Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Daily Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency

Daily is a foreign WebRTC video and audio API whose media runs on AWS worldwide — its own security page says it never routes data through servers in China. Carrying your China users' live streams, recordings (voiceprint and faces) and identifiers offshore is a PIPL cross-border transfer, providing real-time comms in the mainland needs a value-added telecom license a foreign API can't hold, and the app needs an ICP filing. A compliance-first look at the telecom-licensing, residency and cross-border exposure.

Does Daily work in China?

Your China users' live video, audio and any recordings ride Daily's offshore AWS infrastructure — which, in Daily's own words, never routes data through servers in China — so providing real-time communication in the mainland needs a value-added telecom license a foreign API can't hold, and the app that embeds the SDK needs an ICP filing.

Daily (daily.co) is a foreign WebRTC video and audio API: the media runs on its globally distributed servers on AWS with no mainland-China region, and recordings and transcripts are stored in Daily's cloud by default. A call recording captures the speaker's voiceprint and the participants' faces — sensitive biometric personal information under PIPL Article 28 (separate consent under Article 29) — and carrying that media, those recordings and participant identifiers offshore is a PIPL cross-border transfer (Articles 38–40). The lawful lever is to route the real-time service through a licensed in-country operator, keep China-participant media and recordings on an in-country path, obtain the Article 28/29 consent, and ICP-file the app — not to make an offshore endpoint reachable. On telecom licensing 21YunBox is advisory; it holds no China telecom license.

This is a risk map, not a ruling — settle the specifics with counsel. Our China team can map your exposure →

What Daily's own documentation says about China

FactPrimary source
Daily runs on AWS infrastructure worldwide and states it never routes data through servers in China. Daily's security page says "AWS infrastructure located around the world hosts Daily's services" and, under Data protection, "We never route data through servers in China." Its Global Mesh Network is a globally distributed WebRTC SFU built on AWS, with regions named across the EU and United States and none in the mainland — so your China users' live streams are carried offshore. Daily, Security (daily.co/security) and Global Mesh Network (docs.daily.co), retrieved 2026-10-10
Recordings are stored in Daily's cloud by default, and transcription runs on a third-party engine. Daily's recording guide describes "server-side video recording stored in Daily's cloud" (MP4), with only HIPAA or custom setups redirecting captures to a customer-managed Amazon S3 or OCI bucket; real-time and post-call transcription are "both powered by Deepgram," and "Transcripts are stored in Daily's cloud by default." A recording of a call is the speaker's voiceprint and the participants' faces — biometric personal information. Daily, Recording and Transcription guides (docs.daily.co), retrieved 2026-10-10
Carrying call media, recordings and identifiers offshore is a PIPL cross-border transfer, and recordings are sensitive biometric data. Routing participant streams, chat, identifiers and call metadata to servers outside the mainland triggers PIPL Articles 38–40 — notice, a separate consent, and one transfer mechanism. A recording captures a voiceprint and faces: sensitive personal information under PIPL Article 28, needing the specific, separate consent of Article 29 and a prior impact assessment, and it cannot be anonymized away. Personal Information Protection Law of the PRC, Articles 28–29 and 38–40 (cac.gov.cn), retrieved 2026-10-10
Providing real-time communication to China users is a licensed value-added telecom business, with in-country storage duties for critical or high-volume handlers. Under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42), providing voice and video communication capability is a value-added telecom business requiring the 增值电信业务经营许可证, which a foreign API cannot hold directly — so the service must ride a licensed in-country operator. For a critical-information-infrastructure operator or high-volume handler, data must stay in-country under Cybersecurity Law Article 39 (formerly Article 37). Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42, gov.cn); Cybersecurity Law of the PRC, Article 39 (formerly 37)

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a China-facing product, the question to settle about Daily is not whether the SDK loads or whether a video call connects — it is where your users’ live media and recordings are allowed to live, who may lawfully provide real-time communication to people in the mainland, and whether the app that embeds the call is on file with the authorities. Daily (daily.co) is a foreign WebRTC video and audio API: you embed its SDK, and the media runs on Daily’s own globally distributed servers on AWS, which — in Daily’s own words — never route data through servers in China. There is no mainland-China media region to select and no Daily China telecom entity to run it from. That raises four prongs at once: a value-added telecom license a foreign API cannot hold, live media and recordings that leave the country, a recording that captures a voiceprint and a face (sensitive biometric personal information), and in-country storage duties for a CIIO or high-volume handler. None of them turn on milliseconds.

Daily's own security page, under the 'Data protection' heading, stating it never stores audio, video, or screen-sharing data other than through its documented recording APIs and that it never routes data through servers in China, with services hosted on AWS infrastructure located around the world
"We never route data through servers in China." Daily's own security page confirms there is no mainland-China media region: its services are hosted on AWS infrastructure located around the world, so your China users' streams and recordings are carried offshore. Source: Daily security page

Daily in China at a glance

What decides it In Daily's own terms — and China's law
What it is and carries Daily (daily.co) is a foreign WebRTC video and audio API you embed in your own app: live audio and video, chat and app messages, screen sharing, recording, and real-time or post-call transcription (powered by Deepgram). The media runs on Daily's globally distributed servers on AWS — there is no Daily mainland-China media region, no Daily China telecom entity to run it from, and no self-hosted build, because it is a managed service.
Where the media and records live Daily's security page states that AWS infrastructure located around the world hosts its services and that it never routes data through servers in China; recordings are stored in Daily's cloud by default, and transcripts likewise. With no mainland-China region, the streams, recordings and records tied to your China participants come to rest offshore — a PIPL cross-border transfer (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism.
The telecom-licensing door Providing real-time voice and video communication capability to users in the mainland is a value-added telecom business. Under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) a foreign API cannot hold directly — so the lawful route carries the China real-time leg through a licensed in-country operator, not Daily alone.
Biometric recordings = sensitive PI, plus residency A recording is the speaker's voiceprint and the participants' faces — sensitive personal information under PIPL Article 28, requiring a specific purpose and the separate consent of Article 29, and it cannot be anonymized away. For a critical-information-infrastructure operator or high-volume handler, in-country storage can also bite: Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Reachability is not the axis — the lawful path Daily is not "blocked," but reachability was never the question. Because the media runs offshore and recordings capture biometric data, the real decision is licensing and residency — and where live transcription or AI summaries score or route a participant, the PIPL Article 24 automated-decision duty applies. The lawful path routes the China real-time leg through a licensed in-country operator, keeps media and recordings in-country with the Article 29 consent, and delivers China-facing surfaces on ICP-filed infrastructure. On telecom 21YunBox is advisory — it holds no China telecom license.

What you actually carry — live media, recordings and identifiers

A Daily deployment carries more personal information than a video window suggests. Every call moves each participant’s live audio and video, their display name and any user or session identifier you pass, the chat and app messages exchanged, and the session metadata around it — who joined, when, from where, and for how long. Turn on recording and the call also produces a durable artifact: Daily’s recording guide describes server-side video recording stored in Daily’s cloud, encoded as MP4, with audio-only and raw-track variants, and only a HIPAA or custom setup redirects the capture to a customer-managed Amazon S3 or OCI bucket. That recording is the most sensitive thing in the stack — it is the speaker’s voiceprint and the participants’ faces, a biometric identifier, not merely their words. On top of the media, Daily offers transcription: real-time during the call and post-call through its Batch Processor, both powered by Deepgram, with transcripts stored in Daily’s cloud by default. Where you enable those AI features to summarize, score, or route by participant, an automated-decision question arises as well. And all of it runs on Daily’s globally distributed servers on AWS: Daily’s own security page states that AWS infrastructure located around the world hosts its services and that it never routes data through servers in China, so for your mainland users the media and its records are created and held offshore.

The first door is licensing, and it is the one a foreign API cannot open for you. Providing real-time voice and video communication capability to users in the mainland is a value-added telecommunications business: under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it requires a Value-Added Telecommunications Business License (增值电信业务经营许可证), and China’s foreign-investment rules mean a foreign provider cannot hold that license directly. So Daily cannot, on its own, lawfully provide the real-time communication service to mainland users — the lawful route runs the real-time leg through a licensed in-country operator, exactly as it does for in-country messaging and voice.

The second door is the cross-border transfer. The live streams, recordings, transcripts, chat content, participant identifiers and session metadata you carry are personal information, and sending them to Daily’s offshore AWS region is a transfer out of China performed by you, the handler — PIPL Articles 38–40 (数据出境): notice, a separate consent distinct from the service agreement, and one approved transfer mechanism (a CAC security assessment, the CAC standard contract, or certification).

The third door is the recording itself. A call recording captures a voiceprint and faces, which are sensitive personal information under PIPL Article 28 — it requires a specific purpose and the separate, explicit consent of Article 29, plus a prior impact assessment, and because it is biometric it cannot be anonymized away. And where you are a critical-information-infrastructure operator or a high-volume handler, in-country storage is a duty in its own right under Cybersecurity Law Article 39 (formerly Article 37).

Reaching the endpoint isn’t the question — a compliant in-country real-time path is

Daily’s SDK loads and its calls connect; neither fact decides whether you may run it for China. The deciding questions are whether the real-time service is provided by a party licensed to provide it in the mainland, and whether the media and recordings it generates had a lawful basis to leave the country — or whether they should have stayed in the first place. The lawful answer is not to make an offshore service reachable, and it is never a concealed route that ships the media offshore anyway; it is to carry the China real-time leg through a licensed in-country operator, keep China-participant media and recordings on an in-country path — including directing any recordings to an in-country, customer-controlled store and obtaining the Article 28/29 consent before they are made — and to deliver the app that embeds the SDK on ICP-filed, in-country infrastructure. You can narrow what crosses — minimize, pseudonymize, keep certain recordings or transcripts out of certain flows — but as long as the media region is offshore, those choices decide how much crosses and to which offshore region, not whether it crosses. On the telecom leg our role is advisory and lighter: 21YunBox holds no China telecom license and is not a carrier. Because whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, and how any automated-decision duty applies all turn on facts only your team and counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.

The lawful path — map, localize, deliver

Reaching your China users with Daily the lawful way has a shape, and it keeps Daily where it already runs for the rest of your markets. 21YunBox is a compliant overlay, not a migration, and for a real-time platform like Daily we are a partner to it, not a competitor. We map your exposure first — reading the PIPL cross-border, sensitive-biometric, data-residency, value-added-telecom-licensing, and automated-decision obligations against your entity, your call and recording volumes, the AI features you enable, and who your participants actually are — so you know exactly what counsel and a licensed in-country operator need to confirm. We localize what must stay on mainland soil — standing up consented, in-country processing and storage for the media, recordings, and transcripts that cannot lawfully sit offshore, and routing the China real-time leg through a licensed in-country operator — a lawful, in-country, licensed path, never a concealed route that ships the media offshore. And we deliver every China-facing surface — the app that embeds the SDK, the join page, the intake or scheduling form — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the stack you already run, with no rebuild and no second codebase. On telecom licensing our role is advisory and lighter: 21YunBox holds no China telecom license and is not a carrier; that license and the operator relationship sit with a licensed local provider and your counsel. The result is a real-time communications stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Can I use Daily for video or audio calls with users in mainland China?
The SDK generally loads and calls generally connect, but reachability was never the deciding question. Daily is a foreign WebRTC API whose media runs on AWS infrastructure worldwide with no mainland-China region — its own security page says it never routes data through servers in China — so your users' live streams, recordings and identifiers are carried offshore. Providing real-time communication in the mainland is a value-added telecom business a foreign API cannot license, and a recording is a voiceprint and faces, sensitive biometric data under PIPL Article 28. There is no lawful shortcut, and we never use or suggest circumvention — treat the specifics as a risk to confirm with counsel.
Where does Daily store recordings and transcripts, and why does that matter for China?
By default Daily stores server-side recordings in Daily's cloud, and transcripts in Daily's cloud as well; only HIPAA or custom setups redirect them to a customer-managed Amazon S3 or OCI bucket. For your China participants that storage sits outside the mainland, so it is a PIPL cross-border transfer (Articles 38–40), and because a recording captures a voiceprint and faces it is Article 28 sensitive biometric personal information requiring the separate consent of Article 29. The lawful pattern keeps China-participant media and recordings on an in-country path with that consent, rather than letting them come to rest offshore.
What is the lawful way to run real-time communication for China users, and what does 21YunBox do?
Route the real-time service through a licensed in-country operator, keep China-participant media and recordings in-country, obtain the Article 28/29 consent for recordings, and deliver the app that embeds the SDK on ICP-filed, in-country infrastructure — in front of the stack you already run, with no rebuild. On telecom licensing 21YunBox is advisory and holds no China telecom license; that license and the operator relationship sit with a licensed local provider and your counsel. We map the exposure, localize the China leg, and deliver in-country. We never use or suggest circumvention. Get in touch to map your case.

ARTICLES RELATED TO DAILY

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.