Does Daily Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
Daily is a foreign WebRTC video and audio API whose media runs on AWS worldwide — its own security page says it never routes data through servers in China. Carrying your China users' live streams, recordings (voiceprint and faces) and identifiers offshore is a PIPL cross-border transfer, providing real-time comms in the mainland needs a value-added telecom license a foreign API can't hold, and the app needs an ICP filing. A compliance-first look at the telecom-licensing, residency and cross-border exposure.
Does Daily work in China?
Your China users' live video, audio and any recordings ride Daily's offshore AWS infrastructure — which, in Daily's own words, never routes data through servers in China — so providing real-time communication in the mainland needs a value-added telecom license a foreign API can't hold, and the app that embeds the SDK needs an ICP filing.
Daily (daily.co) is a foreign WebRTC video and audio API: the media runs on its globally distributed servers on AWS with no mainland-China region, and recordings and transcripts are stored in Daily's cloud by default. A call recording captures the speaker's voiceprint and the participants' faces — sensitive biometric personal information under PIPL Article 28 (separate consent under Article 29) — and carrying that media, those recordings and participant identifiers offshore is a PIPL cross-border transfer (Articles 38–40). The lawful lever is to route the real-time service through a licensed in-country operator, keep China-participant media and recordings on an in-country path, obtain the Article 28/29 consent, and ICP-file the app — not to make an offshore endpoint reachable. On telecom licensing 21YunBox is advisory; it holds no China telecom license.
This is a risk map, not a ruling — settle the specifics with counsel. Our China team can map your exposure →
What Daily's own documentation says about China
| Fact | Primary source |
|---|---|
| Daily runs on AWS infrastructure worldwide and states it never routes data through servers in China. Daily's security page says "AWS infrastructure located around the world hosts Daily's services" and, under Data protection, "We never route data through servers in China." Its Global Mesh Network is a globally distributed WebRTC SFU built on AWS, with regions named across the EU and United States and none in the mainland — so your China users' live streams are carried offshore. | Daily, Security (daily.co/security) and Global Mesh Network (docs.daily.co), retrieved 2026-10-10 |
| Recordings are stored in Daily's cloud by default, and transcription runs on a third-party engine. Daily's recording guide describes "server-side video recording stored in Daily's cloud" (MP4), with only HIPAA or custom setups redirecting captures to a customer-managed Amazon S3 or OCI bucket; real-time and post-call transcription are "both powered by Deepgram," and "Transcripts are stored in Daily's cloud by default." A recording of a call is the speaker's voiceprint and the participants' faces — biometric personal information. | Daily, Recording and Transcription guides (docs.daily.co), retrieved 2026-10-10 |
| Carrying call media, recordings and identifiers offshore is a PIPL cross-border transfer, and recordings are sensitive biometric data. Routing participant streams, chat, identifiers and call metadata to servers outside the mainland triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism. A recording captures a voiceprint and faces: sensitive personal information under PIPL Article 28, needing the specific, separate consent of Article 29 and a prior impact assessment, and it cannot be anonymized away. | Personal Information Protection Law of the PRC, Articles 28–29 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| Providing real-time communication to China users is a licensed value-added telecom business, with in-country storage duties for critical or high-volume handlers. Under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42), providing voice and video communication capability is a value-added telecom business requiring the 增值电信业务经营许可证, which a foreign API cannot hold directly — so the service must ride a licensed in-country operator. For a critical-information-infrastructure operator or high-volume handler, data must stay in-country under Cybersecurity Law Article 39 (formerly Article 37). | Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42, gov.cn); Cybersecurity Law of the PRC, Article 39 (formerly 37) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a China-facing product, the question to settle about Daily is not whether the SDK loads or whether a video call connects — it is where your users’ live media and recordings are allowed to live, who may lawfully provide real-time communication to people in the mainland, and whether the app that embeds the call is on file with the authorities. Daily (daily.co) is a foreign WebRTC video and audio API: you embed its SDK, and the media runs on Daily’s own globally distributed servers on AWS, which — in Daily’s own words — never route data through servers in China. There is no mainland-China media region to select and no Daily China telecom entity to run it from. That raises four prongs at once: a value-added telecom license a foreign API cannot hold, live media and recordings that leave the country, a recording that captures a voiceprint and a face (sensitive biometric personal information), and in-country storage duties for a CIIO or high-volume handler. None of them turn on milliseconds.
Daily in China at a glance
| What decides it | In Daily's own terms — and China's law |
|---|---|
| What it is and carries | Daily (daily.co) is a foreign WebRTC video and audio API you embed in your own app: live audio and video, chat and app messages, screen sharing, recording, and real-time or post-call transcription (powered by Deepgram). The media runs on Daily's globally distributed servers on AWS — there is no Daily mainland-China media region, no Daily China telecom entity to run it from, and no self-hosted build, because it is a managed service. |
| Where the media and records live | Daily's security page states that AWS infrastructure located around the world hosts its services and that it never routes data through servers in China; recordings are stored in Daily's cloud by default, and transcripts likewise. With no mainland-China region, the streams, recordings and records tied to your China participants come to rest offshore — a PIPL cross-border transfer (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism. |
| The telecom-licensing door | Providing real-time voice and video communication capability to users in the mainland is a value-added telecom business. Under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) a foreign API cannot hold directly — so the lawful route carries the China real-time leg through a licensed in-country operator, not Daily alone. |
| Biometric recordings = sensitive PI, plus residency | A recording is the speaker's voiceprint and the participants' faces — sensitive personal information under PIPL Article 28, requiring a specific purpose and the separate consent of Article 29, and it cannot be anonymized away. For a critical-information-infrastructure operator or high-volume handler, in-country storage can also bite: Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. |
| Reachability is not the axis — the lawful path | Daily is not "blocked," but reachability was never the question. Because the media runs offshore and recordings capture biometric data, the real decision is licensing and residency — and where live transcription or AI summaries score or route a participant, the PIPL Article 24 automated-decision duty applies. The lawful path routes the China real-time leg through a licensed in-country operator, keeps media and recordings in-country with the Article 29 consent, and delivers China-facing surfaces on ICP-filed infrastructure. On telecom 21YunBox is advisory — it holds no China telecom license. |
What you actually carry — live media, recordings and identifiers
A Daily deployment carries more personal information than a video window suggests. Every call moves each participant’s live audio and video, their display name and any user or session identifier you pass, the chat and app messages exchanged, and the session metadata around it — who joined, when, from where, and for how long. Turn on recording and the call also produces a durable artifact: Daily’s recording guide describes server-side video recording stored in Daily’s cloud, encoded as MP4, with audio-only and raw-track variants, and only a HIPAA or custom setup redirects the capture to a customer-managed Amazon S3 or OCI bucket. That recording is the most sensitive thing in the stack — it is the speaker’s voiceprint and the participants’ faces, a biometric identifier, not merely their words. On top of the media, Daily offers transcription: real-time during the call and post-call through its Batch Processor, both powered by Deepgram, with transcripts stored in Daily’s cloud by default. Where you enable those AI features to summarize, score, or route by participant, an automated-decision question arises as well. And all of it runs on Daily’s globally distributed servers on AWS: Daily’s own security page states that AWS infrastructure located around the world hosts its services and that it never routes data through servers in China, so for your mainland users the media and its records are created and held offshore.
Three doors: a telecom license, cross-border media, and recording consent
The first door is licensing, and it is the one a foreign API cannot open for you. Providing real-time voice and video communication capability to users in the mainland is a value-added telecommunications business: under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it requires a Value-Added Telecommunications Business License (增值电信业务经营许可证), and China’s foreign-investment rules mean a foreign provider cannot hold that license directly. So Daily cannot, on its own, lawfully provide the real-time communication service to mainland users — the lawful route runs the real-time leg through a licensed in-country operator, exactly as it does for in-country messaging and voice.
The second door is the cross-border transfer. The live streams, recordings, transcripts, chat content, participant identifiers and session metadata you carry are personal information, and sending them to Daily’s offshore AWS region is a transfer out of China performed by you, the handler — PIPL Articles 38–40 (数据出境): notice, a separate consent distinct from the service agreement, and one approved transfer mechanism (a CAC security assessment, the CAC standard contract, or certification).
The third door is the recording itself. A call recording captures a voiceprint and faces, which are sensitive personal information under PIPL Article 28 — it requires a specific purpose and the separate, explicit consent of Article 29, plus a prior impact assessment, and because it is biometric it cannot be anonymized away. And where you are a critical-information-infrastructure operator or a high-volume handler, in-country storage is a duty in its own right under Cybersecurity Law Article 39 (formerly Article 37).
Reaching the endpoint isn’t the question — a compliant in-country real-time path is
Daily’s SDK loads and its calls connect; neither fact decides whether you may run it for China. The deciding questions are whether the real-time service is provided by a party licensed to provide it in the mainland, and whether the media and recordings it generates had a lawful basis to leave the country — or whether they should have stayed in the first place. The lawful answer is not to make an offshore service reachable, and it is never a concealed route that ships the media offshore anyway; it is to carry the China real-time leg through a licensed in-country operator, keep China-participant media and recordings on an in-country path — including directing any recordings to an in-country, customer-controlled store and obtaining the Article 28/29 consent before they are made — and to deliver the app that embeds the SDK on ICP-filed, in-country infrastructure. You can narrow what crosses — minimize, pseudonymize, keep certain recordings or transcripts out of certain flows — but as long as the media region is offshore, those choices decide how much crosses and to which offshore region, not whether it crosses. On the telecom leg our role is advisory and lighter: 21YunBox holds no China telecom license and is not a carrier. Because whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, and how any automated-decision duty applies all turn on facts only your team and counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.
The lawful path — map, localize, deliver
Reaching your China users with Daily the lawful way has a shape, and it keeps Daily where it already runs for the rest of your markets. 21YunBox is a compliant overlay, not a migration, and for a real-time platform like Daily we are a partner to it, not a competitor. We map your exposure first — reading the PIPL cross-border, sensitive-biometric, data-residency, value-added-telecom-licensing, and automated-decision obligations against your entity, your call and recording volumes, the AI features you enable, and who your participants actually are — so you know exactly what counsel and a licensed in-country operator need to confirm. We localize what must stay on mainland soil — standing up consented, in-country processing and storage for the media, recordings, and transcripts that cannot lawfully sit offshore, and routing the China real-time leg through a licensed in-country operator — a lawful, in-country, licensed path, never a concealed route that ships the media offshore. And we deliver every China-facing surface — the app that embeds the SDK, the join page, the intake or scheduling form — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the stack you already run, with no rebuild and no second codebase. On telecom licensing our role is advisory and lighter: 21YunBox holds no China telecom license and is not a carrier; that license and the operator relationship sit with a licensed local provider and your counsel. The result is a real-time communications stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
