Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does DeepL Work in China? PIPL Cross-Border Data Transfer & Content Residency

Send a string or a whole document to DeepL and it travels to DeepL's offshore servers — the EU by default, or the US or Japan, never mainland China — to be translated, carrying whatever personal, sensitive or confidential information the text holds: a PIPL cross-border transfer. A compliance-first look at translating China content with DeepL.

Does DeepL work in China?

Whether DeepL works in China is a data-residency question about the content you send it, not a speed one.

DeepL's API and apps generally resolve from the mainland; the risk is that every string or document you send is shipped to DeepL's own servers — the EU by default, or the US or Japan, never mainland China — to be translated, carrying whatever personal or sensitive information it holds. That is a PIPL cross-border transfer of everything inside it, and an Article 28 matter when the content is sensitive. DeepL is genuinely strong on handling — for paid plans, by its own words, "texts aren't saved on persistent storage and aren't used to train our models" — but that governs retention, not the export, and its residency add-on reaches only the EU, the US and Japan. The lawful lever is to keep China content's translation in-country — minimize and pseudonymize personal information in strings and route China content through a licensed in-country alternative — not to make the offshore API reachable.

This is a risk picture, not a verdict — your obligations turn on your entity and data volumes. Our China team can map your DeepL content exposure with you →

What DeepL's own documentation says about China

FactPrimary source
DeepL's paid-plan posture is strong on retention — and precise about tier. DeepL's developer documentation states that with "DeepL API paid plans, texts aren't saved on persistent storage and aren't used to train our models," and that DeepL "adheres strictly to EU data protection laws and ISO 27001"; its data-security page adds SOC 2 Type II and Bring Your Own Key encryption. The free Translator and Write are a different footing — DeepL's terms bar personal data on them — so anything carrying personal information belongs on the paid API or Pro under a data-processing agreement, not the free tier. DeepL API Documentation — About (Maximum data security), retrieved 2026-10-10
DeepL processes your text offshore — the EU, the US or Japan, never mainland China. DeepL states it "will no longer process data exclusively within Europe" and has "added AWS as a sub-processor," while "DeepL remains the data processor"; its regional API endpoints are the EU (default), the United States and Japan, and its Data Residency add-on pins processing to one of those regions. None is in mainland China, so a China-origin string or document is transferred across the border on every call. DeepL blog — We're expanding DeepL's data infrastructure; DeepL API Documentation — Regional endpoints, retrieved 2026-10-10
Sending a document abroad to be translated is a cross-border transfer of everything inside it. Under PIPL Articles 38–40 the handler must give notice, obtain a separate consent, and use a transfer mechanism (CAC security assessment, standard contract, or certification); sensitive content adds Article 28 — specific purpose, strict necessity, separate consent, and a prior impact assessment. You cannot anonymize a text you need translated in full. PIPL Articles 28 and 38–40, retrieved 2026-10-10
A CIIO or high-volume handler owes an in-country storage duty an offshore translation service cannot meet. Mainland personal information and important data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. DeepL's residency add-on reaches only the EU, the US and Japan, so it does not satisfy a China storage duty. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a product, support or localization team serving mainland China, the question about DeepL was never whether its API or apps resolve from the mainland — they generally do. The real question is what happens to the content you send to be translated. DeepL is a machine-translation service: you pass it a string, a support ticket, a contract or an entire document, and it ships that text to its own servers to translate it and hand it back. By DeepL’s own account it “will no longer process data exclusively within Europe” — paid traffic runs in the region your account is assigned or selects (the EU by default, the United States, or Japan), with AWS added as a sub-processor, and there is no mainland-China region. So every job is a live cross-border transfer of whatever personal, sensitive or confidential information the text carries — the names and emails in a ticket, the employee data in an HR file, clinical or financial language, unreleased copy. That trips PIPL’s cross-border rules (Articles 38–40, 数据出境), Article 28 where the content is sensitive, and — for a CIIO or high-volume handler — a content-residency duty under CSL Article 39.

DeepL's API documentation stating that with DeepL API paid plans, texts are not saved on persistent storage and are not used to train its models, and that DeepL adheres strictly to EU data protection laws and ISO 27001
"texts aren't saved on persistent storage and aren't used to train our models." DeepL's own developer documentation describes a strong no-retention, no-training posture for the paid API — one that still runs on DeepL's servers in the EU, the US or Japan, never in mainland China, so the text still leaves the country to be translated. Source: DeepL API Documentation — About

DeepL in China at a glance

What decides it In DeepL's own terms — and China's law
What you send to translate, and that it carries personal information The content you most need translated is the content most likely to carry personal or confidential information — names, emails and addresses in support tickets; employee records in HR documents; clinical, financial or legal text; source strings and unreleased copy. DeepL's API lists the document formats it ingests — DOCX, PPTX, XLSX, PDF, HTML, IDML, XLIFF, XML, JSON and more — so an entire document, and everything in it, is what leaves. Tied to people in China, that is personal information under PIPL; health, financial, ID or biometric content is Article 28 sensitive.
It is sent offshore — a cross-border transfer DeepL states it "will no longer process data exclusively within Europe"; paid traffic runs in the region your account is assigned or selects — the EU (default), the United States, or Japan — with "AWS as a sub-processor … providing the necessary infrastructure for global scale," while "DeepL remains the data processor." None of those regions is in mainland China. Shipping a China-origin string or document there is a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (Articles 38–40, 数据出境).
Sensitive content, and the content-residency duty You cannot anonymize a document you need translated in full, so sensitive categories travel with it — Article 28 requires a specific purpose, strict necessity, separate consent, and a prior personal-information protection impact assessment. For a critical information infrastructure operator or high-volume handler, mainland personal information must also be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged — a duty an offshore translation service cannot meet.
Is the text kept or used to train models? Here DeepL is genuinely strong — and precise about tier. For paid plans it states "texts aren't saved on persistent storage and aren't used to train our models," adds "SOC 2 Type II" and Bring Your Own Key encryption, and a Data Residency add-on can pin processing to one chosen region. But the free Translator and Write are a different posture — DeepL's terms bar personal data on them — and residency's regions are the EU, the US and Japan, not mainland China. The posture reduces the retention and training exposure; it does not make the cross-border transfer disappear.
Reachability is not the axis That DeepL resolves and returns a translation from the mainland is the delivery half, not the answer — a reachable offshore API simply exports more content. The lawful lever is to keep China-origin content's translation in-country: minimize and pseudonymize personal information in strings before any offshore call, use the paid API's no-storage, no-training posture under a signed data-processing agreement for what may lawfully cross, and route the rest through a licensed in-country translation alternative — while the China-facing site or app that consumes the translations carries its own ICP filing and in-country delivery (State Council Order No. 292; MIIT Order No. 33).

What you actually send — and where it goes

DeepL is a raw machine-translation service, not a content repository: text goes in through its API, apps or website, a translation comes back, and the exposure is the transfer itself rather than a permanent corpus it keeps about you. (DeepL is not a translation-management system — it is the engine many of those systems and computer-assisted-translation tools call.) But the transfer is the whole point. Its own API documentation lists the formats it ingests — “DOCX, PPTX, XLSX, PDF, HTML, IDML, XLIFF, XML, JSON” and more — which means a complete document, with every name, figure and clause in it, is what crosses the border to be translated. The content you most need translated is precisely the content most likely to carry personal or confidential information: the address in a shipping query, the diagnosis in a patient message, the salary in an HR letter, the terms in a contract, the strings in an unreleased build.

And it does not stay in Europe. DeepL writes that it “will no longer process data exclusively within Europe”; paid traffic now runs in the region an account is assigned or selects — the EU by default, the United States, or Japan — on DeepL-operated European data centers plus AWS as a sub-processor. There is no mainland-China region or endpoint to select. For a visitor or employee in China, each call is their content leaving the country in real time.

On retention DeepL is, to its credit, clear and tier-specific. For paid plans its developer documentation states that “texts aren’t saved on persistent storage and aren’t used to train our models,” and its data-security page says texts are “never stored or used for model training without your consent,” backed by SOC 2 Type II, ISO 27001 and GDPR alignment, with Bring Your Own Key encryption available. The free Translator and Write are a different footing — DeepL’s terms prohibit putting personal data through them — so the compliant route for anything carrying personal information is the paid API or Pro under a data-processing agreement, never the free tier. Two wrinkles remain even on paid plans: document jobs land on disk for the duration of the job, and glossaries you save persist so they follow you across devices.

It’s a cross-border data transfer — under PIPL

Sending a China-origin string or document to DeepL’s servers in the EU, the US or Japan is a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境). As the handler, you — not DeepL, the processor — must give notice, obtain a separate consent for the export, and put one transfer mechanism in place: a CAC security assessment, the CAC standard contract, or certification. Sending a document abroad to be translated is a cross-border transfer of everything inside it, not merely of “a file.”

Where the content is sensitive — medical, financial, biometric, religious, government-ID — PIPL Article 28 adds a higher bar: a specific purpose, strict necessity, separate consent, and a prior personal-information protection impact assessment. You cannot strip the sensitive parts out of a document whose point is to be translated in full, so the sensitive content travels with it.

Where your organization is a critical information infrastructure operator, or your volumes cross the regulators’ thresholds, an in-country storage duty attaches: mainland personal information and important data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). And where volume or sensitivity crosses a threshold, a CAC-led data-export security assessment can be required before any of it lawfully leaves. DeepL’s EU, US and Japan footprint, its no-retention posture and its residency add-on are real data-protection strengths — but they are EU-law and regional-choice strengths, not a mainland-China residency, and none of them furnishes the PIPL basis the export itself requires.

Reaching the API isn’t the question — keeping the content in-country is

The instinct for most China problems is to make a slow or failing third-party call load faster or more reliably. On this axis that instinct is backwards: making DeepL’s offshore API respond more dependably for mainland users does not shrink the exposure — it exports more content, more smoothly, without supplying the lawful basis the transfer needs.

What actually works is to keep China-origin content’s translation on an in-country path. Start by minimizing: pseudonymize or redact the personal information in strings before any call, so that what does cross the border carries as little identifiable content as possible. For what may lawfully cross, use DeepL’s paid API or Pro — not the free tier — under a signed data-processing agreement, with its no-storage, no-training posture in force, so the transfer is governed and the retention exposure is cut. It is worth being precise about what DeepL does and does not offer here: it is a cloud service, and there is no current DeepL on-premises or air-gapped deployment of the translation engine to run inside China; its Data Residency add-on pins processing to one region, but only the EU, the US or Japan — not mainland China. So the paid posture and residency, valuable as they are, will not by themselves keep China content in China. For the China-origin content that cannot lawfully make the trip, route it through a licensed in-country machine-translation or localization alternative whose data stays in the mainland. None of this is a tunnel that ships the content offshore anyway while hiding that it does.

This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, a data-export assessment, in-country storage, or an ICP filing — and in what combination — turns on your entity, your data volumes, how much of your China traffic is personal or sensitive, and exactly what you send to translate. Settle the specifics with counsel before you send a single mainland document abroad to be translated.

The lawful path — map, localize, deliver

You do not have to drop DeepL for your other markets to translate China content lawfully. 21YunBox is a compliant overlay, not a migration — and, for a service you already use, a partner alongside your stack rather than a competitor to the translation engine. There are three moves, and they fit together.

Map. Our China compliance team inventories what content flows to DeepL — which strings, tickets, documents and glossaries, and the personal, sensitive or confidential information inside them — where DeepL processes and stores it, whether it is retained or used for training, and where you lack a lawful basis for the cross-border leg, so the exposure is written down before anything changes.

Localize. Because the risk is China-origin content leaving the country, localize here means keeping that content’s translation in-country: minimize and pseudonymize personal information in strings, use DeepL’s paid API no-storage, no-training posture under a data-processing agreement for what may lawfully cross, and route the rest through a licensed in-country translation alternative whose data stays in the mainland. It never means a tunnel that makes the offshore call anyway. 21YunBox never uses or suggests circumvention of any kind.

Deliver. The China-facing site or app that consumes the translations is a public internet service with an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer provides it, ICP-filed and in-country, in front of the stack you already run. No rebuild, no second codebase.

The goal is plain: your site runs legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Is DeepL blocked in China?
Generally no — DeepL's API and apps usually resolve and return translations from the mainland, so reachability is not the issue. The compliance issue is that the content you send is transferred to DeepL's offshore servers (the EU, the US or Japan — there is no mainland-China region) to be translated, which is a PIPL cross-border transfer of the personal and sensitive information inside it.
Does DeepL store my text or use it to train its models?
For paid plans, DeepL's own documentation says texts "aren't saved on persistent storage and aren't used to train our models," and it holds SOC 2 Type II and ISO 27001. The free Translator and Write are different — DeepL's terms bar personal data on them. But even on the paid API, this strong no-retention posture governs how the text is handled after it arrives; it does not change the fact that the text left China, which is the cross-border transfer PIPL regulates.
Can DeepL be deployed inside China to keep translation in-country?
Not today — DeepL is a cloud service, there is no current DeepL on-premises deployment of the translation engine, and its Data Residency add-on offers only the EU, the US or Japan, not mainland China. The lawful in-country path is to minimize and pseudonymize personal information in strings before any offshore call, use the paid API's no-storage, no-training posture under a data-processing agreement for what may lawfully cross, and route China-origin content that cannot cross through a licensed in-country translation alternative — while the China-facing site that consumes the translations carries its own ICP filing. Settle the specifics with counsel.

ARTICLES RELATED TO DEEPL

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.