Language

All About Face: Use of Facial Recognition and Legal Restrictions

All About Face: Use of Facial Recognition and Legal Restrictions

 

Author: Yingying Zhu, Partner of Beijing MingDun Law Firm

Email: zhu.yingying@mdlaw.cn

Date: November 10, 2021

 

Introduction

From public places laden with facial verification cameras to residential buildings that shut strangers out with facial identification requirements, facial recognition technology is being used almost everywhere in China which has contributed to the low criminal rates and high level of public security, earning China the reputation as one of the safest places in the world to travel around.[1] Beyond the bright side, there has been at least one dark side to the overwhelming use of cameras-the possible leaks of people’s biometric identification information to outlaws and hackers. Nowadays, the public becomes increasingly concerned about providing their facial data to various service providers. The calls for safeguarding and curbing excessive uses of people’s facial data are on the rise.

 

Background

On November 1st, 2021, China’s first comprehensive data privacy law, the Personal Information Protection Law of the People’s Republic of China (the “PIPL”), has become effective. The PIPL basically requires that the operators of websites, mobile phone applications or any other technologies doing data collection and processing should obtain consent from users in order to collect/process the users’ data.

To address the increasing public concerns of the necessity to curb the abuses of people’s biometric data, the PIPL specifically regulates the collection of biometric data and the use of facial recognition technology in public areas.

Apart from the enactment of the PIPL, there was a lawsuit in Hangzhou stemming from dispute over the use of facial recognition equipment and a judicial interpretation on the same subject promulgated by the China Supreme People’s Court.

 

What is facial recognition?

No definition is provided under the PIPL or the judicial interpretation. According to The Future of Privacy Forum, the Facial recognition (currently defined to include facial verification and facial identification) means the technology that creates, collects, compares and retains facial templates that are identified or identifiable to particular individuals.[2]

Facial verification means a task where the facial recognition system confirms an individual’s claimed identity by comparing the template generated from a submitted facial image with a specific known template generated from a previously enrolled facial image. This process is also called one-to-one verification, or authentication.[3] 

Facial Identification means searching a database for a reference matching a submitted facial template and returning a corresponding identity, also known as “one-to-many” matching.[4]

From the above definitions, it can be deduced that facial recognition technology is not an equivalent of the conventional public camera surveillance[5] because it involves more than passive facial scanning and recording. If the usage of public surveillance camera involves no creation of personably identifiable facial templates which are identified or linked, or identifiable or linkable to individuals, it would neither constitute “facial recognition” nor arouse the same type of privacy concerns discussed under this article.

 

PIPL on facial recognition

 

1) processing of facial recognition data

Under the PIPL, facial recognition data, being a type of the biometric identification information, are classified under a specific category of information, sensitive personal information,[6] that must be treated with the following extra safeguarding:

1)   Personal information processors may not process sensitive personal information unless there are specific purposes and sufficient necessity, and strict protection measures are taken (Art. 28);

2)   An individual's separate consent shall be obtained for processing his or her sensitive personal information. Where any law or administrative regulation provides that written consent shall be obtained for processing sensitive personal information, such provision shall prevail (Art. 29); and

3)   To process sensitive personal information, personal information processors shall, notify individuals of the following:

    (a) identity of the processor (Art. 17);

    (b) purposes and methods of processing of personal information, categories of personal information to be processed, and the retention periods (Art. 17);

    (c) methods and procedures for individuals to exercise their rights (Art. 17);

    (d) necessity of the processing of sensitive personal information (Art. 30); and

    (e) the impacts on individuals’ rights and interests, except that it is not required by this Law to so notify (Art. 30).

 

2) use of facial recognition technology in public areas

Regarding the use of facial recognition technology in public areas, the PIPL provides as follows:

1)   The installation of image collection or personal identification equipment in public areas shall be necessary for maintaining public security and comply with relevant regulations issued by the state (Art. 26);

2)   Conspicuous signs shall be erected (Art. 26); and

3)   The collected personal images and identification information can only be used for the purpose of maintaining public security, and shall not be used for other purposes, except with the separate consent of individuals (Art. 26).

The above provisions basically provide that the use of facial recognition technology in public areas is only allowed for the purpose of maintaining public security where conspicuous signs shall be erected. It cannot be used for marketing, targeted advertising or any other commercial purposes, unless separate consent of individuals has been obtained.

One has but one face. Facial information is of a unique and unchangeable character for the individuals. As improper disclosures of facial data can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that facial data be specifically categorized and appropriately protected. The PIPL’s position in regulating the use of facial recognition data echoes with that of the GDPR. [7]

 

A GDPR decision on the use of facial recognition

A decision handed down in August 2019 under the GDPR could shed some light on the position taken by the GDPR towards the use of facial recognition data. The Swedish Data Protection Authority (“DPA”) has imposed a fine of approximately 20,000 euros upon a municipality for using facial recognition technology to monitor the attendance of students in school. The school in northern Sweden has conducted a trial program using facial recognition to keep track of students’ attendance in school. The students’ guardians were asked to give and gave explicit consent and they also had the option of excluding their child from the program. The school has based the processing on consent but the Swedish DPA considers that consent was not a valid legal basis given the clear imbalance between the data subject and the controller. The Swedish DPA concluded the school has processed sensitive biometric data unlawfully and failed to do an adequate impact assessment including seeking prior consultation with the Swedish DPA. [8]

Under the GDPR, biometric data, [9] including that generated through facial recognition technology, is protected as a special category of personal data since it is uniquely and strongly identifying to a person. The GDPR prohibits the processing of such data unless there is explicit consent, a legal obligation or public interest. In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation.[10] Judging from the clear imbalance between the students/their guardians and the school in the above case, the Swedish Data Protection Authority held the school liable under the GDPR for unlawfully processing the students’ facial data.

 

First lawsuit over facial recognition in China

Interestingly in contrast with the Swedish school case, also happened in 2019 and before the enactment of the PIPL, a court in Hangzhou ruled in the country’s first facial recognition lawsuit that the use of facial recognition technology for admission to a local safari park constituted a breach of the contract between the plaintiff and the Park.

Guo Bing, an associate law professor in Hangzhou city, filed a civil lawsuit against Hangzhou Safari Park in late 2019 after the Park required a facial identification process for his annual membership pass. He argued the Hangzhou Safari Park has no legal basis to collect visitors’ biometric data. Both courts in the first instance and second instance ruled in favor of Guo Bing, ordering the Park to refund him and delete his facial data and fingerprints.[11]

However, the courts’ judgements are criticized for being too narrow and also for the failure to touch on the legitimacy of the Park’s overbearing policy which mandated facial identification for entry. From the perspective of contract law, the courts of first and second instance ruled that the Park’s requirement of facial recognition to enter the park does not have legal effect on Guo contractually, but the courts avoided the review of the arbitrary clause that 'users who have not registered their face for facial recognition will not be able to enter the park ever'. That is however the key claim in Guo’s lawsuit against the Park.

 The above being said, Guo’s case is still significant as the first lawsuit to challenge the commercial use of facial recognition technology. Citing Guo’s case, China’s Supreme People’s Court (“SPC”) announced that consumers’ privacy must be protected from unwarranted face tracking,[12] a signal that China is tightening the leash on the facial recognition industry.

 

Judicial interpretation on use of facial recognition

On July 28, 2021 the SPC promulgated the Provisions (the “Provisions”) on several issues concerning the application of law in the trial of civil cases relating to processing of personal information by using the facial recognition technology.[13] The Provisions came into force on August 1, 2021.

The Provisions apply to civil cases that involve facial recognition technology. The Provisions set forth that hotels, shopping malls, airports and other commercial venues should not use facial recognition in violation of the laws and administrative regulations. The use of the technology is only allowed when there is clear legal basis and cannot exceed what is necessary, and companies must take measures to protect the facial data. The Provisions also provide that consent is not a valid legal basis if companies denied providing products or services on the condition that a consent is given, unless the processing of facial information is necessary for the provision of such products or services. Property management companies must obtain the consent of the residents before using facial recognition. In case of refusal of consent, alternative verification methods must be offered.

While the Provisions are not clear on what counts as necessary use, the possibility of penalties from lawsuits is likely to curb some excessive uses of people’s facial data. The Provisions also specifies a mechanism for the public to sue if their privacy has been violated and option for injunction is also available in cases where irreparable harm would be caused without an injunctive relief.

 

Key Takeaways

·   Thorough impact assessment should be conducted prior to the launching of any facial recognition implementation.

·   For businesses to stay compliant with the PIPL, despite the scale and the intent of the use of facial recognition technology, regulatory and professional opinions have to be consulted.

·   Consent should not provide a valid legal ground for the processing of personal data in cases where there is a clear imbalance between the data subject and the controller.

·   Consent should be invalid if there is an “opt-in-or-leave” situation, unless the processing of facial data is absolutely necessary for the products or services offered.

 

Conclusion

After the enactment of the PIPL and the China Supreme People’s Court’s promulgation of the Provisions, it remains to be seen how the administration will enforce these rules, how the courts will adjudicate in lawsuits involving facial recognition and whether such enforcement/adjudication will actually curb the abuses of facial recognition technology. For whatever the future holds, one thing is certain: businesses must realize that to advance any frontier technology, building public trust is essential to the effectuation that the public can enjoy the benefits offered by the technology. Before the public can entrust their sensitive personal data to the facial recognition businesses, they must have confidence that the use is with necessity, and that the use is lawful, fair, transparent and also safely guarded.



 



[1] See https://www.globaltimes.cn/content/1067645.shtml.

[2] See The Future of Privacy Forum, Privacy Principles for Facial-Recognition Technology in Commercial Applications (September 2018), https://fpf.org/wp-content/uploads/2019/03/Final-Privacy-Principles-Edits-1.pdf.

[3] Ibid.

[4] Ibid.

[5] Closed-circuit television (CCTV) or video surveillance is camera systems used to transmit signals to a specific location often with visualization on a limited number of televisions or computer monitors. See Hong Kong Lawyer, CCTV and Privacy Rights (December 2019).

[6]  Under the PIPL, sensitive personal information is defined as “the personal information of which the leakage or illegal use   could easily lead to the violation of the personal dignity of a natural person or harm to personal or property safety, including    information on biometric identification, religious beliefs, specific identity, health care, financial accounts, and personal whereabouts, and personal information of minors under the age of fourteen.” (Art. 28).

[7] The General Data Protection Regulation (EU) 2016/679.

[8] See https://edpb.europa.eu/news/national-news/2019/facial-recognition-school-renders-swedens-first-gdpr-fine_sv.

[9] GDPR defines “biometric data” as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data. See https://gdpr-info.eu/art-4-gdpr/.

[10] See https://www.privacy-regulation.eu/en/recital-43-GDPR.htm.

[11] See https://xw.qq.com/cmsid/20201120A0EPDD00.

[12] See https://m.thepaper.cn/baijiahao_13819929.

[13] See http://en.pkulaw.cn/Display.aspx?Lib=law&Id=36687&keyword.


  • 相关资讯 More
  • 点击次数: 4
    2026 - 06 - 12
    微结构能否申请实用新型专利?——从《专利法》规定、《客体指引》到司法实践的全面解析实用新型专利因审查周期短、费用较低、授权相对容易,成为许多中小企业和个人保护结构类创新的常用选择。然而,随着微纳制造、材料表面工程、微流控器件、电池电极等领域的快速发展,“微结构”相关技术日益增多,申请人常常面临一个核心问题:这类微尺度特征能否通过实用新型专利获得保护?本文结合《中华人民共和国专利法》(2020年修正)、国家知识产权局2023年发布的《关于实用新型专利保护客体判断的指引》(以下简称《客体指引》)、专利审查指南以及最高人民法院相关判例,系统分析微结构实用新型的保护边界,并提出实务撰写建议。一、实用新型专利的法律定义与保护客体《专利法》第二条第三款规定:“实用新型,是指对产品的形状、构造或者其结合所提出的适于实用的新的技术方案。”据此,实用新型保护客体需同时满足三个要件:产品、形状和/或构造,以及技术方案。《客体指引》进一步明确,实用新型仅保护经过产业方法制造的、有确定形状和构造且占据一定空间的实体。一切方法以及自然存在的物品,均不在保护范围之内。二、《客体指引》对形状、构造及微结构的明确界定《客体指引》对实用新型保护客体作出了较为细致的解释。其中,产品的形状是指可以从外部观察到的确定空间形态,不能以自然形成或随意堆放的形态作为特征。而产品的构造则是指各组成部分的安排、组织与相互关系,包括机械构造、线路构造以及复合层结构等。值得注意的是,《客体指引》明确将“物质的分子结构、组分、金相结构等”排除在构造之外。这意味着,如果微结构本质上是材料内部的分子或微观组织变化,即使能够产生积极技术效果,也难以被认定为受实用新型保护的构造。相比之下,复合层结构(如渗碳层、氧化层)因在宏观层面形成明确的分层与物理差异,通常可以作为构造特征获得保护。在材料特征的处理上,《客体指引》指出:仅使用已知材料...
  • 点击次数: 5
    2026 - 06 - 08
    2020年9月国务院国资委印发《关于加快推进国有企业数字化转型工作的通知》,明确提出要“构建数据治理体系”,定期评估数据治理能力成熟度,要求“以构建企业数字时代核心竞争能力为主线,制定数字化转型方案,纳入企业年度工作计划”后,我国数据基础制度建设进入快车道。继《民法典》《个人信息保护法》《数据安全法》等法律法规为数据安全与流通合规奠定基础后,2022年中共中央、国务院印发《关于构建数据基础制度更好发挥数据要素作用的意见》(“数据二十条”),创新确立数据资源持有权、数据加工使用权、数据产品经营权“三权分置”框架,2026年4月3日国家数据局综合司发布关于向社会公开征求《数据产权登记工作指引(试行)》(公开征求意见稿),也加快构建了数据确权、登记、交易等基础制度。这一系列法律法规、政策文件的协同推进,也为国有企业数字化转型提供了发展新思路,如何推动国企数据要素从“资源”走向“资产”,从合规必答题转化为增值新引擎成为亟待深度探索的命题。一、国企数字化转型过程中面临的机遇与挑战国有企业作为国民经济“顶梁柱”,在数字化转型与高质量发展进程中,既面临战略机遇,也面临多重挑战。当前国企数字化转型过程可能存在两大挑战:一方面,数据资源甄别能力不足,国企在各行各业经营过程中可能积累了大量不同的业务数据,但对哪些数据资源可以申请产权登记、哪些数据资源可以入表、如何归集成本、怎样评估等存在模糊界限,导致大量潜在数据资产未能有效识别和挖掘;另一方面,数据产权界定复杂,因国企自身的所有制属性,其数据资源往往涉及政府部门、产业链上下游等多方主体,在数据持有权、加工使用权、产品经营权框架下,各方权责利边界尚未完全厘清,收益分配机制缺位,使得数据资源难以顺利转化为可确认、可计量的数据资产。二、为什么国企要重视数据资产入表根据财政部《企业数据资源相关会计处理暂行规定》,“企业合法拥有或控制的、预期会给企业带...
  • 点击次数: 1000036
    2026 - 04 - 10
    作者:金涟伊一、官网的定义与功能定位“官网”是“官方网站”的简称,在中国法律语境下,通常指由特定组织、企业或政府机构正式设立和运营的网站,使用经合法注册的域名(如.cn、.com.cn等)。官网应当完成ICP备案(非经营性)或取得ICP许可证(经营性),代表该主体的正式立场,具有公示和公信力。在实践中,政府官网使用.gov.cn域名,需经严格审批,且仅限政府机构注册。企业自称“官网”则主要受《反不正当竞争法》《广告法》约束,不得进行虚假宣传。本文主要聚焦于企业官网,即由企业自行或委托他人创建、注册和运营,代表企业意志、面向社会公众、展示企业信息的网站。企业官网通常包含首页、关于我们、产品(服务)中心、技术服务、新闻中心、联系我们等板块。它作为数字时代的核心商业基础设施,承载着多维度的功能。有些官网构成运营场所,用于展示产品/服务信息、技术参数、应用场景,发布促销活动、案例故事,有些官网还具有交易功能,如在线支付、订单管理。对于中小企业而言,官网更重要的功能是输出统一的视觉识别系统、品牌故事、企业价值观,进而为企业获得消费者信任。二、官网展示行为的法律定性如前所述,官网承载着对外展示企业形象、品牌美誉的功能,因此大部分官网都会展示企业相关产品。那么,企业在官网上发布自家产品及品牌的行为是否构成广告宣传,是否构成商标法意义上的使用?从广告法的角度来说,根据《广告法》第二条,商品经营者或者服务提供者通过一定媒介和形式直接或者间接地介绍自己所推销的商品或者服务的商业广告活动,适用本法。企业作为产品的生产者或者销售者,在自己所能控制的互联网空间中向不特定的人群介绍自己的产品或服务,符合广告法的定义,属于应当被广告法所规制的行为,即广告宣传行为。如果未介绍产品或服务,仅是单纯发布自身名称(姓名)、简称、商标、标识、经营范围、成立时间、发展历程、企业简介等信息,且未直接或者间接推销商品或...
  • 点击次数: 1000019
    2026 - 04 - 03
    作者:张嘉畅3月29日,歌手李荣浩在社交媒体上公开指出歌手单依纯在其演唱会“纯妹妹2.0”上演唱了《李白》一作,侵犯了自己的著作权。3月30日凌晨,单依纯长文回复致歉,并承诺不再演唱《李白》。此争议引发了大众的广泛讨论,大部分网友支持原创者维权,也有小部分网友支持新版本翻唱,也有一些过往的类似案件被再度提及。在本文中,笔者将对不同的观点从法律角度进行解读。 一、争议观点 著作权,又称版权,是作品的作者依法享有的权利。根据《著作权法》第十条,著作权包括“发表权”、“署名权”、“修改权”、“保护作品完整权”……等13项权利。在本次争议当中,网友提出了以下几种观点: (1)该行为侵犯了修改权 修改权,即修改,或者授权他人修改作品的权利。修改权属于人身权,只有作者本人或受到授权的人可以对作品进行修改。网络上有部分观点认为对歌曲进行再加工侵犯了作者的修改权。然而在本案中,因为《李白》一作已经发表,且翻唱并未对《李白》作品本身进行修改,不影响原作的呈现方式,所以笔者认为本案不涉及到侵犯修改权。 (2)改编作品具有独立著作权 其实,单依纯并非首次演唱《李白》。早在去年的《歌手2025》节目上,单依纯团队就已对《李白》一歌进行了改编和翻唱。有小部分网友依据《著作权法》第十三条提出观点,认为单依纯团队对改编后的《李白》享有著作权,因此其演唱行为并无不当。但这一说法在法律上并非没有争议。首先,对于公众而言,目前并不清楚《歌手 2025》节目录制时,双方就《李白》一歌的改编权具体是如何约定的,权利基础尚不明确。其次,从司法实践来看,法院在类似案件中已形成较为一致的裁判观点:改编后的作品能否产生独立的著作权,核心取决于改编过程中新增的创作部分是否具备独创性。具体到本案,新增的念白与编曲是否达到独创性标准、能否构成新的作品,仍需要结合行业标...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2026 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开