Does Mindee Work in China? PIPL Cross-Border, Data Residency & Sensitive-Data Rules
Mindee is a French-origin document-OCR API that processes documents only in EU and US data centers, with no mainland-China region. The passports, ID cards and invoices your China operation sends it to read ARE the personal information, often sensitive (ID and financial-account numbers under PIPL Article 28), so handling them offshore is a PIPL cross-border transfer of sensitive personal data. A compliance-first look at the residency, sensitive-data and cross-border exposure.
Does Mindee work in China?
The documents your China operation sends Mindee to read — invoices, receipts, and the sharp cases, passports, ID cards and bank statements — ARE the personal information, often its most sensitive kind (ID numbers, financial-account numbers), and Mindee processes them only in EU or US data centers with no mainland-China region, so handling them is a PIPL cross-border transfer of sensitive personal data.
Mindee is a French-origin document-OCR and intelligent-document-processing API; its own docs call the ID Card model "a critical component for use cases like identity verification, KYC, and onboarding." You cannot minimize an ID or passport number before you send it, because the identifier IS what you sent the document to read — and such identifiers are sensitive personal information under PIPL Article 28. Routing it to Mindee's EU or US zone is a cross-border transfer (Articles 38–40) needing the Article 29 separate consent, and an auto-approve/reject onboarding step engages Article 24. The lawful lever is to keep the document processing in-country, minimize, get the separate consent, and ICP-file any China-facing surface — not to make the offshore API reachable.
This is a risk map, not a verdict — your duties turn on what you process and your role. Our China team can map your exposure →
What Mindee's own documentation says about China
| Fact | Primary source |
|---|---|
| Mindee processes documents only in EU or US data centers — no mainland-China region. Its Data Processing Policies give a Processing Zone that "determines the geographic region where your document will be processed," offering only Europe — "Forces all data processing to occur exclusively within data centers located in Europe (EU)" — and the United States; left on default, "your data may be processed in Europe and in the United States." There is no China option and no customer-run, in-country edition of the hosted API, so documents from a China operation are processed offshore. | Mindee Docs — Data Processing Policies, retrieved 2026-10-11 |
| The content you send Mindee IS the personal information — often the most sensitive kind. Mindee's prebuilt models read invoices, receipts and financial documents, plus identity documents: its own docs say the International ID Card model "enables the automatic extraction of structured identity data from ID cards" and is "a critical component for use cases like identity verification, KYC, and onboarding," the Passport model "helps you parse structured passport data with accuracy," and there are Driver's License, Bank Statement and Bank Account Details models. The ID, passport and bank-account numbers it extracts cannot be minimized — they are the input. | Mindee Docs — Use cases overview, retrieved 2026-10-11 |
| ID numbers, financial-account numbers and biometrics are sensitive personal information under PIPL Article 28. Handling them requires a separate consent and a prior personal-information protection impact assessment (PIPL Articles 28–29), and Article 24 lets an individual refuse a decision made solely by automated means — relevant when a KYC or onboarding flow auto-decides an outcome from the extraction. Because the sensitive identifier IS the document's content, it cannot be minimized or anonymized before transfer. | PIPL Articles 28, 29 & 24 — 21YunBox gov-doc, retrieved 2026-10-11 |
| Processing China-collected documents in an EU or US region is a cross-border transfer the handler must legalize. PIPL Articles 38–40 require notice, a transfer mechanism (a CAC security assessment, the CAC standard contract, or certification) and the Article 29 separate consent for sensitive data; a CIIO or high-volume handler also owes in-country storage under Cybersecurity Law Article 39 (formerly Article 37). At volume, identity/financial data can be "important data," making a CAC data-export security assessment mandatory. | PIPL Articles 38–40 & CAC data-export assessment — 21YunBox gov-doc, retrieved 2026-10-11 |
Sources verified by the 21YunBox compliance team on 2026-10-11.
For a team running Mindee in mainland China, the instinct is to ask whether the API answers from Shanghai. That is not the China decision. Mindee is a document-OCR and intelligent-document-processing API — French-origin, built in Paris — and it works by you sending it the document to be read: an invoice, a receipt, and the sharp cases, a passport, an international ID card, a driver’s license, a bank statement. That content IS the personal information, and frequently its most sensitive kind — the ID numbers and financial-account numbers that PIPL Article 28 singles out. Mindee processes documents only in European or United States data centers, with no mainland-China region and no customer-run, in-country edition of the hosted API. So for a China operation the real prongs are these: the content is sensitive personal information that cannot be minimized; sending it offshore is a PIPL cross-border transfer that needs a separate, reinforced consent; an automated onboarding or KYC decision engages Article 24; and any China-facing upload or verification surface owes an ICP filing.
Mindee in China at a glance
| What decides it | In Mindee's own terms — and China's law |
|---|---|
| What you send it | Mindee reads the document you upload. Its prebuilt models cover invoices, receipts and financial documents, and — the sharp cases — the International ID Card, Passport, Driver's License, Bank Statement and Bank Account Details models. Mindee's own docs call the ID Card model "a critical component for use cases like identity verification, KYC, and onboarding." The content you send to be read IS the personal information — and an ID number, a passport number or a bank-account number is its most sensitive kind. |
| Where it runs | Offshore. Mindee's Processing Zone control routes documents to data centers in Europe (EU) or the United States; left on default, "your data may be processed in Europe and in the United States." There is no mainland-China region and no customer-run, in-country edition of the hosted API. So the documents your China operation sends are processed outside the mainland — a cross-border transfer (数据出境) of personal information under PIPL Articles 38–40, with a separate consent reinforced for sensitive data under Article 29. |
| The sensitive-PI door | This is the half most reviews miss. An ID-card number, a passport number and a bank-account number are sensitive personal information under PIPL Article 28 — which requires a separate consent and a prior personal-information protection impact assessment. You cannot minimize or anonymize them, because the identifier IS the thing you sent the document to read. A blank form template is not sensitive; a scanned passport or ID card is. |
| Automated decisions & residency | If your flow auto-approves or rejects an onboarding or KYC check from Mindee's extraction, that is automated decision-making under PIPL Article 24 (the individual may refuse a decision made solely by automated means). For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37 — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) sets an in-country storage duty an offshore region cannot meet. At volume, large quantities of ID and financial-document data can also raise the "important data" (重要数据) question and a mandatory CAC data-export security assessment. |
| Reachability is not the axis | Whether Mindee's endpoint answers quickly from the mainland is an operational matter, not the decision. The lawful path is to keep the China document processing in-country — an in-country / self-managed deployment where a vendor offers one, a China-resident processing path, or a China-legal domestic alternative — minimize what crosses the border, carry the Article 29 separate consent, and deliver any China-facing upload or verification surface under an ICP filing. 21YunBox maps the exposure, localizes the regulated data onto an in-country path, and delivers in-country. |
What you actually send it — and why the content is the risk
Mindee does not hold a database you populate; it reads a document you hand it and returns the fields as structured JSON. So the compliance surface is defined by what you send. Mindee’s prebuilt models span invoices, receipts and financial documents — and, the sharp edge, identity and financial documents: in Mindee’s own words, the International ID Card model “enables the automatic extraction of structured identity data from ID cards” and is “a critical component for use cases like identity verification, KYC, and onboarding”; the Passport model “helps you parse structured passport data with accuracy” for a “Know Your Customer (KYC) process, onboarding flow, or document verification pipeline”; and there are Driver’s License, Bank Statement and Bank Account Details models too.
That matters because the content you upload to be read IS the personal information — and for identity and financial documents it is the most sensitive kind. A passport number, an ID-card number and a bank-account number are not metadata around the request; they are the request. Where does that content get processed? Mindee’s Data Processing Policies give you a Processing Zone setting that “determines the geographic region where your document will be processed,” and the only regions it offers are Europe (EU) and the United States; the default “may be processed in Europe and in the United States.” None is in mainland China, and Mindee ships no customer-run, in-country edition of the hosted API, so for a China operation the documents are read offshore. Routing between Mindee’s EU and US zones only relocates the transfer — it does not bring the processing onshore.
The doors: sensitive personal data, cross-border transfer, and automated decisions
Once China-collected documents are processed abroad, several bodies of Chinese law decide whether that was allowed — and for identity and financial documents they open at once.
Sensitive personal information — the distinctive door. The ID numbers, passport numbers and financial-account numbers Mindee extracts are sensitive personal information under PIPL Article 28, which requires a separate consent and a prior personal-information protection impact assessment before you handle them. The usual “minimize or de-identify before you transfer” escape does not apply here, because the sensitive identifier IS the input — you sent the document precisely to read it. Whether a given document is sensitive depends on what it is: a scanned passport or ID card is; a blank form is not.
Cross-border transfer and separate consent. Sending China-collected documents to a service processing them in the EU or the US is a cross-border transfer (数据出境) under PIPL. The law puts the duty on the handler — your China entity, not Mindee the processor: Articles 38–40 require notice, a transfer mechanism (a CAC security assessment, the CAC standard contract, or certification), and a separate consent that Article 29 reinforces for the sensitive data, on top of the Article 13/23 basis for collecting it at all.
Automated decisions, residency, and important data. If your onboarding or KYC flow decides an outcome solely from Mindee’s extraction — approve, reject, flag — that is automated decision-making under PIPL Article 24, and the individual may refuse a decision made only by automated means. For a critical information infrastructure operator or a high-volume handler, Cybersecurity Law Article 39 (formerly Article 37) imposes an in-country storage duty an offshore region cannot satisfy. And at scale, high volumes of identity and financial-document data can raise the “important data” (重要数据) question under the Data Security Law, which makes a CAC data-export security assessment mandatory before anything leaves — regardless of personal-information volume. Which of these applies turns on what you process and your role; it is a risk to assess, not a foregone conclusion.
Calling the API isn’t the question — compliant in-country processing is
Notice what is not on that list: how quickly Mindee returns a parsed invoice from Shanghai, or how to force a smoother connection to its offshore endpoint. Those are operational questions, and chasing them misses the decision. The decision is whether the documents your China operation sends Mindee — which ARE the personal information, often sensitive — are allowed to be processed where Mindee processes them, and under what consent and transfer basis.
For an API with no mainland-China region, the lawful move is not to make the offshore endpoint reachable — it is to keep the China document processing on an in-country footing. You keep Mindee as your global document-processing layer, and for the China entity you keep the regulated documents on a China-resident processing path — an in-country / self-managed deployment where one exists, or a China-legal domestic alternative for the sensitive flows — minimize what crosses the border, carry the Article 29 separate consent for the sensitive identifiers, and handle any Article 24 automated-decision and important-data duty. Localizing means keeping the processing on an in-country path — never a tunnel that quietly ships the documents offshore anyway. Any China-facing surface the flow powers — a document-upload page, a KYC or verification step, a customer onboarding form — is a public service in the mainland and carries an ICP filing duty, delivered compliantly and in-country.
None of this is a verdict that Mindee is “blocked” or “illegal.” It is a risk map: whether a given document or image is sensitive or “important data” turns on what you process and your sector, and whether you owe separate consent, a transfer mechanism, in-country storage, an important-data classification and data-export assessment, an ICP filing, or some combination depends on your entity, your data volumes and your role under Chinese law — specifics to settle with counsel before your China operation depends on them.
The lawful path — map, localize, deliver
There is a compliant way to run a document-processing API for a China operation, and it has a shape.
First, map: our China team inventories what your China entity sends Mindee — the invoices, receipts and financial documents, and the identity documents (passports, ID cards, driver’s licenses, bank statements) — flags which of it is sensitive personal information (ID numbers, financial-account numbers), records where it is processed (an EU or US Mindee zone, since there is no mainland-China region), whether any of it is “important data,” and whether your flow makes an automated decision under Article 24. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we help you keep the China document processing in-country — a China-resident processing path or a China-legal domestic alternative for the sensitive and identity-document flows, with what crosses the border minimized, the Article 13/23 notice-and-consent and the Article 29 separate consent for sensitive data in place, and any Article 24 and important-data duty handled — while Mindee stays your global document layer everywhere else. Localizing means keeping the processing on an in-country path, never moving the documents offshore by stealth.
Then deliver: the China-facing surfaces the flow powers — a document-upload page, a KYC or verification step, an onboarding form — carry an ICP filing (备案) duty and need compliant, in-country delivery. 21YunBox delivers them in-country — the 21YunBox Optimizer — in front of what you already run, with no rebuild and no re-platform, so the service runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. We are a compliance overlay and partner to the stack you already run, not a competitor to it.
Related reading:
- China’s Personal Information Protection Law (PIPL)
- Cross-border data transfers under PIPL
- China’s data-export security assessment (CAC)
- How to get an ICP filing for China
