Does Tealium Work in China? Data Residency, CDP Consent & Cross-Border Transfer
Tealium's tags and collection endpoints are callable from mainland China, so reachability is not the real question. The decision is data residency and consent: Tealium (iQ Tag Management + the AudienceStream CDP) runs no mainland-China region — its documented regions span the US, the EU, and Asia-Pacific — so the identifiers, events, and visitor profiles your China tags collect sit offshore, making that collection a cross-border transfer (数据出境) under PIPL, while the tag-based tracking and profiling itself needs consent, and for a critical information infrastructure operator the Cybersecurity Law's in-country storage duty under Article 39 (formerly Article 37) is one an offshore region cannot meet. A compliance-first look at Tealium's region availability, the data-residency and consent questions, and the lawful path.
Does Tealium work in China?
Yes — Tealium's tags and collection endpoints are callable from mainland China, so the honest answer is that reachability is not the problem. What decides the China question for a customer-data platform is data residency and consent.
Tealium's own documentation lists its regions across the United States, the European Union, and Asia-Pacific — germany, usEast, oregon, sydney, tokyo, and hongKong for the AudienceStream CDP, and San Jose, Ashburn, Dublin, Frankfurt, Tokyo, Singapore, Sydney, and Dubai in its server-side region table — and none is in mainland China. The moment the identifiers, events, and visitor profiles your tags collect from users in China land in an offshore Tealium region, that is a cross-border transfer (数据出境) under PIPL — requiring notice, a separate consent, and a transfer mechanism — and it may be subject to China's data-export security assessment. Separately, the tag-based tracking and profiling a CDP performs needs a lawful basis under PIPL, and for a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) requires China-collected personal information to be stored in China.
21YunBox maps your cross-border, residency, and consent exposure, localizes the China-collected data onto a China-resident CDP and tagging footing (keeping Tealium for your other markets), and delivers your China-facing app in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.
What Tealium's own documentation says about China
| Fact | Primary source |
|---|---|
| Tealium's AudienceStream CDP runs in a fixed set of regions, none in mainland China. Tealium's Moments API region reference lists its available regions as germany, usEast, sydney, oregon, tokyo, and hongKong (plus a custom option) and states: “The region determines which Tealium AudienceStream instance the API calls are made against.” No mainland-China region is listed. | Tealium for Swift SDK Reference, “MomentsAPIRegion Enumeration Reference” (docs.tealium.com), retrieved 2026-10-08 |
| Tealium's documented data-center regions span the US, the EU, Asia-Pacific, and the Middle East — but not mainland China. Tealium's IP allow-list documentation lists its regions by location: San Jose (us-west-1), Oregon (us-west-2), Ashburn (us-east-1), Dublin (eu-west-1), Frankfurt (eu-central-1), Hong Kong (ap-east-1), Tokyo (ap-northeast-1), Singapore (ap-southeast-1), Sydney (ap-southeast-2), and Dubai (me-central-1). None is in mainland China. | Tealium Docs, “IP allow list” (docs.tealium.com), retrieved 2026-10-08 |
| China-collected personal information sent to an offshore Tealium region is a PIPL cross-border transfer. Moving the identifiers, events, and profiles collected from users in mainland China to a Tealium region hosted offshore triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-08 |
| Tag-based tracking and CDP profiling need a lawful basis — consent — under PIPL. PIPL makes consent a primary basis for processing personal information (Article 13) and sets transparency and fairness duties for automated decision-making such as profiling and audience-building (Article 24) — a duty separate from, and additional to, the cross-border-transfer rules. | Personal Information Protection Law of the PRC, Articles 13 and 24 (cac.gov.cn), retrieved 2026-10-08 |
Sources verified by the 21YunBox compliance team on 2026-10-08.
For a team running Tealium behind a China-facing site or app, the first question is usually “will the tags even fire from the mainland?” — and on the wire, they generally do: Tealium’s tags and collection endpoints are callable from China, and it is not a service China blocks outright. So reachability is not where the China decision is won or lost. The decision is about data residency and consent: where the identifiers, events, and visitor profiles Tealium collects actually live, and whether you had a lawful basis to collect and move them.
That is because Tealium — the Customer Data Hub, spanning iQ Tag Management, EventStream, and the AudienceStream CDP — is built to collect first-party user data and concentrate it into unified profiles and audiences. Tealium’s own documentation lists its regions across the United States, the European Union, and Asia-Pacific, but none in mainland China. The moment the personal information your tags collect from users in China lands in an offshore Tealium region, you have made a cross-border transfer (数据出境), and a different body of law decides whether that was lawful — on top of the consent you needed to track those users in the first place.
Tealium in China at a glance
| What decides it | In Tealium's own terms — and China's law |
|---|---|
| What it is | Tealium is a Customer Data Hub — iQ Tag Management (client-side tags), EventStream, and the AudienceStream CDP. It collects first-party identifiers, device IDs, and behavioral events and stitches them into unified visitor profiles and audiences. |
| Is it reachable from the mainland? | Yes. Tealium's tags and collection endpoints are callable from China — it is not a service China blocks outright. Reachability is not the China question. |
| Where do the profiles actually sit? | Offshore. Tealium's documented regions span the US, the EU, and Asia-Pacific — its AudienceStream (CDP) regions are germany, usEast, oregon, sydney, tokyo, and hongKong, and its server-side region table adds San Jose, Ashburn, Dublin, Frankfurt, Singapore, and Dubai. None is in mainland China. (Hong Kong appears, but it is a separate jurisdiction; moving mainland data there is itself a cross-border transfer.) |
| Collecting China users' data into it | A cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. The tag-based tracking and profiling itself also needs a lawful basis — consent — under PIPL (Articles 13, 24); and because a CDP concentrates identity, the exposure is larger, not smaller. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet. |
| The lawful path | Keep the China-collected identifiers, events, and profiles in-country on a China-resident CDP and tagging footing, keep Tealium for your other markets, and deliver the China-facing app in-country on ICP-filed infrastructure. 21YunBox maps, localizes, and delivers; it never uses or suggests circumvention. |
Availability: callable from the mainland — but which region holds your data?
Tealium’s position is set in its own documentation, not by a load-time test. The Customer Data Hub is delivered to the browser and reached over collection endpoints that are callable from the mainland; it is not a service China blocks outright. What its documentation does not offer is a mainland-China home for the data. Tealium’s AudienceStream region reference lists its regions as germany, usEast, sydney, oregon, tokyo, and hongKong (with a custom option for future regions), and its server-side IP allow-list documentation lists them by location — San Jose, Oregon, Ashburn, Dublin, Frankfurt, Hong Kong, Tokyo, Singapore, Sydney, and Dubai. None of them is in mainland China. Hong Kong appears on the list, but it is a separate jurisdiction from the mainland; moving mainland-collected data there is itself a cross-border transfer.
So “do the tags fire in Beijing?” is the wrong test. They fire. The real question is which region holds the identifiers, events, and visitor profiles your China tags build, and whether that data was allowed to leave the country at all. For that reason this page publishes no first-party China latency figure for Tealium: speed is not the axis for a decision that turns on data residency and consent. And to be unambiguous — 21YunBox neither provides nor suggests any form of circumvention; the productive question is how to keep your China customer data on a lawful footing.
The data-residency question: an offshore CDP is a cross-border transfer
Here is the gate most teams miss. A Tealium instance running in any offshore region is, by definition, outside the mainland. The identifiers, device IDs, behavioral events, and stitched visitor profiles it holds for your users in China are personal information. Collecting and storing that data in an offshore Tealium is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, not the platform vendor: Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use your product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
Above certain thresholds, or where the data is “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization duty was renumbered by the 2025 amendment in force since January 1, 2026, with its substance unchanged) requires that personal information collected and generated in China be stored in China — an in-country storage duty that a Tealium region hosted offshore simply cannot satisfy. None of this turns on how fast a tag loads; it turns on whether the data had a lawful basis to be there. Whether, and which of these, apply to your specific deployment is a risk to confirm with counsel against what you actually collect and store.
A customer-data platform concentrates identity — which raises the stakes
A CDP is not one more analytics tag; it is the place everything else feeds into. AudienceStream exists to resolve identifiers across web, app, and offline sources into a single stitched profile, and to turn those profiles into audiences you can act on. That is its value — and, for China data, its exposure. The more completely you centralize a mainland user’s identity and behavior in an offshore platform, the larger and more sensitive the cross-border transfer becomes, and the more a single store concentrates personal information that several of China’s duties attach to at once. A decision that might look minor for one isolated tag is rarely minor for the system that unifies all of them.
Consent: tag-based tracking and profiling is its own duty
Residency is only half of it. Before a single tag fires, the tracking itself needs a lawful basis. A tag manager and CDP exist to collect first-party identifiers and events and build them into profiles and audiences — exactly the kind of tracking and automated profiling PIPL regulates. PIPL makes consent a primary basis for processing personal information (Article 13) and sets transparency and fairness duties for automated decision-making such as profiling (Article 24). This is a separate duty from the cross-border question: even data that never leaves China still needs a lawful basis to be collected and profiled, and the separate consent PIPL requires to move it out is additional to it. Whether consent is required, how it must be worded, and which exemptions apply are questions to settle with counsel against your actual tag and audience configuration.
The lawful path — map, localize, deliver
There is a lawful way to run a customer-data platform for a China-facing product, and it has a shape. First, map: our China team works through your PIPL cross-border exposure, your consent duties, and your data-residency obligations — identifying which identifiers, events, and profiles collected in China must stay in the country, what may lawfully leave, and where a data-export security assessment or an Article 39 storage duty bites. Settle the legal conclusions with counsel; we frame the technical picture that feeds them.
Then localize: stand up a China-resident CDP and tagging footing that keeps the China-collected identifiers, events, and profiles in-country, while you keep Tealium for the markets where it already serves you. 21YunBox integrates that China-resident path in place of the offshore collection, so your China tags stop being the thing that quietly carries personal information — and a whole stitched identity — out of the country.
Then deliver: the China-facing app or site those tags live on is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a China-facing data program that runs legally and compliantly for your users in China. What we do not do, and what no one lawfully can, is hand you a way around China’s data-export rules or around any block: we keep what must stay in China and deliver in front of it in-country, and we never move personal information across the border by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
