Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Smartling Work in China? PIPL Cross-Border Data Transfer & Content Residency

Smartling is a translation-management and localization platform: the source content you send it — UI strings, support tickets, documents, product copy — is stored and translated on Amazon Web Services locations worldwide and handled by human linguists offshore. For mainland-China content that is a PIPL cross-border transfer of the personal and sensitive information inside it. A compliance-first look at the exposure and the lawful in-country path.

Does Smartling work in China?

Whether you can use Smartling in China is a data-residency and cross-border-transfer question, not a question of whether the platform loads.

Smartling is a translation-management and localization platform: the source content you connect to it — UI strings, support tickets, documents, product copy — is stored and translated on "Amazon Web Services locations across the globe," by machine engines and by its network of human linguists, with no mainland-China region. So every sync ships your content, and whatever personal or sensitive information is inside it, offshore — a PIPL cross-border transfer — into a translation-memory and glossary corpus that persists and grows there. The lawful lever is to keep China-origin content's translation in-country: minimize and pseudonymize personal information before any string is sent, and route what must stay in China to a licensed in-country translation path — not to make the offshore platform sync faster.

This is a risk map, not a verdict — your duties turn on your data volumes and your role. Our China team can map your Smartling content exposure →

What Smartling's own documentation says about China

FactPrimary source
Smartling houses customer data offshore, with no mainland-China region. On its own data page Smartling states it "uses Amazon Web Services locations across the globe to house customer data," and that its "Translation Management System" resides "at Amazon Web Services" (HITRUST e1 certified). Its security and personal-data pages name no mainland-China region and describe no customer-selectable China data location or self-hosted deployment of the service. Smartling — Personal Data and Information Security; Security at Smartling, retrieved 2026-10-10
Your content is handled offshore by human linguists and outside contractors, and the content corpus persists there. Smartling translates through machine engines and its "network of 4,000+ linguists," and "employs a number of independent contractors" plus "independent translation service providers" — each an added handler of your strings — while stating it cannot "provide lists of these contractors." Source, translations, translation memory and glossaries accumulate and persist on its AWS infrastructure. Smartling — Security at Smartling; Personal Data and Information Security, retrieved 2026-10-10
Sending China-origin content abroad to be translated is a cross-border transfer under PIPL. The source text and the personal information inside it leave China, so the handler (you, the customer) owes notice, a separate consent, and a transfer mechanism — a CAC security assessment, the standard contract, or certification — under PIPL Articles 38–40. Sensitive categories (medical, financial, legal, ID) add Article 28's separate consent and prior impact assessment. Personal Information Protection Law (PIPL), Articles 28 and 38–40
For a CIIO or high-volume handler, China-origin personal information must be stored in China. Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — is a storage duty that an offshore translation-memory corpus on worldwide AWS cannot meet. Cybersecurity Law of the PRC, Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

The question teams ask about Smartling in China is usually whether the platform loads and the integrations sync — whether strings flow in and translations come back. For mainland-China content that is the wrong test. Smartling is a translation-management and localization platform: the source content you connect to it — UI strings, help-center articles, support tickets, product and marketing copy, documents, contracts — is uploaded to Smartling’s cloud, translated there by machine engines and by its network of human linguists, and kept. Smartling states it “uses Amazon Web Services locations across the globe to house customer data,” and names no mainland-China region. So your source text, its translations, and the translation memory and glossaries that accumulate from every job sit offshore and grow with each sync — and whatever personal, sensitive or confidential information is inside those strings travels with them. Under China’s privacy law that is a cross-border transfer of personal information (PIPL Articles 38–40), it reaches sensitive categories under Article 28, and for a CIIO or high-volume handler it raises an in-country storage duty — before the platform’s reachability even enters.

Smartling's Personal Data and Information Security page stating that Smartling uses Amazon Web Services locations across the globe to house customer data, largely because of the risks associated with data crossing jurisdictional boundaries
"Smartling uses Amazon Web Services locations across the globe to house customer data." Smartling's own data page says it houses customer content on AWS sites worldwide — chosen, it says, "largely because of the risks associated with data crossing jurisdictional boundaries" — and names no mainland-China region. Source: Smartling — Personal Data and Information Security

Smartling in China at a glance

What decides it In Smartling's own terms — and China's law
What content you send Smartling is where your localization content lives — UI strings, help-center and knowledge-base articles, support tickets, product and marketing copy, documents and contracts flow in to be translated. That is exactly the content most likely to carry names, emails, addresses, and medical, financial or legal detail. Under PIPL those online and personal details are personal information, and the sensitive categories engage Article 28 — a separate consent and a prior protection impact assessment. You cannot anonymize a document you need translated in full.
Where it goes Offshore. Smartling states it "uses Amazon Web Services locations across the globe to house customer data," and names no mainland-China region. Moving a Chinese user's content into that offshore platform is a cross-border transfer (数据出境) under PIPL — notice, a separate consent, and a transfer mechanism (Articles 38–40).
A permanent offshore corpus A translation-management platform does not translate-and-forget: your source, its translations, the translation memory and glossaries accumulate and persist in the platform and grow with every sync. For a critical information infrastructure operator or a high-volume handler, personal information generated in China must be stored in China — Cybersecurity Law Article 39 (formerly Article 37) — a duty an offshore content store cannot meet.
Who handles it, and what's kept Translation runs through machine engines and Smartling's "network of 4,000+ linguists," plus the "independent contractors" and "independent translation service providers" it engages — each an added handler of your content. Smartling says it cannot "provide lists of these contractors," and its own pages describe no customer-selectable China region, no self-hosted or private-cloud deployment, and no published no-data-retention tier for this service. Confirm with Smartling what is retained, whether inputs feed any model, and who touches China content.
Reachability is not the axis That the platform loads and syncs from the mainland is a delivery matter, not the decision. The lawful move is to minimize and pseudonymize personal information before any string is sent, keep China-origin content that cannot be stripped on a licensed in-country translation path, and govern who handles it — while the China-facing site that consumes the translations still needs an ICP filing and in-country delivery.

What you actually send — and where it goes

Smartling is a translation-management system (TMS) and localization platform, not a one-shot translate box. You connect it to your repositories, your CMS, your help center and your apps; it ingests your source content, stores it, routes it for translation — by machine engines and by human linguists — and syncs the finished translations back. Along the way it builds and keeps a persistent corpus for you: the source strings, every translation, the translation memory and glossaries that grow job over job, and the CAT-tool visual context that shows translators where each string appears. That corpus is the point of a TMS — it is why the next job is cheaper and more consistent — and it is also why the exposure is a standing offshore store of your content, not a transient call.

And translation is not only software. Smartling runs managed human translation through its “network of 4,000+ linguists,” alongside a marketplace that facilitates “purchase of translation services by Smartling end users from independent translation service providers,” and it “employs a number of independent contractors to provide services throughout its business.” Each of those people is an additional handler who can see your content — a set of data handlers a pure-software tool does not have — and Smartling states it cannot “provide lists of these contractors.” Machine translation, in turn, routes across multiple third-party engines. So your strings are not merely stored offshore; they are read and processed by machines and by people, in places and by parties you do not fully enumerate.

Where all of it lives is offshore. Smartling attained “a HITRUST e1 certification for its Translation Management System residing at Amazon Web Services,” and states plainly that it “uses Amazon Web Services locations across the globe to house customer data” — a worldwide footprint it attributes, with some irony for a China buyer, to “the risks associated with data crossing jurisdictional boundaries.” None of its public pages names a mainland-China region, a customer-selectable China data location, or a self-hosted deployment of the service. From China’s standpoint, that worldwide AWS footprint does not avoid a cross-border transfer — sending your content into it is one.

Smartling does do something many platforms do not, and it is worth stating fairly: it says it makes “a concerted effort during each Customer’s onboarding and throughout their relationship to segregate personal data and prevent it from entering the Smartling Platform.” That is the right instinct and a genuine data-minimization measure. But read it precisely. It is an effort, not a guarantee; the content corpus — source, translations, translation memory — still resides offshore regardless; the content you most need translated (support tickets, HR and legal documents, medical or financial text) is exactly the content most likely to carry personal information in the first place; and Smartling still “must create and maintain files on each of its customers, including personal information.” The segregation posture reduces the exposure. It does not remove the cross-border leg.

It’s a cross-border data transfer — under PIPL

Where the content goes decides the law. Because Smartling’s platform and content corpus sit outside the mainland, sending a China-origin string — and the personal information inside it — into the platform to be translated is a cross-border transfer of personal information under China’s Personal Information Protection Law. The handler — you, the Smartling customer, not Smartling — owes three things: notice to the individual, a separate consent for the overseas transfer distinct from any general agreement to use your product, and one lawful transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Sending a document abroad to be translated is a cross-border transfer of everything in it.

The content frequently crosses into sensitive territory. Support tickets, HR files, legal and medical text and identity documents routinely contain the categories PIPL Article 28 treats as sensitive personal information — which require a separate consent and a prior personal-information protection impact assessment before the transfer. You cannot strip a contract or a medical record of its substance and still have it translated usefully, so “anonymize it first” is not a general escape here; it has to be done string by string, with judgment about what can be pseudonymized and what simply must not leave.

Then there is residency. For a critical information infrastructure operator or a high-volume handler, personal information generated in China must be stored in China — Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged); PIPL Article 40 carries the parallel duty. A translation memory that persists and grows on worldwide AWS infrastructure is the opposite of in-country storage, and it is not a one-time event you can consent to and forget — every sync adds to it.

Reaching the platform isn’t the question — keeping the content in-country is

The instinct, once the brief is “make Smartling work in China,” is to make the platform sync faster or more reliably from the mainland. For a China audience that is backwards. Pushing more China-origin content through the platform does not cure the problem — it completes, on every sync, the unconsented cross-border transfer and the offshore accumulation the law is concerned with. The compliant direction is the opposite: send less, and keep what must stay.

Concretely, that means minimizing and pseudonymizing personal information in strings before any offshore call — extending Smartling’s own effort to keep personal data out of the platform into a rigorous, enforced step for China-origin content, and keeping sensitive categories out entirely. It means routing the China-origin content that cannot be stripped through a licensed in-country machine-translation or localization alternative, whose data is processed and stored in the mainland on a lawful basis, rather than into the offshore corpus by default. And it means governing who and what handles China content — which linguists, which third-party engines, and the retention and model-training settings — rather than accepting the defaults. Because Smartling’s own pages describe no China region and no self-hosted deployment of the service, the lawful path does not depend on one; it keeps the China leg in-country instead. Localizing here means stopping the offshore export of China content and keeping its translation on an in-country path — never a tunnel that ships the content offshore anyway.

None of this is a ruling that Smartling is banned in China. It is a risk map: which duties actually bite depends on what content you send, what personal or sensitive information it carries, your data volumes, your role under Chinese law, and who your users are — settle the specifics with counsel before a China workflow relies on any of it.

The lawful path — map, localize, deliver

There is a compliant way to localize for a China audience, and it starts by separating the legal question from the technical one.

First, map. Our China compliance team inventories what content actually flows to Smartling — which connectors and projects, which string sources — and charts, for each, what personal, sensitive or confidential information it carries, where Smartling stores and processes it, whether it persists in the translation memory, who handles it (human linguists, contractors, machine engines), whether inputs are retained or used to train models, and where you lack a lawful basis for the cross-border leg. The legal conclusions are settled with your counsel; we build the technical picture that feeds them.

Then localize. We make personal-information minimization and pseudonymization an enforced step before any string leaves — so the content that reaches Smartling is stripped of what should never have crossed the border — keep sensitive categories out entirely, and stand up a licensed, in-country translation path for the China-origin content that must stay in the mainland, its data processed and stored in China. The shape is a compliant in-country pattern, not the same offshore platform pointed at China by another route.

Then deliver. The China-facing site or app that consumes the translations is a public internet service in the mainland, so it needs an ICP filing and compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no re-platform. The result is a localization workflow and a site that run legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind: we keep what must stay in-country, stop what must not leave, and deliver the rest in the open.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Smartling have a data center or region in mainland China?
Not on its own public pages. Smartling states it "uses Amazon Web Services locations across the globe to house customer data" and that its Translation Management System resides at Amazon Web Services; it names no mainland-China region and describes no customer-selectable China data location or self-hosted deployment of the service. Confirm your account's hosting regions with Smartling directly.
Is sending content to Smartling to translate a cross-border data transfer under PIPL?
Yes — sending a document or string abroad to be translated is a cross-border transfer of everything in it. If the content pertains to people in China or comes from a China-facing operation, the personal information inside it leaves China, triggering PIPL Articles 38–40 (notice, separate consent, a transfer mechanism), Article 28 for sensitive categories, and — for a CIIO or high-volume handler — the Cybersecurity Law Article 39 (formerly 37) storage duty on the persisting corpus.
Can we keep using Smartling for China content compliantly?
Often, with the right controls. The lawful lever is to keep China-origin content's translation in-country: minimize and pseudonymize personal information in strings before any offshore call (extending Smartling's own effort to keep personal data out of the platform), keep sensitive categories out entirely, route content that must stay in China through a licensed in-country translation path, and govern who and which engines handle it. 21YunBox maps the exposure and stands up that in-country path plus ICP-filed delivery for the site that consumes the translations — without a rebuild. Settle the specifics with your counsel.

ARTICLES RELATED TO SMARTLING

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.