Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Proofpoint Work in China? Data Residency, Localization & PIPL Cross-Border

Proofpoint's email-security, archive and DLP cloud runs on regional data centers — US, EU (Germany), Japan, Australia, UAE, India and Singapore — with no mainland-China region. Filtering mail routes it through that offshore cloud, so email content and DLP matches from China cross the border: a PIPL transfer. A compliance-first look at where Proofpoint lets your email data rest.

Does Proofpoint work in China?

Whether Proofpoint works in China is a data-residency question, not a reachability one — and for an email-security cloud it has a sharp edge.

Proofpoint is an email-security, archive and data-loss-prevention cloud: to filter mail it routes every inbound and outbound message through its own regional data center in real time, its Enterprise Archive retains full message bodies, Targeted Attack Protection detonates URLs and attachments in the cloud, and Email/Cloud DLP scan content for sensitive-data matches. Those regions are in the US, the EU (Germany), Japan, Australia, the UAE, India and Singapore — none in mainland China — so email content and DLP matches gathered from your China users come to rest offshore. That is a cross-border transfer PIPL governs (often Article 28 sensitive personal information), and for a CIIO or high-volume handler an in-country storage duty an offshore cloud cannot meet. The tool bought to secure your email is itself the offshore path for it.

This is a risk map, not a verdict — your duties turn on your data volumes and role. Our China team can map your exposure →

What Proofpoint's own documentation says about China

FactPrimary source
Proofpoint localizes data where regulations demand it — but not in mainland China. Its September 1, 2026 data-sovereignty expansion adds in-country hosting across Singapore, India, Japan and Australia (joining existing EU, US and a 2025 UAE site): "Email DLP, Endpoint DLP/ITM SaaS and Cloud DLP are currently supported locally in Australia." No mainland-China data center appears on the roster, so email content and DLP matches from China rest on an offshore region. Proofpoint — Proofpoint Expands Data Security Capabilities across Asia Pacific and Japan, retrieved 2026-10-10
Proofpoint enumerates its storage regions as the US, the EU and APAC — none in China. Its own documentation says storage options cover "APAC region on top of our options within the U.S. and European Union (EU) regions" and that "The storage for the APAC region is based out of Japan and the EU region is based out of Germany." The nearest region to the mainland is Japan; there is no mainland-China option to select. Proofpoint — Information Protection data storage (blog), retrieved 2026-10-10 (published 2021-10-19)
Routing China email through an offshore Proofpoint region is a cross-border transfer under PIPL. PIPL Articles 38–40 put the duty on the handler — you, the operator, not Proofpoint the processor — to give notice, obtain a separate consent, and satisfy one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Email content routinely includes Article 28 sensitive personal information (health, financial, government-ID), which carries a higher bar. PIPL Chapter III, Articles 38–43; Article 28
A CIIO or high-volume handler must keep mainland personal information in the mainland. Personal information and important data collected in China must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore email-security cloud with no mainland-China region structurally cannot satisfy that duty. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For an organization running Proofpoint across mailboxes in mainland China, the first instinct is to check whether mail still routes — and it generally does. That is not where the China decision is settled. Proofpoint is an email-security, archive and data-loss-prevention cloud, and to do its job it must ingest the one thing a company most wants protected: to filter inbound and outbound mail it routes every message through its own cloud in real time; its Enterprise Archive retains full message bodies; Targeted Attack Protection detonates URLs and attachments in that cloud; and Email and Cloud DLP scan content for sensitive-data matches. So the real question is a residency one — where all that email content is allowed to come to rest, and whether sending it to Proofpoint’s cloud crossed the border. The irony is exact: the tool bought to secure your email is itself an offshore cross-border path for it.

That posture is set by where Proofpoint’s data centers are, not by a load-time test. Its email security is delivered as Proofpoint on Demand (Email Protection): mail is pointed at Proofpoint’s cloud, filtered there, and each tenant is provisioned onto a regional cluster. Proofpoint has been adding in-country data centers wherever data-sovereignty demand appears — onshore storage in Australia for Email Protection and its data-security products, a United Arab Emirates site in 2025, and, in its September 2026 data-sovereignty announcement, local data centers across Singapore, India and Japan, all framed around keeping data “hosted where regulations require it.” Its own regional storage documentation lists the United States, the European Union (hosted in Germany) and APAC (hosted in Japan). Not one of those regions is in mainland China — so the moment email content gathered in China lands in a US, EU or Japan Proofpoint region, you have made a cross-border transfer, and a separate body of law decides whether that was allowed.

Proofpoint press release 'Proofpoint Expands Data Security Capabilities across Asia Pacific and Japan as Data Sovereignty Demands Accelerate,' September 1, 2026, listing new in-country data centers across Singapore, India, Japan and Australia for Email DLP and data-security products — naming no mainland-China data center
Proofpoint's September 2026 data-sovereignty expansion adds in-country hosting across Singapore, India, Japan and Australia (joining the EU, the US and a 2025 UAE site): "Email DLP, Endpoint DLP/ITM SaaS and Cloud DLP are currently supported locally in Australia." The roster names no mainland-China data center, so email content and DLP matches gathered in China come to rest on an offshore Proofpoint region. Source: Proofpoint — Data Security Capabilities across Asia Pacific and Japan

Proofpoint in China at a glance

What decides it In Proofpoint's own terms — and China's law
Where the email data physically rests Proofpoint's email security (Proofpoint on Demand / Email Protection), Targeted Attack Protection, Enterprise Archive and Email/Cloud DLP are delivered from regional data centers. Its own records put storage in the United States, the EU (hosted in Germany) and APAC (hosted in Japan), with onshore options added in Australia, a UAE site (2025), and local data centers rolling out in India and Singapore. Its data-sovereignty expansion localizes "where regulations require it" — but names no mainland-China data center.
What it ingests, and why residency bites To filter mail, every inbound and outbound message transits Proofpoint's cloud in real time; Enterprise Archive retains full message bodies, Targeted Attack Protection detonates URLs and attachments in the cloud, and Email/Cloud DLP scan content for sensitive-data matches. That is the full content of corporate email — routinely Article 28 sensitive personal information (health, financial, government-ID) and trade secrets — concentrated in the vendor's cloud.
Your China users' mail in that cloud Email content, attachments, archive copies and DLP matches generated in China and processed or held in an offshore Proofpoint region are a cross-border transfer (数据出境) PIPL governs: notice, a separate consent, and one transfer mechanism (PIPL Articles 38–40). The handler on the hook is you, the operator — not Proofpoint (owned by Thoma Bravo since 2021), the processor.
In-country storage duty A critical information infrastructure operator or high-volume handler owes an in-country storage duty an offshore email cloud cannot meet — mainland personal information and important data must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Is it reachable? Treat reachability as the delivery half, not the question — mail routing to Proofpoint's cloud generally works from the mainland. The lawful lever is to keep the China email-security data layer in-country (a licensed in-country or sovereign equivalent; a legacy on-premises gateway inspects mail in-country, but the cloud sandbox, archive and DLP analytics have no mainland region). Any China-facing surface — the admin console, the end-user quarantine/digest page — needs an ICP filing tied to a mainland hosting resource (State Council Order No. 292; MIIT Order No. 33).

Where the data actually rests

Proofpoint’s China posture is set by where its data centers are, not by a load-time test. Its email security is delivered as Proofpoint on Demand (Email Protection): mail is pointed at Proofpoint’s cloud, filtered there, and each customer tenant is provisioned onto a regional cluster. Proofpoint has been adding in-country data centers wherever data-sovereignty demand appears — storing data onshore in Australia for Email Protection and its data-security products, a United Arab Emirates site in 2025, and, in its September 2026 data-sovereignty announcement, local data centers across Singapore, India and Japan. Its own regional storage documentation is plain about the rest: storage options cover “APAC region on top of our options within the U.S. and European Union (EU) regions,” and “the storage for the APAC region is based out of Japan and the EU region is based out of Germany.” The nearest region to the mainland is Japan. There is no mainland-China region on that map, and no China data-residency option to select.

The honest picture on self-hosting is mixed, and worth stating plainly rather than overselling. A legacy on-premises email gateway still exists and can inspect mail on infrastructure you run — including on mainland soil — but Proofpoint’s modern value sits in the cloud: Targeted Attack Protection’s URL and attachment sandboxing, Enterprise Archive, Cloud DLP and its threat-intelligence analytics are cloud-delivered services with no mainland-China region to select. So “just run it on-prem in China” is only a partial lever; the practical in-country path is a lawful in-country or licensed sovereign equivalent for the data that must stay — a deployment that runs on mainland soil, not a connection routed back to the offshore cloud.

What it ingests is personal information

The residency question is sharper for email security than for almost any other tool, because of what Proofpoint handles. Its whole function is to see everything: to filter mail it processes the full content of every inbound and outbound message in real time; Enterprise Archive then retains those message bodies for years; Targeted Attack Protection uploads and detonates attachments and rewrites URLs; and Email and Cloud DLP exist precisely to read content and flag sensitive-data matches. That is the most sensitive operational data a company holds — corporate correspondence, contracts, credentials, and routinely Article 28 sensitive personal information such as health, financial and government-ID data, plus trade secrets. The tool you deployed to protect email is, by design, the single place all of that email is concentrated.

Once that content is gathered from users in China and processed or stored in a US, EU or Japan Proofpoint region, moving it there is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization whose mail it is, not Proofpoint the processor: Articles 38–40 require notice, a separate consent distinct from any general IT or employment agreement, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Two further regimes can bite. Above certain volume thresholds, where the data qualifies as “important data,” or where you are a critical information infrastructure operator, the transfer may require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if you are a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37), together with PIPL Article 40, requires personal information generated in China to be stored in China — an in-country storage duty an offshore email cloud cannot satisfy no matter which region the tenant sits in. None of this turns on how fast a message is scanned; it turns on whether the content had a lawful basis to be there, and in what volume.

Running it on a no-China-region cloud doesn’t meet the residency duty — and what does

The obvious move is to switch the tenant’s region and keep the data in place — but every region Proofpoint offers is outside the mainland, so none resolves a China residency duty. Moving a tenant from the US region to the EU or Japan region merely relocates the cross-border transfer; it does not end it, and it certainly does not bring the data onshore. Keeping China email-security data in-country means standing up a lawful in-country handling path for that data — a licensed in-country or sovereign-cloud equivalent for the filtering, archive and DLP that must stay — and sending offshore Proofpoint only what may lawfully leave. That split, what must stay and what may go, is the heart of the work, and it is a legal question before it is a technical one. You do not have to migrate off Proofpoint to get there: 21YunBox is a compliant overlay that sits in front of the stack you already run.

This is a risk map, not a verdict. Whether you owe separate consent, a transfer mechanism, a data-export security assessment, in-country storage, an ICP filing, or some combination turns on your entity, your data volumes, how much of the mail is sensitive or belongs to people in China, and who your users are — worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

You do not have to drop Proofpoint to run it lawfully for mainland China. 21YunBox is a compliant overlay, not a migration — and, for a platform you already run, a partner alongside your stack, not a competitor to it. There are three moves, and they fit together.

Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your actual entity, your data volumes, and whose personal information your email, archive and DLP ingest — so the exposure is written down before anything is moved.

Localize. Because the risk is where the email content rests, we keep the China email-security data layer in-country — on a licensed in-country or sovereign-cloud equivalent for the filtering, archive and DLP that must stay on mainland soil — so the content China requires to stay in the country does. Localize means a lawful in-country deployment of that layer, not a connection routed back to an offshore endpoint; only the minimized, lawfully transferable subset ever crosses.

Deliver. For any China-facing surface in front of the platform — the admin console, the reporting portal, the end-user quarantine and digest page your mainland users hit — the 21YunBox Optimizer provides ICP-filed, in-country delivery, in front of the stack you already run. No rebuild, no second codebase. 21YunBox never uses or suggests circumvention of any kind; the entire point is a lawful, filed, in-country path.

The goal is plain: your Proofpoint deployment runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Proofpoint have a data center in mainland China?
No. Proofpoint delivers its email-security, archive and DLP cloud from regional data centers in the US, the EU (Germany), Japan, Australia, the UAE, India and Singapore. Its own data-sovereignty expansions add in-country hosting where regulations demand it, but none is in mainland China — so email content and DLP data gathered from China come to rest on an offshore region.
Is it illegal to use Proofpoint for email in China?
Not inherently. The issue is the cross-border transfer of personal information: to filter mail, Proofpoint routes it through an offshore cloud, and PIPL permits that transfer if you give notice, obtain separate consent and meet one transfer mechanism. Whether you also face a data-localization duty depends on your role (for example, whether you are a CIIO) and your data volumes. Treat it as a risk to settle with counsel, not a blanket ban.
Can Proofpoint run on-premises in China to keep email data in-country?
Partly. A legacy on-premises email gateway can inspect mail on infrastructure you run inside China, but Proofpoint's modern analytics — attachment/URL sandboxing, Enterprise Archive and Cloud DLP — are cloud-delivered with no mainland-China region. 21YunBox maps your exposure, stands up a lawful in-country or licensed sovereign equivalent for the data that must stay, and delivers any China-facing console over ICP-filed infrastructure — no rebuild. Get a compliance assessment.

ARTICLES RELATED TO PROOFPOINT

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.