Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Azure SQL Database Work in China? Data Residency, Localization & PIPL Cross-Border

Azure SQL Database runs no mainland-China region on a standard global Azure subscription, so your database comes to rest offshore and your Chinese users' personal data is a PIPL cross-border transfer; a real in-country option exists only as Microsoft Azure operated by 21Vianet, a separate sovereign cloud. A compliance-first look at where your data lives.

Does Azure SQL Database work in China?

Reachability is not the question. Azure SQL Database is your system of record, and on a standard global Azure subscription there is no mainland-China region to keep it in — so your Chinese users' personal information rests offshore, a cross-border transfer under PIPL. A genuine in-country option exists, but only as Microsoft Azure operated by 21Vianet: a separate sovereign cloud, not a region you toggle on your account.

Microsoft describes Azure in China as “a physically separated instance of cloud services located in China,” independently operated by Shanghai Blue Cloud Technology Co., Ltd. (21Vianet), with a published “feature parity gap” against global Azure. Azure SQL Database is offered there, but reaching it means a separate account under a Chinese legal entity, separate endpoints, its own ICP, and its own compliance footing. Run the database in an offshore region instead and your China users’ personal data leaves the mainland: a cross-border transfer PIPL governs (notice, separate consent, and a transfer mechanism), and for a critical information infrastructure operator or large-volume handler, data the law says must stay in-country (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). The in-country region is a real option — it is not automatic compliance.

This is a risk map, not a verdict — which duty applies turns on your entity, your data volumes, and whose data you hold. Our China team can map your exposure →

What Azure SQL Database's own documentation says about China

FactPrimary source
Azure in China is a separate cloud, not a region you switch on. Microsoft's own documentation calls Microsoft Azure operated by 21Vianet “a physically separated instance of cloud services located in China,” “independently operated and transacted by Shanghai Blue Cloud Technology Co., Ltd. ("21Vianet"),” and states that “Azure in China has a feature parity gap, but the gap is narrowing.” On a standard global Azure subscription there is no mainland-China region to select — the in-country region lives only in that separate sovereign cloud. Microsoft Learn — Microsoft Azure in China (overview-operations), retrieved 2026-10-10
Azure SQL Database runs in China only through the 21Vianet cloud. Microsoft's Azure SQL Database connectivity documentation directs readers to “Gateway IP address ranges for regions in China” on the “Microsoft Azure operated by 21Vianet” docs — a separate operator's regions, reached on separate endpoints and a separate account, not the region picker on your global subscription. The service does exist in-country, but as part of that sovereign cloud rather than global Azure. Microsoft Learn — Connectivity architecture for Azure SQL Database, retrieved 2026-10-10
Your China users' records in an offshore database are a cross-border transfer. Because Azure SQL Database is the system of record holding personal information collected from people in China, keeping it in an offshore Azure region is a cross-border transfer under PIPL: the handler — you, Microsoft's customer, not Microsoft — must give notice, obtain separate consent, and clear one transfer mechanism, whether a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–43). PIPL Articles 38–43 (gov.cn)
Some handlers owe in-country storage a global subscription cannot provide. If you are a critical information infrastructure operator, or you process personal information above the regulated volume thresholds, personal information collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). Because a standard global Azure subscription has no mainland region, no configuration of it can meet that data-localization duty — only an in-country deployment (the 21Vianet sovereign cloud or in-mainland hosting) can. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) (gov.cn)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, the real question about Azure SQL Database is not whether it accepts a connection or how fast a query returns — it is where the data inside it is allowed to come to rest. Azure SQL Database is Microsoft’s managed, cloud-native relational database on the SQL Server engine, and it is your system of record: it holds your application’s customer records, user accounts, orders and transactions, and the personal information of your Chinese users among them. On a standard global Azure subscription, Microsoft offers no region inside mainland China, so your database rests in whichever offshore region you choose. A genuine in-country option does exist — but not as a drop-down: it is Microsoft Azure operated by 21Vianet, a separate sovereign cloud with its own account, operator, ICP, and compliance footing. The endpoint answers; the exposure is residency.

Microsoft Learn 'Microsoft Azure in China' page describing Microsoft Azure operated by 21Vianet as a physically separated instance of cloud services located in China, independently operated by Shanghai Blue Cloud Technology Co., Ltd. (21Vianet), with a feature parity gap against global Azure
Microsoft's own documentation: Azure in China is “a physically separated instance of cloud services located in China,” independently operated by Shanghai Blue Cloud Technology Co., Ltd. (“21Vianet”), and it carries a “feature parity gap” with global Azure — so running Azure SQL Database in-country means a separate sovereign cloud, not a region you toggle on your existing subscription. Source: learn.microsoft.com/azure/china/overview-operations

Azure SQL Database in China at a glance

What decides it In Azure SQL Database's own terms — and China's law
Where the data physically rests Azure SQL Database stores each database in the Azure region you select, and on a standard global Azure subscription none of those regions is inside mainland China. An in-country region exists only in a different cloud — “Microsoft Azure operated by 21Vianet” — which Microsoft calls “a physically separated instance of cloud services located in China,” not a region of your global account.
What it holds, and why it's personal information A managed relational database on the SQL Server engine — the system of record. It holds your application's customer records, user accounts, orders and transactions, so the personal information of people in China physically comes to rest inside it.
Your China users' records Kept in an offshore region, your Chinese users' personal information is a cross-border transfer PIPL governs (Articles 38–43) — held in a place China's law treats as outside the country it was collected in.
The in-country storage duty A critical information infrastructure operator or large-volume handler must store China-collected personal information in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). A global Azure subscription has no in-China region to meet it.
Reachability is not the axis Reaching the server is not the test. The lawful in-country paths are the 21Vianet sovereign cloud or in-mainland hosting; and the ICP filing (State Council Order No. 292; MIIT Order No. 33) a mainland audience needs sits on the application in front of the database, not on the database itself.

Where the data actually rests

Azure SQL Database stores each database in the Azure region you select, and that region is where the data physically rests. On a standard global Azure subscription, Microsoft offers no region inside mainland China, so whichever region you choose for a China-facing application binds your users’ records to a place China’s law treats as foreign soil. There is a real in-country option, but it is not a setting on your existing account. Microsoft’s own documentation describes “Microsoft Azure operated by 21Vianet” as “a physically separated instance of cloud services located in China,” one “independently operated and transacted by Shanghai Blue Cloud Technology Co., Ltd. (“21Vianet”).” Azure SQL Database is offered in that cloud — Microsoft’s connectivity documentation points to “Gateway IP address ranges for regions in China” on the 21Vianet docs — but it sits behind a separate account under a Chinese legal entity, on separate endpoints, with its own ICP and compliance footing, and, in Microsoft’s words, a “feature parity gap” against global Azure. “We already run on Azure” does not carry across that line.

What it holds is personal information

Azure SQL Database is not a cache or an edge in front of your data — it is your data. As the system of record on the SQL Server engine, it holds your application’s customer records, user accounts, orders and transactions, which for a China-facing product means the personal information of people in the mainland. Keep that database in an offshore Azure region and, under China’s Personal Information Protection Law, you are making a cross-border transfer: the handler — you, not Microsoft — must give notice, obtain separate consent, and clear one transfer mechanism, whether a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–43). And if you are a critical information infrastructure operator, or you process personal information above the regulators’ volume thresholds, that data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a residency duty that a global Azure region has no way to meet.

Running it offshore doesn’t meet the residency duty — and what does

Running Azure SQL Database in an offshore region — or on any managed database service with no mainland-China region — keeps your China users’ personal data outside the country, which is exactly what a data-localization duty forbids for the handlers it covers. The lawful lever is not a route back to an offshore endpoint; it is to run the database in-country. For Azure SQL Database that means the licensed sovereign option — the 21Vianet cloud — or standing up an equivalent on in-mainland infrastructure, so the personal information that must stay on Chinese soil actually does. An in-country region is a real option, but it is not automatic compliance: the 21Vianet cloud is a separate operator with its own account, ICP filing, and obligations, and any data still flowing across the border keeps its PIPL transfer requirements. None of this requires abandoning Azure SQL Database or rewriting your application — it requires putting the data where the law allows it to rest and filing the China-facing surface correctly. Whether a localization duty applies to you, which cross-border mechanism fits, and whether you need the sovereign cloud at all depend on your entity, how much personal data you hold, and whose it is — worth settling with counsel before you build.

The lawful path — map, localize, deliver

You keep Azure SQL Database as your database. What 21YunBox adds is the compliance layer it was never meant to provide on its own, arranged around the stack you already run — no rebuild, no second codebase, no migration.

  • Map. Our China team reads your PIPL cross-border, data-residency, and data-localization (CII) obligations, and any ICP duty, against your entity, your data volumes, and whose personal information sits in the database.
  • Localize. Where the law requires your China users’ data to stay on the mainland, we run the database in-country — on a licensed sovereign option or in-mainland infrastructure — and keep consented, in-country storage for what must stay. Localize means an in-country database, not a route back to an offshore endpoint.
  • Deliver. Any China-facing surface in front of the database — the app, the API edge, the admin or reporting portal your mainland users reach — runs over ICP-filed, in-country delivery (the 21YunBox Optimizer), in front of the stack you already have.

The result runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We are a compliant overlay and a partner to Microsoft and Azure, not a competitor and not a migration.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Azure SQL Database have a mainland-China region?
On a standard global Azure subscription, no. Microsoft runs its mainland regions as a separate cloud — “Microsoft Azure operated by 21Vianet” — which it calls “a physically separated instance of cloud services located in China.” Azure SQL Database is offered in that sovereign cloud (China East / China North), but reaching it means a separate account under a Chinese legal entity, separate endpoints, and its own ICP and compliance footing — not a region you pick on your global subscription. So a global deployment leaves your China data offshore.
Is running Azure SQL Database offshore for Chinese users illegal?
Treat it as a risk to assess with counsel, not a blanket yes or no. One thing follows directly: personal information you collect from people in China and keep in an offshore region is, under PIPL, a cross-border transfer — you must give notice, obtain separate consent, and clear a transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Whether an in-country storage duty also bites, requiring the data to stay in the mainland, turns on your role (for example a critical information infrastructure operator) and the volume of personal information you handle (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)).
Can 21YunBox help make our Azure SQL Database setup compliant for China?
Yes. Our China team maps your PIPL cross-border and data-residency exposure for your entity, data volumes and users, then — where the law requires your China users' data to stay on the mainland — runs the database in-country on a licensed sovereign option or in-mainland infrastructure, and stands up the ICP-filed, in-country delivery the application in front of it needs, around the stack you already run, with no rebuild and no migration. Get in touch to work through your specific data flows.

ARTICLES RELATED TO AZURE SQL DATABASE

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.