Does Rollbar Work in China? Error Data, PIPL & Data Residency
Rollbar runs no data region inside mainland China — its environment is hosted on Google Cloud with a primary data center in the Iowa region, and every sub-processor it lists sits in the United States. So the error items it ingests from your Chinese users — carrying user IDs, emails, client IPs and request context — come to rest offshore, a cross-border transfer of personal information under PIPL. A compliance-first look at the data-residency door, and the lawful in-country path.
Does Rollbar work in China?
Yes — Rollbar ingests and its dashboard loads from mainland China, but that is the easy half. Rollbar operates no data region inside the mainland: its environment runs on Google Cloud with a primary data center in the Iowa region, so every error item you capture in China comes to rest offshore — a cross-border transfer of personal information, not a speed problem.
Rollbar's Security & Compliance Policy states that "Our primary data center, where data is stored and encrypted at rest, is located in the Iowa region," and its sub-processor list (current as of December 3, 2025) names fourteen vendors, every one in the USA. Each error item is personal: Rollbar's configuration reference keeps "Track user's IP address" on by default and can attach a user's id, email and username, alongside request URLs and parameters. Gathered from mainland users and sent to an offshore backend, that is a cross-border transfer PIPL governs (notice, a separate consent and a transfer mechanism, Articles 38–40), and for a CIIO or large-volume handler it must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). The table below is Rollbar's own wording and the rule each line triggers.
This is a risk map, not a verdict — what applies turns on what your error payloads carry, how much is personal, and who your users are. Our China team can map your exposure with you →
What Rollbar's own documentation says about China
| Fact | Primary source |
|---|---|
| Rollbar operates no data region inside mainland China. In its Security & Compliance Policy Rollbar states that it uses "Google Cloud Platform to host the complete Rollbar environment" and that "Our primary data center, where data is stored and encrypted at rest, is located in the Iowa region." There is no mainland-China option to choose, so the error items — stack traces wrapped in user, request and IP context — that you capture in China come to rest on infrastructure in the United States. | Rollbar — Security and Compliance Policy (docs.rollbar.com), retrieved 2026-10-09 |
| The error items Rollbar collects are personal information. Rollbar's configuration reference keeps "Track user's IP address" on by default, and sets email and username capture to false "Pursuant to General Data Protection Regulation (GDPR) (EU) 2016/679," telling you to "make sure you have their consent." Its person-tracking feature attaches a user's id, email and username to each error, and occurrences carry request URLs and parameters too. Collected from mainland users and shipped offshore, that is a cross-border transfer of personal information under PIPL — notice, a separate consent and a transfer mechanism (Articles 38–40). | Rollbar — PHP Configuration Reference and Person Tracking (docs.rollbar.com), retrieved 2026-10-09; PIPL Articles 38–40 |
| Every Rollbar sub-processor sits in the United States — none in China. Rollbar's published Data Subprocessors list, current as of December 3, 2025, names fourteen vendors (Google Cloud for infrastructure among them) and gives the location of each as "USA." Mainland China appears nowhere on the list, so there is no in-country region where a critical information infrastructure operator or large-volume handler could meet the data-localization duty (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). | Rollbar — Data Subprocessors (docs.rollbar.com), retrieved 2026-10-09; PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) |
| Reachability is the easy half — Rollbar is a backend, not a hosted site. Rollbar's privacy policy (effective October 2, 2024) says it may "process, and transmit information in the United States and locations around the world — including those outside your country," and its environment reaches mainland users through a global points-of-presence network. So the exposure is not whether Rollbar connects but where the error data it ingests is stored. The ICP filing (State Council Order No. 292; MIIT Order No. 33) attaches to the public mainland site or app you operate and to any China-facing dashboard served from inside the mainland — not to Rollbar itself. | Rollbar — Privacy Policy (docs.rollbar.com), retrieved 2026-10-09; State Council Order No. 292; MIIT Order No. 33 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a mainland-China audience, the Rollbar question is almost never whether the dashboard opens — it does, and new error items keep reaching Rollbar’s ingestion endpoint. The real question is where those error items are allowed to come to rest. Rollbar answers it in its own documentation: it operates no data region inside mainland China. Its environment runs on Google Cloud with a primary data center in the Iowa region, and every sub-processor it publishes sits in the United States. So the exceptions your mainland app throws — each one wrapped in the user, request and IP context that makes it debuggable — are captured in China and stored on infrastructure offshore. Because that context is personal information, exporting it is a cross-border transfer China’s law governs. That the dashboard loads is the delivery side; where the error data is stored is the exposure.
Rollbar in China at a glance
| What decides it | In Rollbar's own terms |
|---|---|
| Where it comes to rest | Rollbar's Security & Compliance Policy says it uses “Google Cloud Platform to host the complete Rollbar environment,” with a primary data center “located in the Iowa region.” Its sub-processor list, current as of December 3, 2025, puts all fourteen vendors in the “USA.” None is in mainland China. |
| Can you keep it in China | There is no mainland region or in-country option to select. Rollbar's privacy policy says it may “process, and transmit information in the United States and locations around the world — including those outside your country.” |
| What each error item carries | Person data — a user's “id,” and optionally “email” and “username” — attaches to each error, and the configuration reference keeps “Track user's IP address” on by default. Occurrences also carry request URLs, parameters and headers. |
| Your China users' error data | Captured in the mainland and sent to an offshore backend, it is a cross-border transfer PIPL governs; CIIOs and large-volume handlers owe an in-country storage duty Rollbar's offshore data center cannot meet. |
| Is it reachable? | Yes — ingestion reaches Rollbar from inside China over a global points-of-presence network. The exposure is where the error data is stored, not whether it arrives. |
No mainland region, so your error telemetry leaves the country
Rollbar’s environment runs on Google Cloud, and in its Security & Compliance Policy the company states that “Our primary data center, where data is stored and encrypted at rest, is located in the Iowa region.” Its published Data Subprocessors list — current as of December 3, 2025 — names fourteen vendors, Google Cloud among them as the infrastructure provider, and gives the location of every one as the USA. Rollbar’s privacy policy (effective October 2, 2024) adds that it may “process, and transmit information in the United States and locations around the world — including those outside your country.” Not one of those places is mainland China, and there is no in-country region to pick. So the SDK embedded in your mainland app, and the server libraries on your mainland hosts, gather errors in China and send them to a backend offshore. Reaching Rollbar was never the obstacle; keeping the data each error carries inside the country is.
The error data Rollbar collects is personal information
An error item is not an anonymous stack trace. Rollbar’s person-tracking feature “can track which of your People (users) are affected by each error,” attaching an id and, optionally, an email and username to each occurrence. Its configuration reference sets “Track user’s IP address” on by default, while email and username capture are “set to false by default” — in Rollbar’s own words, “Pursuant to General Data Protection Regulation (GDPR) (EU) 2016/679” — with the instruction to “make sure you have their consent as required by the regulation.” On top of that, occurrences routinely carry request URLs, parameters and headers. A single mainland user’s client IP is already personal information, and under China’s Personal Information Protection Law sending it to an offshore backend is a cross-border transfer: the handler — you, not Rollbar — must give notice, obtain a separate consent, and clear one transfer mechanism, whether a CAC data-export security assessment, the CAC standard contract, or certification (Articles 38–40). Rollbar’s own GDPR-driven defaults are a tell — the tool already treats this as regulated personal information.
Scrubbing narrows the exposure — it does not close the door
Rollbar gives you levers to reduce what leaves: you can set IP capture to anonymize so only part of the address is kept, leave email and username off, and scrub sensitive fields before an occurrence is sent. Those are worth doing. But scrubbing changes what crosses the border, not the fact that it crosses, and it does nothing for residency. If you are a critical information infrastructure operator or a large-volume handler, personal information gathered in China has to be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39) — and with every Rollbar data center offshore, there is no in-country store on Rollbar to meet that duty. The ICP filing (State Council Order No. 292; MIIT Order No. 33) is a separate door: it attaches to the public mainland site or app whose errors you are tracking, and to any China-facing Rollbar dashboard you serve from inside the mainland — not to Rollbar as a backend service.
None of this is a verdict. Whether you owe a transfer mechanism, in-country storage, a separate consent, or some combination of them turns on what your error payloads actually carry, how much of it is personal, and who your users are — settle it with counsel before you wire the SDK into a mainland release.
Where 21YunBox fits — a compliant overlay, not a migration
You keep running Rollbar. What an error-tracking service hosted entirely offshore cannot give you is a lawful place inside China for the personal data its SDKs collect there — and that is the gap 21YunBox closes. We map the PIPL cross-border, data-residency and ICP obligations that attach to your error telemetry, against your entity, your data volumes and who your users are. Where an error stream cannot lawfully leave, we localize it onto a consented, in-country processing-and-storage pattern that keeps regulated data in the mainland. And we deliver any China-facing dashboard or origin over ICP-filed, in-country infrastructure — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no second codebase. 21YunBox never uses or suggests circumvention of any kind; every node sits on lawful, in-country footing.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s data-export security assessment measures
- China’s Cybersecurity Law and data localization
