Does MessageBird Work in China? PIPL Cross-Border, Recipient Data & Delivery Compliance
MessageBird — now Bird, an EU-based omnichannel CPaaS — routes SMS to mainland China, but every send hands an offshore service your recipients' phone numbers and message content: a PIPL cross-border transfer. China A2P SMS also needs a registered signature and pre-filed templates a foreign API can't file. A compliance-first look at the recipient-data and delivery-licensing exposure and the lawful in-country path.
Does MessageBird work in China?
MessageBird — now Bird — can route SMS to mainland China, but every send hands an offshore service your recipients' phone numbers and message content, and China A2P SMS runs through a licensed domestic regime a foreign API can't file into.
You upload a mainland recipient's phone number and the message body (an OTP, an order or account notice, a marketing blast) to Bird's offshore infrastructure — its live regions are eu1 and us1, with no mainland-China region — which makes it a PIPL cross-border transfer of the recipients' personal information (Articles 38–40; marketing adds the Article 13/23 consent and opt-out). Bird's own “SMS to China” page shows the second door: delivery requires a registered signature (短信签名), pre-filed and whitelisted templates (模板报备), and a local business license to register them — the licensed domestic A2P route a foreign API cannot satisfy directly, so it routes international SMS instead. The lawful lever is a licensed in-country delivery path plus consent and data minimization — not making the offshore API reachable.
This is a risk map, not a verdict — settle the specifics with counsel. On telecom and SMS licensing our role is advisory: 21YunBox does not hold a China telecom or SMS license. Our China team can map your exposure →
What MessageBird's own documentation says about China
| Fact | Primary source |
|---|---|
| Bird's own “SMS to China” page sets out a domestic A2P regime a foreign API cannot satisfy directly. It states that “All message content must include a registered 【Signature】 at the beginning of the message. Messages without a registered signature will fail to deliver,” that “Only companies with a local business license can register a signature,” that “All templates must be whitelisted before sending,” and that “Senders will automatically be replaced with a random numeric code starting with 106.” The registered signature (短信签名) and pre-filed templates (模板报备) are filed through the Chinese carriers — not set by an API call — so a foreign CPaaS routes international SMS rather than the licensed domestic route. | Bird (formerly MessageBird), “SMS to China” (bird.com), retrieved 2026-10-10 |
| Bird has no mainland-China region; recipient data and event logs stay in its EU or US region, offshore. Bird's API documentation states that only “us1 and eu1 are live today,” that “The workspace, API keys, messages, recipient data, and event logs remain in that region,” and that “They are never replicated across regions.” For a China audience that means every recipient phone number, message body, suppression entry, and delivery log is processed and stored outside the mainland — the cross-border transfer is structural, not incidental. | Bird, “Base URLs & regions” API docs (bird.com), retrieved 2026-10-10 |
| Sending to a China recipient is a PIPL cross-border transfer, and marketing needs its own consent. Uploading a mainland recipient's phone number and message content to an offshore service triggers PIPL Articles 38–40 — notice, a separate consent distinct from the service agreement, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). Commercial and marketing messages additionally require a lawful basis and consent (Articles 13 and 23) and must honor opt-out. | Personal Information Protection Law of the PRC, Articles 38–40 and 13/23 (cac.gov.cn), retrieved 2026-10-10 |
| Operating SMS for mainland users is a licensed value-added telecom activity a foreign API can't hold. Under China's Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42, in force September 1, 2017), running a value-added telecom business requires a Value-Added Telecommunications Business License (增值电信业务经营许可证); the licensed domestic SMS gateway and the signature/template filing sit with a local operator, and the China-facing app needs its own ICP filing. Where a CIIO or high-volume handler stores mainland personal information, data localization applies (Cybersecurity Law Article 39, formerly Article 37). | Measures for the Administration of Telecommunications Business Licensing, MIIT Order No. 42 (gov.cn), in force 2017-09-01 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question about MessageBird — rebranded Bird in early 2024, and run from the Netherlands as an EU-based omnichannel CPaaS — is not whether its API can be reached from inside the country. It is what happens the moment you hand that offshore service your China recipients’ phone numbers and the content you want delivered: an order confirmation, a password reset, a one-time passcode, a marketing blast. Two things follow, and neither is about speed. First, a recipient’s phone number and the message body are personal information, so sending them to Bird’s offshore infrastructure — its live regions are eu1 and us1, and there is no mainland-China region — is a cross-border transfer under PIPL. Second, delivering application-to-person SMS to Chinese numbers is a licensed, filed activity that a foreign API cannot satisfy directly — Bird’s own China page spells out the terms. The two legs are the recipients’ contact data crossing the border, and the delivery-licensing door.
MessageBird in China at a glance
| What decides it | In MessageBird's own terms — and China's law |
|---|---|
| What it is | MessageBird — rebranded Bird in early 2024 — is a Netherlands-based omnichannel CPaaS (SMS, WhatsApp, voice, and email). It is operated from outside the mainland; its live data regions are eu1 and us1, and there is no mainland-China region or China SMS/telecom entity you send as from inside the country. |
| What you hand it | A recipient's phone number and the message content — an OTP, an order or account notice, a marketing offer. Both are personal information. Sent to Bird's offshore infrastructure for delivery, that is a cross-border transfer under PIPL (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism; commercial messages add the Article 13/23 lawful-basis-and-consent and opt-out duty. |
| The delivery-licensing door (SMS) | China A2P SMS runs through the domestic carriers. Bird's own “SMS to China” page requires a registered signature (短信签名) at the start of every message and pre-filed, whitelisted templates (模板报备), states “Only companies with a local business license can register a signature,” replaces the sender with a numeric code starting with 106, and is one-way. Operating messaging for mainland users as a business needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) under the Measures for the Administration of Telecommunications Business Licensing — which a foreign API cannot hold or file into directly, so it routes international SMS instead. |
| Retention & residency | Suppression lists, delivery and open/click logs, and recipient data persist offshore in eu1/us1; omnichannel WhatsApp, voice, and email add more recipient PII. Where you are a CII operator or high-volume handler, mainland personal information must be stored in the mainland — the data-localization duty of the Cybersecurity Law Article 39 (formerly Article 37). |
| The lawful path | Route China-recipient messaging through a licensed in-country delivery path — for SMS, a licensed domestic SMS gateway carrying the registered signatures and pre-filed templates — minimize recipient PII, obtain marketing consent, keep a lawful cross-border basis, and ICP-file and deliver the app in-country. 21YunBox maps that path, localizes the China leg, and delivers the app; on telecom its role is advisory — we do not hold a China telecom or SMS license. |
What you actually hand it — your recipients’ phone numbers and message content
A transactional or notification message is never just a payload. Every send to a mainland recipient carries that person’s phone number and whatever the body reveals — a one-time passcode tied to a real account, an order or shipping confirmation, a balance or a finance notice, or a marketing offer. All of that is personal information, and with MessageBird (now Bird) it is processed and delivered from outside the mainland. Bird’s own API documentation is explicit about where that happens: its live data regions are eu1 and us1, and “The workspace, API keys, messages, recipient data, and event logs remain in that region,” where “They are never replicated across regions.” There is no mainland-China region. So the recipient’s number, the message content, the suppression list, and the delivery and open/click logs all live offshore — and because Bird is omnichannel, the same is true of any WhatsApp, voice, or email you route through it. Bird acts as your processor; the handler that carries the China-law duty is you.
It’s a cross-border transfer — and, for SMS, a licensing question
Put those two facts together and the picture is a regulatory one, on two legs. The first is data. Collecting a mainland user’s phone number and message content and sending it to a service operated offshore is a cross-border transfer of personal information under China’s Personal Information Protection Law (数据出境). PIPL puts the duty on the handler — you, the operator of the app, not only the vendor — and Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use the service, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. If any of the messaging is commercial, Articles 13 and 23 add a lawful-basis-and-consent requirement and a working opt-out. Where you are a critical information infrastructure operator or handle personal information above the state threshold, storage localizes in the mainland — the data-localization duty of the Cybersecurity Law Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged).
The second leg is delivery, and for SMS it is a licensing question before it is anything else. Application-to-person SMS to Chinese numbers does not run on a foreign route by right: it runs through the domestic carriers, and Bird’s own “SMS to China” page states the terms — “All message content must include a registered 【Signature】 at the beginning of the message. Messages without a registered signature will fail to deliver,” “All templates must be whitelisted before sending,” and “Only companies with a local business license can register a signature.” The registered signature (短信签名) and pre-filed templates (模板报备) are filed through the carriers; the sender name is replaced with a numeric code starting with 106, and messaging is one-way. Operating that messaging service for mainland users as a business is itself a licensed value-added telecom activity — a Value-Added Telecommunications Business License (增值电信业务经营许可证) under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) — which a foreign CPaaS cannot hold or file into directly. That is why a foreign API reaching Chinese numbers routes as international SMS, outside the compliant domestic A2P regime.
Reaching the API isn’t the question — a licensed in-country delivery path is
So the useful question is not “can Bird’s API push a text to Shanghai today?” It is whether your China-bound messaging rides a lawful channel and has a lawful basis to leave the country at all. For SMS that means a licensed domestic SMS gateway that already holds the telecom license and carries the registered signatures (短信签名) and pre-filed templates (模板报备) the carriers require; for the email side of an omnichannel setup it means a compliant, China-deliverable relay and the sending app’s own ICP filing. On top of either, it means minimizing the recipient PII you send, obtaining the Article 13/23 consent for marketing and honoring opt-out, and keeping a lawful cross-border basis for anything that still leaves. This is a localization of the China leg onto the licensed path — it is emphatically not a tunnel that ships the recipients’ data offshore anyway, and 21YunBox is advisory, not a licensee, on the telecom and SMS-licensing leg: the license and the carriage sit with a licensed domestic operator and your counsel. Whether and how each of these rules applies to your exact use case, volumes, and entity is a risk to settle with qualified counsel against what you actually ship.
The lawful path — map, localize, deliver
There is a lawful way to reach your users in China with SMS, OTPs, and notifications, and it has three moves. Map: inventory which messages go to China recipients, what contact data and content each one carries, where Bird processes and stores it (eu1/us1) and what it retains — suppression lists, delivery and event logs, message content — the consent basis for any marketing, and whether you are relying on an international route instead of the licensed domestic A2P regime. Localize / govern: route China-recipient messaging onto a licensed in-country delivery path — for SMS, a licensed domestic SMS gateway with registered signatures and pre-filed templates through the carriers — keep recipient PII minimized, obtain the consent marketing requires and honor opt-out, and hold a lawful cross-border basis for anything that still leaves; on the telecom and SMS-licensing leg our role is advisory, because 21YunBox does not hold or imply a China telecom or SMS license. Deliver: the app or site that triggers and manages the messaging is a public internet service with an ICP filing duty, and it needs compliant, in-country delivery — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild or migration. The result is a messaging flow that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Data Export Security Assessment Measures
- China’s Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42)
- How to get an ICP filing for China
