Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does ElevenLabs Work in China? PIPL Cross-Border, Voiceprint Biometrics & Data Residency

The audio you send ElevenLabs to synthesize, clone, or transcribe carries the speaker's voiceprint — Article 28 sensitive biometric personal information you cannot anonymize — and shipping it to ElevenLabs' offshore servers (the U.S. by default, no mainland-China region) is a PIPL cross-border transfer. A compliance-first look at using ElevenLabs voice AI in mainland China.

Does ElevenLabs work in China?

ElevenLabs has no mainland-China region — the audio you send it to synthesize, clone, or transcribe is a recording of someone's voiceprint shipped to its offshore servers, which is sensitive biometric personal information you cannot anonymize.

A voice recording carries both the speaker's voiceprint (an Article 28 sensitive biometric identifier) and whatever was said, and ElevenLabs stores customer data in the U.S. by default (the EU, India, and Singapore for Enterprise only) — so every call is a PIPL cross-border transfer of sensitive biometric personal information, and because ElevenLabs synthesizes and clones voices, a China-facing feature also triggers the deep-synthesis and generative-AI filing and content-labeling duties. The lawful lever is to keep China-origin audio's processing in-country — a licensed domestic voice service, or an in-country deployment vetted with counsel — with the Article 28 separate consent and a prior impact assessment, not to make the offshore API more reachable.

This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →

What ElevenLabs's own documentation says about China

FactPrimary source
ElevenLabs stores customer data in the U.S. by default, with no mainland-China region. Its data-residency documentation states, "As a standard, ElevenLabs' customer data is hosted/stored in the U.S.," names the EU, India, and Singapore as Enterprise-only storage options, and warns that even then "processing may nevertheless occur outside of the selected location" through its international affiliates and subprocessors. No option keeps mainland-China audio in the mainland. ElevenLabs Docs — Data residency (elevenlabs.io), retrieved 2026-10-10
ElevenLabs uses inputs to train its models by default and itself flags voice data as possibly biometric. Its privacy policy says, "We use your personal information to research, build, train and improve our AI models," that this includes "our models learning patterns in speech and audio," and that in verifying a voice it "may be handling biometric or sensitive or special category data under some laws." Zero Retention Mode is "available to select enterprise customers" and "applies to API use only"; a training opt-out exists but is prospective. ElevenLabs Privacy Policy & Zero Retention Mode docs (elevenlabs.io), retrieved 2026-10-10
A voiceprint is sensitive biometric personal information under PIPL Article 28, and sending it offshore is a cross-border transfer. Article 28 treats biometric information as a sensitive category requiring a specific purpose, strict necessity, a separate consent, and a prior personal-information protection impact assessment; Articles 38–40 require notice, a separate consent, and a transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) before a Chinese user's audio leaves the country. You cannot anonymize a recording whose point is the voice. Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10
A China-facing synthesized or cloned voice adds a deep-synthesis and generative-AI filing door. China's deep-synthesis provisions and the Interim Measures for Generative AI Services impose a CAC filing (生成式人工智能服务备案) and AI-content-labeling duties on a generative service offered to the public in the mainland; cloning a real person's voice without consent is also an Article 28 and portrait-and-voice-rights matter. For a CII operator or high-volume handler, in-country storage attaches under PIPL Article 40 and Cybersecurity Law Article 39 (formerly Article 37). Interim Measures for the Management of Generative AI Services, CAC (cac.gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a product, support, or voice team serving mainland China, the question about ElevenLabs was never whether its API resolves from the mainland — it generally does. The real question is what happens to the audio you send it, and to the voices you ask it to build. ElevenLabs is a generative voice platform: you send text and a chosen voice to synthesize speech, a sample of a real person’s voice to clone it, or — through its Scribe speech-to-text and voice-changer endpoints — recorded audio to transcribe or transform. By ElevenLabs’ own account, “As a standard, ElevenLabs’ customer data is hosted/stored in the U.S.,” with EU, India, and Singapore storage for Enterprise accounts only, and no mainland-China region. So each call ships a recording — a biometric voiceprint plus whatever was said — out of the country: a PIPL cross-border transfer (Articles 38–40, 数据出境), Article 28 for the sensitive voiceprint (a separate consent and a prior impact assessment), a content-residency duty under CSL Article 39 for a CIIO or high-volume handler, and — because the service synthesizes and clones voices — China’s deep-synthesis and generative-AI filing obligations for any China-facing feature.

ElevenLabs' data residency documentation stating that customer data is hosted and stored in the U.S. by default, with additional storage in the EU, India, and Singapore for Enterprise accounts, and that processing may occur outside the selected location through ElevenLabs' international affiliates and subprocessors
"As a standard, ElevenLabs' customer data is hosted/stored in the U.S." The only additional residency regions are the EU, India, and Singapore, and for Enterprise accounts only — there is no mainland-China region, and even then ElevenLabs states "processing may nevertheless occur outside of the selected location." Source: ElevenLabs Docs — Data residency

ElevenLabs in China at a glance

What decides it In ElevenLabs' own terms — and China's law
What you send, and that it carries the speaker's voiceprint The point of a voice service is the voice itself. To synthesize or clone, you send text and a chosen voice — or, for a Professional Voice Clone, a sample of a real person speaking; to transcribe or transform, you send recorded audio to the Scribe speech-to-text or voice-changer endpoints. A recording of a person is their voiceprint — a biometric identifier — and it carries whatever was said: a support call, a voice message, a dictated note. Tied to a person in China, that is personal information under PIPL; the voiceprint, and any health, financial, or ID content in the speech, is Article 28 sensitive.
It is sent offshore — a cross-border transfer ElevenLabs states, "As a standard, ElevenLabs' customer data is hosted/stored in the U.S.," with "additional storage locations in the EU, India, and Singapore" for Enterprise accounts, and warns that even then "processing may nevertheless occur outside of the selected location" through its "international affiliates and subprocessors." None of those is in mainland China. Sending a China-origin recording or voice sample there is a cross-border transfer PIPL governs: notice, a separate consent, and one transfer mechanism (Articles 38–40, 数据出境).
Sensitive biometric — Article 28, and you can't anonymize a voice A voiceprint is biometric data, which PIPL Article 28 treats as sensitive: it requires a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment (PIPIA) before it is processed or transferred. You can redact a transcript, but you cannot anonymize the audio — the voice is the identifier. ElevenLabs itself notes that in verifying a voice it "may be handling biometric or sensitive or special category data under some laws."
Generative voice, retention, and residency ElevenLabs synthesizes and clones voices, so a feature offered to the public in China also triggers China's deep-synthesis provisions and the generative-AI measures — a CAC filing (生成式人工智能服务备案) and AI-content-labeling duties — and cloning a real person's voice without consent is an Article 28 and portrait-and-voice-rights matter. On retention, ElevenLabs uses inputs to "research, build, train and improve our AI models" by default; Zero Retention Mode is Enterprise-only and "applies to API use only." For a critical information infrastructure operator or high-volume handler, in-country storage also attaches (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged.
Reachability is not the axis That ElevenLabs resolves and returns audio from the mainland is the delivery half, not the answer — a reachable offshore API simply exports more voiceprints. The lawful lever is to keep China-origin audio's processing in-country: route it through a licensed in-country voice service whose data stays in the mainland, or run an in-country deployment vetted with counsel, with the Article 28 separate consent, training retention disabled, and — for any China-facing synthesized or cloned voice — the deep-synthesis and generative-AI filing met. The China-facing app that captures the audio carries its own ICP filing and in-country delivery.

What you actually send — your speakers’ voiceprints and words

ElevenLabs is first a generative voice platform — text-to-speech and voice cloning — and also runs speech-to-text (its Scribe model) and a voice changer. Across all of them, what crosses the border is audio of a person, or a sample used to build a synthetic copy of their voice. A recording is not like a form field you can mask before you send it: it is a biometric identifier of the speaker, and it carries the content of what was said — a customer’s account details on a support call, a patient’s symptoms in a dictated note, an executive’s remarks in a recorded meeting. For a Professional Voice Clone you deliberately upload a sample of a real person speaking, and both the sample and the resulting clone are biometric.

And it does not stay in China — there is no mainland option. ElevenLabs states, “As a standard, ElevenLabs’ customer data is hosted/stored in the U.S.,” with the EU, India, and Singapore available as storage locations, and “Data residency is an exclusive feature available to ElevenLabs’ Enterprise customers.” Crucially, storage is not processing: ElevenLabs warns that “While storage will take place in the selected location, processing may nevertheless occur outside of the selected location,” including by its “international affiliates and subprocessors,” for support and content-moderation purposes. For a speaker in China, each call is their voice leaving the country in real time.

On retention and training, ElevenLabs’ privacy policy says it uses personal information to “research, build, train and improve our AI models,” and that this includes “our models learning patterns in speech and audio,” on a legitimate-interests basis, with consent only “if required by law.” A prospective training opt-out exists, and ElevenLabs commits not to keep “data we generate about your voice for longer than 3 years after your last interaction,” though that cap is worded around data it generates rather than plainly around the recordings and clones you upload. Zero Retention Mode — which deletes “most data in requests and responses” once a request completes — is “available to select enterprise customers” and “applies to API use only,” not the web app or playground. These are real controls, but they are account-tier and API-scoped, and none of them turns an offshore service into a mainland-resident one.

It’s a cross-border transfer of sensitive biometric data — under PIPL

Sending a China-origin recording, or a sample used to clone a voice, to ElevenLabs’ servers in the U.S. (or the EU, India, or Singapore) is a cross-border transfer of personal information under PIPL Articles 38–40 (数据出境). As the handler, you — not ElevenLabs, the processor — must give notice, obtain a separate consent for the export, and put one transfer mechanism in place: a CAC security assessment, the CAC standard contract, or certification. A recording is a transfer of everything audible in it, not merely of “a file.”

Because a voiceprint is biometric, PIPL Article 28 adds a higher bar on top of the transfer: a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment before the voice is processed or transferred. Spoken content can pile on further sensitive categories — health, finance, government ID. And you cannot strip the identifier out of audio whose purpose is the voice, so the sensitive element travels with every call.

Because ElevenLabs synthesizes and clones voices, a China-facing feature built on it also runs into China’s deep-synthesis provisions and the generative-AI measures: a CAC filing (生成式人工智能服务备案) and AI-content-labeling duties for a generative service offered to the public in the mainland — a second door that sits on top of the transfer. Cloning a real person’s voice without their consent is separately an Article 28 problem and a portrait-and-voice-rights problem under the Civil Code.

Where your organization is a critical information infrastructure operator, or your volumes cross the regulators’ thresholds, an in-country storage duty attaches — mainland personal information must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — and a CAC-led data-export security assessment can be required before any of it lawfully leaves. ElevenLabs’ U.S., EU, India, and Singapore footprint and its Zero Retention Mode are real data-protection features, but they are regional-choice and API-scoped controls, not a mainland-China residency, and none of them furnishes the PIPL basis the export itself requires.

Reaching the API isn’t the question — keeping the audio in-country is

The instinct for most China problems is to make a slow or failing third-party call load faster. On this axis that instinct is backwards: making ElevenLabs’ offshore endpoints respond more dependably for mainland users does not shrink the exposure — it exports more voiceprints, more smoothly, without supplying the lawful basis the transfer needs.

What actually works is to keep China-origin audio’s processing on an in-country path, and it is worth being precise about ElevenLabs’ options here, because they changed. Historically a cloud-only service, ElevenLabs announced in 2026 an early-access on-premise and on-device deployment — “Built for governments, public sector, and regulated enterprises,” where it says “No customer data or audio ever leaves your infrastructure” — alongside a VPC mode that runs the models inside your own AWS or GCP account. That is a genuine in-country lever where ElevenLabs grants it and you run the hardware inside the mainland — but it is early access, the VPC clouds do not offer a clean mainland-China region, and, decisively, keeping the audio in-country does not by itself clear the deep-synthesis and generative-AI filing or the Article 28 consent for a China-facing synthesized or cloned voice. So for most teams the dependable route is a licensed in-country voice service whose data stays in the mainland, paired with the Article 28 separate consent and a PIPIA, training retention disabled, and the deep-synthesis and content-labeling duties met for any generated voice. For speech-to-text specifically, an open, self-hostable transcription model run on servers inside China is another way to keep the audio from ever leaving. None of this is a tunnel that ships the audio offshore anyway while hiding that it does.

This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, a data-export assessment, in-country storage, a deep-synthesis or generative-AI filing, or an ICP filing — and in what combination — turns on your entity, your data volumes, how much of your China audio is sensitive, and exactly what you send to synthesize, clone, or transcribe. Settle the specifics with counsel before you send a single mainland recording abroad.

The lawful path — map, localize, deliver

You do not have to drop ElevenLabs for your other markets to handle China voice lawfully. 21YunBox is a compliant overlay, not a migration — and, for a service you already use, a partner alongside your stack rather than a competitor to the voice engine. There are three moves, and they fit together.

Map. Our China compliance team inventories what audio flows to ElevenLabs — which recordings, voice samples, and clones, whose voiceprints, and the spoken content inside them — where ElevenLabs processes and stores it, whether it is retained or used to train models, whether any China-facing feature synthesizes or clones a voice, and where you lack a lawful basis (an Article 28 separate consent and PIPIA; a transfer mechanism; a deep-synthesis or generative-AI filing), so the exposure is written down before anything changes.

Localize. Because the risk is China-origin audio leaving the country, localize here means keeping that audio’s processing in-country — a licensed in-country voice service whose data stays in the mainland, or an in-country deployment vetted with counsel — with the Article 28 separate consent, training retention disabled, and, for any China-facing synthesized or cloned voice, the deep-synthesis and generative-AI filing and content-labeling duties met. It never means a tunnel that makes the offshore call anyway. 21YunBox never uses or suggests circumvention of any kind.

Deliver. The China-facing site or app that captures and plays the audio is a public internet service with an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer provides it, ICP-filed and in-country, in front of the stack you already run. No rebuild, no second codebase.

The goal is plain: your voice features run legally and compliantly for your users in China.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does ElevenLabs work in China?
Its API generally resolves from the mainland, but reachability is not the compliance question. ElevenLabs has no mainland-China region — its data-residency docs say customer data is "hosted/stored in the U.S." by default, with the EU, India, and Singapore as Enterprise-only options — so the audio you send to synthesize, clone, or transcribe is processed offshore. A recording of a person is their voiceprint, which PIPL Article 28 treats as sensitive biometric personal information you cannot anonymize, and shipping it abroad is a cross-border transfer under Articles 38–40 (notice, a separate consent, and a transfer mechanism). Because ElevenLabs synthesizes and clones voices, a China-facing feature also triggers the deep-synthesis and generative-AI filing and content-labeling duties. We never use or suggest any form of circumvention — confirm your exact obligations with counsel.
Is a voice recording really sensitive biometric data under PIPL?
Yes. A recording of a person's voice is their voiceprint, a biometric identifier, and PIPL Article 28 classifies biometric information as sensitive personal information — it requires a specific purpose, strict necessity, a separate specific consent, and a prior personal-information protection impact assessment before the voice is processed or transferred. You can redact a transcript, but you cannot anonymize the audio: the voice itself is the identifier. ElevenLabs acknowledges that in verifying a voice it "may be handling biometric or sensitive or special category data under some laws." Spoken content can add further sensitive categories — health, finance, government ID — which travel with every call.
What's the compliant, in-country path for voice AI in China?
Keep China-origin audio's processing in the mainland. For most teams that means a licensed in-country voice service whose data stays in China, or — where ElevenLabs grants its early-access on-premise or VPC deployment and you run the hardware inside the mainland — an in-country deployment vetted with counsel, paired with the Article 28 separate consent and a prior impact assessment, training retention disabled, and, for any synthesized or cloned voice, the deep-synthesis and generative-AI filing and content-labeling duties met. For speech-to-text, an open, self-hostable transcription model run inside China keeps the audio from ever leaving. Then deliver the China-facing app that captures the audio on ICP-filed, in-country infrastructure. 21YunBox maps the exposure, localizes onto the in-country option, and provides the delivery — no rebuild. It is a lawful in-country deployment, not a way around anyone's terms.

ARTICLES RELATED TO ELEVENLABS

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.