Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does Sumsub Work in China? KYC Biometric & ID Data Residency, PIPL Cross-Border & ICP

Sumsub's identity-verification cloud is reachable from the mainland, so the real question isn't speed — it's data residency for sensitive personal information. Sumsub's own documentation hosts applicant data in a region the customer selects — Germany by default, with the USA, UAE and Singapore as its Local Data Processing options and no mainland-China region — so the government-ID images, face biometrics, liveness video and AML screening results it collects on your Chinese users rest offshore: a cross-border transfer of sensitive PI under PIPL, with an in-country storage duty under the Cybersecurity Law for a CIIO or large-volume handler, and no footing for an ICP filing. A compliance-first look at the sensitive-PI, cross-border and ICP exposure, and the lawful in-country path.

Does Sumsub work in China?

There's a twist worth naming up front: Sumsub is the platform you buy to pass KYC and AML checks, yet used as-is for mainland China it can create a data-compliance exposure of its own. Reaching it isn't the problem — where it keeps your Chinese users' ID images and face biometrics is.

By Sumsub's own documentation, applicant data is hosted in a region you select — "Germany – by default" — and the Local Data Processing regions it "currently support[s]" are the USA, UAE and Singapore, with no mainland-China option. So every government-ID scan, selfie-biometric, liveness recording and AML screening result it captures from a person in China is sensitive personal information held offshore — a cross-border transfer PIPL governs (notice, a separate consent specific to the overseas transfer, a transfer mechanism and a protection-impact assessment, Articles 38–40 and 55), with an in-country storage duty for a CIIO or large-volume handler (Cybersecurity Law Article 39 (formerly Article 37)). A China-facing onboarding flow served from inside the mainland also needs an ICP filing Sumsub names no region to anchor. The table below is Sumsub's own wording and the rule each line triggers.

This is a risk map, not a verdict — what you owe turns on your data volumes, your role as handler and who your users are, and it's worth settling with counsel. Our China team can map your exposure with you →

What Sumsub's own documentation says about China

FactPrimary source
Sumsub hosts applicant data in a region you pick — defaulting to Germany, with no mainland-China option. Its processor documentation lists AWS hosting as "Germany – by default, other countries and regions – by request and if available," and its Local Data Processing page states that "Applicant data, images, videos, and other binary files will be stored locally in a particular region." None of its regions is inside the mainland, so the ID images, face biometrics and liveness recordings it holds on your Chinese users rest offshore — a cross-border transfer of personal information under PIPL (notice, a separate consent and a transfer mechanism, Articles 38–40). Sumsub Docs — Third-Party Processors and Affiliates, retrieved 2026-10-09; PIPL Articles 38–40
Its selectable data-residency regions don't include mainland China. Under the heading "Supported regions," Sumsub's Local Data Processing documentation says "For the v2 processing level, we currently support the following regions:" — the USA, UAE and Singapore. It adds that it is "working to expand support to include non-AWS data centers such as Huawei Cloud and AliCloud," a stated future plan rather than a mainland-China option you can turn on today — and even an in-country region would resolve only the storage half, not the consent, impact-assessment and ICP duties. Sumsub Docs — Local Data Processing, retrieved 2026-10-09
What a KYC platform collects is mostly sensitive personal information, which raises the bar. A government-ID document and a facial biometric are sensitive personal information under PIPL: processing them requires a specific purpose and necessity, a separate and specific consent, and a personal-information protection impact assessment (Articles 55–56) completed before collection. Transferring them to an offshore region then needs a further consent specific to the overseas transfer, and above thresholds may require a data-export security assessment before anything leaves. PIPL Articles 28, 38–40, 55–56 (sensitive personal information; cross-border transfer; impact assessment)
For some handlers the data must stay in China — and serving from inside the mainland triggers an ICP filing. Where the handler is a critical information infrastructure operator or moves personal information at volume, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — which an offshore verification store cannot satisfy. And any public-facing onboarding flow actually served from inside China must carry an ICP filing (State Council Order No. 292; MIIT Order No. 33), bound to a mainland hosting resource Sumsub does not provide. PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37); State Council Order No. 292; MIIT Order No. 33

Sources verified by the 21YunBox compliance team on 2026-10-09.

For a fintech, exchange, marketplace or bank standing up customer onboarding for mainland China, the first instinct with Sumsub is to ask whether its verification flow will load from inside the country. It generally will — Sumsub’s KYC endpoints are not what China blocks at the border, so reachability is not where the China decision is settled. What settles it is data residency and the cross-border transfer of sensitive personal information: where the government-ID images, facial biometrics, liveness video and AML screening results Sumsub captures about your users come to rest, and whether you had a lawful basis to move that data out of China at all. Those are questions of China’s law, and they sit upstream of latency. Sumsub answers the residency half in its own documentation.

Sumsub runs no verification cloud inside mainland China. By its own docs its hosting defaults to Germany, and the data-residency regions it lets you choose are all offshore — so the moment an ID scan, a selfie-biometric or a liveness recording collected from a person in China lands in one of them, you have made a cross-border transfer (数据出境) of sensitive personal information, and a stricter body of law decides whether that was allowed.

Sumsub's own Local Data Processing documentation on docs.sumsub.com, showing that applicant data, images and videos are stored in a region the customer selects, and listing the supported v2 processing regions as USA, UAE and Singapore — with no mainland-China region
Sumsub's own Local Data Processing documentation: “Applicant data, images, videos, and other binary files will be stored locally in a particular region,” and “For the v2 processing level, we currently support the following regions:” — USA, UAE and Singapore. None is in mainland China, so the government-ID image and face-biometric an applicant uploads come to rest offshore. Source: Sumsub Docs — Local Data Processing

Sumsub in China at a glance

What decides it In Sumsub's own terms — and China's law
What it is Sumsub is a KYC/AML identity-verification platform — government-ID document checks, a selfie/liveness biometric face match, and AML, PEP and sanctions screening — delivered as a cloud service via SDK and API. It collects and stores a highly identifying record of real people: ID document images, facial biometric data, liveness recordings, and screening results.
Is it reachable from the mainland? Generally, yes. Sumsub's verification endpoints are callable from China and it is not blocked at the border, so reachability is not the China question. (Cross-border verification calls from the mainland to an offshore endpoint can be inconsistent — an operational matter, below, not the decision.)
Where does the verification data sit? Offshore. Sumsub says it “lets you determine the physical location where data is stored and processed”; by its own processor docs AWS hosting is “Germany – by default, other countries and regions – by request and if available,” and the Local Data Processing regions it “currently support[s]” are the USA, UAE and Singapore. There is no mainland-China region, and “Applicant data, images, videos, and other binary files will be stored locally in a particular region.”
Collecting China ID & biometric data into it ID-document images, facial biometrics and liveness are sensitive personal information under PIPL, and AML results are personal information too. Holding them in an offshore region is a cross-border transfer (数据出境) under PIPL (Articles 38–40): notice, a separate consent specific to the overseas transfer, a transfer mechanism, and a protection-impact assessment (Article 55); a data-export security assessment may apply above thresholds. For a critical information infrastructure operator or large-volume handler, the Cybersecurity Law's Article 39 (formerly Article 37) sets an in-country storage duty an offshore region cannot meet.
Serving the public A China-facing onboarding or verification flow actually served to mainland visitors from inside China needs an ICP filing bound to a mainland hosting resource. Sumsub names no mainland region, so there is nothing of its own to file against.
The lawful path Keep China-collected ID, biometric and AML data in-country on a consented, China-resident verification route, with in-country processing and storage, and deliver the China-facing onboarding surface in-country on ICP-filed infrastructure. 21YunBox maps, localizes and delivers; it never uses or suggests circumvention of any kind.

Availability: reachable — but where does the identity data live?

Sumsub’s position is set in its own documentation, not by a load-time test. Its Local Data Processing page states that Sumsub “lets you determine the physical location where data is stored and processed,” that “Applicant data, images, videos, and other binary files will be stored locally in a particular region,” and — under the heading “Supported regions” — that “For the v2 processing level, we currently support the following regions:” namely the USA, UAE and Singapore. Its processor documentation is just as plain about the default: AWS hosting is “Germany – by default, other countries and regions – by request and if available.” Not one of those is inside the mainland.

So “can the onboarding screen reach Sumsub from Shanghai?” is the wrong test. It reaches. The real question is where your China-collected ID and biometric data sits, and whether it was allowed to leave the country at all — which is why this page publishes no first-party China latency or reachability figure for Sumsub: speed is not the axis for a decision that turns on residency and consent. One operational note worth naming: cross-border verification calls from the mainland to an offshore service can be inconsistent, and the temptation is to force them through a network workaround. 21YunBox neither uses nor suggests any such circumvention — it is both a compliance risk and beside the point. The productive question is how to keep the China verification data on a lawful footing.

The data-residency question: an offshore verification store is a cross-border transfer of sensitive PI

Here is the gate most onboarding teams miss. Applicant data hosted in any of Sumsub’s regions is, by definition, outside the mainland. The ID-document images, facial biometrics, liveness recordings and AML results it holds for your users in China are personal information, and loading them into an offshore region is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the organization operating the onboarding flow, not Sumsub the processor: Articles 38–40 require notice, a separate consent distinct from any general agreement to use your service, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification.

Two things sharpen this for a KYC platform specifically. First, most of what it captures is sensitive personal information, so the transfer consent must be specific to the overseas transfer and sit on top of the separate consent that sensitive processing already requires. Second, above certain thresholds, or where the data qualifies as “important data,” the transfer may require China’s data-export security assessment (数据出境安全评估) before anything leaves. And if your organization is a critical information infrastructure operator, the Cybersecurity Law’s Article 39 (formerly Article 37 — the data-localization clause was renumbered by the 2025 amendment that took effect on January 1, 2026, with its substance unchanged) requires that personal information generated in China be stored in China, an in-country storage duty an AWS region in Germany, the USA, the UAE or Singapore simply cannot satisfy. None of this turns on how quickly a check clears; it turns on whether the data had a lawful basis to be there. Which of these bite your specific deployment is a risk to confirm with counsel against what your verification flow actually collects.

Residency is only half of it. A KYC platform works by collecting the most identifying attributes a person has — a government-ID document, a photograph of their face matched to it, a liveness recording to prove they are real, and a trail of screening hits against watchlists. Under PIPL, a face biometric and a government-identity document are sensitive personal information, which carries a stricter standard than ordinary PI: a specific purpose and demonstrated necessity, a separate, specific consent before collection, and a personal-information protection impact assessment (PIPIA, Articles 55–56) completed in advance. The cross-border transfer to an offshore region then needs a further consent on top of all of that. Sumsub gives you controls that can help — regional data residency, retention settings, and the ability to minimize what each environment holds — but those reduce exposure; they do not discharge the consent, notice and impact-assessment duties, which rest with you as the handler. Whether a given attribute counts as sensitive, and exactly what your consent flow and PIPIA must cover, are questions to settle with counsel.

No mainland region to file against — and why “pick another region” isn’t the fix

A China-facing onboarding page, verification screen or customer portal actually served to mainland visitors from inside China turns on an ICP filing (ICP 备案) under State Council Order No. 292 and MIIT Order No. 33, and that filing has to attach to a hosting resource physically in the mainland. Sumsub provides none, so there is nothing on Sumsub to file against — the same structural gap the residency duty exposes, seen from the licensing side.

The obvious move is to switch the Local Data Processing region to one nearer China and call it in-country — but the regions Sumsub offers are the USA, UAE and Singapore, with Germany as the default, and none is in the mainland. Moving applicant data from, say, Singapore to the UAE merely relocates the cross-border transfer; it does not end it. Sumsub’s own docs note it is “working to expand support to include non-AWS data centers such as Huawei Cloud and AliCloud” — but that is a stated future plan, not a mainland-China residency option you can turn on today, and even an in-country region would resolve only the storage half: the separate consent, the impact assessment and the ICP filing would still sit with you. Keeping China-collected verification data in-country means standing up a consented, China-resident route for the identity checks your China entity runs — in-country processing and storage for the ID, biometric and AML records — while you keep Sumsub for the markets it already serves. That split — what must stay, what may go — is the heart of the work, and it is a legal question before it is a technical one.

This is a risk map, not a verdict: whether you owe separate consent, a transfer mechanism, a data-export assessment, an impact assessment, in-country storage, an ICP filing, or some combination depends on your entity, the identity data you hold, your role as handler, and who your users are — worth settling with counsel before you rely on it.

The lawful path — map, localize, deliver

There is a lawful way to run identity verification for a China-facing presence, and it has a shape. First, map: our China team works through your PIPL exposure on both fronts — the sensitive-PI processing and the transfer — identifying which verification records collected in China (ID images, face biometrics, liveness, AML results) must stay in the country, what may lawfully leave, where a data-export security assessment or an Article 39 storage duty bites, and what your consent flow and impact assessment have to cover. The legal conclusions are settled with counsel; we build the technical picture that feeds them.

Then localize: we stand up and integrate a consented, China-resident footing for the China verification data — in-country processing and storage on a China-legal identity-verification route for the China entity — so onboarding keeps working while those sensitive records stop leaving the country by default, and you keep Sumsub for the markets where it already serves you.

Then deliver: the China-facing onboarding flow, portal or app your users actually reach is itself a public service in the mainland, so it carries an ICP filing (备案) duty and needs compliant, in-country delivery. 21YunBox delivers it in-country — the 21YunBox Optimizer — set in front of what you already run, with no rebuild and no re-platform. The result is customer onboarding that runs legally and compliantly for your users in China. What we never do — and what no one lawfully can — is hand you a route around China’s data-export rules or around any network restriction: we localize what must stay and deliver in-country, and we never move personal information out of China by stealth.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Sumsub store Chinese users' ID and biometric data in China?
No. By Sumsub's own documentation, applicant data is hosted in a region the customer selects — "Germany – by default" — and its Local Data Processing regions are the USA, UAE and Singapore, with no mainland-China option. The government-ID images, face biometrics, liveness recordings and AML results it captures from Chinese users are held offshore, which makes them a cross-border transfer of sensitive personal information under PIPL: the handler (you, not Sumsub) owes notice, a separate consent specific to the overseas transfer, a transfer mechanism, and a protection-impact assessment.
If Sumsub is a KYC/AML compliance tool, how can it be a compliance risk in China?
Because China compliance turns on where the sensitive data lives and whether you had consent to move it — not on what the tool is for. An identity-verification platform exists to collect the most identifying data a person has: a government ID, a face biometric, a liveness recording. If those records rest in Germany, the USA, the UAE or Singapore, you have created exactly the cross-border transfer of sensitive personal information PIPL regulates, plus a residency duty an offshore store can't meet for a CIIO or large-volume handler. Treat it as a risk to work through with counsel: using a compliance tool does not exempt the personal information it collects from China's transfer, residency and impact-assessment rules.
Can 21YunBox help make our Sumsub setup work in China?
Yes. Our China team can map your exposure — assessing the PIPL sensitive-PI, cross-border and data-residency obligations that attach to the ID, biometric and AML data Sumsub collects, for your entity, data volumes and users — help localize China-collected verification data onto a consented, in-country footing, and stand up the ICP-filed, in-country delivery a compliant China presence requires, in front of the onboarding stack you already run. We never use or suggest circumvention of any kind. Get in touch to work through your specific case.

ARTICLES RELATED TO SUMSUB

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.