PTS Managed Services · China · Hong Kong · Singapore
The China IT navigator for foreign companies
Entering China, acquiring a business there, or untangling an operation that grew on its own? Pick your situation and the navigator shows which laws actually apply, how compliant connectivity works, what runs (and what doesn't) from inside the mainland — and turns your answers into a readiness assessment you can keep as a PDF or send to PTS.
Pick your situation, then answer the basics on the Overview tab — the whole navigator tailors itself as you go.
Start here
Showing for Setting up in China · data leaves ChinaChina IT is not mysterious — it is specific. Four laws, one connectivity regime and two separate cloud worlds cover almost everything foreign companies get wrong. Answer the basics, then work through the readiness checklist — the whole navigator tailors itself to setting up in china.
Decide three things before anyone signs a lease: your tenant strategy (global M365 on licensed connectivity vs a 21Vianet tenant), your connectivity route (circuits or SD-WAN, ordered early — provisioning takes weeks), and whether anything will be hosted in the mainland (which triggers ICP and MLPS). Getting these right on day one costs a fraction of retrofitting them.
Next: the readiness checklist →
PTS has run China IT for foreign companies for over two decades, with our own registered mainland entity, engineers in Shanghai, and delivery across Hong Kong and Singapore — see IT for foreign companies in China & HK.
A grounded start for setting up in china
- A China IT readiness assessment against everything in this navigator — connectivity, tenancy, filings, data flows — with a prioritised plan
- Licensed connectivity designed and procured: IPLC/IEPL, MPLS or SD-WAN through our carrier relationships
- Tenant strategy and migration: global, 21Vianet or hybrid — decided on facts, then delivered
- On-the-ground engineers through PTS's registered China entity, from Shanghai outwards
Your readiness checklist
Showing for Setting up in China · data leaves ChinaAnswer from what you actually know — "Not sure" is a perfectly good answer and usually the honest one for a China operation. Your answers build the assessment on the next tab and stay in this browser unless you send them.
Connectivity
Data
Systems
Operations
Your China IT readiness assessment
Showing for Setting up in China · data leaves ChinaSetting up in China · None yet staff in China · running Not sure · no goals selected yet
What you'll likely need
Built from the shape of your business and your goals — each item says why it's there. This is a starting scope, not a quote: PTS validates it in the free readiness check.
China office network build
Cabling, firewall, Wi-Fi and local breakout engineered for the mainland — delivered by engineers on the ground.
Because you told us: a first mainland presence usually starts with the office build.
HQ integration & data-flow design
Which systems bridge, which stay local, and the transfer mechanics that keep the data flows in the light bands.
Because you told us: personal data already flows to systems outside the mainland.
Get your China IT readiness check — free, engineer-led
Send this to PTS and within two business days we'll come back to arrange a free readiness conversation with an engineer who works on China estates every week — then a costed, prioritised plan. Your situation and answers are attached automatically.
The laws, in plain English
Showing for Setting up in China · data leaves ChinaEverything below is a real obligation with a real enforcement history — but almost all of it is manageable for an SME once someone owns it. Marked applies or watch for your situation. For the deeper legal picture see our guide to China & Hong Kong data laws.
Applies to your situation
Cybersecurity Law
The foundation. Anyone operating networks or systems in China is a "network operator" with baseline security duties: protection measures, real-name requirements where applicable, incident response and cooperation with regulators. It also created the critical information infrastructure (CIIO) category — stricter localisation and review duties that most foreign SMEs will not trigger, but the concepts flow down through everything below.
Data Security Law
Applies to all data, not just personal data. Requires classification (the 2025 regulations formalise ordinary / important / core tiers), security management by data category, and government approval before providing data stored in China to foreign judicial or law-enforcement authorities — a clause every multinational's legal team should know exists before a discovery request arrives.
Personal Information Protection Law
China's GDPR-equivalent, with teeth: up to RMB 50 million or 5% of the previous year's turnover. Consent-centric (with separate consent for cross-border transfers and sensitive data), extraterritorial — it reaches foreign companies with no China entity that sell into China or analyse people in China — and the legal hook for the transfer mechanisms below.
Network Data Security Management Regulations
The State Council regulations that operationalise CSL, DSL and PIPL from 1 January 2025: tiered data classification, security self-assessments, incident response with 24-hour reporting duties in serious cases, annual reports for important-data processors — and, for foreign companies in scope of PIPL's extraterritorial reach, a mandatory designated institution or representative in China, reported to the local cyberspace administration.
Cross-border data transfer mechanisms
Three mechanisms — CAC security assessment, Chinese standard contractual clauses (SCC filing), or certification — with 2024 relaxations that exempt most SMEs: under 100,000 individuals' non-sensitive personal information (cumulative from 1 January) needs no mechanism at all, and employee data needed for HR management is exempt regardless of volume. SCC filing covers 100,000–1 million individuals (or under 10,000 sensitive); the CAC assessment bites at 1 million+, 10,000+ sensitive, any "important data", and always for CIIOs. Free trade zones run their own negative lists that can relax this further.
Cross-border connectivity rules
Cross-border corporate connectivity must run on channels from licensed carriers — international private leased circuits (IPLC/IEPL), MPLS, or SD-WAN over a licensed underlay — with the circuits registered to your entity and used for internal business only. Consumer VPN apps are not a compliance strategy: they are routinely disrupted, contractually fragile and put the traffic your China business depends on outside any service guarantee.
Worth watching
Multi-Level Protection Scheme
China's mandatory security grading for systems run in the mainland. You self-classify each system Level 1–5; Level 2 and above is filed with the public security bureau, and Level 3+ needs annual expert assessment. A typical foreign SME's China ERP or file server lands at Level 2. If you host nothing in the mainland it usually stays theoretical — until you acquire a company that should have filed and never did.
China representative requirement
A foreign company caught by PIPL's extraterritorial reach — selling into China or analysing people in China without a mainland entity — must designate a dedicated institution or representative in China and report their contact details to the municipal cyberspace administration. It is the piece remote-first companies most often discover late.
Turning law into a worklist
- A data map of what China personal data you hold and where it flows — the input every obligation shares
- The filings done: MLPS grading, ICP, representative registration, SCC filing where your numbers require it
- Working with your counsel, not replacing them — we bring the systems reality, they bring the legal call
Connectivity: the part everyone feels first
Showing for Setting up in China · data leaves ChinaThe Great Firewall is not a rumour; it is a daily performance characteristic. The question is never "how do we get around it" — it is "which licensed route fits our size and systems". These are the four realistic options.
Public internet + patience
- Free, instant — and unpredictable: cross-border traffic transits the Great Firewall with high latency, packet loss and outright blocks
- Global SaaS (Google, many Western tools) ranges from degraded to unreachable
- Acceptable for browsing and low-stakes email; not for ERP, VoIP, file servers or anything the business depends on
IPLC / IEPL leased lines
- Dedicated licensed circuits between your China office and HK/SG/HQ — predictable latency, no firewall transit for the private traffic
- Provisioning takes weeks and is priced per bandwidth; registered to your entity for internal use
- The classic backbone for ERP, file services and voice between China and the region
SD-WAN on a licensed underlay
- Managed overlay from licensed providers combining local internet breakout in China with compliant cross-border transit
- Faster to deploy and more flexible than point-to-point circuits; quality depends entirely on the underlay being licensed and well-peered
- The usual modern answer for a China office that needs global M365/cloud plus local speed
Premium transit (e.g. CN2) via HK
- Hosting or relaying in Hong Kong on premium China-facing routes improves mainland reachability without ICP obligations
- No guarantees — still public-internet class — but often the pragmatic middle step while an entity or circuits are being set up
Consumer VPN apps as business infrastructure. They are periodically disrupted, carry no service guarantee, and an operation that depends on one has an outage — and a finding — waiting to happen. If you have just acquired a company and this is how it reaches HQ, treat it as the first thing to replace.
Connectivity, delivered
- Route selection and sizing against your actual traffic — not the biggest circuit a carrier will sell you
- Procurement and provisioning through licensed carriers in China, HK and Singapore, managed end to end
- SD-WAN designs that give China staff fast local breakout AND compliant access to global systems
- Ongoing monitoring, because cross-border quality is a moving target
Getting data out of China
Showing for Setting up in China · data leaves ChinaThe 2024 rules turned this from a wall into a set of doors — most foreign SMEs walk through an exempt one. What matters is knowing which door you're at, because the thresholds are cumulative and someone has to keep count.
| Your volume (cumulative since 1 Jan) | Mechanism | In practice |
|---|---|---|
| Employee data for HR management | Exempt — any volume | Global HR, payroll and travel systems are workable; keep notices and records clean |
| Under 100,000 individuals (non-sensitive) | Exempt | No filing — but you need the data map that proves you're under it |
| 100,000 – 1 million individuals, or under 10,000 sensitive | Chinese SCCs filed, or certification | A contract-and-filing exercise; weeks, not months, when the data map exists |
| 1 million+ individuals, 10,000+ sensitive, any "important data", or CIIO | CAC security assessment | The heavy path — months, counsel-led; most SMEs never reach it |
Shanghai, Beijing, Tianjin and other FTZs publish their own negative lists — data outside the list moves without a mechanism for entities registered there. If your China entity sits in an FTZ, check its list before building process around the national thresholds.
Making the exempt path real
- The data map and counting that the exemptions quietly assume you have
- System-level fixes that keep you in the light bands — minimising what leaves China at all
- SCC filing support alongside your counsel when your numbers require it
Your stack: what works from inside China
Showing for Setting up in China · data leaves ChinaTwo separate cloud worlds, one blocked ecosystem, and a lot of nuance. Observed reality as at 26 August 2026 — statuses shift, so treat "Degraded" and "Mixed" as "test before you commit".
| Service | From the mainland | What it means |
|---|---|---|
| Microsoft 365 (global tenant) | Degraded | Reachable but slow/unstable over public internet; workable with licensed connectivity. Copilot and some services depend on endpoints that suffer most. |
| Microsoft 365 (21Vianet) | Works | Separate China cloud run by 21Vianet: fast and lawful locally, but a distinct tenant — separate identities, no Copilot or Autopilot, thinner feature set, and no simple federation with your global tenant. |
| Google Workspace / Gmail | Blocked | Google services have been blocked for years. A China operation cannot run on Workspace without routing every user over cross-border circuits — plan a Microsoft or local stack for mainland staff instead. |
| AWS (global regions) | Degraded | Consoles and APIs reachable but slow; latency to ap-east-1 (HK) is the usual compromise for serving China users without ICP. |
| AWS China (Beijing/Ningxia) | Works | Physically separate regions run by Sinnet (Beijing) and NWCD (Ningxia). Separate account, Chinese business licence required, ICP filing per region for anything public-facing. |
| Azure / Dynamics (21Vianet China regions) | Works | Same pattern as M365 China: local, lawful, separate subscription and feature cadence. |
| Teams / Zoom / Slack | Mixed | Teams (global) is usable on good connectivity; Zoom works via its China arrangements for licensed use; Slack is unreliable. For all-hands with mainland staff, test before you commit. |
| WeCom / DingTalk / Feishu | Works | The local collaboration stacks. Many acquired businesses live on WeCom or DingTalk — plan integration or coexistence rather than assuming a rip-and-replace. |
The Microsoft 365 decision
Global tenant + licensed connectivity
One identity, one tenant, Copilot and the full feature set — China staff reach it over circuits or SD-WAN. The default answer for most foreign SMEs, and the one that keeps collaboration simple.
21Vianet China tenant
Fast and local with no cross-border dependency — but a separate world: separate accounts, no Copilot or Autopilot, thinner features, and awkward federation with your global tenant. Right when China headcount is large, data must stay local, or connectivity budgets don't stretch.
The full trade-off, costs and migration paths are in our decision guide: Microsoft 365 in China — global vs 21Vianet.
Stack decisions, made and delivered
- Tenant strategy on facts: usage, headcount, data constraints and budget — then the migration itself
- AWS/Azure China builds through the operator accounts, with the ICP filings that public-facing workloads need
- Coexistence with WeCom or DingTalk where the local business already lives there
Acquiring a Chinese business: the IT you inherit
Showing for Setting up in China · data leaves ChinaAt completion you own their decisions — and their liabilities. These are the six findings we meet most often in acquired mainland businesses, in the order they usually hurt.
Admin control held personally
Domains, servers, WeCom/WeChat official accounts and banking USB-keys registered to the founder or a departed IT person. Day-zero task: enumerate and take control of every credential and registration, before relationships cool.
The consumer-VPN "solution"
HQ access that depends on a personal VPN subscription. Replace with licensed circuits or SD-WAN before you standardise anything on it.
ICP and MLPS gaps
Websites on someone else's ICP filing, systems never MLPS-graded. Quiet until an inspection, a takedown or an incident makes them loud.
Unlicensed software
Pirated Windows, Office and CAD remain common in acquired SMEs — an easy enforcement target and an integration blocker. Budget for true-up early.
Liabilities that transferred with the shares
Customer databases collected without PIPL-grade consent, data flowing abroad with no mechanism, no processing records. Your exposure now — map it before you integrate it.
The business runs on personal WeChat
Orders, approvals and customer relationships in personal chat histories. Move it to controlled WeCom/company channels with care — it is where the revenue lives.
This is the same discipline behind our private equity IT & M&A due-diligence practice, applied to mainland targets.
Diligence through integration
- Pre-deal IT due diligence on mainland targets through our China entity — see IT & M&A due diligence for private equity
- The first-100-days plan: admin control, connectivity, licensing true-up, filings, then tenant integration
- On-the-ground execution in China rather than instructions emailed from HQ
The questions we're actually asked
Short, factual answers to the confusions that fill our inbox — from companies entering China and companies that just bought one.
Can our China office just use our global Microsoft 365 tenant?
Often yes — that is the most common setup for foreign SMEs — but only with proper connectivity. Over the public internet the experience ranges from sluggish to unusable; over licensed circuits or a good SD-WAN it works well. The alternative is a separate 21Vianet tenant: fast and local, but separate identities, no Copilot, and real friction collaborating with your global tenant. It's a genuine architecture decision — our guide to Microsoft 365 in China walks through it.
Is it legal to use a VPN for our China office?
Corporate cross-border connectivity is legal when it runs on channels from licensed carriers — leased circuits, MPLS, or SD-WAN over a licensed underlay, registered to your entity for internal use. Consumer VPN apps are a different matter: periodically disrupted, outside any service guarantee, and not something to build a business process on. If your acquired company "solves China" with a consumer VPN subscription, that's a finding, not a solution.
Does PIPL apply to us if we have no entity in China?
It can. PIPL reaches foreign companies that sell products or services into China or analyse the behaviour of people in China — and since January 2025 the Network Data Security Management Regulations require such companies to designate a representative or institution in China and report it to the authorities. No entity does not mean no obligations.
Can our China staff's HR data go to our global HR system?
Usually yes, and more easily than people fear: the 2024 cross-border rules exempt employee data transferred for genuine HR management from all three transfer mechanisms, regardless of volume. You still need PIPL-compliant notices and, in practice, clean records of what goes where — but the routine global-HR scenario is no longer the blocker it briefly was.
Do we need a CAC security assessment to send customer data to HQ?
Only at scale or sensitivity: the assessment applies from 1 million individuals, 10,000 sensitive-data individuals, any "important data", or if you're critical infrastructure. Between 100,000 and 1 million non-sensitive individuals it's an SCC filing; below 100,000, no mechanism at all. Most foreign SMEs land in the exempt or SCC bands — but someone has to do the counting and keep it current.
Can we run our China business on Google Workspace?
Realistically, no. Google's services are blocked in the mainland, so every user would depend on cross-border circuits for email and files — fragile and expensive. Companies standardised on Workspace globally usually run their mainland staff on Microsoft 365 or a local stack and bridge the two, rather than fighting the firewall daily.
Do we need an ICP filing?
If you serve the public from hosting inside mainland China — a website, a portal, an app backend — yes: at least an ICP filing, which needs a Chinese business licence, and a commercial ICP licence for paid online services. Serving China from Hong Kong avoids ICP at the cost of performance. An acquired business running on a vendor's or founder's filing is a risk to fix, not a convenience to keep.
What's different about AWS or Azure in China?
They're separate worlds. AWS China (Beijing under Sinnet, Ningxia under NWCD) and Azure China (21Vianet) run as physically separate regions with separate accounts, requiring a Chinese business licence — and anything public-facing needs its ICP filing in the hosting region. Global-account resources and China-account resources don't mingle; architect for two estates with controlled bridges.
What is MLPS 2.0 and do we care?
China's mandatory grading scheme for systems operated in the mainland. You classify each system Level 1–5; Level 2+ gets filed with the public security bureau and Level 3+ needs annual assessment. A foreign SME's China file server or local ERP is typically Level 2 — light-touch, but it's a filing that inspectors and incident investigations expect to see.
What happens if we just ignore all this?
Frequently nothing — until something forces the question: an incident with a 24-hour reporting clock, a customer or partner audit, a deal's due diligence, or a takedown of an unfiled site. PIPL fines reach RMB 50 million or 5% of turnover at the top end; the everyday cost is a China operation running on connectivity and filings that can vanish without notice. The fix is rarely expensive; discovering the gap mid-crisis is.
Ask us the one that isn't here
- A thirty-minute conversation with an engineer who works in China every week — not a sales call
- The answer is usually a short list of what to check first
Sources
- Cyberspace Administration of China, Provisions on Promoting and Regulating Cross-border Data Flows, 22 March 2024, with 2025 official Q&A clarifications. Summaries: IAPP; Arnold & Porter.
- State Council, Network Data Security Management Regulations, effective 1 January 2025. Summaries: Mayer Brown; China Briefing.
- Personal Information Protection Law (2021); Data Security Law (2021); Cybersecurity Law (2017); MLPS 2.0 standards (from 2019). Overview: DLA Piper Data Protection Laws of the World — China.
- Microsoft, service descriptions for Microsoft 365 operated by 21Vianet (feature availability, incl. Copilot and Autopilot exclusions as at 26 August 2026). See also PTS, Microsoft 365 in China — global vs 21Vianet.
- Amazon Web Services, AWS in China FAQs — Sinnet (Beijing) and NWCD (Ningxia) operation, separate China accounts, business-licence and ICP requirements.
- MIIT, Circular on Cleaning up and Regulating the Internet Access Service Market (2017) — licensed cross-border channels for corporate use.
- PTS guides: China & Hong Kong data laws; IT for foreign companies in China & HK; PIPL explained.
The China IT Navigator is a technology and operations reference prepared by PTS Managed Services Limited. It is not legal advice; China's rules change quickly and their application turns on specifics — verify against current sources and engage qualified PRC counsel before acting. References current at 26 August 2026.