Why 21YunBox Pricing Contact Log in
Talk to an expert Test your site in China

Does ZEGOCLOUD Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency

ZEGOCLOUD (即构科技) already runs real-time audio and video inside mainland China — its own docs list 'Mainland China' as an SDK region — so reachability isn't the question. Your app still needs an ICP filing, real-time comms in China ride a value-added telecom license a foreign API can't hold, and recordings are PIPL Article 28 biometric: a compliance-first look at the telecom-licensing, residency, and cross-border exposure.

Does ZEGOCLOUD work in China?

ZEGOCLOUD (即构科技) already operates inside mainland China — it runs real-time audio, video, and signaling on a licensed in-country footing — so reachability is not the question; the open doors are your app's own ICP filing, the value-added telecom license the service rides on, content moderation of the user audio and video, and the residency and consent duties for recordings.

ZEGOCLOUD's own developer docs list "Mainland China" among the regions an app can pin real-time media to, and its website carries a mainland ICP filing — so it is not the thing standing between your app and your users in China. What it carries is still participant personal information: live media, session metadata, identifiers, and any recordings or transcripts, which capture a speaker's voiceprint and participants' faces — sensitive biometric data under PIPL Article 28 (separate, specific consent under Article 29). Providing real-time communication in China is a value-added telecom business that needs a license a foreign API cannot hold directly, so the lawful route runs the service through a licensed in-country operator; and if your other systems pull that media or those recordings out of the mainland, that is a PIPL cross-border transfer (Articles 38–40). The lever is to keep the media and recordings in-country, route the real-time service through a licensed in-country operator, get the Article 28/29 consent, moderate the user content, and ICP-file the app — not to make an endpoint reachable, since it already is. 21YunBox is advisory on telecom licensing.

This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →

What ZEGOCLOUD's own documentation says about China

FactPrimary source
ZEGOCLOUD operates inside mainland China. ZEGOCLOUD's own developer documentation on geofencing lets an app restrict "the transmission of audio, video, and signaling data to a specific region," and lists "Mainland China" (code CN) among its supported regions — so its real-time network runs inside the mainland, and reachability is not the blocker. ZEGOCLOUD Docs, "Geofencing" (zegocloud.com), retrieved 2026-10-10
ZEGOCLOUD's own website carries a mainland ICP filing. ZEGOCLOUD's site footer displays a Chinese ICP record ("粤ICP备15113647号") and a Guangdong public-security filing — a licensed, in-country web presence of a kind a foreign-only provider cannot hold. Using a licensed domestic vendor can be part of the lawful path, but it does not discharge your app's own ICP filing or your PIPL data duties. ZEGOCLOUD security page footer (zegocloud.com/security), retrieved 2026-10-10
Providing real-time communication in China is a licensed telecom business. Offering real-time voice, video, or messaging capability to users in China is a value-added telecommunications business (增值电信业务) requiring an MIIT license a foreign API provider cannot hold directly under China's telecom foreign-investment rules; the lawful route runs the service through a licensed in-country operator. This sits alongside your PIPL and ICP duties. China Telecommunications Business Licensing Measures (MIIT) — 21YunBox compliance reference, retrieved 2026-10-10
Recordings are sensitive biometric data, and sending them offshore is a cross-border transfer. A recording or transcript captures a speaker's voiceprint and participants' faces — sensitive personal information under PIPL Article 28 (separate, specific consent under Article 29) that cannot be anonymized away; routing that media out of the mainland is a cross-border transfer under Articles 38–40, and for a CII or high-volume handler mainland data must stay in-country (Cybersecurity Law Article 39, formerly Article 37). Personal Information Protection Law of the PRC, Articles 28–29 & 38–40 (cac.gov.cn), retrieved 2026-10-10

Sources verified by the 21YunBox compliance team on 2026-10-10.

For a mainland-China audience, the reflexive “+China” question — will the SDK even connect? — is the wrong place to start with ZEGOCLOUD. ZEGOCLOUD (即构科技), the Shenzhen-based real-time engagement vendor, is not a foreign API reaching in from offshore: it operates a licensed in-country presence. Its own developer documentation lists “Mainland China” among the regions an app can pin real-time audio, video, and signaling data to, and its own website carries a mainland ICP filing (粤ICP备). So on reachability the honest answer is yes — ZEGOCLOUD is not the thing standing between your app and your users in China. The decision that actually matters is a compliance one, and it sits at the level of your app, not ZEGOCLOUD’s network: your app’s own ICP filing; the value-added telecom license that providing real-time communication in China rides on; content moderation of the user audio, video, and chat you carry; and the residency and consent duties for recordings, which capture a speaker’s voiceprint and participants’ faces — sensitive biometric personal information under PIPL. None of that is cleared by ZEGOCLOUD’s network reaching the mainland.

ZEGOCLOUD's developer documentation on geofencing listing the supported SDK regions, with a Mainland China (code CN) region among them, confirming it runs real-time media inside the mainland
"The currently supported regions for SDK configuration are as follows" — ZEGOCLOUD's own developer docs let an app pin real-time audio, video, and signaling data to a region, and list a Mainland China (code CN) region among them, so ZEGOCLOUD runs real-time media inside the mainland and reachability is not the question. Using a licensed domestic vendor can be part of the lawful path, but it does not discharge your own app's ICP filing or your PIPL data duties. Source: ZEGOCLOUD Docs — Geofencing

ZEGOCLOUD in China at a glance

What decides it In ZEGOCLOUD's own terms — and China's law
What it carries Real-time voice, video, interactive live streaming, and in-app chat — plus AI features (Conversational AI, Cloud ASR transcription, AI effects). The live streams, session metadata (who called whom, when, from where), participant identifiers, and any recordings or transcripts are participant personal information; a recording captures a speaker's voiceprint and participants' faces — sensitive biometric personal information under PIPL Article 28.
Where it runs Unlike most foreign real-time APIs, ZEGOCLOUD operates in-country: its docs list “Mainland China” as a selectable SDK region, and its site carries a mainland ICP filing — so reachability is settled. But if your other systems pull that media, those recordings, or the identifiers out of the mainland, that is a PIPL cross-border transfer (数据出境) by you, the handler, under Articles 38–40.
The telecom-licensing door Providing real-time voice/video/messaging capability to users in China is a value-added telecommunications business (增值电信业务) requiring an MIIT license a foreign API provider cannot hold directly under China's telecom foreign-investment rules. ZEGOCLOUD operates under that regime through its own licensed China entity; your commercial use still sits inside it, so the lawful route runs the real-time service through a licensed in-country operator.
Consent, moderation & residency Biometric recordings need separate, specific consent (PIPL Article 29) and a prior impact assessment, and — being biometric — cannot be anonymized away. User audio, video, and chat is user-generated content, so the Cybersecurity Law Article 49 (formerly Article 47) content-management duties apply; for a CII operator or high-volume handler, mainland-collected data must stay in the mainland under Article 39 (formerly Article 37). The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered these provisions — data localization from Article 37 to 39 and content management from Article 47 to 49 — with the substance unchanged.
Reachability isn't the axis ZEGOCLOUD already runs in the mainland, so the open doors are your app's ICP filing, the telecom licensing the service rides on, UGC moderation, and recording residency and consent. 21YunBox maps the exposure, routes the real-time service through a licensed in-country operator, keeps the media and recordings in-country, obtains the Article 28/29 consent, and ICP-files the app — advisory on telecom licensing, never through circumvention of any kind.

What you actually carry — live media, recordings and identifiers

A real-time session is never just a connection. Through ZEGOCLOUD your app carries live audio and video streams, screen shares, and in-app chat; the session metadata that says who called whom, when, and from where; the participant identifiers tied to real people; and any recordings or transcripts you keep. Every one of those is participant personal information under China’s Personal Information Protection Law. The recordings are the sharp edge: a saved call is a speaker’s voiceprint and the participants’ faces, which are sensitive biometric personal information under PIPL Article 28 — a higher bar that calls for a separate, specific consent (Article 29), a prior personal-information impact assessment, and, because biometrics identify the individual, cannot be scrubbed to anonymity and waved through.

ZEGOCLOUD also ships AI features — Conversational AI, Cloud ASR transcription, and AI effects. Where a feature transcribes, scores, or otherwise makes an automated decision about an individual user, that engages the automated-decision rules in PIPL Article 24 (transparency, fairness, and — where a decision significantly affects the person — a route to human review). The point for your architecture is simple: inventory what the API carries and where each piece is processed and stored. Because ZEGOCLOUD runs in the mainland, the media path can stay in-country; whether your whole data flow does — recordings, transcripts, logs, analytics, user records — is a question about your systems, not about ZEGOCLOUD’s network.

The first door is a license, not a connection. Offering real-time voice, video, or messaging capability to the public in China is a value-added telecommunications business (增值电信业务), and operating it requires an MIIT license that a foreign API provider cannot hold directly under China’s telecom foreign-investment rules. ZEGOCLOUD itself operates under that regime through a licensed China entity — which is exactly why reachability is not your problem — but the license attaches to the operator who offers the service to the public, which is you. The lawful route runs the real-time service through a licensed in-country operator (and the public app on a commercial ICP footing where it trades), a leg on which 21YunBox is advisory and holds no telecom license.

The second door is cross-border media. ZEGOCLOUD can keep the real-time path in the mainland, but the instant your own systems route or store participant media, recordings, chat content, identifiers, or call metadata outside the mainland — an offshore recording store, an overseas analytics pipeline, a non-China region on an adjacent service — that is a cross-border transfer by you under PIPL Articles 38–40 (数据出境): notice, a separate consent distinct from agreeing to use the feature, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). For a critical-information-infrastructure operator, or a handler above the state-set volume threshold, the mainland-collected personal information must be stored in the mainland — the data-localization duty in the Cybersecurity Law Article 39 (formerly Article 37).

The third door is recording consent and content duties. Because recordings are sensitive biometric data, you need the Article 28/29 separate consent and the impact assessment before you capture them — not a line buried in a terms-of-service click. And because the audio, video, and chat your users produce is user-generated content, a China-facing service carries real-name and real-time content-moderation duties under the Cybersecurity Law Article 49 (formerly Article 47) and the related network audio-video and live-streaming rules. Which permits and checks apply turns on exactly what your users do — one-to-one calls, group rooms, and public live broadcast are treated differently — so confirm the specifics against your real use case.

Reaching the endpoint isn’t the question — a compliant in-country real-time path is

ZEGOCLOUD already runs in China, so the open doors are ICP, telecom licensing, moderation, and residency — not getting a packet to the mainland. There is a clean way to stand a China-facing real-time feature up on a compliant footing, and it does not involve working around anything. Keep the participant media and recordings on an in-country path — ZEGOCLOUD’s mainland network is the enabler — and run the real-time service through a licensed in-country operator rather than offering it yourself; obtain the Article 28/29 consent for biometric recordings; moderate the user-generated content; and deliver the app that embeds the SDK on ICP-filed infrastructure. Localizing here means keeping the media on an in-country path — never a tunnel that ships it offshore anyway. This page publishes no first-party latency figure for ZEGOCLOUD, because speed is not the axis for a service that already operates in-country — licensing, residency, and consent are. Treat the specific licensing, consent, and residency questions as a risk map, not a verdict, and settle the specifics with counsel against what you actually ship.

The lawful path — map, localize, deliver

Our China team works on that footing and does three things. We map the exposure — the live media, recordings and transcripts (biometric), participant identifiers, chat content and session metadata the API carries, where each is processed and stored, whether any AI feature scores users (Article 24), and the consent basis (Articles 28/29 for recordings) — so you know exactly what counsel and the regulators need to see. We localize the setup onto a compliant in-country footing: keep the China-participant media and recordings in the mainland, route the real-time service through a licensed in-country telecom operator, minimize and pseudonymize what you can, obtain the Article 13/23 and Article 28/29 consent, and moderate the user content. And we deliver the app that embeds the SDK in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no re-platform. The result is a real-time feature that runs legally and compliantly for your users in China. What we never do — because ZEGOCLOUD already operates in the mainland and no one lawfully needs it — is route traffic around any block: 21YunBox never uses or suggests circumvention of any kind. 21YunBox is advisory on telecom licensing, a compliant overlay and partner, not a competitor to ZEGOCLOUD.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does ZEGOCLOUD work in mainland China?
Yes, on reachability. ZEGOCLOUD (即构科技) operates inside the mainland — its own developer docs list "Mainland China" as a selectable SDK region for real-time audio, video, and signaling, and its website carries a mainland ICP filing — so it is not the thing blocking your app from your users in China. The deciding question for a China-facing product is therefore not reachability but compliance: your app's own ICP filing, the value-added telecom license the service rides on, content moderation of the user audio and video, and the residency and consent duties for recordings under PIPL. There is no circumvention involved, and we never use or suggest it. Confirm the specifics with counsel.
What licenses does a China-facing real-time app using ZEGOCLOUD need?
As a public mainland service the app needs an ICP filing (usually a commercial ICP license). Providing real-time voice, video, or messaging capability is a value-added telecommunications business (增值电信业务) requiring an MIIT license a foreign API provider cannot hold directly, so the lawful route runs the real-time service through a licensed in-country operator — ZEGOCLOUD operates under that regime through its own licensed China entity, but the license attaches to whoever offers the service to the public, which is you. Interactive and live content adds real-name registration and content-moderation duties. Telecom carries foreign-investment limits, so settle the exact category with counsel before you build.
Where do ZEGOCLOUD recordings and call data have to live?
Recordings and transcripts are a speaker's voiceprint and participants' faces — sensitive biometric personal information under PIPL Article 28, needing a separate, specific consent (Article 29) and an impact assessment, and they cannot be anonymized away. Keeping the media and recordings on ZEGOCLOUD's mainland path keeps them in-country; if your other systems pull them offshore — a recording store, an analytics pipeline, a non-China region — that is a cross-border transfer under PIPL Articles 38–40, needing notice, a separate consent, and a transfer mechanism. For a critical-information-infrastructure operator or a high-volume handler, mainland-collected data must stay in the mainland (Cybersecurity Law Article 39, formerly Article 37). Whether your whole data flow stays in-country is an architecture question.

ARTICLES RELATED TO ZEGOCLOUD

Make Your Site Work inside the Great Firewall of China

Enter your information, and our staff will assist you in getting a 21YunBox account for China.

Make Your Site Work Within the Great Firewall of China
Make Your Site Work Within the Great Firewall of China

By clicking 'Get Started', I also agree to 21YunBox's Terms of Service and Privacy Policy.