Does 100ms Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
100ms is an embeddable real-time video and audio API: your China users' live media, recordings (voiceprint and face — sensitive biometric) and identifiers ride its offshore infrastructure, with no mainland-China region. Providing real-time comms in China needs a value-added telecom license a foreign API can't hold, and the app needs an ICP filing — a compliance-first look at the telecom-licensing, residency and cross-border exposure.
Does 100ms work in China?
Embedding 100ms for your users in China carries their live media, any recordings (a voiceprint and a face — sensitive biometric) and identifiers to an offshore API with no mainland-China region; providing real-time communication in China needs a value-added telecom license a foreign API can't hold, and the app itself needs an ICP filing.
100ms carries live audio and video, session metadata and participant identifiers, and its recording, RTMP/HLS and live-transcription features produce recordings and transcripts — a recording captures the speaker's voiceprint and the participants' faces, which is sensitive biometric personal information under PIPL Article 28. Its own Security page lists core databases in the United States, Europe and India and no mainland-China region, so running it for China users is a PIPL cross-border transfer (Articles 38–40). The lawful lever is to route the real-time service through a licensed in-country operator, keep the media and recordings in-country, get the Article 28/29 consent and ICP-file the app — not to make the offshore endpoint reachable (21YunBox is advisory on telecom licensing).
This is a risk map, not a verdict — settle the telecom, residency and consent specifics with counsel. Our China team can map your exposure →
What 100ms's own documentation says about China
| Fact | Primary source |
|---|---|
| 100ms has no mainland-China region — its core databases are in the US, Europe and India. Its Security page states: “Our customers have the option to choose where their data is stored. We have core databases setup in United States of America, Europe and India,” with production “hosted on multiple secure cloud services platforms, including Google Cloud Platform (GCP), Amazon Web Services (AWS).” For users in China, participant media, recordings and identifiers are therefore carried and stored offshore. | 100ms, Security (100ms.live), retrieved 2026-10-10 |
| 100ms records audio and video and auto-transcribes calls — producing biometric data and transcripts. Its recording feature captures each peer's tracks, each peer's combined stream, or a single composite (“Record as a single composed asset combining media tracks of all peers in the room”), delivered over RTMP and HLS, and it offers “auto-generated live transcription in English” (beta). A recording captures voiceprints and faces — sensitive biometric personal information under PIPL Article 28. | 100ms Docs — Recordings overview and Live transcription (100ms.live), retrieved 2026-10-10 |
| Carrying China participant media offshore is a PIPL cross-border transfer, and recordings are sensitive biometric data. A voiceprint and a face are sensitive personal information (PIPL Article 28), needing separate, specific consent and a prior impact assessment (Article 29) and resisting anonymization; routing participant streams, identifiers and content to offshore servers is a cross-border transfer under Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). | Personal Information Protection Law of the PRC, Articles 28–29 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| Providing real-time communication to users in China is a licensed value-added telecom business. Under the Measures for the Administration of Telecommunications Business Licensing (电信业务经营许可管理办法, MIIT Order No. 42, in force September 1, 2017), operating a value-added telecom service requires a Value-Added Telecommunications Business License (增值电信业务经营许可证); China's foreign-investment telecom rules mean a foreign API cannot hold it directly, so the real-time service must run through a licensed in-country operator. | Measures for the Administration of Telecommunications Business Licensing, MIIT Order No. 42 (gov.cn), in force 2017-09-01, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question to settle about 100ms is not whether its SDK connects or how quickly a stream starts — it is where your users’ live media and any recordings live, who may lawfully provide real-time communication to users in China, and whether the app that embeds it is ICP-filed. 100ms is an embeddable real-time video and audio API: you wire in its SDK and the media runs on its own global infrastructure. On its Security page, 100ms states that its core databases sit in the United States, Europe, and India — there is no mainland-China region — so participant streams, recordings, and identifiers are carried and stored offshore. Four things decide the compliance risk: a value-added telecom license a foreign API cannot hold, media and recording residency (a recording is a voiceprint and a face — sensitive biometric personal information under PIPL Article 28), the cross-border transfer of participant personal information and content, and in-country storage for a critical information infrastructure operator or high-volume handler.
100ms in China at a glance
| What decides it | In 100ms's own terms — and China's law |
|---|---|
| What it carries | 100ms carries your users' live audio and video streams, session metadata (who joined a room, when), and participant identifiers. Its recording and RTMP/HLS features and its auto-generated live transcription produce recordings and transcripts — all participant personal information. A recording captures the speaker's voiceprint and the participants' faces, which is sensitive biometric personal information under PIPL Article 28 and cannot be anonymized away. |
| Where it runs | On its own Security page 100ms states its core databases are in the United States, Europe, and India, with production on GCP and AWS — there is no mainland-China region. Run for users in China, carrying that live media, those recordings, and identifiers offshore is a cross-border transfer under PIPL (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism. |
| The telecom-licensing door | Providing real-time voice and video communication capability to users in mainland China is a value-added telecommunications business that needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) under the Telecommunications Business Licensing Measures (MIIT Order No. 42). A foreign API cannot hold it directly; the lawful route runs the real-time service through a licensed in-country operator. |
| Recording consent & residency | Because a recording is biometric, it needs separate, specific consent and a prior impact assessment (PIPL Articles 28 and 29) — and, being biometric, cannot be anonymized. Where the app's operator is a critical information infrastructure operator or high-volume handler, mainland-collected personal information must stay in the mainland (Cybersecurity Law Article 39 (formerly Article 37)). |
| The lawful path | Reachability was never the axis. Route the real-time service through a licensed in-country operator, keep China-participant media and recordings in-country, get the Article 28/29 consent, and deliver the ICP-filed app in-country. 21YunBox maps that path and delivers the app — on telecom its role is advisory: it does not hold a China telecom license. |
What you actually carry — live media, recordings and identifiers
Embedding 100ms means handing it your users’ live audio and video. The SDK carries the real-time streams between participants, along with the session metadata that frames them — who joined a room, when, and from where — and the participant identifiers your app attaches. None of that is anonymous: a live stream of a person in Shanghai, and the identifier tied to their account, is that person’s personal information.
The recordings are where the exposure sharpens. 100ms ships recording across modes — each peer’s tracks, each peer’s combined stream, or a single composite (“Record as a single composed asset combining media tracks of all peers in the room”) — delivered over RTMP and HLS. A recording of a call is not just content: it captures the speaker’s voiceprint and the participants’ faces, and a voiceprint and a face are sensitive biometric personal information under PIPL Article 28, which cannot be anonymized away. 100ms states on its Security page that it “never stores, or records audio-video or data streams unless the client explicitly asks 100ms to store recordings,” and that “in the most common configuration, recordings are uploaded directly to the customer’s storage bucket” — so the recording decision, and where those biometric files land, sit with you.
On top of the media, 100ms offers “auto-generated live transcription in English” (in beta), which turns participants’ speech into transcripts carried in the HLS stream. A transcript is participant content and personal information in its own right; and where a built-in AI feature scores or makes decisions about individual users, PIPL Article 24 (automated decision-making) attaches. If your rooms carry user-generated audio, video, or chat, you also take on content-management and moderation duties for a China-facing service. All of this is processed on 100ms’s own infrastructure, which — per its Security page — runs core databases in the United States, Europe, and India, on GCP and AWS, with no mainland-China region.
Three doors: a telecom license, cross-border media, and recording consent
The first door is a license, and it is the one a foreign API cannot open for you. Providing real-time voice and video communication capability to users in mainland China is a value-added telecommunications business. Under the Measures for the Administration of Telecommunications Business Licensing (电信业务经营许可管理办法, MIIT Order No. 42, in force September 1, 2017), operating a value-added telecom service requires a Value-Added Telecommunications Business License (增值电信业务经营许可证), and China’s foreign-investment telecom rules mean a foreign API provider cannot hold that license directly. The lawful route is to run the real-time service through a licensed in-country operator — the vendor does not become your telecom licensee by virtue of shipping an SDK.
The second door is the data. Routing your China participants’ live media, recordings, identifiers, chat content, and call metadata to 100ms’s offshore servers is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the operator of the app, not only the vendor: Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use the service, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Where the operator is a critical information infrastructure operator or processes personal information above the state-set threshold, the mainland-collected personal information must be stored in the mainland — the data-localization duty the Cybersecurity Law sets in its Article 39 (formerly Article 37, renumbered by the 2025 amendment in force January 1, 2026, with the substance unchanged).
The third door is consent for the recordings specifically. Because a recording captures a voiceprint and a face, it is sensitive biometric personal information under PIPL: Article 28 requires a specific purpose and demonstrated necessity, Article 29 requires separate, specific consent, and a prior personal-information protection impact assessment is required. Being biometric, it cannot be de-identified into something outside the rules. None of these three doors turns on how quickly a stream connects; they turn on who may lawfully provide the service, whether the media had a lawful basis to leave the country, and whether the recordings had the consent they require.
Reaching the endpoint isn’t the question — a compliant in-country real-time path is
Because a foreign API cannot hold the China telecom license and runs no mainland-China region, the productive question is not how to make 100ms’s media servers respond from Beijing — it is how to run real-time communication for your China users lawfully. That path has a shape. Route the real-time service through a licensed in-country operator that holds the value-added telecom license; keep the China participants’ media and any recordings on an in-country path rather than carrying them to the US, EU, or India region; obtain the Article 28/29 consent before you record; and deliver the app that embeds the SDK on an ICP-filed footing in-country. This is the opposite of a tunnel that ships the media offshore anyway — localizing means the live media and recordings stay on an in-country path, not that an offshore server is made to answer.
On the telecom and licensing leg, be clear about the limits of any vendor’s role: 21YunBox is advisory there — it does not hold a China telecom license and is not a telecom operator; the license and the carrier relationship sit with a licensed in-country operator and your counsel. Which obligations actually bind you — telecom category, CIIO status, transfer mechanism, consent basis — turns on your entity, your volumes, and what your app does. Treat this page as a risk map, not a verdict, and settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a lawful way to run real-time video and audio for your users in China, and it does not run through the offshore API endpoint. It runs through a licensed in-country operator, an in-country media path, the consent the recordings require, and a China-facing app that is itself licensed and served in-country — in front of the stack you already run, with no rebuild. 21YunBox does three things on that footing.
Map. We inventory what your 100ms integration carries — the live audio and video, any recordings and transcripts (voiceprint and face: sensitive biometric personal information), the participant identifiers, chat content, and session metadata — where it is processed and stored (offshore: the US, EU, or India region, with no mainland-China option), whether the built-in transcription or any AI feature scores users, and the consent basis for recording, so you know exactly what counsel and a licensed in-country operator need to confirm.
Localize / govern. We help you route the real-time service through a licensed in-country operator and keep China-participant media and recordings on an in-country path; minimize and pseudonymize the participant data; secure the Article 28/29 consent for recordings and the Article 13/23 consent for processing; and moderate user-generated content. On the telecom-licensing leg our role is advisory: 21YunBox does not hold or imply a China telecom license. Localizing means keeping the media in-country — never a tunnel that ships it offshore anyway.
Deliver. The app that embeds the SDK is a public internet service with an ICP filing duty; we deliver it in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of the product you already run, so it runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. 21YunBox is a compliant overlay and partner, advisory on telecom licensing, not a competitor to the real-time communication vendor.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
