Skip to main content
China Legal Guides · National framework

Cloud Computing in China: Licensing, Foreign Providers & Data

China cloud computing legal guide covering IDC and internet-resource-collaboration licensing, foreign-provider pilot routes, deployment, data and contracts.

63lawyer profiles listed
Updated7 Sep 2026
AudienceForeign businesses & individuals
Author China Legal Portal Editorial · Reviewer Wang Yong · Last reviewed · 4 min read · Editorial policy · AI content policy · Disclaimer · Not legal advice — confirm current rules with counsel and authorities

At a glance

Practice: typical process stages

Four high-level stages — details and local variations are in the guide below.

  1. FrameMap facts to PRC rules
  2. PlanOptions, risks & timeline
  3. ExecuteFilings, contracts, forums
  4. ReviewCompliance & next steps
City hubs

Local guides & lawyers

Drill into city × practice hubs where available, or open the city legal market guide.

Legal planning desk with source documents, authority records and evidence file
Working file · authority, workflow and evidence

Cloud computing in China sits at the intersection of telecommunications licensing, foreign-investment access, data and cybersecurity controls, and the customer contract. The correct route depends on what is supplied, where infrastructure sits, which entity operates it and who controls the customer relationship.

This guide focuses on cloud infrastructure and foreign-provider entry. General ICP, VATS and SaaS questions remain with the linked specialist guides.

Why cloud can fall within IDC licensing

The MIIT catalogue places internet resource collaboration within internet data centre (IDC) services. Its definition covers use of data-centre equipment and resources to provide on-demand, scalable and shared data storage, application-development environments, and application deployment and operations management. That wording captures core cloud-service patterns, but the actual technical and contractual service still controls classification.

Build the service map first

  1. List compute, storage, database, container, development, deployment, security, CDN and network functions.
  2. Identify the entity that owns or leases infrastructure, operates the platform, contracts, invoices and supports customers.
  3. Locate data centres, availability zones, CDN nodes, cross-border connections, administration and disaster recovery.
  4. Separate infrastructure supplied to customers from software, consulting and the provider's internal IT.
  5. Record whether the service is national, cross-provincial or confined to an approved pilot area.

Deployment and operating routes

RouteQuestions to resolveEvidence to keep
Licensed mainland operatorExact IDC/resource-collaboration scope, service area, facilities and customer-facing entityLicence, architecture, facilities, contracts and service catalogue
Foreign-invested pilot operatorWhether the applicant, location, business and infrastructure fit the approved pilot and MIIT approvalPilot approval, licence, ownership chain and geographic controls
Licensed local partnerWho genuinely controls and supplies the regulated service; whether branding, billing and operations match the licenceResponsibility matrix, licence verification, customer terms and operational records
Cross-border serviceChina-facing activity, accessibility, data transfers, contracts, sector rules and any locally supplied telecom functionNetwork/data flows, entity roles, transfer mechanism and customer disclosures
Private or dedicated environmentWhether the provider supplies software only or also managed infrastructure, storage, compute or network resourcesStatement of work, asset control, access records and service boundaries

Foreign-provider access and the pilot route

The national foreign-investment screen and the telecommunications rules remain the baseline. In 2024 MIIT launched expanded VATS opening pilots in Beijing, Shanghai, Hainan and Shenzhen. For approved pilot areas, the notice removes foreign-equity limits for specified services including IDC, CDN, ISP and online data and transaction processing. A foreign-invested enterprise must still obtain the required MIIT pilot approval and operate within the approval and applicable rules. The pilot is not an automatic national exemption.

Data and cybersecurity workstream

  • Define controller/handler, processor, infrastructure-provider and subprocessor roles by actual control.
  • Map customer content, account data, logs, telemetry, support records and administrator access.
  • Determine mainland storage, remote access, backup and cross-border transfer routes.
  • Allocate incident response, regulator cooperation, deletion, portability and exit duties.
  • Screen MLPS, critical-information-infrastructure and sector-specific requirements where facts warrant.
  • Keep security measures and customer promises aligned with the deployed architecture.

Customer and partner contract controls

  • Name the actual operator and describe the licensed service accurately.
  • State data locations, access model, subprocessors and cross-border dependencies.
  • Set availability, maintenance, support, business-continuity and recovery commitments.
  • Allocate security configuration, identity management, encryption and incident duties.
  • Control acceptable use, prohibited content, suspension and lawful-request handling.
  • Plan export, deletion, transition assistance and service termination.
  • Align reseller and partner language with operational control; avoid paper structures that contradict the facts.

Launch evidence pack

  1. Service classification memorandum tied to current architecture.
  2. Entity and ultimate-ownership chart.
  3. Licence, pilot and geographic-scope verification.
  4. Infrastructure, network and data-flow diagrams.
  5. Customer, partner, data-processing and intercompany agreements.
  6. ICP/app filings and sector approvals where relevant.
  7. Security, incident, complaint and regulatory-contact procedures.
  8. Change-control trigger list for new features, regions, entities and infrastructure.

Connected guides

Official sources and version control

Version note: Sources checked 30 August 2026. Confirm pilot geography, approvals, later amendments and current authority practice for the actual service.

General information only, not legal advice. Obtain advice for the actual service, architecture, entity, ownership and deployment.

Legal source archive with indexed legislation and official records
Source register · primary authorities and verification
Sources & trust

How to use this guide

Editorial, AI and verification policies

This page is general information for orientation. It is not legal advice and does not create an attorney–client relationship.

Review the Editorial Policy, AI Content Policy, and Lawyer Verification Policy.

Consultation preparation

What to prepare before contacting counsel

Send a focused first package so counsel can check conflicts, understand scope, and identify urgent deadlines.

  • A concise timeline and the result you want to achieve.
  • Names of all parties and affiliates for a conflict check.
  • Key contracts, notices, correspondence, filings, or decisions.
  • Known deadlines, preferred language, location, and budget constraints.
Directory

Practice lawyer profiles

China-based listings shown first. Review profiles for practice, then request a free initial consultation.

Status shown per profileFree initial consultationChina-first directory sort

Browse practice directory →

Cross-border legal details arranged for a prepared counsel enquiry
Next route · prepared enquiry

Move from orientation to a properly prepared legal brief.

Bring the parties, objective, relevant documents, chronology, known deadlines and the decision you need counsel to make.

Prepare your legal enquiry →

Need counsel on practice?

Review listed lawyer profiles and request a free initial consultation. No obligation.