Does LiveKit Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
Your users' live audio and video, any recordings (the speaker's voiceprint and face — sensitive biometric data) and their identifiers ride LiveKit's infrastructure, which has no mainland-China region; providing real-time comms in China needs a value-added telecom license a foreign API can't hold, and the app needs an ICP filing — a compliance-first look at the telecom-licensing, residency and cross-border exposure.
Does LiveKit work in China?
Your China users' live audio and video, any recordings (voiceprint and face — sensitive biometric data) and their identifiers ride LiveKit's media infrastructure, and providing real-time communications in China is a value-added telecom business a foreign API provider can't license — so the question is compliance risk, not whether the SDK connects.
LiveKit's open-source WebRTC SFU moves participants' live media, and its Egress service can record a participant's audio and video — a voiceprint and face that PIPL Article 28 treats as sensitive biometric personal information that cannot be anonymized. Managed LiveKit Cloud runs in US, EU, Asia-Pacific and India regions with none in mainland China, so carrying your China participants' streams and recordings there is a PIPL cross-border transfer under Articles 38–40. Because the LiveKit server is Apache-2.0 licensed and self-hostable, the lawful lever is to run the media server in-country so the media and recordings stay on the mainland, route the real-time service through a licensed in-country operator, obtain the Article 28/29 consent for recordings, and ICP-file the app — not to make an offshore endpoint reachable (21YunBox is advisory on telecom licensing).
This is a risk map, not a verdict — your duties turn on your data volumes and role, so settle the specifics with counsel. Our China team can map your exposure →
What LiveKit's own documentation says about China
| Fact | Primary source |
|---|---|
| LiveKit's media server is open-source and self-hostable. LiveKit's own repository states that "LiveKit server is licensed under Apache License v2.0" and lists it as "Easy to deploy: single binary, Docker or Kubernetes." It is a "scalable, distributed WebRTC SFU" that moves participants' realtime audio and video — so you can run the media server on infrastructure you control inside China, keeping your China participants' media and recordings on the mainland. | LiveKit server README — github.com/livekit/livekit, retrieved 2026-10-10 |
| Managed LiveKit Cloud has no mainland-China region, and its Egress service records participant audio and video. LiveKit Cloud's realtime regions cover the US, EU (France, Germany), Asia-Pacific (Japan, Singapore), India, the Middle East, Australia and Brazil — none inside mainland China — and its docs state "The project data region determines where LiveKit Cloud stores and processes your project data." Its Egress service can "Record a participant's audio and video tracks," capturing the speaker's voiceprint and face. | LiveKit Docs — Region pinning, Data residency and Egress overview, retrieved 2026-10-10 |
| A recording is sensitive biometric personal information, and carrying it offshore is a cross-border transfer. A voice recording is the speaker's voiceprint and the video is their face, which PIPL Article 28 classifies as sensitive personal information requiring separate, specific consent (Article 29) and a prior impact assessment — and biometrics cannot be anonymized away. Routing China participants' media and recordings to an offshore region is a cross-border transfer under PIPL Articles 38–40 for which you, the handler, must give notice, obtain separate consent and clear a transfer mechanism. | PIPL Articles 28, 29 and 38–40 (CAC), retrieved 2026-10-10 |
| Providing real-time communications in China is a licensed telecom business, and the app itself needs an ICP filing. Offering a real-time voice or video capability to users in China is a value-added telecommunications business (增值电信业务) requiring an MIIT license a foreign API provider cannot hold directly, so the lawful route runs the service through a licensed in-country operator. A CIIO or high-volume handler must also store China-collected personal information on the mainland under Cybersecurity Law Article 39 (formerly Article 37), and the China-facing app carries an ICP filing duty. | PRC value-added telecom licensing (MIIT); Cybersecurity Law Article 39 (formerly Article 37), 2025 amendment in force 2026-01-01 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question to settle about LiveKit is not whether its SDK can connect or whether a room will join — it is where your participants’ live media lives, who may lawfully provide real-time communications in China, and whether the app that embeds it is filed. LiveKit is an open-source WebRTC SFU: it moves participants’ realtime audio, video and data, and its Egress service can record a participant’s audio and video. That live media is participant personal information, and a recording is the speaker’s voiceprint and the participants’ faces — sensitive biometric data under PIPL Article 28. The answer turns on which form you run: managed LiveKit Cloud, whose regions sit offshore with none in mainland China, or the Apache-2.0 server you self-host. Four prongs decide it: value-added telecom licensing, media and recording residency, a cross-border transfer of participant personal information, and in-country storage for a CIIO or high-volume handler.
LiveKit in China at a glance
| What decides it | In LiveKit's own terms — and China's law |
|---|---|
| What you carry | LiveKit is a WebRTC SFU: it moves participants' live audio, video and data, and its Egress service can record a participant's audio and video. That live media is participant personal information, and a recording is the speaker's voiceprint and the participants' faces — sensitive biometric personal information under PIPL Article 28 that you cannot anonymize away. |
| Where the media runs | Managed LiveKit Cloud's realtime regions span the US, EU, Asia-Pacific (Japan, Singapore), India and more — none in mainland China. Carrying your China participants' streams and recordings there is a cross-border transfer (数据出境) under PIPL Articles 38–40. The LiveKit server is Apache-2.0 and self-hostable, so you can instead run it in-country. |
| The telecom-licensing door | Providing a real-time voice or video communication capability to users in China is a value-added telecommunications business (增值电信业务) that needs an MIIT license a foreign API provider cannot hold directly. The lawful route runs the real-time service through a licensed in-country operator (21YunBox is advisory here and holds no telecom license). |
| Recording consent and residency | A biometric recording needs a separate, specific consent (PIPL Article 29) and a prior impact assessment. For a CIIO or high-volume handler, China-collected personal information must be stored on the mainland — PIPL Article 40 with Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, the substance unchanged. |
| Reachability is not the axis | Whether the SDK connects was never the question. The lever is to keep the media and recordings in-country — self-host the open-source server inside China — route the real-time service through a licensed in-country operator, obtain the Article 28/29 consent, and carry the ICP filing on the app in front. |
What you actually carry — live media, recordings and identifiers
LiveKit is a WebRTC SFU: it moves participants’ realtime audio, video and data between people and, increasingly, AI models. The useful way to see the compliance exposure is to look at what rides it. First, the live streams themselves — the audio and video of identifiable people. Second, the identifiers and session metadata: who joined which room, when, and from where. Third, any chat or data messages sent in the session. And fourth, through LiveKit’s Egress service, any recording or transcript written to a file. Every one of those describes identifiable people, and when those people are in China, that is their personal information — in motion for the live session, and at rest for anything you record.
Two very different forms wear the LiveKit name, and the compliance answer depends on which you run:
- The managed LiveKit Cloud — media and project data are served and stored in the regions LiveKit operates. Its own documentation states that “The project data region determines where LiveKit Cloud stores and processes your project data,” and its realtime regions include the US, the EU, Japan, Singapore and India, with none inside mainland China. Run a China-facing session there and the streams, identifiers and recordings are processed and stored offshore.
- The open-source server — the LiveKit server is Apache-2.0 licensed and, in its own words, “Easy to deploy: single binary, Docker or Kubernetes.” You run it on infrastructure you choose, including your own servers inside China, so the media need never leave the country.
The recording is the part that raises the sensitivity bar. LiveKit Egress can “Record a participant’s audio and video tracks,” and that capture is the speaker’s voiceprint and the participants’ faces — biometric identifiers, not ordinary content. Separately, where you add LiveKit’s Agents framework for live transcription, translation or moderation, AI features that score or decide per participant bring PIPL Article 24 automated-decision duties into scope, and carrying user-generated audio, video and chat brings content-moderation duties with it. The honest clarification about the axis: LiveKit itself is realtime media infrastructure; the AI arrives through the Agents framework you choose to add, and you name those duties only where you ship those features.
Three doors: a telecom license, cross-border media, and recording consent
A telecom license a foreign API can’t hold. Providing a real-time voice, video or messaging communication capability to users in China is a value-added telecommunications business (增值电信业务) that requires a value-added telecom license (增值电信业务经营许可证) from the MIIT — one a foreign API provider cannot hold directly under China’s foreign-investment telecom rules. Neither the open-source project nor the managed LiveKit Cloud holds that license. The lawful route is to run the real-time service through a licensed in-country operator; 21YunBox is advisory on this leg and holds no telecom license.
A cross-border transfer of participant data. Carry your China participants’ live streams, identifiers, chat and call metadata to offshore media servers and you have built a cross-border transfer of personal information (数据出境), and the duty sits on you as the handler, not on the vendor. PIPL Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use the feature, and one lawful transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
Separate consent for a biometric recording, and residency. Any recording or transcript LiveKit Egress produces captures the speaker’s voiceprint and the participants’ faces — sensitive biometric personal information under PIPL Article 28, which demands a separate, specific consent (Article 29) and a prior personal-information protection impact assessment, and which — being biometric — you cannot anonymize away. Underneath consent sits residency: a critical information infrastructure operator or a large-volume handler must store China-collected personal information inside the mainland — PIPL Article 40 together with Cybersecurity Law Article 39 (formerly Article 37) — a duty an offshore region structurally cannot meet.
Reaching the endpoint isn’t the question — a compliant in-country real-time path is
Whether a room joins from Shanghai is not the decision. The exposure is that your China participants’ live media, their recordings (biometric) and their identifiers are processed and stored on infrastructure that has no mainland-China region, provided by a party that cannot hold the China telecom license. For LiveKit the honest answer has a better shape than most real-time APIs can offer, because the server is open.
The strongest lever is to self-host the open-source LiveKit server on infrastructure you run inside China, so the media and recordings never cross the border and residency is satisfied by design; route the real-time service itself through a licensed in-country operator so the telecom-licensing door is answered; obtain the Article 28/29 consent for recordings; and minimize what you capture and keep. What this is not is an arrangement that carries a China participant’s media to an offshore server anyway while presenting it as local — keeping the media on a genuine in-country path is the whole point.
This page is a risk map, not a verdict: whether a localization duty binds you, which cross-border mechanism fits, and how a licensed-operator arrangement is structured turn on your entity, your data volumes and whose data it is — settle the specifics with counsel before you build.
The lawful path — map, localize, deliver
21YunBox is a compliant overlay around the stack you already run — advisory on the telecom-licensing leg, a partner to LiveKit, not a competitor. The work has three parts. Map: inventory the live media, recordings and transcripts, participant identifiers, chat and session metadata the API carries, where it is processed and stored (an offshore region, with no mainland-China option on the managed service), whether any Agents AI features score participants (Article 24), and the consent basis you rely on (Article 28/29 for recordings). Localize: keep your China participants’ media and recordings in-country — self-host the open-source LiveKit server on mainland infrastructure — route the real-time service through a licensed in-country operator, minimize and pseudonymize, obtain the Article 28/29 and Article 13/23 consent, and moderate user-generated content; localization means keeping the media on an in-country path, never shipping it offshore and back. Deliver: the app that embeds the SDK is a public service that carries an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer — set in front of the stack you already run, with no rebuild and no second codebase. 21YunBox never uses or suggests circumvention of any kind. The result is a real-time communication feature that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — Article 39 (formerly Article 37) and data localization
- China’s Personal Information Protection Law (PIPL) explained
- How to get an ICP filing for China
