Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Five9 Work in China? Voice Telecom Licensing, Call Recordings & PIPL Data Residency

Five9's data-center footprint is North America, the EU, and India — no mainland-China region — so the call recordings, voice transcripts, IVR inputs, and caller PII it holds come to rest offshore as a PIPL cross-border transfer, and carrying interactive voice to and from China is a licensed value-added telecom activity. A compliance-first look at Five9 and China's data-residency and telecom rules.

Does Five9 work in China?

Five9 can be reached from China, but that was never the compliance question — it runs no mainland-China region, so the recordings and caller data it holds rest offshore, and carrying interactive voice to and from the mainland is a licensed activity a foreign contact center can't perform directly.

Five9's published data-center footprint is North America, the EU (Frankfurt, Amsterdam), and India (Delhi, Mumbai) — there is no mainland-China region to select. The call recordings, voice transcripts, IVR and keypad entries, screen recordings, and caller and agent PII a cloud contact center holds are personal information — a voiceprint and a payment card read over the phone are sensitive personal information under PIPL Article 28 — so holding them offshore is a PIPL cross-border transfer (Articles 38–40), with an in-country storage duty for CII and high-volume handlers (Cybersecurity Law Article 39, formerly Article 37 — renumbered by the 2025 amendment in force January 1, 2026). Separately, carrying inbound/outbound voice to and from China is a value-added telecom service that needs a Chinese license a foreign provider can't hold, so cross-border voice is best-effort — not a block.

Five9 is a partner, not a competitor: 21YunBox maps your exposure, localizes the records that must stay on mainland soil, and delivers your China-facing surfaces on ICP-filed in-country infrastructure in front of the Five9 stack you already run. Treat this as a risk map, not a ruling — our China team can map your exposure →

What Five9's own documentation says about China

FactPrimary source
Five9 operates no mainland-China region, and where it carries voice in-country it first obtains a local telecom license. Announcing its India expansion, Five9 said it added “two new Five9 Data Centers in Delhi and Mumbai, India” and “has achieved Department of Telecommunications (DOT) Unified License (Virtual Network Operator) (UL VNO) licensing to provide Access Services, National Long Distance and International Long Distance in India.” Its published footprint is North America, the EU (Frankfurt, Amsterdam), and India — no mainland-China region exists to select. Five9, “Five9 Expands Global Footprint with New Data Centers in India” (five9.com), retrieved 2026-10-10
Five9 aligns its data protection to Western privacy regimes — China's PIPL is not among them. Five9's data-protection page says it maintains safeguards “in accordance with a number of data protection laws, regulations, and standards including, but not limited to” HIPAA, PCI DSS, the California privacy regulations (CCPA/CRPA), Canada's PIPEDA, “the General Data Protection Regulation (GDPR), and the UK Data Protection Act 1998.” China's PIPL cross-border and data-localization duties are not covered by that footprint — they remain the customer's responsibility. Five9, “Corporate Data Security & Protection” / Trust (five9.com/trust/data-protection), retrieved 2026-10-10
Carrying interactive voice for mainland users is a licensed value-added telecom activity. Under China's Measures for the Administration of Telecommunications Business Licensing (电信业务经营许可管理办法, MIIT Order No. 42, in force September 1, 2017), a value-added telecom operator must hold the Value-Added Telecommunications Business License (增值电信业务经营许可证) and operate only within the service type and coverage area it states (Articles 4 and 16). A foreign contact center holds no such license, so cross-border voice is best-effort — not a block. Measures for the Administration of Telecommunications Business Licensing, MIIT Order No. 42, Arts. 4 and 16 (gov.cn), in force 2017-09-01
Call recordings, transcripts, and caller PII are personal information — some of it sensitive — crossing the border. A voiceprint and payment-card or financial-account data are sensitive personal information under PIPL Article 28; moving a mainland caller's data to an offshore platform triggers Articles 38–40 (notice, a separate cross-border consent, and one transfer mechanism — a CAC security assessment, the standard contract, or certification). For a CII or high-volume handler, mainland personal information must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37 — the 2025 amendment, in force January 1, 2026, renumbered it from 37). Personal Information Protection Law of the PRC, Articles 28 and 38–40 (cac.gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, the question to settle about Five9 is not whether an agent can open the dashboard or whether a call can be dialed — it is where the record of every conversation is allowed to come to rest, and whether that conversation may lawfully be carried at all. Five9 is a cloud contact center: it records calls, transcribes voice, captures IVR and keypad entries, stores screen recordings and case histories, and holds the caller’s and the agent’s personal details. Its published data-center footprint is North America, the European Union, and India — there is no mainland-China region to select, so those records come to rest offshore. On top of that sits a second gate: carrying interactive inbound and outbound voice to and from the mainland is a licensed value-added telecom activity, not a reachability setting. Neither gate is about milliseconds.

Five9 press release 'Five9 Expands Global Footprint with New Data Centers in India' stating Five9 added two new data centers in Delhi and Mumbai and achieved a Department of Telecommunications Unified License to provide Access Services, National Long Distance and International Long Distance in India
Announcing its India expansion, Five9 described "two new Five9 Data Centers in Delhi and Mumbai, India, to support both local and multi-national enterprises powering customer experience strategies in-region" and said it had obtained a Department of Telecommunications license to carry voice there — a local region and a local telecom license Five9 holds for North America, the EU, and India, but not for mainland China. Source: five9.com — Five9 Expands Global Footprint with New Data Centers in India

Five9 in China at a glance

What decides it In Five9's own terms — and China's law
What it is Five9 — a cloud contact center (CCaaS): inbound and outbound voice, IVR, ACD, digital channels, and call recording. It is operated by Five9 from its own regions — North America, the EU, and India — and there is no Five9 mainland-China region or China telecom entity you run it from.
Where the interaction records live Five9's published data-center footprint is North America, the EU (Frankfurt, Amsterdam), and India (Delhi, Mumbai). No mainland-China region exists to select, so the call recordings, transcripts, IVR entries, and case histories tied to your China callers come to rest offshore.
What it holds, and why it is personal (and sensitive) information Call recordings, voice transcripts, IVR and keypad entries, screen recordings, ticket histories, and caller plus agent PII. A voiceprint and a payment card read aloud to pay an invoice are sensitive personal information under PIPL Article 28; held offshore, all of it is a cross-border transfer (PIPL Articles 38–40): notice, a separate consent, and one transfer mechanism.
The telecom-licensing door, and the storage duty Carrying interactive voice to and from the mainland is a value-added telecom service. Under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) a foreign contact center cannot hold directly — so cross-border voice is best-effort and delivery is not guaranteed. In-country storage can also bite for a CII or high-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). Five9 is not "blocked"; it simply is not a China-licensed in-country carrier.
The lawful path Map the PIPL, residency, sensitive-PI, and telecom exposure; localize consented in-country processing and storage for the records that must stay on mainland soil; and deliver any China-facing surface over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the Five9 stack you already run. On telecom 21YunBox is advisory — we hold no China telecom license.

No mainland region, so the recordings leave the country

Five9 runs from its own regions, and the public list of them is short: North America; the European Union, where it brought Frankfurt and Amsterdam online in 2022 so that European customers could keep data in-region; and India, where in October 2024 it opened data centers in Delhi and Mumbai and obtained a Department of Telecommunications Unified License (Virtual Network Operator) to carry voice in-country. That last move is worth pausing on, because it is exactly what lawful in-country operation looks like — a local telecom license of the kind the value-added telecom rules require before anyone may carry interactive voice for a country’s users, paired with in-region storage. Five9 has done it for India. It has not done it for mainland China. There is no Five9 mainland-China region and no China telecom license, so when a China-based customer or agent is on the line, the call recording, the transcript, the IVR entries, and the case record are written to infrastructure outside the mainland. Sent from or about a person in China to a platform operated offshore, that is a cross-border transfer of personal information under PIPL, and for a critical-information-infrastructure operator or a high-volume handler it can also require a CAC security assessment before the data may leave.

Call recordings, transcripts, and caller PII are personal information

A contact-center record is dense with personal information, and some of it is the most sensitive kind there is. A recorded call carries the caller’s voice — a biometric identifier — along with their name, phone number, account references, and whatever they happen to say: an address, a health complaint, a card number read aloud to settle a bill, the details of a disputed transaction. The transcript, the sentiment score, the IVR and keypad entries, the screen recording of the agent’s desktop, and the ticket history all inherit that content. Under China’s Personal Information Protection Law, a voiceprint and financial-account or payment-card information are sensitive personal information (Article 28), which raises the bar: handling them requires a specific purpose, strict necessity, and a separate consent, and moving them across the border layers on the Article 38–40 duties of notice, a distinct cross-border consent, and one approved transfer mechanism. The duty falls on the handler — the business operating the contact center — not only on Five9 as the vendor. None of this turns on how clearly the call connects; it turns on whether that content had a lawful basis to leave the country, and whether it had to stay in the first place.

Narrowing the exposure doesn’t close the door

Five9 gives you real levers to reduce what crosses. You can choose which region stores recordings, suppress or redact the card-entry (PCI) segments of a call, keep transcripts out of certain flows, pause recording on sensitive steps, or bring your own carrier. Each of these narrows what leaves the mainland. None of them changes that it leaves. As long as the storage region is North America, the EU, or India, a China caller’s personal information is still crossing the border the moment it is written — region choice only decides which offshore region, and redaction only decides how much. Self-hosting is not an escape either: Five9 is a multi-tenant cloud service with no mainland-China deployment to point an on-premises install at. So the residency question is not softened by configuration; it is only made smaller. And because the specifics — whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, how ICP filing applies to your China-facing surfaces, and how the renumbered Cybersecurity Law Article 39 (formerly Article 37) bears on you — turn on facts only your team and your counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.

The lawful path — map, localize, deliver

Reaching Chinese users with a contact center the lawful way has a shape, and it keeps Five9 where it already runs. 21YunBox is a compliant overlay, not a migration, and for an enterprise platform like Five9 we are a partner to it, not a competitor. We map your exposure first — reading the PIPL cross-border, data-residency, sensitive-PI, and value-added telecom obligations against your entity, your call and recording volumes, and who your callers and agents actually are, so you know exactly what counsel and a licensed local carrier need to confirm. We localize the records that must stay on mainland soil — standing up consented, in-country processing and storage for the recordings, transcripts, and caller data that cannot lawfully sit offshore, and routing the China voice leg through a China-licensed carrier where interactive calling is in scope. And we deliver every China-facing surface — the agent console, the customer portal, the callback or intake form — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the Five9 stack you already run, with no rebuild and no second codebase. On the telecom leg our role is advisory and lighter: 21YunBox does not hold a China telecom license and is not a carrier; that license and the carrier relationship sit with a licensed local provider and your counsel. The result is a customer-experience stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Five9 have a data center in mainland China?
No. Five9's published data-center footprint is North America, the European Union (Frankfurt and Amsterdam), and India (Delhi and Mumbai); there is no mainland-China region to select. That matters because a cloud contact center stores call recordings, voice transcripts, IVR entries, and caller PII in the region you run on — so for a China caller, that data comes to rest offshore, which is a PIPL cross-border transfer. Reachability is not the issue; where the records rest is.
Can Five9 place and receive calls in China?
Five9 is not blocked, but carrying interactive inbound and outbound voice to and from the mainland is a licensed value-added telecom service in China — it requires a Chinese value-added telecom license (增值电信业务经营许可证) that a foreign contact-center provider cannot hold directly. Five9 obtained a local telecom license to operate in India; it has no equivalent for mainland China. So cross-border voice is best-effort with no delivery guarantee, and the lawful route runs the China voice leg through a China-licensed carrier. We never use or suggest circumvention.
What does 21YunBox do for a Five9 deployment serving China?
We are a compliant overlay and a partner to Five9, not a replacement. We map your PIPL cross-border, data-residency, sensitive-PI, and telecom exposure against your entity and your call and recording volumes; we localize consented, in-country storage for the records that must stay on mainland soil; and we deliver your China-facing surfaces — agent console, customer portal, intake forms — over ICP-filed, in-country infrastructure in front of the Five9 stack you already run. On telecom our role is advisory: we hold no China telecom license. Settle the specifics with qualified counsel. Get a compliance assessment.

ARTICLES RELATED TO FIVE9

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.