Does 1Password Work in China? Data Residency, PIPL Cross-Border & Where Your Secrets Live
1Password holds the most sensitive data your organization has — the passwords, passkeys, API keys and secrets that unlock your China systems, plus the account identities of your China employees. Its own documentation offers only three hosting regions — the United States, Canada and the European Union — none in mainland China, so all of it rests offshore, making its storage a cross-border transfer of personal information under PIPL (数据出境). A compliance-first look at the data-residency and cross-border questions — and the lawful, in-country path.
Does 1Password work in China?
1Password holds the most sensitive data your organization has — the passwords, passkeys, API keys and secrets that unlock your China systems, plus the account identities of your China employees. So the China question is not whether the app opens; it is where all of that comes to rest, and whether it was allowed to leave the country.
1Password's own “Choose your region” page offers exactly three hosting regions — the United States, Canada and the European Union — and none is in mainland China. That places your China users' vault data and account identities offshore, which makes their storage a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40: notice, a separate consent, and one transfer mechanism), and because 1Password says “your data stays in the region you choose” and is “never automatically moved from one region to another,” no setting keeps it in China. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet, and secrets sensitive enough to run your China systems can raise China's data-export security assessment.
End-to-end encryption means 1Password's staff can't read your items — a real security control, but not one that changes where the data rests or discharges these duties. 21YunBox maps your cross-border and residency exposure, localizes the China secrets and account data onto a China-resident footing, and delivers any China-facing surface in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.
What 1Password's own documentation says about China
| Fact | Primary source |
|---|---|
| 1Password offers exactly three hosting regions — the US, Canada and the EU — with no mainland-China region. Its “Choose your region” support page states, “You can create your 1Password account in one of three different regions,” and maps each to where data is hosted: 1Password.com to the United States, 1Password.ca to Canada, and 1Password.eu to the European Union. China is named nowhere on the page, so the vaults and account identities you keep for your China users rest offshore. | 1Password, “Choose your region” (support.1password.com), retrieved 2026-10-09 |
| The region is fixed, and no setting relocates your data into China. 1Password states that “your data stays in the region you choose” and “is never automatically moved from one region to another,” and that changing region means creating a new account elsewhere and migrating by hand. Switching from the US region to the EU merely moves the cross-border transfer; it does not bring the data into the mainland. | 1Password, “Choose your region” (support.1password.com), retrieved 2026-10-09 |
| End-to-end encryption is a security control, not a residency fix. 1Password states that “regardless of your region, 1Password staff can’t access your saved logins or other items.” That zero-knowledge design governs who can read the data — but it does not change the country the data sits in, nor discharge the PIPL duties that attach when personal information collected in China is stored offshore. | 1Password, “Choose your region” (support.1password.com), retrieved 2026-10-09 |
| China-collected account and vault data sent to an offshore region is a PIPL cross-border transfer. Moving personal information collected from users in mainland China to a 1Password account hosted in the US, Canada or the EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The duty sits with the handler (you), not the processor. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
Ask whether 1Password “works” in mainland China and the honest answer redirects the question. A password manager is reachable or not like any app, but reachability is not what settles it here. 1Password is the vault for the most sensitive things your company keeps — the passwords, passkeys, API keys and recovery secrets that open your systems, and an account identity for every employee you add to it. For a China operation the decision turns on where that vault physically lives, and whether the law allowed those credentials and identities to leave the country at all. 1Password answers the “where” in its own documentation, and the answer is: not in China.
1Password in China at a glance
| What decides it | In 1Password's own terms — and China's law |
|---|---|
| What it holds | 1Password is a password and secrets manager. Its vaults hold the passwords, passkeys, API keys and recovery secrets that unlock your systems, plus an account identity for every user you add — so it concentrates your most sensitive credential data, and personal information about your China employees, in one hosted service. |
| Where the data is hosted | 1Password's “Choose your region” page offers exactly three regions — the United States (1Password.com), Canada (1Password.ca) and the European Union (1Password.eu). None is in mainland China, and “your data stays in the region you choose.” |
| Account data crossing the border | The identities, email addresses, group and vault membership and access records 1Password keeps about your China users are personal information. Held in a US, Canadian or EU region, they are a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. |
| End-to-end encryption | 1Password says that “regardless of your region, 1Password staff can’t access your saved logins or other items.” That zero-knowledge design is a genuine security control — but it does not change the country the data rests in, nor discharge the PIPL duties that attach to moving it offshore. |
| The secrets themselves | These vaults hold the keys to your China systems, not just contact details. For a CIIO or large-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires in-country storage an offshore region can't meet; whether any secret rises to “important data” that triggers a data-export security assessment (数据出境安全评估) is fact-specific — a question for counsel. |
| The lawful path | Keep the China entity's secrets and account data on a China-resident footing, send offshore only what may lawfully leave, and deliver any China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention. |
Every region 1Password offers is offshore
1Password’s position is set on its own “Choose your region” support page, not by a connection test. It offers your account one of three regions — the United States (1Password.com), Canada (1Password.ca) or the European Union (1Password.eu) — and tells you plainly that “your data stays in the region you choose” and “is never automatically moved from one region to another.” There is no mainland-China region on that list, and no fourth option to request.
So wherever your organization signed up, the vaults that hold your China team’s credentials — and the account record of who those people are — sit in the US, Canada or the EU. That single fact settles the China questions that follow, well before performance ever enters the picture.
Storing it offshore is a cross-border transfer — even end-to-end encrypted
Start with what 1Password necessarily holds about people, not only their passwords: the email addresses, names, group and vault membership, device records and access logs it keeps to run your account. For your users in China that is personal information, and holding it in a US, Canadian or EU region is a cross-border transfer under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization, not 1Password the processor — and Articles 38–40 require notice, a separate consent distinct from any general terms of use, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification.
1Password will point out, correctly, that it cannot read your vaults — “regardless of your region, 1Password staff can’t access your saved logins or other items.” Its end-to-end, zero-knowledge design is a real strength, and China’s law positively encourages strong technical safeguards. But encryption answers a different question from residency. It governs who can read the data; it does not change the country the data sits in, and it does not discharge the notice, consent and transfer-mechanism duties that attach the moment personal information collected in China comes to rest offshore. A locked box in Frankfurt is still a box in Frankfurt.
Two further duties can bite depending on who you are and what you store. If your organization is a critical information infrastructure operator, or moves personal information at volume, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China, which an offshore 1Password region cannot do. And because these particular vaults hold the keys to your China systems rather than ordinary contact details, the sensitivity of what is leaving is unusually high: whether any of it rises to “important data” that triggers China’s data-export security assessment (数据出境安全评估) before it may leave is fact-specific, and exactly the kind of question to put to counsel rather than assume away.
”Pick a different region” doesn’t reach the mainland
The instinct is to flip the account to a region that keeps the data closer. But the only regions 1Password offers are the United States, Canada and the European Union — none in mainland China — so none resolves a China residency duty; moving a China team from the US region to the EU region simply relocates the cross-border transfer, it does not end it. And 1Password is explicit that the region is fixed once set: data “is never automatically moved from one region to another,” and changing it means standing up a new account in the new region and migrating by hand. There is no setting that puts your China credentials inside China.
Keeping them in-country is a different exercise — a consented, China-resident place for the China entity’s secrets and account data, with only what may lawfully leave going abroad — and that is a legal design before it is a technical one.
None of this says 1Password is “blocked” or “illegal.” It is a risk map: which duties apply turns on your entity, your role under Chinese law, the data your vaults actually hold, and who your users are. Whether the apps sync smoothly from the mainland is an operational matter that can vary — and it is never something to “solve” with any form of circumvention, which is both a compliance risk and beside the point. The productive question is how to keep the China credentials and identities on a lawful footing, and that is worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
There is a compliant way to run a secrets manager for a China operation, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the account identities and metadata 1Password holds about your China users, and the credential data itself — identifying what must stay in the country, what may lawfully leave, where an Article 39 storage duty or a data-export security assessment bites, and what your consent and notice have to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we stand up a China-resident footing for the China entity’s secrets and account data — a consented, in-country place for what has to stay — so your team keeps a working secrets workflow while that data stops leaving the mainland by default, and you keep 1Password for the markets where it already serves you.
Then deliver: any China-facing surface in your stack — the apps and services that actually consume these secrets, or an in-country provisioning endpoint — is a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a credential and identity layer that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law (data localization, Article 39)
- China’s data-export security assessment
- How to get an ICP filing for China
