Does Deepgram Work in China? PIPL Cross-Border, Voiceprint Biometrics & Data Residency
Audio you send Deepgram to transcribe or synthesize carries the speaker's voiceprint — Article 28 sensitive biometric personal information you cannot anonymize — and is processed on Deepgram's offshore servers (US, with EU, Australia and India endpoints but no mainland-China region): a PIPL cross-border transfer. A compliance-first look at Deepgram speech in China and the in-country self-hosting lever.
Does Deepgram work in China?
Deepgram can be reached from the mainland, but that is not the question: the audio you send it carries the speaker's voiceprint — Article 28 sensitive biometric personal information you cannot anonymize — and Deepgram's hosted API processes it on offshore servers, with no mainland-China region.
Every recording you transcribe, and every voice you synthesize, ships a biometric identifier plus whatever the words reveal to Deepgram's servers (Global, EU, Australia or India endpoints — none in the mainland). That is a PIPL cross-border transfer of sensitive biometric data (Articles 38–40; Article 28 adds a separate consent and a prior impact assessment), and for a critical information infrastructure operator a residency problem under Cybersecurity Law Article 39 (formerly Article 37); a China-facing synthesized voice adds a deep-synthesis and generative-AI filing door. The lawful lever is to keep China audio's processing in-country — self-host Deepgram's models inside China, or a licensed domestic speech service, with Article 28 consent — not to make the offshore API more reachable.
This is a risk map, not a verdict — settle the specifics with counsel. 21YunBox never uses or suggests circumvention of any kind. Our China team can map your exposure →
What Deepgram's own documentation says about China
| Fact | Primary source |
|---|---|
| Deepgram offers a self-hosted deployment you run in your own environment. Its Self-Hosted Voice AI page states the speech models are "available to self-host on your own infrastructure, both in the cloud or on-premises," delivered as containers with "the same API and feature set as our hosted API," and that "Your audio never leaves your environment." Run on in-country infrastructure, this keeps the audio and the voiceprint in the mainland — the honest lever a pure cloud service lacks. | Deepgram — Self-Hosted Voice AI (deepgram.com), retrieved 2026-10-10 |
| Deepgram's hosted API has no mainland-China region. Its regional-endpoints documentation lists a default Global endpoint plus EU (api.eu.deepgram.com), Australia (api.au.deepgram.com) and India (api.in.deepgram.com) — each keeping requests from being routed outside that region — with no China endpoint. A China-origin recording sent to the hosted API is therefore processed offshore. | Deepgram Docs — Regional Endpoints (developers.deepgram.com), retrieved 2026-10-10 |
| A voiceprint sent offshore is a PIPL cross-border transfer of sensitive biometric data. Shipping a China user's audio to Deepgram's servers triggers PIPL Articles 38–40 — notice, a separate consent, and a transfer mechanism — and, because a recording is a biometric identifier, Article 28 adds a separate specific consent and a prior impact assessment (PIPIA). For a critical information infrastructure operator, mainland personal information must also be stored in the mainland (Article 40; Cybersecurity Law Article 39 (formerly Article 37)). | Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| A synthesized voice offered in China opens a second door. Deepgram's Aura text-to-speech and Voice Agent API generate speech; a China-facing feature that synthesizes a voice falls under China's deep-synthesis rules and the generative-AI measures (a CAC service filing and AI-content labeling) — a duty on the feature you build, on top of the cross-border transfer of the underlying audio. | Interim Measures for Generative AI Services (生成式人工智能服务管理暂行办法), CAC Order No. 15 (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a team building voice features for mainland China with Deepgram, the question was never whether its API resolves from the mainland — it generally does. What decides it is what happens to the audio you send it. Deepgram is a speech-AI platform: its Nova speech-to-text models turn recorded audio into text, while its Aura text-to-speech models and Voice Agent API generate synthesized speech. Either way, a recording of a person speaking is that person’s voiceprint — a biometric identifier PIPL Article 28 treats as sensitive, and one you cannot anonymize — plus whatever the spoken words reveal. Deepgram’s hosted API processes that audio on its own offshore servers, with Global, EU, Australia and India endpoints but no mainland-China region. So each call is a cross-border transfer of sensitive biometric personal information (PIPL Articles 38–40, 数据出境; Article 28 adds a separate consent and a prior impact assessment), with a residency duty for a CIIO or high-volume handler and — for a China-facing synthesized-voice feature — a deep-synthesis and generative-AI filing door on top. The honest exception: Deepgram can be self-hosted in your own environment.
Deepgram in China at a glance
| What decides it | In Deepgram's own terms — and China's law |
|---|---|
| What you send, and that it carries a voiceprint | On the speech-to-text side you send a recording — a call, a support conversation, a voice message, a dictated clinical or legal note — and get back a transcript, often with diarization that separates and labels each speaker. On the text-to-speech and Voice Agent side you send text and a chosen voice and get synthesized audio. A recording of a person speaking is that person's voiceprint, a biometric identifier you cannot anonymize (stripping it defeats the purpose), and the spoken content — health, financial, ID — is frequently sensitive in its own right. |
| It is sent offshore — a cross-border transfer | Deepgram's hosted API processes the audio on its own servers. Its regional endpoints are a default Global endpoint plus EU (api.eu.deepgram.com), Australia (api.au.deepgram.com) and India (api.in.deepgram.com), each of which Deepgram says keeps requests "never routed outside" that region — and none of them is in mainland China. Shipping a China-origin recording there is a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (Articles 38–40, 数据出境). |
| Sensitive biometric — Article 28 | A voiceprint is biometric data, a sensitive category under PIPL Article 28: processing or exporting it requires a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment (PIPIA) before the audio moves. Because the audio is the identifier, you cannot redact it the way you can a transcript — the voiceprint travels whenever the recording does. |
| Kept or used to train — and must it stay in China? | Deepgram runs a Model Improvement Partnership Program; you can keep any request out of it with mip_opt_out=true, and Deepgram states "Data from opted-out requests is retained only for the duration necessary to process the request," with a single-tenant Dedicated tier offering regional data residency and a self-hosted option. For a critical information infrastructure operator or high-volume handler, mainland personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. For a China-facing synthesized voice (Aura, Voice Agent), the deep-synthesis and generative-AI measures (CAC filing + content labeling) add a second door. |
| Reachability is not the axis | That Deepgram resolves and returns a transcript from the mainland is the delivery half, not the answer — a reachable offshore API simply exports more voiceprints. The lawful lever is to keep China-origin audio's processing in-country: self-host Deepgram's models inside China, or route China voice through a licensed in-country speech service whose data stays in the mainland, with the Article 28 separate consent and data minimization — while the China-facing app that captures or plays the audio carries its own ICP filing and in-country delivery. |
What you actually send — your speakers’ voiceprints and words
Deepgram is a raw speech-AI engine, not a content archive about you: audio goes in through its API, and text or synthesized speech comes back. On the speech-to-text side (Nova), you send a recording — a sales or support call, a voice message, a dictated clinical or legal note — and it returns a transcript, often with diarization that separates and labels each speaker. That recording is two things at once: the spoken content, which may itself be health, financial, or identity information, and the speaker’s voiceprint, a biometric identifier unique to that person. You can redact a transcript; you cannot anonymize the audio, because the audio is the identifier. On the text-to-speech side (Aura, Aura-2) and in the Voice Agent API, you send text and a chosen voice and get synthesized audio back — a generative feature that carries its own China duties when offered to the public.
Where does the audio go? Deepgram’s hosted API runs on its own servers, and its regional-endpoints documentation names the geographies: a default Global endpoint, plus EU (api.eu.deepgram.com), Australia (api.au.deepgram.com), and India (api.in.deepgram.com), each of which Deepgram says keeps requests “never routed outside” that region. None of those regions is in mainland China, and there is no China endpoint to select. For a caller or employee in China, each request is their voice leaving the country in real time.
On retention and training, Deepgram runs a Model Improvement Partnership Program: you can keep any request out of it by adding mip_opt_out=true, and Deepgram states that “Data from opted-out requests is retained only for the duration necessary to process the request.” A single-tenant Dedicated tier adds regional data residency. These are real data-protection controls — but they govern retention and training, not the border crossing itself, and none of the hosted regions sits in the mainland.
It’s a cross-border transfer of sensitive biometric data — under PIPL
Sending a China-origin recording to Deepgram’s servers in the US, the EU, Australia, or India is a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境). As the handler, you — not Deepgram, the processor — must give notice, obtain a separate consent for the export, and put one transfer mechanism in place: a CAC security assessment, the CAC standard contract, or certification.
What sharpens this case is that a voiceprint is sensitive personal information. PIPL Article 28 treats biometric data as a sensitive category, so processing or exporting it requires a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment (PIPIA) before the audio moves. The spoken content can pile on further sensitive categories — a diagnosis in a telehealth call, a card number read aloud to support, an ID recited to verify identity. And because the audio is the identifier, you cannot strip the sensitive part out and keep the rest: the voiceprint travels whenever the recording does.
Two more duties attach at the edges. Where you are a critical information infrastructure operator, or your volumes cross the regulators’ thresholds, mainland personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and a CAC-led data-export security assessment can be required before any of it lawfully leaves. And where you build a China-facing feature that synthesizes a voice with Aura or the Voice Agent API, China’s deep-synthesis rules and the generative-AI measures add a service-filing and content-labeling duty on that feature — a second door on top of the transfer.
Reaching the API isn’t the question — keeping the audio in-country is
The reflex for a China problem is to make a slow or failing third-party call respond faster. On this axis that reflex is backwards: making Deepgram’s offshore API more reachable for mainland users does not reduce the exposure — it simply exports more voiceprints, more smoothly, without supplying the lawful basis the transfer needs.
What actually works is to keep China-origin audio’s processing in-country, and here Deepgram offers a genuine lever that a pure cloud service does not: its models can be self-hosted. Deepgram states its voice AI is “available to self-host on your own infrastructure, both in the cloud or on-premises,” delivered as containers (Docker, Podman, Kubernetes) with “the same API and feature set as our hosted API,” and it describes the deployment plainly — “Your audio never leaves your environment.” Run that self-hosted stack on in-country infrastructure and the recording, the transcript, and the voiceprint are processed inside the mainland rather than shipped abroad. (Self-hosting is an enterprise-contract option; confirm the current terms and which models it covers with Deepgram.) Where self-hosting does not fit, route China audio through a licensed in-country speech service whose data stays in the mainland. Either way, obtain the Article 28 separate consent, run the PIPIA, minimize what you capture and keep, and — for any synthesized-voice feature you expose in China — meet the deep-synthesis and generative-AI filing and labeling duties. None of this is a tunnel that ships the audio offshore while hiding that it does.
This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, a data-export assessment, in-country storage, a generative-AI filing, or an ICP filing — and in what combination — turns on your entity, your data volumes, whose voices you capture, and exactly what you send to transcribe or synthesize. Settle the specifics with counsel before a single mainland recording leaves the country.
The lawful path — map, localize, deliver
You do not have to drop Deepgram for your other markets to handle China voice lawfully. 21YunBox is a compliant overlay, not a migration — and, for a service you already use, a partner alongside your stack rather than a competitor to the speech vendor. There are three moves, and they fit together.
Map. Our China compliance team inventories what audio flows to Deepgram — which calls, recordings, and voice features; whose voiceprints and what spoken content they carry; where Deepgram processes and stores the audio; whether it is retained or used to train models; whether any feature synthesizes a voice; and where you lack a lawful basis for the cross-border leg (a separate Article 28 consent and a PIPIA, a transfer mechanism, a deep-synthesis/generative-AI filing). The exposure is written down before anything changes.
Localize. Because the risk is China-origin audio leaving the country, localize here means keeping that audio’s processing in-country: self-host Deepgram’s speech models inside China, or route China voice through a licensed in-country speech service whose data stays in the mainland; obtain the Article 28 separate consent; disable training retention; and, for a China-facing synthesized voice, meet the deep-synthesis and generative-AI filing and labeling duties. It never means a tunnel that makes the offshore call anyway. 21YunBox never uses or suggests circumvention of any kind.
Deliver. The China-facing site or app that captures or plays the audio is a public internet service with an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer provides it, ICP-filed and in-country, in front of the stack you already run. No rebuild, no second codebase.
The goal is plain: your voice features run legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization (Article 39)
- China’s data-export security assessment measures
- China’s generative-AI measures (生成式人工智能服务管理暂行办法)
- How to get an ICP filing for China
