Cloud computing in China sits at the intersection of telecommunications licensing, foreign-investment access, data and cybersecurity controls, and the customer contract. The correct route depends on what is supplied, where infrastructure sits, which entity operates it and who controls the customer relationship.
This guide focuses on cloud infrastructure and foreign-provider entry. General ICP, VATS and SaaS questions remain with the linked specialist guides.
Why cloud can fall within IDC licensing
The MIIT catalogue places internet resource collaboration within internet data centre (IDC) services. Its definition covers use of data-centre equipment and resources to provide on-demand, scalable and shared data storage, application-development environments, and application deployment and operations management. That wording captures core cloud-service patterns, but the actual technical and contractual service still controls classification.
Build the service map first
- List compute, storage, database, container, development, deployment, security, CDN and network functions.
- Identify the entity that owns or leases infrastructure, operates the platform, contracts, invoices and supports customers.
- Locate data centres, availability zones, CDN nodes, cross-border connections, administration and disaster recovery.
- Separate infrastructure supplied to customers from software, consulting and the provider's internal IT.
- Record whether the service is national, cross-provincial or confined to an approved pilot area.
Deployment and operating routes
| Route | Questions to resolve | Evidence to keep |
|---|---|---|
| Licensed mainland operator | Exact IDC/resource-collaboration scope, service area, facilities and customer-facing entity | Licence, architecture, facilities, contracts and service catalogue |
| Foreign-invested pilot operator | Whether the applicant, location, business and infrastructure fit the approved pilot and MIIT approval | Pilot approval, licence, ownership chain and geographic controls |
| Licensed local partner | Who genuinely controls and supplies the regulated service; whether branding, billing and operations match the licence | Responsibility matrix, licence verification, customer terms and operational records |
| Cross-border service | China-facing activity, accessibility, data transfers, contracts, sector rules and any locally supplied telecom function | Network/data flows, entity roles, transfer mechanism and customer disclosures |
| Private or dedicated environment | Whether the provider supplies software only or also managed infrastructure, storage, compute or network resources | Statement of work, asset control, access records and service boundaries |
Foreign-provider access and the pilot route
The national foreign-investment screen and the telecommunications rules remain the baseline. In 2024 MIIT launched expanded VATS opening pilots in Beijing, Shanghai, Hainan and Shenzhen. For approved pilot areas, the notice removes foreign-equity limits for specified services including IDC, CDN, ISP and online data and transaction processing. A foreign-invested enterprise must still obtain the required MIIT pilot approval and operate within the approval and applicable rules. The pilot is not an automatic national exemption.
Data and cybersecurity workstream
- Define controller/handler, processor, infrastructure-provider and subprocessor roles by actual control.
- Map customer content, account data, logs, telemetry, support records and administrator access.
- Determine mainland storage, remote access, backup and cross-border transfer routes.
- Allocate incident response, regulator cooperation, deletion, portability and exit duties.
- Screen MLPS, critical-information-infrastructure and sector-specific requirements where facts warrant.
- Keep security measures and customer promises aligned with the deployed architecture.
Customer and partner contract controls
- Name the actual operator and describe the licensed service accurately.
- State data locations, access model, subprocessors and cross-border dependencies.
- Set availability, maintenance, support, business-continuity and recovery commitments.
- Allocate security configuration, identity management, encryption and incident duties.
- Control acceptable use, prohibited content, suspension and lawful-request handling.
- Plan export, deletion, transition assistance and service termination.
- Align reseller and partner language with operational control; avoid paper structures that contradict the facts.
Launch evidence pack
- Service classification memorandum tied to current architecture.
- Entity and ultimate-ownership chart.
- Licence, pilot and geographic-scope verification.
- Infrastructure, network and data-flow diagrams.
- Customer, partner, data-processing and intercompany agreements.
- ICP/app filings and sector approvals where relevant.
- Security, incident, complaint and regulatory-contact procedures.
- Change-control trigger list for new features, regions, entities and infrastructure.
Connected guides
- China ICP, VATS & Telecom Licensing Guide
- SaaS in China: Legal, Data & Licensing Compliance
- China ICP Filing Guide
- China Data Privacy & Cybersecurity Guide
- China FDI & National Security Guide
Official sources and version control
- MIIT Telecommunications Business Classification Catalogue
- MIIT explanation of IDC and internet resource collaboration
- MIIT 2024 expanded VATS opening pilot notice
- MIIT notice confirming launch of the four-area pilot
- Foreign-invested telecommunications enterprise provisions
- 2024 national foreign-investment negative list
Version note: Sources checked 30 August 2026. Confirm pilot geography, approvals, later amendments and current authority practice for the actual service.
General information only, not legal advice. Obtain advice for the actual service, architecture, entity, ownership and deployment.


