Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Amazon Textract Work in China? PIPL Cross-Border, Data Residency & Sensitive-Data Rules

Amazon Textract is a cloud-only document-OCR and intelligent-document-processing service AWS offers only in its global regions — none in the Beijing or Ningxia China partition. The ID cards, passports, invoices and KYC files your China operation sends it to read ARE the personal information — often sensitive — so reading them offshore is a PIPL cross-border transfer of sensitive personal data. A compliance-first look at the residency, sensitive-data and cross-border exposure, and the lawful in-country path.

Does Amazon Textract work in China?

The invoices, contracts and — the sharp case — the ID cards, passports and KYC files your China operation sends Amazon Textract to read ARE the personal information, often sensitive (ID numbers, financial-account numbers), and AWS offers Textract only in its global regions with no mainland-China endpoint — so reading them is a PIPL cross-border transfer of sensitive personal data.

Textract is a cloud-only document-OCR service: you upload the document and it extracts the text and fields, so the content you send IS the data — and an ID or financial-account number is sensitive personal information under PIPL Article 28 that you cannot minimize, because the number is the very thing you sent the document to read. Because AWS publishes Textract endpoints only in its US, Canada, European, Asia Pacific and GovCloud regions — none in the Beijing or Ningxia China partition — reading China-collected documents there is a cross-border transfer (PIPL Articles 38–40, plus the Article 29 separate consent for sensitive PI). The lawful lever is to keep the document processing in-country, minimize what crosses the border, obtain the separate consent, and ICP-file any China-facing upload or verification surface — not to make the offshore API reachable.

This is a risk map, not a verdict — whether a given document is sensitive or "important data" turns on what you process and your sector. Our China team can map your exposure →

What Amazon Textract's own documentation says about China

FactPrimary source
AWS offers Amazon Textract only in its global regions — none in mainland China. Amazon's General Reference lists Textract endpoints across US, Canada, European and Asia Pacific regions and GovCloud; there is no endpoint in its Beijing (operated by Sinnet) or Ningxia (operated by NWCD) China partition, and Textract has no self-hosted or on-premises edition. So documents a China operation sends it are read in a region outside the mainland. AWS General Reference — Amazon Textract endpoints and quotas, retrieved 2026-10-11
Textract is built to read the very documents that carry sensitive data. Its operations detect text, pull key-value fields from forms, parse invoices and receipts (AnalyzeExpense) and extract fields from identity documents such as passports and driver's licenses (AnalyzeID) — so the content you upload for it to read is itself the personal information, and for an ID card, passport, bank card or KYC file that information is sensitive and cannot be minimized away. AWS — Amazon Textract product page (features), retrieved 2026-10-11
ID and financial-account numbers are sensitive personal information under PIPL Article 28. China's PIPL treats a natural person's ID-document numbers and financial-account numbers as sensitive personal information, which needs a separate, specific consent (Article 29) and a prior protection-impact assessment before processing — and sending China-collected documents to an offshore region is itself a cross-border transfer under PIPL Articles 38–40 (notice, separate consent, and a CAC security assessment, standard contract, or certification). 21YunBox — China Personal Information Protection Law (PIPL), Articles 28–29 & 38–40, retrieved 2026-10-11
At volume, residency and a data-export assessment can bite. For a critical information infrastructure operator or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires personal information collected in China to be stored in China — and high volumes of document data, or data a regulator treats as "important data," can make a CAC data-export security assessment mandatory before anything leaves the mainland. 21YunBox — China Cybersecurity Law (Article 39) & Measures for the Security Assessment of Data Exports, retrieved 2026-10-11

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running Amazon Textract for a mainland-China operation, the question is not whether the API answers a call from Shanghai. Textract works by you uploading the document to be read — and that document is the personal information. It is a cloud-only, fully managed AWS service for document OCR and intelligent document processing: it detects text, pulls key-value fields from forms, parses invoices and receipts, and — the sharp case — extracts the fields from identity documents. AWS publishes Textract endpoints only in its US, Canada, European, Asia Pacific and GovCloud regions; there is no endpoint in the Beijing or Ningxia China partition, and no self-hosted Textract. So the invoices, contracts and — most sharply — the ID cards, passports, bank cards and KYC files your China operation sends it to read are processed offshore. For a China operation that is a cross-border transfer under PIPL, and the ID and financial-account numbers inside those documents are sensitive personal information under Article 28 that cannot be minimized — the number is the very thing you sent the document to read. A separate consent for the sensitive data, a transfer mechanism, automated-decision duties where a check is auto-approved, in-country storage for a CIIO or high-volume handler, and an ICP filing for any China-facing upload surface all follow.

AWS General Reference page 'Amazon Textract endpoints and quotas' listing Textract service endpoints by Region — US, Canada, Europe, Asia Pacific and GovCloud — with no Beijing or Ningxia China endpoint.
"To connect programmatically to an AWS service, you use an endpoint." Amazon's published endpoint list for Textract spans the US, Canada, Europe, Asia Pacific and GovCloud — none in mainland China; the Beijing (cn-north-1) and Ningxia (cn-northwest-1) China regions carry no Textract endpoint, so documents sent to the service are read in a region outside the mainland. Source: AWS — Amazon Textract endpoints and quotas

Amazon Textract in China at a glance

What decides it In Amazon Textract's own terms — and China's law
What you send it Whole documents, uploaded for the service to read: invoices, contracts, forms, and — the sharp case — ID cards, passports, driver's licenses, bank cards and KYC files. Textract's own operations parse invoices and receipts (AnalyzeExpense) and extract the fields of identity documents (AnalyzeID). The content you send IS the personal information, and for an ID or financial-account number it is sensitive personal information under PIPL Article 28.
Where it runs AWS publishes Textract endpoints only in its US, Canada, European and Asia Pacific regions and in GovCloud — none in the Beijing or Ningxia China partition — and offers no self-hosted Textract. For a China operation, documents read in a region outside the mainland are a cross-border transfer (数据出境) of personal information under PIPL Articles 38–40, with a separate consent required for the sensitive data (Article 29).
The sensitive-PI door ID-document numbers and financial-account numbers are sensitive personal information under PIPL Article 28 — a separate, specific consent and a prior impact assessment before processing. You cannot minimize or anonymize them away: the number is the very thing you uploaded the document to read, so the usual "de-identify before transfer" escape does not apply.
Automated decision + residency If your flow auto-approves or rejects a person from what Textract extracts, that is an automated decision under PIPL Article 24. For a CIIO or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China-collected personal information to be stored in China; and high volumes of document data — or data treated as "important data" — can make a CAC data-export security assessment mandatory before anything leaves.
Reachability is not the axis Whether the Textract endpoint answers quickly from the mainland is an operational matter, not the compliance question. What decides it is where the documents are read and which of them is sensitive PI. 21YunBox maps the exposure, keeps the document processing on a lawful in-country path, and delivers any China-facing upload or verification surface compliantly, with an ICP filing — in front of the stack you already run.

What you actually send it — and why the content is the risk

Amazon Textract is a document service: you hand it a file and it reads the file back to you as structured data. Its DetectDocumentText and AnalyzeDocument operations pull the raw text, the form key-value pairs and the tables out of a page; AnalyzeExpense is tuned for invoices and receipts; AnalyzeID is built specifically to extract the fields of identity documents such as passports and driver’s licenses. That is the whole point of the service — and it is also the whole of the compliance problem, because the file you upload for it to read is not metadata about personal information, it is the personal information. For an ordinary form that may be unremarkable. For the sharp cases a document pipeline exists to handle — an ID card for onboarding, a passport for KYC, a bank card or statement for a financial check — the content is the most sensitive category Chinese law recognizes: identification numbers and financial-account numbers. Textract is a cloud-only, fully managed service; there is no on-premises or self-hosted edition, and AWS runs it only in its global regions, so there is no in-country AWS path to point it at. Where the reading happens is therefore fixed by AWS’s region map — and that map has no mainland-China entry for Textract.

The doors: sensitive personal data, cross-border transfer, and automated decisions

Once China-collected documents are read in a region outside the mainland, a separate body of law decides whether they were allowed to go there. What you upload to Textract — an invoice, a contract, a scanned ID card, a passport, a KYC file — is personal information under China’s Personal Information Protection Law, and sending it to an offshore region to be read is a cross-border transfer (数据出境). PIPL puts the duty on the handler — your China entity, not AWS: Articles 38–40 require notice, a transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and a separate consent for the overseas transfer. The ID-document numbers and financial-account numbers inside those files raise the bar: they are sensitive personal information under Articles 28–29, which add a separate, specific consent, a prior protection-impact assessment, and strict minimization. And minimization is exactly the escape you do not have here — the ID number is the very field you sent the document to read, so it cannot be stripped before transfer without defeating the purpose of the call.

Two more doors can open depending on what you do with the output and at what scale. If your flow then auto-approves or rejects a person from what Textract extracted — an automated KYC or identity decision — that is automated decision-making under PIPL Article 24, which lets the data subject refuse a decision made solely by automated means. On residency, if your organization is a critical information infrastructure operator or a large-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China, a duty an offshore service cannot meet. And at volume — many thousands of documents, or data a regulator treats as “important data” under the Data Security Law — a CAC data-export security assessment can become mandatory before anything leaves. Which of these bite your specific case turns on your sector, your data volumes and your role under Chinese law.

Calling the API isn’t the question — compliant in-country processing is

The fix is not to make an offshore Textract endpoint reachable from the mainland — reachability was never the question. It is to put the document reading where the law needs it: keep the China document processing on an in-country path — a China-resident processing path or a China-legal domestic document-recognition alternative — so the ID cards, passports and KYC files your mainland operation handles are read inside the country, with only what may lawfully leave crossing the border. Minimize what you send, obtain the Article 13/23 notice-and-consent and the Article 29 separate consent for the sensitive data, and handle any Article 24 automated-decision and important-data duty. Then, any China-facing surface that feeds the pipeline — a document-upload page, an onboarding or verification flow, a customer portal that accepts scans — is an internet information service served in the mainland, so it carries an ICP filing (备案) duty bound to a mainland hosting resource, plus compliant in-country delivery. None of this is a verdict that Textract is “blocked” or “illegal” in China; it is a residency-and-exposure map, and whether a given document or image is sensitive or “important data” turns on what you process and your sector — worth settling the specifics with counsel before your China operations depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run document OCR for a China operation, and it has a shape. First, map: our China team inventories what you send Textract — the invoices, contracts, forms and, above all, the ID cards, passports, bank cards and KYC files — flags which of it is sensitive personal information (identification numbers, financial-account numbers), establishes where it is read today (an offshore AWS region), the cross-border and Article 28/29 consent basis each transfer needs, whether any of it is “important data,” and whether your flow makes an automated decision under Article 24. We build the technical picture; the legal conclusions are settled with counsel.

Then localize: we help you keep the China document processing in-country — on a China-resident processing path or a China-legal domestic alternative — so the sensitive files your mainland operation handles are read inside the country by default, minimizing what crosses the border and obtaining the Article 29 separate consent for what remains. Localize means keeping the data on an in-country path, never a tunnel that ships it offshore anyway.

Then deliver: any China-facing surface on top of the pipeline — an upload page, an onboarding or verification flow — needs compliant, in-country delivery and carries an ICP filing duty. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a document pipeline that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Amazon Textract available in a mainland-China AWS region?
No. AWS publishes Textract endpoints only in its US, Canada, European, Asia Pacific and GovCloud regions; it offers no Textract endpoint in its Beijing or Ningxia China partition, and there is no self-hosted or on-premises Textract. So documents a China operation sends Textract are processed in a region outside mainland China — which, for personal information collected in China, is a cross-border transfer governed by PIPL.
Why is sending documents to Textract a sensitive-data problem under PIPL?
Because the document you upload IS the personal information. For an invoice or contract that may be ordinary PI; for an ID card, passport, bank card or KYC file, the ID number and financial-account number inside are sensitive personal information under PIPL Article 28 — and you cannot minimize or anonymize them, because the number is the very thing you sent the document to read. Sensitive PI needs a separate, specific consent (Article 29) and a prior impact assessment, and the transfer offshore needs a PIPL Articles 38–40 mechanism. Whether important-data volume rules or a CAC data-export assessment also apply turns on what you process and your sector.
Can 21YunBox make our Amazon Textract document processing compliant in China?
Yes. Our China compliance team maps what you send Textract and which of it is sensitive PI, helps you keep the China document processing on a lawful in-country path — a China-resident processing path or a China-legal domestic alternative — minimizes what crosses the border, and helps you obtain the Article 29 separate consent. Any China-facing upload or verification surface carries an ICP filing duty and needs compliant in-country delivery via the 21YunBox Optimizer, in front of the stack you already run. Get in touch to work through your specific case.

ARTICLES RELATED TO AMAZON TEXTRACT

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.