Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does 1Password Work in China? Data Residency, PIPL Cross-Border & Where Your Secrets Live

1Password holds the most sensitive data your organization has — the passwords, passkeys, API keys and secrets that unlock your China systems, plus the account identities of your China employees. Its own documentation offers only three hosting regions — the United States, Canada and the European Union — none in mainland China, so all of it rests offshore, making its storage a cross-border transfer of personal information under PIPL (数据出境). A compliance-first look at the data-residency and cross-border questions — and the lawful, in-country path.

Does 1Password work in China?

1Password holds the most sensitive data your organization has — the passwords, passkeys, API keys and secrets that unlock your China systems, plus the account identities of your China employees. So the China question is not whether the app opens; it is where all of that comes to rest, and whether it was allowed to leave the country.

1Password's own “Choose your region” page offers exactly three hosting regions — the United States, Canada and the European Union — and none is in mainland China. That places your China users' vault data and account identities offshore, which makes their storage a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40: notice, a separate consent, and one transfer mechanism), and because 1Password says “your data stays in the region you choose” and is “never automatically moved from one region to another,” no setting keeps it in China. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet, and secrets sensitive enough to run your China systems can raise China's data-export security assessment.

End-to-end encryption means 1Password's staff can't read your items — a real security control, but not one that changes where the data rests or discharges these duties. 21YunBox maps your cross-border and residency exposure, localizes the China secrets and account data onto a China-resident footing, and delivers any China-facing surface in-country on ICP-filed infrastructure — with no rebuild, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What 1Password's own documentation says about China

FactPrimary source
1Password offers exactly three hosting regions — the US, Canada and the EU — with no mainland-China region. Its “Choose your region” support page states, “You can create your 1Password account in one of three different regions,” and maps each to where data is hosted: 1Password.com to the United States, 1Password.ca to Canada, and 1Password.eu to the European Union. China is named nowhere on the page, so the vaults and account identities you keep for your China users rest offshore. 1Password, “Choose your region” (support.1password.com), retrieved 2026-10-09
The region is fixed, and no setting relocates your data into China. 1Password states that “your data stays in the region you choose” and “is never automatically moved from one region to another,” and that changing region means creating a new account elsewhere and migrating by hand. Switching from the US region to the EU merely moves the cross-border transfer; it does not bring the data into the mainland. 1Password, “Choose your region” (support.1password.com), retrieved 2026-10-09
End-to-end encryption is a security control, not a residency fix. 1Password states that “regardless of your region, 1Password staff can’t access your saved logins or other items.” That zero-knowledge design governs who can read the data — but it does not change the country the data sits in, nor discharge the PIPL duties that attach when personal information collected in China is stored offshore. 1Password, “Choose your region” (support.1password.com), retrieved 2026-10-09
China-collected account and vault data sent to an offshore region is a PIPL cross-border transfer. Moving personal information collected from users in mainland China to a 1Password account hosted in the US, Canada or the EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The duty sits with the handler (you), not the processor. Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

Ask whether 1Password “works” in mainland China and the honest answer redirects the question. A password manager is reachable or not like any app, but reachability is not what settles it here. 1Password is the vault for the most sensitive things your company keeps — the passwords, passkeys, API keys and recovery secrets that open your systems, and an account identity for every employee you add to it. For a China operation the decision turns on where that vault physically lives, and whether the law allowed those credentials and identities to leave the country at all. 1Password answers the “where” in its own documentation, and the answer is: not in China.

1Password's Choose your region support page showing its three hosting regions — 1Password.com in the United States, 1Password.ca in Canada, and 1Password.eu in the European Union — with no mainland-China region, and stating that your data stays in the region you choose and is never automatically moved from one region to another
1Password's own “Choose your region” support page offers exactly three places to host your data — the United States, Canada and the European Union — and states: “You can create your 1Password account in one of three different regions,” and “Your data stays in the region you choose. It is never automatically moved from one region to another.” None is in mainland China, so the vaults and account identities it keeps for your China users rest offshore. Source: support.1password.com — Choose your region

1Password in China at a glance

What decides it In 1Password's own terms — and China's law
What it holds 1Password is a password and secrets manager. Its vaults hold the passwords, passkeys, API keys and recovery secrets that unlock your systems, plus an account identity for every user you add — so it concentrates your most sensitive credential data, and personal information about your China employees, in one hosted service.
Where the data is hosted 1Password's “Choose your region” page offers exactly three regions — the United States (1Password.com), Canada (1Password.ca) and the European Union (1Password.eu). None is in mainland China, and “your data stays in the region you choose.”
Account data crossing the border The identities, email addresses, group and vault membership and access records 1Password keeps about your China users are personal information. Held in a US, Canadian or EU region, they are a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism.
End-to-end encryption 1Password says that “regardless of your region, 1Password staff can’t access your saved logins or other items.” That zero-knowledge design is a genuine security control — but it does not change the country the data rests in, nor discharge the PIPL duties that attach to moving it offshore.
The secrets themselves These vaults hold the keys to your China systems, not just contact details. For a CIIO or large-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires in-country storage an offshore region can't meet; whether any secret rises to “important data” that triggers a data-export security assessment (数据出境安全评估) is fact-specific — a question for counsel.
The lawful path Keep the China entity's secrets and account data on a China-resident footing, send offshore only what may lawfully leave, and deliver any China-facing surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention.

Every region 1Password offers is offshore

1Password’s position is set on its own “Choose your region” support page, not by a connection test. It offers your account one of three regions — the United States (1Password.com), Canada (1Password.ca) or the European Union (1Password.eu) — and tells you plainly that “your data stays in the region you choose” and “is never automatically moved from one region to another.” There is no mainland-China region on that list, and no fourth option to request.

So wherever your organization signed up, the vaults that hold your China team’s credentials — and the account record of who those people are — sit in the US, Canada or the EU. That single fact settles the China questions that follow, well before performance ever enters the picture.

Storing it offshore is a cross-border transfer — even end-to-end encrypted

Start with what 1Password necessarily holds about people, not only their passwords: the email addresses, names, group and vault membership, device records and access logs it keeps to run your account. For your users in China that is personal information, and holding it in a US, Canadian or EU region is a cross-border transfer under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization, not 1Password the processor — and Articles 38–40 require notice, a separate consent distinct from any general terms of use, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification.

1Password will point out, correctly, that it cannot read your vaults — “regardless of your region, 1Password staff can’t access your saved logins or other items.” Its end-to-end, zero-knowledge design is a real strength, and China’s law positively encourages strong technical safeguards. But encryption answers a different question from residency. It governs who can read the data; it does not change the country the data sits in, and it does not discharge the notice, consent and transfer-mechanism duties that attach the moment personal information collected in China comes to rest offshore. A locked box in Frankfurt is still a box in Frankfurt.

Two further duties can bite depending on who you are and what you store. If your organization is a critical information infrastructure operator, or moves personal information at volume, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China, which an offshore 1Password region cannot do. And because these particular vaults hold the keys to your China systems rather than ordinary contact details, the sensitivity of what is leaving is unusually high: whether any of it rises to “important data” that triggers China’s data-export security assessment (数据出境安全评估) before it may leave is fact-specific, and exactly the kind of question to put to counsel rather than assume away.

”Pick a different region” doesn’t reach the mainland

The instinct is to flip the account to a region that keeps the data closer. But the only regions 1Password offers are the United States, Canada and the European Union — none in mainland China — so none resolves a China residency duty; moving a China team from the US region to the EU region simply relocates the cross-border transfer, it does not end it. And 1Password is explicit that the region is fixed once set: data “is never automatically moved from one region to another,” and changing it means standing up a new account in the new region and migrating by hand. There is no setting that puts your China credentials inside China.

Keeping them in-country is a different exercise — a consented, China-resident place for the China entity’s secrets and account data, with only what may lawfully leave going abroad — and that is a legal design before it is a technical one.

None of this says 1Password is “blocked” or “illegal.” It is a risk map: which duties apply turns on your entity, your role under Chinese law, the data your vaults actually hold, and who your users are. Whether the apps sync smoothly from the mainland is an operational matter that can vary — and it is never something to “solve” with any form of circumvention, which is both a compliance risk and beside the point. The productive question is how to keep the China credentials and identities on a lawful footing, and that is worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

There is a compliant way to run a secrets manager for a China operation, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the account identities and metadata 1Password holds about your China users, and the credential data itself — identifying what must stay in the country, what may lawfully leave, where an Article 39 storage duty or a data-export security assessment bites, and what your consent and notice have to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up a China-resident footing for the China entity’s secrets and account data — a consented, in-country place for what has to stay — so your team keeps a working secrets workflow while that data stops leaving the mainland by default, and you keep 1Password for the markets where it already serves you.

Then deliver: any China-facing surface in your stack — the apps and services that actually consume these secrets, or an in-country provisioning endpoint — is a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a credential and identity layer that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is 1Password available in mainland China?
1Password is not a service China blocks at the border, so availability is not the real obstacle — the app being reachable does not make the setup compliant. The China question is data residency: 1Password offers only three hosting regions, the United States, Canada and the European Union, with none in mainland China, so the vaults and account identities you keep for your China users rest offshore. Whether the apps sync smoothly from the mainland can vary, but that is an operational matter, not the decision — and the answer is never a network workaround. Treat the specifics as a risk to confirm with counsel.
Is storing our China team's 1Password data offshore a cross-border transfer?
If your account is in the US, Canada or the EU region — anywhere outside the mainland — then the account identities, membership and access records it holds for your China users, together with the vault data itself, are stored offshore, a cross-border transfer (数据出境) under PIPL. That means notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). End-to-end encryption does not change this: it governs who can read the data, not which country it rests in. For a critical information infrastructure operator, Cybersecurity Law Article 39 (formerly Article 37) adds an in-country storage duty an offshore region cannot meet, and sensitive secrets can raise a data-export security assessment. Confirm your exact obligations with counsel.
Can we just choose a different 1Password region to keep the data in China?
No — the only regions 1Password offers are the United States, Canada and the European Union, and none is in mainland China, so none resolves a China residency duty. 1Password also states that data is never automatically moved between regions, so switching merely relocates the cross-border transfer rather than ending it. Keeping China-collected secrets and account data in-country means standing up a consented, China-resident footing for that data and sending offshore only what may lawfully leave, while you keep 1Password for your other markets. 21YunBox maps that split, localizes the in-country data, and delivers any China-facing surface on ICP-filed infrastructure — it is not a route around China's data-export rules.

ARTICLES RELATED TO 1PASSWORD

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.