Does RSA Archer Work in China? Risk, Audit & Compliance Records, PIPL & Data Residency
Archer (formerly RSA Archer) runs its integrated risk & compliance SaaS on AWS across the US, Europe, Australia and Asia Pacific — later UAE, India and Canada — with no mainland-China region. That turns the risk registers, audit evidence and ethics-case records it holds for Chinese users into a PIPL cross-border transfer. A compliance-first look at the data-residency exposure.
Does RSA Archer work in China?
Whether you can run Archer (formerly RSA Archer) for mainland China is a data-residency question, not a reachability one — the console opens, but the risk, audit and case records it holds come to rest offshore.
Archer SaaS runs on Amazon Web Services across the US, Europe, Australia and the Asia Pacific region — later extended to the UAE, India and Canada, but with no mainland-China region. So the risk registers, control and audit evidence, third-party contract records and ethics or investigation case files it holds for your Chinese users and employees are a cross-border transfer of personal information under PIPL — some of it (allegations about identifiable people) potentially Article 28 sensitive personal information — with an in-country storage duty for CIIOs and large-volume handlers that an offshore region cannot meet. This is a risk map, not a verdict: settle the specifics with counsel.
What Archer's own documentation says about China
| Fact | Primary source |
|---|---|
| Archer's own account puts its SaaS footprint outside mainland China. In its press release on extending its SaaS infrastructure, Archer states that "Archer SaaS is currently available in the US, Europe, Australia and throughout the Asia Pacific region," built "in conjunction with Amazon Web Services (AWS)." It has since added UAE, India and Canada regions — but names no mainland-China region, so there is no in-country Archer resource for your risk, audit and case records to live on. | Archer — “Archer Announces Plans to Extend SaaS Infrastructure”, May 25, 2022 |
| Archer can be run on-premises or self-managed, not only as offshore SaaS. Archer's product pages describe deploying it "on-premises or SaaS, without a costly migration or rebuild." That on-prem or self-managed option is the real residency lever: it lets the records that must stay on mainland soil be held in-country — a choice Archer's offshore SaaS regions cannot provide on their own. | Archer — SaaS IRM product page, retrieved 2026-10-10 |
| Exporting those records abroad is a cross-border transfer under PIPL. Personal information collected in China and stored in Archer's offshore regions is a cross-border transfer: the personal-information handler — you, the Archer customer, not Archer — must give notice, obtain separate consent, and satisfy one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) under PIPL Articles 38–40. | Personal Information Protection Law of the PRC, Articles 38–40 |
| For CIIOs and large-volume handlers, the data must stay in China. Personal information and important data collected by a critical information infrastructure operator must be stored in the mainland (Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40), and exporting it can trigger a mandatory CAC data-export security assessment — duties an offshore SaaS region cannot meet. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37); PIPL Article 40 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question about Archer — the integrated risk and compliance platform formerly sold as RSA Archer — is not whether the console opens. It does. The question is where the records it keeps are allowed to come to rest. Archer is the system of record for enterprise risk registers, control libraries and policy exceptions, audit evidence and workpapers, incident and issue case files, third-party and vendor-risk assessments, and the counterparty and signatory details inside the contracts it tracks — and, where the ethics and investigations capability is switched on, reports and case notes that name identifiable people. All of that is personal information, some of it sensitive. By Archer’s own account its SaaS runs on Amazon Web Services across the US, Europe, Australia and the Asia Pacific region — later extended to the UAE, India and Canada — with no mainland-China region. So those records sit offshore, and that is a data-residency and cross-border question under China’s law well before it is ever a performance one.
Archer in China at a glance
| What decides it | In Archer's own terms — and China's law |
|---|---|
| Where the records live | Archer states that “Archer SaaS is currently available in the US, Europe, Australia and throughout the Asia Pacific region,” built “in conjunction with Amazon Web Services (AWS),” with later UAE, India and Canada regions. None is inside mainland China, so the risk registers, audit evidence and case files it holds sit offshore. |
| What it holds, and why it's personal information | Risk and control owners, auditors, incident and issue parties, and the counterparty and signatory details inside tracked contracts are all personal information. Where the ethics or investigations capability runs, case records carry allegations about identifiable people — potentially sensitive personal information under PIPL Article 28. |
| Your China users' and employees' data | Personal information collected in China and held in Archer's offshore regions is a cross-border transfer. The handler — you, the Archer customer, not Archer — owes notice, separate consent and one transfer mechanism (PIPL Articles 38–40). |
| In-country storage duty | A critical information infrastructure operator or large-volume handler must store personal information collected in China on the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and export can trigger a mandatory CAC security assessment — duties an offshore region cannot satisfy. |
| Reachability is not the axis | The dashboard loads from inside China, but that is the delivery half, not the legal one. A China-facing Archer surface actually served from the mainland — a risk portal, attestation campaign, third-party intake form or ethics hotline — needs an ICP filing bound to a mainland hosting resource Archer does not provide. |
No mainland region, so the risk and audit records leave the country
Archer’s geography settles two separate questions before performance ever enters the picture. In its own press release the company states that “Archer SaaS is currently available in the US, Europe, Australia and throughout the Asia Pacific region,” built on Amazon Web Services; it has since extended that footprint into the UAE, India and Canada specifically to “store data that must remain in-country.” That is the tell: Archer stands up in-country regions where a market’s sovereignty rules demand it — and it has stood up none for mainland China.
First, residency. If you are a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged. An offshore Archer region cannot meet that duty no matter which locality you pick, and moving important data out of the country can require a CAC data-export security assessment before it is permitted at all.
Second, the export mechanism. Holding your risk, audit and case records in an offshore region is a cross-border transfer of personal information under PIPL: the handler must give notice, obtain separate consent, and clear one route — a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). The platform you deployed to document good governance does not discharge the duty attached to where its own records then live.
Risk registers, audit evidence and case files are personal information — some of it sensitive
The exposure is structural, not incidental. Archer’s job is to be the single source of truth for how an organization manages risk and compliance — which means it accumulates personal information by design: the names, roles and contact details of risk and control owners, auditors and attestation respondents; the identities of people named in incidents and issues; and the counterparty and signatory details carried inside the third-party contracts it tracks.
Where you also run Archer’s ethics, issues-management or investigations capability, the sensitivity steps up. Those case records hold allegations about identifiable individuals, and can touch financial conduct or health — the category PIPL Article 28 treats as sensitive personal information, which requires its own separate consent, a demonstrated necessity, and a personal-information protection impact assessment, with heightened care when it crosses a border. So the tool an organization adopts to run compliance can quietly create a PIPL exposure of its own: the most sensitive records it holds are precisely the ones coming to rest offshore. Whether a given deployment reaches that bar depends on which Archer capabilities you have switched on and what they capture.
Narrowing the exposure doesn’t close the door
There are real levers, and they are worth using — but they change what crosses or where it sits, not that a transfer occurs. Field-level redaction and masking shrink how much personal information lands in an offshore region. Pseudonymizing case data lowers the sensitivity of what leaves. Choosing the nearest Archer region trims latency. Archer can also be deployed “on-premises or SaaS, without a costly migration or rebuild,” and that on-prem or self-managed option is the one lever that genuinely moves residency — because it lets the records that must stay on mainland soil be held in-country rather than in an offshore pair.
What none of these does is manufacture a mainland presence out of an offshore SaaS region: region choice among overseas localities is still overseas, and masking a field does not change the country the record rests in. Residency and the ICP-filing footing for any mainland-served surface are unaffected by how much you redact. This is a risk map, not a verdict — whether you owe separate consent, a transfer mechanism, in-country storage, a CAC security assessment, an ICP filing, or some combination turns on your entity, your data volumes, your role as handler, and who your users are, and it is worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
You keep running Archer. 21YunBox adds the part an offshore SaaS platform structurally cannot, as a compliant overlay set in front of the stack you already run — not a migration off Archer, and, for an enterprise GRC platform, a partner to it rather than a competitor.
- Map. Our China compliance team reads the PIPL cross-border, data-residency and sensitive-PI obligations — and any CII and ICP duties — against your entity, your data volumes and who your users and employees are, so you know exactly which Archer records are exposed and why.
- Localize. For the records that must stay on mainland soil, we stand up consented, in-country processing and storage — including self-hosted or self-managed Archer deployment where you run it that way — so residency is satisfied at the source, not assumed away.
- Deliver. Any China-facing Archer surface — a risk portal, an attestation or policy-acknowledgment campaign, a third-party intake form, an ethics hotline — is served over ICP-filed, in-country delivery (the 21YunBox Optimizer), in front of the system you already operate, with no rebuild and no second codebase.
21YunBox never uses or suggests circumvention of any kind. The result is an Archer setup that runs legally and compliantly for your users in China.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s data-export security assessment measures
- China Cybersecurity Law — data localization
