Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Ping Identity Work in China? Identity Data Residency, PIPL Cross-Border & ICP

Ping Identity's PingOne cloud is reachable from the mainland, so the real question isn't speed — it's data residency. Ping's own documentation hosts PingOne tenants only in offshore regions (North America, Europe, Australia, Canada, Singapore), with no mainland-China site, so the usernames, directory attributes, MFA factors and authentication logs it holds about your China employees and users rest offshore — a cross-border transfer under PIPL, with an in-country storage duty under the Cybersecurity Law for a CIIO or large-volume handler, and no footing for an ICP filing. A compliance-first look at the residency, cross-border and ICP exposure, and the lawful in-country path.

Does Ping Identity work in China?

Reachability isn't the problem — Ping's PingOne endpoints are generally callable from mainland China, so the honest answer is that speed isn't the axis. What decides the China question is data residency and cross-border transfer: where the identity records Ping keeps about your China people come to rest.

Ping runs no identity cloud inside the mainland. Its own docs host PingOne only offshore — North America, Europe and Australia in the PingID guide; the United States, Germany, Ireland, Australia, Canada and Singapore in its Data Supplement — with no mainland site, and it states that “PII is stored in the specified regional hosting facility only.” So the usernames, directory attributes, MFA factors and authentication logs collected from people in China rest offshore, which makes their collection a cross-border transfer under PIPL (notice, a separate consent and one transfer mechanism, Articles 38–40), and it may trigger China's data-export security assessment. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) requires such data to be stored in China — which no offshore PingOne region can satisfy — and a public login served from inside the mainland needs an ICP filing PingOne gives nothing to attach to.

21YunBox maps your cross-border, residency and consent exposure, localizes China-resident identity data onto an in-country footing (a self-managed PingFederate/PingAccess deployment or a domestic IAM for the China entity), and delivers your China-facing login surface in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Ping Identity's own documentation says about China

FactPrimary source
Ping hosts identity data only in offshore regions — and keeps it there. Ping's PingID Administration Guide states that “The PingID service is currently installed at the following regional data centers” — North America (East and West Coasts), Europe and Australia — that “All PingID service installations are hosted in the Amazon cloud,” and that “Users’ personally identifiable information (PII) is stored in the specified regional hosting facility only.” None of the facilities is in mainland China, so identity PII stays in whichever offshore region you choose. Ping Identity docs — PingID regional data centers (docs.pingidentity.com), retrieved 2026-10-09
Ping's own Data Supplement places its cloud infrastructure outside mainland China. Effective September 2026, Ping's Data Supplement (sub-processor list) states that “Customers select the region(s) of data residency” and that “Data is stored in region(s) selected by customer for PingOne tenant,” naming AWS — the provider of its infrastructure-as-a-service — in “United States, Germany, Ireland, Australia, Canada, Singapore.” Mainland China appears nowhere as a hosting location. Ping Identity — Data Supplement / sub-processor list (pingidentity.com), effective September 2026, retrieved 2026-10-09
China-collected identity data sent to an offshore PingOne tenant is a PIPL cross-border transfer. Moving personal information collected from people in mainland China — usernames, directory attributes, MFA factors, authentication logs — to a PingOne tenant hosted in the US, Europe, Australia, Canada or Singapore triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Personal Information Protection Law of the PRC, Articles 38–40 (npc.gov.cn), retrieved 2026-10-09
For some handlers the data must stay in China, and serving from inside the mainland triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (Cybersecurity Law Article 39, formerly Article 37, as renumbered by the 2025 amendment in force 1 January 2026; PIPL Article 40) — which an offshore PingOne region cannot satisfy. And any public site actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource PingOne does not provide. Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40; State Council Order No. 292; MIIT Order No. 33 (npc.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For an enterprise standing up single sign-on, MFA or customer identity for mainland China, the first instinct with Ping Identity is to ask whether PingOne can be reached from inside the country. On the wire it generally can — Ping’s authentication endpoints are not a service China blocks at the border the way some consumer platforms are. So reachability is not where the China decision is settled. What settles it is data residency and cross-border transfer: where the identity records PingOne keeps about your people come to rest, and whether you had a lawful basis to move them out of the country in the first place. Those are questions of China’s law, and they sit upstream of latency. Ping answers the residency half in its own documentation.

Ping runs no identity cloud inside mainland China. Its own product docs and sub-processor list place every PingOne hosting region offshore — North America, Europe, Australia, Canada and Singapore — with no mainland site to choose. The moment a username, a directory attribute, an MFA factor or an authentication log collected from a person in China lands in one of those regions, you have made a cross-border transfer (数据出境) of personal information, and a different body of law decides whether that was allowed.

Ping Identity's PingID Administration Guide 'PingID regional data centers' page on docs.pingidentity.com, listing the regional data centers as North America (East and West Coasts), Europe and Australia — all hosted in the Amazon cloud, with no mainland-China region — and stating that users' personally identifiable information is stored in the specified regional hosting facility only
Ping's own PingID Administration Guide: “The PingID service is currently installed at the following regional data centers” — North America (East and West Coasts), Europe and Australia — “All PingID service installations are hosted in the Amazon cloud,” and “Users’ personally identifiable information (PII) is stored in the specified regional hosting facility only.” None of the facilities is in mainland China, so the identity data stays in whichever offshore region you pick. Source: Ping Identity docs — PingID regional data centers

Ping Identity in China at a glance

What decides it In Ping Identity's own terms — and China's law
What it is Ping Identity is an enterprise identity and access management platform — workforce SSO and MFA, plus customer identity (CIAM) — delivered mainly as the PingOne cloud, with self-managed components (PingFederate, PingAccess) you can run yourself. It holds a continuous record of identifiable people: usernames, directory attributes, MFA factors, and session and authentication logs.
Is it reachable from the mainland? Generally, yes. Ping's authentication endpoints are callable from China and it is not blocked at the border, so reachability is not the China question. (Cross-border authentication calls from the mainland to an offshore identity provider can be inconsistent — an operational matter, below, not the decision.)
Where does the identity data sit? Offshore. Ping's PingID guide lists its regional data centers as North America (East and West Coasts), Europe and Australia, all “hosted in the Amazon cloud”; its Data Supplement places AWS infrastructure in “United States, Germany, Ireland, Australia, Canada, Singapore,” with “Data … stored in region(s) selected by customer for PingOne tenant.” There is no mainland-China region, and “PII is stored in the specified regional hosting facility only.”
Collecting China identity data into it Usernames, directory attributes, MFA factors and auth logs are personal information — and MFA factors such as a phone number or a biometric can be sensitive personal information. Holding them in an offshore PingOne is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism; a data-export security assessment may apply above thresholds. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
Serving the public A China-facing login, portal or sign-in page actually served to mainland visitors from inside China needs an ICP filing bound to a mainland hosting resource. PingOne names no mainland region, so there is nothing of its own to file against.
The lawful path Keep China-resident identity data in-country — a self-managed PingFederate/PingAccess deployment on China-resident infrastructure, or a domestic IAM for the China entity — with consented in-country processing and storage, and deliver the China-facing login surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

Availability: reachable — but where does the identity data live?

Ping’s position is set in its own documentation, not by a load-time test. Its PingID Administration Guide states that “The PingID service is currently installed at the following regional data centers” — North America (East and West Coasts), Europe and Australia — that “All PingID service installations are hosted in the Amazon cloud,” and that “Users’ personally identifiable information (PII) is stored in the specified regional hosting facility only.” Its Data Supplement, effective September 2026, is just as plain for the wider PingOne cloud: “Customers select the region(s) of data residency,” and “Data is stored in region(s) selected by customer for PingOne tenant” — the AWS regions it names are “United States, Germany, Ireland, Australia, Canada, Singapore.” Not one of those is inside the mainland.

So “can the login page reach PingOne from Shanghai?” is the wrong test. It reaches. The real question is where your China-collected identity data sits and whether it was allowed to leave the country at all — which is why this page publishes no first-party China latency or reachability figure for Ping: speed is not the axis for a decision that turns on residency and consent. One operational note worth naming: cross-border authentication from the mainland to an offshore identity provider can be inconsistent, and the temptation is to force it through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. The productive question is how to keep the China identity data on a lawful footing.

The data-residency question: an offshore identity store is a cross-border transfer

Here is the gate most teams miss. A PingOne tenant in any of Ping’s regions is, by definition, outside the mainland. The usernames, directory attributes, MFA factors and authentication logs it holds for your people in China are personal information, and loading them into an offshore PingOne is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization operating the identity system, not Ping the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your service, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Above certain thresholds, or where the data qualifies as “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China — an in-country storage duty a PingOne tenant hosted in the US, Europe, Australia, Canada or Singapore simply cannot satisfy. None of this turns on how quickly a token is issued; it turns on whether the data had a lawful basis to be there. Which of these bite your specific deployment is a risk to confirm with counsel against what your directory actually holds.

Residency is only half of it. An identity platform works by collecting and verifying attributes about identifiable people — who they are, which groups they belong to, the device and factor they authenticate with, and a running log of when and from where they signed in. Under PIPL, that processing needs its own lawful basis: in practice, informed consent and a clear notice before collection begins. Some of what an IAM holds goes further — a phone number used as an MFA factor, and especially any biometric used for passwordless or step-up authentication, can be sensitive personal information, which carries a stricter standard again: a separate, specific consent and a demonstrated necessity. The cross-border transfer to an offshore PingOne then needs a further separate consent on top of all of that. Ping gives you controls that can help — regional data residency, deletion and access tooling, and the option to minimize what each environment holds — but those reduce exposure; they do not discharge the consent and notice duties, which sit with you as the handler. Whether a given attribute counts as sensitive, and what your consent flow must say, are questions to settle with counsel.

No mainland region to file against — and why “pick another region” isn’t the fix

A public-facing login, customer portal or sign-in screen actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing has to attach to a hosting resource physically in the mainland. PingOne provides none, so there is nothing on PingOne to file against — the same structural gap the residency duty exposes, seen from the licensing side.

The obvious move is to flip the tenant to a region nearer China and call it in-country — but the only regions Ping offers are North America, Europe, Australia, Canada and Singapore. None is in the mainland, so none resolves a China residency duty; moving identity data from, say, the Singapore region to the Australia region merely relocates the cross-border transfer, it does not end it. Keeping China-collected identity data in-country means standing up a China-resident home for it — and here Ping’s own architecture helps, because PingFederate and PingAccess are software you run yourself, so a self-managed deployment on China-resident infrastructure (or a domestic IAM for the China entity) can hold that data in the country while you keep PingOne for your other markets. That split — what must stay, what may go — is the heart of the work, and it is a legal question before it is a technical one.

This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination depends on your entity, the identity data you hold, your role as handler, and who your users are — worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

There is a lawful way to run enterprise identity for a China-facing presence, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the processing and the transfer — identifying which identity records collected in China (usernames, directory attributes, MFA factors, authentication logs) must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your consent and notice flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a China-resident footing for the China identity data — a self-managed PingFederate/PingAccess deployment on in-country infrastructure, or a domestic IAM for the China entity — so authentication keeps working while those records stop leaving the country by default, and you keep PingOne for the markets where it already serves you.

Then deliver: the China-facing login, portal or app your users actually reach is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is identity that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Ping Identity available in mainland China?
Ping's PingOne authentication endpoints are generally callable from the mainland — it is not a service China blocks at the border — so availability is not the obstacle. The real question for a China-facing deployment is data residency and consent: Ping runs no identity cloud in mainland China (its regions are North America, Europe, Australia, Canada and Singapore), so the identity data you collect from China users rests offshore. Cross-border authentication from the mainland to an offshore identity provider can be inconsistent, but that is an operational matter, not the decision — and the answer is never a network workaround. Treat the specifics as a risk to confirm with counsel.
Is sending China identity data to PingOne a cross-border transfer?
If your PingOne tenant is in any of Ping's regions — all of them outside the mainland — then the usernames, directory attributes, MFA factors and authentication logs it holds for your China users are stored offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and it may be subject to China's data-export security assessment. Where an MFA factor is sensitive personal information — a biometric, for example — a stricter, separate consent applies on top. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. Confirm your exact obligations with counsel.
Can we just pick a PingOne region closer to China to keep data in-country?
No — the only regions Ping offers are the US, Europe, Australia, Canada and Singapore, and none is in mainland China, so none resolves a China residency duty. Switching from one offshore region to another merely relocates the cross-border transfer; it does not end it. Keeping China-collected identity data in-country means standing up a China-resident footing for it — and because PingFederate and PingAccess are software you run yourself, a self-managed deployment on China-resident infrastructure (or a domestic IAM for the China entity) can hold that data in the country, while you keep PingOne for your other markets. 21YunBox maps that split, localizes the in-country data, and delivers the China-facing login on ICP-filed infrastructure — it is not a route around China's data-export rules.

ARTICLES RELATED TO PING IDENTITY

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.