Does Vonage Work in China? PIPL Cross-Border, Recipient Data & Delivery Compliance
Vonage Communications APIs (formerly Nexmo) deliver SMS from offshore infrastructure, so a China recipient's phone number and message content cross the border on every send - a PIPL transfer - while China A2P SMS needs a pre-registered Chinese-character signature and filed templates a foreign API cannot hold. A compliance-first look at the recipient-data and SMS-licensing exposure, and the lawful China path.
Does Vonage work in China?
Reaching Vonage's API was never the question — the question is that you are handing an offshore service your China recipients' phone numbers and message content to deliver, and for SMS the compliant channel is China's licensed domestic A2P route, not a foreign API.
With Vonage Communications APIs (formerly Nexmo) you send a recipient's phone number and the message body to infrastructure operated outside the mainland, so every send is a PIPL cross-border transfer of the recipient's personal information (Articles 38–40), and Vonage retains those call detail records including personal data for thirteen months. Delivering application-to-person SMS to Chinese numbers is a licensed, pre-registered activity — a registered Chinese-character signature (短信签名) and pre-filed templates (模板报备) through the carriers — and Vonage's own China SMS page restricts registration to companies with a local China entity, so a foreign API cannot file those directly and routes international SMS. The lawful lever is a licensed in-country delivery path plus consent and data minimization, not making the offshore API reachable.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What Vonage's own documentation says about China
| Fact | Primary source |
|---|---|
| Vonage's own China SMS rules require a pre-registered Chinese-character signature, and bar foreign senders without a China entity from registering. Vonage's China SMS Features and Restrictions page states that since late November 2024 “only Chinese contents with Chinese character signature can be supported,” that “Messages must have a signature included at the front of the message body,” and that from April 2025 registration is possible only for companies with “a local entity and China business license” whose legal representative “must be a China national.” Alphanumeric sender IDs are not supported for China. | Vonage API Support, “China SMS Features and Restrictions” (api.support.vonage.com), retrieved 2026-10-10 |
| Vonage retains the recipient number and message content offshore after sending. Vonage's data-storage policy states it “stores call detail records (CDRs) of your communications transactions including personal data for thirteen months” (removable via the Redact API), keeps financial-record CDRs “for ten years” with no personal data, and holds technical logs “for up to 30 days.” Vonage Communications APIs are operated from outside the mainland, so a recipient's phone number and the message body are processed and retained offshore on every send. | Vonage API Support, “How long does Vonage API store data?” (api.support.vonage.com), retrieved 2026-10-10 |
| Sending a Chinese recipient's number and content offshore is a PIPL cross-border transfer. A phone number is personal information; sent from or about a mainland user to a service operated offshore, it triggers PIPL Articles 38–40 — notice, a separate consent distinct from the agreement to use the service, and one transfer mechanism (a CAC security assessment, the standard contract, or certification). Marketing messages additionally need a lawful basis and consent under Articles 13 and 23. | Personal Information Protection Law of the PRC, Articles 13, 23, 38–40 (cac.gov.cn), retrieved 2026-10-10 |
| A2P SMS and messaging-as-a-business sit inside China's value-added telecom regime. Delivering application-to-person SMS to Chinese numbers runs through the carriers' registered-signature (短信签名) and pre-filed-template (模板报备) regime, and operating a messaging service commercially requires a Value-Added Telecommunications Business License (增值电信业务许可证) under the Telecommunications Business Licensing Measures (MIIT Order No. 42) — which a foreign API cannot hold directly. Where the sending app is a CII operator or high-volume handler, data localization applies (Cybersecurity Law Article 39, formerly Article 37). | Measures for the Administration of Telecommunications Business Licensing, MIIT Order No. 42 (gov.cn); Cybersecurity Law of the PRC (as amended, in force 2026-01-01), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the question to settle about Vonage Communications APIs — the SMS and messaging platform Ericsson acquired in 2022, formerly Nexmo — is not whether an API call reaches a carrier. It is what happens when you hand an offshore service your China recipients’ phone numbers and the message body to deliver on your behalf. Two legs decide it. First, a recipient’s phone number and the content you send — a one-time passcode, an order notice, a marketing offer — are personal information, and uploading them to Vonage’s offshore infrastructure to send is a cross-border transfer under PIPL. Second, delivering application-to-person SMS to Chinese numbers is a licensed, pre-registered activity: Vonage’s own China SMS page requires a Chinese-character signature and pre-registered content and restricts registration to companies with a local China entity — a foreign API cannot file those directly, so it routes international SMS instead.
Vonage in China at a glance
| What decides it | In Vonage's own terms — and China's law |
|---|---|
| What it is | Vonage Communications APIs (formerly Nexmo; a wholly owned Ericsson subsidiary since 2022) — cloud SMS, voice, and verification APIs operated from outside the mainland. There is no Vonage China telecom entity or domestic A2P sending identity you operate as from inside the country; messages to Chinese numbers are sent from offshore infrastructure. |
| What you send it | A recipient's phone number and the message body — a one-time passcode, an order or account notice, a marketing offer — often with a name or reference. The phone number is personal information, and the content frequently is too. Handed to a service operated offshore to deliver, that is a cross-border transfer under PIPL (Articles 38–40, 数据出境): notice, a separate consent, and one transfer mechanism. |
| The second door: A2P licensing | Delivering application-to-person SMS to Chinese numbers runs through the domestic carriers' pre-registration regime — a registered Chinese-character signature (短信签名) and pre-filed content (模板报备). Vonage's China SMS page says “only Chinese contents with Chinese character signature can be supported,” and from April 2025 registration is possible only for companies with “a local entity and China business license.” Operating messaging commercially is a value-added telecom activity (增值电信业务许可证) under the Telecommunications Business Licensing Measures; a foreign API holds none of this directly and routes international SMS. |
| Retention & residency | Vonage states it stores call detail records “including personal data for thirteen months,” with technical logs up to 30 days — the recipient number and message text persist offshore after the send. Where the sending app is a CII operator or high-volume handler, personal information collected in the mainland must be stored there (Cybersecurity Law Article 39 (formerly Article 37)). Marketing messages additionally need a lawful basis and consent (PIPL Articles 13 and 23) and must honor opt-out. |
| The lawful path | Reachability was never the axis. Route China-recipient messaging onto a licensed domestic SMS gateway with registered signatures and pre-filed templates, keep Vonage for the markets where it is licensed to operate, minimize recipient data and keep a lawful cross-border basis for anything that still leaves, and deliver the China-facing app in-country on an ICP-filed footing. 21YunBox maps that path and delivers the app — on telecom its role is advisory: it does not hold a China SMS or telecom license. |
What you actually hand it — your recipients’ contact data and content
Vonage Communications APIs (the product formerly called Nexmo, now a wholly owned Ericsson subsidiary) are operated from outside the mainland. When you send to a Chinese recipient, you pass Vonage two things that are personal information: the recipient’s phone number, and the message body — which routinely carries a name, a one-time passcode tied to a real account, an order or shipping reference, or an account or finance notice. Those do not simply pass through. Vonage’s own data-storage policy states it “stores call detail records (CDRs) of your communications transactions including personal data for thirteen months” (removable through the Redact API), keeps financial-record CDRs “for ten years” with no personal data, and holds technical logs “for up to 30 days.” So the recipient’s number and the message text persist on Vonage’s offshore systems after the send — they are not momentary.
On the SMS leg specifically, Vonage does not offer alphanumeric sender IDs for China, and a random numeric sender is replaced for pre-registration traffic; generic labels such as INFO or NOTICE are prohibited. The deliverable identity for China is a registered Chinese-character signature carried at the front of every message body — which is where the second leg, licensing, begins.
It’s a cross-border transfer — and, for SMS, a licensing question
Start with the data. A phone number is personal information, and so is most of what a message carries. Collected from or about a user in the mainland and handed to a service operated offshore to deliver, that is a cross-border transfer of personal information under China’s Personal Information Protection Law. PIPL puts the duty on the handler — you, the operator of the sending app, not only the API vendor: Articles 38–40 require notice, a separate consent distinct from the user’s agreement to use the service, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). If the messages are marketing rather than transactional, you also need a lawful basis and consent under Articles 13 and 23, and you must honor opt-out.
Then the second door, which is specific to SMS. Delivering application-to-person SMS to Chinese mobile numbers is not just an API call — it runs through the domestic carriers under a pre-registration regime: a registered Chinese-character signature (短信签名) and pre-filed message content (模板报备). Vonage’s own China SMS page states that since late November 2024 “only Chinese contents with Chinese character signature can be supported,” that “Message content that is not registered or has no signature will be subject to filtering by the operators, which will result in delivery failures,” and that since April 2025 “registration is not allowed” for international companies without a local entity — registration is possible only for companies with “a local entity and China business license” whose legal representative “must be a China national.” Operating a messaging service as a business is itself a value-added telecom activity requiring a Value-Added Telecommunications Business License (增值电信业务许可证) under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42). A foreign API holds none of this directly; what it can do is route international SMS, which the carriers filter when it is unregistered.
Residency can bite on top of consent. Where the sending app’s operator is a critical information infrastructure operator or processes personal information above the state-set threshold, personal information collected and generated in the mainland must be stored in the mainland — the data-localization duty the Cybersecurity Law sets in its Article 39 (formerly Article 37, renumbered by the 2025 amendment in force January 1, 2026, with the substance unchanged). None of this turns on how quickly a text arrives; it turns on whether a recipient’s number and the message content had a lawful basis to leave the country, and whether they had to stay in the first place.
Reaching the API isn’t the question — a licensed in-country delivery path is
Because a foreign API cannot register a China sender signature or file templates directly, the productive question is not how to make Vonage’s endpoint respond from Shanghai — it is how to deliver to Chinese recipients lawfully. That has a shape. Route the mainland leg onto a licensed domestic SMS gateway that holds the telecom license and carries registered signatures (短信签名) and pre-filed templates (模板报备) through the carriers, and keep Vonage for the markets where it is licensed to operate. Minimize the recipient data you expose, obtain the Article 13/23 consent for any marketing, honor opt-out, and keep a lawful cross-border basis for anything that still leaves China. This is the opposite of a tunnel that ships the data offshore anyway: localizing means the unconsented offshore send of China contact data stops and China delivery moves onto the licensed domestic path.
On the licensing and carriage itself, be clear about the limits of any vendor’s role. 21YunBox is advisory on the telecom and SMS-licensing leg — it does not hold a China telecom or SMS license and is not a messaging carrier; the license, the carrier relationship, and the signature and template registrations sit with a licensed domestic operator and your counsel. Which arrangement fits your entity, your volumes, and your data is a risk to confirm with qualified counsel against what you actually ship — treat this page as a risk map, not a verdict, and settle the specifics with counsel.
The lawful path — map, localize, deliver
There is a lawful way to reach Chinese users with SMS and one-time passcodes, and it does not run through the offshore API. It runs through a licensed in-country delivery path, a governed transfer, and a China-facing app that is itself licensed and served in-country — in front of the stack you already run, with no rebuild. 21YunBox does three things on that footing.
Map. We inventory what messages go to China recipients, what contact data and content each carries, where Vonage processes and retains it and for how long (call detail records including personal data for thirteen months), the consent basis for any marketing, and whether you are currently relying on international SMS routes instead of the licensed domestic A2P regime — so you know exactly what counsel and a licensed local operator need to confirm.
Localize / govern. We help you route China-recipient messaging onto a licensed domestic SMS gateway with registered signatures and pre-filed templates, keep recipient data minimized, secure the Article 13/23 consent for marketing and honor opt-out, and keep a lawful cross-border basis for anything that still leaves. On the telecom and licensing leg our role is advisory: 21YunBox does not hold or imply a China telecom or SMS license. Localizing means stopping the unconsented offshore send of China contact data and moving China delivery onto the licensed domestic path — never a tunnel that ships the data offshore anyway.
Deliver. The app or site that triggers and manages the messaging is a public internet service with an ICP filing duty; we deliver it in-country on ICP-filed infrastructure — the 21YunBox Optimizer — so it runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind. 21YunBox is a compliant overlay and partner, not a competitor to the messaging vendor.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Data Export Security Assessment Measures
- China’s Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42)
- How to get an ICP filing for China
