Does Redis Work in China? Data Residency, Localization & PIPL Cross-Border
Redis is free, self-hostable software — it is not blocked in China — so the real question is residency, not reachability. It routinely holds sessions, auth tokens and cached user records, and an offshore managed instance (Redis Cloud lists no mainland-China region) stores that personal data abroad. A compliance-first look at the data-residency, PIPL cross-border and localization exposure.
Does Redis work in China?
Redis runs in China — the engine is free, self-hostable software, not a blocked service; the real question is where the session and user data it holds comes to rest.
Teams call Redis "just a cache," but it routinely stores login sessions, auth tokens and cached user records — personal information. Run it on an offshore managed instance (Redis Cloud, which lists no mainland-China region; AWS ElastiCache/MemoryDB; or Azure Cache in a non-China region) and that China personal information rests abroad: a cross-border transfer under PIPL (Articles 38–40). For a critical-information-infrastructure operator or high-volume handler, personal information collected in the mainland must stay in the mainland (Cybersecurity Law Article 39, formerly Article 37; PIPL Article 40) — a duty no offshore instance can meet. Because the engine is residency-neutral, the lawful lever is simply where you run it: self-hosted on mainland infrastructure, or a licensed in-country / sovereign-cloud option.
This is a risk map, not a verdict — whether you owe a transfer mechanism, in-country storage, or both turns on your data, your volumes and who your users are. Our China team can map your exposure →
What Redis's own documentation says about China
| Fact | Primary source |
|---|---|
Redis Cloud's managed service has no mainland-China region. Redis's own documentation says "Redis Cloud supports databases on the following cloud providers" — Amazon Web Services, Google Cloud and Microsoft Azure — and across those published region tables the nearest locations are Hong Kong (ap-east-1) and Taiwan; no Beijing or Ningxia (mainland-China) region is listed. A managed cluster serving mainland users therefore stores their data offshore. | Redis — Supported Cloud providers and regions (redis.io/docs), retrieved 2026-10-10 |
| The Redis engine is free, source-available software you can run anywhere — including on mainland-China soil. In March 2024 Redis moved from the BSD license to the dual RSALv2/SSPLv1 source-available licenses, and with Redis 8 (May 1, 2025) it added the OSI-approved AGPLv3 as a third option; the Linux Foundation separately forked the engine as Valkey (2024). None of that changes the residency axis: whichever license or fork you run, the engine installs on your own in-country infrastructure — so it is never "blocked," and where it runs is your choice. | Redis blog — "Redis is now available under the AGPLv3 open source license" (redis.io/blog), published 2025-05-01, retrieved 2026-10-10 |
| China personal information left on an offshore instance is a cross-border transfer under PIPL. When Redis holds sessions, tokens or user records collected from mainland users and that data rests offshore, the handler must give notice, obtain separate consent and clear one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification (PIPL Articles 38–40; see the security-assessment measures). | PIPL Articles 38–40; Measures for the Security Assessment of Outbound Data Transfers (CAC), gov.cn |
| CII operators and high-volume handlers owe in-China storage an offshore Redis cannot provide. Personal information collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore instance structurally cannot satisfy that duty, and a public mainland surface in front of Redis also needs an ICP filing. | PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) (gov.cn) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question about Redis is not whether it installs or whether your application can connect — it is where the data Redis holds is allowed to come to rest. Redis is an in-memory data store that teams think of as “just a cache,” yet it routinely keeps login sessions, authentication tokens, rate-limit counters and cached user records — personal information by any reading of China’s law. And Redis is free, source-available software: the engine itself is residency-neutral and self-hostable anywhere you install it, including on mainland-China soil, so it is never “blocked.” The exposure lives in how you run it. An offshore managed instance — Redis Cloud, whose own documentation lists no mainland-China region, or AWS ElastiCache/MemoryDB or Azure Cache in a non-China region — stores your China users’ personal data abroad, which is where China’s residency and cross-border rules take over.
ap-east-1), alongside Taipei, Tokyo and Singapore, with no mainland-China (Beijing or Ningxia) region to select. Source: redis.io/docs/latest/operate/rc/supported-regionsRedis in China at a glance
| What decides it | In Redis's own terms — and China's law |
|---|---|
| Where the data physically rests | Redis is an engine, not a datacenter. Self-hosted, the data rests wherever you install it — including on mainland-China soil. On a managed service it rests in the region you pick, and Redis Cloud's documentation lists AWS, Google Cloud and Azure regions with no mainland-China location (nearest: Hong Kong ap-east-1, Taiwan). |
| What Redis holds — and why it's PI | "Just a cache" is a myth: Redis routinely stores login sessions, authentication tokens, rate-limit counters keyed to users and cached user profiles. For your mainland users that is personal information under PIPL — wherever the instance happens to run. |
| Your China users' records, run offshore | On any offshore instance (Redis Cloud with no China region, AWS ElastiCache/MemoryDB, or Azure Cache in a non-China region), that China personal information rests abroad — a cross-border transfer PIPL governs (Articles 38–40). |
| The in-country storage duty | A critical-information-infrastructure operator or high-volume handler must keep mainland personal information in the mainland (PIPL Article 40; Cybersecurity Law Article 39, formerly Article 37) — a duty an offshore Redis instance structurally cannot meet. |
| Is it reachable? (not the axis) | Yes — Redis is software your app connects to, never a blocked site. The lawful lever is where you run it: self-host in-country, or a licensed sovereign option, with the China-facing surface on ICP-filed, in-country delivery. Reachability is the delivery half; residency is the half the law turns on. |
Where the data actually rests
Redis is not a hosted site you reach or fail to reach — it is an engine. You install free, source-available software on a server you control, and the data rests wherever that server physically sits, including, with no special edition, on mainland-China infrastructure. That makes the engine residency-neutral: it does not decide where your data lives; your deployment does.
Its licensing has shifted, but the residency point does not. In March 2024 Redis moved from the BSD license to the dual, source-available RSALv2 and SSPLv1 licenses; with Redis 8 (released May 1, 2025) it added the OSI-approved AGPLv3 as a third option, and the Linux Foundation separately forked the engine as Valkey in 2024. Whichever license or fork you run, the software still installs and runs on your own in-country hardware — so Redis is never “blocked,” and where it runs stays your choice.
The residency question lands on the managed offerings. Redis Cloud’s documentation says “Redis Cloud supports databases on the following cloud providers” — AWS, Google Cloud and Microsoft Azure — and across those region tables the nearest locations are Hong Kong (ap-east-1) and Taiwan, with no mainland-China region to select. AWS ElastiCache and MemoryDB, and Azure Cache for Redis / Azure Managed Redis, run on those same global clouds, which likewise have no mainland region. China capacity exists only in the separate sovereign partitions — AWS China (Beijing and Ningxia) operated by Sinnet and NWCD, and Azure China operated by 21Vianet — which are distinct clouds with their own accounts, feature gaps, ICP and compliance. An in-country region is not automatic compliance, but it is the honest in-country option.
What it holds is personal information
The reason Redis matters here is what teams forget it holds. People describe Redis as “just a cache,” but in practice it stores login sessions, authentication and refresh tokens, password-reset and one-time codes, rate-limit and fraud counters keyed to individual users, queued jobs carrying customer payloads, and cached copies of user profiles and orders. For mainland users that is personal information — and some of it (identifiers, contact details, tokens that unlock an account) is sensitive personal information.
So an offshore Redis instance that holds your China users’ sessions and records is not an infrastructure detail — it is a store of personal information resting outside the mainland. China’s Personal Information Protection Law treats keeping it there as a cross-border transfer, and the handler — you, not the engine’s authors — must give notice, obtain separate consent, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification (Articles 38–43).
If you are a critical information infrastructure operator, or you process personal information above the regulated volume thresholds, the duty is heavier: personal information collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged). An offshore Redis instance cannot satisfy that; neither can a managed region that does not exist in the mainland.
Running it offshore (or on a no-China-region managed service) doesn’t meet the residency duty — and what does
This is why a no-China-region managed instance is the exposure, not the engine. Pointing a mainland app at an offshore Redis endpoint moves personal information across the border on every read and write, and an offshore instance can hold neither an in-country copy of that data nor the footing a localization duty requires. The fix is not a connection back to that offshore endpoint — it is to run Redis where the data must live.
Because the engine is residency-neutral, the lawful lever is straightforward: run Redis in-country. Self-host it on mainland infrastructure, or use a licensed in-country / sovereign-cloud option, so the sessions, tokens and user records stay on mainland soil. It is the same Redis — same data types, same clients, same commands — so this is a deployment change, not a migration to a different database or a second codebase. Localize means standing up a lawful in-country Redis, not a tunnel back to an offshore endpoint. Any public mainland surface in front of it — the app, the API edge, an admin or reporting portal — separately needs an ICP filing.
This is a risk map, not a verdict: whether you owe a transfer mechanism, in-country storage, or both depends on your entity, the data you keep in Redis, your volumes and who your users are — worth settling with counsel before you build.
The lawful path — map, localize, deliver
You keep Redis. 21YunBox adds the part a global cache or managed region cannot: a lawful, in-country home for the data and an ICP-filed way to serve it — set in front of the stack you already run, with no rebuild and no second codebase.
- Map. Our China compliance team reads your PIPL cross-border, data-residency and data-localization (CII) obligations against your entity, your data volumes, and whose personal information actually sits in Redis.
- Localize. We run Redis in-country — self-hosted on mainland infrastructure, or on a licensed in-country / sovereign-cloud option — so sessions, tokens and user records stay on mainland soil. Localize means an in-country Redis, never a tunnel back to an offshore endpoint.
- Deliver. Any China-facing surface in front of Redis — the application, the API edge, the admin or reporting portal your mainland users hit — runs over ICP-filed, in-country delivery (the 21YunBox Optimizer), in front of the stack you already run.
21YunBox is a compliant overlay, not a migration, and a partner to Redis and your cloud, not a competitor. 21YunBox never uses or suggests circumvention of any kind. The result is Redis that runs legally and compliantly for your users in China.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law and data localization
- China’s data-export security assessment measures
- How to get an ICP filing for China
