning profiles and agent PII it holds come to rest offshore: a cross-border transfer under PIPL.

Pega's subprocessor list names Amazon Web Services, Inc. and Google LLC — the "Cloud services provider (for Pega Cloud clients on Google Cloud)" — as the providers that run Pega Cloud, and a customer picks one offshore deployment region; none sits inside the mainland. Serving China from that footprint stores your customers' and agents' personal information outside the mainland, a cross-border transfer PIPL governs that needs notice, a separate consent and a transfer mechanism — and, for a CIIO or large-volume handler, an in-country storage duty an offshore region cannot meet. Pega does, though, support client-managed cloud and on-premises deployment — the genuine in-country lever.

This is a risk map, not a verdict — whether you owe a transfer mechanism, in-country storage, an ICP filing, or all three turns on your entity, your data and whose it is. Our China team can map your exposure →

What Pega's own documentation says about China

FactPrimary source
Managed Pega Cloud runs on Amazon Web Services and Google Cloud — with no mainland-China region. Pega's own subprocessor list states that "Pegasystems uses third-party Subprocessors to provide infrastructure services," and names Amazon Web Services, Inc. and Google LLC — the latter the "Cloud services provider (for Pega Cloud clients on Google Cloud)" — as the providers that run Pega Cloud. A customer selects one deployment region from that worldwide AWS and Google Cloud footprint, and none of those regions is inside mainland China, so the nearest footing Pega Cloud offers a China audience is still offshore. Pega — Subprocessor Information (pega.com/subprocessors), retrieved 2026-10-10
Pega genuinely supports client-managed cloud and on-premises deployment — the in-country lever. Pega documents three deployment models: a Pegasystems-managed Pega Cloud, a client-managed cloud where "customer-managed cloud environments are run within private clouds or run on Infrastructure-as-a-Service (IaaS)," and on-premises, where the software is "installed and operate on customer sites." Unlike a SaaS-only tool, Pega Platform can therefore run on infrastructure you or a partner operate inside mainland China — the one option that lets the customer data stay in-country. Pega Academy — Deployment options, retrieved 2026-10-10
A China audience's customer records on managed Pega Cloud are a cross-border transfer under PIPL. Personal information collected in the mainland and stored in an offshore AWS or Google Cloud region is exported under China's Personal Information Protection Law: the handler must give notice, obtain a separate consent for the export, and clear one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (Articles 38–43). Case content that carries payment, identity-document or health details is Article 28 sensitive personal information, with a higher consent and necessity bar. PIPL Articles 38–43 and Article 28, retrieved 2026-10-10
A CIIO or large-volume handler must store China-collected data in the mainland, and any China-facing surface needs an ICP filing. Personal information collected in China must be stored inside the mainland for a critical information infrastructure operator or large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty an offshore Pega Cloud region cannot meet. A public China-facing surface served from inside the mainland also turns on an ICP filing under State Council Order No. 292 and MIIT Order No. 33. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33; retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a team serving mainland China, the deciding question about Pega is not whether the app opens or how fast a case loads — it is where the records inside it are allowed to come to rest. Pega Platform and Pega Customer Decision Hub sit at the center of customer operations: they hold the customer master record, the full case and interaction history, the decisioning and next-best-action profiles built on a person’s behavior, and the agent and customer identities attached to every case. Run as a managed Pega Cloud service, that data lives in the Amazon Web Services or Google Cloud deployment region you select — and Pega operates no region inside mainland China. So for a China audience the customer data rests offshore, which turns every mainland customer and agent record into a cross-border transfer China’s law governs, and makes the consent and mechanism behind that transfer — not the load time — the thing that decides whether you may use it.

Pega's public subprocessor list naming Google LLC as a 'Cloud services provider (for Pega Cloud clients on Google Cloud)' and Amazon Web Services, Inc. as a cloud services provider, with no mainland-China location shown
Pega's own subprocessor list: “Cloud services provider (for Pega Cloud clients on Google Cloud)”. It names Google LLC and Amazon Web Services, Inc. as the cloud providers that run Pega Cloud, and no mainland-China location appears anywhere on the page. Source: pega.com/subprocessors

Pega in China at a glance

What decides it In Pega's own terms — and China's law
Where the customer records live Managed Pega Cloud is Pegasystems' own hosted service, and Pega's subprocessor list names Amazon Web Services, Inc. and Google LLC — "Cloud services provider (for Pega Cloud clients on Google Cloud)" — as the providers that run it. A customer picks a deployment region from that global AWS and Google Cloud footprint; none of those regions is inside mainland China.
What it holds, and why it is personal The customer master record, the full case and interaction history, the decisioning and next-best-action profiles built on a person's behavior, and the agent and customer identities on every case. Those are personal information; and in Pega Customer Service or Customer Decision Hub a case can carry financial-account, government-ID or health details — PIPL Article 28 sensitive personal information.
Your China customers' and agents' data Records collected in or relating to the mainland, then stored in an offshore AWS or Google Cloud region, are a cross-border transfer PIPL governs — notice, a separate consent, and one transfer mechanism (Articles 38–40).
In-country storage duty A critical information infrastructure operator or large-volume handler must store personal information collected in China inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a duty the managed Pega Cloud footprint cannot meet.
Is it reachable? Treat reachability as the delivery half, not the question. The exposure is where the customer data is stored, not whether the console loads — and any China-facing surface (a self-service portal, a web-chat widget, a case-intake form) also needs an ICP filing.

No mainland region, so your customer records leave the country

Managed Pega Cloud is Pegasystems’ own cloud platform service, and where your records rest is a function of the deployment region your subscription is provisioned into. Pega’s public subprocessor list is explicit about the infrastructure underneath it: “Pegasystems uses third-party Subprocessors to provide infrastructure services,” and the providers it names are Amazon Web Services, Inc. and Google LLC — the latter described as the “Cloud services provider (for Pega Cloud clients on Google Cloud).” A Pega Cloud customer selects one deployment region from that worldwide AWS and Google Cloud footprint, data and backups stay in the region selected, and the nearest options to China sit offshore in Asia-Pacific — none inside the mainland. Pega has even stood up a European sovereign-cloud boundary in Germany for EU data-sovereignty rules; there is no mainland-China equivalent to select. For a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment that took effect on January 1, 2026, with the substance unchanged)) — a floor an offshore region cannot satisfy, and the point at which any mainland-served surface also turns on an ICP filing (State Council Order No. 292; MIIT Order No. 33).

A customer operations platform is personal information — and some of it is sensitive

Pega does not store anonymous rows. The customer master record ties a real person to their contact details, account and history; the case and interaction log records who contacted you, about what, and when; and the decisioning and next-best-action profiles are, by design, a behavioral model of an identified individual. Every one of those is personal information under China’s law. In Pega Customer Service and Customer Decision Hub the exposure climbs: a case can capture payment-card and bank details read into a service record, government-identity numbers, or health and financial disclosures — Article 28 sensitive personal information, which carries a higher bar of separate consent and necessity. Because that personal information is collected in or relates to the mainland and comes to rest in an offshore region, the Personal Information Protection Law treats the move as a cross-border transfer: the handler — you, the Pega subscriber, not Pega — must give notice, obtain a separate consent for the export, and clear one lawful mechanism, whether the CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40).

Narrowing the exposure doesn’t close the door — but changing the deployment model can

Inside managed Pega Cloud you have levers to shrink what crosses the border — pin your tenant to one deployment region, mask or redact fields, minimize what each case stores — but none of them moves the border. Region choice is a pick among offshore AWS and Google Cloud regions, every one of which is still offshore of China, so data residency is unaffected and the cross-border transfer still happens; scrubbing a sensitive field narrows the Article 28 exposure inside a case, it does not keep the case in the mainland. The one lever that actually changes residency is leaving the managed service: Pega genuinely supports client-managed cloud and on-premises deployment, so Pega Platform can run on infrastructure you or a partner operate — and on mainland infrastructure the customer data can stay in-country. That is a different operating model, and even then any support access, product updates or telemetry that leave the mainland still need their own PIPL analysis. This is a risk map, not a verdict: whether you owe a transfer mechanism, a separate consent, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes, how much of the data is sensitive, and whose data it is — worth settling with counsel before you route mainland customer data into an offshore Pega Cloud tenant.

The lawful path — map, localize, deliver

You do not have to pull Pega out to run it compliantly for mainland China. 21YunBox is a compliant overlay, not a migration — and a partner to the platform you already run, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads the PIPL cross-border, data-residency, sensitive-PI and ICP obligations against your entity, your customer and case volumes, and whose data those records carry — so your exposure is written down before anything is rewired.

Localize. Where customer records, decisioning profiles or agent data must stay on mainland soil, we stand up consented, in-country processing and storage for them — making the most of Pega’s own client-managed and on-premises deployment where it fits — so the data that has to remain in China remains in China, while the Pega your team already uses stays exactly where it runs.

Deliver. For any China-facing surface — a self-service portal, a web-chat or case-intake page, an agent console reached from the mainland — the 21YunBox Optimizer provides ICP-filed, in-country delivery in front of the stack you already run, with no rebuild and no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.

The goal is plain: your customer operations run legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Pega Cloud have a data center in mainland China?
No. Pega's own subprocessor list names Amazon Web Services, Inc. and Google LLC as the cloud providers that run Pega Cloud, a customer selects one deployment region from that worldwide AWS and Google Cloud footprint, and none of those regions is inside mainland China — the nearest sit offshore in Asia-Pacific. For a China audience, managed Pega Cloud is reachable but hosted outside the mainland.
Can we run Pega inside China to stay compliant?
Potentially. Unlike a SaaS-only platform, Pega supports client-managed cloud and on-premises deployment, so Pega Platform can run on infrastructure you or a partner operate inside the mainland — the one path that lets the customer data stay in-country. Even then you still owe the PIPL analysis for any support access, updates or telemetry that leave China, and any mainland-served surface still needs an ICP filing. Confirm the specifics with counsel; this is a risk map, not a ruling.
Can 21YunBox help make our Pega setup work in China?
Yes. Our China team can map which obligations apply — assessing your PIPL cross-border and data-residency exposure for your entity, data volumes and users — stand up consented in-country storage for the records that must stay on mainland soil, and deliver any China-facing surface over ICP-filed, in-country infrastructure in front of the Pega you already run. You keep building on Pega; we add the mainland footing the managed service does not provide. Get in touch to work through your specific case.

ARTICLES RELATED TO PEGA

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.