Does Vonage Video API Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
The Vonage Video API (formerly TokBox / OpenTok) runs your users' live video, voice and recordings on media routers worldwide with no mainland-China region, so carrying China participants' streams, recordings (voiceprint and face = biometric) and identifiers offshore is a PIPL cross-border transfer — and providing real-time comms in China needs a value-added telecom license a foreign API can't hold, while the app needs an ICP filing. A compliance-first look at the telecom-licensing, residency and cross-border exposure.
Does Vonage Video API work in China?
Whether you can run the Vonage Video API for users in mainland China is first a compliance question, not a speed one: your users' live video, audio and any recording (voiceprint and face = biometric data) and identifiers ride media routers with no mainland-China region, providing real-time comms in China needs a value-added telecom license a foreign API cannot hold, and the app that embeds the SDK needs an ICP filing.
The Vonage Video API — formerly TokBox / OpenTok, now part of Vonage, an Ericsson company — runs media on routers worldwide; its Regional Media Zones cover the United States, the European Union, Germany, Australia, Canada, Japan, South Korea, Singapore, and Brazil, with none in mainland China, and archives upload to an offshore Amazon S3 bucket. Carrying your China participants' streams, recordings and identifiers to that infrastructure is a PIPL cross-border transfer you perform as the handler, and a recording is sensitive biometric data needing PIPL Article 28/29 separate consent. The lawful lever is to route the real-time service through a licensed in-country operator, keep the media and recordings in-country, obtain that consent, and ICP-file the app — not to make the offshore endpoint reachable (21YunBox is advisory on telecom licensing).
This is a risk map, not a legal verdict — what you owe turns on your entity, data volumes and role. Our China team can map your exposure →
What Vonage Video API's own documentation says about China
| Fact | Primary source |
|---|---|
| Media runs worldwide — no mainland-China region. Vonage's own Regional Media Zones guide states the platform "includes media servers located worldwide," and lists the available zones as the United States, the European Union, Germany, Australia, Canada, Japan, South Korea, Singapore, and Brazil — none in mainland China. So your China participants' live video and audio are carried on media routers outside the mainland. | Vonage Video API — Regional Media Zones guide, retrieved 2026-10-10 |
| Recordings are stored offshore on Amazon S3. Vonage's archiving guide says "Recordings are uploaded to the Amazon S3 bucket you specify," with the default endpoint being Amazon's own https://s3.amazonaws.com. The platform offers no mainland-China storage region, so a recording of a China call — which captures faces and voiceprints — comes to rest in a bucket outside the mainland unless you intervene. | Vonage Video API — Archiving using AWS S3 guide, retrieved 2026-10-10 |
| A recording is sensitive biometric data under PIPL. A video recording captures participants' faces and the speaker's voiceprint, which is sensitive personal information under PIPL Article 28 — it requires a specific purpose, a prior impact assessment, and under Article 29 a separate, explicit consent, and being biometric it cannot be anonymized away. Carrying it to offshore servers is also a cross-border transfer under Articles 38–40. | PIPL Articles 28, 29 and 38–40 (21YunBox translation; original on gov.cn), retrieved 2026-10-10 |
| Providing real-time comms in China needs a telecom license a foreign API can't hold. Offering real-time voice and video communication to users in the mainland is a value-added telecommunications business requiring a Value-Added Telecommunications Business License (增值电信业务经营许可证) under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42), which a foreign-operated API cannot hold directly; the lawful route runs the service through a licensed in-country operator. For a CIIO or high-volume handler, in-country storage is also required — Cybersecurity Law Article 39 (formerly Article 37). | Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42); Cybersecurity Law Article 39 (formerly Article 37) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a China-facing app, the question to settle about the Vonage Video API is not whether its SDK initializes or whether a call connects — it is where your users’ live video and audio come to rest, who may lawfully provide real-time communication to people in the mainland, and whether the app that embeds it is filed. The Vonage Video API — the platform formerly known as TokBox / OpenTok, now part of Vonage, an Ericsson company — is an embeddable, foreign-operated real-time communication API: you drop in its SDK and the media runs on Vonage’s media routers worldwide, with no mainland-China region. That single fact opens four prongs at once. Providing real-time comms in China is a value-added telecom business a foreign API cannot license. The live streams and any recording are participant personal information — and a recording captures voiceprints and faces, sensitive biometric data under PIPL Article 28. Carrying that media and those identifiers to offshore servers is a PIPL cross-border transfer. And for a critical-information-infrastructure or high-volume handler, the data carries an in-country storage duty. None of these turn on milliseconds.
Vonage Video API in China at a glance
| What decides it | In Vonage Video API's own terms — and China's law |
|---|---|
| What it carries | Live participant video and audio, the signaling and chat that ride alongside, session metadata (who joined which session, when, and from where), and — when Recording (archiving) is on — a saved file that captures the participants' faces and the speaker's voiceprint. A recording is therefore sensitive biometric personal information under PIPL Article 28, and the Live Captions feature adds a transcript. All of it is participant personal information. |
| Where it runs | On the Vonage Video API's media routers, which are located worldwide; its Regional Media Zones cover the United States, the European Union, Germany, Australia, Canada, Japan, South Korea, Singapore, and Brazil, and archives upload to an Amazon S3 bucket (default endpoint s3.amazonaws.com). None is in mainland China, and there is no on-premises build. Running it for China participants is a cross-border transfer — PIPL Articles 38–40 (数据出境): notice, a separate consent, and one transfer mechanism. |
| The telecom-licensing door | Providing real-time voice and video communication to users in the mainland is a value-added telecom business. Under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it needs a Value-Added Telecommunications Business License (增值电信业务经营许可证) a foreign-operated API cannot hold directly — so the lawful route carries the China real-time leg through a licensed in-country operator, not the offshore platform alone. |
| Recording consent and residency | A recording's faces and voiceprints are sensitive personal information under PIPL Article 28, which cannot be anonymized away and which Article 29 says needs a separate, specific consent plus a prior impact assessment. For a critical-information-infrastructure operator or high-volume handler, in-country storage also bites: Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, substance unchanged. |
| Reachability is not the axis — the lawful path | The SDK resolves, but reachability was never the question. Carrying China participants' live media and biometric recordings on infrastructure with no mainland-China region, provided by a party that cannot hold the China telecom license, is the exposure. The lawful path routes the real-time leg through a licensed in-country operator, keeps media and recordings in-country with the Article 29 consent, and delivers the app on ICP-filed infrastructure. On telecom 21YunBox is advisory — we hold no China telecom license. |
What you actually carry — live media, recordings and identifiers
Embedding the Vonage Video API means your app carries the live, unedited substance of a conversation: each participant’s real-time video and audio, their name and any account reference you attach to a connection, the session metadata that records who joined which session and when, and the signaling and chat messages and any shared screen that ride alongside the call. Turn on Recording (archiving) and the platform captures that session to a file — and a recording of a video call is the participants’ faces and the speaker’s voiceprint, which is sensitive biometric personal information under PIPL Article 28 that cannot be anonymized away. Enable Live Captions and the audio is also streamed to a transcription engine — the feature is generally available and powered by a third-party transcription service — producing transcript text as well.
All of this runs on the Vonage Video API’s media routers, which are located worldwide; its Regional Media Zones cover the United States, the European Union, Germany, Australia, Canada, Japan, South Korea, Singapore, and Brazil, and archives are uploaded to an Amazon S3 bucket (the default endpoint is Amazon’s own s3.amazonaws.com). None of those locations is in mainland China, and because this is a managed, foreign-operated API there is no on-premises build to point at mainland infrastructure. For your China participants, the live media and every record derived from it are created and stored offshore. Where Live Captions or other automated features score or decide how an individual is handled, the PIPL Article 24 automated-decision duty can also apply, and because the API carries user-generated audio, video, and chat, content-moderation duties under the Cybersecurity Law come into play as well.
Three doors: a telecom license, cross-border media, and recording consent
The first door is licensing, and it is the one a foreign API cannot open by itself. Providing real-time voice and video communication to users in the mainland is a value-added telecommunications business: under the Measures for the Administration of Telecommunications Business Licensing (MIIT Order No. 42) it requires a Value-Added Telecommunications Business License (增值电信业务经营许可证), and China’s foreign-investment rules mean a foreign-operated API cannot hold that license directly. The lawful route is to run the real-time service through a licensed in-country operator, not on the offshore platform alone.
The second door is the cross-border transfer. The live streams, recordings, transcripts, session metadata, and participant identifiers you carry are personal information, and running the API for China participants sends them to media routers and storage with no mainland-China region — a cross-border transfer under PIPL Articles 38–40 (数据出境) that you, the handler, must support with notice, a separate consent, and one approved transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). For a critical-information-infrastructure operator or a high-volume handler, in-country storage is a duty in its own right under Cybersecurity Law Article 39 (formerly Article 37).
The third door is consent for the recording. Because a recording captures faces and voiceprints, it is sensitive biometric personal information under PIPL Article 28, which requires a specific purpose and — under Article 29 — a separate, explicit consent distinct from the general agreement to use the service, along with a prior personal-information protection impact assessment. Being biometric, it cannot be anonymized away. These three doors are legal questions about who may carry the service and where the data may live; none of them is answered by how quickly the SDK loads.
Reaching the endpoint isn’t the question — a compliant in-country real-time path is
The Vonage Video API’s endpoints resolve and its SDK initializes; a call between participants can be set up. None of that is the fact that decides whether you may run it for China. The deciding questions are whether the real-time service is carried by an operator licensed to provide it in the mainland, whether the live media and recordings had a lawful basis to leave the country — or whether they had to stay in the first place — and whether the app that embeds the SDK is ICP-filed. The lawful answer is not to make an offshore media server reachable, and not a concealed route that ships the media offshore anyway; it is to route the China real-time leg through a licensed in-country operator, keep the live media and recordings on an in-country path, obtain the Article 28/29 separate consent for the biometric recordings, and file the app. You can narrow what crosses — minimize, pseudonymize, record less, keep certain sessions out of certain flows — but as long as the media region is offshore, those choices decide only which offshore region and how much, not whether it crosses. Because whether you are a CII operator, which volume thresholds you cross, which transfer mechanism fits, and how the Article 24 position applies all turn on facts only your team and counsel hold, treat this page as a map of the exposure, not a ruling: settle the specifics with qualified counsel against what you actually run.
The lawful path — map, localize, deliver
Running the Vonage Video API for users in China the lawful way has a shape, and it keeps the API where it already runs. 21YunBox is a compliant overlay, not a migration, and for a platform like this we are a partner to it, not a competitor. We map your exposure first — inventorying the live media, recordings and transcripts, session metadata, participant identifiers, and chat the API carries, where each is processed and stored (an offshore region, with no mainland-China option), whether features such as Live Captions score or decide per user (Article 24), and the consent basis for the biometric recordings (Articles 28 and 29) — so you know exactly what counsel and a licensed in-country operator need to confirm. We localize what must stay on mainland soil — keeping the China participants’ live media and recordings on an in-country path and routing the real-time service through a licensed in-country operator, with the data minimized, the Article 28/29 and Article 13/23 consent in hand, and user-generated content moderated — a lawful, in-country path, never a concealed route that ships the media offshore. And we deliver every China-facing surface that embeds the SDK — the web app, the meeting page, the waiting room — over ICP-filed, in-country infrastructure (the 21YunBox Optimizer), in front of the stack you already run, with no rebuild and no second codebase. On the telecom leg our role is advisory and lighter: 21YunBox holds no China telecom license and is not a carrier; that license and the operator relationship sit with a licensed in-country provider and your counsel. The result is a real-time communication stack that runs legally and compliantly for your users in China. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
