Does Statsig Work in China? PIPL Cross-Border, Automated Decisions & Data Residency
Statsig's SDK is reachable from China, but the user context and behavioral events you send it are evaluated and stored offshore to decide which flag, experiment, or variant each user sees — a PIPL cross-border transfer and an Article 24 automated decision. A compliance-first look at Statsig's data residency, its warehouse-native in-country option, and the lawful path into China.
Does Statsig work in China?
Statsig's SDK reaches China — but the user attributes and behavior you send it are evaluated on offshore servers to decide which flag, experiment, or variant each person sees, and that decision, not the connection, is where the China exposure sits.
You hand Statsig a user's targeting context (user ID, email, plan, country, IP, device, custom traits) and the exposure and behavioral events that follow; in its default cloud these are processed and stored offshore, under the US-centered data-transfer frameworks Statsig publishes, with no mainland-China region. For China users that is both a PIPL cross-border transfer and an Article 24 automated decision about what each person sees. The lawful lever is to keep the flag-evaluation and user data in-country — run Statsig's Warehouse Native deployment on a mainland-region warehouse so user-level data stays in your warehouse, or use a licensed domestic alternative, minimize the context you evaluate on, and honor the Article 24 right to refuse profiling — not to make the offshore SDK reachable.
Which duty bites first depends on what you send, how much, and to whom — a risk map to settle with counsel. Our China team can map your exposure →
What Statsig's own documentation says about China
| Fact | Primary source |
|---|---|
| Statsig's Warehouse Native deployment keeps user-level data in your own warehouse. Statsig's documentation states that "with Statsig Warehouse Native, user-level data stays in your warehouse" — it "reads it directly from your source of truth without copying it or moving it out," writing only to "a staging environment you control" and consuming small aggregates. Running it on a mainland-China-region warehouse (Snowflake, BigQuery, Redshift, or Databricks) is the honest in-country lever; the default Statsig cloud, by contrast, evaluates and stores the data offshore. | Statsig Docs — Warehouse Native, Data Privacy, retrieved 2026-10-10 |
| Statsig's default cloud processes data offshore, under US-centered transfer frameworks, with no mainland-China region. Statsig's security documentation states that "for cross-border data transfers, Statsig complies with the EU-US Data Privacy Framework, the UK Extension to the EU-US Data Privacy Framework, and the Swiss-US Data Privacy Framework," uses "AES-256 encryption at rest and TLS 1.2 or higher in transit," and "maintains a SOC 2 Type II certification" — all US/EU-anchored, none in mainland China. (Statsig agreed in September 2025 to be acquired by OpenAI and continues to operate its platform.) | Statsig Docs — AI Governance, Security & Privacy, retrieved 2026-10-10 |
| Evaluating a China user's flag offshore is both a cross-border transfer and an automated decision under PIPL. Sending a user's identifiers and behavior out of the mainland is a cross-border transfer of personal information (数据出境) requiring notice, a separate consent, and a transfer mechanism (PIPL Articles 38–40). Deciding what each user sees from their attributes or profile is automated decision-making under PIPL Article 24, which requires transparency, a way to refuse, and — for profiling-based decisions — an option not targeted to the individual's characteristics. | PIPL Articles 38–40 (cross-border) and Article 24 (automated decision-making) |
| A CIIO or high-volume handler owes in-country storage, and the China app needs an ICP filing. Personal information collected in China must be stored in China for a critical information infrastructure operator or high-volume handler under the Cybersecurity Law Article 39 (formerly Article 37 — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article, substance unchanged). Separately, the public mainland app that runs the flags carries an ICP filing (备案) duty and needs compliant, in-country delivery. | Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292 (ICP filing) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a product running feature flags, experiments, or analytics on users in mainland China, the question about Statsig is rarely whether its SDK can be reached — it can. What decides it is what happens to the data you hand it: the targeting context that identifies each user (user ID, email, plan, IP, device, custom attributes) and the exposure and behavioral events that stream back. In Statsig’s default cloud, that context and those events are evaluated and stored on its offshore servers to decide which flag is on, which experiment variant a person gets, and which audience they belong to. Three duties follow for a China-facing team: a PIPL cross-border transfer of that personal information (Articles 38–40, 数据出境), an Article 24 automated decision about what each user sees, and consent for behavioral tracking (Articles 13/23) — plus in-country storage where a high-volume handler or critical information infrastructure operator is involved.
Statsig in China at a glance
| What decides it | In Statsig's own terms — and China's law |
|---|---|
| What you send Statsig | A user object for every flag or experiment — a user ID, and often email, plan or tier, country, IP, device, and custom attributes — plus the exposure and behavioral events that flow back. Each field is personal information once the user is a person in mainland China. |
| Where it's evaluated and stored | Offshore. In its default cloud, Statsig evaluates that context and retains the events on its own servers; for cross-border transfers it publicly “complies with the EU-US Data Privacy Framework,” the “UK Extension,” and the “Swiss-US Data Privacy Framework” — US-centered, with no mainland-China region. Sending China-collected data there is a cross-border transfer (数据出境) under PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism. |
| It decides what each user sees | A flag, an experiment variant, or an analytics-driven audience is a decision about what each user experiences, made from their attributes or profile — automated decision-making under PIPL Article 24. That requires transparency and fairness, a way to refuse, and, where the decision is by profiling, an option not targeted to the individual's personal characteristics. |
| Consent, retention & residency | Behavioral capture needs a lawful basis and consent (PIPL Articles 13/23), not a buried “by using this product…”. A critical information infrastructure operator or high-volume handler also owes an in-country storage duty — Cybersecurity Law Article 39 (formerly Article 37) — which an offshore experiment and analytics store cannot meet. Statsig's product-analytics side builds a growing offshore behavioral record. |
| The lawful path | Reachability is not the axis. Keep flag evaluation and user data in-country — run Statsig's Warehouse Native deployment on a mainland-region warehouse so user-level data stays in your warehouse, or use a licensed domestic alternative — minimize and pseudonymize the context you evaluate on, honor the Article 24 opt-out, and deliver the triggering app in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; licensing and legal calls sit with your counsel. |
What you actually send — your users’ attributes and behavior
A flag or experiment call is not a page to render; it is a judgment about a person. To evaluate a gate, a dynamic config, or an experiment, a Statsig SDK takes a user object — commonly a user ID, and often email, a plan or tier, country, IP, app version, device, and whatever custom attributes you attach — because those attributes are exactly what the targeting rules test. Statsig’s client SDKs send that context to Statsig to be evaluated and to record an exposure; server SDKs can evaluate rules inside your own process after downloading the rule set, but the exposure and event telemetry still stream back. In Statsig’s default cloud, those exposures, custom events, and the user context behind them are processed and retained on Statsig’s offshore infrastructure — the same store that powers its product-analytics side. Each of those fields is personal information once the user is a person in mainland China, and together they form a behavioral record of what that user did and what you decided to show them.
Statsig itself agreed in September 2025 to be acquired by OpenAI and continues to operate its platform; the point for a China-facing team is unchanged, because that store still sits offshore. Statsig’s security documentation says that for cross-border data transfers it “complies with the EU-US Data Privacy Framework,” the “UK Extension to the EU-US Data Privacy Framework,” and the “Swiss-US Data Privacy Framework,” protects data with “AES-256 encryption at rest and TLS 1.2 or higher in transit,” and “maintains a SOC 2 Type II certification.” Those commitments are US- and EU-anchored; none of them places a data region in mainland China.
It’s a cross-border transfer — and an automated decision — under PIPL
Two rules bite at once. First, the moment you evaluate a China user’s flag or log their exposure in Statsig’s cloud, you move that user’s identifiers and behavior out of the mainland to offshore servers. Under China’s Personal Information Protection Law that is a cross-border transfer of personal information (数据出境), and the duty sits on you, the handler — not on Statsig. Articles 38–40 require notice, a separate consent distinct from any general terms, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where important data is involved, China’s data-export security assessment (数据出境安全评估) may have to clear before anything leaves.
Second — and this is the prong most experimentation teams miss — deciding which feature, variant, or experience each user receives from their attributes or profile is automated decision-making under PIPL Article 24. A targeted rollout, an experiment on a cohort, or analytics-driven personalization is profiling, and Article 24 demands transparency and fairness, a way for the individual to refuse, and — where a decision is made through profiling — an option that is not based on their personal characteristics. A buried “by using this product…” does not satisfy the Article 13/23 consent that behavioral capture also requires. And if your organization is a critical information infrastructure operator or a high-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization article was renumbered by the 2025 amendment, in force since January 1, 2026, with its substance unchanged) requires that personal information collected in China be stored in China, which an offshore experiment and analytics store cannot satisfy. None of this turns on how fast the SDK answers.
Reaching the SDK isn’t the question — keeping the decisioning in-country is
So “can we call Statsig from China?” is the wrong test; it answers. The useful question is how to run flags, experiments, and analytics for your mainland users while keeping the decisioning and the user data on a lawful, in-country footing — and Statsig itself offers the lever. Its Warehouse Native deployment runs the experiment and analytics computation on top of your own data warehouse — Snowflake, BigQuery, Redshift, or Databricks — so that, in Statsig’s words, user-level data stays in your warehouse and Statsig reads it in place “without copying it or moving it out,” writing only to a staging environment you control and consuming small aggregates. Point that warehouse at a mainland-China region and the user-level records and the computation stay in-country; send Statsig only minimized, aggregated, non-identifying data. Where even that is more than you want to export, route China users through a licensed in-country experimentation or analytics path instead.
Pair either route with the least identifying context you can evaluate on — avoid raw identifiers — the Article 13/23 consent, and the Article 24 right to refuse profiling. This is a path that keeps the data and the decision in China, not a tunnel that ships them offshore anyway. This is a risk map, not a verdict: which transfer mechanism, storage posture, and consent flow apply to your program depends on what you actually send, how much, and to whom — settle the specifics with counsel before you build.
The lawful path — map, localize, deliver
There is a lawful way to run Statsig for a China-facing product, and it has a shape. First, map: our China team inventories which flags, experiments, and events touch mainland users, what user context and attributes each call carries, where Statsig evaluates and stores them, whether the decision is driven by a profile, and the consent basis behind it — then works through your PIPL cross-border exposure, your Article 24 automated-decision duties, and any Article 39 in-country storage duty. We frame the technical picture; you settle the legal conclusions with counsel.
Then localize: keep flag evaluation and user data on an in-country path — run Statsig’s Warehouse Native deployment on a mainland-region warehouse so the user-level records never leave, or route China users through a licensed domestic alternative — while minimizing and pseudonymizing the context you evaluate on and honoring the Article 24 option not to be profiled. Localizing means keeping the decisioning and the user data in China, never a tunnel that ships them offshore anyway.
Then deliver: the app or site that runs those flags and consumes those decisions is a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery — the 21YunBox Optimizer, in front of the stack you already run, with no rebuild and no re-platform. The result is experimentation and analytics that run legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We are a compliant overlay and partner to Statsig, not a competitor to it.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law (data localization, Article 39)
- China’s data-export security assessment
- How to get an ICP filing for China
