Language

All About Face: Use of Facial Recognition and Legal Restrictions

All About Face: Use of Facial Recognition and Legal Restrictions

 

Author: Yingying Zhu, Partner of Beijing MingDun Law Firm

Email: zhu.yingying@mdlaw.cn

Date: November 10, 2021

 

Introduction

From public places laden with facial verification cameras to residential buildings that shut strangers out with facial identification requirements, facial recognition technology is being used almost everywhere in China which has contributed to the low criminal rates and high level of public security, earning China the reputation as one of the safest places in the world to travel around.[1] Beyond the bright side, there has been at least one dark side to the overwhelming use of cameras-the possible leaks of people’s biometric identification information to outlaws and hackers. Nowadays, the public becomes increasingly concerned about providing their facial data to various service providers. The calls for safeguarding and curbing excessive uses of people’s facial data are on the rise.

 

Background

On November 1st, 2021, China’s first comprehensive data privacy law, the Personal Information Protection Law of the People’s Republic of China (the “PIPL”), has become effective. The PIPL basically requires that the operators of websites, mobile phone applications or any other technologies doing data collection and processing should obtain consent from users in order to collect/process the users’ data.

To address the increasing public concerns of the necessity to curb the abuses of people’s biometric data, the PIPL specifically regulates the collection of biometric data and the use of facial recognition technology in public areas.

Apart from the enactment of the PIPL, there was a lawsuit in Hangzhou stemming from dispute over the use of facial recognition equipment and a judicial interpretation on the same subject promulgated by the China Supreme People’s Court.

 

What is facial recognition?

No definition is provided under the PIPL or the judicial interpretation. According to The Future of Privacy Forum, the Facial recognition (currently defined to include facial verification and facial identification) means the technology that creates, collects, compares and retains facial templates that are identified or identifiable to particular individuals.[2]

Facial verification means a task where the facial recognition system confirms an individual’s claimed identity by comparing the template generated from a submitted facial image with a specific known template generated from a previously enrolled facial image. This process is also called one-to-one verification, or authentication.[3] 

Facial Identification means searching a database for a reference matching a submitted facial template and returning a corresponding identity, also known as “one-to-many” matching.[4]

From the above definitions, it can be deduced that facial recognition technology is not an equivalent of the conventional public camera surveillance[5] because it involves more than passive facial scanning and recording. If the usage of public surveillance camera involves no creation of personably identifiable facial templates which are identified or linked, or identifiable or linkable to individuals, it would neither constitute “facial recognition” nor arouse the same type of privacy concerns discussed under this article.

 

PIPL on facial recognition

 

1) processing of facial recognition data

Under the PIPL, facial recognition data, being a type of the biometric identification information, are classified under a specific category of information, sensitive personal information,[6] that must be treated with the following extra safeguarding:

1)   Personal information processors may not process sensitive personal information unless there are specific purposes and sufficient necessity, and strict protection measures are taken (Art. 28);

2)   An individual's separate consent shall be obtained for processing his or her sensitive personal information. Where any law or administrative regulation provides that written consent shall be obtained for processing sensitive personal information, such provision shall prevail (Art. 29); and

3)   To process sensitive personal information, personal information processors shall, notify individuals of the following:

    (a) identity of the processor (Art. 17);

    (b) purposes and methods of processing of personal information, categories of personal information to be processed, and the retention periods (Art. 17);

    (c) methods and procedures for individuals to exercise their rights (Art. 17);

    (d) necessity of the processing of sensitive personal information (Art. 30); and

    (e) the impacts on individuals’ rights and interests, except that it is not required by this Law to so notify (Art. 30).

 

2) use of facial recognition technology in public areas

Regarding the use of facial recognition technology in public areas, the PIPL provides as follows:

1)   The installation of image collection or personal identification equipment in public areas shall be necessary for maintaining public security and comply with relevant regulations issued by the state (Art. 26);

2)   Conspicuous signs shall be erected (Art. 26); and

3)   The collected personal images and identification information can only be used for the purpose of maintaining public security, and shall not be used for other purposes, except with the separate consent of individuals (Art. 26).

The above provisions basically provide that the use of facial recognition technology in public areas is only allowed for the purpose of maintaining public security where conspicuous signs shall be erected. It cannot be used for marketing, targeted advertising or any other commercial purposes, unless separate consent of individuals has been obtained.

One has but one face. Facial information is of a unique and unchangeable character for the individuals. As improper disclosures of facial data can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that facial data be specifically categorized and appropriately protected. The PIPL’s position in regulating the use of facial recognition data echoes with that of the GDPR. [7]

 

A GDPR decision on the use of facial recognition

A decision handed down in August 2019 under the GDPR could shed some light on the position taken by the GDPR towards the use of facial recognition data. The Swedish Data Protection Authority (“DPA”) has imposed a fine of approximately 20,000 euros upon a municipality for using facial recognition technology to monitor the attendance of students in school. The school in northern Sweden has conducted a trial program using facial recognition to keep track of students’ attendance in school. The students’ guardians were asked to give and gave explicit consent and they also had the option of excluding their child from the program. The school has based the processing on consent but the Swedish DPA considers that consent was not a valid legal basis given the clear imbalance between the data subject and the controller. The Swedish DPA concluded the school has processed sensitive biometric data unlawfully and failed to do an adequate impact assessment including seeking prior consultation with the Swedish DPA. [8]

Under the GDPR, biometric data, [9] including that generated through facial recognition technology, is protected as a special category of personal data since it is uniquely and strongly identifying to a person. The GDPR prohibits the processing of such data unless there is explicit consent, a legal obligation or public interest. In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation.[10] Judging from the clear imbalance between the students/their guardians and the school in the above case, the Swedish Data Protection Authority held the school liable under the GDPR for unlawfully processing the students’ facial data.

 

First lawsuit over facial recognition in China

Interestingly in contrast with the Swedish school case, also happened in 2019 and before the enactment of the PIPL, a court in Hangzhou ruled in the country’s first facial recognition lawsuit that the use of facial recognition technology for admission to a local safari park constituted a breach of the contract between the plaintiff and the Park.

Guo Bing, an associate law professor in Hangzhou city, filed a civil lawsuit against Hangzhou Safari Park in late 2019 after the Park required a facial identification process for his annual membership pass. He argued the Hangzhou Safari Park has no legal basis to collect visitors’ biometric data. Both courts in the first instance and second instance ruled in favor of Guo Bing, ordering the Park to refund him and delete his facial data and fingerprints.[11]

However, the courts’ judgements are criticized for being too narrow and also for the failure to touch on the legitimacy of the Park’s overbearing policy which mandated facial identification for entry. From the perspective of contract law, the courts of first and second instance ruled that the Park’s requirement of facial recognition to enter the park does not have legal effect on Guo contractually, but the courts avoided the review of the arbitrary clause that 'users who have not registered their face for facial recognition will not be able to enter the park ever'. That is however the key claim in Guo’s lawsuit against the Park.

 The above being said, Guo’s case is still significant as the first lawsuit to challenge the commercial use of facial recognition technology. Citing Guo’s case, China’s Supreme People’s Court (“SPC”) announced that consumers’ privacy must be protected from unwarranted face tracking,[12] a signal that China is tightening the leash on the facial recognition industry.

 

Judicial interpretation on use of facial recognition

On July 28, 2021 the SPC promulgated the Provisions (the “Provisions”) on several issues concerning the application of law in the trial of civil cases relating to processing of personal information by using the facial recognition technology.[13] The Provisions came into force on August 1, 2021.

The Provisions apply to civil cases that involve facial recognition technology. The Provisions set forth that hotels, shopping malls, airports and other commercial venues should not use facial recognition in violation of the laws and administrative regulations. The use of the technology is only allowed when there is clear legal basis and cannot exceed what is necessary, and companies must take measures to protect the facial data. The Provisions also provide that consent is not a valid legal basis if companies denied providing products or services on the condition that a consent is given, unless the processing of facial information is necessary for the provision of such products or services. Property management companies must obtain the consent of the residents before using facial recognition. In case of refusal of consent, alternative verification methods must be offered.

While the Provisions are not clear on what counts as necessary use, the possibility of penalties from lawsuits is likely to curb some excessive uses of people’s facial data. The Provisions also specifies a mechanism for the public to sue if their privacy has been violated and option for injunction is also available in cases where irreparable harm would be caused without an injunctive relief.

 

Key Takeaways

·   Thorough impact assessment should be conducted prior to the launching of any facial recognition implementation.

·   For businesses to stay compliant with the PIPL, despite the scale and the intent of the use of facial recognition technology, regulatory and professional opinions have to be consulted.

·   Consent should not provide a valid legal ground for the processing of personal data in cases where there is a clear imbalance between the data subject and the controller.

·   Consent should be invalid if there is an “opt-in-or-leave” situation, unless the processing of facial data is absolutely necessary for the products or services offered.

 

Conclusion

After the enactment of the PIPL and the China Supreme People’s Court’s promulgation of the Provisions, it remains to be seen how the administration will enforce these rules, how the courts will adjudicate in lawsuits involving facial recognition and whether such enforcement/adjudication will actually curb the abuses of facial recognition technology. For whatever the future holds, one thing is certain: businesses must realize that to advance any frontier technology, building public trust is essential to the effectuation that the public can enjoy the benefits offered by the technology. Before the public can entrust their sensitive personal data to the facial recognition businesses, they must have confidence that the use is with necessity, and that the use is lawful, fair, transparent and also safely guarded.



 



[1] See https://www.globaltimes.cn/content/1067645.shtml.

[2] See The Future of Privacy Forum, Privacy Principles for Facial-Recognition Technology in Commercial Applications (September 2018), https://fpf.org/wp-content/uploads/2019/03/Final-Privacy-Principles-Edits-1.pdf.

[3] Ibid.

[4] Ibid.

[5] Closed-circuit television (CCTV) or video surveillance is camera systems used to transmit signals to a specific location often with visualization on a limited number of televisions or computer monitors. See Hong Kong Lawyer, CCTV and Privacy Rights (December 2019).

[6]  Under the PIPL, sensitive personal information is defined as “the personal information of which the leakage or illegal use   could easily lead to the violation of the personal dignity of a natural person or harm to personal or property safety, including    information on biometric identification, religious beliefs, specific identity, health care, financial accounts, and personal whereabouts, and personal information of minors under the age of fourteen.” (Art. 28).

[7] The General Data Protection Regulation (EU) 2016/679.

[8] See https://edpb.europa.eu/news/national-news/2019/facial-recognition-school-renders-swedens-first-gdpr-fine_sv.

[9] GDPR defines “biometric data” as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data. See https://gdpr-info.eu/art-4-gdpr/.

[10] See https://www.privacy-regulation.eu/en/recital-43-GDPR.htm.

[11] See https://xw.qq.com/cmsid/20201120A0EPDD00.

[12] See https://m.thepaper.cn/baijiahao_13819929.

[13] See http://en.pkulaw.cn/Display.aspx?Lib=law&Id=36687&keyword.


  • 相关资讯 More
  • 点击次数: 1000001
    2025 - 08 - 22
    作者:刘艳玲随着科技的发展,越来越多的发明不再局限于单一技术领域,而是跨越多个技术领域形成创新,这种跨领域的技术创新会产生全新的商业价值和应用场景。先来假设一个场景,假如你或你的团队深耕大健康产业,你们注意到中医理疗市场2019年规模达2920亿元,到了2023年市场规模已经初步统计超过7000亿元,未来增长空间巨大,因此希望在中医理疗市场拓展业务。相比于传统的针灸、推拿、艾灸、拔罐和刮痧等保健方法,你们想结合现代技术提供有市场竞争力的产品和服务。人工智能技术和机器人技术是未来的发展方向,因此看好与电或磁相关的中医理疗产品和服务。上面描述的这类技术创新就涉及多个技术领域,需要了解甚至掌握中医、信息通信技术(ICT)和机械设计等相关知识才能实现创新,很明显这需要团队合作,因为一个人甚至一个团队不可能具备这么多技术领域的知识储备。而且,可能还需要能提供相应技术和/或产品部件的外部供应商支持。通常来说,技术专家大多熟悉的是自己从事的技术领域的最新发展,较少了解其他领域的技术及其发展,希望横跨多个技术领域进行研发创新并商业化落地,那么熟悉专利检索和分析是非常必要的。下面以这个场景为例来介绍专利检索和分析。 第一步,学习和了解业务方向的技术和市场发展情况,确定专利检索主题。随着医学的发展,现代科学已发现生物电和人体细胞、血液、经络和神经都有关系。中医讲究气血循环、经络畅通,气血之“气”为人体之“电气”,即人体生物电。经络是导电的,也即“电气”会循着人体经络流动。因此,将专利检索主题初步确定为利用电技术作用于人体经络实现理疗的发明创新。第二步,进行初步专利检索尝试。这里我们选择国家知识产权局提供的公共专利检索数据库https://pss-system.cponline.cnipa.gov.cn/conventionalSearch为例进行说明,当然你也可以选择其他免费或收费的商业专利数...
  • 点击次数: 1000000
    2025 - 08 - 15
    作者:张琳自我国上世纪80年代开始推行社会保险制度、到90年代各地陆续实施了社会保险制度以来,存在大量用人单位未为劳动者缴纳社会保险的情况。很多劳动者当时并未意识到社会保险的意义和价值,同时每月还可以多到手一些工资,因此并未对此提出质疑。随着人们法律意识的增强,许多劳动者开始认识到了社会保险在养老、看病等方面的价值,开始运用法律武器维护自身的权益。特别是将于2025年9月1日生效的《最高人民法院关于审理劳动争议案件适用法律问题的解释(二)》再一次将社保问题推到了风口浪尖。劳动者社保维权的其中一种方式是向社保部门投诉要求用人单位补缴在职期间的社会保险。但是,如果劳动者无法提供与用人单位的劳动合同,社保部门就无法认定双方之间存在劳动关系,进而无法启动社会保险稽核程序。在这种情况下,劳动者就需要先通过劳动仲裁/诉讼程序确认其与用人单位之间存在劳动关系,之后再带着确认双方劳动关系的裁决书/判决书向社保部门投诉。但是,由于有些劳动者已离职多年,时过境迁,有些用人单位已经注销了,这种情况下劳动者还能否通过劳动仲裁/诉讼主张确认劳动关系?把谁作为被申请人/被告?确认与谁存在劳动关系?这种确认劳动关系之诉是否受仲裁时效或诉讼时效的限制?确认劳动关系后还能否向社保部门投诉要求补缴社保?鉴于我国各地经常就劳动争议和社保等问题出台地方性法规、政府规章、司法文件、规范性文件等,各地劳动仲裁机构和人民法院基于对现有劳动相关法律的理解不一致和地方规定的不一致在同类劳动争议案件中往往作出不一致的裁判结果,本文引用北京的两个案例对上述问题进行分析和讨论,仅供大家参考。 一、案例简介案例一:邢某与某红公司劳动争议案件(参见北京市朝阳区人民法院(2022)京0105民初75494号民事判决书、北京市第三中级人民法院(2024)京03民终9047号民事判决书)邢某于1983年8月1日至1984年3月3...
  • 点击次数: 1000003
    2025 - 08 - 08
    作者:金涟伊《中华人民共和国商标法》(以下简称“商标法”)第三十条规定:“申请注册的商标,凡不符合本法有关规定或者同他人在同一种商品或者类似商品上已经注册的或者初步审定的商标相同或者近似的,由商标局驳回申请,不予公告。” 该法条是商标审查实践中判断商标是否应予核准注册的重要法律依据。 尽管该条款本身并未出现“混淆”二字,但《最高人民法院关于审理商标民事纠纷案件适用法律若干问题的解释》及《北京市高级人民法院商标授权确权行政案件审理指南》等配套规范,已将“容易导致混淆”确立为独立的评判要件。司法实践中,法院援引本条时,除审查标识是否“相同或近似”、商品是否“同一种或类似”外,还需进一步评估是否存在混淆可能。本文拟以某公司诉国家知识产权局商标驳回复审行政纠纷一案为切入点,探析《商标法》第三十条中“混淆可能性”的认定尺度与适用逻辑。 一、《商标法》第30条规定与混淆 现行《商标法》明文提及“混淆”的法条只有3条,即第13条对驰名商标的保护条款、第42条关于转让的条款,以及第57条关于侵犯注册商标专用权的条款。但在商标相关司法解释、部门规章等法规中,“混淆”是商标法第30条认定商标近似的重要判断依据。 2010年《最高人民法院关于审理商标授权确权行政案件若干问题的规定》第16条规定,人民法院认定商标是否近似,既要考虑商标标志构成要素及其整体的近似程度,也要考虑相关商标的显著性和知名度、所使用商品的关联程度等因素,以是否容易导致混淆作为判断标准。 而2019年北京市高级人民法院发布的《商标授权确权行政案件审理指南》第15条进一步明确了,“适用商标法第三十条、第三十一条时,可以综合考虑商标标志的近似程度、商品的类似程度、引证商标的显著性和知名度、相关公众的注意程度以及诉争商标申请人的主观意图等因素,以及前述因素之间的相互影响,以是否容易造...
  • 点击次数: 1000009
    2025 - 07 - 25
    作者:陈巴特运输毒品罪指的是在中国境内,通过携带、邮寄、利用他人或交通工具等方式,将毒品从一地转移到另一地。该罪行具体表现为改变毒品的所在地。作为毒品犯罪链条中的重要环节,运输毒品的行为为毒品的流通提供了条件,加剧了毒品的泛滥,不仅严重危害公民的身心健康,还可能导致社会治安问题频发,甚至关系民族兴衰、国家安危。从社会危害性来看,运输毒品罪无疑属于性质恶劣的犯罪类型。因此,厉行禁毒、依法严厉打击包括运输毒品犯罪在内的毒品犯罪,是党和政府的一贯立场和主张。【基本案情】王某和妻子均是执业药师,且一同就职于中部某市中心医院药房。与药品药材打交道,成为夫妻二人日常工作。幸福的家庭,稳定的工作,较高的收入,在这个三线城市,二人简直是大多数人“羡慕嫉妒恨”的对象。然而,天有不测风云,正是这份职业以及优越的生活,加之王某为人厚道、乐于助人的性格,给王某带来牢狱之灾,给家人生活长期蒙上巨大阴影。2021年9月某天,王某的一个普通朋友范某来电话,称因治病需要,其从西南某市购进一箱中药,想让王某率先看一看药材真假好坏,让王某提供医院的地址,用于接收从西南某市邮寄过来的中药。王某未加思索便同意并提供了地址。几天后,范某再次致电王某,称中药包裹已到医院收发室,收件人为“贾某”,收件电话尾号为“XXXX”,让王某帮忙取一下。王某仍然没有过多考虑,大摇大摆地去医院收发室取包裹。在医院收发室,一个并非收发室工作人员的陌生男子简单询问后,将一个纸箱包裹交给王某。王某抱着包裹就往外走,没走几米,感觉很不对劲儿:收发室的人他都认识啊,今天怎么是一个说着普通话的陌生人将包裹交给他?又想到范某吸毒,曾经引诱过自己吸毒,难道包裹里……简直不敢往下想!但王某也不能确定包裹里到底是什么,于是将包裹放在一旁,抽上烟,静观其变。很快,几名陌生人向王某围过来,简单询问后,便亮出“真家伙”将王某铐住,将其带至当地公安机关讯问。在...
× 扫一扫,关注微信公众号
铭盾MiNGDUN www.mdlaw.cn
Copyright© 2008 - 2025 铭盾京ICP备09063742号-1犀牛云提供企业云服务
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开