Does Payload CMS Work in China? Self-Hosted Deployment, Data Residency, PIPL & ICP
Payload CMS is open source and self-deployed, so it isn't blocked in mainland China — its own docs say it "can be deployed anywhere that Next.js can run." That makes where you deploy it the compliance question: a content, accounts and collection-PII store you run offshore is a cross-border transfer under PIPL, and the China-facing site it powers needs an ICP filing bound to in-country hosting. A compliance-first look at the data-residency and ICP exposure — and the in-country deployment that keeps your Payload stack lawful.
Does Payload CMS work in China?
Payload is open source and you deploy it yourself, so it isn't a service China blocks — its own docs say it “can be deployed anywhere that Next.js can run.” That is precisely why the China question isn't whether it loads: it's where you deploy it.
Payload holds your content collections, your editor and admin accounts, and whatever personal information your collections model — in a database you provision. Deploy that database offshore (a managed option, or your own US or EU cloud) and every such record gathered from users in mainland China rests outside the country — a cross-border transfer (数据出境) under PIPL (Articles 38–40: notice, a separate consent, one transfer mechanism), possibly triggering China's data-export security assessment. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) requires that data to stay in the mainland, and the public site Payload powers needs an ICP filing bound to in-country hosting.
Because Payload deploys anywhere Next.js runs, the lawful path is a configuration, not a rebuild: deploy Payload and its database on China-resident, ICP-filed infrastructure so content and accounts stay in-country by design, and keep your offshore deployment for other markets. 21YunBox maps, localizes and delivers — never any form of circumvention. Treat the specifics as a risk to confirm with counsel. Our China team can map your exposure with you →
What Payload CMS's own documentation says about China
| Fact | Primary source |
|---|---|
| Payload is self-deployed, so where your data lives is your deployment choice. Payload's own Production Deployment docs state that Payload “can be deployed anywhere that Next.js can run - including Vercel, Netlify, SST, DigitalOcean, AWS, and more,” and that “Because it's open source, you can self-host it.” It is not a hosted service China blocks at the border — it runs wherever you deploy it, which is what turns the China question into one of residency and ICP, not speed. | Payload Docs — Production Deployment (payloadcms.com), retrieved 2026-10-09 |
| Payload stores your content, your accounts and your collection PII in a database you provision — the location of that database is the residency question. Its docs state Payload works with “any Postgres database or MongoDB-compatible database including AWS DocumentDB or Azure Cosmos DB,” and that you must “make sure your production environment has access to the database that Payload uses.” Because Payload ships its own authentication, that database also holds your editor/admin accounts — so a deployment hosted offshore keeps all of it outside the mainland. | Payload Docs — Production Deployment (payloadcms.com), retrieved 2026-10-09 |
| China-collected personal information held in an offshore Payload is a PIPL cross-border transfer. Moving personal information collected from users in mainland China to a Payload deployment hosted in the US or EU triggers PIPL Articles 38–40: notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. | Personal Information Protection Law of the PRC, Articles 38–40 (cac.gov.cn), retrieved 2026-10-09 |
| For some handlers the data must stay in China, and the public site always owes an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, the Cybersecurity Law's Article 39 (formerly Article 37) requires personal information collected in China to be stored in the mainland — which an offshore deployment cannot satisfy — and any public site served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33) bound to a mainland hosting resource. | Cybersecurity Law of the PRC, Article 39 (formerly Article 37) (cac.gov.cn); State Council Order No. 292; MIIT Order No. 33, retrieved 2026-10-09 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a product aimed at mainland China, the Payload question doesn’t resolve the way it does for a hosted SaaS. Payload is open source, and you deploy it yourself — its own documentation states it “can be deployed anywhere that Next.js can run.” So it is not a service China blocks at the border; it runs wherever you choose to run it. That is exactly why the China decision is a compliance one and not a speed one: what matters is where you deploy Payload, whether the content, the editor accounts and the personal information its collections hold come to rest inside or outside the mainland, and whether the public site it powers is served on infrastructure that can be ICP-filed. Payload’s own docs settle the first half of that; China’s law settles the rest.
Payload CMS in China at a glance
| What decides it | In Payload's own terms — and China's law |
|---|---|
| What it is | An open-source, self-deployed headless CMS and application framework (Node.js and Next.js, on a Postgres or MongoDB-compatible database you provision). It stores your content collections, your editor and admin accounts — Payload ships its own authentication — and whatever personal information your collections model: members, form submissions, customer records. |
| Does it reach the mainland? | It is not a hosted service China blocks; it runs wherever you deploy it. Payload's docs say it “can be deployed anywhere that Next.js can run.” Reachability is a property of your deployment, not of Payload — so it is not where the China question is settled. |
| Where the data lives | Wherever you deploy Payload and its database. Deploy offshore — a managed option, or your own US or EU cloud — and the content, accounts and collection PII gathered from China users all rest outside the mainland. |
| Collecting China PII into an offshore deployment | Those records are personal information. Holding them in an offshore Payload is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) adds an in-country storage duty an offshore deployment cannot meet. |
| Serving the public | The China-facing site or app Payload powers is a public internet service in the mainland, so it needs an ICP filing bound to in-country hosting (State Council Order No. 292; MIIT Order No. 33) — which an offshore deployment has nothing in the mainland to attach to. |
| The lawful path | Because Payload deploys anywhere Next.js runs, deploy it and its database on China-resident, ICP-filed infrastructure for the China entity so content and accounts stay in-country by design; keep offshore deployments for your other markets. 21YunBox maps, localizes and delivers — never any form of circumvention. |
Where your data lives is a deployment decision, not a Payload default
Here is the gate most teams miss, and it is sharper for an application framework than for a hosted tool. Payload is not a place your data goes; it is software you run, on a database you provision. Its documentation is explicit that Payload works with “any Postgres database or MongoDB-compatible database including AWS DocumentDB or Azure Cosmos DB,” and that you must “make sure your production environment has access to the database that Payload uses.” That database is where your content collections live — and, because Payload ships its own authentication, it is also where your editor and admin accounts live, alongside whatever personal information your collections model: members, form submissions, customer records. The location of that one database is the whole data-residency question.
Deploy Payload and its database offshore — on a managed option, or on your own cloud in the US or EU — and every one of those records gathered from users in mainland China comes to rest outside the country. Under China’s Personal Information Protection Law that is a cross-border transfer (数据出境), and the duty falls on the handler — you, not Payload — to give notice, obtain a separate consent for the transfer, and satisfy one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Above certain thresholds, or where the data is “important data,” the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves.
And if your organization is a critical information infrastructure operator or moves personal information at volume, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in the mainland. An offshore Payload deployment, however well tuned, cannot meet that duty. None of this turns on how fast the admin panel loads; it turns on where the data sits and whether it had a lawful basis to be there.
The public site Payload powers still needs an ICP filing
Payload is the back end; the front end is a site or app your users in China actually open. That public-facing service is where the second gate sits. A website or application served to mainland visitors from inside China must carry an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing has to attach to a hosting resource physically in the mainland. An offshore Payload deployment — the admin panel, the content API and the rendered front end all served from outside the country — has nothing in the mainland to file against, and from inside China an offshore-served front end can also load unevenly. So “we already run Payload” does not carry across the border on its own: the content model can be identical, but the delivery and the filing have to be stood up in-country. This is the delivery half of the question, and it stacks on top of the residency half rather than replacing it.
Joining Figma didn’t change where your data runs
One piece of recent news is worth settling, because it changes less than it sounds. In a post dated June 17, 2025, Payload announced it is “joining Figma.” Payload remains open source and self-deployable, and none of the facts above moves: you still choose the host and the database, and the data still lives wherever you deploy it. The acquisition is a reason to re-confirm the current managed-hosting details against Payload’s own docs before you rely on them — not a reason to treat the residency and ICP questions as already answered.
This is a risk map, not a verdict. Whether you owe a separate consent, a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination of them depends on your entity, your data volumes, your role as handler under Chinese law, and who your users are — all worth settling with counsel before your China presence depends on it.
The lawful path — map, localize, deliver
There is a lawful way to run Payload for a China-facing product, and because Payload deploys anywhere Next.js runs, the path is unusually clean.
First, map: our China team works through your exposure on both gates — the cross-border-transfer and residency duties that attach to the content, accounts and collection PII Payload holds, and the ICP obligation on the public site it serves — against your entity, your data volumes and who your users are. We build the technical picture; the legal conclusions are settled with counsel.
Then localize: we stand up Payload and its database on China-resident, ICP-filed infrastructure for your China entity, so the content, the editor accounts and the personal information your collections capture stay inside the mainland by design — while you keep your offshore Payload deployment for the markets it already serves. Payload’s own “deploy anywhere” nature is what makes this a configuration, not a rebuild.
Then deliver: the China-facing front end is served in-country on ICP-filed infrastructure — the 21YunBox Optimizer, set in front of what you already run, with no re-platform. What we never do — and what no one lawfully can — is route your users around China’s data-export rules or around any network restriction; we localize what must stay and deliver it in-country, and we never move personal information out of the mainland by stealth. The result is a Payload stack that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s data-export security assessment
- China’s Cybersecurity Law (data localization, Article 39)
- How to get an ICP filing for China
