Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Stripe Identity Work in China? Sensitive ID & Biometric Data Residency, PIPL Cross-Border & ICP

Stripe Identity is an API you can call from the mainland, so the real question isn't speed. It's that Stripe, by its own statement, processes and stores every verification record — the government-ID image and the biometric face map — in the United States, no matter where the user is, which turns a Chinese user's most sensitive personal information into a cross-border transfer under PIPL, with a stricter sensitive-PI consent standard, a possible data-export assessment, an in-country storage duty for critical or large-volume handlers, and no mainland footing for an ICP filing. Stripe Identity also isn't offered to businesses based in mainland China and lists China among the jurisdictions it prohibits verifying people linked to. A compliance-first look at the residency, sensitive-PI and ICP exposure — and the lawful, in-country verification path.

Does Stripe Identity work in China?

Stripe Identity is an API you can reach from the mainland — it can even read a Chinese government-issued photo ID — so the honest first answer is that it technically runs. That isn't the China question. The question is that it captures the most sensitive personal information there is, and keeps it offshore.

Stripe states on its own support page that it is "processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located" — and that record is a government-ID image plus the biometric identifiers from the selfie check. For a person in China that is a cross-border transfer of sensitive personal information under PIPL (notice, a separate and specific consent, and a transfer mechanism, Articles 38–40), with a possible data-export security assessment above thresholds and an in-country storage duty for a critical or large-volume handler under the Cybersecurity Law Article 39 (formerly Article 37). Two more facts close the door from the vendor's side: Stripe Identity isn't offered to businesses based in mainland China, and Stripe's own terms list China among the jurisdictions it won't let you use the product to verify people linked to.

This is a risk map, not a verdict — what you owe turns on your entity, the identity data you hold, your role as handler and who your users are, and it's worth settling with counsel. The lawful route is a consented, in-country verification path, never a workaround; 21YunBox never uses or suggests circumvention of any kind. Our China team can map your exposure with you →

What Stripe Identity's own documentation says about China

FactPrimary source
Stripe processes and stores every verification record in the United States, wherever the user is. On its own support page, Stripe states: "We are also processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located." That record is the government-ID image plus the biometric identifiers from the selfie check — so for a person in mainland China it is the most sensitive category of personal information, held offshore by default, a cross-border transfer under PIPL. Stripe Support — Managing your ID verification information, retrieved 2026-10-09
Stripe Identity isn't offered to businesses based in mainland China. Stripe's own supported-locations page makes Stripe Identity "generally available for businesses based in" Great Britain, Japan and the United States, with a self-serve public beta for 31 further countries (the EU/EEA plus Australia, Canada, New Zealand and a few others). Mainland China is in neither list, so a mainland entity cannot be the contracting customer — consistent with the fact that Stripe does not support mainland-China businesses generally. Stripe Docs — Supported use cases and locations for Stripe Identity, retrieved 2026-10-09
Stripe prohibits using Stripe Identity to verify anyone linked to China. The same page lists, among unsupported uses, "Verifying anyone who is linked directly or indirectly with the jurisdictions listed below or that Stripe has deemed high risk" — and the jurisdictions it then lists include China. So even where the technology could read a Chinese ID, Stripe's own terms place China-linked verification outside the product's permitted use. Stripe Docs — Supported use cases and locations for Stripe Identity (Unsupported use cases), retrieved 2026-10-09
The selfie check is biometric processing, and Stripe says so. Stripe's documentation describes selfie checks looking "for distinguishing biological traits, such as face geometry," and warns that "there are privacy laws that require you to justify your use of biometric technology or offer an alternative, non-biometric means of verification," recommending you "consult with your legal counsel." Under PIPL a face map and a government ID are sensitive personal information, which carries a stricter standard — a separate, specific consent and demonstrated necessity — on top of the cross-border duty. Stripe Docs — Verification checks (Selfie), retrieved 2026-10-09; PIPL Articles 28–29, 38–40

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a company onboarding or verifying users in mainland China, the first instinct with Stripe Identity is to ask whether its API can be called from inside the country. It can — Stripe Identity is a hosted verification flow reached over Stripe’s ordinary endpoints, not something China blocks at the border, and its selfie-check coverage list even names Chinese government-issued photo IDs. So reachability is not where the China decision is settled. What settles it is the kind of data the product collects and where that data comes to rest. Stripe Identity exists to capture a government-ID image and a selfie and to run a biometric comparison between them — about the most sensitive category of personal information there is — and Stripe states, in its own support documentation, that it processes and stores all of it in the United States. For a person in China, that single fact turns the verification into a cross-border transfer of sensitive personal information before latency ever enters the conversation.

Two further facts from Stripe’s own pages sit on top. Stripe Identity is not offered to businesses based in mainland China at all, and Stripe’s own terms list China among the jurisdictions it will not let you use the product to verify people linked to. The compliance picture, then, is not “it’s slow” — it is that the product is built around offshore processing of biometric identity data, and that Stripe itself closes the mainland door from two directions. China’s law decides the rest.

The Stripe Support page 'Managing your ID verification information', stating that Stripe is processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located
Stripe's own support page is unconditional about where the identity data lives: “We are also processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located.” That record is a government-ID image plus the biometric identifiers from the selfie check — so for a user in mainland China it is sensitive personal information held offshore by default, with no region to choose. Source: Stripe Support — Managing your ID verification information

Stripe Identity in China at a glance

What decides it In Stripe Identity's own terms — and China's law
What it is Stripe Identity is an identity-verification product: it collects a government-issued photo ID and a selfie and runs a biometric face-geometry match between them, returning a verified identity and extracted fields. By design it holds the most sensitive kind of personal data — a face map and an ID document — about identifiable people.
Is it reachable from the mainland? Generally, yes. It is an API-based hosted flow, not blocked at the border, and its selfie-check availability list even includes Chinese government-issued photo IDs (CN). So "can it technically read the document?" is not the China question — the decision sits with data residency and consent, below.
Who can use it (business location) Not mainland-China businesses. Stripe makes Stripe Identity “generally available for businesses based in” Great Britain, Japan and the United States, with a 31-country self-serve beta (EU/EEA plus Australia, Canada, New Zealand and a few more). The mainland is in neither list — consistent with the fact that Stripe does not support mainland-China businesses generally.
Where does the verification data sit? The United States, with no region option. Stripe states it is “processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located.” By its own retention notes, the biometric identifiers are removed within one year and the rest of the submitted identity information is typically stored for seven years — all of it offshore.
A prohibited use Stripe's unsupported-use list says you may not use Stripe Identity for “Verifying anyone who is linked directly or indirectly with the jurisdictions listed below or that Stripe has deemed high risk” — and the jurisdictions it then lists include China. Even where the technology could read a Chinese ID, China-linked verification is outside the product's permitted use.
Collecting China identity data into it An ID image and a biometric face map are sensitive personal information. Sending them to a US-based processor is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate and specific consent, and one transfer mechanism; a data-export security assessment may apply above thresholds. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty a US-only store cannot meet.
The lawful path Keep the sensitive step in-country: a consented, in-country identity-verification route (a CAC-filed or licensed domestic eKYC/real-name option) that captures, checks and stores the ID image and face match inside the mainland, with the China-facing flow delivered in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

Availability: reachable as an API — but not offered to mainland-China businesses

Whether Stripe Identity can be reached from Shanghai is the wrong first question, because it mostly can: it is a hosted verification flow called over Stripe’s ordinary API, and its selfie-check coverage even names Chinese government-issued photo IDs. Being technically able to read a document, though, is not the same as being allowed to use the product for China — and here Stripe’s own pages, not a load-time test, decide the matter.

Stripe Identity’s supported-locations page makes the product “generally available for businesses based in” Great Britain, Japan and the United States, with a self-serve public beta for a further 31 countries across the EU/EEA plus Australia, Canada and New Zealand. Mainland China is in neither list, so a mainland entity cannot be the contracting customer in the first place — the same structural gap covered on our sibling page on whether Stripe works in China. And in its unsupported-use list Stripe goes further: you may not use Stripe Identity for “Verifying anyone who is linked directly or indirectly with the jurisdictions listed below or that Stripe has deemed high risk,” and the jurisdictions it then lists include China. One operational temptation, when a cross-border call is awkward, is to force the flow through a network workaround; 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. The productive question is where the sensitive identity data is allowed to live.

The data-residency question: a US-only verification store is a cross-border transfer

Here is the gate most teams miss. Stripe does not offer a region choice for Stripe Identity the way some clouds do; it states plainly that it is “processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located.” The record in question is the government-ID image, the selfie, the biometric identifiers derived from them, and the extracted fields — and for a person in China, the moment that record is created it has left the country.

That is a cross-border transfer (数据出境) of personal information under China’s Personal Information Protection Law, and because an ID document and a face map are sensitive personal information, the standard is stricter than for ordinary data. PIPL puts the duty on the handler — you, the organization running the onboarding, not Stripe the processor: Articles 38–40 require notice, a separate and specific consent distinct from any general agreement to use your service, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. Above certain thresholds, or where the data qualifies as important data, the transfer may also require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator or a large-volume handler, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization provision was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China, which a US-only verification store cannot satisfy no matter how it is configured. None of this turns on how quickly the check returns; it turns on whether the data had a lawful basis to be in the United States at all.

Residency is only half of it. Stripe Identity works by collecting a government-issued photo ID and a picture of the user’s face and then, in Stripe’s own words, looking “for distinguishing biological traits, such as face geometry,” using “machine learning algorithms to confirm that the face pictures belong to the same person.” Stripe itself flags what follows: in some places “there are privacy laws that require you to justify your use of biometric technology or offer an alternative, non-biometric means of verification,” and it recommends you “consult with your legal counsel.” China is squarely one of those places. Under PIPL a biometric face map and an identity-document image are sensitive personal information, which carries a stricter bar again — a separate, specific consent, a demonstrated necessity for processing it, and a personal-information protection impact assessment — all before the further separate consent the cross-border transfer itself requires. By Stripe’s own retention notes the biometric identifiers are removed within one year and the rest of the submitted identity information is typically stored for seven years; useful housekeeping, but retention windows abroad do not discharge the consent, necessity and residency duties that attach to collecting the data from a person in China. Whether a given check is necessary and proportionate, and what your consent flow must say, are questions to settle with counsel.

This is a risk map, not a verdict: whether you owe a separate and specific consent, a transfer mechanism, a data-export assessment, in-country storage, an ICP filing, or some combination depends on your entity, the identity data you hold, your role as handler, and who your users are — worth settling with counsel before you rely on it.

No mainland region to file against — and no region to “pick” either

A public-facing onboarding or verification page actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing has to attach to a hosting resource physically in the mainland. Stripe Identity provides none, so there is nothing of its own to file against — the same structural gap the residency duty exposes, seen from the licensing side.

With most offshore services the fallback is to flip a tenant to a nearer region and call it in-country. Stripe Identity removes even that option: there is no region selector, and Stripe’s statement is unconditional — the verification data is processed and stored in the United States regardless of where anyone is. So keeping China-collected identity data in-country cannot mean reconfiguring Stripe Identity; it means running the sensitive verification step on a China-resident footing instead. That split — what must stay in the mainland, what may lawfully leave — is the heart of the work, and it is a legal question before it is a technical one.

The lawful path — map, localize, deliver

There is a lawful way to verify a China-facing audience, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the sensitive-data processing and the cross-border transfer — identifying which identity records collected in China must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your consent, necessity and notice flow has to cover for biometric and document data. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a consented, in-country identity-verification route — a CAC-filed or licensed domestic eKYC/real-name option — so the ID image and the face match are captured, checked and stored inside the mainland, while you keep Stripe Identity for the markets where it is offered and permitted. The sensitive step stops leaving the country by default.

Then deliver: the China-facing onboarding or verification screen your users actually reach is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is identity verification that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Can a business in mainland China use Stripe Identity?
No. Stripe Identity's own supported-locations page lists its business locations as Great Britain, Japan and the United States (generally available) plus a 31-country self-serve beta; mainland China is in neither, so a mainland entity can't be the contracting customer — and Stripe does not support mainland-China businesses generally. Stripe's terms also place "anyone who is linked directly or indirectly with" China among the people you may not use the product to verify. There is no lawful way around that, and we never use or suggest circumvention; treat the specifics as a risk to confirm with counsel.
Where does Stripe Identity store the ID image and selfie, and why does it matter for China?
Stripe states it is "processing and storing your verification data in the United States, no matter where you are based or where the business that requested verification is located." By Stripe's own retention notes the biometric identifiers are removed within one year and the rest of the submitted identity information is typically kept for seven years — all of it offshore, with no mainland region to choose. For a user in China that makes the verification a cross-border transfer of sensitive personal information under PIPL: notice, a separate and specific consent, a transfer mechanism, a possible data-export security assessment above thresholds, and an in-country storage duty for a critical or large-volume handler. Which of these bite your case is a question for counsel.
What's the lawful way to verify Chinese users' identity, and what does 21YunBox do?
Keep the sensitive step in-country. The lawful pattern is a consented, in-country identity-verification route — a CAC-filed or licensed domestic eKYC/real-name option — that captures and checks the ID image and the face match inside the mainland and stores the result there, while you keep Stripe Identity for the markets where it's offered and permitted. 21YunBox maps your PIPL cross-border, sensitive-PI, residency and ICP exposure, helps you localize China identity verification onto that in-country footing, and delivers the China-facing onboarding flow in-country on ICP-filed infrastructure — in front of the stack you already run, with no rebuild. The legal calls are settled with counsel; we build the technical path and never move personal information out of China by stealth. Get in touch to map your case.

ARTICLES RELATED TO STRIPE IDENTITY

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.