Does Qdrant Work in China? PIPL Cross-Border, Data Residency & Self-Hosting
Qdrant is an open-source vector database whose embeddings and payloads are personal information stored at rest, and Qdrant Cloud runs only on AWS, GCP and Azure — no mainland-China region — so indexing your Chinese users' data there is a PIPL cross-border transfer with a data-localization duty. A compliance-first look at the residency exposure and the in-country self-host lever.
Does Qdrant work in China?
Qdrant stores embeddings and their payloads — personal information about your Chinese users — and Qdrant Cloud runs only on AWS, GCP and Azure with no mainland-China region, so that content sits at rest offshore: a residency and cross-border-transfer problem, not a performance one.
You load Qdrant with embeddings computed from users' messages, documents and records, plus a payload that in Qdrant's own words can be "any information that can be represented using JSON" — routinely the raw text itself. Because an embedding is derived from personal data (and supports inversion and membership inference) and the payload often holds that data verbatim, the index is personal information at rest, so keeping it in an offshore region is a cross-border transfer under PIPL (notice, separate consent and a transfer mechanism, Articles 38–40), with an in-mainland storage duty for CIIOs and large-volume handlers (Article 40; Cybersecurity Law Article 39, formerly Article 37). The lawful lever is to keep the index and embeddings in-country by self-hosting the Apache-2.0 engine (or Hybrid/Private Cloud on the mainland), not to make the offshore endpoint reachable; the ICP filing lands on the app in front of Qdrant.
This is a risk map, not a verdict — which transfer mechanism fits, and whether a localization duty applies, turns on your entity, your data volumes and whose data it is. Our China team can map your exposure →
What Qdrant's own documentation says about China
| Fact | Primary source |
|---|---|
| What Qdrant holds is personal information — embeddings plus a payload that often stores the raw text. Into each point you load a vector (an embedding computed from a user's message, document or record) and a payload: Qdrant says it lets you "store additional information along with vectors" and "any information that can be represented using JSON," which in practice carries user IDs and the original text. An embedding is a derivative of personal data and is not anonymous — it supports inversion and membership inference — so an index built from your Chinese users' activity is their personal information at rest. | Qdrant Docs — Payload (qdrant.tech), retrieved 2026-10-10 |
| Qdrant Cloud runs only on AWS, GCP and Azure — no mainland-China region — while the same Apache-2.0 engine is fully self-hostable. Creating a managed cluster, you "choose your data center region or Hybrid Cloud environment," and the providers offered are Amazon Web Services, Google Cloud Platform and Microsoft Azure, with none inside mainland China. The engine itself is open source — "Qdrant is licensed under the Apache License, Version 2.0" — and can run in your own infrastructure via Docker, Kubernetes, a compiled binary, or Qdrant Hybrid/Private Cloud. | Qdrant Docs — Create a cluster (qdrant.tech); Qdrant GitHub (LICENSE), retrieved 2026-10-10 |
| Indexing China-user data into an offshore Qdrant Cloud region is a cross-border transfer under PIPL. Because the embeddings and payloads are personal information, populating an offshore index from China triggers PIPL Articles 38–40: the handler — you, not Qdrant — must give notice, obtain a separate consent and satisfy one transfer mechanism (a CAC security assessment, the standard contract, or certification). See cross-border data transfers under PIPL. | PIPL Articles 38–40; China cross-border data transfer rules, retrieved 2026-10-10 |
| For some handlers the data must stay in China — and offshore Qdrant Cloud has nowhere in-country to keep it. A critical information infrastructure operator, or a handler above the regulators' volume thresholds, must store China-collected personal data in the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37; the 2025 amendment in force January 1, 2026 renumbered 37 to 39, substance unchanged). The in-country remedy is to self-host the open engine or run Hybrid/Private Cloud on the mainland. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a China-facing application, the deciding question about Qdrant is not whether its API answers a query quickly — it is where the data behind that query is allowed to live. Qdrant is an open-source vector database, licensed under Apache 2.0 and fully self-hostable: you load it with embeddings computed from your users’ messages, documents and records, and beside each vector it stores a payload — arbitrary JSON that routinely carries the source text itself. For your Chinese users, that is personal information at rest, and Qdrant Cloud — the managed service — runs only on AWS, Google Cloud and Microsoft Azure, with no region inside mainland China, so by default it sits offshore. Three prongs decide the answer: residency and cross-border transfer of the indexed content; that embeddings are themselves personal information and cannot be anonymized away; and the clean lever — self-hosting the open engine in-country.
Qdrant in China at a glance
| What decides it | In Qdrant's own terms — and China's law |
|---|---|
| What you load into it | Embeddings computed from your users' messages, documents and records, plus a payload — “any information that can be represented using JSON,” which routinely includes the raw text and user metadata the vector was built from. For Chinese users, that is personal information at rest. |
| Where the engine runs | Qdrant Cloud is managed only on AWS, GCP and Azure — no mainland-China region. The same Apache-2.0 engine can be self-hosted (Docker, Kubernetes, binary) or run as Hybrid/Private Cloud in your own infrastructure. Indexing China-user data into an offshore cluster is a cross-border transfer (PIPL Articles 38–40; 数据出境). |
| Embeddings are personal information | A vector is computed from personal data and is not anonymous — it supports inversion (approximate reconstruction of the source) and membership inference — and the payload often stores the raw text beside it. “We only store vectors” does not take the index outside PIPL. |
| Data localization and logs | A CIIO or large-volume handler must keep China-collected personal data in the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37). Query traffic and logs expose the same personal data. Offshore Qdrant Cloud has no in-China region to satisfy it. |
| Reachability is not the axis | The question is residency, not whether the endpoint responds. The lawful lever is to self-host the open-source engine on mainland infrastructure and minimize or pseudonymize what you index; the ICP filing lands on the app in front of the index, not on Qdrant. |
What you actually store — indexed content and its embeddings
A vector database is not a cache in front of your data; it is your data, held in two linked forms. Into Qdrant you load points, and each point is a vector plus a payload. The vector is an embedding — a numeric representation computed directly from a user’s message, support ticket, profile or document, kept precisely because it preserves the meaning of that source. The payload is the information beside it, and Qdrant describes it plainly: “One of the significant features of Qdrant is the ability to store additional information along with vectors … Qdrant allows you to store any information that can be represented using JSON.” In practice that payload holds user IDs, timestamps and, very often, the original text the vector was built from, so a match can be shown and filtered. Put together, an index built from your Chinese users’ activity is a store of their personal information — transformed in the vectors, frequently verbatim in the payload. Where that store physically sits is therefore a data-residency question, and Qdrant Cloud offers nowhere in the mainland to sit it.
It’s a residency and cross-border-transfer problem — and embeddings don’t anonymize it — under PIPL
Because the index holds personal information, keeping it in an offshore Qdrant Cloud region is a cross-border transfer the moment it is populated from China. China’s Personal Information Protection Law (数据出境) puts the duty on the handler — you, the operator of the application, not Qdrant — and Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use your product, and one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. If you are a critical information infrastructure operator or you process personal information above the regulators’ volume thresholds, that data must also be stored in the mainland — the data-localization duty of the Cybersecurity Law Article 39 (formerly Article 37; the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged) — which no offshore region can meet.
The tempting escape is to say the index is “just vectors,” arrays of floating-point numbers rather than names and faces. That instinct is wrong in the way that matters here. An embedding is a derivative of the personal data it was computed from, and research on embedding inversion and membership inference shows vectors can be used to approximately reconstruct their source text and to test whether a given record was in the set — so a store of embeddings of your users’ data is a store of their personal information, carrying the same residency and cross-border duties. Qdrant’s payload, which commonly holds the raw text outright, removes any remaining doubt. Treating the vectors as anonymized does not make them so.
Reaching the endpoint isn’t the question — keeping the index in-country is
Whether the Qdrant endpoint is reachable from China is not the compliance question; where the index and its embeddings rest is. And here Qdrant’s license is the opening most teams miss. The engine is open source under Apache 2.0 and fully self-hostable: the documentation says that “if you want to run Qdrant in your own infrastructure, without any cloud connection,” you deploy it on Kubernetes — or run the container, or compile the Rust binary — and its Hybrid Cloud and Private Cloud options run the same engine inside your environment, where, in Qdrant’s words, “all user data will stay securely within your environment.” The lawful path, then, is to keep China-user embeddings and payloads on mainland infrastructure by running the open engine in-country, and to minimize and pseudonymize what you index so less personal information is at stake in the first place. Qdrant Cloud has no mainland-China managed region and no licensed in-country partition to lean on, so for Qdrant the in-country answer is self-hosted or Hybrid/Private Cloud on the mainland — a path that keeps the data where the law wants it, never one that ships it offshore and back.
This is a risk map, not a verdict: whether a localization duty applies, and which cross-border mechanism fits, turns on your entity, how much personal data you hold and whose it is — settle the specifics with counsel before you build.
The lawful path — map, localize, deliver
Qdrant stays your vector database; nothing is rebuilt or migrated. What 21YunBox adds is the compliance and delivery layer around it.
- Map. We inventory what you vectorize, what personal information the embeddings and payloads carry, where the engine runs today, your query-log exposure and your consent basis — so the residency and cross-border picture is concrete.
- Localize. We help you keep the index and its embeddings in-country by self-hosting the open-source engine (or running Hybrid/Private Cloud) on mainland infrastructure, minimize and pseudonymize what is indexed, and govern any residual transfer under PIPL. Keeping the data in-country means exactly that — the store stays on a mainland path.
- Deliver. The application that queries your index carries an ICP filing duty and needs compliant, in-country delivery — the 21YunBox Optimizer, in front of the stack you already run, with no rebuild.
21YunBox is a compliant overlay and partner, not a competitor to Qdrant. 21YunBox never uses or suggests circumvention of any kind. The goal is simple: your Qdrant-backed product runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s data export security assessment measures
- How to get an ICP filing for China
