Does Avaya Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
Carrying your China users' calls, recordings and interaction data to Avaya's offshore cloud is a PIPL cross-border transfer of voiceprint-grade sensitive data, and providing voice or contact-center service in China touches a value-added telecom license a foreign platform cannot hold — though Avaya's on-premises heritage is a genuine residency lever. A compliance-first look at the licensing door and residency exposure.
Does Avaya work in China?
Providing voice and contact-center service to users in China needs a value-added telecom license a foreign platform cannot hold, and the calls and recordings Avaya carries are voiceprint-grade sensitive data that, in its cloud form, sit offshore.
Avaya spans on-premises unified communications (Avaya Aura) and a cloud contact center (Avaya Experience Platform, now under Avaya Infinity) that carries calls, recordings (a voiceprint = PIPL Article 28 sensitive personal information), transcripts, CDRs and contact data. Avaya runs its cloud on Microsoft Azure with no mainland-China region and records through Verint on Azure/AWS, so carrying your China users' voice there is a PIPL cross-border transfer needing a separate, heightened consent (Articles 28/29) — on top of the telecom-licensing door. The lawful lever is to route China voice and contact-center through a licensed in-country operator and keep recordings and interaction data in-country (Avaya's on-premises/private deployment is a genuine residency lever), not to make the offshore platform reachable. 21YunBox is advisory on the telecom-licensing leg.
A risk map, not a verdict — the specifics turn on your entity, your callers and your recordings. Our China team can map your exposure →
What Avaya's own documentation says about China
| Fact | Primary source |
|---|---|
| Avaya offers cloud, hybrid and on-premises deployment — the on-prem/private option is the residency lever. Avaya's Avaya Infinity platform page states “Cloud, hybrid, and on-premises deployments are all supported” and frames it as “the advantages of cloud with the security and data sovereignty of on-prem,” with “Organizations retain control over deployment, data, and AI choices.” An on-premises or private in-country deployment can keep recordings and interaction data inside China — the telecom-licensing door still applies. | Avaya — Avaya Infinity platform, retrieved 2026-10-10 |
| Avaya's cloud runs on Microsoft Azure, with no mainland-China region; recordings route through Verint on Azure and AWS. Avaya's DORA resilience documentation describes AXP Private Cloud as “Running on a dedicated instance of Microsoft Azure,” notes that “the location of datacenters depends on the geographical location where the AXP Customer is based,” and lists AXP datacenters in the US, UK, Germany, Brazil and Singapore (Public Cloud adds Canada, Australia and Japan) — none in mainland China, with nearby markets served from Singapore. The call-recording path runs through the Verint recorder on “Microsoft's Azure and Amazon's AWS.” | Avaya Trust Center — DORA / Avaya solutions, retrieved 2026-10-10 |
| Providing voice or contact-center service in China is a value-added telecom business a foreign operator cannot license directly. A domestic phone number, carrying calls on China's networks and operating a contact center touch the 增值电信业务经营许可证 (value-added telecom business license); under the foreign-investment rules for telecommunications, foreign participation runs only through a tightly limited, licensed domestic arrangement. Lawful reach runs through a licensed in-country operator, not a sale from abroad. | China — Regulations on the Administration of Foreign-Invested Telecommunications Enterprises (State Council Order No. 333), via gov.cn |
| A call recording is a voiceprint — PIPL Article 28 sensitive personal information — needing a separate, heightened Article 29 consent. Carrying recordings, transcripts and CDRs collected in China to an offshore cloud is a cross-border transfer under PIPL Articles 38–40 (notice, a separate consent, and a transfer mechanism). For a CIIO or high-volume handler, that data must be stored in-country under Cybersecurity Law Article 39 (formerly Article 37); AI routing or scoring adds the Article 24 automated-decision duty. | PIPL Articles 28–29, 38–40, 24; CSL Article 39 (formerly 37), via CAC |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a China-facing operation, the question about Avaya is not whether an agent can log in — it is whether a foreign platform may carry and store your Chinese users’ voice at all. Avaya spans both halves of the market: Avaya Aura is an on-premises unified-communications platform, while the Avaya Experience Platform (AXP), now presented under the Avaya Infinity platform, is a cloud contact center carrying calls, recordings, transcripts, call detail records (CDRs) and contact data, often with AI agent-assist and analytics. Two doors decide it. First, providing voice and contact-center service to users in China is a value-added telecom business a foreign operator cannot license directly. Second, a call recording is the speaker’s voiceprint — Article 28 sensitive personal information under PIPL, needing Article 29 separate consent — and in Avaya’s cloud form the recordings, CDRs and transcripts sit offshore: a cross-border transfer under PIPL Articles 38–40, with an in-country storage duty for a CIIO or high-volume handler and a PIPL Article 24 angle wherever AI routes or scores.
Avaya in China at a glance
| What decides it | In Avaya's own terms — and China's law |
|---|---|
| What it carries and stores | Avaya carries business voice, video and team messaging (Avaya Aura) and inbound/outbound contact-center interactions (Avaya Experience Platform / Avaya Infinity): live calls, call recordings, voicemail, transcripts, call detail records (CDRs), IVR inputs, screen recordings and contact lists. Each is personal information, and a recording is the speaker's voiceprint — which PIPL Article 28 treats as sensitive personal information that cannot be anonymized away. |
| Where it is processed | Avaya's cloud runs on Microsoft Azure — AXP Private Cloud is “a dedicated instance of Microsoft Azure” — and the recording path runs through its Verint recorder on “Microsoft's Azure and Amazon's AWS.” Avaya's own DORA documentation lists AXP datacenters in the US, UK, Germany, Brazil and Singapore (Public Cloud adds Canada, Australia and Japan) — none in mainland China; nearby markets are served from its Singapore datacenter. Carrying mainland users' voice there is a cross-border transfer under PIPL Articles 38–40 (数据出境): notice, a separate consent, and one transfer mechanism. |
| Door one — telecom-business licensing | Providing voice, telephony or contact-center service to users in China is a value-added telecom business gated by the 增值电信业务经营许可证 (value-added telecom business license), which under China's foreign-investment rules a foreign operator cannot hold directly. A foreign platform cannot lawfully originate or terminate domestic Chinese telephony or run a licensed in-country contact center on its own — lawful reach routes through a licensed in-country telecom/contact-center operator. Even an on-premises deployment's PSTN carriage touches China's licensed carriers. See the Telecommunications Business Licensing Measures. |
| Door two — voiceprint, consent & residency | A recording is a voiceprint — PIPL Article 28 sensitive personal information (biometric) — so it needs the heightened Article 29 separate consent, with transcripts, CDRs and contact data personal information in their own right. For a critical information infrastructure operator or high-volume handler, personal information collected in the mainland must be stored there — the data-localization duty in Cybersecurity Law Article 39 (formerly Article 37) (the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). AI agent-assist, sentiment or routing adds the PIPL Article 24 automated-decision angle. |
| Reachability is not the axis | Whether an agent can reach the console was never the question. The lawful shape is to route China-facing voice and contact-center through a licensed in-country operator, keep recordings, transcripts, CDRs and interaction data in-country — Avaya's on-premises / private deployment is a genuine residency lever here — obtain the Article 29 separate consent, and deliver the surrounding app or portal on an ICP-filed in-country footing. On telecom licensing 21YunBox's role is advisory: it holds no China telecom license; the license and carriage sit with a licensed domestic operator and your counsel. |
What you actually carry and store — calls, recordings and interaction data
Avaya sits across two product families, and both carry personal data that matters here. Avaya Aura is the on-premises unified-communications core — Communication Manager for call processing, Session Manager for SIP routing, System Manager, Media Server, presence and messaging — the business phone system, voicemail and video your organization runs. The Avaya Experience Platform (AXP), which Avaya now presents under its Avaya Infinity platform, is the cloud contact center: inbound and outbound voice, digital channels, IVR, agent desktop, call and (optionally) screen recording, quality monitoring, call reporting and AI agent-assist.
What flows through them is the speaker’s voice and everything attached to it: live calls, call recordings, voicemail, transcripts, call detail records (CDRs), IVR selections, screen recordings and the contact lists and account context an agent sees. Every one of those is personal information — and a recording is more than that. It is a voiceprint.
Where that data lives depends on the deployment, and Avaya is explicit about the menu. Its cloud contact center runs on Microsoft Azure; Avaya’s own resilience documentation describes AXP Private Cloud as “Running on a dedicated instance of Microsoft Azure,” with the recording path through its Verint recorder on “Microsoft’s Azure and Amazon’s AWS.” The published AXP datacenters sit in the US, UK, Germany, Brazil and Singapore, with Canada, Australia and Japan added for Public Cloud — none in mainland China, and nearby markets are served from its Singapore datacenter. So in its cloud form, the recordings, CDRs and transcripts of calls with your Chinese users are carried to, and stored on, infrastructure outside the mainland.
Avaya’s distinguishing feature is that this is not the only option. Avaya Aura has always been an on-premises platform — “Organizations can continue to operate Aura in on-premises environments” — and Avaya markets its contact center with “Cloud, hybrid, and on-premises deployments are all supported” and “the security and data sovereignty of on-prem.” An on-premises or private in-country deployment is a real data-residency lever: it can keep the recordings and interaction data inside China. It does not, however, dissolve the first door — the telephony itself.
Two doors: a telecom license you can’t hold, and a cross-border transfer of sensitive voice data
Door one — the telecom license. Providing voice, telephony or contact-center service to users in China is not a plain software subscription; it is a value-added telecom business. Originating or terminating domestic Chinese phone calls, issuing Chinese numbers and operating a contact center are activities gated by the 增值电信业务经营许可证 (value-added telecom business license), and under China’s foreign-investment rules for telecommunications a foreign operator cannot hold that license directly — participation runs through a tightly limited, licensed domestic arrangement rather than a sale from abroad. A foreign UCaaS/CCaaS platform therefore cannot, on its own, lawfully carry domestic Chinese telephony or run a licensed in-country contact center; lawful reach runs through a licensed in-country telecom/contact-center operator. This is the voice counterpart of the signature-and-template regime that governs application-to-person SMS. An on-premises Avaya deployment helps with the data, but the moment a call touches China’s public phone network it touches licensed Chinese carriers — so the licensing door stands whether you deploy in the cloud or on your own floor.
Door two — the data crosses the border, and it is sensitive. When calls with people in China are recorded, transcribed or logged and that data is processed or stored outside the mainland, you — the personal-information handler, not Avaya — are making a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL Articles 38–40 (数据出境) require notice, a separate consent, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. A call recording raises the bar: it is the speaker’s voiceprint, and PIPL Article 28 classifies biometric information as sensitive personal information that cannot be anonymized away, so processing and transfer need the heightened Article 29 separate consent and a genuine necessity. Transcripts, CDRs, IVR inputs and contact lists are personal information in their own right. Where your organization is a critical information infrastructure operator or a high-volume handler, personal information collected in the mainland must be stored there — the data-localization duty the Cybersecurity Law now carries in Article 39 (formerly Article 37). And where Avaya’s AI agent-assist, sentiment scoring or routing makes decisions about individuals, PIPL Article 24 adds an automated-decision-making obligation on top.
This is a risk map, not a verdict: whether you face the licensing door, a residency duty, the sensitive-PI consent bar, or all three turns on your entity, who your callers are, the volume and kind of recordings you keep, and whether AI is in the loop — worth settling with counsel before you commit.
Reaching the platform isn’t the question — a licensed in-country path is
Because a foreign platform cannot hold the telecom license and Avaya publishes no mainland-China cloud region, the useful question is not how to make the AXP console answer from Shanghai — it is how to run voice and contact-center for Chinese users lawfully. That path has a shape. Route the China-facing voice and contact-center leg through a licensed in-country telecom/contact-center operator that holds the value-added telecom license and carries the calls on China’s networks. Keep the recordings, transcripts, CDRs and interaction data in-country — this is exactly where Avaya’s on-premises and private-deployment heritage earns its place, letting the voiceprint-bearing data stay on infrastructure inside China rather than on an offshore cloud. Obtain the Article 29 separate consent for the recordings, minimize and pseudonymize what you keep, honor any Article 24 option where AI scores or routes, and keep a lawful cross-border basis for anything that still has to leave. This is the opposite of a tunnel that ships the data offshore anyway: localizing means the voice and the recordings stay on a lawful, licensed, in-country path.
Be precise about roles. 21YunBox is advisory on the telecom-licensing leg — it holds no China telecom license and is not a carrier; the license, the carrier relationship and the contact-center permits sit with a licensed domestic operator and your counsel. What 21YunBox owns is the mapping, the in-country data and delivery design, and the compliant ICP-filed delivery of the app and portals around the contact center. Which arrangement fits your entity, your call volumes and your recordings is a risk to confirm with qualified counsel against what you actually run — treat this page as a risk map, not a verdict, and settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a lawful way to run voice and a contact center for users in mainland China, and it does not depend on making an offshore platform reachable. It runs through a licensed in-country operator, recordings and interaction data that stay in-country, a governed transfer for anything that leaves, and a China-facing app that is itself ICP-filed and served in-country — in front of the stack you already run, with no rebuild or migration. 21YunBox works on that footing.
Map. We inventory the calls, recordings, voicemail, transcripts, CDRs, IVR inputs and contact data your Avaya setup carries, which of it is sensitive voiceprint data, where Avaya processes and stores it today (Microsoft Azure and the Verint recorder, offshore for the cloud variants), how your Chinese telephony is originated and terminated now, where AI makes automated decisions, and the consent basis you rely on — so you know exactly what counsel and a licensed local operator need to confirm.
Localize / govern. We help you route China-facing voice and contact-center through a licensed in-country operator, keep the recordings, transcripts, CDRs and interaction data in-country — using Avaya’s on-premises or private deployment where that is the right fit — secure the Article 29 separate consent for the voiceprint data, minimize and pseudonymize, honor any Article 24 option, and keep a lawful cross-border basis for anything that still leaves. On the telecom-licensing leg our role is advisory: 21YunBox holds no China telecom license. Localizing means keeping the voice and the recordings on a lawful, licensed, in-country path — never a tunnel that ships the data offshore anyway.
Deliver. The app, agent portal and customer pages around the contact center are public internet services with an ICP filing duty; we deliver them in-country on ICP-filed infrastructure — the 21YunBox Optimizer — so they run legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. 21YunBox is a compliant overlay and partner, advisory on telecom licensing, not a competitor to Avaya.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Data Export Security Assessment Measures
- How to get an ICP filing for China
