Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does 100ms Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency

100ms is an embeddable real-time video and audio API: your China users' live media, recordings (voiceprint and face — sensitive biometric) and identifiers ride its offshore infrastructure, with no mainland-China region. Providing real-time comms in China needs a value-added telecom license a foreign API can't hold, and the app needs an ICP filing — a compliance-first look at the telecom-licensing, residency and cross-border exposure.

Does 100ms work in China?

Embedding 100ms for your users in China carries their live media, any recordings (a voiceprint and a face — sensitive biometric) and identifiers to an offshore API with no mainland-China region; providing real-time communication in China needs a value-added telecom license a foreign API can't hold, and the app itself needs an ICP filing.

100ms carries live audio and video, session metadata and participant identifiers, and its recording, RTMP/HLS and live-transcription features produce recordings and transcripts — a recording captures the speaker's voiceprint and the participants' faces, which is sensitive biometric personal information under PIPL Article 28. Its own Security page lists core databases in the United States, Europe and India and no mainland-China region, so running it for China users is a PIPL cross-border transfer (Articles 38–40). The lawful lever is to route the real-time service through a licensed in-country operator, keep the media and recordings in-country, get the Article 28/29 consent and ICP-file the app — not to make the offshore endpoint reachable (21YunBox is advisory on telecom licensing).

This is a risk map, not a verdict — settle the telecom, residency and consent specifics with counsel. Our China team can map your exposure →

What 100ms's own documentation says about China

FactPrimary source
100ms has no mainland-China region — its core databases are in the US, Europe and India. Its Security page states: “Our customers have the option to choose where their data is stored. We have core databases setup in United States of America, Europe and India,” with production “hosted on multiple secure cloud services platforms, including Google Cloud Platform (GCP), Amazon Web Services (AWS).” For users in China, participant media, recordings and identifiers are therefore carried and stored offshore. 100ms, Security (100ms.live), retrieved 2026-10-10
100ms records audio and video and auto-transcribes calls — producing biometric data and transcripts. Its recording feature captures each peer's tracks, each peer's combined stream, or a single composite (“Record as a single composed asset combining media tracks of all peers in the room”), delivered over RTMP and HLS, and it offers “auto-generated live transcription in English” (beta). A recording captures voiceprints and faces — sensitive biometric personal information under PIPL Article 28. 100ms Docs — Recordings overview and Live transcription (100ms.live), retrieved 2026-10-10
Carrying China participant media offshore is a PIPL cross-border transfer, and recordings are sensitive biometric data. A voiceprint and a face are sensitive personal information (PIPL Article 28), needing separate, specific consent and a prior impact assessment (Article 29) and resisting anonymization; routing participant streams, identifiers and content to offshore servers is a cross-border transfer under Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Personal Information Protection Law of the PRC, Articles 28–29 and 38–40 (cac.gov.cn), retrieved 2026-10-10
Providing real-time communication to users in China is a licensed value-added telecom business. Under the Measures for the Administration of Telecommunications Business Licensing (电信业务经营许可管理办法, MIIT Order No. 42, in force September 1, 2017), operating a value-added telecom service requires a Value-Added Telecommunications Business License (增值电信业务经营许可证); China's foreign-investment telecom rules mean a foreign API cannot hold it directly, so the real-time service must run through a licensed in-country operator. Measures for the Administration of Telecommunications Business Licensing, MIIT Order No. 42 (gov.cn), in force 2017-09-01, retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, the question to settle about 100ms is not whether its SDK connects or how quickly a stream starts — it is where your users’ live media and any recordings live, who may lawfully provide real-time communication to users in China, and whether the app that embeds it is ICP-filed. 100ms is an embeddable real-time video and audio API: you wire in its SDK and the media runs on its own global infrastructure. On its Security page, 100ms states that its core databases sit in the United States, Europe, and India — there is no mainland-China region — so participant streams, recordings, and identifiers are carried and stored offshore. Four things decide the compliance risk: a value-added telecom license a foreign API cannot hold, media and recording residency (a recording is a voiceprint and a face — sensitive biometric personal information under PIPL Article 28), the cross-border transfer of participant personal information and content, and in-country storage for a critical information infrastructure operator or high-volume handler.

100ms's own Security page stating that customers can choose where their data is stored and that 100ms has core databases set up in the United States of America, Europe and India — with no mainland-China region listed — and that it never records audio-video streams unless the client explicitly asks
“We have core databases setup in United States of America, Europe and India.” 100ms's own Security page lists no mainland-China region — media runs on its global infrastructure (GCP and AWS), so participant streams and recordings are carried and stored offshore. Source: 100ms — Security

100ms in China at a glance

What decides it In 100ms's own terms — and China's law
What it carries 100ms carries your users' live audio and video streams, session metadata (who joined a room, when), and participant identifiers. Its recording and RTMP/HLS features and its auto-generated live transcription produce recordings and transcripts — all participant personal information. A recording captures the speaker's voiceprint and the participants' faces, which is sensitive biometric personal information under PIPL Article 28 and cannot be anonymized away.
Where it runs On its own Security page 100ms states its core databases are in the United States, Europe, and India, with production on GCP and AWS — there is no mainland-China region. Run for users in China, carrying that live media, those recordings, and identifiers offshore is a cross-border transfer under PIPL (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism.
The telecom-licensing door Providing real-time voice and video communication capability to users in mainland China is a value-added telecommunications business that needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) under the Telecommunications Business Licensing Measures (MIIT Order No. 42). A foreign API cannot hold it directly; the lawful route runs the real-time service through a licensed in-country operator.
Recording consent & residency Because a recording is biometric, it needs separate, specific consent and a prior impact assessment (PIPL Articles 28 and 29) — and, being biometric, cannot be anonymized. Where the app's operator is a critical information infrastructure operator or high-volume handler, mainland-collected personal information must stay in the mainland (Cybersecurity Law Article 39 (formerly Article 37)).
The lawful path Reachability was never the axis. Route the real-time service through a licensed in-country operator, keep China-participant media and recordings in-country, get the Article 28/29 consent, and deliver the ICP-filed app in-country. 21YunBox maps that path and delivers the app — on telecom its role is advisory: it does not hold a China telecom license.

What you actually carry — live media, recordings and identifiers

Embedding 100ms means handing it your users’ live audio and video. The SDK carries the real-time streams between participants, along with the session metadata that frames them — who joined a room, when, and from where — and the participant identifiers your app attaches. None of that is anonymous: a live stream of a person in Shanghai, and the identifier tied to their account, is that person’s personal information.

The recordings are where the exposure sharpens. 100ms ships recording across modes — each peer’s tracks, each peer’s combined stream, or a single composite (“Record as a single composed asset combining media tracks of all peers in the room”) — delivered over RTMP and HLS. A recording of a call is not just content: it captures the speaker’s voiceprint and the participants’ faces, and a voiceprint and a face are sensitive biometric personal information under PIPL Article 28, which cannot be anonymized away. 100ms states on its Security page that it “never stores, or records audio-video or data streams unless the client explicitly asks 100ms to store recordings,” and that “in the most common configuration, recordings are uploaded directly to the customer’s storage bucket” — so the recording decision, and where those biometric files land, sit with you.

On top of the media, 100ms offers “auto-generated live transcription in English” (in beta), which turns participants’ speech into transcripts carried in the HLS stream. A transcript is participant content and personal information in its own right; and where a built-in AI feature scores or makes decisions about individual users, PIPL Article 24 (automated decision-making) attaches. If your rooms carry user-generated audio, video, or chat, you also take on content-management and moderation duties for a China-facing service. All of this is processed on 100ms’s own infrastructure, which — per its Security page — runs core databases in the United States, Europe, and India, on GCP and AWS, with no mainland-China region.

The first door is a license, and it is the one a foreign API cannot open for you. Providing real-time voice and video communication capability to users in mainland China is a value-added telecommunications business. Under the Measures for the Administration of Telecommunications Business Licensing (电信业务经营许可管理办法, MIIT Order No. 42, in force September 1, 2017), operating a value-added telecom service requires a Value-Added Telecommunications Business License (增值电信业务经营许可证), and China’s foreign-investment telecom rules mean a foreign API provider cannot hold that license directly. The lawful route is to run the real-time service through a licensed in-country operator — the vendor does not become your telecom licensee by virtue of shipping an SDK.

The second door is the data. Routing your China participants’ live media, recordings, identifiers, chat content, and call metadata to 100ms’s offshore servers is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the operator of the app, not only the vendor: Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use the service, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Where the operator is a critical information infrastructure operator or processes personal information above the state-set threshold, the mainland-collected personal information must be stored in the mainland — the data-localization duty the Cybersecurity Law sets in its Article 39 (formerly Article 37, renumbered by the 2025 amendment in force January 1, 2026, with the substance unchanged).

The third door is consent for the recordings specifically. Because a recording captures a voiceprint and a face, it is sensitive biometric personal information under PIPL: Article 28 requires a specific purpose and demonstrated necessity, Article 29 requires separate, specific consent, and a prior personal-information protection impact assessment is required. Being biometric, it cannot be de-identified into something outside the rules. None of these three doors turns on how quickly a stream connects; they turn on who may lawfully provide the service, whether the media had a lawful basis to leave the country, and whether the recordings had the consent they require.

Reaching the endpoint isn’t the question — a compliant in-country real-time path is

Because a foreign API cannot hold the China telecom license and runs no mainland-China region, the productive question is not how to make 100ms’s media servers respond from Beijing — it is how to run real-time communication for your China users lawfully. That path has a shape. Route the real-time service through a licensed in-country operator that holds the value-added telecom license; keep the China participants’ media and any recordings on an in-country path rather than carrying them to the US, EU, or India region; obtain the Article 28/29 consent before you record; and deliver the app that embeds the SDK on an ICP-filed footing in-country. This is the opposite of a tunnel that ships the media offshore anyway — localizing means the live media and recordings stay on an in-country path, not that an offshore server is made to answer.

On the telecom and licensing leg, be clear about the limits of any vendor’s role: 21YunBox is advisory there — it does not hold a China telecom license and is not a telecom operator; the license and the carrier relationship sit with a licensed in-country operator and your counsel. Which obligations actually bind you — telecom category, CIIO status, transfer mechanism, consent basis — turns on your entity, your volumes, and what your app does. Treat this page as a risk map, not a verdict, and settle the specifics with counsel.

The lawful path — map, localize, deliver

There is a lawful way to run real-time video and audio for your users in China, and it does not run through the offshore API endpoint. It runs through a licensed in-country operator, an in-country media path, the consent the recordings require, and a China-facing app that is itself licensed and served in-country — in front of the stack you already run, with no rebuild. 21YunBox does three things on that footing.

Map. We inventory what your 100ms integration carries — the live audio and video, any recordings and transcripts (voiceprint and face: sensitive biometric personal information), the participant identifiers, chat content, and session metadata — where it is processed and stored (offshore: the US, EU, or India region, with no mainland-China option), whether the built-in transcription or any AI feature scores users, and the consent basis for recording, so you know exactly what counsel and a licensed in-country operator need to confirm.

Localize / govern. We help you route the real-time service through a licensed in-country operator and keep China-participant media and recordings on an in-country path; minimize and pseudonymize the participant data; secure the Article 28/29 consent for recordings and the Article 13/23 consent for processing; and moderate user-generated content. On the telecom-licensing leg our role is advisory: 21YunBox does not hold or imply a China telecom license. Localizing means keeping the media in-country — never a tunnel that ships it offshore anyway.

Deliver. The app that embeds the SDK is a public internet service with an ICP filing duty; we deliver it in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of the product you already run, so it runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. 21YunBox is a compliant overlay and partner, advisory on telecom licensing, not a competitor to the real-time communication vendor.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does 100ms work in mainland China?
Reachability is not the deciding question. 100ms is a foreign real-time video and audio API with no mainland-China region — its Security page lists core databases in the United States, Europe and India — so your China users' live media, recordings and identifiers are carried and stored offshore. That makes three things decisive: providing real-time communication to users in China is a value-added telecom business a foreign API cannot license; carrying the media and recordings offshore is a PIPL cross-border transfer (Articles 38–40); and a recording captures a voiceprint and a face, which is sensitive biometric personal information under PIPL Article 28. The lawful path runs the real-time service through a licensed in-country operator, keeps the media and recordings in-country, gets the Article 28/29 consent, and ICP-files the app. Confirm the specifics with counsel.
Where does 100ms store recordings and call media, and why does it matter for China users?
100ms runs its core databases in the United States, Europe and India, with production on GCP and AWS, and states it “never stores, or records audio-video or data streams unless the client explicitly asks 100ms to store recordings,” with recordings in the common case “uploaded directly to the customer's storage bucket.” For users in China this still matters: the live media and any recordings are carried on offshore infrastructure with no mainland-China region, which is a PIPL cross-border transfer; and a recording captures the speaker's voiceprint and the participants' faces — sensitive biometric personal information under PIPL Article 28 that needs separate consent (Article 29) and cannot be anonymized. For a critical information infrastructure operator or high-volume handler, mainland-collected personal information must stay in the mainland (Cybersecurity Law Article 39, formerly Article 37).
What is the lawful way to run 100ms's real-time features for users in China?
Route the real-time service through a licensed in-country operator that holds the value-added telecom license — a foreign API cannot hold it directly — keep the China participants' media and any recordings on an in-country path rather than carrying them to the US, EU or India region, obtain the Article 28/29 consent before recording, and deliver the app that embeds the SDK on ICP-filed infrastructure in-country. 21YunBox maps the exposure, localizes the China leg onto that in-country path, and delivers the app — in front of the stack you already run, with no rebuild. On telecom licensing our role is advisory: 21YunBox does not hold a China telecom license. This is keeping the media in-country, never a tunnel that ships it offshore. Treat it as a risk map and settle the specifics with counsel.

ARTICLES RELATED TO 100MS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.