Language

All About Face: Use of Facial Recognition and Legal Restrictions

All About Face: Use of Facial Recognition and Legal Restrictions

 

Author: Yingying Zhu, Partner of Beijing MingDun Law Firm

Email: zhu.yingying@mdlaw.cn

Date: November 10, 2021

 

Introduction

From public places laden with facial verification cameras to residential buildings that shut strangers out with facial identification requirements, facial recognition technology is being used almost everywhere in China which has contributed to the low criminal rates and high level of public security, earning China the reputation as one of the safest places in the world to travel around.[1] Beyond the bright side, there has been at least one dark side to the overwhelming use of cameras-the possible leaks of people’s biometric identification information to outlaws and hackers. Nowadays, the public becomes increasingly concerned about providing their facial data to various service providers. The calls for safeguarding and curbing excessive uses of people’s facial data are on the rise.

 

Background

On November 1st, 2021, China’s first comprehensive data privacy law, the Personal Information Protection Law of the People’s Republic of China (the “PIPL”), has become effective. The PIPL basically requires that the operators of websites, mobile phone applications or any other technologies doing data collection and processing should obtain consent from users in order to collect/process the users’ data.

To address the increasing public concerns of the necessity to curb the abuses of people’s biometric data, the PIPL specifically regulates the collection of biometric data and the use of facial recognition technology in public areas.

Apart from the enactment of the PIPL, there was a lawsuit in Hangzhou stemming from dispute over the use of facial recognition equipment and a judicial interpretation on the same subject promulgated by the China Supreme People’s Court.

 

What is facial recognition?

No definition is provided under the PIPL or the judicial interpretation. According to The Future of Privacy Forum, the Facial recognition (currently defined to include facial verification and facial identification) means the technology that creates, collects, compares and retains facial templates that are identified or identifiable to particular individuals.[2]

Facial verification means a task where the facial recognition system confirms an individual’s claimed identity by comparing the template generated from a submitted facial image with a specific known template generated from a previously enrolled facial image. This process is also called one-to-one verification, or authentication.[3] 

Facial Identification means searching a database for a reference matching a submitted facial template and returning a corresponding identity, also known as “one-to-many” matching.[4]

From the above definitions, it can be deduced that facial recognition technology is not an equivalent of the conventional public camera surveillance[5] because it involves more than passive facial scanning and recording. If the usage of public surveillance camera involves no creation of personably identifiable facial templates which are identified or linked, or identifiable or linkable to individuals, it would neither constitute “facial recognition” nor arouse the same type of privacy concerns discussed under this article.

 

PIPL on facial recognition

 

1) processing of facial recognition data

Under the PIPL, facial recognition data, being a type of the biometric identification information, are classified under a specific category of information, sensitive personal information,[6] that must be treated with the following extra safeguarding:

1)   Personal information processors may not process sensitive personal information unless there are specific purposes and sufficient necessity, and strict protection measures are taken (Art. 28);

2)   An individual's separate consent shall be obtained for processing his or her sensitive personal information. Where any law or administrative regulation provides that written consent shall be obtained for processing sensitive personal information, such provision shall prevail (Art. 29); and

3)   To process sensitive personal information, personal information processors shall, notify individuals of the following:

    (a) identity of the processor (Art. 17);

    (b) purposes and methods of processing of personal information, categories of personal information to be processed, and the retention periods (Art. 17);

    (c) methods and procedures for individuals to exercise their rights (Art. 17);

    (d) necessity of the processing of sensitive personal information (Art. 30); and

    (e) the impacts on individuals’ rights and interests, except that it is not required by this Law to so notify (Art. 30).

 

2) use of facial recognition technology in public areas

Regarding the use of facial recognition technology in public areas, the PIPL provides as follows:

1)   The installation of image collection or personal identification equipment in public areas shall be necessary for maintaining public security and comply with relevant regulations issued by the state (Art. 26);

2)   Conspicuous signs shall be erected (Art. 26); and

3)   The collected personal images and identification information can only be used for the purpose of maintaining public security, and shall not be used for other purposes, except with the separate consent of individuals (Art. 26).

The above provisions basically provide that the use of facial recognition technology in public areas is only allowed for the purpose of maintaining public security where conspicuous signs shall be erected. It cannot be used for marketing, targeted advertising or any other commercial purposes, unless separate consent of individuals has been obtained.

One has but one face. Facial information is of a unique and unchangeable character for the individuals. As improper disclosures of facial data can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that facial data be specifically categorized and appropriately protected. The PIPL’s position in regulating the use of facial recognition data echoes with that of the GDPR. [7]

 

A GDPR decision on the use of facial recognition

A decision handed down in August 2019 under the GDPR could shed some light on the position taken by the GDPR towards the use of facial recognition data. The Swedish Data Protection Authority (“DPA”) has imposed a fine of approximately 20,000 euros upon a municipality for using facial recognition technology to monitor the attendance of students in school. The school in northern Sweden has conducted a trial program using facial recognition to keep track of students’ attendance in school. The students’ guardians were asked to give and gave explicit consent and they also had the option of excluding their child from the program. The school has based the processing on consent but the Swedish DPA considers that consent was not a valid legal basis given the clear imbalance between the data subject and the controller. The Swedish DPA concluded the school has processed sensitive biometric data unlawfully and failed to do an adequate impact assessment including seeking prior consultation with the Swedish DPA. [8]

Under the GDPR, biometric data, [9] including that generated through facial recognition technology, is protected as a special category of personal data since it is uniquely and strongly identifying to a person. The GDPR prohibits the processing of such data unless there is explicit consent, a legal obligation or public interest. In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation.[10] Judging from the clear imbalance between the students/their guardians and the school in the above case, the Swedish Data Protection Authority held the school liable under the GDPR for unlawfully processing the students’ facial data.

 

First lawsuit over facial recognition in China

Interestingly in contrast with the Swedish school case, also happened in 2019 and before the enactment of the PIPL, a court in Hangzhou ruled in the country’s first facial recognition lawsuit that the use of facial recognition technology for admission to a local safari park constituted a breach of the contract between the plaintiff and the Park.

Guo Bing, an associate law professor in Hangzhou city, filed a civil lawsuit against Hangzhou Safari Park in late 2019 after the Park required a facial identification process for his annual membership pass. He argued the Hangzhou Safari Park has no legal basis to collect visitors’ biometric data. Both courts in the first instance and second instance ruled in favor of Guo Bing, ordering the Park to refund him and delete his facial data and fingerprints.[11]

However, the courts’ judgements are criticized for being too narrow and also for the failure to touch on the legitimacy of the Park’s overbearing policy which mandated facial identification for entry. From the perspective of contract law, the courts of first and second instance ruled that the Park’s requirement of facial recognition to enter the park does not have legal effect on Guo contractually, but the courts avoided the review of the arbitrary clause that 'users who have not registered their face for facial recognition will not be able to enter the park ever'. That is however the key claim in Guo’s lawsuit against the Park.

 The above being said, Guo’s case is still significant as the first lawsuit to challenge the commercial use of facial recognition technology. Citing Guo’s case, China’s Supreme People’s Court (“SPC”) announced that consumers’ privacy must be protected from unwarranted face tracking,[12] a signal that China is tightening the leash on the facial recognition industry.

 

Judicial interpretation on use of facial recognition

On July 28, 2021 the SPC promulgated the Provisions (the “Provisions”) on several issues concerning the application of law in the trial of civil cases relating to processing of personal information by using the facial recognition technology.[13] The Provisions came into force on August 1, 2021.

The Provisions apply to civil cases that involve facial recognition technology. The Provisions set forth that hotels, shopping malls, airports and other commercial venues should not use facial recognition in violation of the laws and administrative regulations. The use of the technology is only allowed when there is clear legal basis and cannot exceed what is necessary, and companies must take measures to protect the facial data. The Provisions also provide that consent is not a valid legal basis if companies denied providing products or services on the condition that a consent is given, unless the processing of facial information is necessary for the provision of such products or services. Property management companies must obtain the consent of the residents before using facial recognition. In case of refusal of consent, alternative verification methods must be offered.

While the Provisions are not clear on what counts as necessary use, the possibility of penalties from lawsuits is likely to curb some excessive uses of people’s facial data. The Provisions also specifies a mechanism for the public to sue if their privacy has been violated and option for injunction is also available in cases where irreparable harm would be caused without an injunctive relief.

 

Key Takeaways

·   Thorough impact assessment should be conducted prior to the launching of any facial recognition implementation.

·   For businesses to stay compliant with the PIPL, despite the scale and the intent of the use of facial recognition technology, regulatory and professional opinions have to be consulted.

·   Consent should not provide a valid legal ground for the processing of personal data in cases where there is a clear imbalance between the data subject and the controller.

·   Consent should be invalid if there is an “opt-in-or-leave” situation, unless the processing of facial data is absolutely necessary for the products or services offered.

 

Conclusion

After the enactment of the PIPL and the China Supreme People’s Court’s promulgation of the Provisions, it remains to be seen how the administration will enforce these rules, how the courts will adjudicate in lawsuits involving facial recognition and whether such enforcement/adjudication will actually curb the abuses of facial recognition technology. For whatever the future holds, one thing is certain: businesses must realize that to advance any frontier technology, building public trust is essential to the effectuation that the public can enjoy the benefits offered by the technology. Before the public can entrust their sensitive personal data to the facial recognition businesses, they must have confidence that the use is with necessity, and that the use is lawful, fair, transparent and also safely guarded.



 



[1] See https://www.globaltimes.cn/content/1067645.shtml.

[2] See The Future of Privacy Forum, Privacy Principles for Facial-Recognition Technology in Commercial Applications (September 2018), https://fpf.org/wp-content/uploads/2019/03/Final-Privacy-Principles-Edits-1.pdf.

[3] Ibid.

[4] Ibid.

[5] Closed-circuit television (CCTV) or video surveillance is camera systems used to transmit signals to a specific location often with visualization on a limited number of televisions or computer monitors. See Hong Kong Lawyer, CCTV and Privacy Rights (December 2019).

[6]  Under the PIPL, sensitive personal information is defined as “the personal information of which the leakage or illegal use   could easily lead to the violation of the personal dignity of a natural person or harm to personal or property safety, including    information on biometric identification, religious beliefs, specific identity, health care, financial accounts, and personal whereabouts, and personal information of minors under the age of fourteen.” (Art. 28).

[7] The General Data Protection Regulation (EU) 2016/679.

[8] See https://edpb.europa.eu/news/national-news/2019/facial-recognition-school-renders-swedens-first-gdpr-fine_sv.

[9] GDPR defines “biometric data” as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data. See https://gdpr-info.eu/art-4-gdpr/.

[10] See https://www.privacy-regulation.eu/en/recital-43-GDPR.htm.

[11] See https://xw.qq.com/cmsid/20201120A0EPDD00.

[12] See https://m.thepaper.cn/baijiahao_13819929.

[13] See http://en.pkulaw.cn/Display.aspx?Lib=law&Id=36687&keyword.


  • 相关资讯 More
  • 点击次数: 999999
    2025 - 11 - 07
    作者:张琳一、引言合同是当事人之间的法律,与企业经营成败息息相关,因此加强合同管理对于企业来说至关重要。2015年12月4日最高人民法院发布了19起合同纠纷典型案例,其中有一个案例虽已时隔数年,但仍具有重要的现实指导意义。本文拟结合该案例探讨当今企业如何加强合同管理。 二、案情简介案号:临沂市兰山区人民法院(2013)临兰商初字第3091号民事判决书、山东省临沂市中级人民法院(2014)临商终字第99号 王XX从事贩卖板皮业务,孙YY为个体工商户AA板材厂的经营者,孙ZZ为孙YY之兄。王XX多次与AA板材厂发生买卖夹心皮的业务关系。2012年4月1日,王XX给AA板材厂送夹心皮,孙ZZ当时给王XX出具了出货单,载明:夹心皮,货款236000元。孙YY分别于2012年4月14日和10月17日向王XX名下银行账户存款54000元和10000元。2023年9月17日,王XX给孙YY打电话催要226000元货款,孙YY表示十月一过后安排点。 后王XX以买卖合同纠纷为由将孙YY、孙ZZ诉至一审法院,请求判令孙YY、孙ZZ支付所欠货款226000元及利息。一审法院经审理认为:1、孙ZZ收到王XX价值236000元夹心皮的事实有当事人陈述及王XX提交的出库单一份等证据予以证实。王XX向孙ZZ索要货款,孙ZZ理应支付。但是,王XX提交的证据不足以证明孙ZZ、孙YY系合伙经营或共同经营,故王XX要求孙YY共同偿付欠款的诉讼请求,证据不足,不予支持。2、王XX对孙YY于2012年10月17日金额为10000元的转账凭证无异议。孙ZZ主张已偿付欠款64000元,有其提交的合计金额为64000元的银行个人业务凭证予以证实,王XX虽主张2012年4月14日金额为54000元的转款并非偿付该案所诉欠款,但未提交相关证据予以证实。因此,合计金额为64000元的转款应当在王X...
  • 点击次数: 1000004
    2025 - 10 - 31
    作者:金涟伊《中华人民共和国民法典》第一百二十三条将“地理标志”与商标、著作权等并列为可产生专有权利的知识产权客体。简言之,地理标志是一种可确权、可受益的资产,谁能证明“原产地身份”,谁就能合法获得商业红利。 一、地理标志的渊源 根据国家知识产权局商标局发布的《地理标志的概念和特征》一文,地理标志(Geographical Indications)是现代知识产权制度的重要组成部分,是TRIPs协定所确定的七大类知识产权之一。与商标、专利侧重“个体智慧成果”不同,地理标志保护的是“传统集体智慧”,即因特定自然与人文条件而成就的产品品质与声誉。其概念历经“货源标记—原产地名称—地理标志”的演进,各国保护模式亦呈多样化。 我国对地理标志的系统保护始于 1999 年《原产地域产品保护规定》,后逐步过渡到 2005 年《地理标志产品保护规定》及 2023 年《地理标志产品保护办法》。。 二、核心概念拆解 地理标志是一个法定概念。要深入了解地理标志,首先要分清几个相关概念:地理标志产品、地理标志产品保护、地理标志产品名称、地理标志专用标志。后文将以五常大米为例辅助理解。 1、地理标志产品 地理标志产品是指产自特定地域,所具有的质量、声誉或其他特性本质上取决于该产地的自然因素和人文因素,经审核批准以地理名称进行命名的产品。如产自五常地区、经原国家质量监督检验检疫总局审核公告核准实施原产地域产品保护(即地理标志产品保护)的五常大米产品。根据百度百科记载,五常大米历史可追溯到唐初渤海国时期,受产区独特的地理、气候等因素影响,干物质积累多,直链淀粉含量适中,支链淀粉含量较高,颗粒饱满,质地坚硬,色泽清白透明;饭粒油亮,香味浓郁。 2、地理标志产品保护 地理标志产品保护目前主要由《地理标志产品保护规定》(2...
  • 点击次数: 1000002
    2025 - 10 - 24
    作者:张嘉畅您是否正在经营自主品牌?您是否在网购平台发现类似商品?您是否在投诉、警告过程中,被对方以商品描述为“同款”而抗辩?我相信很多权利人都曾遇到过这种问题,对方明明销售了类似的商品,明明在网店当中使用了您的商标,但因为标注了“XX同款”而被网购平台判定为不是商标性使用,仅为商品描述,进而认定未侵权。针对这种情况,江苏省南京市中级人民法院做出判决,认定在商品描述中使用他人的商标,也可被认定为商标侵权。一、 案件概况原告上海亚朵商业管理(集团)有限公司是国内知名酒店管理公司,经营酒店及相关产品供应链。2021年,原告在24类“织物;纺织品毛巾;浴巾;被子;毛毯;床单;家庭日用纺织品;餐桌用布;毡”等商品上获准注册其主营商标“亚朵”,注册号为49867247号。被告一某某易购集团股份有限公司主营国内中型网购平台,被告二某某易购集团有限公司某某采购中心是被告一的分公司,在被告一的网购平台上注册并经营“某某易购官方旗舰店”。原告发现,被告二在其经营的网店当中,未经原告许可,大量销售侵害原告涉案注册商标专用权的商品,在网店介绍、商品图片中大量使用并突出展示侵权标识。被告在网店当中使用“记忆棉枕头芯沉睡慢回弹护颈椎助睡眠儿童亚朵酒店同款旗舰店1847”“全棉可水洗羽丝绒枕芯柔软枕头亚朵酒店同款家用护颈枕25”及“旗舰店亚朵同款星球枕枕头枕芯沉睡枕护颈枕助睡眠枕头旗”等商品标题。在公证购买后,原告取证到被告二邮寄的商品包裹内有枕头一个,无制造商信息,且快递面单上写有“亚朵双拼枕”字样。综上,原告认为被告的行为构成商标侵权和不正当竞争。被告一、二辩称:1. 被诉侵权商品是枕头,与原告享有商标权的49867247号商标指定商品具有明显差异,不应认定为相同或类似商品,不构成商标侵权。2. 被诉侵权商品的详情页中明确标明自有品牌,“亚朵同款”的描述是指同种款式、平价替代,并非商标性...
  • 点击次数: 1000004
    2025 - 09 - 26
    作者:王辉 在员工严重失职给公司造成重大损失时,公司能否依据《劳动合同法》第三十九条解除劳动合同?公司解雇行为属于合法维权还是违法侵权?司法实践中,公司胜诉与败诉的案例皆不鲜见。下文就结合司法案例,从公司合法解除与违法解除两个视角剖析其中关键。一、实务案例◆案例1  合法解除 (参见(2022)京0105民初16489号判决书)原告张某与某顾问公司分别于2007年12月24日、2010年1月1日、2013年1月1日签订劳动合同,2015年3月1日张某与北京某人力资源有限公司签订劳动合同,张某与上述案外公司签订劳动合同后均派遣至被告某公司工作。2021年1月1日原告与被告某公司签订无固定期限劳动合同,从事销售岗位。2021年3月26日,被告某公司以原告张某从事货品职务,因工作失误造成北京某零售部订货损失870件,价值375354元为由解除与张某签署的劳动合同。后张某向北京市朝阳区劳动人事争议仲裁委员会提出仲裁申请,朝阳仲裁委作出京朝劳人仲字[2021]第18715号裁决书,驳回张某的全部仲裁请求。张某不服,诉至法院。被告某公司为证明其解雇行为合法提交了《员工违纪过失单》、邮件截屏、微信聊天记录截屏、损失明细表、《零售员工手册》、征求意见函、通知工会函。《员工违纪过失单》载明:“违纪人姓名:张某;违纪时间:2021年3月25日;违纪经过:工作失误导致某零售公司订货损失870件金额375354元。违反的规定条款:条款原文:丙类(严重)过失行为:由于管理不当、工作失误或玩忽职守或其他个人原因,造成人身伤害或公司财产损失人民币500元以上。”员工签字处显示张某姓名签字,落款日期为2021年3月26日。微信聊天记录截屏显示时间为“星期四12:40”的信息内容:“某某今天有补货,邮件转给你了,销售好款保证店铺两周周转,从开始到导完单告诉我用了多长时间。”张某回复:“好...
× 扫一扫,关注微信公众号
铭盾MiNGDUN   www.mdlaw.cn                                               犀牛云提供企业云服务 
Copyright© 2008 - 2025 铭盾京ICP备14029762号-1                                                                                                                                隐私政策   免责声明       
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开