Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does UKG Work in China? Employee Data Residency, PIPL Cross-Border & Biometric Time Data

UKG Pro and UKG Ready are reachable from mainland China, so speed is not the question — employee data residency is. UKG is US-headquartered and hosts customer data by product and ordering region across the US, Canada, the EU and Australia (its APAC region) on Google Cloud, with no mainland-China region — so your China employees' HR, payroll, benefits and time-and-attendance records, and the finger- and face-scan templates its timeclocks collect, rest in an offshore UKG tenant: a cross-border transfer of often-sensitive personal information under PIPL. A compliance-first look at the residency, cross-border, sensitive-PI and consent exposure, and the lawful in-country path.

Does UKG work in China?

Yes — UKG Pro and UKG Ready are reachable from mainland China, so the honest answer is that reaching them is not the problem. For a human-capital system the China question is where your employees' records are allowed to live, and whether they had a lawful basis to leave the country.

UKG is US-headquartered and, by its own subprocessor list, hosts customer data by product and ordering region across the USA, Canada, the EU and Australia (its APAC region) on Google Cloud — with no mainland-China region. So the HR, payroll, benefits and scheduling records of your China staff — and the finger- and face-scan templates its timeclocks enroll — come to rest offshore, which makes holding them there a cross-border transfer (数据出境) under PIPL (Articles 38–40: notice, a separate consent, and one transfer mechanism). Payroll, benefits and biometric time data are sensitive personal information (Articles 28–29), carrying a specific-purpose, separate-consent and prior-impact-assessment bar on top. For a critical information infrastructure operator or large-volume handler, personal information generated in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), which no offshore UKG region can meet, and a data-export security assessment may apply first.

21YunBox maps your cross-border, residency, sensitive-PI and consent exposure, localizes the China employee data that must stay onto a China-resident footing (sending UKG only what may lawfully leave), and delivers any China-facing employee surface in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What UKG's own documentation says about China

FactPrimary source
UKG names no mainland-China hosting region. UKG's own third-party subprocessor list sets the hosting location of customer data by the product and the region in which the order is placed, and its "Hosting Provider Location by Customer Region" table lists only the USA, Canada, EMEA (the EU), LATAM and APAC regions — the APAC region for UKG Pro Workforce Management is served from Australia on Google — none of them inside mainland China. Your China employees' records therefore rest in an offshore UKG tenant, which makes holding them there a cross-border transfer of personal information under PIPL (Articles 38–40). UKG — Third-Party Subprocessors (Hosting Provider Location by Customer Region), retrieved 2026-10-09; PIPL Articles 38–40
UKG's timeclocks collect finger and face scans — biometric sensitive PI. UKG's own Device Finger and Face Scan Data Statement describes its Touch ID, Touch ID Plus, TouchFree ID, TouchBase and TimeBase devices enrolling an employee's fingerprint or facial geometry as an encrypted, encoded numeric template held on the device and in the timekeeping database, and places the duty to obtain biometric consent on the employer. Under PIPL, biometric data is sensitive personal information (Articles 28–29), requiring a specific purpose, a separate and specific consent, and a prior impact assessment (Article 55) — layered on top of the consent the cross-border transfer already requires. UKG — Device Finger and Face Scan Data Statement (June 30, 2025), retrieved 2026-10-09; PIPL Articles 28–29, 55
UKG is US-headquartered and transfers personal data across borders. UKG's Data Privacy Framework statement describes its EU group companies transferring personal data to the United States, India and other countries to deliver the services, relying on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses as transfer tools. For personal information collected from employees in mainland China, that offshore handling is itself a cross-border transfer requiring notice, a separate consent and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. UKG — Data Privacy Framework Statement (ukg.com), retrieved 2026-10-09; PIPL Articles 38–40
In-country storage and an ICP filing can both apply. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), which an offshore UKG region cannot satisfy, and moving sensitive employee data across the border can trigger China's data-export security assessment before anything leaves. Any China-facing employee portal actually served from inside the mainland also needs an ICP filing bound to a mainland hosting resource UKG does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-09.

Whether UKG “works” in mainland China is, for a human-capital system, a question of where employee data is allowed to live — and it is settled long before anyone measures how quickly a screen paints. UKG Pro and UKG Ready are the systems of record for a workforce: the personal details, pay, benefits, schedules and time-and-attendance history of every employee, and — on the workforce-management side, in the timeclocks UKG inherited from Kronos — the finger and face scans some of those clocks collect. The applications are reachable from the mainland, so the decision was never whether they load. It is whether the records they hold had a lawful basis to leave China, and where UKG keeps them. UKG is US-headquartered and hosts customer data in regions it sets by product and by where the order was placed — none of them in mainland China — and that geography, not latency, is what China’s law responds to.

UKG's own Subprocessors page (Hosting Provider), showing UKG hosts customer data in the EMEA, LATAM, Canada, APAC and USA regions on Google — with the APAC region served from Australia and no mainland-China region
UKG's own subprocessor list sets where your workforce data rests: “the hosting location of customer data is contingent upon the region where an order is placed and the specific product involved.” Its Hosting Provider table gives the hosting location for each customer region — EMEA, LATAM, Canada, APAC and USA — with the APAC region for UKG Pro Workforce Management served from Australia on Google, and mainland China not among them, so the records of your China employees rest in an offshore UKG tenant. Source: UKG — Subprocessors (Hosting Provider)

UKG in China at a glance

What decides it In UKG's own terms — and China's law
What it is UKG Pro and UKG Ready are the cloud systems of record for your workforce — personal details, compensation, benefits, schedules, and time and attendance. On the workforce-management side, its timeclocks also enroll finger and face scans. It holds a continuous, identifiable record of every employee, much of it sensitive.
Is it reachable from the mainland? Yes. UKG's applications are reachable from China and it is not a service blocked at the border. Reachability is not the China question. (Cross-border access from the mainland to an offshore tenant can be inconsistent — an operational matter, below, not the decision.)
Where do the employee records live? Offshore. UKG is US-headquartered and, by its own subprocessor list, hosts customer data by product and ordering region across the USA, Canada, EMEA (the EU) and APAC — served from Australia — on Google Cloud, with Amazon Web Services for some products. There is no mainland-China region, so China employees' records sit in an offshore UKG tenant.
Putting China employee data into it The records are personal information, much of it sensitive. Holding them in an offshore UKG tenant is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a transfer mechanism, and — where consent is the basis — a separate consent that is hard to treat as freely given at work. Pay, benefits and the timeclock's biometric templates are sensitive personal information (Articles 28–29), adding a specific-purpose, separate-consent and impact-assessment bar.
In-country storage & volume For a critical information infrastructure operator or large-volume handler, personal information generated in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and a CAC data-export security assessment may apply before data leaves — duties an offshore UKG region cannot meet.
The lawful path Keep the China employee data that must stay on a China-resident footing, send UKG only what may lawfully leave, keep UKG for the rest of your workforce, and deliver any China-facing employee surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention.

Reachable — so the real question is where the employee records live

UKG’s applications answer from China, and it is not a service China blocks at the border, so reachability is not where the decision is settled. Residency is. By UKG’s own third-party subprocessor list, where a customer’s data rests depends on the product and the region in which the order was placed, and the regions it enumerates — the USA, Canada, EMEA (the EU), LATAM and APAC — run on Google Cloud, with Amazon Web Services behind some products. The APAC region is served from Australia. Mainland China is not among them. So unless and until that changes, your China employees’ system-of-record data sits in an offshore UKG tenant.

Cross-border access from the mainland to an offshore tenant can be inconsistent, and the temptation is to force it through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. For the same reason this page publishes no first-party China latency figure for UKG: speed is not the axis for a decision that turns on residency and consent. The productive question is where the employee data lives and whether it was allowed to be there.

Employee data in an offshore tenant is a cross-border transfer under PIPL

Here is the gate most HR and payroll teams miss. Collecting personal information from staff in mainland China and keeping it in a UKG tenant hosted abroad is a cross-border transfer (数据出境) of personal information under the Personal Information Protection Law. PIPL puts the duty on the personal-information handler — the employer, not UKG the processor: Articles 38–40 require notice, one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and, where consent is your basis, a separate consent for the overseas transfer.

Employee data makes that consent awkward. PIPL does allow an employer to process staff personal information where it is necessary for human-resources management under a lawfully adopted labor policy (Article 13(2)), so routine HR processing need not always rest on consent. But exporting those records to an offshore UKG tenant is a distinct act that engages the cross-border rules in their own right, and a separate consent is rarely something an employee can give freely to their employer. Recent CAC rules relieve some human-resources transfers of the heaviest assessment route, yet they do not switch off the underlying duties of notice, a lawful basis and a transfer mechanism. And for a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37 — the data-localization provision renumbered by the 2025 amendment that took effect on January 1, 2026, its substance unchanged)) — a duty an offshore UKG region cannot satisfy. Which of these bite your organization is a risk to confirm with counsel against your actual headcount and data.

Payroll — and the timeclock’s finger and face scans — are sensitive PI

The exposure is sharper for UKG than for an ordinary application, because of what it holds. Pay, bonuses, benefits and often bank and health details are sensitive personal information under PIPL (Articles 28–29) — and so is biometric data. UKG’s own Device Finger and Face Scan Data Statement describes its timeclocks — among them the Touch ID, Touch ID Plus, TouchFree ID, TouchBase and TimeBase units — enrolling an employee’s fingerprint or facial geometry as an encrypted, encoded numeric template held on the device and in the timekeeping database, and it places the duty to obtain biometric consent on the employer. Processing sensitive personal information under PIPL demands a specific purpose, a separate and specific consent, and a prior personal-information protection impact assessment (Article 55). In China that biometric consent layers on top of the separate consent the cross-border transfer already requires — and neither is easy to treat as freely given in an employment relationship. Moving sensitive employee data across the border above volume thresholds can additionally trigger China’s data-export security assessment (数据出境安全评估) before anything leaves. None of this turns on how fast a page renders; it turns on whether the data had a lawful basis to be abroad. Because so much of the employee data here is sensitive, treat every line as a risk to settle with counsel before you rely on it.

Picking UKG’s nearest region doesn’t make it in-country

The obvious move is to choose the UKG region closest to China — the Australian APAC region — and call the data localized. But every region UKG offers (the USA, Canada, the EU and APAC in Australia) sits outside mainland China. Moving China employee data from the US region to the APAC region relocates the cross-border transfer; it does not end it. Keeping China-collected employee data in-country means standing up a China-resident footing for the records that must stay, and sending UKG only what may lawfully leave. That split — what must stay and what may go — is a legal question before it is a technical one, and it is the heart of the work.

The lawful path — map, localize, deliver

There is a lawful way to run UKG for a workforce that includes mainland China, and it has a shape. First, map: our China team works through your PIPL exposure — which employee records collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 (formerly Article 37) storage duty bites, and what your notice, consent and impact-assessment flow has to cover for ordinary HR data and for the sensitive and biometric data on top. The legal conclusions are reached with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a China-resident footing for the China employee data that has to stay — a consented, in-country home for those records — while you keep UKG as the system of record for the rest of your workforce, sending it only what may lawfully cross the border.

Then deliver: any China-facing surface of the system — an employee self-service portal, an onboarding page, or a time-clock sign-in actually served to people in the mainland — is a public service there, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. The 21YunBox Optimizer delivers it in-country, in front of what you already run, with no rebuild and no re-platform. The result is a workforce system that runs legally and compliantly for your people in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is UKG available in mainland China?
UKG Pro and UKG Ready are reachable from the mainland — they are not blocked at the border — so availability is not the obstacle. The real question for a workforce that includes China is data residency and consent: UKG hosts customer data by product and ordering region across the USA, Canada, the EU and Australia (its APAC region), with no mainland-China region, so your China employees' records rest offshore. Cross-border access to an offshore tenant can be inconsistent, but that is an operational matter, not the decision — and the answer is never a network workaround. Confirm the specifics with counsel.
Is putting our China employees' data in UKG a cross-border transfer?
If your UKG tenant is hosted anywhere outside the mainland — the US, Canada, the EU or the Australian APAC region — then the HR, payroll, benefits, scheduling and time-and-attendance records it holds for your China staff are stored offshore, a cross-border transfer (数据出境) under PIPL: notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Pay, benefits and the finger- and face-scan templates UKG timeclocks collect are sensitive personal information (Articles 28–29), adding a specific-purpose, separate-consent and prior-impact-assessment duty. A PIPL human-resources-management basis (Article 13(2)) can support day-to-day HR processing, but it does not switch off the cross-border mechanism or the sensitive-PI duties. For a critical information infrastructure operator the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty no offshore region can meet. Settle your exact obligations with counsel.
Can we just choose UKG's APAC region to keep data in China?
No — UKG serves its APAC region from Australia, not mainland China, and every other region it offers (the US, Canada and the EU) is also offshore, so none resolves a China residency duty. Switching from one UKG region to another relocates the cross-border transfer; it does not end it. Keeping China-collected employee data in-country means standing up a China-resident footing for the records that must stay and sending UKG only what may lawfully leave, while you keep UKG as the system of record for the rest of your workforce. 21YunBox maps that split, localizes the in-country data, and delivers any China-facing employee surface on ICP-filed infrastructure — it is never a route around China's data-export rules.

ARTICLES RELATED TO UKG

CATEGORIES

HCM

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.