Does Bitwarden Work in China? Vault Data Residency, PIPL & Self-Hosting
Bitwarden's cloud stores vault and account data only in its US or EU regions — it runs no mainland-China data center — so holding your China users' passwords, passkeys and secrets in that cloud is a cross-border transfer of personal information under PIPL, with an in-country storage duty for a CIIO or large-volume handler that an offshore region cannot meet. End-to-end encryption lowers the exposure but does not discharge the notice, consent, transfer-mechanism and residency duties. The lawful path runs through Bitwarden's own self-hosted deployment on China-resident, ICP-filed infrastructure.
Does Bitwarden work in China?
For a password manager the China question is not whether the app opens — it is where the vault comes to rest. Bitwarden's cloud stores vault and account data only in its US or EU regions, with no mainland-China data center. So reaching it is a delivery detail; residency and lawful basis are what decide whether you may use it for your China users.
Holding your China users' passwords, passkeys, secrets and account PII in an offshore Bitwarden cloud is a cross-border transfer (数据出境) of personal information under PIPL (Articles 38–40: notice, a separate consent, and one transfer mechanism), and it may trigger China's data-export security assessment. Bitwarden's end-to-end encryption lowers the exposure but does not discharge those duties — encryption is a safeguard, not an exemption. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) and PIPL Article 40 add an in-country storage duty an offshore region cannot meet.
The strong move is Bitwarden's own self-hosted deployment: 21YunBox stands it up on China-resident, ICP-filed infrastructure for your China entity, keeps Bitwarden's cloud for your other markets, and delivers it in-country — with no move off Bitwarden, and never any form of circumvention. Treat the specifics as a risk to confirm with counsel.
What Bitwarden's own documentation says about China
| Fact | Primary source |
|---|---|
| Bitwarden's cloud stores data only in the US and EU — with no mainland-China region. Bitwarden's Server Regions help article states: “The Bitwarden cloud is available globally with data storage in both United States and European Union regions,” and that “Bitwarden server regions are separate, and your account or organization only exists in the region where it was first created.” The page names no mainland-China region, so the vault and account data of your China users rests offshore. | Bitwarden Help Center — Server Regions (bitwarden.com), retrieved 2026-10-09 |
| Vault data is stored in Microsoft Azure in the US or EU. Bitwarden's Data Storage help article states: “Bitwarden processes and stores all vault data securely in the Microsoft Azure Cloud in the US or EU using services that are managed by the team at Microsoft.” Neither location is in mainland China, so collecting your China users' credentials into it is a cross-border transfer of personal information under PIPL. | Bitwarden Help Center — Data Storage (bitwarden.com), retrieved 2026-10-09 |
| Bitwarden can be self-hosted on your own infrastructure — the basis of the lawful in-country route. Bitwarden's documentation states: “Before you can self-host an organization, you'll need to install and deploy Bitwarden to your server,” and “Bitwarden can be run, using Docker, on Linux and Windows machines,” including “methods for offline or air-gapped environments.” Run on China-resident infrastructure for your China entity, this keeps the vault in the country by design. | Bitwarden Help Center — Self-host an Organization (bitwarden.com), retrieved 2026-10-09 |
| China-collected vault and account data sent to an offshore cloud is a PIPL cross-border transfer, with an in-country storage duty for some handlers. Moving personal information collected from users in mainland China to a Bitwarden cloud in the US or EU triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) — with an in-country storage duty under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37) for a critical information infrastructure operator or large-volume handler. | Personal Information Protection Law of the PRC, Articles 38–40; Cybersecurity Law Article 39 (formerly Article 37) (cac.gov.cn), retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a password manager, the China question is not whether the app opens — it is where the vault comes to rest. Bitwarden holds the most concentrated personal data a company keeps: the passwords, passkeys, secrets and vault items of its people, plus the account identifiers behind them. Reaching the service from the mainland is a delivery detail; what decides whether you may use it for your China users is where that vault is stored and on what lawful basis it left the country. Bitwarden answers the storage half plainly in its own documentation — and it offers a second deployment model that changes the whole picture.
Bitwarden in China at a glance
| What decides it | In Bitwarden's own terms — and China's law |
|---|---|
| What it is | An open-source password, passkey and secrets manager, offered two ways: Bitwarden's cloud (Bitwarden hosts) and a self-hosted/self-managed deployment you run yourself. Either way it holds a concentrated store of credentials plus account personal information — the most sensitive data category, in one place. |
| Is it reachable from the mainland? | Bitwarden's apps and browser extensions sync to its cloud servers, so this is a delivery question, and cross-border connections to an offshore vault can be inconsistent — an operational matter, not the decision. Reachability is not the China question; where the vault and account data live, and under what lawful basis, is. |
| Where the cloud data lives | Offshore. Bitwarden says its cloud offers “data storage in both United States and European Union regions,” and stores vault data “in the Microsoft Azure Cloud in the US or EU.” There is no mainland-China region, so your China users' vault and account data rests outside the country. |
| Collecting China vault & account data into the cloud | The passwords, passkeys, secrets and account identifiers are personal information. Holding them in a US or EU Bitwarden is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. End-to-end encryption is a safeguard, not an exemption. For a CIIO or large-volume handler, PIPL Article 40 and the Cybersecurity Law's Article 39 (formerly Article 37) add an in-country storage duty an offshore region cannot meet. |
| Serving the public / ICP | An offshore vault cannot hold an ICP filing. A self-hosted Bitwarden that serves your China users from inside the mainland is a public internet service — it needs an ICP filing bound to a mainland hosting resource, plus compliant in-country delivery. |
| The lawful path | Self-host Bitwarden on China-resident infrastructure for your China entity (consented, in-country storage), keep Bitwarden's cloud for your other markets, and deliver it in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention. |
Availability isn’t the question — the vault’s location is
The first instinct is to check whether Bitwarden’s apps and browser extensions can reach the service from the mainland. They sync to Bitwarden’s cloud servers, so that is a delivery question, and cross-border connections to an offshore vault can be inconsistent — an operational matter, not the decision. For that reason this page publishes no China latency or reachability figure for Bitwarden: speed is not the axis for a decision that turns on residency and lawful basis. And the temptation, when a cross-border sync is flaky, is to force it through a network workaround — 21YunBox neither uses nor suggests any form of circumvention, because it is both a compliance risk and beside the point. The productive question is where the vault may lawfully live.
The vault is the most sensitive data you hold — and offshore by default
Bitwarden’s storage posture is stated plainly, not inferred from a load test. Its Data Storage article says Bitwarden “processes and stores all vault data securely in the Microsoft Azure Cloud in the US or EU,” and its Server Regions article says the cloud offers “data storage in both United States and European Union regions,” with each account living “only… in the region where it was first created.” There is no mainland-China region to choose.
So the moment the passwords, passkeys, secrets and account identifiers you hold for people in China land in a US or EU Bitwarden, you have made a cross-border transfer (数据出境) of personal information, and China’s Personal Information Protection Law decides whether that was allowed. PIPL puts the duty on the handler — you, not Bitwarden the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your product, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the data is “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And for a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — an in-country storage duty a US or EU vault cannot meet.
It is fair to ask whether Bitwarden’s end-to-end encryption settles this. It helps, and honestly so: vault contents are encrypted on the device before they reach the server, so Bitwarden stores ciphertext it cannot read. But encryption is a safeguard the law credits, not an exemption from it. PIPL is triggered by the cross-border movement of personal information, encrypted or not; the account-level data around the vault — email, billing, IP and login metadata, organization membership — is still held offshore; and the residency duty above turns on where the data sits, not on whether it is readable. Which of these bite your specific case is a risk to confirm with counsel against what you actually collect and store.
No mainland region on the cloud — and why self-hosting changes that
Two duties settle before performance ever enters. Residency: for a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland — a duty a US or EU vault cannot satisfy however it is tuned. Licensing: a public-facing service actually served to mainland users from inside China turns on an ICP filing (备案) bound to a mainland hosting resource, and an offshore vault has nothing to file against. On Bitwarden’s cloud, both are structurally out of reach.
This is where Bitwarden differs from a cloud-only platform. Bitwarden is built to be self-hosted — in its own words, you “install and deploy Bitwarden to your server,” and it “can be run, using Docker, on Linux and Windows machines,” with methods even for air-gapped environments. Stood up on China-resident infrastructure for your China entity, that same product keeps the vault in the country by design. A light license-and-billing tie to Bitwarden’s cloud remains — metadata, not the vault — and what must stay versus what may leave is exactly the line to draw with counsel. A self-hosted server that then serves your China users is itself a public internet service, so it carries the ICP filing and in-country delivery duties in turn.
The lawful path — map, localize, deliver
There is a compliant way to run Bitwarden for China, and self-hosting gives it an unusually clean shape.
First, map: our China team works through your PIPL exposure — which credentials, secrets and account data collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your notice and consent flow has to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: rather than send the most sensitive data you hold across the border, we stand up Bitwarden’s own self-hosted deployment on China-resident infrastructure for your China entity, so the vault stays in-country by design — and you keep Bitwarden’s cloud for the markets where it already serves you.
Then deliver: a self-hosted vault that serves your China users is a public service in the mainland, so it carries an ICP filing duty and needs compliant in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — in front of what you run, with no rebuild and no re-platform. The result is a password manager that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a way around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
