Skip to main content
PTS Managed Services

PTS Managed Services · China · Hong Kong · Singapore

The China IT navigator for foreign companies

Entering China, acquiring a business there, or untangling an operation that grew on its own? Pick your situation and the navigator shows which laws actually apply, how compliant connectivity works, what runs (and what doesn't) from inside the mainland — and turns your answers into a readiness assessment you can keep as a PDF or send to PTS.

Your situation

Pick your situation, then answer the basics on the Overview tab — the whole navigator tailors itself as you go.

Your situation
Setting up in China
planning or building a first mainland presence
Regimes that apply
6 apply, 2 to watch
see The laws tab
Data leaving China
In scope
check your transfer route — many SMEs are exempt
Connectivity
Licensed routes
circuits or SD-WAN on a licensed underlay — never consumer VPNs
Readiness
0 of 10
confirmed on the checklist tab

Start here

Showing for Setting up in China · data leaves China

China IT is not mysterious — it is specific. Four laws, one connectivity regime and two separate cloud worlds cover almost everything foreign companies get wrong. Answer the basics, then work through the readiness checklist — the whole navigator tailors itself to setting up in china.

Tell us the basics30 seconds — everything below tailors itself as you answer.
People in China
What you run today (select all)
What you're looking to do (select all)
Applies to you
6 regimes
CSL · DSL · PIPL · Regulations · CBDT Provisions · MIIT rules
The big three data laws
CSL · DSL · PIPL
operationalised since 1 Jan 2025 by the Network Data Security Management Regulations
Transfer rules
Check your band
under 100k non-sensitive individuals and routine HR data are exempt
Tooling reality
Two cloud worlds
global vs China-operated (21Vianet, Sinnet/NWCD) — Google effectively unavailable
Setting up

Decide three things before anyone signs a lease: your tenant strategy (global M365 on licensed connectivity vs a 21Vianet tenant), your connectivity route (circuits or SD-WAN, ordered early — provisioning takes weeks), and whether anything will be hosted in the mainland (which triggers ICP and MLPS). Getting these right on day one costs a fraction of retrofitting them.

Next: the readiness checklist →

How PTS helps

PTS has run China IT for foreign companies for over two decades, with our own registered mainland entity, engineers in Shanghai, and delivery across Hong Kong and Singapore — see IT for foreign companies in China & HK.

A grounded start for setting up in china

  • A China IT readiness assessment against everything in this navigator — connectivity, tenancy, filings, data flows — with a prioritised plan
  • Licensed connectivity designed and procured: IPLC/IEPL, MPLS or SD-WAN through our carrier relationships
  • Tenant strategy and migration: global, 21Vianet or hybrid — decided on facts, then delivered
  • On-the-ground engineers through PTS's registered China entity, from Shanghai outwards

Your readiness checklist

Showing for Setting up in China · data leaves China

Answer from what you actually know — "Not sure" is a perfectly good answer and usually the honest one for a China operation. Your answers build the assessment on the next tab and stay in this browser unless you send them.

Connectivity

Your China–HQ connectivity runs on licensed circuits or SD-WAN from a licensed provider — not consumer VPN appsWhy it mattersUnlicensed routes fail without notice and put core traffic outside any guarantee
People in China can actually use the systems they need at usable speed (tested, not assumed)Why it matters"It works from HQ" is the most common false assumption in China IT

Data

You know what personal data about people in China you hold, and every system it flows to outside the mainlandWhy it mattersEvery PIPL obligation starts from this map
You've confirmed which transfer route applies — exemption, SCC filing or CAC assessment — and filed where neededWhy it mattersUnder 100k non-sensitive individuals and HR data are often exempt; someone still has to establish that
Your China-facing privacy notices and consents meet PIPL — including separate consent where data leaves ChinaWhy it mattersPIPL is consent-centric and fines reach 5% of turnover
A designated China representative or institution is in place and reported to the authoritiesWhy it mattersRequired for foreign companies in PIPL's reach — the 2025 regulations made it concrete

Systems

Your tenant strategy is a deliberate decision — global tenant on licensed connectivity, 21Vianet, or a hybrid — not an accidentWhy it mattersRetro-fitting a tenant split is far more painful than choosing one
Software in the China operation is genuinely licensed — no inherited pirated Windows, Office or CADWhy it mattersA standard acquired-business surprise, and an easy enforcement target

Operations

Someone can physically reach your China site — trusted local hands for the day the router diesWhy it mattersRemote-only support ends at the first hardware failure or chop-stamped delivery
You know how a China security incident gets reported — internally and to authorities, within the 24-hour windows that can applyWhy it mattersThe 2025 regulations put hard clocks on serious incidents

See your readiness assessment →

Your China IT readiness assessment

Showing for Setting up in China · data leaves China

Setting up in China · None yet staff in China · running Not sure · no goals selected yet

Confirmed
0 of 10
nothing answered yet — the checklist tab takes two minutes
Position
Not yet assessed
answer the checklist to see where you stand
Worth checking
10
answered "not sure" — the first things a readiness check confirms

What you'll likely need

Built from the shape of your business and your goals — each item says why it's there. This is a starting scope, not a quote: PTS validates it in the free readiness check.

China office network build

Cabling, firewall, Wi-Fi and local breakout engineered for the mainland — delivered by engineers on the ground.

Because you told us: a first mainland presence usually starts with the office build.

HQ integration & data-flow design

Which systems bridge, which stay local, and the transfer mechanics that keep the data flows in the light bands.

Because you told us: personal data already flows to systems outside the mainland.

Opens your browser's print dialog — choose "Save as PDF". Includes your situation, the regimes that apply, your readiness picture and likely needs. Nothing is sent to PTS unless you submit below.

Get your China IT readiness check — free, engineer-led

Send this to PTS and within two business days we'll come back to arrange a free readiness conversation with an engineer who works on China estates every week — then a costed, prioritised plan. Your situation and answers are attached automatically.

Free readiness conversation · Costed plan · No obligation · Goes to our inbox, not a database

The laws, in plain English

Showing for Setting up in China · data leaves China

Everything below is a real obligation with a real enforcement history — but almost all of it is manageable for an SME once someone owns it. Marked applies or watch for your situation. For the deeper legal picture see our guide to China & Hong Kong data laws.

Applies to your situation

CSL · 2017applies

Cybersecurity Law

The foundation. Anyone operating networks or systems in China is a "network operator" with baseline security duties: protection measures, real-name requirements where applicable, incident response and cooperation with regulators. It also created the critical information infrastructure (CIIO) category — stricter localisation and review duties that most foreign SMEs will not trigger, but the concepts flow down through everything below.

DSL · 2021applies

Data Security Law

Applies to all data, not just personal data. Requires classification (the 2025 regulations formalise ordinary / important / core tiers), security management by data category, and government approval before providing data stored in China to foreign judicial or law-enforcement authorities — a clause every multinational's legal team should know exists before a discovery request arrives.

PIPL · 2021applies

Personal Information Protection Law

China's GDPR-equivalent, with teeth: up to RMB 50 million or 5% of the previous year's turnover. Consent-centric (with separate consent for cross-border transfers and sensitive data), extraterritorial — it reaches foreign companies with no China entity that sell into China or analyse people in China — and the legal hook for the transfer mechanisms below.

Regulations · eff. 1 Jan 2025applies

Network Data Security Management Regulations

The State Council regulations that operationalise CSL, DSL and PIPL from 1 January 2025: tiered data classification, security self-assessments, incident response with 24-hour reporting duties in serious cases, annual reports for important-data processors — and, for foreign companies in scope of PIPL's extraterritorial reach, a mandatory designated institution or representative in China, reported to the local cyberspace administration.

CBDT Provisions · Mar 2024, clarified 2025applies

Cross-border data transfer mechanisms

Three mechanisms — CAC security assessment, Chinese standard contractual clauses (SCC filing), or certification — with 2024 relaxations that exempt most SMEs: under 100,000 individuals' non-sensitive personal information (cumulative from 1 January) needs no mechanism at all, and employee data needed for HR management is exempt regardless of volume. SCC filing covers 100,000–1 million individuals (or under 10,000 sensitive); the CAC assessment bites at 1 million+, 10,000+ sensitive, any "important data", and always for CIIOs. Free trade zones run their own negative lists that can relax this further.

MIIT rules · 2017 circularapplies

Cross-border connectivity rules

Cross-border corporate connectivity must run on channels from licensed carriers — international private leased circuits (IPLC/IEPL), MPLS, or SD-WAN over a licensed underlay — with the circuits registered to your entity and used for internal business only. Consumer VPN apps are not a compliance strategy: they are routinely disrupted, contractually fragile and put the traffic your China business depends on outside any service guarantee.

Worth watching

MLPS 2.0 · since 2019watch

Multi-Level Protection Scheme

China's mandatory security grading for systems run in the mainland. You self-classify each system Level 1–5; Level 2 and above is filed with the public security bureau, and Level 3+ needs annual expert assessment. A typical foreign SME's China ERP or file server lands at Level 2. If you host nothing in the mainland it usually stays theoretical — until you acquire a company that should have filed and never did.

PIPL art. 53 · 2025 Regulationswatch

China representative requirement

A foreign company caught by PIPL's extraterritorial reach — selling into China or analysing people in China without a mainland entity — must designate a dedicated institution or representative in China and report their contact details to the municipal cyberspace administration. It is the piece remote-first companies most often discover late.

How PTS helps

Turning law into a worklist

  • A data map of what China personal data you hold and where it flows — the input every obligation shares
  • The filings done: MLPS grading, ICP, representative registration, SCC filing where your numbers require it
  • Working with your counsel, not replacing them — we bring the systems reality, they bring the legal call

Connectivity: the part everyone feels first

Showing for Setting up in China · data leaves China

The Great Firewall is not a rumour; it is a daily performance characteristic. The question is never "how do we get around it" — it is "which licensed route fits our size and systems". These are the four realistic options.

Casual, non-critical use

Public internet + patience

  • Free, instant — and unpredictable: cross-border traffic transits the Great Firewall with high latency, packet loss and outright blocks
  • Global SaaS (Google, many Western tools) ranges from degraded to unreachable
  • Acceptable for browsing and low-stakes email; not for ERP, VoIP, file servers or anything the business depends on
Site-to-site links the business depends on

IPLC / IEPL leased lines

  • Dedicated licensed circuits between your China office and HK/SG/HQ — predictable latency, no firewall transit for the private traffic
  • Provisioning takes weeks and is priced per bandwidth; registered to your entity for internal use
  • The classic backbone for ERP, file services and voice between China and the region
Multi-site, cloud-heavy estates

SD-WAN on a licensed underlay

  • Managed overlay from licensed providers combining local internet breakout in China with compliant cross-border transit
  • Faster to deploy and more flexible than point-to-point circuits; quality depends entirely on the underlay being licensed and well-peered
  • The usual modern answer for a China office that needs global M365/cloud plus local speed
Improving reach without full circuits

Premium transit (e.g. CN2) via HK

  • Hosting or relaying in Hong Kong on premium China-facing routes improves mainland reachability without ICP obligations
  • No guarantees — still public-internet class — but often the pragmatic middle step while an entity or circuits are being set up
What not to do

Consumer VPN apps as business infrastructure. They are periodically disrupted, carry no service guarantee, and an operation that depends on one has an outage — and a finding — waiting to happen. If you have just acquired a company and this is how it reaches HQ, treat it as the first thing to replace.

How PTS helps

Connectivity, delivered

  • Route selection and sizing against your actual traffic — not the biggest circuit a carrier will sell you
  • Procurement and provisioning through licensed carriers in China, HK and Singapore, managed end to end
  • SD-WAN designs that give China staff fast local breakout AND compliant access to global systems
  • Ongoing monitoring, because cross-border quality is a moving target

Getting data out of China

Showing for Setting up in China · data leaves China

The 2024 rules turned this from a wall into a set of doors — most foreign SMEs walk through an exempt one. What matters is knowing which door you're at, because the thresholds are cumulative and someone has to keep count.

Your volume (cumulative since 1 Jan)MechanismIn practice
Employee data for HR managementExempt — any volumeGlobal HR, payroll and travel systems are workable; keep notices and records clean
Under 100,000 individuals (non-sensitive)ExemptNo filing — but you need the data map that proves you're under it
100,000 – 1 million individuals, or under 10,000 sensitiveChinese SCCs filed, or certificationA contract-and-filing exercise; weeks, not months, when the data map exists
1 million+ individuals, 10,000+ sensitive, any "important data", or CIIOCAC security assessmentThe heavy path — months, counsel-led; most SMEs never reach it
Free trade zones can lighten this further

Shanghai, Beijing, Tianjin and other FTZs publish their own negative lists — data outside the list moves without a mechanism for entities registered there. If your China entity sits in an FTZ, check its list before building process around the national thresholds.

How PTS helps

Making the exempt path real

  • The data map and counting that the exemptions quietly assume you have
  • System-level fixes that keep you in the light bands — minimising what leaves China at all
  • SCC filing support alongside your counsel when your numbers require it

Your stack: what works from inside China

Showing for Setting up in China · data leaves China

Two separate cloud worlds, one blocked ecosystem, and a lot of nuance. Observed reality as at 26 August 2026 — statuses shift, so treat "Degraded" and "Mixed" as "test before you commit".

ServiceFrom the mainlandWhat it means
Microsoft 365 (global tenant)DegradedReachable but slow/unstable over public internet; workable with licensed connectivity. Copilot and some services depend on endpoints that suffer most.
Microsoft 365 (21Vianet)WorksSeparate China cloud run by 21Vianet: fast and lawful locally, but a distinct tenant — separate identities, no Copilot or Autopilot, thinner feature set, and no simple federation with your global tenant.
Google Workspace / GmailBlockedGoogle services have been blocked for years. A China operation cannot run on Workspace without routing every user over cross-border circuits — plan a Microsoft or local stack for mainland staff instead.
AWS (global regions)DegradedConsoles and APIs reachable but slow; latency to ap-east-1 (HK) is the usual compromise for serving China users without ICP.
AWS China (Beijing/Ningxia)WorksPhysically separate regions run by Sinnet (Beijing) and NWCD (Ningxia). Separate account, Chinese business licence required, ICP filing per region for anything public-facing.
Azure / Dynamics (21Vianet China regions)WorksSame pattern as M365 China: local, lawful, separate subscription and feature cadence.
Teams / Zoom / SlackMixedTeams (global) is usable on good connectivity; Zoom works via its China arrangements for licensed use; Slack is unreliable. For all-hands with mainland staff, test before you commit.
WeCom / DingTalk / FeishuWorksThe local collaboration stacks. Many acquired businesses live on WeCom or DingTalk — plan integration or coexistence rather than assuming a rip-and-replace.

The Microsoft 365 decision

Global tenant + licensed connectivity

One identity, one tenant, Copilot and the full feature set — China staff reach it over circuits or SD-WAN. The default answer for most foreign SMEs, and the one that keeps collaboration simple.

21Vianet China tenant

Fast and local with no cross-border dependency — but a separate world: separate accounts, no Copilot or Autopilot, thinner features, and awkward federation with your global tenant. Right when China headcount is large, data must stay local, or connectivity budgets don't stretch.

The full trade-off, costs and migration paths are in our decision guide: Microsoft 365 in China — global vs 21Vianet.

How PTS helps

Stack decisions, made and delivered

  • Tenant strategy on facts: usage, headcount, data constraints and budget — then the migration itself
  • AWS/Azure China builds through the operator accounts, with the ICP filings that public-facing workloads need
  • Coexistence with WeCom or DingTalk where the local business already lives there

Acquiring a Chinese business: the IT you inherit

Showing for Setting up in China · data leaves China

At completion you own their decisions — and their liabilities. These are the six findings we meet most often in acquired mainland businesses, in the order they usually hurt.

1 · Access

Admin control held personally

Domains, servers, WeCom/WeChat official accounts and banking USB-keys registered to the founder or a departed IT person. Day-zero task: enumerate and take control of every credential and registration, before relationships cool.

2 · Connectivity

The consumer-VPN "solution"

HQ access that depends on a personal VPN subscription. Replace with licensed circuits or SD-WAN before you standardise anything on it.

3 · Filings

ICP and MLPS gaps

Websites on someone else's ICP filing, systems never MLPS-graded. Quiet until an inspection, a takedown or an incident makes them loud.

4 · Licensing

Unlicensed software

Pirated Windows, Office and CAD remain common in acquired SMEs — an easy enforcement target and an integration blocker. Budget for true-up early.

5 · Data

Liabilities that transferred with the shares

Customer databases collected without PIPL-grade consent, data flowing abroad with no mechanism, no processing records. Your exposure now — map it before you integrate it.

6 · Shadow ops

The business runs on personal WeChat

Orders, approvals and customer relationships in personal chat histories. Move it to controlled WeCom/company channels with care — it is where the revenue lives.

How PTS helps

This is the same discipline behind our private equity IT & M&A due-diligence practice, applied to mainland targets.

Diligence through integration

  • Pre-deal IT due diligence on mainland targets through our China entity — see IT & M&A due diligence for private equity
  • The first-100-days plan: admin control, connectivity, licensing true-up, filings, then tenant integration
  • On-the-ground execution in China rather than instructions emailed from HQ

The questions we're actually asked

Short, factual answers to the confusions that fill our inbox — from companies entering China and companies that just bought one.

Can our China office just use our global Microsoft 365 tenant?

Often yes — that is the most common setup for foreign SMEs — but only with proper connectivity. Over the public internet the experience ranges from sluggish to unusable; over licensed circuits or a good SD-WAN it works well. The alternative is a separate 21Vianet tenant: fast and local, but separate identities, no Copilot, and real friction collaborating with your global tenant. It's a genuine architecture decision — our guide to Microsoft 365 in China walks through it.

Is it legal to use a VPN for our China office?

Corporate cross-border connectivity is legal when it runs on channels from licensed carriers — leased circuits, MPLS, or SD-WAN over a licensed underlay, registered to your entity for internal use. Consumer VPN apps are a different matter: periodically disrupted, outside any service guarantee, and not something to build a business process on. If your acquired company "solves China" with a consumer VPN subscription, that's a finding, not a solution.

Does PIPL apply to us if we have no entity in China?

It can. PIPL reaches foreign companies that sell products or services into China or analyse the behaviour of people in China — and since January 2025 the Network Data Security Management Regulations require such companies to designate a representative or institution in China and report it to the authorities. No entity does not mean no obligations.

Can our China staff's HR data go to our global HR system?

Usually yes, and more easily than people fear: the 2024 cross-border rules exempt employee data transferred for genuine HR management from all three transfer mechanisms, regardless of volume. You still need PIPL-compliant notices and, in practice, clean records of what goes where — but the routine global-HR scenario is no longer the blocker it briefly was.

Do we need a CAC security assessment to send customer data to HQ?

Only at scale or sensitivity: the assessment applies from 1 million individuals, 10,000 sensitive-data individuals, any "important data", or if you're critical infrastructure. Between 100,000 and 1 million non-sensitive individuals it's an SCC filing; below 100,000, no mechanism at all. Most foreign SMEs land in the exempt or SCC bands — but someone has to do the counting and keep it current.

Can we run our China business on Google Workspace?

Realistically, no. Google's services are blocked in the mainland, so every user would depend on cross-border circuits for email and files — fragile and expensive. Companies standardised on Workspace globally usually run their mainland staff on Microsoft 365 or a local stack and bridge the two, rather than fighting the firewall daily.

Do we need an ICP filing?

If you serve the public from hosting inside mainland China — a website, a portal, an app backend — yes: at least an ICP filing, which needs a Chinese business licence, and a commercial ICP licence for paid online services. Serving China from Hong Kong avoids ICP at the cost of performance. An acquired business running on a vendor's or founder's filing is a risk to fix, not a convenience to keep.

What's different about AWS or Azure in China?

They're separate worlds. AWS China (Beijing under Sinnet, Ningxia under NWCD) and Azure China (21Vianet) run as physically separate regions with separate accounts, requiring a Chinese business licence — and anything public-facing needs its ICP filing in the hosting region. Global-account resources and China-account resources don't mingle; architect for two estates with controlled bridges.

What is MLPS 2.0 and do we care?

China's mandatory grading scheme for systems operated in the mainland. You classify each system Level 1–5; Level 2+ gets filed with the public security bureau and Level 3+ needs annual assessment. A foreign SME's China file server or local ERP is typically Level 2 — light-touch, but it's a filing that inspectors and incident investigations expect to see.

What happens if we just ignore all this?

Frequently nothing — until something forces the question: an incident with a 24-hour reporting clock, a customer or partner audit, a deal's due diligence, or a takedown of an unfiled site. PIPL fines reach RMB 50 million or 5% of turnover at the top end; the everyday cost is a China operation running on connectivity and filings that can vanish without notice. The fix is rarely expensive; discovering the gap mid-crisis is.

How PTS helps

Ask us the one that isn't here

  • A thirty-minute conversation with an engineer who works in China every week — not a sales call
  • The answer is usually a short list of what to check first

Sources

  1. Cyberspace Administration of China, Provisions on Promoting and Regulating Cross-border Data Flows, 22 March 2024, with 2025 official Q&A clarifications. Summaries: IAPP; Arnold & Porter.
  2. State Council, Network Data Security Management Regulations, effective 1 January 2025. Summaries: Mayer Brown; China Briefing.
  3. Personal Information Protection Law (2021); Data Security Law (2021); Cybersecurity Law (2017); MLPS 2.0 standards (from 2019). Overview: DLA Piper Data Protection Laws of the World — China.
  4. Microsoft, service descriptions for Microsoft 365 operated by 21Vianet (feature availability, incl. Copilot and Autopilot exclusions as at 26 August 2026). See also PTS, Microsoft 365 in China — global vs 21Vianet.
  5. Amazon Web Services, AWS in China FAQs — Sinnet (Beijing) and NWCD (Ningxia) operation, separate China accounts, business-licence and ICP requirements.
  6. MIIT, Circular on Cleaning up and Regulating the Internet Access Service Market (2017) — licensed cross-border channels for corporate use.
  7. PTS guides: China & Hong Kong data laws; IT for foreign companies in China & HK; PIPL explained.

The China IT Navigator is a technology and operations reference prepared by PTS Managed Services Limited. It is not legal advice; China's rules change quickly and their application turns on specifics — verify against current sources and engage qualified PRC counsel before acting. References current at 26 August 2026.

Call Request a proposal