Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Zscaler Work in China? A Licensed China Path, PIPL Cross-Border & Data Residency

Zscaler does run in mainland China — but only through a separate, locally-licensed offering (China Premium Access / Plus) on its Chinese technology partners' network, not the ordinary global cloud, because running traffic inspection in-country is licensed activity a foreign vendor cannot freely perform. The deeper question is PIPL: a cloud security / SASE platform that inspects and forwards all your users' traffic — and keeps the logs — moves the personal information in it across the border, and Zscaler's own FAQ puts that compliance duty on you, the customer. A compliance-first look at the ICP/licensing, cross-border-transfer and data-residency exposure, and the lawful in-country path.

Does Zscaler work in China?

Yes — but not the way most teams assume, and reachability is not the point. Zscaler does serve mainland China, yet only through a separate, locally-licensed offering on its Chinese technology partners' network — not the ordinary global cloud — and the real question is the personal information a traffic-inspection platform moves across the border.

By Zscaler's own China compliance FAQ, “China Premium Access is based on our Chinese technology partners’ IP backbone,” those partners “registered on Zscaler’s behalf all IP addresses assigned to the China Premium Access service under China’s Internet Content Provider (ICP) scheme,” and “have obtained the ICP licenses on our behalf” — because running traffic inspection inside the mainland is licensed activity a foreign vendor cannot freely perform. A cloud security / SASE platform inspects and forwards all of your users' traffic and keeps the logs, so the personal information in it is a cross-border transfer under PIPL (Articles 38–40) whenever it leaves the mainland, with an in-country storage duty under the Cybersecurity Law's Article 39 (formerly Article 37) for a CIIO or large-volume handler. Zscaler says it “complies with the China Personal Information Protection Law (PIPL),” yet “it is ultimately the responsibility of the end user customer to ensure their own compliance.”

21YunBox maps your cross-border, ICP-licensing and data-residency exposure, keeps the regulated China traffic and its logs on a lawful in-country footing, and delivers your China-facing stack in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Zscaler's own documentation says about China

FactPrimary source
Zscaler serves mainland China through a separate, locally-licensed offering — not its ordinary global cloud. Its own China compliance FAQ states that “China Premium Access is based on our Chinese technology partners’ IP backbone,” and that “our technology partners have registered on Zscaler’s behalf all IP addresses assigned to the China Premium Access service under China’s Internet Content Provider (ICP) scheme.” The in-country path is a purchased, deliberately provisioned arrangement, not the global cloud your other regions run on. Zscaler — “Zscaler and China Compliance” FAQ (zscaler.com), last updated 2026-06-18, retrieved 2026-10-09
Running traffic inspection inside the mainland is licensed activity — Zscaler relies on local partners to hold the licenses. The FAQ says its Chinese partners “have obtained the ICP licenses on our behalf” and “have made the necessary filings with MIIT for Zscaler’s clouds that allow them to be used in China,” and that Zscaler “uses data centres providers in China who hold MLPS certifications.” A foreign security vendor cannot freely operate this infrastructure on its own; the licensing is a feature of how any lawful in-country path is built. Zscaler — “Zscaler and China Compliance” FAQ (zscaler.com), retrieved 2026-10-09
Any cross-border link is gated to licensed Chinese carriers. For China Premium Access Plus, the FAQ states “the cross-border link is only provided by the three main Chinese telecom companies that possess the ICP A14-4 license needed to provide this service,” registered by Zscaler's China partner on the customer's behalf — and that this license “is not required for China Premium Access as there is no cross-border link to be registered.” Zscaler — “Zscaler and China Compliance” FAQ (zscaler.com), retrieved 2026-10-09
Zscaler complies with PIPL for its own role — but the compliance duty for your deployment stays with you. The FAQ states Zscaler “complies with the China Personal Information Protection Law (PIPL)” and reports a Ministry of Public Security network-security product testing certificate under the Cybersecurity Law, yet “it is ultimately the responsibility of the end user customer to ensure their own compliance with all applicable Chinese laws and regulations when using the Zscaler Services.” Because the platform inspects and logs all of your users' traffic, the personal information in it is a cross-border transfer under PIPL (Articles 38–40) whenever it leaves the mainland, with an in-country storage duty under the Cybersecurity Law's Article 39 (formerly Article 37) for a CIIO or large-volume handler. Zscaler — “Zscaler and China Compliance” FAQ (zscaler.com), retrieved 2026-10-09; PIPL Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37)

Sources verified by the 21YunBox compliance team on 2026-10-09.

Whether Zscaler “works” in mainland China is a licensing and data-protection question long before it is a speed one. Zscaler is a cloud security / SASE platform — Zscaler Internet Access and Zscaler Private Access — that sits in the path of your users’ traffic, routing and inspecting all of it through its cloud to apply policy. That design is exactly what turns China into a compliance question rather than a reachability one: a platform that inspects and forwards everything your people send, and keeps the logs, is handling their personal information, and China’s law cares a great deal about where that handling happens and where the records come to rest. Zscaler does serve the mainland — but through a separate, locally-licensed arrangement, not the global cloud you already run — and it says so in its own words.

Zscaler's 'Zscaler and China Compliance' FAQ (last updated June 18, 2026), stating that China Premium Access is based on its Chinese technology partners' IP backbone, that the partners registered the service's IP addresses under China's ICP scheme and obtained the ICP licenses on Zscaler's behalf, and that it is ultimately the end-user customer's responsibility to ensure their own compliance with Chinese law
Zscaler's own China compliance FAQ describes a separate, locally-licensed path — not the ordinary global cloud. It states that “China Premium Access is based on our Chinese technology partners’ IP backbone,” that “our technology partners have registered on Zscaler’s behalf all IP addresses assigned to the China Premium Access service under China’s Internet Content Provider (ICP) scheme,” and that “it is ultimately the responsibility of the end user customer to ensure their own compliance with all applicable Chinese laws and regulations when using the Zscaler Services.” Source: Zscaler — Zscaler and China Compliance FAQ

Zscaler in China at a glance

What decides it In Zscaler's own terms — and China's law
What it is A cloud security / SASE platform (Zscaler Internet Access and Zscaler Private Access). It sits in the path of your users' traffic, routing and inspecting all of it through its cloud and keeping the logs — so that traffic and those logs, not a web page's load time, are the compliance surface in China.
Is it reachable from the mainland? Not the deciding question. Zscaler is not simply blocked at the border; it serves China through a separate, purchased offering — China Premium Access and China Premium Access Plus — that, in its own FAQ, runs on “our Chinese technology partners’ IP backbone.” The ordinary global cloud has no mainland node you can lawfully route China users' full traffic to by default.
Who operates it in-country Zscaler's Chinese technology partners. They “registered on Zscaler’s behalf all IP addresses assigned to the China Premium Access service under China’s Internet Content Provider (ICP) scheme” and “have obtained the ICP licenses on our behalf,” and Zscaler “uses data centres providers in China who hold MLPS certifications.” Running inspection infrastructure in the mainland is licensed activity.
The cross-border link For China Premium Access Plus, “the cross-border link is only provided by the three main Chinese telecom companies that possess the ICP A14-4 license needed to provide this service,” registered by Zscaler's China partner on the customer's behalf. Base China Premium Access has no such link to register.
Where your users' data sits The traffic Zscaler inspects and the logs it keeps are personal information. Held or routed outside the mainland, that is a cross-border transfer under PIPL (Articles 38–40); for a critical information infrastructure operator or large-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires in-country storage an offshore log store cannot meet.
Who owes compliance Zscaler says it “complies with the China Personal Information Protection Law (PIPL)” and reports a Ministry of Public Security network-security product testing certificate — but “it is ultimately the responsibility of the end user customer to ensure their own compliance.” The duty is yours.

Reachability isn’t the question — a separate, licensed China path is

The first instinct is to ask whether Zscaler is reachable from Shanghai or Shenzhen, and that is the wrong test. Zscaler is not a service China blocks at the border the way some foreign platforms are; it reaches the mainland through a dedicated offering its documentation calls China Premium Access, with a higher tier, China Premium Access Plus. What matters is that this is not the same thing as the global Zscaler cloud your other regions run on. In Zscaler’s own compliance FAQ, “China Premium Access is based on our Chinese technology partners’ IP backbone,” and the service’s addresses were filed in-country under China’s ICP scheme by those partners.

So “we already run Zscaler everywhere else” does not quietly extend into China. The in-country path is a separate, purchased, locally-licensed arrangement you provision deliberately, and the ordinary global cloud has no mainland node you can lawfully point China users’ full traffic at by default. For that reason this page publishes no China latency or throughput figure for Zscaler: speed is not where the decision is settled, and a number invented for the occasion would only distract from the questions that are.

A platform that inspects all your users’ traffic moves it across the border

Here is the gate most security teams miss. The whole point of a cloud security / SASE platform is that every request your users make is routed through it, inspected, and logged. Those requests — and the logs, which record who went where — are personal information. The moment that inspection happens outside the mainland, or those logs come to rest offshore, you have made a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization whose users are being inspected, not Zscaler the processor: Articles 38–40 require notice, a separate consent distinct from any general IT-use agreement, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Above certain thresholds, or where the traffic carries “important data,” that movement may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — a duty inspection logs held in an offshore region cannot satisfy. None of this turns on how fast a packet clears; it turns on whether the data had a lawful basis to leave. Which of these bite your deployment is a risk to confirm with counsel against what you actually inspect, log and retain.

Running inspection inside the mainland is licensed — which is why Zscaler uses partners

The reason Zscaler reaches China through partners rather than its own global cloud is itself the second door. Operating traffic-inspection and cross-border network infrastructure inside the mainland is licensed activity, and a foreign vendor cannot simply switch it on. Zscaler’s FAQ is candid about the arrangement: its Chinese technology partners “registered on Zscaler’s behalf all IP addresses assigned to the China Premium Access service under China’s Internet Content Provider (ICP) scheme,” those partners “have obtained the ICP licenses on our behalf” and “have made the necessary filings with MIIT for Zscaler’s clouds that allow them to be used in China,” and Zscaler “uses data centres providers in China who hold MLPS certifications.” For the Plus tier’s dedicated cross-border link, it adds that “the cross-border link is only provided by the three main Chinese telecom companies that possess the ICP A14-4 license needed to provide this service.”

Read together, that is a map of how much licensing stands between a global security platform and lawful in-country operation: an ICP filing held by a local entity, MIIT filings for the clouds, MLPS-certified data-center operators, and a carrier-only license for any cross-border link. Zscaler assembles that through partners — but the obligations it leaves to you do not disappear because the plumbing is licensed. Its FAQ says as much: it “complies with the … PIPL,” yet “it is ultimately the responsibility of the end user customer to ensure their own compliance with all applicable Chinese laws and regulations when using the Zscaler Services.”

None of this is a verdict that Zscaler is “blocked” or “illegal” in China — it plainly offers a licensed in-country path, and reports a Ministry of Public Security product-testing certificate under the Cybersecurity Law for its platform. It is a risk map: which obligations bite — a separate consent, a transfer mechanism, a data-export assessment, in-country log storage, who counts as the handler — turns on your entity, the data your users’ traffic carries, your role under Chinese law, and who those users are. It is worth settling with counsel before your China security posture depends on it.

The lawful path — map, localize, deliver

There is a compliant way to secure a China-facing operation, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the inspection and the transfer — identifying which traffic and which logs collected in China carry personal information, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your notice and consent flow must cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we help you put the regulated China traffic and its logs on a lawful in-country footing — licensed in-country operation with the logs and configuration kept in the mainland, the same footing Zscaler’s own China offering is built on — in place of quietly routing China users’ full traffic to the offshore cloud. You keep Zscaler where it already serves your other regions; what changes is that the China-resident pieces stop leaving the country by default.

Then deliver: the China-facing sites and applications your users actually reach are themselves public services in the mainland, so they carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a China-facing operation that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we map what applies, localize what must stay, and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Zscaler available in mainland China?
Yes, but not through the ordinary global cloud. Zscaler serves the mainland through a separate, purchased offering — China Premium Access and China Premium Access Plus — that its own FAQ says runs on “our Chinese technology partners’ IP backbone,” with the service's IP addresses registered under China's ICP scheme by those partners. So availability is a licensing-and-provisioning question, not a simple on/off: the global cloud has no mainland node you can lawfully route China users' full traffic to by default. Confirm the specifics with counsel.
Is routing our China users' traffic through Zscaler a cross-border transfer under PIPL?
If the inspection and the logs sit outside the mainland, then yes. A cloud security / SASE platform inspects and forwards all of your users' traffic and keeps the logs, and that traffic and those logs contain personal information. Moving it out of China is a cross-border transfer under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification — and a high-volume link may trigger China's data-export security assessment. For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty. Zscaler says it complies with PIPL for its own role, but its FAQ puts ultimate compliance on you. Settle your exact obligations with counsel.
Can 21YunBox help make our Zscaler setup compliant in China?
Yes. Our China team maps your exposure — the PIPL cross-border and data-residency obligations that attach to the traffic Zscaler inspects and the logs it keeps, for your entity, data volumes and users — keeps the regulated China traffic and its logs on a lawful in-country footing, and stands up the ICP-filed, in-country delivery your China-facing stack needs, in front of what you already run. We never use or suggest circumvention of any kind. Get in touch to work through your specific case.

ARTICLES RELATED TO ZSCALER

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.