PTS Managed Services · China · Hong Kong · Singapore
The China IT navigator for foreign companies
Entering China, acquiring a business there, or untangling an operation that grew on its own? Pick your situation and the navigator shows which laws actually apply, how compliant connectivity works, what runs (and what doesn't) from inside the mainland, and turns your answers into a readiness assessment you can keep as a PDF or send to PTS.
Pick your situation, then answer the basics on the Overview tab; the whole navigator tailors itself as you go.
Start here
Showing for Setting up in China · data leaves ChinaChina IT is not mysterious: it is specific. Four laws, one connectivity regime and two separate cloud worlds cover almost everything foreign companies get wrong. Answer the basics, then work through the readiness checklist; the whole navigator tailors itself to setting up in china.
Decide three things before anyone signs a lease: your tenant strategy (global M365 on licensed connectivity vs a 21Vianet tenant), your connectivity route (circuits or SD-WAN, ordered early; provisioning takes weeks), and whether anything will be hosted in the mainland (which triggers ICP and MLPS). Getting these right on day one costs a fraction of retrofitting them.
Next: the readiness checklist →
PTS has run China IT for foreign companies for over two decades, with our own registered mainland entity, engineers in Shanghai, and delivery across Hong Kong and Singapore; see IT for foreign companies in China & HK.
A grounded start for setting up in china
- A China IT readiness assessment against everything in this navigator (connectivity, tenancy, filings, data flows), with a prioritised plan
- Licensed connectivity designed and procured: IPLC/IEPL, MPLS or SD-WAN through our carrier relationships
- Tenant strategy and migration: global, 21Vianet or hybrid, decided on facts, then delivered
- On-the-ground engineers through PTS's registered China entity, from Shanghai outwards
Your readiness checklist
Showing for Setting up in China · data leaves ChinaAnswer from what you actually know. "Not sure" is a perfectly good answer, and usually the honest one for a China operation. Your answers build the assessment on the next tab and stay in this browser unless you send them.
Connectivity
Data
Systems
Operations
Your China IT readiness assessment
Showing for Setting up in China · data leaves ChinaSetting up in China · None yet staff in China · running Not sure · no goals selected yet
What you'll likely need
Built from the shape of your business and your goals; each item says why it's there. This is a starting scope, not a quote: PTS validates it in the free readiness check.
China office network build
Cabling, firewall, Wi-Fi and local breakout engineered for the mainland, delivered by engineers on the ground.
Because you told us: a first mainland presence usually starts with the office build.
HQ integration & data-flow design
Which systems bridge, which stay local, and the transfer mechanics that keep the data flows in the light bands.
Because you told us: personal data already flows to systems outside the mainland.
Get your China IT readiness check
Send this to PTS and within two business days we'll come back to arrange a free readiness conversation with an engineer who works on China estates every week, then a costed, prioritised plan. Your situation, answers and architecture map are attached automatically.
Build your China architecture
Place the pieces of your estate on each side of the border and every connection that crosses it is checked against the same rules as the rest of this navigator: what works, what needs a licensed route or a filing, and what will not work at all. Nothing is sent anywhere.
What the map checks
Two things decide what a connection costs you, and companies routinely conflate them:
Transport: how the traffic leaves China
Cross-border corporate traffic has to run on channels from licensed carriers. That is a connectivity decision with a price and a lead time, and it is the one most companies think about first.
Data: what is allowed to leave
Personal data crossing the border needs its own legal basis under PIPL, sized by volume and sensitivity. This is a separate question with a separate answer.
Buying a leased line turns the connectivity findings green and leaves your transfer obligations exactly where they were. It is the most common misconception we see in China enquiries, and the map is built to show it: choose a licensed route and watch the connectivity flags clear while a customer database crossing the border stays flagged for an SCC filing.
Cross-border connectivity, compared
Every option below is a licensed route except the first. Consumer VPN apps are not on this list and are not a compliance strategy: they are routinely disrupted, sit outside any service guarantee, and put the traffic your China business depends on beyond anyone's accountability.
Public internet No licensed route
What it is. No private circuit at all. Everything between China and the outside world transits the public internet, and the national firewall along with it.
How it works. The China office uses an ordinary local broadband or business line. Traffic to HQ, to global SaaS and to your cloud takes whatever path the internet offers that day.
What it gives you. Nothing to provision and nothing to pay beyond the local line. Genuinely fine for browsing, and often fine for a handful of people doing light work.
What it does not solve. Latency and packet loss vary hour to hour, some services are unreachable outright, and none of it sits under any service guarantee. It is not a base for ERP, voice, file services, or anything the business stops without.
Site-to-site VPN (self-managed) No licensed route
What it is. An encrypted tunnel between your own firewalls — the China office on one end, HQ or a cloud on the other — over the ordinary public internet.
How it works. Your IT team (or the acquired company’s) configures IPsec or similar on each firewall. No licensed cross-border service is involved: the tunnel rides whatever internet path exists, national firewall and all.
What it gives you. Cheap, quick and encrypted, which is why so many China estates arrive on one. For a small office with modest needs it can limp along for a long time.
What it does not solve. It inherits every public-internet problem and adds one: encrypted tunnels are among the traffic the national firewall is observed to throttle or drop — without notice, and at the worst moments. It is not a channel from a licensed carrier, and no one is accountable for it.
Commercial VPN apps No licensed route
What it is. Consumer or commercial VPN subscriptions running on individual laptops and phones.
How it works. Each person tunnels out through the VPN provider’s servers. There is no company infrastructure at all — every user is their own cross-border link.
What it gives you. Nothing to build, and it sometimes works today, which is why inherited China operations so often run on it.
What it does not solve. Providing VPN services without a Chinese telecoms licence is unlawful, and unapproved cross-border channels are what the national firewall targets — which is why the apps are routinely disrupted, most reliably around sensitive dates. Per-device, invisible to your IT team, and outside any service guarantee. Not a compliance strategy.
Dedicated leased line (IPLC/IEPL) Licensed route
What it is. A dedicated point-to-point circuit from a licensed carrier, running between your mainland site and a termination point outside it (usually Hong Kong or Singapore).
How it works. The carrier provisions physical capacity end to end and registers the circuit to your China entity for internal business use. Your private traffic rides that circuit rather than transiting the public internet, so it never crosses the national firewall.
What it gives you. Predictable latency and loss, a bandwidth figure you actually get, and a contract with someone accountable for it. This is the classic backbone for ERP, file services and voice between China and the region.
What it does not solve. Weeks to provision and priced per megabit. It is a pipe between two points: it gives you no local internet breakout on its own, and it does nothing whatsoever about cross-border data obligations.
Private multi-site network (MPLS) Licensed route
What it is. A carrier-run private WAN joining several of your sites, rather than a single point-to-point circuit.
How it works. A licensed carrier (or a partner reselling one) puts each site on their MPLS backbone and routes between them privately, with agreed traffic classes so voice and business applications get priority over bulk traffic.
What it gives you. Any-to-any connectivity across multiple China and regional sites, carrier-managed quality of service, and one operator accountable for the whole WAN instead of a separate circuit per pair of offices.
What it does not solve. Longer contracts, a cost per site, and less flexible than an overlay when sites open and close. Like a leased line, it answers connectivity and nothing else.
Managed SD-WAN (licensed underlay) Licensed route
What it is. A managed overlay that steers traffic per application across several links, where the cross-border leg runs over a licensed carrier underneath.
How it works. Appliances at each site choose a path per application: local internet breakout in China for what can stay local, and the licensed cross-border path for what has to leave. The provider runs the overlay and holds the carrier relationship.
What it gives you. Much faster to deploy and far more flexible than fixed circuits, with application-aware routing and local breakout. It is the usual modern answer when a China office needs global Microsoft 365 as well as good local speed.
What it does not solve. Quality depends entirely on the underlay genuinely being licensed and well peered. “SD-WAN” from a vendor who cannot name the licensed carrier beneath it is a consumer VPN with a dashboard.
What you can place on the map
Inside mainland China
- China office
- On-prem server (China)
- Data centre (China)
- Public website / app in China
- Microsoft 365 (21Vianet)
- AWS / Azure China region
- Alibaba / Tencent Cloud
- WeChat official account / mini-program
- WeCom / DingTalk
Outside the mainland
- HQ office
- Data centre (outside China)
- Microsoft 365 (global tenant)
- Google Workspace
- AWS / Azure (global)
- Global HR system
- Global CRM / ERP / finance
- Backup / DR (outside China)
- Identity / single sign-on (global)
- Device management (Intune / MDM, global)
- Security monitoring / EDR (global)
Anything sharing a side is assumed to be on that side's network, so the map draws a line only where a connection crosses the border. That is deliberate: the border crossing is the part that carries an obligation.
Amber and red findings on your map are the agenda for a free architecture conversation.
Turn the map into a costed plan
- An architecture review with engineers who work in the mainland through PTS's registered China entity
- Licensed connectivity sized and procured: IPLC/IEPL, MPLS or SD-WAN on a licensed underlay
- The tenant decision made on facts: global Microsoft 365 on good connectivity, 21Vianet, or a planned hybrid
- Filings and transfer routes identified before they become someone's emergency
The laws, in plain English
Showing for Setting up in China · data leaves ChinaEverything below is a real obligation with a real enforcement history, but almost all of it is manageable for an SME once someone owns it. Marked applies or watch for your situation. For the deeper legal picture see our guide to China & Hong Kong data laws.
Applies to your situation
Cybersecurity Law
The foundation. Anyone operating networks or systems in China is a "network operator" with baseline security duties: protection measures, real-name requirements where applicable, incident response and cooperation with regulators. It also created the critical information infrastructure (CIIO) category: stricter localisation and review duties that most foreign SMEs will not trigger, but the concepts flow down through everything below.
Data Security Law
Applies to all data, not just personal data. Requires classification (the 2025 regulations formalise ordinary / important / core tiers), security management by data category, and government approval before providing data stored in China to foreign judicial or law-enforcement authorities, a clause every multinational's legal team should know exists before a discovery request arrives.
Personal Information Protection Law
China's GDPR-equivalent, with teeth: up to RMB 50 million or 5% of the previous year's turnover. Consent-centric (with separate consent for cross-border transfers and sensitive data), extraterritorial (it reaches foreign companies with no China entity that sell into China or analyse people in China), and the legal hook for the transfer mechanisms below.
Network Data Security Management Regulations
The State Council regulations that operationalise CSL, DSL and PIPL from 1 January 2025: tiered data classification, security self-assessments, incident response with 24-hour reporting duties in serious cases, annual reports for important-data processors; and, for foreign companies in scope of PIPL's extraterritorial reach, a mandatory designated institution or representative in China, reported to the local cyberspace administration.
Cross-border data transfer mechanisms
Three mechanisms: CAC security assessment, Chinese standard contractual clauses (SCC filing), or certification. The 2024 relaxations exempt most SMEs: under 100,000 individuals' non-sensitive personal information (cumulative from 1 January) needs no mechanism at all, and employee data needed for HR management is exempt regardless of volume. SCC filing covers 100,000–1 million individuals (or under 10,000 sensitive); the CAC assessment bites at 1 million+, 10,000+ sensitive, any "important data", and always for CIIOs. Free trade zones run their own negative lists that can relax this further.
Cross-border connectivity rules
Cross-border corporate connectivity must run on channels from licensed carriers: international private leased circuits (IPLC/IEPL), MPLS, or SD-WAN over a licensed underlay, with the circuits registered to your entity and used for internal business only. Consumer VPN apps are not a compliance strategy: they are routinely disrupted, contractually fragile and put the traffic your China business depends on outside any service guarantee.
Worth watching
Multi-Level Protection Scheme
China's mandatory security grading for systems run in the mainland. You self-classify each system Level 1–5; Level 2 and above is filed with the public security bureau, and Level 3+ needs annual expert assessment. A typical foreign SME's China ERP or file server lands at Level 2. If you host nothing in the mainland it usually stays theoretical, until you acquire a company that should have filed and never did.
China representative requirement
A foreign company caught by PIPL's extraterritorial reach (selling into China or analysing people in China without a mainland entity) must designate a dedicated institution or representative in China and report their contact details to the municipal cyberspace administration. It is the piece remote-first companies most often discover late.
Turning law into a worklist
- A data map of what China personal data you hold and where it flows: the input every obligation shares
- The filings done: MLPS grading, ICP, representative registration, SCC filing where your numbers require it
- Working with your counsel, not replacing them: we bring the systems reality, they bring the legal call
Connectivity: the part everyone feels first
Showing for Setting up in China · data leaves ChinaThe Great Firewall is not a rumour; it is a daily performance characteristic. The question is never "how do we get around it"; it is "which licensed route fits our size and systems". These are the four realistic options.
Public internet + patience
- Free, instant, and unpredictable: cross-border traffic transits the Great Firewall with high latency, packet loss and outright blocks
- Global SaaS (Google, many Western tools) ranges from degraded to unreachable
- Acceptable for browsing and low-stakes email; not for ERP, VoIP, file servers or anything the business depends on
IPLC / IEPL leased lines
- Dedicated licensed circuits between your China office and HK/SG/HQ: predictable latency, no firewall transit for the private traffic
- Provisioning takes weeks and is priced per bandwidth; registered to your entity for internal use
- The classic backbone for ERP, file services and voice between China and the region
SD-WAN on a licensed underlay
- Managed overlay from licensed providers combining local internet breakout in China with compliant cross-border transit
- Faster to deploy and more flexible than point-to-point circuits; quality depends entirely on the underlay being licensed and well-peered
- The usual modern answer for a China office that needs global M365/cloud plus local speed
Premium transit (e.g. CN2) via HK
- Hosting or relaying in Hong Kong on premium China-facing routes improves mainland reachability without ICP obligations
- No guarantees (still public-internet class), but often the pragmatic middle step while an entity or circuits are being set up
Consumer VPN apps as business infrastructure. They are periodically disrupted, carry no service guarantee, and an operation that depends on one has an outage (and a finding) waiting to happen. If you have just acquired a company and this is how it reaches HQ, treat it as the first thing to replace.
Connectivity, delivered
- Route selection and sizing against your actual traffic, not the biggest circuit a carrier will sell you
- Procurement and provisioning through licensed carriers in China, HK and Singapore, managed end to end
- SD-WAN designs that give China staff fast local breakout AND compliant access to global systems
- Ongoing monitoring, because cross-border quality is a moving target
Getting data out of China
Showing for Setting up in China · data leaves ChinaThe 2024 rules turned this from a wall into a set of doors; most foreign SMEs walk through an exempt one. What matters is knowing which door you're at, because the thresholds are cumulative and someone has to keep count.
| Your volume (cumulative since 1 Jan) | Mechanism | In practice |
|---|---|---|
| Employee data for HR management | Exempt (any volume) | Global HR, payroll and travel systems are workable; keep notices and records clean |
| Under 100,000 individuals (non-sensitive) | Exempt | No filing, but you need the data map that proves you're under it |
| 100,000 – 1 million individuals, or under 10,000 sensitive | Chinese SCCs filed, or certification | A contract-and-filing exercise; weeks, not months, when the data map exists |
| 1 million+ individuals, 10,000+ sensitive, any "important data", or CIIO | CAC security assessment | The heavy path: months, counsel-led; most SMEs never reach it |
Shanghai, Beijing, Tianjin and other FTZs publish their own negative lists: data outside the list moves without a mechanism for entities registered there. If your China entity sits in an FTZ, check its list before building process around the national thresholds.
Making the exempt path real
- The data map and counting that the exemptions quietly assume you have
- System-level fixes that keep you in the light bands, minimising what leaves China at all
- SCC filing support alongside your counsel when your numbers require it
Your stack: what works from inside China
Showing for Setting up in China · data leaves ChinaTwo separate cloud worlds, one blocked ecosystem, and a lot of nuance. Observed reality as at 31 August 2026. Statuses shift, so treat "Degraded" and "Mixed" as "test before you commit".
| Service | From the mainland | What it means |
|---|---|---|
| Microsoft 365 (global tenant) | Degraded | Reachable but slow/unstable over public internet; workable with licensed connectivity. Copilot and some services depend on endpoints that suffer most. |
| Microsoft 365 (21Vianet) | Works | Separate China cloud run by 21Vianet: fast and lawful locally, but a distinct tenant. Separate identities, no Copilot or Autopilot, thinner feature set, and no simple federation with your global tenant. |
| Google Workspace / Gmail | Blocked | Google services have been blocked for years. A China operation cannot run on Workspace without routing every user over cross-border circuits; plan a Microsoft or local stack for mainland staff instead. |
| AWS (global regions) | Degraded | Consoles and APIs reachable but slow; latency to ap-east-1 (HK) is the usual compromise for serving China users without ICP. |
| AWS China (Beijing/Ningxia) | Works | Physically separate regions run by Sinnet (Beijing) and NWCD (Ningxia). Separate account, Chinese business licence required, ICP filing per region for anything public-facing. |
| Azure / Dynamics (21Vianet China regions) | Works | Same pattern as M365 China: local, lawful, separate subscription and feature cadence. |
| Teams / Zoom / Slack | Mixed | Teams (global) is usable on good connectivity; Zoom works via its China arrangements for licensed use; Slack is unreliable. For all-hands with mainland staff, test before you commit. |
| WeCom / DingTalk / Feishu | Works | The local collaboration stacks. Many acquired businesses live on WeCom or DingTalk. Plan integration or coexistence rather than assuming a rip-and-replace. |
The Microsoft 365 decision
Global tenant + licensed connectivity
One identity, one tenant, Copilot and the full feature set; China staff reach it over circuits or SD-WAN. The default answer for most foreign SMEs, and the one that keeps collaboration simple.
21Vianet China tenant
Fast and local with no cross-border dependency, but a separate world: separate accounts, no Copilot or Autopilot, thinner features, and awkward federation with your global tenant. Right when China headcount is large, data must stay local, or connectivity budgets don't stretch.
The full trade-off, costs and migration paths are in our decision guide: Microsoft 365 in China: global vs 21Vianet.
Stack decisions, made and delivered
- Tenant strategy on facts: usage, headcount, data constraints and budget, then the migration itself
- AWS/Azure China builds through the operator accounts, with the ICP filings that public-facing workloads need
- Coexistence with WeCom or DingTalk where the local business already lives there
Acquiring a Chinese business: the IT you inherit
Showing for Setting up in China · data leaves ChinaAt completion you own their decisions, and their liabilities. These are the six findings we meet most often in acquired mainland businesses, in the order they usually hurt.
Admin control held personally
Domains, servers, WeCom/WeChat official accounts and banking USB-keys registered to the founder or a departed IT person. Day-zero task: enumerate and take control of every credential and registration, before relationships cool.
The consumer-VPN "solution"
HQ access that depends on a personal VPN subscription. Replace with licensed circuits or SD-WAN before you standardise anything on it.
ICP and MLPS gaps
Websites on someone else's ICP filing, systems never MLPS-graded. Quiet until an inspection, a takedown or an incident makes them loud.
Unlicensed software
Pirated Windows, Office and CAD remain common in acquired SMEs: an easy enforcement target and an integration blocker. Budget for true-up early.
Liabilities that transferred with the shares
Customer databases collected without PIPL-grade consent, data flowing abroad with no mechanism, no processing records. Your exposure now: map it before you integrate it.
The business runs on personal WeChat
Orders, approvals and customer relationships in personal chat histories. Move it to controlled WeCom/company channels with care; it is where the revenue lives.
This is the same discipline behind our private equity IT & M&A due-diligence practice, applied to mainland targets.
Diligence through integration
- Pre-deal IT due diligence on mainland targets through our China entity; see IT & M&A due diligence for private equity
- The first-100-days plan: admin control, connectivity, licensing true-up, filings, then tenant integration
- On-the-ground execution in China rather than instructions emailed from HQ
The questions we're actually asked
Short, factual answers to the confusions that fill our inbox, from companies entering China and companies that just bought one.
Can our China office just use our global Microsoft 365 tenant?
Often yes (that is the most common setup for foreign SMEs), but only with proper connectivity. Over the public internet the experience ranges from sluggish to unusable; over licensed circuits or a good SD-WAN it works well. The alternative is a separate 21Vianet tenant: fast and local, but separate identities, no Copilot, and real friction collaborating with your global tenant. It's a genuine architecture decision; our guide to Microsoft 365 in China walks through it.
Is it legal to use a VPN for our China office?
Corporate cross-border connectivity is legal when it runs on channels from licensed carriers: leased circuits, MPLS, or SD-WAN over a licensed underlay, registered to your entity for internal use. Consumer VPN apps are a different matter: periodically disrupted, outside any service guarantee, and not something to build a business process on. If your acquired company "solves China" with a consumer VPN subscription, that's a finding, not a solution.
Does PIPL apply to us if we have no entity in China?
It can. PIPL reaches foreign companies that sell products or services into China or analyse the behaviour of people in China, and since January 2025 the Network Data Security Management Regulations require such companies to designate a representative or institution in China and report it to the authorities. No entity does not mean no obligations.
Can our China staff's HR data go to our global HR system?
Usually yes, and more easily than people fear: the 2024 cross-border rules exempt employee data transferred for genuine HR management from all three transfer mechanisms, regardless of volume. You still need PIPL-compliant notices and, in practice, clean records of what goes where, but the routine global-HR scenario is no longer the blocker it briefly was.
Do we need a CAC security assessment to send customer data to HQ?
Only at scale or sensitivity: the assessment applies from 1 million individuals, 10,000 sensitive-data individuals, any "important data", or if you're critical infrastructure. Between 100,000 and 1 million non-sensitive individuals it's an SCC filing; below 100,000, no mechanism at all. Most foreign SMEs land in the exempt or SCC bands, but someone has to do the counting and keep it current.
Can we run our China business on Google Workspace?
Realistically, no. Google's services are blocked in the mainland, so every user would depend on cross-border circuits for email and files: fragile and expensive. Companies standardised on Workspace globally usually run their mainland staff on Microsoft 365 or a local stack and bridge the two, rather than fighting the firewall daily.
Do we need an ICP filing?
If you serve the public from hosting inside mainland China (a website, a portal, an app backend), yes: at least an ICP filing, which needs a Chinese business licence, and a commercial ICP licence for paid online services. Serving China from Hong Kong avoids ICP at the cost of performance. An acquired business running on a vendor's or founder's filing is a risk to fix, not a convenience to keep.
What's different about AWS or Azure in China?
They're separate worlds. AWS China (Beijing under Sinnet, Ningxia under NWCD) and Azure China (21Vianet) run as physically separate regions with separate accounts, requiring a Chinese business licence, and anything public-facing needs its ICP filing in the hosting region. Global-account resources and China-account resources don't mingle; architect for two estates with controlled bridges.
What is MLPS 2.0 and do we care?
China's mandatory grading scheme for systems operated in the mainland. You classify each system Level 1–5; Level 2+ gets filed with the public security bureau and Level 3+ needs annual assessment. A foreign SME's China file server or local ERP is typically Level 2: light-touch, but it's a filing that inspectors and incident investigations expect to see.
Does a leased line to Hong Kong solve our PIPL problem?
No, and this is the most common misconception we see. A licensed circuit answers TRANSPORT: it is the compliant, reliable way to carry cross-border corporate traffic, and it makes your connectivity problems go away. It says nothing about whether the personal data on that circuit is allowed to leave China. That is a separate question answered by the transfer mechanisms: exempt below 100,000 non-sensitive individuals, an SCC filing between 100,000 and 1 million, a CAC security assessment above that or for sensitive data at scale. You can buy the best circuit available and still need the filing. The architecture builder on this page shows exactly this: choose a licensed route and the connectivity flags clear while a customer database crossing the border stays flagged.
What is the difference between IPLC, MPLS and SD-WAN for China?
All three are licensed routes, and the right one depends on shape. An IPLC or IEPL is a dedicated point-to-point circuit between your mainland site and a termination point outside it: the most predictable, the slowest to provision, and priced per megabit. MPLS is a carrier-run private WAN joining several sites with managed quality of service, which makes sense once you have multiple China and regional offices. SD-WAN over a licensed underlay is a managed overlay that routes per application, keeping local traffic local and sending only what must leave over the licensed path, and it is the usual modern answer for a China office that needs global Microsoft 365 plus good local speed. The warning sign is a vendor who cannot name the licensed carrier underneath their SD-WAN.
Do backups of China data outside China count as a cross-border transfer?
Yes. A backup or DR copy replicates everything in the systems it protects, so pushing China backups to storage or a cloud region outside the mainland transfers personal data at full volume — plus anything that could be classed "important data" under the Data Security Law. The volume exemptions that might cover a single business flow rarely fit a whole-estate backup set. The usual answers are a mainland backup tier for China systems, or a deliberately scoped, counted and documented off-mainland copy under the same transfer mechanism as your live flows. What does not work is discovering the backup job in a compliance review.
Will our staff's laptops and phones work when they travel to China?
Mostly, and for a reason worth understanding: on international roaming, traffic breaks out through the home carrier, so the global stack — mail, files, even blocked services — generally works as it does at home. Connect the same device to hotel Wi-Fi or a local SIM and it is on the Chinese internet, where the usual blocks and slowdowns apply, and per-device VPN apps are not a dependable or compliant answer. For visits, roaming is the pragmatic approach; for anything sustained — a team, an office, a project — that is what licensed connectivity is for.
What happens if we just ignore all this?
Frequently nothing, until something forces the question: an incident with a 24-hour reporting clock, a customer or partner audit, a deal's due diligence, or a takedown of an unfiled site. PIPL fines reach RMB 50 million or 5% of turnover at the top end; the everyday cost is a China operation running on connectivity and filings that can vanish without notice. The fix is rarely expensive; discovering the gap mid-crisis is.
Ask us the one that isn't here
- A thirty-minute conversation with an engineer who works in China every week, not a sales call
- The answer is usually a short list of what to check first
Sources
- Cyberspace Administration of China, Provisions on Promoting and Regulating Cross-border Data Flows, 22 March 2024, with 2025 official Q&A clarifications. Summaries: IAPP; Arnold & Porter.
- State Council, Network Data Security Management Regulations, effective 1 January 2025. Summaries: Mayer Brown; China Briefing.
- Personal Information Protection Law (2021); Data Security Law (2021); Cybersecurity Law (2017); MLPS 2.0 standards (from 2019). Overview: DLA Piper Data Protection Laws of the World: China.
- Microsoft, service descriptions for Microsoft 365 operated by 21Vianet (feature availability, incl. Copilot and Autopilot exclusions as at 31 August 2026). See also PTS, Microsoft 365 in China: global vs 21Vianet.
- Amazon Web Services, AWS in China FAQs: Sinnet (Beijing) and NWCD (Ningxia) operation, separate China accounts, business-licence and ICP requirements.
- MIIT, Circular on Cleaning up and Regulating the Internet Access Service Market (2017). Licensed cross-border channels for corporate use.
- PTS guides: China & Hong Kong data laws; IT for foreign companies in China & HK; PIPL explained.
The China IT Navigator is a technology and operations reference prepared by PTS Managed Services Limited. It is not legal advice; China's rules change quickly and their application turns on specifics: verify against current sources and engage qualified PRC counsel before acting. References current at 31 August 2026.