Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Bitwarden Work in China? Vault Data Residency, PIPL & Self-Hosting

Bitwarden's cloud stores vault and account data only in its US or EU regions — it runs no mainland-China data center — so holding your China users' passwords, passkeys and secrets in that cloud is a cross-border transfer of personal information under PIPL, with an in-country storage duty for a CIIO or large-volume handler that an offshore region cannot meet. End-to-end encryption lowers the exposure but does not discharge the notice, consent, transfer-mechanism and residency duties. The lawful path runs through Bitwarden's own self-hosted deployment on China-resident, ICP-filed infrastructure.

Does Bitwarden work in China?

For a password manager the China question is not whether the app opens — it is where the vault comes to rest. Bitwarden's cloud stores vault and account data only in its US or EU regions, with no mainland-China data center. So reaching it is a delivery detail; residency and lawful basis are what decide whether you may use it for your China users.

Holding your China users' passwords, passkeys, secrets and account PII in an offshore Bitwarden cloud is a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40: notice, a separate consent, and one transfer mechanism), and it may trigger China's data-export security assessment. Bitwarden's end-to-end encryption lowers the exposure but does not discharge those duties — encryption is a safeguard, not an exemption. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) and PIPL Article 40 add an in-country storage duty an offshore region cannot meet.

The strong move is Bitwarden's own self-hosted deployment: 21YunBox stands it up on China-resident, ICP-filed infrastructure for your China entity, keeps Bitwarden's cloud for your other markets, and delivers it in-country — with no move off Bitwarden, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.

What Bitwarden's own documentation says about China

FactPrimary source
Bitwarden's cloud stores data only in the US and EU — with no mainland-China region. Bitwarden's Server Regions help article states: “The Bitwarden cloud is available globally with data storage in both United States and European Union regions,” and that “Bitwarden server regions are separate, and your account or organization only exists in the region where it was first created.” The page names no mainland-China region, so the vault and account data of your China users rests offshore. Bitwarden Help Center — Server Regions (bitwarden.com), retrieved 2026-10-09
Vault data is stored in Microsoft Azure in the US or EU. Bitwarden's Data Storage help article states: “Bitwarden processes and stores all vault data securely in the Microsoft Azure Cloud in the US or EU using services that are managed by the team at Microsoft.” Neither location is in mainland China, so collecting your China users' credentials into it is a cross-border transfer of personal information under PIPL. Bitwarden Help Center — Data Storage (bitwarden.com), retrieved 2026-10-09
Bitwarden can be self-hosted on your own infrastructure — the basis of the lawful in-country route. Bitwarden's documentation states: “Before you can self-host an organization, you'll need to install and deploy Bitwarden to your server,” and “Bitwarden can be run, using Docker, on Linux and Windows machines,” including “methods for offline or air-gapped environments.” Run on China-resident infrastructure for your China entity, this keeps the vault in the country by design. Bitwarden Help Center — Self-host an Organization (bitwarden.com), retrieved 2026-10-09
China-collected vault and account data sent to an offshore cloud is a PIPL cross-border transfer, with an in-country storage duty for some handlers. Moving personal information collected from users in mainland China to a Bitwarden cloud in the US or EU triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) — with an in-country storage duty under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) for a critical information infrastructure operator or large-volume handler. Personal Information Protection Law of the PRC, Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-09

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a password manager, the China question is not whether the app opens — it is where the vault comes to rest. Bitwarden holds the most concentrated personal data a company keeps: the passwords, passkeys, secrets and vault items of its people, plus the account identifiers behind them. Reaching the service from the mainland is a delivery detail; what decides whether you may use it for your China users is where that vault is stored and on what lawful basis it left the country. Bitwarden answers the storage half plainly in its own documentation — and it offers a second deployment model that changes the whole picture.

Bitwarden's Server Regions help page stating that the Bitwarden cloud offers data storage in both United States and European Union regions, naming no mainland-China region
Bitwarden's own Server Regions help page: “The Bitwarden cloud is available globally with data storage in both United States and European Union regions.” The only regions it names are the US and the EU — no mainland-China data center — so the vault your China users keep is held offshore. Source: Bitwarden Help Center — Server Regions

Bitwarden in China at a glance

What decides it In Bitwarden's own terms — and China's law
What it is An open-source password, passkey and secrets manager, offered two ways: Bitwarden's cloud (Bitwarden hosts) and a self-hosted/self-managed deployment you run yourself. Either way it holds a concentrated store of credentials plus account personal information — the most sensitive data category, in one place.
Is it reachable from the mainland? Bitwarden's apps and browser extensions sync to its cloud servers, so this is a delivery question, and cross-border connections to an offshore vault can be inconsistent — an operational matter, not the decision. Reachability is not the China question; where the vault and account data live, and under what lawful basis, is.
Where the cloud data lives Offshore. Bitwarden says its cloud offers “data storage in both United States and European Union regions,” and stores vault data “in the Microsoft Azure Cloud in the US or EU.” There is no mainland-China region, so your China users' vault and account data rests outside the country.
Collecting China vault & account data into the cloud The passwords, passkeys, secrets and account identifiers are personal information. Holding them in a US or EU Bitwarden is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. End-to-end encryption is a safeguard, not an exemption. For a CIIO or large-volume handler, PIPL Article 40 and the Cybersecurity Law's Article 39 (formerly Article 37) add an in-country storage duty an offshore region cannot meet.
Serving the public / ICP An offshore vault cannot hold an ICP filing. A self-hosted Bitwarden that serves your China users from inside the mainland is a public internet service — it needs an ICP filing bound to a mainland hosting resource, plus compliant in-country delivery.
The lawful path Self-host Bitwarden on China-resident infrastructure for your China entity (consented, in-country storage), keep Bitwarden's cloud for your other markets, and deliver it in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention.

Availability isn’t the question — the vault’s location is

The first instinct is to check whether Bitwarden’s apps and browser extensions can reach the service from the mainland. They sync to Bitwarden’s cloud servers, so that is a delivery question, and cross-border connections to an offshore vault can be inconsistent — an operational matter, not the decision. For that reason this page publishes no China latency or reachability figure for Bitwarden: speed is not the axis for a decision that turns on residency and lawful basis. And the temptation, when a cross-border sync is flaky, is to force it through a network workaround — 21YunBox neither uses nor suggests any form of circumvention, because it is both a compliance risk and beside the point. The productive question is where the vault may lawfully live.

The vault is the most sensitive data you hold — and offshore by default

Bitwarden’s storage posture is stated plainly, not inferred from a load test. Its Data Storage article says Bitwarden “processes and stores all vault data securely in the Microsoft Azure Cloud in the US or EU,” and its Server Regions article says the cloud offers “data storage in both United States and European Union regions,” with each account living “only… in the region where it was first created.” There is no mainland-China region to choose.

So the moment the passwords, passkeys, secrets and account identifiers you hold for people in China land in a US or EU Bitwarden, you have made a cross-border transfer (数据出境) of personal information, and China’s Personal Information Protection Law decides whether that was allowed. PIPL puts the duty on the handler — you, not Bitwarden the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the data is “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And for a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — an in-country storage duty a US or EU vault cannot meet.

It is fair to ask whether Bitwarden’s end-to-end encryption settles this. It helps, and honestly so: vault contents are encrypted on the device before they reach the server, so Bitwarden stores ciphertext it cannot read. But encryption is a safeguard the law credits, not an exemption from it. PIPL is triggered by the cross-border movement of personal information, encrypted or not; the account-level data around the vault — email, billing, IP and login metadata, organization membership — is still held offshore; and the residency duty above turns on where the data sits, not on whether it is readable. Which of these bite your specific case is a risk to confirm with counsel against what you actually collect and store.

No mainland region on the cloud — and why self-hosting changes that

Two duties settle before performance ever enters. Residency: for a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland — a duty a US or EU vault cannot satisfy however it is tuned. Licensing: a public-facing service actually served to mainland users from inside China turns on an ICP filing (备案) bound to a mainland hosting resource, and an offshore vault has nothing to file against. On Bitwarden’s cloud, both are structurally out of reach.

This is where Bitwarden differs from a cloud-only platform. Bitwarden is built to be self-hosted — in its own words, you “install and deploy Bitwarden to your server,” and it “can be run, using Docker, on Linux and Windows machines,” with methods even for air-gapped environments. Stood up on China-resident infrastructure for your China entity, that same product keeps the vault in the country by design. A light license-and-billing tie to Bitwarden’s cloud remains — metadata, not the vault — and what must stay versus what may leave is exactly the line to draw with counsel. A self-hosted server that then serves your China users is itself a public internet service, so it carries the ICP filing and in-country delivery duties in turn.

The lawful path — map, localize, deliver

There is a compliant way to run Bitwarden for China, and self-hosting gives it an unusually clean shape.

First, map: our China team works through your PIPL exposure — which credentials, secrets and account data collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your notice and consent flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: rather than send the most sensitive data you hold across the border, we stand up Bitwarden’s own self-hosted deployment on China-resident infrastructure for your China entity, so the vault stays in-country by design — and you keep Bitwarden’s cloud for the markets where it already serves you.

Then deliver: a self-hosted vault that serves your China users is a public service in the mainland, so it carries an ICP filing duty and needs compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you run, with no rebuild and no re-platform. The result is a password manager that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Bitwarden store my China users' passwords in China?
No. By Bitwarden's own Server Regions article, “The Bitwarden cloud is available globally with data storage in both United States and European Union regions” — there is no mainland-China region, and Bitwarden stores vault data in Microsoft Azure “in the US or EU.” So the passwords, passkeys, secrets and account PII you hold for your China users rest offshore, which makes their collection a cross-border transfer of personal information under PIPL: the handler (you, not Bitwarden) owes notice, a separate consent, and one transfer mechanism. Confirm your exact obligations with counsel.
Doesn't end-to-end encryption mean China's data rules don't apply?
No. Bitwarden's zero-knowledge encryption genuinely lowers the exposure — vault contents are encrypted on your device before they reach the server, so Bitwarden stores ciphertext it cannot read — but it does not discharge the duty. PIPL is triggered by the cross-border movement of personal information, encrypted or not; account-level data such as email, billing and login metadata still sits offshore; and the residency duty turns on where the data sits, not on whether it is readable. Encryption is a safeguard the law credits, not an exemption from notice, consent, a transfer mechanism, or — for a CIIO or large-volume handler — the in-country storage duty under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37). Treat it as a risk to work through with counsel.
Can 21YunBox make our Bitwarden setup work in China?
Yes. Because Bitwarden supports self-hosting, there is an unusually clean in-country path: our China team maps your PIPL cross-border and residency exposure for your entity and data volumes, stands up Bitwarden's own self-hosted deployment on China-resident, ICP-filed infrastructure so the vault stays in the country, and delivers it in-country in front of what you already run — while you keep Bitwarden's cloud for your other markets. Get in touch to work through your specific case. It is never a route around China's data-export rules.

ARTICLES RELATED TO BITWARDEN

CATEGORIES

Security

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.