Does Onfido Work in China? Identity-Verification Data Residency, PIPL Sensitive PI & ICP
Onfido — now part of Entrust — runs its identity-verification cloud only in offshore regions (EU, US and Canada), with no mainland-China site, so the question isn't speed. The government-ID images and facial biometrics it captures to verify your China users are sensitive personal information under PIPL, and holding them offshore is a cross-border transfer with a stricter separate-consent and data-export burden, plus an in-country storage duty for a CIIO or large-volume handler and no footing for an ICP filing. A compliance-first look at the sensitive-PI residency, cross-border and ICP exposure, and the lawful in-country path.
Does Onfido work in China?
The question isn't speed. Onfido's checks run inside your own onboarding flow and generally reach China — but the government-ID images and facial biometrics it captures to verify your users are sensitive personal information under PIPL, and Onfido keeps them only in offshore regions.
Onfido — now part of Entrust — offers just three "region-specific environments: EU, US, and Canada," with no mainland-China site, so every ID scan and face match collected from a Chinese user is held offshore. Because that data is sensitive, China's law is stricter: a separate, specific consent and a demonstrated necessity to process it (PIPL Articles 28–30), then a further consent and a transfer mechanism to send it abroad — a cross-border transfer PIPL governs (Articles 38–40), with a data-export security assessment likelier to apply, an in-country storage duty for a CIIO or large-volume handler (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), and no mainland resource to attach an ICP filing to. The table below is Onfido's own wording and the rule each line triggers.
This is a risk map, not a verdict — what you owe turns on your entity, the identity data you collect, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →
What Onfido's own documentation says about China
| Fact | Primary source |
|---|---|
| Onfido is now part of Entrust — and it verifies users with exactly the data China treats as most sensitive. Entrust completed its acquisition of Onfido in 2024, and the product's own API documentation now notes that "following the acquisition, Onfido is now known as Entrust." The service reads a government-ID document and matches it to a facial biometric from a selfie or liveness scan — ID and biometric data that is sensitive personal information under PIPL (Article 28), carrying a stricter separate-consent and necessity standard before the cross-border question is even reached. | Onfido (now part of Entrust) API documentation — v3 to v3.6 migration guide, retrieved 2026-10-09; PIPL Article 28 |
| Onfido hosts identity-verification data only in EU, US and Canada — never mainland China. Its own API documentation states, "We offer region-specific environments: EU, US, and Canada," each with its own base URL, and that "for the EU region, data is physically stored in the Republic of Ireland, with backup storage in Germany." There is no mainland-China region on offer, so the ID images and face scans collected from your Chinese users rest offshore, and there is no in-country resource to attach an ICP filing to. | Onfido (now part of Entrust) API Reference — Regions, retrieved 2026-10-09 |
| Holding that data offshore is a cross-border transfer of sensitive personal information. When ID and biometric data collected in China lands in an EU, US or Canada region, PIPL treats it as a cross-border transfer and puts the duty on you, the handler, not on Onfido: notice, a separate consent for the transfer, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (Articles 38–40) — with a data-export security assessment likelier to bite because the data is sensitive. | PIPL Articles 28–30 and 38–40, retrieved 2026-10-09 |
| For some handlers the data must stay in China — and serving onboarding from inside the mainland triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore region cannot satisfy. And any China-facing sign-up or verification page actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Onfido does not provide. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a company onboarding customers or verifying users in mainland China, the first instinct with Onfido is to ask whether its identity checks will run from inside the country. They generally will — Onfido’s verification is an API and SDK embedded in your own onboarding flow, not a consumer destination that China blocks at the border. So reachability is not where the China decision is settled. What settles it is the nature of the data Onfido collects to do its job, and where that data comes to rest. A passport or ID-card image and a live selfie or liveness scan are about as sensitive as personal information gets under China’s law, and Onfido keeps them in regions outside the mainland. That is a sensitive-personal-information, cross-border and data-residency question — and it sits upstream of latency. Onfido answers the residency half in its own documentation.
Onfido — now part of Entrust, which completed its acquisition in 2024 — runs no identity-verification cloud inside mainland China. Its own API documentation offers three region-specific environments, EU, US and Canada, and names no mainland-China site to choose. The moment a government-ID image, a facial biometric or a verification result collected from a person in China lands in one of those regions, you have made a cross-border transfer (数据出境) of personal information — and because that data is sensitive, a stricter branch of China’s law decides whether you were allowed to move it at all.
Onfido in China at a glance
| What decides it | In Onfido's own terms — and China's law |
|---|---|
| What it is | Onfido (now part of Entrust) is an identity-verification / KYC platform: it reads a government-ID document and matches it to a live selfie or biometric face scan to onboard and verify users. The records it creates — ID images, facial biometrics, extracted identity fields and verification results — are personal information about identifiable people, and the biometric and ID data are sensitive personal information. |
| Is it reachable from the mainland? | Generally, yes. Onfido's verification runs as an API and SDK inside your own onboarding flow, not as a destination blocked at the border, so reachability is not the China question. (Cross-border verification calls from the mainland to an offshore endpoint can be inconsistent — an operational matter, below, not the decision.) |
| Where does the identity data sit? | Offshore. Onfido's own API documentation states, “We offer region-specific environments: EU, US, and Canada,” each with its own base URL, and that “for the EU region, data is physically stored in the Republic of Ireland, with backup storage in Germany.” There is no mainland-China region to choose. |
| What kind of data is it? | Government-ID images and facial/biometric scans. Under PIPL (Article 28) biometric characteristics and data revealing a specific identity are sensitive personal information, which carries a stricter standard: a separate, specific consent and a demonstrated necessity (Articles 29–30) before you even reach the cross-border question. |
| Collecting China identity data into it | Holding China-collected ID and biometric data in an offshore region is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent for the transfer, and one transfer mechanism; a data-export security assessment may apply above thresholds, and is likelier to bite because the data is sensitive. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet. |
| Serving the public | A China-facing sign-up, onboarding or verification page actually served to mainland visitors from inside China needs an ICP filing bound to a mainland hosting resource. Onfido names no mainland region, so there is nothing of its own to file against. |
| The lawful path | Keep China-collected ID and biometric data in-country on a consented, in-country verification route — captured, processed and stored in the mainland — and deliver the China-facing onboarding surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind. |
Availability: reachable — but where does the identity data come to rest?
Onfido’s position is set in its own documentation, not by a load-time test. Its API documentation lists three “region-specific environments: EU, US, and Canada,” each with its own base URL and token, notes that “there is no default region” so you must pick one, and states that “for the EU region, data is physically stored in the Republic of Ireland, with backup storage in Germany.” Not one of the three is inside the mainland. So “can the onboarding SDK reach Onfido from Shenzhen?” is the wrong test. It reaches. The real question is where the ID images and face scans you collect in China come to rest, and whether they were allowed to leave the country at all — which is why this page publishes no first-party China latency figure for Onfido: speed is not the axis for a decision that turns on sensitive-data residency and consent.
One operational note worth naming: cross-border verification calls from the mainland to an offshore endpoint can be inconsistent, and the temptation is to force them through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. The productive question is how to keep the China identity data on a lawful footing in the first place.
The data-residency question: an offshore KYC store is a cross-border transfer
Here is the gate most teams miss. A region in the EU, the US or Canada is, by definition, outside the mainland. The government-ID images, facial biometrics, extracted identity fields and verification results Onfido holds for your users in China are personal information, and loading them into an offshore region is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization running the onboarding, not Onfido the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your service, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.
Above certain thresholds, or where the data qualifies as “important data,” that transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves — and because ID and biometric data is sensitive, those thresholds are reached sooner. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires personal information generated in China to be stored in China — an in-country storage duty an offshore region in Ireland, Virginia or Montreal simply cannot satisfy. None of this turns on how quickly a check completes; it turns on whether the data had a lawful basis to be there. Which of these bite your specific deployment is a risk to confirm with counsel against what your verification flow actually collects.
ID documents and face scans are sensitive personal information — consent sits on top
Residency is only half of it, and for identity verification the other half is sharper than for most tools. Onfido works by capturing exactly the categories China’s law treats as most sensitive: an image of a government identity document, and a facial biometric from a selfie or liveness check. Under PIPL, biometric characteristics and data revealing a specific identity are sensitive personal information (Article 28), and processing them carries a stricter standard than ordinary data — a separate, specific consent and a demonstrated necessity, with a clear notice of the purpose and the impact before collection begins (Articles 29–30). The cross-border transfer to an offshore region then needs a further separate consent stacked on top of that.
Onfido gives you controls that can help — regional residency selection, deletion and retention tooling, and the ability to minimize what each environment holds — but those reduce exposure; they do not discharge the sensitive-PI consent, necessity and notice duties, which rest with you as the handler. Whether your necessity case holds, and exactly what your consent flow must say before a user uploads a document, are questions to settle with counsel.
No mainland region to file against — and why switching regions isn’t the fix
A China-facing sign-up screen, onboarding journey or verification page actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing has to attach to a hosting resource physically in the mainland. Onfido provides none, so there is nothing on Onfido to file against — the same structural gap the residency duty exposes, seen from the licensing side.
The obvious move is to switch the Onfido region to the one nearest China and call it in-country — but the three on offer are EU, US and Canada, and none is in the mainland, so moving from, say, the US region to the Canada region merely relocates the cross-border transfer; it does not end it. Keeping China-collected ID and biometric data in-country means standing up a China-resident home for the verification itself, so the sensitive data is captured, processed and stored in the country rather than sent abroad — while Onfido keeps serving the markets where it already works for you. That split — what must stay, what may go — is the heart of the work, and it is a legal question before it is a technical one.
This is a risk map, not a verdict: whether you owe a separate sensitive-PI consent, a further consent for the transfer, a data-export assessment, in-country storage, an ICP filing, or some combination depends on your entity, the identity data you collect, your role as handler, and who your users are — worth settling with counsel before you rely on it.
The lawful path — map, localize, deliver
There is a lawful way to verify identities for a China-facing presence, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the sensitive-data processing and the cross-border transfer — identifying which identity records collected in China (ID images, facial biometrics, extracted fields, verification results) must stay in the country, what may lawfully leave, where a data-export assessment or an Article 39 storage duty bites, and what your consent and necessity notice has to cover before a user ever uploads a document. The legal conclusions are settled with counsel; we build the technical picture that feeds them.
Then localize: we stand up and integrate a consented, in-country identity-verification route for your China users — one that captures, processes and stores the ID and biometric data inside the mainland — so onboarding keeps working while that sensitive data stops leaving the country by default, and you keep Onfido for the markets where it already serves you.
Then deliver: the China-facing onboarding or sign-up surface your users actually reach is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is identity verification that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
