Does Kafka / Confluent Work in China? Confluent Cloud Regions, Self-Hosted Kafka & Data Residency
Apache Kafka is open-source software you can self-host anywhere, including inside mainland China; Confluent Cloud is managed Kafka with no mainland-China region. So the deciding question isn't speed — it's data residency: streaming China-collected personal or important data through an offshore Confluent Cloud cluster is a cross-border transfer under PIPL, with a CAC security assessment and CSL in-country storage (Article 39, formerly Article 37) for important data and CIIOs. A compliance-first look at the data door — and the self-hosted, in-country path.
Does Apache Kafka / Confluent work in China?
Whether Kafka works in China depends on which “Kafka” you mean — and it is a data-residency question, not a speed one. Apache Kafka is open-source event-streaming software you can self-host anywhere, including inside mainland China; Confluent Cloud is Confluent's fully managed Kafka service, and by its own documentation it runs only in AWS, Azure, and Google Cloud regions — none inside mainland China.
So if you stream data you collect from users in China through a Confluent Cloud cluster in an offshore region (the nearest being Hong Kong, Taiwan, Tokyo, Seoul or Singapore), the personal — and sometimes important — data riding through those topics comes to rest abroad. That is a cross-border transfer (数据出境) PIPL governs: notice, a separate consent, and a transfer mechanism, with a CAC security assessment for important data, large volumes, or a CIIO. For a CIIO or important data, the Cybersecurity Law's in-country storage duty (Article 39, formerly Article 37) keeps that data on the mainland — which no offshore cluster can meet.
The data-resident path is the open-source one: self-host Apache Kafka (or a China-resident managed Kafka) inside China, keep the streams in-country, and deliver the China-facing app in-country on ICP-filed infrastructure. This is a risk map, not a verdict — your obligations turn on your data, your volumes and your role, so confirm them with counsel. Our China team can map your Kafka data exposure with you →
What Apache Kafka / Confluent's own documentation says about China
| Fact | Primary source |
|---|---|
| Confluent Cloud is a fully managed service with no mainland-China region. Confluent describes Confluent Cloud as “a fully managed, cloud-native service for Apache Kafka®,” and its Cloud documentation states it “runs on AWS, Azure, and Google Cloud, including AWS GovCloud and Jio Cloud regions.” Those region tables list Asia-Pacific sites — Hong Kong, Taiwan, Tokyo, Osaka, Seoul, Singapore, Jakarta, Mumbai and Sydney — but none inside mainland China, the nearest being Hong Kong and Taiwan. | Confluent Documentation, “Cloud Providers and Regions for Confluent Cloud,” and Confluent, “Confluent Cloud, a Fully Managed Apache Kafka® Service” (docs.confluent.io / confluent.io), retrieved 2026-10-08 |
| Apache Kafka is open-source software you run yourself. The Apache Software Foundation describes it as “an open-source distributed event streaming platform.” Because you deploy and operate the brokers, you can run Apache Kafka anywhere — including on infrastructure inside mainland China — which is the path that keeps event data on Chinese soil. | Apache Kafka, Apache Software Foundation (kafka.apache.org), retrieved 2026-10-08 |
| Streaming China-collected personal data offshore is a PIPL cross-border transfer. Sending personal information collected from users in China to a cluster outside the mainland triggers PIPL Articles 38–40: notice, a separate consent distinct from ordinary use, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. The duty is the personal-information handler's — yours, the Confluent customer, not the Kafka vendor's. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-08 |
| Important data and CIIO data must stay in the mainland. Under the Cybersecurity Law, personal information and important data collected by a critical information infrastructure operator in China must be stored in the mainland — Article 39 (formerly Article 37, renumbered by the 2025 amendment effective 2026-01-01) — and any outbound transfer of important data requires a CAC security assessment under the Measures for the Security Assessment of Outbound Data Transfers. An offshore Confluent Cloud cluster cannot meet an in-mainland storage duty. | Cybersecurity Law of the PRC, Art. 39 (formerly Art. 37); Measures for the Security Assessment of Outbound Data Transfers (cac.gov.cn), retrieved 2026-10-08 |
| The exposure scales with volume and role. Under the CAC's March 2024 Regulations on Promoting and Regulating Cross-border Data Flows, a non-CIIO transferring fewer than 100,000 individuals' non-sensitive personal information in a calendar year is exempt from the security assessment, the standard contract and certification — while exporting important data, or any export by a CIIO, still requires the CAC security assessment. | CAC — Regulations on Promoting and Regulating Cross-border Data Flows, March 2024 (gov.cn), retrieved 2026-10-08 |
Sources verified by the 21YunBox compliance team on 2026-10-08.
“Does Kafka work in China?” has two answers, because “Kafka” names two different things. Apache Kafka is open-source event-streaming software you run yourself — and you can run it anywhere, including on servers inside mainland China. Confluent Cloud is Confluent’s fully managed Kafka service, and it runs only in the AWS, Azure, and Google Cloud regions Confluent offers — none of which is in mainland China. So the deciding question is not whether a broker is reachable or how fast a message streams; it is where the data riding through your topics is allowed to come to rest. For a China-facing product that is a data-residency question — 数据出境 — and which of the two you run settles it.
Apache Kafka / Confluent in China at a glance
| What decides it | In Apache's and Confluent's own terms — and China's law |
|---|---|
| What you're actually running | Apache Kafka is open-source software you host yourself — “an open-source distributed event streaming platform” — and you can run it anywhere, including inside mainland China. Confluent Cloud is Confluent's “fully managed, cloud-native service for Apache Kafka®,” consumed from the regions Confluent offers. |
| Where Confluent Cloud puts your data | By Confluent's docs, Confluent Cloud “runs on AWS, Azure, and Google Cloud,” across US, European and Asia-Pacific regions — Hong Kong, Taiwan, Tokyo, Osaka, Seoul, Singapore, Jakarta, Mumbai, Sydney — with no region inside mainland China. The nearest are Hong Kong and Taiwan. |
| The cross-border transfer | Personal — and sometimes important — data your app streams from users in China lands in that offshore cluster. That is a cross-border transfer (数据出境) PIPL governs, and the handler is you, the Confluent customer, not Confluent. |
| Important data & residency | Carry important data, or operate as a CIIO, and the data must be stored in the mainland (Cybersecurity Law Article 39, formerly Article 37), with any export cleared through a CAC security assessment — duties no Confluent Cloud region can meet. |
| The data-resident path | Self-host Apache Kafka (or a China-resident managed Kafka) inside China so the streams stay in-country, and deliver the China-facing app in-country on ICP-filed infrastructure. No region toggle on a managed cloud substitutes for this. |
Apache Kafka vs Confluent Cloud: which one you run is the whole question
The two are easy to blur and important to separate. Apache Kafka is, in the Apache Software Foundation’s words, “an open-source distributed event streaming platform” — software you download, deploy, and operate on infrastructure you choose. Nothing about it forces your data offshore; run the brokers on servers inside mainland China and the event data stays on Chinese soil.
Confluent Cloud is the opposite trade. Confluent markets it as “a fully managed, cloud-native service for Apache Kafka®” — you do not place it on your own servers; you consume it from the regions Confluent runs. By Confluent’s own Cloud documentation, “Confluent Cloud runs on AWS, Azure, and Google Cloud,” and its published region tables cover the United States, Europe, and Asia-Pacific sites such as Hong Kong, Taiwan, Tokyo, Osaka, Seoul, Singapore, Jakarta, Mumbai and Sydney — but not one region inside mainland China. So the moment a China-facing app streams through Confluent Cloud, the data in those topics comes to rest in an offshore region. That, not latency, is what China’s data law responds to.
Stream China data through an offshore cluster and it crosses the border
The records flowing through your topics are rarely anonymous. Event streams carry sign-ups, orders, clickstreams, payments, and device and location signals — personal information under China’s law, and sometimes important data as well. When those streams are produced by users in mainland China and land in a Confluent Cloud cluster in an offshore region, that is a cross-border transfer of personal information that China’s Personal Information Protection Law governs. PIPL puts the duty on the personal-information handler — you, the Confluent customer, not Confluent — and asks for notice, a separate consent for the transfer distinct from ordinary use, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. Where the data includes important data or crosses volume lines, the Measures for the Security Assessment of Outbound Data Transfers make the CAC security assessment the mandatory route. Running on Confluent Cloud settles none of that; reaching a cluster and being cleared to move Chinese users’ data to it are different questions.
How much is at stake — volume, role, and important data
The weight of these duties is not uniform. Under the CAC’s March 2024 Regulations on Promoting and Regulating Cross-border Data Flows, a handler that is not a critical information infrastructure operator and moves fewer than 100,000 individuals’ non-sensitive personal information in a calendar year is exempt from the security assessment, the standard contract and certification — a genuinely lighter path for a small app.
At the other end sit two cases Confluent Cloud structurally cannot serve. If your streams carry important data, or if you are a critical information infrastructure operator, China’s Cybersecurity Law requires that personal information and important data collected in the mainland be stored in the mainland — Article 39 (formerly Article 37, renumbered by the 2025 amendment that took effect January 1, 2026) — and any outbound transfer runs through the CAC security assessment. No Confluent Cloud region can meet an in-mainland storage duty, because none of them sits in China. Whether your streams reach these tiers is a risk to confirm with counsel against the data you actually move.
The data-resident path: keep the streams on Chinese soil
Here the open-source half of the story is the answer. Because Apache Kafka is software you operate yourself, you can run it inside mainland China — self-hosted on in-country infrastructure, or on a China-resident managed Kafka offering operated by a local provider — so the topics that carry Chinese users’ data never leave the mainland. The streaming stays identical; what changes is where the brokers and the data live. For the strictest cases — important data, or a CIIO’s data — that in-country footing is not an optimization, it is the condition for being allowed to run at all. And the China-facing app that produces and consumes those streams is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery like any other China-facing property.
Where 21YunBox fits — map the obligation, localize the data, deliver in-country
You keep building on Kafka; nothing about your architecture has to change shape. Our China team works on three fronts. We map your cross-border and data-residency obligations — which of PIPL’s mechanisms you owe, whether your streams carry important data, and whether your role pulls you into the CIIO tier. We localize the data itself: where the law requires Chinese users’ records to stay on the mainland, we help you run a self-hosted Apache Kafka deployment, or a China-resident managed Kafka, inside China, so the streams never leave. And we deliver the China-facing app that produces and consumes those streams in-country, on ICP-filed infrastructure standing in front of the origin you already run — the 21YunBox Optimizer — with no rebuild and no second codebase. The result is a streaming stack whose China data sits on Chinese soil and whose app is delivered lawfully in the mainland. This is a risk map, not a verdict: your exact duties turn on your data, your volumes and your role, so settle them with counsel before you build.
Related reading:
- Measures for the Security Assessment of Outbound Data Transfers
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization and Article 39
