Does SAP Analytics Cloud Work in China? Data Residency, Localization & PIPL Cross-Border
SAP Analytics Cloud is a SaaS BI, planning and predictive cloud whose tenants run offshore by default on SAP (NEO) or hyperscaler data centers, though SAP's own docs also reference an Alibaba Cloud China (AliCloud CN40) region. A compliance-first look at where your planning and analytics data rests, PIPL cross-border transfer, and the lawful in-country path.
Does SAP Analytics Cloud work in China?
Whether a dashboard opens is not the test — data residency is, and SAP Analytics Cloud runs offshore by default.
SAC is a SaaS BI, planning and predictive cloud; by default its tenants sit in SAP’s own (NEO) or non-SAP hyperscaler data centers, all outside the mainland, and SAP’s own support documentation separately references a SAC tenant hosted in AliCloud (CN40), its Alibaba Cloud China region. Loading China-collected personal information into an offshore tenant is a PIPL cross-border transfer (Articles 38–40), and for a CIIO or large-volume handler the in-country storage duty (PIPL Art 40; CSL Art 39, formerly Art 37) is one an offshore tenant cannot meet. The lawful lever is residency — keep the China analytics data in-country on a licensed in-country or sovereign option, not a global tenant.
This is a risk map, not a ruling — confirm specifics with counsel. Our China team can map your exposure →
What SAP Analytics Cloud's own documentation says about China
| Fact | Primary source |
|---|---|
| SAP Analytics Cloud is hosted on SAP or non-SAP data centers — offshore by default. SAP’s support documentation states: “SAP Analytics Cloud can be hosted either on SAP data centers or on non-SAP data centers,” and the region code in a tenant’s URL identifies which — a single-digit code (us1, jp1) is an SAP data center (NEO), a two-digit code (eu10, us30) a non-SAP data center on Cloud Foundry — all outside mainland China. | SAP KBA 2397165, “How do I connect the SAP Cloud Connector (SCC) to SAP Analytics Cloud (SAC)?” (apps.support.sap.com), retrieved 2026-10-10 |
| A separate Alibaba Cloud China option exists, operated apart from global tenants. The same SAP article gives a distinct instruction for a “SAC tenant hosted in AliCloud (CN40),” SAP’s Alibaba Cloud China region, reached through a separate .cn account-registration system — an in-country region that is separately operated, not a setting you toggle on a global tenant. | SAP KBA 2397165, “How do I connect the SAP Cloud Connector (SCC) to SAP Analytics Cloud (SAC)?” (apps.support.sap.com), retrieved 2026-10-10 |
| China personal information in an offshore SAC tenant is a PIPL cross-border transfer. Under China’s Personal Information Protection Law Articles 38–40, moving mainland-collected personal information to an offshore analytics tenant requires notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. | Personal Information Protection Law of the PRC, Articles 38–40, retrieved 2026-10-10 |
| CIIOs and large-volume handlers owe an in-country storage duty. PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37 — renumbered by the 2025 amendment in force January 1, 2026, substance unchanged) require personal information collected in the mainland to be stored there — a duty an offshore SAC tenant cannot meet. | PIPL Art 40; PRC Cybersecurity Law Art 39 (formerly Art 37), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a team rolling out SAP Analytics Cloud (SAC) to mainland China, the first question is usually whether people can open a story or a planning model from inside the country. They generally can — reachability is not where this decision is settled. What settles it is data residency: where the models, planning data, stories, extracts and in-memory result sets SAC builds are allowed to come to rest. SAC is a software-as-a-service analytics cloud, and by default its tenants run from SAP’s own (NEO) data centers or non-SAP data centers on hyperscaler infrastructure — all offshore. SAP’s own support documentation also references a SAC tenant hosted in AliCloud (CN40), its Alibaba Cloud China region, operated through a separate .cn account system. So an in-country region exists — but having one is not automatic compliance. The decision is where your China analytics data physically lives.
SAP Analytics Cloud in China at a glance
| What decides it | In SAP's own terms — and China's law |
|---|---|
| Where the data physically rests | SAC is SAP's SaaS BI, planning and predictive cloud on SAP Business Technology Platform. By default a tenant runs from SAP's own data centers (NEO) or non-SAP data centers on Cloud Foundry (hyperscaler infrastructure) — all offshore. SAP's support docs also reference a "SAC tenant hosted in AliCloud (CN40)," its Alibaba Cloud China region, which is separately operated. |
| What it holds & why it is PI | SAC ingests, models, extracts and caches your business data — customer records, financial figures, and headcount and workforce-planning numbers, plus the named individuals in stories and models. Much of that is personal information under Chinese law, and a BI platform concentrates it in one place. |
| Your China users' records → cross-border if offshore | Load China-collected personal information into an offshore SAC tenant and that is a cross-border transfer (数据出境) under PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. |
| The in-country storage duty | For a critical information infrastructure operator or large-volume handler, PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) require personal information collected in China to be stored in China — a duty an offshore SAC tenant cannot meet. |
| Reachability is not the axis | Whether a dashboard opens is not the test. The lawful levers are to keep the China analytics data in-country — on the licensed in-country (AliCloud CN40) option where it fits, or a mainland-resident analytics deployment — and to deliver any China-facing dashboards over ICP-filed, in-country infrastructure (the 21YunBox Optimizer). |
Where the data actually rests
SAP Analytics Cloud is delivered only as a managed cloud service — there is no customer-run SAC server you install on your own hardware. That makes the hosting region the whole of the residency question. SAP’s own support article spells out the model: “SAP Analytics Cloud can be hosted either on SAP data centers or on non-SAP data centers,” and the region code in your tenant URL tells you which — a single-digit code such as us1 or jp1 is an SAP data center (NEO), a two-digit code such as eu10 or us30 is a non-SAP data center on Cloud Foundry (hyperscaler infrastructure). Every one of those is outside the mainland. The same article carries a separate instruction for a “SAC tenant hosted in AliCloud (CN40),” SAP’s Alibaba Cloud China region, which is reached through a distinct .cn account-registration system — an in-country option that is separately operated, not a switch you flip on a global tenant.
That distinction is where most analytics rollouts go wrong, because a BI platform does not just display data — it concentrates it. Acquired and imported models copy source data into the tenant’s in-memory store; even live connections, which query your warehouse in place, still build result sets, caches, variance calculations and metadata that come to rest in the tenant. Whichever data center your tenant runs in is therefore where a large share of your analytics data, and everything SAC derives from it, physically lives. This page publishes no first-party China latency figure for SAC, because speed is not the axis a residency decision turns on.
What it holds is personal information
The data that lands in SAC is rarely anonymous. Planning and consolidation models carry revenue, cost and headcount broken down by entity and often by named employee; sales and service stories carry customer records; workforce and HR planning carries personal and sometimes sensitive information about identifiable people. Under China’s Personal Information Protection Law that is personal information, and some of it — depending on sector and scale — may be classified as “important data.” The handler’s duty falls on you, the operating entity, not on SAP the vendor.
Because a BI deployment pulls from every source system into one place, it is frequently one of the single largest concentrations of China personal information a company holds — which is exactly what can push a handler over the large-volume thresholds that trigger the in-country storage duty. The moment China-collected personal information comes to rest in an offshore SAC tenant, two bodies of law engage: it is a cross-border transfer under PIPL Articles 38–40 (notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification), and for a critical information infrastructure operator or large-volume handler the Cybersecurity Law’s Article 39 (formerly Article 37) requires that personal information to be stored in the mainland in the first place.
Running SAC offshore doesn’t meet the residency duty — and what does
For a CIIO or a large-volume handler, the in-country storage duty under Article 39 (formerly Article 37) is one no offshore tenant can satisfy, however it is configured. Moving a global SAC tenant from a US data center to an EU one does not help — both are outside the mainland, so it relocates the cross-border transfer rather than ending it. Above the thresholds, or where the analytics data is “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves.
The lawful lever is residency, not reach. Because SAC is SaaS-only, keeping the China analytics data in-country means two things working together: provisioning the China-scoped workload on the licensed in-country option — SAP’s AliCloud (CN40) Alibaba Cloud China region — where your entity is eligible and it genuinely fits, and keeping the source data and any China-resident analytics on mainland infrastructure, with only what may lawfully leave flowing to your global tenant. That in-country region is separately operated and is not a compliance verdict in itself. None of this is a ruling that SAC is “blocked” or “illegal” in China — it runs there, lawfully, when the pieces line up. It is a map of exposure: which path fits turns on your entity, the data your models hold, your classification under Chinese law, and who your users are — settle the specifics with counsel before your China operations depend on them.
The lawful path — map, localize, deliver
There is a compliant way to run SAP Analytics Cloud for a China operation, and it has a shape.
First, map: our China compliance team works through where your analytics data lives today and where Chinese law needs it to live — which customer, financial and workforce records collected in the mainland must stay in-country, what may lawfully flow to a global SAC tenant, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty bites, and what your notice and consent has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we keep the China analytics data on mainland soil — on the licensed in-country option (SAP’s AliCloud (CN40) Alibaba Cloud China region) where your entity qualifies, or on a mainland-resident analytics deployment that holds the China data and passes SAC only what may lawfully leave. Localize means standing up a lawful in-country home for the data — never a tunnel back to an offshore endpoint.
Then deliver: the China-facing surfaces built on top — the dashboards, planning-entry screens and embedded analytics your mainland users actually open — are an internet service in the mainland, so they carry an ICP filing (备案) duty and need compliant in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no second codebase: a compliant overlay in front of SAP’s platform, not a migration off it, and a complement to SAC rather than a competitor. The result is an analytics estate that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
