Does Workato Work in China? Data Residency, Cross-Border Automation Data & PIPL
Workato runs a dedicated in-country China data center on AWS China (Ningxia), operated by a local entity with an ICP filing — so China automation data can stay resident. But it's Enterprise-only and isolated from your global tenant, and an iPaaS that moves records across your whole estate makes residency and PIPL cross-border transfer the real test. A compliance-first look at Workato, data residency and PIPL.
Does Workato work in China?
Whether Workato works in China is a data-residency question, not a connectivity one — and the answer turns on which Workato region each recipe runs in.
Workato is an iPaaS whose whole job is to move records between your apps, so a single recipe can carry names, account and order records, HR, payment and ID fields out of a China system. By Workato's own documentation it runs a dedicated in-country China data center "hosted on AWS China (Ningxia) Region and operated by Workato (Beijing) Technology Co., Ltd." under an ICP filing, and automation data there "remains isolated in that specific region and can't be transferred to other regions" — so China data can stay resident if you run it there. But that region is Enterprise-only and walled off from your global tenant; if the recipes touching China data run in your US or EU workspace instead, that movement is a cross-border transfer PIPL governs (notice, separate consent, a transfer mechanism), with an in-country storage duty on top for CIIOs and large-volume handlers.
This is a risk map, not a verdict — your duties turn on your entity, data volumes and who your users are. Our China team can map your Workato exposure →
What Workato's own documentation says about China
| Fact | Primary source |
|---|---|
| Workato operates a dedicated in-country China data center. Its documentation states the China data center is "hosted on AWS China (Ningxia) Region and operated by Workato (Beijing) Technology Co., Ltd." under a Beijing ICP filing (京ICP备2026009801号), "in compliance with local regulatory requirements" — a genuine onshore, ICP-filed region, not an offshore one. | Workato Docs — China data center (retrieved 2026-10-10) |
| The China region is Enterprise-only, isolated and feature-limited. Workato documents that self-service plans "can't choose the region" and "sit in one of Workato's US data centers," that "Workato does not share or transfer customer data across regions," and that the China region omits all AI/Agentic features plus 28 connectors (Gmail, Google Drive, Slack and OpenAI among them). So a global tenant can't absorb China-resident data, and the feature gaps can push teams back to an offshore workspace. | Workato Docs — Supported cloud regions & China data center (retrieved 2026-10-10) |
| Moving China personal information to an offshore Workato region is a cross-border transfer under PIPL. PIPL Articles 38–40 require notice, a separate consent, and a transfer mechanism — a CAC security assessment, the CAC standard contract, or certification; above the regulated thresholds a data-export security assessment may have to clear first. | PIPL Articles 38–40; Measures for the Security Assessment of Data Exports (retrieved 2026-10-10) |
| CIIOs and large-volume handlers must store China personal information in China. Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — with PIPL Article 40 sets an in-country storage duty an offshore region can't meet but Workato's in-country China region can. China-facing surfaces built on Workato also owe an ICP filing. | Cybersecurity Law Art. 39 (formerly Art. 37); PIPL Art. 40; ICP Order 292 / MIIT Order 33 (retrieved 2026-10-10) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
Whether Workato “works” in mainland China is a data-residency question long before it is a connectivity one. Workato is an integration and automation platform (iPaaS) whose entire job is to move records between your systems — so a single recipe can carry names, contact details, account and order records, HR and payroll fields, and payment and identity data from a CRM, ERP or finance app to another. The question is not whether you can open the Workato dashboard from Shanghai; it is where the records your recipes move, and the job history the platform keeps, are allowed to come to rest. Here Workato is unusual: by its own documentation it runs a dedicated in-country China data center, hosted on AWS China (Ningxia) and operated by a China entity with an ICP filing. That changes the picture — but it does not, by itself, make a global Workato tenant compliant.
Workato in China at a glance
| What decides it | In Workato's own terms — and China's law |
|---|---|
| Where the records live | Workato is an iPaaS: the records flowing through your recipes, plus the job history the platform keeps, are the China surface. Workato runs a dedicated in-country China region — hosted on AWS China (Ningxia) and operated by Workato (Beijing) Technology Co., Ltd. under an ICP filing — where automation data "remains isolated in that specific region and can't be transferred to other regions." Every other region (US default, EU, JP, SG, AU, IL, KR, UK) is offshore, and self-service plans "sit in one of Workato's US data centers." |
| What it holds, and why it's personal information | Recipes move records between CRM, ERP, HR, finance, support and messaging systems — names, contacts, account and order records, employee and payroll data, payment and identity fields. That is personal information under PIPL, and because Workato spans the whole estate, a single pipeline can carry Article 28 sensitive personal information (financial accounts, government IDs, location, health). Job history retains traces of what moved. |
| Your China data crossing the border | If the recipes touching China-origin personal information run in an offshore tenant (US default, EU, elsewhere) or on a self-service plan, moving that data out of China is a cross-border transfer under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. A data-export security assessment may apply above the thresholds. |
| In-country storage duty | For a critical information infrastructure operator or a large-volume handler, personal information generated in China must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). Workato's in-country China region can meet this; an offshore region cannot. |
| Reachability is not the axis | You can open Workato from the mainland — that is not the question. Any China-facing surface these automations expose (an API endpoint, a portal, an intake form) is an internet service in China and carries an ICP filing (备案) duty plus in-country delivery; Workato's own docs note API platform custom domains aren't supported in the China region. |
Workato runs an in-country China region — but your global tenant isn’t it
The surprising part first: Workato’s China data center is real and lawful on its own terms. Its documentation states the region is “hosted on AWS China (Ningxia) Region and operated by Workato (Beijing) Technology Co., Ltd. (京ICP备2026009801号), in compliance with local regulatory requirements.” That is a genuine in-country footprint — an onshore cloud region, a China operating entity, and an ICP filing — and the platform keeps the data there resident: automation data, Workato says, “remains isolated in that specific region and can’t be transferred to other regions,” and “Workato does not share or transfer customer data across regions.” If the records your China automations touch live in that region, the in-country storage question is answered in your favor.
The trap is assuming your existing Workato already enjoys that. It does not. Region choice is an Enterprise capability — self-service plans (Free, Pro, Developer Sandbox) “can’t choose the region” and “sit in one of Workato’s US data centers.” And every account is single-region: “Each Workato account is hosted in a single regional data center,” with no cross-region collaboration and no cross-region sharing of recipes or connectors. So your global US or EU Workato tenant is a separate silo from the China region — it cannot absorb China-resident data, and it cannot be made resident after the fact. The moment a recipe in that global tenant ingests personal information from a China system, that movement out of the country is a cross-border transfer under PIPL, no matter that an in-country region exists elsewhere in Workato’s estate.
An iPaaS moves your whole data estate — much of it personal, some of it sensitive
This is the part most teams underestimate. An automation platform exists to move records between systems, and it sits across the whole estate — the CRM, the ERP, the HR and payroll system, the finance and payments stack, the support desk, the messaging tools. Much of what passes through a recipe is personal information: names, contact details, account and order records, employee data, device and user identifiers. And because Workato reaches all of it, a single pipeline can carry Article 28 sensitive personal information — financial-account numbers, government IDs, location, health fields — which PIPL holds to a higher bar: a separate consent, a demonstrated necessity, and a personal-information protection impact assessment. The job history the platform retains keeps traces of what each recipe moved.
So the exposure here is unusually broad. It is not one application’s data that may cross the border; it is whatever your automations touch. Where the account that runs those automations sits is therefore the decision that governs every flow. For an offshore tenant, moving China personal information out becomes a cross-border transfer the moment it leaves, and under the Personal Information Protection Law that duty lands on you, the personal-information handler, not on Workato the processor: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the regulated thresholds, or where the data is “important data,” China’s data-export security assessment (数据出境安全评估) may have to clear before anything leaves.
An in-country region narrows what crosses — it doesn’t decide your duties
Running the China region, choosing where data rests, filtering or redacting fields before a recipe runs — these change what crosses the border and whether it crosses. They do not change the legal analysis you still owe, and they come with traps. Workato’s China region is deliberately feature-limited: by its own documentation, AI and Agentic features (including Model Context Protocol, Copilots, Agent Studio and AIRO) “aren’t available in the China data center,” the Community library “isn’t accessible,” API platform custom domains “aren’t supported,” and its own list names 28 connectors that are unavailable there — Gmail, Google Drive, Slack and OpenAI among them. Teams hit those gaps and are tempted to run the fuller offshore tenant for the China workload, which re-creates the very cross-border transfer the in-country region was meant to avoid. Moving a workload to a “different region” only relocates where the data rests; it does not, on its own, resolve the transfer.
Whether you need the China region at all, whether your transfers require a CAC security assessment, the standard contract or certification, whether the Cybersecurity Law’s Article 39 (formerly Article 37) in-country storage duty binds you as a critical information infrastructure operator, and whether your China-facing surfaces owe an ICP filing — all of it turns on your entity, your data volumes, and who your users are. This is a risk map, not a verdict: map your exposure against what you actually move and store, and settle the specifics with counsel before your automations depend on the answer.
The lawful path — map, localize, deliver
There is a compliant way to run Workato for a China-facing business, and it has a shape. First, map: our China compliance team works through your PIPL exposure recipe by recipe — which automations carry personal information out of China, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty applies, whether the in-country region is required, and what your notice and consent have to cover. We build the technical picture; the legal conclusions are settled with your counsel.
Then localize: we stand up consented, in-country processing and storage for the records that must stay on mainland soil — including running the China-resident automations on Workato’s own in-country China region (or a self-hosted runtime where the tool supports it) so China data stays resident, keeping only what may lawfully leave flowing out, and leaving your global Workato tenant exactly where it already runs for every other market.
Then deliver: the public-facing surfaces these automations expose to users in the mainland — a dashboard, a portal, an intake form, an API — are an internet service in China, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no second codebase. 21YunBox is a compliant overlay, not a migration, and a partner to Workato, not a competitor. 21YunBox never uses or suggests circumvention of any kind. The result is a Workato estate that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
