Does Airwallex Work in China? A China Payment License, Data Residency & PIPL Cross-Border
Airwallex is unusual among foreign payment platforms: it holds a payment license inside mainland China — its own newsroom says it "is now a third-party payment provider in China" — so the licensing gate that stops an offshore-only provider is, at the entity level, one Airwallex has walked through. That turns the China question into a data-residency one: Airwallex states its customer data is held in the United States, Singapore and the Netherlands, so the payer and transaction personal information it holds for a China-facing flow rests offshore — a cross-border transfer under PIPL with in-country storage duties for some handlers — while the China-facing checkout itself still needs an ICP filing. A compliance-first look at the licensing nuance, the data-residency door, and the lawful in-country path.
Does Airwallex work in China?
Unusually for a foreign payment platform, yes — Airwallex holds a payment license inside mainland China, so the licensing gate that stops an offshore-only provider is one it has, at the entity level, already walked through. Airwallex's newsroom says it “has secured a payment business license in China” and “is now a third-party payment provider in China,” and its licensing page names its People's Bank of China–licensed China entity. So “can it operate in China” is largely answered — which moves the real decision somewhere else.
That somewhere is data residency. Airwallex states that its customer data is “held in the United States, Singapore, and the Netherlands” — mainland China is not among them — so the payer and transaction personal information it holds for a China-facing flow rests offshore. A mainland payer's identity and financial-account details are personal information (financial-account data is sensitive PI), so holding or moving them offshore is a cross-border transfer under PIPL (Articles 38–40: notice, a separate consent, a transfer mechanism), with domestic-storage duties under the payment rules (Order No. 768, Articles 19 and 33) and the Cybersecurity Law Article 39 (formerly Article 37) for some handlers. And which Airwallex licence and entity cover your particular flow is itself flow-specific.
21YunBox is not a payment institution and holds no China payment license — Airwallex's licensed rails stay where they serve you. What we do is map which licence, entity and data path your China leg needs, keep the China-resident payer and transaction data on a consented in-country footing where it must stay, and deliver the China-facing checkout or portal in-country on ICP-filed infrastructure — never any form of circumvention. Treat the specifics as a risk to confirm with counsel.
What Airwallex's own documentation says about China
| Fact | Primary source |
|---|---|
| Airwallex holds a China payment license — obtained via acquisition. Airwallex's newsroom states: “Airwallex has secured a payment business license in China, following the successful acquisition of a 100% stake in Guangzhou Shang Wu Tong Network Technology Co., Ltd.,” and that “With this license, Airwallex is now a third-party payment provider in China and has greater access into the local market.” | Airwallex, “Airwallex secures China Online Payment License” newsroom post (airwallex.com), published 2023-03-07, retrieved 2026-10-09 |
| Its China entity is PBOC-licensed for a defined scope. Airwallex's licensing page states: “Yunhui Pay Co. Ltd is licensed in the People's Republic of China as a payment company with permission to conduct Stored Value Account Operation - Type I services under a license issued by the People's Bank of China (license number Z2025844000016).” The licence has a specific scope, so which flow it covers is flow-specific. | Airwallex Help Center, “How is Airwallex licensed and regulated?” (help.airwallex.com), retrieved 2026-10-09 |
| Airwallex states its customer data is held offshore — not in the mainland. On its “Is Airwallex safe?” page Airwallex states: “Customer data is held in the United States, Singapore, and the Netherlands, and we comply with US federal requirements with respect to China and Hong Kong access to US sensitive personal information.” Mainland China is not among the named storage locations, so payer and transaction personal information for a China-facing flow rests outside the mainland. | Airwallex, “Is Airwallex safe?” (airwallex.com), published 2025-01-31, retrieved 2026-10-09 |
| Payer and transaction data carry cross-border and residency duties. Sending a mainland payer's identity and financial-account data offshore is a PIPL cross-border transfer (Articles 38–40: notice, a separate consent, a transfer mechanism). State Council Order No. 768 requires domestic processing, settlement and storage for domestic transactions (Article 19), and in-China storage of personal information for CII operators and large-volume handlers (Article 33); the Cybersecurity Law sets the same localization duty for critical information infrastructure at Article 39 (formerly Article 37). | Regulations on the Supervision and Administration of Non-Bank Payment Institutions, State Council Order No. 768, Arts. 19 & 33 (gov.cn); Personal Information Protection Law, Arts. 38–40 (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a product serving mainland China, Airwallex is a different case from most foreign payment platforms, and the difference is worth stating plainly before anything else. Airwallex is not shut out of China, and it is not merely an offshore tool for accepting Chinese wallets from abroad: it holds a payment license inside the mainland. In its own newsroom Airwallex says it “has secured a payment business license in China,” obtained “following the successful acquisition of a 100% stake in Guangzhou Shang Wu Tong Network Technology Co., Ltd.,” and that “with this license, Airwallex is now a third-party payment provider in China and has greater access into the local market.” Its licensing page names the China-licensed entity it operates today — “Yunhui Pay Co. Ltd” — as holding a People’s Bank of China license for “Stored Value Account Operation - Type I services.” So the payment-licensing gate that stops an offshore-only provider is, at the entity level, one Airwallex has already walked through.
That is exactly why the China question for Airwallex is not “can it operate here” — it demonstrably can — but a narrower and sharper one: for your specific China-facing flow, which licence and which entity actually serve the China leg, and where does the payer and transaction data come to rest. On that second point Airwallex’s own answer sends the decision offshore. It states that customer data is held in the United States, Singapore and the Netherlands — none of them the mainland. The axis, in other words, is data residency and cross-border personal-information transfer, not milliseconds. Nothing that follows is a verdict that Airwallex is “blocked” or “illegal” in China; it is a map of where the real compliance risk actually sits.
Airwallex in China at a glance
| What decides it | In Airwallex's own terms — and China's law |
|---|---|
| What it is | A cross-border payments and financial-operations platform — global collection (including CNY), FX, payouts, multi-currency accounts, and payment acceptance. Unusually for a foreign provider, it runs licensed capability inside the mainland, not only from offshore. |
| Is it licensed in mainland China? | Yes. Airwallex says it “has secured a payment business license in China” after acquiring “a 100% stake in Guangzhou Shang Wu Tong Network Technology Co., Ltd.,” and that it “is now a third-party payment provider in China.” Its licensing page names “Yunhui Pay Co. Ltd” as licensed by the People's Bank of China for “Stored Value Account Operation - Type I services” (license number Z2025844000016). |
| What its China rails actually do | Its docs describe “local CNY payouts to your own business account, UBO or third-party suppliers” over UnionPay / NUCC rails, capped at “4,999,999 CNY” per local transfer, for cross-border e-commerce where “the corresponding goods sold need to be exported from China,” and which “must be supported by declarant information and relevant order information.” The capability is real but defined — not a blanket licence for any China money movement. |
| Where the payer & transaction data lives | Offshore. Airwallex states “Customer data is held in the United States, Singapore, and the Netherlands.” A mainland payer's identity, financial-account details and order records are personal information — financial-account data is sensitive personal information — so holding or moving them offshore is a cross-border transfer under PIPL (Articles 38–40), with in-country storage duties for some handlers. |
| Serving the public in China | The China-facing checkout, portal or app your users actually touch is itself a mainland internet service, so it carries an ICP filing duty and needs compliant in-country delivery — a separate question from whoever holds the payment licence. |
What Airwallex actually has in China — a licence, and defined rails
Start with what is genuinely there, because it is real and it sets Airwallex apart. Airwallex operates a licensed payment entity inside the mainland: its newsroom records that it “secured a payment business license in China” by acquiring Guangzhou Shang Wu Tong Network Technology Co., Ltd. outright, and its current licensing page states that its China entity, “Yunhui Pay Co. Ltd,” is “licensed in the People’s Republic of China as a payment company with permission to conduct Stored Value Account Operation - Type I services under a license issued by the People’s Bank of China.” That is a materially different starting point from an offshore provider that can only accept Chinese wallets cross-border.
But a licence has a scope, and scope is where the nuance lives. Airwallex’s documented China rails are shaped around a specific use: its payout docs say it “supports local CNY payouts to your own business account, UBO or third-party suppliers,” framed around cross-border e-commerce in which “the corresponding goods sold need to be exported from China,” run over UnionPay / NUCC, capped at “4,999,999 CNY” per local transfer, and gated by a declaration requirement — payouts “must be supported by declarant information and relevant order information.” So the licence does not mean “anything you want to do with money in China is covered.” Whether your particular flow — collecting from mainland consumers versus paying out, where your merchant entity sits, which rails and which Airwallex licence it touches — falls inside what that China licence actually authorizes is the first thing to confirm, with counsel and with Airwallex, before you build on it.
The axis that remains — where the payer and transaction data comes to rest
Even once the licensing question is answered for your flow, the data question is separate and it does not go away. A payment is never just an amount: it carries the payer’s name, contact details, card or account identifiers, and an order record tied to a real person — and financial-account information is sensitive personal information under Chinese law. Airwallex’s own statement puts that data offshore: “Customer data is held in the United States, Singapore, and the Netherlands.” For a user in the mainland, moving their personal information to infrastructure outside China is a cross-border transfer under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, alongside the provider: Articles 38–40 require notice, a separate consent distinct from the customer’s agreement to pay, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above the state thresholds, or where the data is “important data,” that transfer may also require China’s data-export security assessment before anything leaves.
Payment law layers a residency duty on top. The Regulations on the Supervision and Administration of Non-Bank Payment Institutions (State Council Order No. 768, in force May 1, 2024) require that, for domestic transactions, transaction processing, fund settlement and data storage be completed within China (Article 19), and that a payment institution which is a critical information infrastructure operator or handles personal information above the state threshold keep that information inside the mainland (Article 33). The same data-localization logic runs through the Cybersecurity Law, whose in-country storage duty for critical information infrastructure now sits at Article 39 (formerly Article 37 — renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged). An offshore store in the US, Singapore or the Netherlands cannot satisfy an in-country storage duty, no matter how the account is configured. Which of these actually bite your product turns on your entity, your volumes, your role under Chinese law and who your users are — a risk to settle with counsel against what you truly collect and store.
The China-facing surface still needs its own licence to be seen — the ICP filing
There is one more gate that sits beneath both the payment licence and the data rules, and it is easy to overlook precisely because Airwallex clears the payment side. The checkout page, customer portal or app that your China users actually load is itself a public internet service provided inside the mainland. Serving it to the public from in-country turns on an ICP filing (备案) bound to a mainland hosting resource — a duty that attaches to the China-facing property, not to the payment provider. Holding a payment licence does not file your storefront, and an offshore-delivered checkout cannot carry an ICP filing. So a compliant China-facing flow needs both: a lawful payment path, and a China-facing surface that is itself licensed and delivered in-country.
None of this adds up to “Airwallex doesn’t work in China.” It works more than most — it is licensed there. The honest reading is narrower: being licensed answers the first gate, and leaves the data-residency gate, the which-licence-covers-which-flow question, and the ICP duty on the surface all still to be worked through. Treat each as a risk to confirm with counsel before your China flow depends on it.
The lawful path — map, localize, deliver
There is a lawful shape for a China-facing flow built on Airwallex, and because Airwallex is genuinely licensed in the mainland it is a gentler shape than for an offshore-only provider: nothing here rips Airwallex out. First, map. Our China team works through which Airwallex licence and entity serve your particular China leg, and where the payer and transaction data must sit — identifying which personal information collected in China has to stay in the country, what may lawfully cross the border, where a data-export security assessment or an in-country storage duty bites, and what your consent and notice flow must cover. The legal conclusions are settled with your counsel and with Airwallex; we build the technical and architectural picture that feeds that decision.
Then localize. Where the China leg must stay in-country, we keep the China-resident payer and transaction data on a consented, in-country footing — stored and processed inside the mainland where the law requires it — while Airwallex’s licensed cross-border rails carry what may lawfully move. The point is not to replace a licensed provider but to put the China-resident data where it belongs and leave the rest where Airwallex already serves you.
Then deliver. The China-facing checkout, portal or app that carries the flow is a public mainland service, so it needs an ICP filing and compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no re-platform. One boundary stated plainly: 21YunBox is not a payment institution and holds no China payment license; the payment licence sits with the licensed provider, and we complement it rather than compete with it. And what we never do — what no one lawfully can — is route you around China’s data-export rules or around any network restriction. We map the path, localize the data that must stay, and deliver the surface in-country; we never use or suggest circumvention of any kind. The result is a China-facing flow that runs legally and compliantly for your users in China.
Related reading:
- China’s Regulations on the Supervision and Administration of Non-Bank Payment Institutions (Order No. 768)
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- How to get an ICP filing for China
