Does Sendbird Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
Sendbird is a foreign chat and voice/video API with no mainland-China region: your China users' messages, live media and call recordings (a voiceprint and face — sensitive biometric data) ride offshore, real-time comms in China need a telecom license a foreign API can't hold, and the app needs an ICP filing. A compliance-first look at the telecom-licensing, residency and cross-border exposure.
Does Sendbird work in China?
Your China users' live chat, voice and video — plus any call recording, which captures a voiceprint and a face — ride Sendbird's offshore infrastructure with no mainland-China region; providing real-time communication in China needs a value-added telecom license a foreign API can't hold, and the app that embeds it needs an ICP filing.
Sendbird is a foreign chat-and-Calls API: messages, user profiles, voice and video streams, call recordings and session metadata are carried and stored on its global data centers (Oregon, North Virginia, Frankfurt, Mumbai, Singapore, Tokyo and Sydney) — none in mainland China. Running that for users in China is a PIPL cross-border transfer you perform as the handler, and a call recording is sensitive biometric personal information needing separate consent. The lawful lever is to route the real-time service through a licensed in-country operator, keep the media and recordings in-country, obtain the Article 28/29 consent, and ICP-file the app — not to make the offshore endpoint reachable (21YunBox is advisory on telecom licensing).
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Sendbird's own documentation says about China
| Fact | Primary source |
|---|---|
| Sendbird runs on global data centers with no mainland-China region. Sendbird's own post states it "now has eight high-availability data centers all over the world" — in Oregon, North Virginia, Frankfurt, Mumbai, Singapore, Tokyo and Sydney — so messages, live media and recordings for users in China are carried and stored offshore. | Sendbird, "Announcing 8 global data centers" (sendbird.com), retrieved 2026-10-10 |
| Sendbird Calls records participants' audio and video. Its Calls documentation says cloud recording "allows you to record participants' audio and video in both direct calls and group call rooms," with files copied to "your S3 storage in the same region" — so a recording (a voiceprint and a face, sensitive biometric PI under PIPL Article 28) lands in an offshore region, not mainland China. | Sendbird Docs, "Cloud recording," Calls Platform API (docs.sendbird.com), retrieved 2026-10-10 |
| Carrying that offshore is a PIPL cross-border transfer, and recordings need separate consent. Routing participant media, chat content and identifiers to offshore servers triggers PIPL Articles 38–40 (notice, a separate consent, a transfer mechanism); a call recording is sensitive biometric information under Article 28, requiring the specific consent of Article 29 and a prior impact assessment, and it cannot be anonymized away. | Personal Information Protection Law of the PRC, Articles 28–29 and 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| Providing real-time comms in China is a licensed telecom business. Offering real-time voice, video or messaging capability to users in China is a value-added telecommunications business requiring a license (增值电信业务经营许可证) that a foreign API provider cannot hold directly — the lawful route runs the service through a licensed in-country operator. For a CIIO or high-volume handler, mainland data must stay in-country under Cybersecurity Law Article 39 (formerly Article 37). | China Telecommunications Business Licensing Measures — 21YunBox compliance reference, retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
If you are embedding Sendbird’s chat and voice/video APIs into an app for users in mainland China, the deciding question is not whether the SDK can reach China. It is where your users’ live media, messages, call recordings and identifiers are processed and stored, who may lawfully provide real-time communication inside China, and whether the app that carries it is ICP-filed. Sendbird is a foreign real-time communication API — a US-headquartered, Korean-origin vendor whose messaging and Calls infrastructure runs on a set of global data centers with no mainland-China region. That posture raises four compliance prongs: a value-added telecom license a foreign API cannot hold; media- and recording-residency, where a call recording captures a voiceprint and a face — sensitive biometric personal information under PIPL Article 28; the cross-border transfer of participant PII and content; and in-country data-residency for a critical-information-infrastructure or high-volume handler.
Sendbird in China at a glance
| What decides it | In Sendbird's own terms — and China's law |
|---|---|
| What it carries | Chat messages, attachments, user profiles and identifiers, plus live voice and video through Sendbird Calls. Its Calls docs record "participants' audio and video" — and a recording is the speaker's voiceprint and the participants' faces, which is sensitive biometric personal information under PIPL Article 28. |
| Where it runs | On Sendbird's "eight high-availability data centers" — Oregon, North Virginia, Frankfurt, Mumbai, Singapore, Tokyo and Sydney — with Calls in only a subset. None is in mainland China, so running it for China users is a PIPL cross-border transfer (Articles 38–40, 数据出境). |
| The telecom-licensing door | Providing real-time voice, video or messaging to users in China is a value-added telecommunications business requiring a license (增值电信业务经营许可证) a foreign API cannot hold directly. The lawful route runs the real-time service through a licensed in-country operator. 21YunBox is advisory on this leg; it holds no telecom license. |
| Recording consent & residency | A recording is biometric: PIPL Article 28/29 require separate, specific consent and a prior impact assessment, and it cannot be anonymized away. For a CIIO or high-volume handler, mainland data must stay in-country under Cybersecurity Law Article 39 (formerly Article 37). |
| Reachability is not the axis | The SDK opening a connection resolves none of the above. The lever is to route comms through a licensed in-country operator, keep media and recordings in-country, obtain the Article 28/29 consent, and ICP-file the app — not to make an offshore endpoint reachable. |
What you actually carry — live media, recordings and identifiers
A real-time session is never just a connection. When you embed Sendbird, the app carries chat messages and attachments, user profiles and identifiers, and — through Sendbird Calls — live voice and video streams between your users. Sendbird’s own Calls documentation describes cloud recording that “allows you to record participants’ audio and video in both direct calls and group call rooms,” with each file copied to “your S3 storage in the same region.” A recording is not metadata: it is the speaker’s voiceprint and the participants’ faces, which is sensitive biometric personal information. Alongside the media sits session metadata — who called whom, when, and from where — and, for chat, the full content of what your China users write to each other.
All of that is processed on Sendbird’s global infrastructure. Its own post announces “eight high-availability data centers all over the world” — Oregon, North Virginia, Frankfurt, Mumbai, Singapore, Tokyo and Sydney — and its Calls service is documented as available in only a subset of those regions. None is in mainland China, and Sendbird is a managed API with no open-source, self-hostable engine you could stand up in-country. Sendbird also ships AI features — an AI agent, suggested replies, and automated moderation that scores user content — and any model that decides or scores per user is a PIPL Article 24 automated-decision concern.
Three doors: a telecom license, cross-border media, and recording consent
A value-added telecom license. Providing real-time voice, video or messaging capability to users in China is a value-added telecommunications business, which requires a license (增值电信业务经营许可证) from the authorities — and under China’s foreign-investment telecom rules a foreign API provider cannot hold that license directly. The lawful route is to run the real-time service through a licensed in-country operator (or a licensed in-country deployment), the same door that governs in-country calling and messaging generally. 21YunBox is advisory on this leg: it holds no telecom license.
Cross-border transfer and residency. Routing participant streams, chat content, identifiers and call metadata to Sendbird’s offshore media servers is a cross-border transfer that you — the handler — perform under PIPL Articles 38–40: a notice, a separate consent distinct from agreeing to use the feature, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). See cross-border data transfers. If your operating entity is designated critical information infrastructure, or handles personal information above the state threshold, the mainland-collected data must stay in the mainland — the data-localization duty in Cybersecurity Law Article 39 (formerly Article 37, renumbered by the 2025 Cybersecurity Law amendment in force January 1, 2026; the substance is unchanged).
Recording consent — biometric. A call recording is sensitive biometric personal information under PIPL Article 28, so it needs the separate, specific consent of Article 29, a prior personal-information protection impact assessment, and — being biometric — it cannot be anonymized away. Where you carry user-generated audio, video or chat, a content-moderation duty attaches under Cybersecurity Law Article 49 (formerly Article 47), and Sendbird’s AI moderation and agent features add the Article 24 automated-decision question above.
Reaching the endpoint isn’t the question — a compliant in-country real-time path is
That the Sendbird SDK can open a connection from a device in China tells you nothing about any of the three doors. Reachability is not the axis; the axis is compliance risk. A lawful setup has a definite shape: the real-time service is routed through a licensed in-country operator, the China-participant media and recordings are kept on an in-country path — a licensed in-country deployment, since Sendbird offers no open-source engine to self-host — the Article 28/29 consent is in place for any recording, the app is ICP-filed, and user-generated content is moderated. What it is not is a hidden route that carries the media offshore anyway while presenting it as local; keeping media in-country means the media actually stays in-country.
This page is a risk map, not a verdict. Which prongs bind your specific service — the telecom category, whether you are a CIIO or high-volume handler, which consents and permits apply — turns on exactly what your app ships, so settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a clean way to run Sendbird-powered chat and calls for users in China, and it does not involve working around anything. Our China team does three things. We map what the API carries — the live media, the recordings and transcripts, the participant identifiers, the chat content and the session metadata — where each is processed and stored (an offshore region, with no mainland-China option), whether Sendbird’s AI features score your users (Article 24), and the consent basis you need (Articles 28/29 for recordings). We localize: route the real-time service through a licensed in-country operator, keep China-participant media and recordings on an in-country path — a licensed in-country deployment in place of any flow that cannot run compliantly — minimize and pseudonymize what is carried, obtain the Article 13/23 and Article 28/29 consent, and moderate user-generated content. We deliver the app that embeds the SDK — a public service that carries an ICP filing duty — on compliant, in-country infrastructure, the 21YunBox Optimizer, in front of the stack you already run, with no rebuild. 21YunBox is a compliant overlay and partner, advisory on telecom licensing, not a competitor to Sendbird. The result is chat and calls that run legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
