Does Authorize.Net Work in China? Payments, PIPL & Cross-Border Card Data
Authorize.Net is a Visa solution operated from offshore — by its own terms the merchant must be based in the US, Canada, UK, Europe or Australia, and it is not a China-licensed payment institution. A China checkout sends cardholder and payer data across the border under PIPL, and card data is sensitive financial information that raises the bar. A compliance-first look at the payment and data doors.
Does Authorize.Net work in China?
Whether Authorize.Net works for a mainland-China checkout is first a payment-licensing and data-residency question, not a speed one. It is a Visa solution operated from offshore, and that is where the legal exposure starts.
By Authorize.Net's own terms it onboards only businesses "based in the United States, Canada, United Kingdom, Europe, and Australia" — none of them mainland China — and it is not a China-licensed payment institution, where the in-country rails are UnionPay, Alipay and WeChat Pay. So a China checkout sends the cardholder's and payer's personal data to offshore US endpoints: a cross-border transfer of personal information PIPL governs, and because card data is sensitive financial information the bar is higher — separate consent and an impact assessment, plus a transfer mechanism or even keeping that data on Chinese soil, which means standing up a lawful in-country, ICP-filed presence, depending on your volume and role. The table below is Authorize.Net's own terms and the China rules they trigger.
This is a risk map, not a legal verdict — your obligations turn on what you collect, how much, and your role. Our China team can map the cross-border and data-residency path with you →
What Authorize.Net's own documentation says about China
| Fact | Primary source |
|---|---|
| In Authorize.Net's own terms, it "supports cross-border eCommerce payments for businesses based in the United States, Canada, United Kingdom, Europe, and Australia," and "to use Authorize.net, your business must be based in the U.S., Canada, the U.K., Europe, or Australia." None of its supported merchant locations is in mainland China. Authorize.Net is a Visa solution operated from offshore (US) infrastructure, with no mainland-China presence. | Authorize.Net — eCommerce payments (supported merchant locations), retrieved 2026-10-07 |
| Providing non-bank payment services inside mainland China requires a payment business license from the People's Bank of China, held by a company established in China (Regulations on the Supervision and Administration of Non-bank Payment Institutions, State Council Order No. 768, in force 1 May 2024). The in-country rails are UnionPay and the licensed institutions behind Alipay and WeChat Pay. Authorize.Net is not a China-licensed payment institution — a factual gap in where it is cleared to operate, not something network tuning can close. | Regulations on the Supervision and Administration of Non-bank Payment Institutions (State Council Order No. 768, effective 2024-05-01) |
| A China checkout sends the cardholder's and payer's personal data to Authorize.Net's offshore (US) endpoints — a cross-border transfer of personal information that PIPL governs. The handler is you, the merchant, not Authorize.Net. Card and bank-account data are financial-account information, which PIPL Article 28 classifies as sensitive personal information; handling it requires separate consent (Articles 29 and 39) and a personal-information protection impact assessment (Article 55) on top of the baseline cross-border duties. | PIPL Articles 28, 29, 38–43 and 55 |
| Exposure scales with volume and role. Under the CAC's March 2024 cross-border rules, the exemption for fewer than 100,000 individuals covers non-sensitive personal information — it does not cover sensitive financial data, for which the thresholds are far lower. There is a carve-out for transfers necessary to perform a contract with the individual (the rules list cross-border payment among the examples), but it removes only the transfer-mechanism step, not the separate-consent and impact-assessment duties. For a CIIO or large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; CSL Article 37) — which an offshore gateway cannot satisfy, and standing up a lawful in-country presence is what brings an ICP filing into play. | CAC — Regulations on Promoting and Regulating Cross-border Data Flows (March 2024); PIPL Article 40; CSL Article 37 |
| Because Authorize.Net onboards no mainland-China merchant and runs from offshore, its API and hosted-payment endpoints are reached from outside the mainland: every China checkout is a cross-border round trip to US infrastructure, with no in-country endpoint. Even where those endpoints load, the compliance facts — offshore data residency and the absence of a China payment license — are what a China-facing checkout has to answer for, and network tuning changes neither. | Authorize.Net — eCommerce payments (operated from offshore; supported merchant locations), retrieved 2026-10-07 |
Sources verified by the 21YunBox compliance team on 2026-10-07.
For a mainland-China checkout, the deciding question about Authorize.Net is not how fast its form loads — it is whether the payment can run there lawfully and where the card data is allowed to live. Authorize.Net is a Visa solution operated from offshore, and it answers the first question in its own terms: it onboards merchants based in the United States, Canada, the United Kingdom, Europe or Australia — not mainland China. So a China checkout built on it sends the cardholder’s and payer’s personal data to offshore US endpoints, which turns every transaction into a cross-border transfer of sensitive financial information China’s data law governs. Reaching the endpoints is not the problem; the payment licensing and the data residency are the exposure.
Authorize.Net in China at a glance
| What decides it | In Authorize.Net's own terms — and the law's |
|---|---|
| Who can be a merchant | By its own documentation, Authorize.Net “supports cross-border eCommerce payments for businesses based in the United States, Canada, United Kingdom, Europe, and Australia.” None of its supported merchant locations is in mainland China. It is a Visa solution operated from offshore (US) infrastructure. |
| Is it a China payment-license holder | No. Non-bank payment services inside the mainland require a payment business license from the People's Bank of China, held by a company established in China. The in-country rails are UnionPay and the licensed institutions behind Alipay and WeChat Pay; Authorize.Net is not among them. |
| The cross-border transfer | A China checkout sends the cardholder's and payer's personal data to Authorize.Net's offshore (US) endpoints — a cross-border transfer of personal information PIPL governs, and the handler is you, the merchant, not Authorize.Net. |
| Why the bar is higher here | Card and bank-account data are financial-account information, which PIPL Article 28 classifies as sensitive personal information. Handling it cross-border adds separate consent and a personal-information protection impact assessment on top of the baseline transfer duties. |
| Is it reachable? | Its API and hosted-payment endpoints are served from offshore, so every China checkout is a cross-border round trip to US infrastructure with no in-country endpoint. Reachability is not the exposure; the licensing and data residency are. |
A US gateway, operated offshore — with no mainland footing
Authorize.Net is a payment gateway owned by Visa, and it runs from offshore. In its own documentation it “supports cross-border eCommerce payments for businesses based in the United States, Canada, United Kingdom, Europe, and Australia,” and it is explicit that “to use Authorize.net, your business must be based in the U.S., Canada, the U.K., Europe, or Australia.” Mainland China is on neither list.
That geography settles the first question before performance enters it. Inside the mainland, non-bank payment services require a payment business license from the People’s Bank of China, held by a company established in China — the framework set out in the State Council’s Regulations on the Supervision and Administration of Non-bank Payment Institutions (Order No. 768, in force since 1 May 2024). The licensed in-country rails are UnionPay and the institutions behind Alipay and WeChat Pay. Authorize.Net is not among them. This is a factual statement of where it is cleared to operate, not advice on your setup — but it is where “we already take cards through Authorize.Net” runs out: being reachable from China is not the same as being cleared to collect payments there.
Run a China checkout and the card data crosses the border
Point a China checkout at Authorize.Net and the cardholder’s name, card number, billing address and the payer’s details are sent to its offshore US endpoints to be processed. Under China’s Personal Information Protection Law that is a cross-border transfer of personal information, and the obligation falls on the personal-information handler — you, the merchant, not Authorize.Net as the gateway.
What raises the bar here is the kind of data. Card and bank-account information is financial-account information, which PIPL Article 28 classifies as sensitive personal information. Handling sensitive personal information across the border asks the handler to give notice, obtain separate consent, and carry out a personal-information protection impact assessment — on top of satisfying a transfer mechanism. A checkout that quietly ships card data offshore meets none of that by default.
How much is at stake — volume, role, and the payment carve-out
The weight of these duties is not uniform. Under the CAC’s March 2024 Regulations on Promoting and Regulating Cross-border Data Flows, the widely cited exemption for transferring fewer than 100,000 individuals’ data applies to non-sensitive personal information; financial-account data is sensitive, so that exemption does not cover it, and the thresholds that trigger the CAC standard contract or a security assessment are reached at far lower volumes. There is a genuine carve-out for transfers necessary to perform a contract to which the individual is a party — the rules list cross-border payment among the examples — but it lifts only the transfer-mechanism step, not the separate-consent and impact-assessment duties that sensitive data carries.
At the strict end, a critical information infrastructure operator or a large-volume handler must keep personal information collected in China inside the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore gateway cannot satisfy that, and keeping payment data on Chinese soil means standing up a lawful in-country presence — which is where an ICP filing and in-country, licensed payment rails come into the picture.
Reachable or not, every China checkout is a cross-border round trip
Because Authorize.Net onboards no mainland-China merchant and runs from offshore, its API and hosted-payment endpoints are reached from outside the mainland. Whatever the latency on a given day, every China checkout is a cross-border round trip to US infrastructure, with no in-country endpoint to fall back on. That is why the real exposure on a China-facing Authorize.Net checkout is not whether the form paints — it is that the payment is being collected offshore, by a gateway that holds no China payment license, with sensitive card data leaving the country. Those are compliance facts, and no amount of network tuning closes them.
This is a risk map, not a verdict: whether you need separate consent only, a full CAC transfer mechanism, in-country storage of the data, or a licensed local payment rail depends on what you collect, how much, and whether your role pulls you into the CIIO or large-volume tier — worth settling with counsel before you build.
Where 21YunBox fits — a compliant overlay, not a migration
We don’t replace your payment processor, and nothing in your existing integration has to move. What our China team adds is the layer an offshore gateway cannot: first, a clear map of the PIPL cross-border and data-residency exposure your China checkout creates, against your entity, your data volumes and your role; then the compliant, ICP-filed delivery from inside the mainland that a lawful China presence needs, set in front of your existing origin — no rebuild and no second codebase. Your Authorize.Net integration stays exactly where it runs for the markets it already serves, while the China side is built to stand on in-country footing.
Related reading:
