Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does SAS Work in China? Data Residency, Localization & PIPL Cross-Border

SAS Viya is deployable across cloud, hybrid, and on-premises, so it can run in mainland China — the question is residency. SAS Managed Cloud Services runs only on Microsoft Azure, Azure Government, and AWS, with no mainland-China environment, so a SAS-hosted deployment of your risk, fraud, credit, and health analytics rests offshore — a PIPL cross-border transfer. A compliance-first look at SAS and the lawful China path.

Does SAS work in China?

SAS the software runs fine in China — SAS Viya deploys across cloud, hybrid, and on-premises, so you can run it in-country; the real question is where its data rests, and the SAS-managed cloud has no mainland-China environment.

SAS concentrates data — it pulls from every source system and builds extracts, in-memory tables, and cached result sets from customer, transaction, credit, risk, and health records — so a SAS environment is frequently a large store of China personal information, much of it sensitive personal information under PIPL Article 28. SAS Viya is deployable on infrastructure you operate, so running it in-country is lawful and needs no migration; but SAS Managed Cloud Services runs only on Microsoft Azure, Microsoft Azure Government, and AWS with no mainland-China environment, so loading China-collected personal data into a SAS-hosted deployment is a PIPL cross-border transfer, and for a critical information infrastructure operator or a large-volume handler the in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) is one an offshore environment cannot meet.

Treat the specifics as a risk to confirm with counsel — we map exposure, we don't rule on it. Our China team can map your exposure →

What SAS's own documentation says about China

FactPrimary source
SAS Managed Cloud Services has no mainland-China environment. SAS's own cloud page states the managed service “supports deployments on Microsoft Azure, Microsoft Azure Government and Amazon Web Services (AWS),” and that its hosted model “provides SAS software deployed on Microsoft Azure, Microsoft Azure Government or AWS infrastructure.” None of the three is a mainland-China environment, so a SAS-hosted deployment comes to rest offshore. SAS, “SAS Managed Cloud Services” (sas.com), retrieved 2026-10-10
SAS Viya is deployable where you choose — including in-country — and concentrates sensitive data. SAS describes Viya as offering “flexible deployment options across cloud, hybrid and on-premises environments,” so it runs on infrastructure you operate, including on mainland-China soil. SAS also says Viya is “used across industries, including for customer intelligence, fraud detection, health care, forecasting” — so the extracts, in-memory tables, and caches it builds are frequently sensitive personal information under PIPL Article 28. SAS, “SAS Viya” platform page (sas.com), retrieved 2026-10-10
China personal data in an offshore SAS deployment is a cross-border transfer under PIPL. Loading the customer, transaction, credit, risk, and health records you collect from users in mainland China into a SAS environment hosted offshore triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-10
At scale, an in-country storage duty applies that an offshore environment cannot meet. For a critical information infrastructure operator — and, at the volumes the CAC specifies, a large-volume handler — personal information collected in the mainland must be stored in the mainland under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37). Because a SAS environment concentrates data from across every source system, it is precisely the kind of store that can cross that threshold. PIPL Article 40; Cybersecurity Law of the PRC Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a product that serves mainland China, the first question about SAS is not whether the software installs or whether a user can open a report — SAS Viya is deployable wherever you choose, and SAS 9 has run in on-premises data centers for decades. The real question is where the data SAS holds is allowed to come to rest. SAS is an analytics, business-intelligence, and statistical platform: it pulls data from across your source systems and builds extracts, in-memory tables, and cached result sets from customer, transaction, credit, risk, and health records. That is personal information, much of it sensitive personal information under PIPL. Two facts fix the posture. SAS Viya offers “flexible deployment options across cloud, hybrid and on-premises environments,” so it can run in-country — the lawful lever — while SAS Managed Cloud Services runs only on Microsoft Azure, Microsoft Azure Government, and AWS, with no mainland-China environment, so a SAS-hosted deployment rests offshore.

SAS Managed Cloud Services documentation stating the managed service supports deployments on Microsoft Azure, Microsoft Azure Government, and Amazon Web Services (AWS), with no mainland-China environment listed
SAS's own cloud page states: “SAS Managed Cloud Services supports deployments on Microsoft Azure, Microsoft Azure Government and Amazon Web Services (AWS).” Those are the only clouds SAS names for its managed service, and none is a mainland-China environment — so a SAS-hosted deployment of your risk, fraud, and customer analytics comes to rest offshore. Source: sas.com — SAS Managed Cloud Services

SAS in China at a glance

What decides it In SAS's own terms — and China's law
Where does the data physically rest? SAS's own cloud page says SAS Managed Cloud Services "supports deployments on Microsoft Azure, Microsoft Azure Government and Amazon Web Services (AWS)." None of the three is a mainland-China environment, so a SAS-hosted deployment rests offshore. SAS Viya itself, by contrast, offers "flexible deployment options across cloud, hybrid and on-premises environments" and is deployable on infrastructure you operate — including on mainland-China soil.
What a SAS environment holds — and why it's personal information SAS says Viya is "used across industries, including for customer intelligence, fraud detection, health care, forecasting." The extracts, in-memory tables (CAS), and cached result sets it builds are drawn from customer records, transactions, credit and risk files, and health data — personal information under PIPL, and sensitive personal information under Article 28 where financial, health, or minors' data appear. A BI platform concentrates this: it pulls from every source system into one place.
Your China users' records = a cross-border transfer if offshore Loading personal information collected from users in mainland China into a SAS deployment hosted in an offshore environment is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
The in-country storage duty For a critical information infrastructure operator — and, at the volumes the CAC specifies, a large-volume handler — personal information collected in the mainland must be stored in the mainland under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37); the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39 (substance unchanged). An offshore SAS Managed Cloud Services environment structurally cannot meet it.
Reachability isn't the axis — the lawful path That a SAS report renders quickly from an offshore environment changes nothing: the data still rests offshore, and the residency duty still applies. Because SAS Viya is deployable where you choose, the lawful path is to run it in-country — self-managed on mainland infrastructure or on a licensed in-country/sovereign managed option — and to put any China-facing surface in front of it on ICP-filed delivery.

Where the data actually rests

SAS’s position is set by where a deployment runs, not by a load-time test. The managed service, SAS Managed Cloud Services, states that it “supports deployments on Microsoft Azure, Microsoft Azure Government and Amazon Web Services (AWS),” and its hosted model “provides SAS software deployed on Microsoft Azure, Microsoft Azure Government or AWS infrastructure.” Those are the only clouds SAS names for the managed offering, and none is a mainland-China environment. Data placed there is offshore relative to the mainland, and moving mainland-collected personal information into it is a cross-border transfer out of China. SAS itself acknowledges the data-location problem directly: its Remote Managed Services model promises to “alleviate your compliance concerns by locating your data in your own data center,” managing the SAS software “while you maintain your own cloud or on-premises infrastructure.” That is the shape of the lawful lever.

Because of all this, the familiar “does it respond from Shanghai?” test is the wrong question — which is why this page publishes no first-party China latency figure for SAS; speed is not the axis for data that is sitting in the wrong country. SAS Viya is a licensed, container-based platform with, in SAS’s words, “flexible deployment options across cloud, hybrid and on-premises environments” and “governed deployment across cloud, hybrid, and on-prem” — it runs on infrastructure you operate, and SAS 9 has long run in on-premises data centers. So the residency question is entirely about how you deploy, not about whether the software works. See our explainer on cross-border data transfers under PIPL.

What it holds is personal information

A SAS environment is rarely a handful of rows. SAS exists to concentrate data: it ingests from across your source systems and builds extracts, in-memory tables, and cached result sets to model and report on. SAS describes Viya as “used across industries, including for customer intelligence, fraud detection, health care, forecasting and AI/ML model deployment,” and as “trusted by regulated and risk-sensitive industries that require speed, scale and compliance.” That is precisely the data that identifies people — customer and account records, transaction histories, credit and risk files, insurance and claims data, and health records. They are personal information under China’s Personal Information Protection Law wherever they relate to an identified or identifiable person, and sensitive personal information under PIPL Article 28 where financial, health, biometric, or minors’ data appear.

The concentration is not incidental — it is the whole point of a BI platform, and it is also what sharpens the China question. A SAS deployment is frequently one of the largest single stores of China personal information a company holds, because it pulls everything into one place. A handler that processes personal information at the scale the Cyberspace Administration of China specifies falls under heightened duties: a mandatory data-export security assessment before personal information may leave the country, and, for a critical information infrastructure operator or a handler holding data at those volumes, an in-country storage duty. Under PIPL Article 40 and the Cybersecurity Law Article 39 (formerly Article 37), personal information and important data collected in the mainland must be stored in the mainland. An offshore SAS Managed Cloud Services environment structurally cannot satisfy that duty, and the more your SAS environment concentrates, the more likely you are to be inside the threshold that triggers it.

Running it on a no-China-region managed service doesn’t meet the residency duty — and what does

If a SAS Managed Cloud Services environment in another country cannot hold mainland-collected personal information that the law requires to stay home, the fix is not to reach back to that offshore environment from inside China — it is to run SAS where the data must live. This is where SAS’s deployment flexibility is decisive, and it is good news: because SAS Viya deploys across cloud, hybrid, and on-premises environments, you do not have to migrate off SAS or rebuild your analytics to become compliant. You run the same platform, in-country.

Two in-country patterns are lawful. The first is a customer-managed SAS Viya deployment on mainland-China infrastructure — on your own cloud account or on-premises — so the environment and the personal information in it never leave the country; SAS’s own Remote Managed Services even keeps the data and infrastructure in your environment while SAS operates the software. The second is a licensed in-country or sovereign-cloud managed option operated on the mainland by a local operator, subject to that operator’s own availability and compliance, which you confirm with them directly. In either case you transfer offshore only the aggregated or de-identified results that may lawfully leave, and you keep the raw, user-level China data in-country. None of this is a verdict on your specific situation: whether you are a critical information infrastructure operator, which volume thresholds you cross, which transfer mechanism applies, and whether any transfer is lawful at all are questions to settle with your counsel against the data you actually hold and the entity that holds it.

The lawful path — map, localize, deliver

There is a lawful, durable way to run SAS for users in China, and it keeps the shape of your stack intact. 21YunBox is a compliant overlay, not a migration — and a partner to SAS, not a competitor. Our China team works in three moves. We map your exposure: the PIPL cross-border question, the data-export security assessment, the in-country storage duty for critical information infrastructure operators and large-volume handlers, and the ICP filing (备案) obligation on any China-facing surface — read against your entity, your data volumes, and whose personal information sits in the SAS environment. We localize the deployment by running it in-country — a customer-managed SAS Viya deployment on mainland infrastructure, or a licensed in-country/sovereign managed option — so the personal information stays on mainland soil; localize means standing up a lawful in-country deployment, never a route back to an offshore environment. And we deliver every China-facing surface in front of SAS — the application, the API edge, the admin and reporting portals your mainland users reach — in-country over ICP-filed infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild and no second codebase. The result runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does SAS work in China?
The software does — SAS Viya offers flexible deployment across cloud, hybrid, and on-premises environments, so it runs wherever you deploy it, including on mainland-China infrastructure, and SAS 9 has long run in on-premises data centers. What has no mainland-China option is the SAS-managed cloud: SAS Managed Cloud Services names only Microsoft Azure, Microsoft Azure Government, and AWS. So availability is not the obstacle; data residency is. Confirm the specifics with counsel.
Does SAS Managed Cloud Services have a China region?
No. SAS's cloud page names only Microsoft Azure, Microsoft Azure Government, and Amazon Web Services (AWS) for the managed service, and none is a mainland-China environment — so a SAS-hosted deployment rests offshore, making the personal information you collect from China users and load into it a cross-border transfer under PIPL (Articles 38–40). For a critical information infrastructure operator or a large-volume handler, an in-country storage duty (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) also applies, which an offshore environment cannot meet. SAS's own Remote Managed Services instead keeps your data and infrastructure in your own on-premises or private cloud.
How do I run SAS compliantly for mainland-China users?
Because SAS Viya is deployable where you choose, the lawful path is to run it in-country rather than reach back to an offshore environment: a customer-managed deployment on mainland infrastructure or your own cloud account, or a licensed in-country/sovereign managed option, keeping the raw China user-level data on mainland soil and transferring offshore only what may lawfully leave. 21YunBox maps the exposure, localizes the deployment in-country, and delivers the China-facing app, API, and reporting surface on ICP-filed infrastructure — not a route around China's data-export rules. Treat the specifics as a risk to confirm with counsel.

ARTICLES RELATED TO SAS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.