Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Azure AI Document Intelligence Work in China? The 21Vianet Path, PIPL Cross-Border & Sensitive-Data Rules

Azure AI Document Intelligence (formerly Form Recognizer) reads the invoices, contracts, passports and ID cards your China operation sends it — content that IS the personal information, often sensitive (ID numbers, financial accounts) under PIPL Article 28. It runs in-country on Microsoft Azure operated by 21Vianet, but a global endpoint processes those documents offshore, a PIPL cross-border transfer. A compliance-first look at the residency, sensitive-data and cross-border exposure.

Does Azure AI Document Intelligence work in China?

The invoices, contracts and — through its prebuilt ID model — the passports and ID cards your China operation sends Azure AI Document Intelligence to read ARE the personal information, often sensitive (ID numbers, financial accounts) under PIPL Article 28; it is offered in-country on Microsoft Azure operated by 21Vianet, but a global endpoint processes those documents offshore — a PIPL cross-border transfer of sensitive personal data.

You send the service documents to extract, and its prebuilt identity-document model is built to read passports, ID cards, and driver's licenses, so the content is frequently sensitive personal information (PIPL Article 28) — an ID or bank-card number that cannot be minimized, because it IS what you sent the document to read. Routing those documents through a global (non-China) endpoint is a cross-border transfer (PIPL Articles 38–40, plus the Article 29 separate consent for sensitive data), and at volume can raise important-data and CAC data-export assessment duties; where the flow decides a KYC outcome, Article 24 applies. The lawful lever is to keep the document processing in-country — on the 21Vianet-operated path or a domestic alternative — minimize, obtain the separate consent, and ICP-file any China-facing surface, not to make the offshore API reachable.

Whether a given document is sensitive or "important data" turns on what you process and your sector — settle the specifics with counsel. Our China team can map your exposure →

What Azure AI Document Intelligence's own documentation says about China

FactPrimary source
Document Intelligence is offered in the 21Vianet-operated Azure China cloud. Microsoft's own FAQ states that “Document Intelligence Studio has separate URL endpoints for sovereign cloud regions,” including one for “Microsoft Azure operated by 21Vianet (Azure China)” (a .azure.cn endpoint) — a separate, network-isolated sovereign cloud, distinct from the global service. Confirm the specific regions, models, and API version with Microsoft and 21Vianet. Microsoft Learn — Azure AI Document Intelligence FAQ (learn.microsoft.com), retrieved 2026-10-11
Its prebuilt ID model reads passports, ID cards, and driver's licenses. Microsoft's Document Intelligence documentation describes the identity-document (ID) model as extracting “key information from passports and ID cards” and lists “Know your customer (KYC) financial services guidelines compliance” as a use case — so the content you upload is frequently sensitive personal information (ID and financial-account numbers). Microsoft Azure operated by 21Vianet — What Is Azure Document Intelligence? (docs.azure.cn), retrieved 2026-10-11
ID and financial-account numbers are sensitive PI, and sending them abroad is a cross-border transfer. Under PIPL Article 28, ID numbers, financial accounts, and biometrics are sensitive personal information — requiring the Article 29 separate consent and a prior impact assessment — and routing China-collected documents to an offshore region is a cross-border transfer under Articles 38–40 (notice, separate consent, and a transfer mechanism). 21YunBox — China Personal Information Protection Law (PIPL), Articles 28–29, 38–40, retrieved 2026-10-11
Residency and a data-export assessment can bite at scale. For a critical information infrastructure operator or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires China-generated personal information to be stored in China; large-volume or “important data” exports add a mandatory CAC data-export security assessment before anything leaves. 21YunBox — China Cybersecurity Law (data localization) & CAC Data-Export Security Assessment Measures, retrieved 2026-10-11

Sources verified by the 21YunBox compliance team on 2026-10-11.

For a company running Azure AI Document Intelligence for a mainland-China operation, the question is not whether the API answers from Shanghai. A document-OCR service works by you sending it the thing to be read — an invoice, a contract, and in its prebuilt identity-document model a scanned passport, ID card, or driver’s license — and that content is the personal information, frequently the most sensitive kind. Azure AI Document Intelligence (the OCR and intelligent-document-processing service formerly called Form Recognizer) is a Microsoft Azure service, and here the honest answer has a hopeful shape: it is offered in-country on Microsoft Azure operated by 21Vianet (世纪互联), the separate, network-isolated sovereign cloud that runs inside the mainland, as well as in Azure’s global regions. Which Azure you call decides the rest. A global endpoint processes your documents offshore — a PIPL cross-border transfer of (often sensitive) personal information, carrying the Article 29 separate consent and Article 28 sensitive-data duties on ID numbers and financial accounts, residency for a CIIO or high-volume handler, an Article 24 question where the flow decides a KYC outcome, and ICP for any China-facing upload surface. The 21Vianet-operated path keeps the processing in-country — a path to confirm, not a block to get past.

Microsoft Learn Azure AI Document Intelligence FAQ, stating that Document Intelligence Studio has separate URL endpoints for sovereign cloud regions, including one for Microsoft Azure operated by 21Vianet (Azure China)
Microsoft's own documentation confirms a dedicated China endpoint: “Document Intelligence Studio has separate URL endpoints for sovereign cloud regions,” among them one for “Microsoft Azure operated by 21Vianet (Azure China).” That 21Vianet-operated cloud is a separate, in-country path — while a global endpoint processes your documents offshore. Source: Microsoft Learn — Document Intelligence FAQ

Azure AI Document Intelligence in China at a glance

What decides it In Azure AI Document Intelligence's own terms — and China's law
What you send it The service works by you uploading the document to be read — invoices, receipts, contracts, and forms through its layout and prebuilt models, and, through the prebuilt identity-document (ID) model, passports, ID cards, and driver's licenses. The content you send is the personal information, and in the ID / KYC case it is the most sensitive kind: an ID number or bank-card number you cannot "minimize," because it is the thing you sent the document to read.
Where it runs Two Azures matter for China. The global Azure service, operated by Microsoft, sits outside the mainland; Microsoft Azure operated by 21Vianet (世纪互联) is a separate, network-isolated sovereign cloud inside the mainland, with its own portal.azure.cn and .azure.cn endpoints — and Document Intelligence is offered there. A global endpoint processing China-collected documents is a cross-border transfer (数据出境) under PIPL Articles 38–40, plus the Article 29 separate consent for sensitive data.
The sensitive-PI door Under PIPL Article 28, ID numbers, financial-account numbers, and biometrics are sensitive personal information — they need a separate specific consent and a prior impact assessment, and strict minimization. The sharp point for OCR: the sensitive datum is the input, so it cannot be anonymized away before transfer. An offshore ID / KYC extraction ships sensitive PI across the border by design.
Automated decision + residency Where the flow automatically decides an outcome — approving or denying a KYC check from the extracted fields — that is automated decision-making under PIPL Article 24 (the data subject can refuse a decision made solely by automation). For a critical information infrastructure operator or high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) requires in-country storage; at volume, "important data" and a CAC data-export security assessment can apply.
Reachability is not the axis Whether the API answers quickly from the mainland is an operational matter, not the compliance question. What decides it is where the documents — and the sensitive data inside them — are processed: in-country on the 21Vianet-operated path (or a domestic alternative), or offshore in a global region. 21YunBox maps the exposure, localizes onto the data-resident option, obtains the separate consent, and delivers any China-facing surface compliantly — no rebuild.

What you actually send it — and why the content is the risk

Azure AI Document Intelligence is an OCR and intelligent-document-processing service: you hand it a file and it returns structured text, key-value pairs, tables, and — for its prebuilt models — named fields. Its general models read forms, invoices, receipts, and contracts; its prebuilt identity-document (ID) model is built, in Microsoft’s own words, to extract “key information from passports and ID cards,” and the documentation lists “Know your customer (KYC) financial services guidelines compliance” among its use cases. That is the heart of the matter. For a blank template or a generic form, the data may be unremarkable. For an onboarding flow, an expense system, or a KYC check, the thing you upload is a person’s passport, national ID, or bank card — and the number on it is sensitive personal information that cannot be minimized, because extracting it is the whole point of the call.

On where it runs, the honest answer is the hopeful one most foreign document-AI services cannot give: a data-resident, in-country footing already exists. Microsoft hosts Document Intelligence’s documentation on its 21Vianet-operated (.azure.cn) docs site and provides a dedicated Document Intelligence Studio endpoint for “Microsoft Azure operated by 21Vianet (Azure China).” That is a separate cloud from the global service, and — as with other Azure AI services on 21Vianet — its catalog, regions, and API versions can lag the global one. So whether the specific models and API version your product depends on are available in the China cloud is something you confirm directly with Microsoft and 21Vianet before you build. What settles the compliance question is not the frame rate of a response; it is which Azure holds the documents.

The doors: sensitive personal data, cross-border transfer, and automated decisions

Once China-collected documents are processed outside the mainland, a different body of law decides whether they were allowed to go there. The contents of an invoice, a contract, or an ID card are personal information under China’s Personal Information Protection Law, and running them through a global (non-China) endpoint is a cross-border transfer (数据出境). PIPL puts the duty on the handler — your China entity, not Microsoft: Articles 38–40 require notice, a separate consent for the overseas transfer, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification).

The sensitive cases raise the bar. Under PIPL Article 28, ID numbers, financial-account numbers, and biometric data are sensitive personal information, and Article 29 adds a separate specific consent and a prior personal-information protection impact assessment before any of it moves. Here the usual escape — minimize or de-identify before transfer — does not apply, because the sensitive datum is the input you sent the document to read. Where the flow decides an outcome automatically (approve or deny a KYC check from the extracted fields), that is automated decision-making under PIPL Article 24. And on residency: if your organization is a critical information infrastructure operator or a large-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with its substance unchanged) requires personal information generated in China to be stored in China. At scale, high volumes of document data can raise the “important data” (重要数据) question under the Data Security Law, which makes a CAC data-export security assessment mandatory before anything leaves. Which of these bite your specific deployment turns on your sector, your data volumes, and your role under Chinese law.

Calling the API isn’t the question — compliant in-country processing is

The fix is not to make an offshore endpoint reachable — it is to put the document processing where the law needs it. Because Document Intelligence runs in-country on the 21Vianet-operated cloud, you have a genuine residency lever: keep the China OCR on that data-resident path (or on a China-legal domestic alternative where the model or API version you need is not yet available there), so the invoices, contracts, and identity documents your mainland entity handles stay on the mainland, with only what may lawfully leave flowing to a global instance. That is localization in the real sense — keeping the data on an in-country path — never a tunnel that ships it offshore anyway. On top of that, any China-facing surface that calls the service — an upload page, an onboarding or verification flow, a document-backed portal — is an internet information service served in the mainland, so it carries an ICP filing (备案) duty bound to a mainland hosting resource, plus compliant in-country delivery. None of this is a verdict that Document Intelligence is “blocked” or “illegal” in China — it runs there lawfully when the pieces line up. It is a residency-and-exposure map, and whether a given document or image is sensitive or “important data” turns on what you process and your sector — worth settling the specifics with counsel before your China operations depend on it.

The lawful path — map, localize, deliver

There is a compliant way to run document AI for a China operation, and it has a shape. First, map: our China team inventories what you send the service — the invoices, contracts, forms, and the identity documents — which of it is sensitive PI (ID numbers, financial accounts), where it is processed today (a global region, or the 21Vianet-operated China cloud), the cross-border and Article 28/29 consent basis each transfer would need, whether any of it is “important data,” and whether the flow makes an automated decision under Article 24. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we help you keep the China document processing in-country — on the data-resident 21Vianet-operated path where the models and API version you need are available, or a China-legal domestic alternative where they are not — so the sensitive data stops leaving the mainland by default, while your global instance keeps serving your other markets. We minimize what crosses the border and help you obtain the Article 13/23 notice-and-consent and the Article 29 separate consent for the sensitive data. Localize means keeping the data on an in-country path, never moving it offshore by stealth.

Then deliver: any China-facing surface on top of the stack — an upload page, a KYC or verification flow, a document-backed community — needs compliant, in-country delivery and carries an ICP filing duty. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform. The result is a document-AI footprint that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind — we keep in-country what the law says must stay, deliver the rest compliantly from inside the mainland, and never move personal information across the border by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is Azure AI Document Intelligence available in mainland China?
Yes, through a separate cloud. Microsoft's FAQ shows Document Intelligence with a dedicated sovereign-cloud endpoint for “Microsoft Azure operated by 21Vianet (Azure China),” and Microsoft hosts the service's documentation on its 21Vianet-operated (.azure.cn) docs site — a separate, network-isolated cloud from the global service. Because the China cloud's catalog, regions, and API versions can lag the global one, confirm the specific models and version you need with Microsoft and 21Vianet before you build. It is a lawful in-country path, not a way around anyone's terms.
Can I just use my existing (global) Document Intelligence resource for documents from China?
You can reach it, but reachability isn't the compliance question. A resource in a global (non-China) region processes the documents you upload outside the mainland — a cross-border transfer under PIPL Articles 38–40 (notice, a separate consent, and a transfer mechanism). The sharp issue is that OCR inputs are often ID cards, passports, and bank cards: ID and financial-account numbers are sensitive personal information under PIPL Articles 28–29, which cannot be minimized because they ARE what you sent the document to read, and at volume important-data and CAC data-export-assessment duties can apply. Confirm your exact obligations with counsel.
What's the compliant, in-country path for document OCR in China?
Keep the document processing in-country — on the 21Vianet-operated Document Intelligence path where the models and API version you need are available, or a China-legal domestic alternative where they are not — so the invoices, contracts, and identity documents stay on the mainland; minimize what crosses the border and obtain the Article 29 separate consent for the sensitive data. Any China-facing upload or verification surface that calls the service needs an ICP filing and compliant in-country delivery. 21YunBox maps the exposure, localizes onto the data-resident option, and delivers it in-country — no rebuild. It is a lawful in-country deployment, not a way around anyone's terms.

ARTICLES RELATED TO AZURE AI DOCUMENT INTELLIGENCE

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.