Does AssemblyAI Work in China? PIPL Cross-Border, Voiceprint Biometrics & Data Residency
The audio you send AssemblyAI to transcribe carries each speaker's voiceprint — Article 28 sensitive biometric personal information you can't anonymize — and it travels to AssemblyAI's offshore AWS servers in the US or EU, never mainland China: a PIPL cross-border transfer. A compliance-first look at transcribing China audio with AssemblyAI.
Does AssemblyAI work in China?
AssemblyAI transcribes your audio on its own AWS servers in the US or EU — never mainland China — so every China recording you send carries the speaker's voiceprint offshore: a PIPL cross-border transfer of sensitive biometric personal information you cannot anonymize.
The question is not whether the API is reachable from China — it is what happens to the audio. A voice recording is the speaker's voiceprint, biometric data PIPL Article 28 treats as sensitive and that you cannot anonymize, and sending it to AssemblyAI's offshore AWS servers is a PIPL cross-border transfer (Articles 38–40); model training is opt-out rather than off by default. The lawful lever is to keep China-origin audio's processing in-country — AssemblyAI offers a self-hosted deployment you can run inside China, or route the audio through a licensed domestic speech service — with the Article 28 separate consent, not to make the offshore endpoint reachable.
What you owe — a separate consent, a transfer mechanism, in-country storage, an ICP filing — is a risk to confirm with counsel. Our China team can map your exposure →
What AssemblyAI's own documentation says about China
| Fact | Primary source |
|---|---|
| AssemblyAI processes audio offshore — AWS US and EU, with no mainland-China region. Its documentation states "Our production server resides in AWS US West 2, AWS EU West 1" (the AWS Oregon and Dublin regions); an EU-residency endpoint exists, but none of its regions is in mainland China, so a China-origin recording is transferred across the border on every job. | AssemblyAI Docs — Where are your servers located? (assemblyai.com), retrieved 2026-10-10 |
| AssemblyAI offers a self-hosted deployment — the in-country lever. It states: "Yes, we offer self-hosted solutions for organizations that require greater control over their data and infrastructure," letting you "deploy our services within your own environment." Run inside China on infrastructure you control, the audio and transcripts need not be exported — though it is an enterprise, contract-based deployment, so confirm the exact data boundary and model parity in writing. | AssemblyAI Docs — Do you offer self-hosted solutions? (assemblyai.com), retrieved 2026-10-10 |
| Model training is opt-out, not off by default. AssemblyAI documents that "Only certain files submitted to the API, as permitted by the applicable contract, are used for model training"; accounts under a Business Associate Addendum, on its European servers, or opted out are excluded, and opted-out Streaming, Sync and Dictation get "zero data retention of audio and transcripts" — but not every account can opt out, and asynchronous uploads otherwise follow a configurable TTL (default deletion of uploaded audio begins at 24 hours). | AssemblyAI Docs — Data Retention and Model Training (assemblyai.com), retrieved 2026-10-10 |
| A voiceprint is sensitive biometric data, and sending it abroad is a PIPL cross-border transfer. PIPL Article 28 treats biometric personal information as sensitive — requiring a specific purpose, strict necessity, a separate consent, and a prior protection impact assessment — and Articles 38–40 govern the export (notice, a separate consent, a transfer mechanism). For a CIIO or high-volume handler, in-country storage attaches under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37). | Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a team that records, transcribes or analyzes calls, meetings, support lines, interviews or voice messages from mainland China, the question about AssemblyAI was never whether its API resolves from the mainland — it generally does. The real question is what happens to the audio you send it. AssemblyAI is a Speech AI company: you upload a recording, or stream live audio, and it ships that audio to its own servers to turn speech into text and to run its Audio Intelligence models — speaker diarization, sentiment analysis, entity detection, PII redaction and the LeMUR/LLM framework over the transcript. By AssemblyAI’s own account its production servers reside in “AWS US West 2, AWS EU West 1” — the AWS Oregon and Dublin regions — with an EU-residency endpoint and no mainland-China region. So every job is a live cross-border transfer of a recording that carries each speaker’s voiceprint, a biometric identifier you cannot anonymize, along with whatever the spoken words reveal. That trips PIPL’s cross-border rules (Articles 38–40, 数据出境), Article 28 for sensitive biometric personal information — a separate consent and a prior protection impact assessment — and, for a CIIO or high-volume handler, a content-residency duty under CSL Article 39.
AssemblyAI in China at a glance
| What decides it | In AssemblyAI's own terms — and China's law |
|---|---|
| What you send to transcribe, and that it carries the speaker's voiceprint | You send raw audio — recorded calls, meetings, support lines, interviews, dictation, voice messages. A recording of a person's voice carries their voiceprint, a biometric identifier, and AssemblyAI's Audio Intelligence (speaker diarization, PII redaction, sentiment, entity detection) derives still more about each speaker and what they said. Tied to people in China, that is personal information under PIPL; a voiceprint is sensitive biometric information under Article 28, and spoken content may add health, financial or ID categories. |
| It is sent offshore — a cross-border transfer | AssemblyAI states its production servers reside in "AWS US West 2, AWS EU West 1" — the Oregon and Dublin regions — and offers an EU-residency endpoint; none of its regions is in mainland China. Streaming or uploading a China-origin recording there is a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (Articles 38–40, 数据出境). |
| A voiceprint is sensitive biometric data — Article 28 | You cannot anonymize a voice — strip the audio and there is nothing to transcribe — so the biometric identifier travels with every job. PIPL Article 28 treats biometric personal information as sensitive: a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment (PIPIA) before it is processed or transferred. |
| Is the audio kept, used to train models — and can it stay in-country? | AssemblyAI documents that "Only certain files submitted to the API, as permitted by the applicable contract, are used for model training"; accounts under a Business Associate Addendum, on its European servers, or opted out are excluded, and opted-out Streaming, Sync and Dictation get "zero data retention of audio and transcripts" — though not every account can opt out. Asynchronous uploads otherwise follow a configurable retention window (TTL), deletion of uploaded audio beginning at 24 hours by default. Crucially, AssemblyAI also offers a self-hosted deployment — the in-country lever below. For a CIIO or high-volume handler, mainland personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. |
| Reaching the API is not the axis | That AssemblyAI resolves and returns a transcript from the mainland is the delivery half, not the answer — a reachable offshore endpoint simply exports more voiceprints. The lawful lever is to keep China-origin audio's processing in-country: run AssemblyAI's self-hosted models inside China, or route China audio through a licensed in-country speech service, with the Article 28 separate consent and data minimization — never a path that ships the audio offshore anyway. The China-facing app or line that captures the audio carries its own ICP filing and in-country delivery. |
What you actually send — your speakers’ voiceprints and words
AssemblyAI is a speech-recognition engine, not a content store: audio goes in through its API, a transcript and structured insights come back, and the exposure is the transfer itself rather than a permanent corpus it keeps about you. It works two ways — pre-recorded (asynchronous) upload and real-time streaming — and layers Audio Intelligence on top: speaker diarization (“who spoke when”), PII redaction, sentiment analysis, entity detection, auto chapters, topic detection and content moderation, plus the LeMUR/LLM Gateway that applies large language models to the transcript. The audio you most need transcribed — recorded support calls, clinical or legal dictation, interviews, meetings — is precisely the audio most likely to carry sensitive content, and every recording carries the speaker’s voiceprint. You can redact a transcript; you cannot anonymize the audio itself.
And it does not stay in China. AssemblyAI documents that its production servers reside in “AWS US West 2, AWS EU West 1” — Oregon and Dublin — and offers an EU-residency endpoint for organizations with strict governance needs; there is no mainland-China region or endpoint to select. For a caller or employee in China, each request is their voice leaving the country in real time.
On retention and training AssemblyAI is specific. Its documentation states that “Only certain files submitted to the API, as permitted by the applicable contract, are used for model training,” that files first pass a step “designed to redact personally identifiable information” (designed to, not guaranteed), and that accounts under a Business Associate Addendum, on its European servers, or that have opted out are excluded from training — though not every account can opt out, and the opt-out reaches only later requests. When you are opted out, AssemblyAI offers “zero data retention of audio and transcripts” for its Streaming, Sync and Dictation products, while “certain metadata … is stored and maintained for logging and billing purposes”; asynchronous uploads otherwise follow a configurable retention window (TTL), with deletion of uploaded audio beginning at 24 hours by default. These controls cut the retention and training exposure; they do not erase the cross-border transfer.
It’s a cross-border transfer of sensitive biometric data — under PIPL
Sending a China-origin recording to AssemblyAI’s servers in the United States or the European Union is a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境). As the handler, you — not AssemblyAI, the processor — must give notice, obtain a separate consent for the export, and put one transfer mechanism in place: a CAC security assessment, the CAC standard contract, or certification.
The voiceprint raises the bar. A recording of a person’s voice is biometric personal information, which PIPL Article 28 classes as sensitive: it requires a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment (PIPIA) before it is processed or transferred. You cannot strip the voice out of audio whose purpose is to be transcribed, so the biometric identifier travels with every job — and speaker diarization and the other Audio Intelligence features derive still more about each speaker. Spoken content can add further sensitive categories — health, financial, government-ID.
Where your organization is a critical information infrastructure operator, or your volumes cross the regulators’ thresholds, an in-country storage duty attaches: mainland personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). Where volume or sensitivity crosses a threshold, a CAC-led data-export security assessment can be required before any of it lawfully leaves. AssemblyAI’s EU-residency endpoint, its no-retention posture and its self-hosted option are real data-protection strengths — but EU residency is EU law, not a mainland-China residency, and none of them furnishes the PIPL basis the export itself requires.
Reaching the API isn’t the question — keeping the audio in-country is
The instinct for most China problems is to make a slow or failing third-party call load faster or more reliably. On this axis that instinct is backwards: making AssemblyAI’s offshore endpoint respond more dependably for mainland users does not shrink the exposure — it exports more voiceprints, more smoothly, without supplying the lawful basis the transfer needs.
What actually works is to keep China-origin audio’s processing in-country — and here AssemblyAI gives you a genuine option. It states that it offers “self-hosted solutions for organizations that require greater control over their data and infrastructure,” letting you “deploy our services within your own environment.” Run that deployment inside China, on infrastructure you control, and the recordings, transcripts and voiceprints are processed in-country rather than exported. Be precise about what that entails: it is an enterprise, contract-based deployment that runs on GPU infrastructure you provide and still involves licensing and usage communication with AssemblyAI, so confirm the exact data boundary, any air-gap, and model parity for the capability you need in writing. For audio you cannot self-host, route it through a licensed in-country speech service whose data stays in the mainland. Either way, obtain the Article 28 separate consent and minimize what you capture. None of this is a tunnel that ships the audio offshore anyway while hiding that it does.
This is a risk map, not a verdict. Whether you owe a separate consent, a PIPIA, a transfer mechanism, a data-export security assessment, in-country storage, or an ICP filing — and in what combination — turns on your entity, your data volumes, how much of your China audio is personal or sensitive, and exactly what you record. Settle the specifics with counsel before you send a single mainland recording abroad to be transcribed.
The lawful path — map, localize, deliver
You do not have to drop AssemblyAI for your other markets to handle China audio lawfully. 21YunBox is a compliant overlay, not a migration — and, for a service you already use, a partner alongside your stack rather than a competitor to the speech vendor. There are three moves, and they fit together.
Map. Our China compliance team inventories what audio flows to AssemblyAI — which calls, meetings, recordings and live streams, whose voiceprints they carry and what the spoken content reveals — where AssemblyAI processes and stores it, whether it is retained or used to train models, and where you lack a lawful basis for the cross-border leg, so the exposure is written down before anything changes.
Localize. Because the risk is China-origin audio leaving the country, localize here means keeping that audio’s processing in-country: run AssemblyAI’s self-hosted deployment inside China, or route China audio through a licensed in-country speech service whose data stays in the mainland — with the Article 28 separate consent and a PIPIA, model-training retention disabled, and only the minimum audio captured. It never means a tunnel that makes the offshore call anyway. 21YunBox never uses or suggests circumvention of any kind.
Deliver. The China-facing app, line or site that captures and uses the audio is a public internet service with an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer provides it, ICP-filed and in-country, in front of the stack you already run. No rebuild, no second codebase.
The goal is plain: your service runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization (Article 39)
- China’s data-export security assessment measures
- How to get an ICP filing for China
