Does ZEGOCLOUD Work in China? PIPL Cross-Border, Telecom Licensing & Data Residency
ZEGOCLOUD (即构科技) already runs real-time audio and video inside mainland China — its own docs list 'Mainland China' as an SDK region — so reachability isn't the question. Your app still needs an ICP filing, real-time comms in China ride a value-added telecom license a foreign API can't hold, and recordings are PIPL Article 28 biometric: a compliance-first look at the telecom-licensing, residency, and cross-border exposure.
Does ZEGOCLOUD work in China?
ZEGOCLOUD (即构科技) already operates inside mainland China — it runs real-time audio, video, and signaling on a licensed in-country footing — so reachability is not the question; the open doors are your app's own ICP filing, the value-added telecom license the service rides on, content moderation of the user audio and video, and the residency and consent duties for recordings.
ZEGOCLOUD's own developer docs list "Mainland China" among the regions an app can pin real-time media to, and its website carries a mainland ICP filing — so it is not the thing standing between your app and your users in China. What it carries is still participant personal information: live media, session metadata, identifiers, and any recordings or transcripts, which capture a speaker's voiceprint and participants' faces — sensitive biometric data under PIPL Article 28 (separate, specific consent under Article 29). Providing real-time communication in China is a value-added telecom business that needs a license a foreign API cannot hold directly, so the lawful route runs the service through a licensed in-country operator; and if your other systems pull that media or those recordings out of the mainland, that is a PIPL cross-border transfer (Articles 38–40). The lever is to keep the media and recordings in-country, route the real-time service through a licensed in-country operator, get the Article 28/29 consent, moderate the user content, and ICP-file the app — not to make an endpoint reachable, since it already is. 21YunBox is advisory on telecom licensing.
This is a risk map, not a verdict — settle the specifics with counsel. Our China team can map your exposure →
What ZEGOCLOUD's own documentation says about China
| Fact | Primary source |
|---|---|
| ZEGOCLOUD operates inside mainland China. ZEGOCLOUD's own developer documentation on geofencing lets an app restrict "the transmission of audio, video, and signaling data to a specific region," and lists "Mainland China" (code CN) among its supported regions — so its real-time network runs inside the mainland, and reachability is not the blocker. | ZEGOCLOUD Docs, "Geofencing" (zegocloud.com), retrieved 2026-10-10 |
| ZEGOCLOUD's own website carries a mainland ICP filing. ZEGOCLOUD's site footer displays a Chinese ICP record ("粤ICP备15113647号") and a Guangdong public-security filing — a licensed, in-country web presence of a kind a foreign-only provider cannot hold. Using a licensed domestic vendor can be part of the lawful path, but it does not discharge your app's own ICP filing or your PIPL data duties. | ZEGOCLOUD security page footer (zegocloud.com/security), retrieved 2026-10-10 |
| Providing real-time communication in China is a licensed telecom business. Offering real-time voice, video, or messaging capability to users in China is a value-added telecommunications business (增值电信业务) requiring an MIIT license a foreign API provider cannot hold directly under China's telecom foreign-investment rules; the lawful route runs the service through a licensed in-country operator. This sits alongside your PIPL and ICP duties. | China Telecommunications Business Licensing Measures (MIIT) — 21YunBox compliance reference, retrieved 2026-10-10 |
| Recordings are sensitive biometric data, and sending them offshore is a cross-border transfer. A recording or transcript captures a speaker's voiceprint and participants' faces — sensitive personal information under PIPL Article 28 (separate, specific consent under Article 29) that cannot be anonymized away; routing that media out of the mainland is a cross-border transfer under Articles 38–40, and for a CII or high-volume handler mainland data must stay in-country (Cybersecurity Law Article 39, formerly Article 37). | Personal Information Protection Law of the PRC, Articles 28–29 & 38–40 (cac.gov.cn), retrieved 2026-10-10 |
Sources verified by the 21YunBox compliance team on 2026-10-10.
For a mainland-China audience, the reflexive “+China” question — will the SDK even connect? — is the wrong place to start with ZEGOCLOUD. ZEGOCLOUD (即构科技), the Shenzhen-based real-time engagement vendor, is not a foreign API reaching in from offshore: it operates a licensed in-country presence. Its own developer documentation lists “Mainland China” among the regions an app can pin real-time audio, video, and signaling data to, and its own website carries a mainland ICP filing (粤ICP备). So on reachability the honest answer is yes — ZEGOCLOUD is not the thing standing between your app and your users in China. The decision that actually matters is a compliance one, and it sits at the level of your app, not ZEGOCLOUD’s network: your app’s own ICP filing; the value-added telecom license that providing real-time communication in China rides on; content moderation of the user audio, video, and chat you carry; and the residency and consent duties for recordings, which capture a speaker’s voiceprint and participants’ faces — sensitive biometric personal information under PIPL. None of that is cleared by ZEGOCLOUD’s network reaching the mainland.
ZEGOCLOUD in China at a glance
| What decides it | In ZEGOCLOUD's own terms — and China's law |
|---|---|
| What it carries | Real-time voice, video, interactive live streaming, and in-app chat — plus AI features (Conversational AI, Cloud ASR transcription, AI effects). The live streams, session metadata (who called whom, when, from where), participant identifiers, and any recordings or transcripts are participant personal information; a recording captures a speaker's voiceprint and participants' faces — sensitive biometric personal information under PIPL Article 28. |
| Where it runs | Unlike most foreign real-time APIs, ZEGOCLOUD operates in-country: its docs list “Mainland China” as a selectable SDK region, and its site carries a mainland ICP filing — so reachability is settled. But if your other systems pull that media, those recordings, or the identifiers out of the mainland, that is a PIPL cross-border transfer (数据出境) by you, the handler, under Articles 38–40. |
| The telecom-licensing door | Providing real-time voice/video/messaging capability to users in China is a value-added telecommunications business (增值电信业务) requiring an MIIT license a foreign API provider cannot hold directly under China's telecom foreign-investment rules. ZEGOCLOUD operates under that regime through its own licensed China entity; your commercial use still sits inside it, so the lawful route runs the real-time service through a licensed in-country operator. |
| Consent, moderation & residency | Biometric recordings need separate, specific consent (PIPL Article 29) and a prior impact assessment, and — being biometric — cannot be anonymized away. User audio, video, and chat is user-generated content, so the Cybersecurity Law Article 49 (formerly Article 47) content-management duties apply; for a CII operator or high-volume handler, mainland-collected data must stay in the mainland under Article 39 (formerly Article 37). The 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered these provisions — data localization from Article 37 to 39 and content management from Article 47 to 49 — with the substance unchanged. |
| Reachability isn't the axis | ZEGOCLOUD already runs in the mainland, so the open doors are your app's ICP filing, the telecom licensing the service rides on, UGC moderation, and recording residency and consent. 21YunBox maps the exposure, routes the real-time service through a licensed in-country operator, keeps the media and recordings in-country, obtains the Article 28/29 consent, and ICP-files the app — advisory on telecom licensing, never through circumvention of any kind. |
What you actually carry — live media, recordings and identifiers
A real-time session is never just a connection. Through ZEGOCLOUD your app carries live audio and video streams, screen shares, and in-app chat; the session metadata that says who called whom, when, and from where; the participant identifiers tied to real people; and any recordings or transcripts you keep. Every one of those is participant personal information under China’s Personal Information Protection Law. The recordings are the sharp edge: a saved call is a speaker’s voiceprint and the participants’ faces, which are sensitive biometric personal information under PIPL Article 28 — a higher bar that calls for a separate, specific consent (Article 29), a prior personal-information impact assessment, and, because biometrics identify the individual, cannot be scrubbed to anonymity and waved through.
ZEGOCLOUD also ships AI features — Conversational AI, Cloud ASR transcription, and AI effects. Where a feature transcribes, scores, or otherwise makes an automated decision about an individual user, that engages the automated-decision rules in PIPL Article 24 (transparency, fairness, and — where a decision significantly affects the person — a route to human review). The point for your architecture is simple: inventory what the API carries and where each piece is processed and stored. Because ZEGOCLOUD runs in the mainland, the media path can stay in-country; whether your whole data flow does — recordings, transcripts, logs, analytics, user records — is a question about your systems, not about ZEGOCLOUD’s network.
Three doors: a telecom license, cross-border media, and recording consent
The first door is a license, not a connection. Offering real-time voice, video, or messaging capability to the public in China is a value-added telecommunications business (增值电信业务), and operating it requires an MIIT license that a foreign API provider cannot hold directly under China’s telecom foreign-investment rules. ZEGOCLOUD itself operates under that regime through a licensed China entity — which is exactly why reachability is not your problem — but the license attaches to the operator who offers the service to the public, which is you. The lawful route runs the real-time service through a licensed in-country operator (and the public app on a commercial ICP footing where it trades), a leg on which 21YunBox is advisory and holds no telecom license.
The second door is cross-border media. ZEGOCLOUD can keep the real-time path in the mainland, but the instant your own systems route or store participant media, recordings, chat content, identifiers, or call metadata outside the mainland — an offshore recording store, an overseas analytics pipeline, a non-China region on an adjacent service — that is a cross-border transfer by you under PIPL Articles 38–40 (数据出境): notice, a separate consent distinct from agreeing to use the feature, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). For a critical-information-infrastructure operator, or a handler above the state-set volume threshold, the mainland-collected personal information must be stored in the mainland — the data-localization duty in the Cybersecurity Law Article 39 (formerly Article 37).
The third door is recording consent and content duties. Because recordings are sensitive biometric data, you need the Article 28/29 separate consent and the impact assessment before you capture them — not a line buried in a terms-of-service click. And because the audio, video, and chat your users produce is user-generated content, a China-facing service carries real-name and real-time content-moderation duties under the Cybersecurity Law Article 49 (formerly Article 47) and the related network audio-video and live-streaming rules. Which permits and checks apply turns on exactly what your users do — one-to-one calls, group rooms, and public live broadcast are treated differently — so confirm the specifics against your real use case.
Reaching the endpoint isn’t the question — a compliant in-country real-time path is
ZEGOCLOUD already runs in China, so the open doors are ICP, telecom licensing, moderation, and residency — not getting a packet to the mainland. There is a clean way to stand a China-facing real-time feature up on a compliant footing, and it does not involve working around anything. Keep the participant media and recordings on an in-country path — ZEGOCLOUD’s mainland network is the enabler — and run the real-time service through a licensed in-country operator rather than offering it yourself; obtain the Article 28/29 consent for biometric recordings; moderate the user-generated content; and deliver the app that embeds the SDK on ICP-filed infrastructure. Localizing here means keeping the media on an in-country path — never a tunnel that ships it offshore anyway. This page publishes no first-party latency figure for ZEGOCLOUD, because speed is not the axis for a service that already operates in-country — licensing, residency, and consent are. Treat the specific licensing, consent, and residency questions as a risk map, not a verdict, and settle the specifics with counsel against what you actually ship.
The lawful path — map, localize, deliver
Our China team works on that footing and does three things. We map the exposure — the live media, recordings and transcripts (biometric), participant identifiers, chat content and session metadata the API carries, where each is processed and stored, whether any AI feature scores users (Article 24), and the consent basis (Articles 28/29 for recordings) — so you know exactly what counsel and the regulators need to see. We localize the setup onto a compliant in-country footing: keep the China-participant media and recordings in the mainland, route the real-time service through a licensed in-country telecom operator, minimize and pseudonymize what you can, obtain the Article 13/23 and Article 28/29 consent, and moderate the user content. And we deliver the app that embeds the SDK in-country on ICP-filed infrastructure — the 21YunBox Optimizer — in front of the stack you already run, with no rebuild and no re-platform. The result is a real-time feature that runs legally and compliantly for your users in China. What we never do — because ZEGOCLOUD already operates in the mainland and no one lawfully needs it — is route traffic around any block: 21YunBox never uses or suggests circumvention of any kind. 21YunBox is advisory on telecom licensing, a compliant overlay and partner, not a competitor to ZEGOCLOUD.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law — data localization (Article 39, formerly Article 37)
- China’s Personal Information Protection Law (PIPL)
- How to get an ICP filing for China
