Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does AWS WAF Work in China? ICP, Cross-Border Request Data & the Separate China Partition

AWS WAF does run inside mainland China — but only in AWS's separate China partition (Beijing operated by Sinnet, Ningxia operated by NWCD), reached with a China account and an ICP filing, not your global AWS account. Keep a non-China AWS WAF in front of a China-facing property instead and the request data it inspects and logs — client IP addresses, headers and bodies — is read across the border, a cross-border transfer of personal information under PIPL. A compliance-first look at the ICP, cross-border and data-residency questions, and the lawful in-country path.

Does AWS WAF work in China?

Yes — AWS WAF does run inside mainland China, so the honest answer isn't "no." But it runs only in AWS's separate China partition, and that is where the compliance question starts, not ends.

AWS offers the service (branded "Amazon WAF" in-country) in its two mainland Regions — Beijing, operated by Sinnet, and Ningxia, operated by NWCD — a partition you reach with a separate China account, a Chinese business license and, for any public property, an ICP filing. Your global AWS account does not carry over. Keep a non-China AWS WAF in front of a China-facing site or API instead, and the request data it is built to read and log — client IP addresses, HTTP headers, request bodies — is inspected from offshore Regions, which makes moving it across the border a cross-border transfer of personal information under PIPL (notice, a separate consent, and one transfer mechanism; Articles 38–40). For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore Region cannot meet.

So the lawful path is to inspect and deliver on an in-country footing — the China partition, ICP-filed, with the data held in the mainland — not a non-China WAF reaching across the border, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel; our China team can map your exposure with you →

What AWS WAF's own documentation says about China

FactPrimary source
AWS WAF runs inside mainland China, but only in the separate AWS China partition. AWS's own "Amazon Web Services in China" Region Table lists Amazon WAF as available ("✓") in both the Beijing and Ningxia Regions, and states that "[t]he service operator and provider for Amazon Web Services China (Beijing) Region … is Beijing Sinnet Technology Co., Ltd. (\"Sinnet\")" and that the Ningxia Region's operator "is Ningxia Western Cloud Data Technology Co., Ltd. (\"NWCD\")." Reaching that partition is a separate step from the global AWS account you already run. Amazon Web Services in China — Region Table (amazonaws.cn), last updated February 28, 2026, retrieved 2026-10-09
The China Regions are a separate, locally-operated partition with its own account gate. Per AWS's China FAQ, customers "are required to sign up for a separate set of account credentials unique to Amazon Web Services China services," and "[c]ustomers with existing Amazon Web Services Inc. credentials will not be able to access resources in the Amazon Web Services China Regions, and vice versa." Registering a China account requires "a valid Chinese business license issued by the Bureau of Industry and Commerce." So "we already run AWS WAF" does not carry into the mainland. Amazon Web Services China FAQs (amazonaws.cn), retrieved 2026-10-09
A public property served from the China Region needs an ICP filing. AWS's China FAQ states that to host a website providing non-commercial internet information services you "must undertake filing procedures for a non-commercial website (\"ICP Recordal\")" and, for commercial services, "must obtain a value-added telecommunications license for a commercial website (\"ICP License\")" — the regime under State Council Order No. 292 and MIIT Order No. 33. A web application firewall is not a substitute for that filing. Amazon Web Services China FAQs (amazonaws.cn), retrieved 2026-10-09; State Council Order No. 292; MIIT Order No. 33
A WAF reads and logs request data — so running it offshore to guard a China property crosses the border. By AWS's own description, Amazon WAF lets you "filter any part of the web request, such as IP addresses, HTTP headers, HTTP body, or URI strings," and offers "comprehensive logging by capturing each inspected web request's full header data." Those client IPs, headers and bodies are personal information; inspecting and storing them in a non-China AWS Region is a cross-border transfer under PIPL Articles 38–40 (notice, a separate consent, and one transfer mechanism), and may trigger China's data-export security assessment. Amazon WAF product page (amazonaws.cn/waf), retrieved 2026-10-09; PIPL Articles 38–40

Sources verified by the 21YunBox compliance team on 2026-10-09.

Whether AWS WAF “works” in mainland China is a compliance question before it is a performance one — and for a web application firewall the compliance question has a particular shape, because a WAF exists to read the traffic it guards. AWS WAF does run inside the mainland, but only through AWS’s separate China partition, reached with a Chinese entity, a separate account and an ICP filing. Keep a non-China AWS WAF in front of a China-facing property instead, and the client IP addresses, headers and request bodies it inspects and logs are read from offshore — a cross-border movement of personal information, not just a routing detail. AWS states where its China service runs, and who operates it, in its own words.

Amazon Web Services in China Region Table showing that the Beijing Region is operated by Beijing Sinnet Technology Co., Ltd. (Sinnet) and the Ningxia Region by Ningxia Western Cloud Data Technology Co., Ltd. (NWCD), with Amazon WAF marked available in both the Beijing and Ningxia Regions
AWS's own “Amazon Web Services in China” Region Table: “The service operator and provider for Amazon Web Services China (Beijing) Region based out of Beijing and adjacent areas is Beijing Sinnet Technology Co., Ltd. (“Sinnet”). And the service operator and provider for Amazon Web Services (Ningxia) Region based out of Ningxia is Ningxia Western Cloud Data Technology Co., Ltd. (“NWCD”).” The same table lists Amazon WAF as available in both the Beijing and Ningxia Regions. Source: Amazon Web Services in China — Region Table

AWS WAF in China at a glance

What decides it In AWS's own terms — and China's law
Where it runs in-country AWS offers the service — branded Amazon WAF in-country — in its two mainland Regions, Beijing (cn-north-1) operated by Sinnet and Ningxia (cn-northwest-1) operated by NWCD, a partition separate from global AWS. AWS's Region Table lists Amazon WAF as available in both.
Entity & account Reaching that partition needs a separate AWS (China) account “unique to Amazon Web Services China services,” under “a valid Chinese business license issued by the Bureau of Industry and Commerce.” Global credentials “will not be able to access resources in the Amazon Web Services China Regions, and vice versa.”
Serving the public A site hosted in a China Region must file: a non-commercial one “must undertake filing procedures … (“ICP Recordal”),” a commercial one “must obtain a value-added telecommunications license … (“ICP License”)” — before it can host public content.
What a firewall inspects By design AWS WAF filters “any part of the web request, such as IP addresses, HTTP headers, HTTP body, or URI strings,” and logs “each inspected web request's full header data.” That request data is personal information.
On a non-China AWS WAF No in-mainland inspection point: a China-facing property guarded by a WAF in any global Region is screened from offshore, routing that request personal information across the border — a transfer PIPL governs, on infrastructure that cannot be ICP-filed.

Door one — in-country AWS WAF lives in AWS’s separate China partition

AWS WAF does reach inside mainland China, but not from the account you already have. AWS offers the service — branded Amazon WAF in-country — in its two mainland Regions, and its own Region Table lists it as available in both Beijing and Ningxia. Those Regions are a partition apart from global AWS: as AWS puts it, the Beijing Region is operated by Beijing Sinnet Technology Co., Ltd. (“Sinnet”) and the Ningxia Region by Ningxia Western Cloud Data Technology Co., Ltd. (“NWCD”).

Reaching that partition means the same gate AWS sets for all of its China Regions. Customers “are required to sign up for a separate set of account credentials unique to Amazon Web Services China services,” and “[c]ustomers with existing Amazon Web Services Inc. credentials will not be able to access resources in the Amazon Web Services China Regions, and vice versa.” Registering one needs “a valid Chinese business license issued by the Bureau of Industry and Commerce.” And to serve the public, AWS’s own FAQ is explicit: a non-commercial site “must undertake filing procedures for a non-commercial website (“ICP Recordal”),” and a commercial one “must obtain a value-added telecommunications license for a commercial website (“ICP License”).” So “we’re already on AWS WAF” does not carry into China; the in-country door is a Chinese entity, a separate account and an ICP filing — the same two-door structure AWS sets out in full for its China Regions (see Does AWS work in China?).

Door two — a firewall reads the traffic, so running it offshore crosses the border

Here is the part specific to a WAF. A web application firewall is not a passive pipe; its whole job is to inspect what passes through it. In AWS’s own description, Amazon WAF lets you “filter any part of the web request, such as IP addresses, HTTP headers, HTTP body, or URI strings,” and it offers “comprehensive logging by capturing each inspected web request’s full header data.” Those client IP addresses, headers and request bodies, pulled from people in China, are personal information.

So where you place the firewall is itself a data-handling decision. Keep a non-China AWS WAF — in Tokyo, Hong Kong, Oregon, anywhere outside the mainland — in front of a China-facing site or API, and every request it screens is carried out of the country to be read, and often logged, offshore. Under China’s Personal Information Protection Law that is a cross-border transfer, and the duty falls on you as the handler, not on AWS as the processor: notice, a separate consent for the overseas transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (Articles 38–40). Above certain thresholds it may also require China’s data-export security assessment (数据出境安全评估) before anything leaves.

Residency is the other half. If your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization clause was renumbered by the 2025 amendment in force since January 1, 2026, its substance unchanged) requires personal information generated in China to be stored in China (see also PIPL Article 40) — a duty a WAF logging full request headers to an offshore Region cannot satisfy. None of this turns on how fast the firewall is; it turns on where it reads and keeps the traffic. For that reason this page publishes no China latency figure for AWS WAF: speed is not the axis for a decision that turns on residency and cross-border transfer.

This is a risk map, not a verdict that AWS WAF is “blocked” or “illegal.” Which of these obligations bite depends on your entity, the personal data your traffic carries, your role under Chinese law and who your users are — worth settling with counsel before your protection depends on it.

Why pointing the WAF at a nearer Region isn’t the fix

The reflex is to move the firewall to the closest AWS Region — Hong Kong, say — and call the distance problem solved. But every global AWS WAF Region sits outside mainland China, so a nearer one changes the latency, not the law: the request data is still inspected and logged across the border, and the transfer is unchanged. The only placement that keeps a China user’s request data in the country is an in-country one — AWS WAF inside the China partition (ICP-filed, the data held in the mainland under Sinnet or NWCD), or an equivalent in-country edge-security layer. Which traffic must be inspected in-country, and which may be screened elsewhere, is a legal question before it is a networking one.

The lawful path — map, localize, deliver

There is a compliant way to keep a web application firewall in front of a China-facing property, and it has a shape.

First, map. Our China compliance team charts where your WAF actually inspects and logs traffic today, and the exposure that follows: whether the client IP addresses, headers and request bodies it reads from China users leave the mainland, which PIPL transfer and consent duties attach, whether a data-export security assessment or an in-country storage duty bites for your role and volumes, and whether the protected property owes an ICP filing. We build the technical picture; the legal conclusions are settled with your counsel.

Then localize. Where request inspection has to happen on a China footing, we move it onto a lawful in-country option — AWS’s own China partition (Beijing/Ningxia, ICP-filed, with the data held in-country under Sinnet or NWCD) or an equivalent in-country edge-security layer — so the firewall protecting your China users stops reading and storing their request data offshore by default, while you keep AWS WAF for the markets where it already serves you.

Then deliver. The China-facing site or API that sits behind the firewall is itself a public service in the mainland, so it carries an ICP-filing duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of the origin you already run, with no rebuild and no re-platform. The result is a China-facing property whose protection and delivery both run legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind: what we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction. We localize what must stay in-country, deliver in-country, and never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is AWS WAF available in mainland China?
Yes — unlike some foreign tools, AWS WAF has a genuine in-country option. AWS offers it (as "Amazon WAF") in its two mainland Regions, Beijing (operated by Sinnet) and Ningxia (operated by NWCD). But that partition is separate from your global AWS account: it needs its own China account under a valid Chinese business license, and any public property it protects needs an ICP recordal or ICP license. Availability is not the obstacle — the China account, the ICP gate, and where your request data is inspected are. Confirm your exact obligations with counsel.
Is using AWS WAF for China a cross-border data transfer?
It can be. If you keep a non-China AWS WAF in front of a China-facing site or API, the request data it is designed to read and log — client IP addresses, HTTP headers, request bodies — is inspected from offshore AWS Regions, which makes moving that personal information across the border a cross-border transfer under PIPL (notice, a separate consent, and one transfer mechanism; Articles 38–40). For a critical information infrastructure operator, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore Region cannot meet, and a data-export security assessment may apply above thresholds. The lawful in-country path is the China partition, not a non-China WAF reaching across the border — settle the specifics with counsel.
Can 21YunBox help run AWS WAF compliantly for China?
Yes. Our China team can map the ICP and cross-border exposure that attaches to the traffic your WAF inspects, for your entity, data volumes and users; localize request inspection onto a lawful in-country footing so your China users' request data stops being read and stored offshore by default; and stand up compliant, ICP-filed, in-country delivery in front of the stack you already run. Get in touch to work through your specific case — we never use or suggest circumvention of any kind.

ARTICLES RELATED TO AWS WAF

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.