Language

All About Face: Use of Facial Recognition and Legal Restrictions

All About Face: Use of Facial Recognition and Legal Restrictions

 

Author: Yingying Zhu, Partner of Beijing MingDun Law Firm

Email: zhu.yingying@mdlaw.cn

Date: November 10, 2021

 

Introduction

From public places laden with facial verification cameras to residential buildings that shut strangers out with facial identification requirements, facial recognition technology is being used almost everywhere in China which has contributed to the low criminal rates and high level of public security, earning China the reputation as one of the safest places in the world to travel around.[1] Beyond the bright side, there has been at least one dark side to the overwhelming use of cameras-the possible leaks of people’s biometric identification information to outlaws and hackers. Nowadays, the public becomes increasingly concerned about providing their facial data to various service providers. The calls for safeguarding and curbing excessive uses of people’s facial data are on the rise.

 

Background

On November 1st, 2021, China’s first comprehensive data privacy law, the Personal Information Protection Law of the People’s Republic of China (the “PIPL”), has become effective. The PIPL basically requires that the operators of websites, mobile phone applications or any other technologies doing data collection and processing should obtain consent from users in order to collect/process the users’ data.

To address the increasing public concerns of the necessity to curb the abuses of people’s biometric data, the PIPL specifically regulates the collection of biometric data and the use of facial recognition technology in public areas.

Apart from the enactment of the PIPL, there was a lawsuit in Hangzhou stemming from dispute over the use of facial recognition equipment and a judicial interpretation on the same subject promulgated by the China Supreme People’s Court.

 

What is facial recognition?

No definition is provided under the PIPL or the judicial interpretation. According to The Future of Privacy Forum, the Facial recognition (currently defined to include facial verification and facial identification) means the technology that creates, collects, compares and retains facial templates that are identified or identifiable to particular individuals.[2]

Facial verification means a task where the facial recognition system confirms an individual’s claimed identity by comparing the template generated from a submitted facial image with a specific known template generated from a previously enrolled facial image. This process is also called one-to-one verification, or authentication.[3] 

Facial Identification means searching a database for a reference matching a submitted facial template and returning a corresponding identity, also known as “one-to-many” matching.[4]

From the above definitions, it can be deduced that facial recognition technology is not an equivalent of the conventional public camera surveillance[5] because it involves more than passive facial scanning and recording. If the usage of public surveillance camera involves no creation of personably identifiable facial templates which are identified or linked, or identifiable or linkable to individuals, it would neither constitute “facial recognition” nor arouse the same type of privacy concerns discussed under this article.

 

PIPL on facial recognition

 

1) processing of facial recognition data

Under the PIPL, facial recognition data, being a type of the biometric identification information, are classified under a specific category of information, sensitive personal information,[6] that must be treated with the following extra safeguarding:

1)   Personal information processors may not process sensitive personal information unless there are specific purposes and sufficient necessity, and strict protection measures are taken (Art. 28);

2)   An individual's separate consent shall be obtained for processing his or her sensitive personal information. Where any law or administrative regulation provides that written consent shall be obtained for processing sensitive personal information, such provision shall prevail (Art. 29); and

3)   To process sensitive personal information, personal information processors shall, notify individuals of the following:

    (a) identity of the processor (Art. 17);

    (b) purposes and methods of processing of personal information, categories of personal information to be processed, and the retention periods (Art. 17);

    (c) methods and procedures for individuals to exercise their rights (Art. 17);

    (d) necessity of the processing of sensitive personal information (Art. 30); and

    (e) the impacts on individuals’ rights and interests, except that it is not required by this Law to so notify (Art. 30).

 

2) use of facial recognition technology in public areas

Regarding the use of facial recognition technology in public areas, the PIPL provides as follows:

1)   The installation of image collection or personal identification equipment in public areas shall be necessary for maintaining public security and comply with relevant regulations issued by the state (Art. 26);

2)   Conspicuous signs shall be erected (Art. 26); and

3)   The collected personal images and identification information can only be used for the purpose of maintaining public security, and shall not be used for other purposes, except with the separate consent of individuals (Art. 26).

The above provisions basically provide that the use of facial recognition technology in public areas is only allowed for the purpose of maintaining public security where conspicuous signs shall be erected. It cannot be used for marketing, targeted advertising or any other commercial purposes, unless separate consent of individuals has been obtained.

One has but one face. Facial information is of a unique and unchangeable character for the individuals. As improper disclosures of facial data can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that facial data be specifically categorized and appropriately protected. The PIPL’s position in regulating the use of facial recognition data echoes with that of the GDPR. [7]

 

A GDPR decision on the use of facial recognition

A decision handed down in August 2019 under the GDPR could shed some light on the position taken by the GDPR towards the use of facial recognition data. The Swedish Data Protection Authority (“DPA”) has imposed a fine of approximately 20,000 euros upon a municipality for using facial recognition technology to monitor the attendance of students in school. The school in northern Sweden has conducted a trial program using facial recognition to keep track of students’ attendance in school. The students’ guardians were asked to give and gave explicit consent and they also had the option of excluding their child from the program. The school has based the processing on consent but the Swedish DPA considers that consent was not a valid legal basis given the clear imbalance between the data subject and the controller. The Swedish DPA concluded the school has processed sensitive biometric data unlawfully and failed to do an adequate impact assessment including seeking prior consultation with the Swedish DPA. [8]

Under the GDPR, biometric data, [9] including that generated through facial recognition technology, is protected as a special category of personal data since it is uniquely and strongly identifying to a person. The GDPR prohibits the processing of such data unless there is explicit consent, a legal obligation or public interest. In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation.[10] Judging from the clear imbalance between the students/their guardians and the school in the above case, the Swedish Data Protection Authority held the school liable under the GDPR for unlawfully processing the students’ facial data.

 

First lawsuit over facial recognition in China

Interestingly in contrast with the Swedish school case, also happened in 2019 and before the enactment of the PIPL, a court in Hangzhou ruled in the country’s first facial recognition lawsuit that the use of facial recognition technology for admission to a local safari park constituted a breach of the contract between the plaintiff and the Park.

Guo Bing, an associate law professor in Hangzhou city, filed a civil lawsuit against Hangzhou Safari Park in late 2019 after the Park required a facial identification process for his annual membership pass. He argued the Hangzhou Safari Park has no legal basis to collect visitors’ biometric data. Both courts in the first instance and second instance ruled in favor of Guo Bing, ordering the Park to refund him and delete his facial data and fingerprints.[11]

However, the courts’ judgements are criticized for being too narrow and also for the failure to touch on the legitimacy of the Park’s overbearing policy which mandated facial identification for entry. From the perspective of contract law, the courts of first and second instance ruled that the Park’s requirement of facial recognition to enter the park does not have legal effect on Guo contractually, but the courts avoided the review of the arbitrary clause that 'users who have not registered their face for facial recognition will not be able to enter the park ever'. That is however the key claim in Guo’s lawsuit against the Park.

 The above being said, Guo’s case is still significant as the first lawsuit to challenge the commercial use of facial recognition technology. Citing Guo’s case, China’s Supreme People’s Court (“SPC”) announced that consumers’ privacy must be protected from unwarranted face tracking,[12] a signal that China is tightening the leash on the facial recognition industry.

 

Judicial interpretation on use of facial recognition

On July 28, 2021 the SPC promulgated the Provisions (the “Provisions”) on several issues concerning the application of law in the trial of civil cases relating to processing of personal information by using the facial recognition technology.[13] The Provisions came into force on August 1, 2021.

The Provisions apply to civil cases that involve facial recognition technology. The Provisions set forth that hotels, shopping malls, airports and other commercial venues should not use facial recognition in violation of the laws and administrative regulations. The use of the technology is only allowed when there is clear legal basis and cannot exceed what is necessary, and companies must take measures to protect the facial data. The Provisions also provide that consent is not a valid legal basis if companies denied providing products or services on the condition that a consent is given, unless the processing of facial information is necessary for the provision of such products or services. Property management companies must obtain the consent of the residents before using facial recognition. In case of refusal of consent, alternative verification methods must be offered.

While the Provisions are not clear on what counts as necessary use, the possibility of penalties from lawsuits is likely to curb some excessive uses of people’s facial data. The Provisions also specifies a mechanism for the public to sue if their privacy has been violated and option for injunction is also available in cases where irreparable harm would be caused without an injunctive relief.

 

Key Takeaways

·   Thorough impact assessment should be conducted prior to the launching of any facial recognition implementation.

·   For businesses to stay compliant with the PIPL, despite the scale and the intent of the use of facial recognition technology, regulatory and professional opinions have to be consulted.

·   Consent should not provide a valid legal ground for the processing of personal data in cases where there is a clear imbalance between the data subject and the controller.

·   Consent should be invalid if there is an “opt-in-or-leave” situation, unless the processing of facial data is absolutely necessary for the products or services offered.

 

Conclusion

After the enactment of the PIPL and the China Supreme People’s Court’s promulgation of the Provisions, it remains to be seen how the administration will enforce these rules, how the courts will adjudicate in lawsuits involving facial recognition and whether such enforcement/adjudication will actually curb the abuses of facial recognition technology. For whatever the future holds, one thing is certain: businesses must realize that to advance any frontier technology, building public trust is essential to the effectuation that the public can enjoy the benefits offered by the technology. Before the public can entrust their sensitive personal data to the facial recognition businesses, they must have confidence that the use is with necessity, and that the use is lawful, fair, transparent and also safely guarded.



 



[1] See https://www.globaltimes.cn/content/1067645.shtml.

[2] See The Future of Privacy Forum, Privacy Principles for Facial-Recognition Technology in Commercial Applications (September 2018), https://fpf.org/wp-content/uploads/2019/03/Final-Privacy-Principles-Edits-1.pdf.

[3] Ibid.

[4] Ibid.

[5] Closed-circuit television (CCTV) or video surveillance is camera systems used to transmit signals to a specific location often with visualization on a limited number of televisions or computer monitors. See Hong Kong Lawyer, CCTV and Privacy Rights (December 2019).

[6]  Under the PIPL, sensitive personal information is defined as “the personal information of which the leakage or illegal use   could easily lead to the violation of the personal dignity of a natural person or harm to personal or property safety, including    information on biometric identification, religious beliefs, specific identity, health care, financial accounts, and personal whereabouts, and personal information of minors under the age of fourteen.” (Art. 28).

[7] The General Data Protection Regulation (EU) 2016/679.

[8] See https://edpb.europa.eu/news/national-news/2019/facial-recognition-school-renders-swedens-first-gdpr-fine_sv.

[9] GDPR defines “biometric data” as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data. See https://gdpr-info.eu/art-4-gdpr/.

[10] See https://www.privacy-regulation.eu/en/recital-43-GDPR.htm.

[11] See https://xw.qq.com/cmsid/20201120A0EPDD00.

[12] See https://m.thepaper.cn/baijiahao_13819929.

[13] See http://en.pkulaw.cn/Display.aspx?Lib=law&Id=36687&keyword.


  • 相关资讯 More
  • 点击次数: 2
    2026 - 09 - 09
    伴随新业态经济的快速持续发展,依托互联网平台的新就业形态从业规模不断扩大,劳动者与平台企业之间的法律关系日趋复杂,有的不良平台企业以“承揽合同”“自由职业者合作协议”等民事协议之名行直接用工之实,有的通过关联企业混同用工规避法律责任,有的公然要求劳动者自带车辆完成配送等等,给传统劳动关系的认定带来了很大冲击和挑战。这种形势下,劳动者权益如何保障?企业发展活力如何兼顾?这是司法必须回应的时代之问。【基本案情】2024年初,平台企业某驴公司发布广告称,在某市区公开招聘配送司机,要求应聘司机自带车内空间七方以上的面包车型车辆;在配送时间方面,要求配送司机半夜23时前到达仓库,配送在上午8-9时结束;月薪12000至18000元。作业内容对配送区域、配送食材以及司机的年龄、驾龄要求进行了具体描述;同时,要求配送司机熟悉基本手机软件操作,能够独立使用APP软件进行送货、签到、打卡等等。失业已有三月的袁先生,得知此消息兴奋不已,自己各方面条件都符合招聘要求,面对如此高薪,怎能在家“坐吃山空”,赶紧挣钱养家才是男人第一大要务。袁先生的应聘非常顺利,很快被录用。在办理入职过程中,某驴公司先是要求其在公司运营的APP软件注册,随后引导其与公司签订了承揽合同,并将其拉入工作微信群。一切都很顺利,一切又似乎让人迷茫。接下来的两年里,老实巴交的袁先生总是在夜间提前到达仓库,提前在APP里签到打卡,然后根据仓库领导在微信群里的工作安排,对配送的货物进行分拣、装车,再送往各个餐饮店,通常在次日上午10点配送结束后回到家里。几次因途中堵车延误时间,遭到客户投诉及某驴公司罚款。时不时接受某驴公司对全体配送司机的培训教育。老家有红白喜事,必须先在微信群向领导请假,获批后方可离开。两年来,袁先生虽有委屈,虽然辛苦,但每月看到某驴公司转给自己的一万多元的“收入”,心理还是有些许安慰的。然而,天有不测风云。202...
  • 点击次数: 7
    2026 - 08 - 17
    引言:创造性判断中,申请人常以“现有技术给出了反向教导”为由主张技术方案非显而易见。那么,什么情况下才能成立反向教导?最高人民法院在(2023)最高法知行终413号案中给出了明确裁判思路。为进一步理解这一标准,我们结合具体案件分析及相关案例一并探讨。一、基本案情德国某公司申请的发明专利“导线连接接触元件”(申请号20181015****.3)被国家知识产权局以不具备创造性为由驳回。复审及一审均维持驳回决定。申请人上诉至最高人民法院,核心理由之一是:对比文件1公开的结构给出了针对区别技术特征的反向教导,本领域技术人员不会作出本申请的改进。最高人民法院于2024年12月24日作出(2023)最高法知行终413号行政判决,驳回上诉,维持原判。二、裁判要旨最高人民法院明确指出:所谓的反向教导属于创造性评价中判断技术启示时可能涉及的问题。判断现有技术是否存在反向教导,应当以发明实际解决的技术问题为基础,如果现有技术公开的内容不构成本领域技术人员解决发明实际解决的技术问题的障碍,则通常不认为其构成反向教导。简言之,反向教导的认定必须锚定在发明实际解决的技术问题上,而非孤立地看待对比文件中的某个结构或功能。三、具体案例分析本案中,本申请权利要求1相对于对比文件1的区别技术特征主要在于提供了一种不同结构的SMD焊接接触件。该接触件并未保留对比文件1中的“摆动抑制作用”,也未实现其他新功能,其核心作用仍是提供支撑面。申请人主张对比文件1因强调摆动抑制功能而构成反向教导。法院对此不予支持,理由如下:以实际解决的技术问题为判断基准 本申请实际解决的技术问题并非“如何实现摆动抑制”,而是提供一种具有支撑功能的SMD焊接接触件结构。对比文件1公开的摆动抑制部位置和结构,并不妨碍本领域技术人员在此基础上进行简化或调整。放弃原有功能不必然构成反向教导 本领域技术人员完全可以从对比文件1公开的结构出发,放...
  • 点击次数: 7
    2026 - 08 - 07
    在侵权赔偿纠纷中,受害人自身疾病或特殊体质与侵权行为结合给受害人造成同一损害或导致损害扩大时,侵权人往往以此为由主张免除或减轻赔偿责任。对此,司法机关是如何考量的呢?本文即以案释法,对此进行分析探讨。一、典型案例(一)案例1:参见(2020)京01民终6829号民事判决书1.基本案情2018年3月21日,孙某到提供游泳服务的某公司处游泳,由于某公司工作人员在游泳池内尚有人在游泳时,将游泳池外围地面处铺设的防滑网垫移开,并用水冲洗游泳池外地面淤泥及桌椅,导致孙某从游泳池内出来后,在游泳池外围的地面滑倒后摔伤。当日,孙某即被送往医院紧急就诊,后住院治疗。住院病历诊断:1.颈椎外伤,无骨折脱位型颈脊髓损伤;2.冠状动脉粥样硬化性心脏病,陈旧性心梗,支架植入术后,心功能II级;3.高血压病3级,极高危;4.陈旧脑梗塞;5.高血脂症;6.II型糖尿病。手术志摘要:颈后正中纵切口12cm,充分暴露C3-7棘突及椎板,逐层缝合关闭切口。后孙某起诉至法院。案件审理过程中,某公司申请对孙某的医疗费合理性进行鉴定,鉴定中心表示,孙某自身患有先天性颈椎狭窄的疾病,这次摔伤加重了孙某的病情,且鉴定意见第2项中有控制高血压、血糖等用药,建议住院后产生的医疗费用外伤的原因力的诱发因素不超过50%。孙某向一审法院起诉请求:判令某公司支付孙某医疗费102991.85元、住院伙食补助费1600元、营养费4500元、护理费6700元、误工费10687元、交通费200元、精神损失费5000元,以上共计131678.85元。2.法院裁判要旨及判决结果(1)裁判要旨一审法院认为,我国侵权责任法规定,宾馆、商场、银行、车站、娱乐场所等公共场所的管理人或者群众性活动的组织者,未尽到安全保障义务,造成他人损害的,应当承担侵权责任。侵害他人造成人身损害的,应当赔偿医疗费、护理费、交通费等为治疗和康复支出的合理费用,以及因误...
  • 点击次数: 21
    2026 - 07 - 17
    导语股权收购、资产并购、业务分拆整合、新设合营企业,是企业扩大市场份额、完善产业链布局的主流商业手段。经营者集中事前申报,是《中华人民共和国反垄断法》设定的强制性前置合规程序,也是投融资交易中法务、合规团队首要核查的法律节点。  实务中,不同赛道的并购交易,监管审查范围、配套申报义务、材料披露尺度存在明显区分。本文结合现行有效法律法规、国家市场监督管理总局、国家发改委发布的官方实操文件,分别梳理大众快消行业并购、外资收购高科技企业两类高频交易场景下经营者集中申报实操要点。    一、快消品类经营者集中 日化、生活用纸、非处方健康消费品、包装食品等民生快消行业的境内、跨境并购,仅需完成经营者集中单一申报流程,不存在外商投资安全审查叠加义务,全部合规工作围绕市场公平竞争维度开展。  1. 申报触发判定标准依据《中华人民共和国反垄断法》(2022 修正)第二十六条、《国务院关于经营者集中申报标准的规定》(2024 修订)第三条,交易参与方上一会计年度的合并营业额达到下述任一标准,必须在股权交割、业务整合前向国家市场监督管理总局提交申报,未取得审查决定不得实施集中:一是参与集中的所有经营者全球合计年营业额超过 120 亿元,且至少两家经营者在中国境内年营业额均超过8 亿元以上;二是全部经营者境内合计年营业额超 40 亿元,且至少两家境内营业额均超过 8 亿元。金佰利公司拟收购科赴(Kenvue)公司股权是当前快消领域典型横向收购案例,交易覆盖纸巾、个人护理、家用护理等重合赛道,交易双方全球及中国区域营收规模均足额触发申报门槛。金佰利提交申报材料后,市场监管总局已要求金佰利就其计划以490亿美元收购Kenvue的交易提供补充信息,是快消行业经营者集中申报的典型参考实例。   ...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2026 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开