Does Phrase Work in China? PIPL Cross-Border Data Transfer & Content Residency
Phrase (the Phrase Localization Platform — Phrase TMS, formerly Memsource, plus Phrase Strings, formerly PhraseApp) sends your source content to EU or US data centers to translate it: a PIPL cross-border transfer of the personal and sensitive information inside, plus a permanent offshore corpus of translation memory and glossaries. A compliance-first look at where your content rests.
Does Phrase work in China?
Phrase reaches China fine — but "does Phrase work in China?" is a compliance question about the content you send it, and the honest answer is that your source text leaves the country: Phrase hosts only EU and US data centers, with no mainland-China region.
Phrase (the Phrase Localization Platform — Phrase TMS, formerly Memsource, and Phrase Strings, formerly PhraseApp) is a translation-management system: you upload source strings, documents and copy to be translated, and as a TMS it keeps them as a permanent offshore corpus — translation memory, glossaries, projects and translator accounts — with another cross-border transfer under PIPL on every sync, carrying whatever personal or sensitive information the text contains (Articles 38–40; Article 28 for sensitive content). Phrase Language AI can route the same text to offshore machine-translation engines, a further hop. The lawful lever is to keep China-origin content's translation in-country — a licensed domestic alternative, personal information minimized before any offshore call — not to make the offshore platform reachable.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Phrase's own documentation says about China
| Fact | Primary source |
|---|---|
| Phrase hosts only EU and US data centers — there is no mainland-China region. Phrase's own documentation states it "currently uses servers based in two different locations": a EU data center on AWS in Ireland (eu-west-1) and a US data center on AWS in the United States (us-east-1), with Phrase Studio on Google Cloud in Poland, the Netherlands and Iowa. It adds that Phrase "does not provide a commitment to keep a customer's data within a particular jurisdiction at all times." China-origin content uploaded to any of them has left the mainland. | Phrase Help Center — Data Centers (support.phrase.com), retrieved 2026-10-10 |
| As a translation-management system, Phrase keeps your content as a permanent offshore corpus — and can route it onward to offshore MT engines. Source and translations persist as translation memory, glossaries, projects and translator accounts on Phrase's EU/US infrastructure, with a transfer on every sync. Phrase's own sub-processor list — "all sub-processors for all Phrase Solutions" — names machine-translation providers including Microsoft (Redmond, WA), Rozetta (Tokyo) and Google (Dublin), so Phrase Language AI can send the same text to additional offshore processors. | Phrase — List of Sub-Processors (phrase.com/subprocessor-overview), retrieved 2026-10-10 |
| Sending content abroad to be translated is a cross-border transfer under PIPL. Shipping China-origin source text — and the personal information inside it — to Phrase's offshore servers requires notice, a separate consent and a transfer mechanism (security assessment, standard contract or certification) under PIPL Articles 38–40, and where the text is medical, financial, legal or ID-bearing it is Article 28 sensitive personal information with a higher bar and a prior impact assessment. | Personal Information Protection Law of the PRC, Articles 38–40 & 28 — DigiChina (Stanford) translation, retrieved 2026-10-10 |
| For a CIIO or high-volume handler, mainland content must stay in the mainland — a duty an offshore corpus cannot meet. Personal information and important data collected in China must be stored in-country (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. Crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment first. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); PIPL Article 40 — DigiChina (Stanford) translation, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a localization team serving mainland China, the question about Phrase was never whether the platform loads or whether translators can reach it — they can. Phrase is the former Memsource (now Phrase TMS) joined with the former PhraseApp (now Phrase Strings) as one Phrase Localization Platform: a translation-management system you connect to your repositories, CMS and content stores, so your source strings, documents and copy are uploaded to Phrase’s servers to be translated. Those servers sit in Phrase’s EU or US data centers — there is no mainland-China region. And the content does not pass through and vanish; as a TMS it accumulates as a permanent offshore corpus — translation memory, glossaries and term bases, projects, context screenshots and translator accounts — with another cross-border transfer on every sync. Whatever personal, sensitive or confidential information lives in the text goes with it: a transfer of personal information under PIPL (Articles 38–40, 数据出境), Article 28 for sensitive text, and an in-country-storage question (Cybersecurity Law Article 39, formerly Article 37) for a CIIO or high-volume handler.
Phrase in China at a glance
| What decides it | In Phrase's own terms — and China's law |
|---|---|
| What you hand Phrase to translate | Phrase is a translation-management platform: you connect repositories, a CMS and content stores and upload the source itself — UI strings, documents, support tickets, marketing and product copy, knowledge-base articles. The content you most need translated is the content most likely to carry personal information: names, emails and addresses in tickets, employee and customer records, and legal, medical or financial text. All of it is uploaded to Phrase's servers to be processed. |
| Where it rests — and that it leaves China | Phrase's own documentation says it "currently uses servers based in two different locations" — a EU data center on AWS in Ireland (eu-west-1) and a US data center on AWS in the United States (us-east-1), with Phrase Studio on Google Cloud in Poland, the Netherlands and Iowa. There is no mainland-China region. China-origin content uploaded to any of them has left the country — a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (Articles 38–40, 数据出境). |
| Sensitive content inside the text | You cannot anonymize a document you need translated in full. Where the source is medical, financial, legal, biometric or ID-bearing, it is Article 28 sensitive personal information, which carries a higher bar — specific purpose, strict necessity, separate consent and a prior personal-information protection impact assessment before it is sent offshore. |
| A permanent offshore corpus | A TMS does not translate and forget. Source and translations accumulate as translation memory, glossaries and term bases, projects, context screenshots and translator accounts (vendors and freelancers who are themselves people handling your content) — a store that lives on Phrase's offshore infrastructure and grows with every sync. For a critical information infrastructure operator or a high-volume handler, mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — a duty an offshore corpus cannot meet. |
| Is it reachable? | Treat reachability as the delivery half, not the question — editors and APIs connect. Phrase's published deployment is its EU or US cloud; it advertises no mainland-China region and, in its own words, "does not provide a commitment to keep a customer's data within a particular jurisdiction at all times." So the lever is not making the offshore endpoint reachable — it is keeping China-origin content's translation in-country on a licensed domestic alternative, minimizing and pseudonymizing personal information in strings before any offshore call, and giving any China-facing surface its own ICP filing (State Council Order No. 292; MIIT Order No. 33). |
What you actually send — and where it goes
The thing to hold onto is that a translation service is a transfer of the exact content you send it. With Phrase you do not send a request that bounces off an edge and returns; you upload the source — the strings, the documents, the copy — so it can be translated and so the results can be reused later. And the content a business most needs translated is, almost by definition, the content most likely to contain personal information: support tickets full of customer names and emails, HR and employee documents, contracts, product and legal copy, knowledge-base articles, user-generated text. Confidential, unreleased and regulated material rides along in the same files.
Where does it go? Phrase names only two homes. Its Data Centers documentation says Phrase “currently uses servers based in two different locations” — a EU data center on AWS in Ireland (eu-west-1) and a US data center on AWS in the United States (us-east-1) — with the newer Phrase Studio running on Google Cloud in Warsaw, the Netherlands and Iowa, each “a separate cloud infrastructure.” None of them is in mainland China; an account picks EU or US at sign-up, and East-Asian teams are simply pointed at the US region. Because Phrase is a translation-management system rather than a one-shot API, the exposure is not a single call: the source and its translations persist offshore as translation memory, glossaries and projects, alongside the accounts of the translators who work on them, and every repository or CMS sync ships more across the border. On top of that, Phrase Language AI can route the same text to third-party machine-translation engines — its sub-processor list (“all sub-processors for all Phrase Solutions”) names providers in Redmond, Tokyo and Dublin among others — a further hop to additional offshore processors, some of which, Phrase warns, “may use their own data centers based in different locations.”
It’s a cross-border data transfer — under PIPL
Uploading China-origin source text to a server in Ireland or Virginia is, in plain terms, a cross-border transfer of personal information (数据出境). PIPL Articles 38–40 set the conditions: you must give notice of the overseas recipient, obtain a separate consent for the export specifically, and put a transfer mechanism in place — a CAC security assessment, the China Standard Contract, or certification. Sending a document abroad to be translated transfers everything inside it, so the lawful basis has to cover the whole payload, not a tidy summary of it.
Two things raise the bar. First, sensitivity: much of what gets translated is Article 28 sensitive personal information — medical, financial, legal, biometric or ID-bearing — and you cannot strip it out of a document you need rendered in full, so it needs the specific purpose, strict necessity, separate consent and prior impact assessment that category demands. Second, residency and volume: for a critical information infrastructure operator or a high-volume handler, personal information and important data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore translation-memory corpus that only grows is, by construction, in the wrong jurisdiction for that duty — and crossing a volume or sensitivity threshold can trigger a CAC-led data-export security assessment before any of it lawfully leaves.
Reaching the platform isn’t the question — keeping the content in-country is
The honest summary is narrow: nothing about Phrase is “blocked” in China, and the exposure is not the software. The exposure is that your China-origin source content — and the personal, sensitive and confidential information inside it — is exported to an offshore region and, in a TMS, kept there. Phrase’s own documentation underlines the point: it offers only EU and US regions and explicitly “does not provide a commitment to keep a customer’s data within a particular jurisdiction at all times.”
So the lever is not to make the offshore endpoint reachable — it is to stop the export of China content and keep its translation on an in-country path. In practice that means routing China-origin content through a licensed in-country machine-translation or localization alternative with the data kept in China; minimizing and pseudonymizing the personal information in strings before any offshore call is ever made; and disabling model-training retention, restricting any machine-translation step to engines that carry a data-region policy rather than the open set. Where Phrase itself must stay in the picture, you keep only the minimized, lawfully transferable subset crossing the border, backed by notice, a separate consent and a transfer mechanism. What this is not is a hidden path that ships the content offshore anyway and calls it local — that solves nothing and keeps the exposure. This is a risk map, not a verdict: whether you owe in-country storage, a transfer mechanism, a separate consent, a data-export security assessment, an ICP filing, or some combination turns on your entity, your data volumes, how much of your content is personal or sensitive, and whose data it is — settle the specifics with counsel before you decide where a single string or document is translated.
The lawful path — map, localize, deliver
You do not have to drop Phrase to run localization lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner alongside your stack rather than a competitor to it. There are three moves, and they fit together.
Map. Our China compliance team inventories what content actually flows into Phrase, what personal, sensitive or confidential information it carries, which region it lands in, whether any machine-translation step retains or reuses it, and where you lack a lawful basis for the cross-border leg — so the exposure is written down before anything moves.
Localize. Because the risk is China content leaving and persisting offshore, we keep that content’s translation in-country — on a licensed domestic machine-translation or localization path, with personal information minimized and pseudonymized in strings before any offshore call and model-training retention switched off. Localize means a lawful in-country translation path, never a tunnel back to an offshore endpoint; only the minimized, lawfully transferable subset ever crosses.
Deliver. For the China-facing site or app that consumes the translations — a public internet service with an ICP filing duty — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.
The goal is plain: your Phrase setup runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization (Article 39)
- China’s data-export security assessment measures
- How to get an ICP filing for China
