Language

All About Face: Use of Facial Recognition and Legal Restrictions

All About Face: Use of Facial Recognition and Legal Restrictions

 

Author: Yingying Zhu, Partner of Beijing MingDun Law Firm

Email: zhu.yingying@mdlaw.cn

Date: November 10, 2021

 

Introduction

From public places laden with facial verification cameras to residential buildings that shut strangers out with facial identification requirements, facial recognition technology is being used almost everywhere in China which has contributed to the low criminal rates and high level of public security, earning China the reputation as one of the safest places in the world to travel around.[1] Beyond the bright side, there has been at least one dark side to the overwhelming use of cameras-the possible leaks of people’s biometric identification information to outlaws and hackers. Nowadays, the public becomes increasingly concerned about providing their facial data to various service providers. The calls for safeguarding and curbing excessive uses of people’s facial data are on the rise.

 

Background

On November 1st, 2021, China’s first comprehensive data privacy law, the Personal Information Protection Law of the People’s Republic of China (the “PIPL”), has become effective. The PIPL basically requires that the operators of websites, mobile phone applications or any other technologies doing data collection and processing should obtain consent from users in order to collect/process the users’ data.

To address the increasing public concerns of the necessity to curb the abuses of people’s biometric data, the PIPL specifically regulates the collection of biometric data and the use of facial recognition technology in public areas.

Apart from the enactment of the PIPL, there was a lawsuit in Hangzhou stemming from dispute over the use of facial recognition equipment and a judicial interpretation on the same subject promulgated by the China Supreme People’s Court.

 

What is facial recognition?

No definition is provided under the PIPL or the judicial interpretation. According to The Future of Privacy Forum, the Facial recognition (currently defined to include facial verification and facial identification) means the technology that creates, collects, compares and retains facial templates that are identified or identifiable to particular individuals.[2]

Facial verification means a task where the facial recognition system confirms an individual’s claimed identity by comparing the template generated from a submitted facial image with a specific known template generated from a previously enrolled facial image. This process is also called one-to-one verification, or authentication.[3] 

Facial Identification means searching a database for a reference matching a submitted facial template and returning a corresponding identity, also known as “one-to-many” matching.[4]

From the above definitions, it can be deduced that facial recognition technology is not an equivalent of the conventional public camera surveillance[5] because it involves more than passive facial scanning and recording. If the usage of public surveillance camera involves no creation of personably identifiable facial templates which are identified or linked, or identifiable or linkable to individuals, it would neither constitute “facial recognition” nor arouse the same type of privacy concerns discussed under this article.

 

PIPL on facial recognition

 

1) processing of facial recognition data

Under the PIPL, facial recognition data, being a type of the biometric identification information, are classified under a specific category of information, sensitive personal information,[6] that must be treated with the following extra safeguarding:

1)   Personal information processors may not process sensitive personal information unless there are specific purposes and sufficient necessity, and strict protection measures are taken (Art. 28);

2)   An individual's separate consent shall be obtained for processing his or her sensitive personal information. Where any law or administrative regulation provides that written consent shall be obtained for processing sensitive personal information, such provision shall prevail (Art. 29); and

3)   To process sensitive personal information, personal information processors shall, notify individuals of the following:

    (a) identity of the processor (Art. 17);

    (b) purposes and methods of processing of personal information, categories of personal information to be processed, and the retention periods (Art. 17);

    (c) methods and procedures for individuals to exercise their rights (Art. 17);

    (d) necessity of the processing of sensitive personal information (Art. 30); and

    (e) the impacts on individuals’ rights and interests, except that it is not required by this Law to so notify (Art. 30).

 

2) use of facial recognition technology in public areas

Regarding the use of facial recognition technology in public areas, the PIPL provides as follows:

1)   The installation of image collection or personal identification equipment in public areas shall be necessary for maintaining public security and comply with relevant regulations issued by the state (Art. 26);

2)   Conspicuous signs shall be erected (Art. 26); and

3)   The collected personal images and identification information can only be used for the purpose of maintaining public security, and shall not be used for other purposes, except with the separate consent of individuals (Art. 26).

The above provisions basically provide that the use of facial recognition technology in public areas is only allowed for the purpose of maintaining public security where conspicuous signs shall be erected. It cannot be used for marketing, targeted advertising or any other commercial purposes, unless separate consent of individuals has been obtained.

One has but one face. Facial information is of a unique and unchangeable character for the individuals. As improper disclosures of facial data can cause greater harm and damage to the image, reputation or security of an individual, it is of significant importance to ensure that facial data be specifically categorized and appropriately protected. The PIPL’s position in regulating the use of facial recognition data echoes with that of the GDPR. [7]

 

A GDPR decision on the use of facial recognition

A decision handed down in August 2019 under the GDPR could shed some light on the position taken by the GDPR towards the use of facial recognition data. The Swedish Data Protection Authority (“DPA”) has imposed a fine of approximately 20,000 euros upon a municipality for using facial recognition technology to monitor the attendance of students in school. The school in northern Sweden has conducted a trial program using facial recognition to keep track of students’ attendance in school. The students’ guardians were asked to give and gave explicit consent and they also had the option of excluding their child from the program. The school has based the processing on consent but the Swedish DPA considers that consent was not a valid legal basis given the clear imbalance between the data subject and the controller. The Swedish DPA concluded the school has processed sensitive biometric data unlawfully and failed to do an adequate impact assessment including seeking prior consultation with the Swedish DPA. [8]

Under the GDPR, biometric data, [9] including that generated through facial recognition technology, is protected as a special category of personal data since it is uniquely and strongly identifying to a person. The GDPR prohibits the processing of such data unless there is explicit consent, a legal obligation or public interest. In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the data subject and the controller, in particular where the controller is a public authority and it is therefore unlikely that consent was freely given in all the circumstances of that specific situation.[10] Judging from the clear imbalance between the students/their guardians and the school in the above case, the Swedish Data Protection Authority held the school liable under the GDPR for unlawfully processing the students’ facial data.

 

First lawsuit over facial recognition in China

Interestingly in contrast with the Swedish school case, also happened in 2019 and before the enactment of the PIPL, a court in Hangzhou ruled in the country’s first facial recognition lawsuit that the use of facial recognition technology for admission to a local safari park constituted a breach of the contract between the plaintiff and the Park.

Guo Bing, an associate law professor in Hangzhou city, filed a civil lawsuit against Hangzhou Safari Park in late 2019 after the Park required a facial identification process for his annual membership pass. He argued the Hangzhou Safari Park has no legal basis to collect visitors’ biometric data. Both courts in the first instance and second instance ruled in favor of Guo Bing, ordering the Park to refund him and delete his facial data and fingerprints.[11]

However, the courts’ judgements are criticized for being too narrow and also for the failure to touch on the legitimacy of the Park’s overbearing policy which mandated facial identification for entry. From the perspective of contract law, the courts of first and second instance ruled that the Park’s requirement of facial recognition to enter the park does not have legal effect on Guo contractually, but the courts avoided the review of the arbitrary clause that 'users who have not registered their face for facial recognition will not be able to enter the park ever'. That is however the key claim in Guo’s lawsuit against the Park.

 The above being said, Guo’s case is still significant as the first lawsuit to challenge the commercial use of facial recognition technology. Citing Guo’s case, China’s Supreme People’s Court (“SPC”) announced that consumers’ privacy must be protected from unwarranted face tracking,[12] a signal that China is tightening the leash on the facial recognition industry.

 

Judicial interpretation on use of facial recognition

On July 28, 2021 the SPC promulgated the Provisions (the “Provisions”) on several issues concerning the application of law in the trial of civil cases relating to processing of personal information by using the facial recognition technology.[13] The Provisions came into force on August 1, 2021.

The Provisions apply to civil cases that involve facial recognition technology. The Provisions set forth that hotels, shopping malls, airports and other commercial venues should not use facial recognition in violation of the laws and administrative regulations. The use of the technology is only allowed when there is clear legal basis and cannot exceed what is necessary, and companies must take measures to protect the facial data. The Provisions also provide that consent is not a valid legal basis if companies denied providing products or services on the condition that a consent is given, unless the processing of facial information is necessary for the provision of such products or services. Property management companies must obtain the consent of the residents before using facial recognition. In case of refusal of consent, alternative verification methods must be offered.

While the Provisions are not clear on what counts as necessary use, the possibility of penalties from lawsuits is likely to curb some excessive uses of people’s facial data. The Provisions also specifies a mechanism for the public to sue if their privacy has been violated and option for injunction is also available in cases where irreparable harm would be caused without an injunctive relief.

 

Key Takeaways

·   Thorough impact assessment should be conducted prior to the launching of any facial recognition implementation.

·   For businesses to stay compliant with the PIPL, despite the scale and the intent of the use of facial recognition technology, regulatory and professional opinions have to be consulted.

·   Consent should not provide a valid legal ground for the processing of personal data in cases where there is a clear imbalance between the data subject and the controller.

·   Consent should be invalid if there is an “opt-in-or-leave” situation, unless the processing of facial data is absolutely necessary for the products or services offered.

 

Conclusion

After the enactment of the PIPL and the China Supreme People’s Court’s promulgation of the Provisions, it remains to be seen how the administration will enforce these rules, how the courts will adjudicate in lawsuits involving facial recognition and whether such enforcement/adjudication will actually curb the abuses of facial recognition technology. For whatever the future holds, one thing is certain: businesses must realize that to advance any frontier technology, building public trust is essential to the effectuation that the public can enjoy the benefits offered by the technology. Before the public can entrust their sensitive personal data to the facial recognition businesses, they must have confidence that the use is with necessity, and that the use is lawful, fair, transparent and also safely guarded.



 



[1] See https://www.globaltimes.cn/content/1067645.shtml.

[2] See The Future of Privacy Forum, Privacy Principles for Facial-Recognition Technology in Commercial Applications (September 2018), https://fpf.org/wp-content/uploads/2019/03/Final-Privacy-Principles-Edits-1.pdf.

[3] Ibid.

[4] Ibid.

[5] Closed-circuit television (CCTV) or video surveillance is camera systems used to transmit signals to a specific location often with visualization on a limited number of televisions or computer monitors. See Hong Kong Lawyer, CCTV and Privacy Rights (December 2019).

[6]  Under the PIPL, sensitive personal information is defined as “the personal information of which the leakage or illegal use   could easily lead to the violation of the personal dignity of a natural person or harm to personal or property safety, including    information on biometric identification, religious beliefs, specific identity, health care, financial accounts, and personal whereabouts, and personal information of minors under the age of fourteen.” (Art. 28).

[7] The General Data Protection Regulation (EU) 2016/679.

[8] See https://edpb.europa.eu/news/national-news/2019/facial-recognition-school-renders-swedens-first-gdpr-fine_sv.

[9] GDPR defines “biometric data” as personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data. See https://gdpr-info.eu/art-4-gdpr/.

[10] See https://www.privacy-regulation.eu/en/recital-43-GDPR.htm.

[11] See https://xw.qq.com/cmsid/20201120A0EPDD00.

[12] See https://m.thepaper.cn/baijiahao_13819929.

[13] See http://en.pkulaw.cn/Display.aspx?Lib=law&Id=36687&keyword.


  • 相关资讯 More
  • 点击次数: 0
    2024 - 07 - 19
    作者:刘艳玲中国商标法第48条规定了商标的使用,是指将商标用于商品、商品包装或者容器以及商品交易文书上,或者将商标用于广告宣传、展览以及其他商业活动中,用于识别商品来源的行为。商标性使用一般用于商业活动,目的是引导消费者购买其认可的商品,帮助商品提供者与消费者在市场上建立起重要的联系。司法审判中区分商标性使用和非商标性使用非常重要,是否侵害他人商标专用权,主要看商标使用是否属于“商标性使用”。非商标性使用一般用于非商业活动,其目的不是引导消费者识别商品或服务来源。即使在商业活动中使用,如果属于描述性使用或指示性使用,也会被认为是商标的正当使用,不侵犯他人商标权。中国商标法第59条第1款列举了商标的描述性使用方式。指示性使用在我国司法实践中存在用于不侵权抗辩,这种使用需限定在合理使用范围内,因此称为指示性合理使用更确切。相对比地,美国商标法“Lanham Act”中也有商标正当使用的概念。美国商标法的正当使用原则包括描述性正当使用和指示性正当使用。在指示性正当使用中,可以未经他人许可使用他人的商标,用于比较广告、新闻报道、新闻评论、学术工作、模仿和批评和评论等目的。 下面展开讨论非商标性使用的情形,这有助于企业或个人初步了解自己对他人商标的使用是否会侵犯商标权。    非商标性使用-描述性使用  商标或服务提供者除标识自己的商标,以便于消费者识别外,还会对商品的质量、主要原料、功能、用途、重量、数量、产地、型号或者生产者的名称等其他特点予以说明,从而使消费者了解商品的特性、使用方法等,以达到促销其商品或服务的目的。根据中国商标法第59条的规定,注册商标权人无权禁止他人正当使用。 例如,A公司在销售网页链接中使用“Dliziz椰子款”标识销售鞋类商品,其中,“Dliziz”是A公司的注册商标,而“椰子”标识是另一B公司...
  • 点击次数: 1000000
    2024 - 07 - 05
    作者:金涟伊在当今互联网迅猛发展的背景下,电子商务已经成为人们最普遍的交易手段。然而,由于法律的相对滞后性,与电子商务相关的法规亟需进一步完善。对于未经商标注册人授权,在网络店铺名称使用与他人注册商标相同或相似的标识的行为,现行的商标法并未对此提供明确的指导。相关权利人在维权过程中通常同时援引商标法和反不正当竞争法,而不同法院在判决时所依据的法律也存在差异。 经检索相关判决书,我们发现法院判决主要有两种不同观点,一是认为网络店铺名称可类比于企业名称,以反不正当竞争法予以规制,二是认为网络店铺名称侵权导致相关公众混淆误认的,应认定为商标侵权。 2018年河北省高级人民法院所持的观点即为第一种观点。在(2018)冀民429号判决书中,河北省高级人民法院支持了一审法院的观点,即“……官方旗舰店的店铺名称属于一种企业(店铺)字号,而将他人注册商标用于自己企业字号的行为,已被《中华人民共和国商标法》第五十八条‘将他人注册商标、未注册的驰名商标作为企业名称中的字号使用,误导公众,构成不正当竞争的,依照《中华人民共和国反不正当竞争法》处理。’的规定吸纳,不属于《中华人民共和国商标法》第五十七条规定的侵害商标专用权的情形。” 故此,法院依据反不正当竞争法作出裁判,维护了权利人的相关权益。 但更多判决倾向于第二种观点。2020年北京市西城区人民法院在(2020)京0102民初27860号判决中认为,被诉侵权店铺将商标使用于店铺名称、店铺内宣传、商品名称及商品图片等位置,此种使用系为标明商品来源,属于商标性使用,因此适用商标法第五十七条第一款的规定,被告的行为侵害了原告的商标专用权。 2022年义乌市人民法院在(2022)浙0782民初6308号判决中认为,“对于被告滔馨公司在其网店名称及网店LOGO中使用‘泉日记’字样的行为,并未经过原告的授...
  • 点击次数: 1000005
    2024 - 06 - 28
    作者:张嘉畅 在对美贸易当中,商标保护是至关重要的一环。注册美国商标有利于商标在海关备案,有利于避免商标侵权,同时,经营亚马逊平台商家也需要注册美国商标从而进行亚马逊店铺的品牌备案。与中国商标法不同,美国商标制度更加注重商标在商业当中的实际使用。从申请到注册甚至续展,申请人在许多环节需要向美国专利商标局提供使用证据,以确保商标有效。本文旨在整理美国商标申请注册需提交使用证据的关键环节,以便外贸企业快速了解,避免商标因错过提交使用证据时间而影响商标效力。 美国注册商标需要提供使用声明及证据的时间节点如下表: 一、申请阶段 美国商标申请的申请依据有五种:1. 根据商标法第 1(a) 条,在商业中使用商标;(2) 根据商标法第 1(b) 条,有在商业中使用商标的真实意图;(3) 根据商标法第 44(d) 条,基于在先提交的外国申请,要求优先权;(4) 根据商标法第 44(e) 条,拥有申请人原籍国的商标注册所有权;以及 (5) 根据商标法第 66(a) 条,将国际注册的保护延伸至美国。 当申请人选择商标法1(a)条款,即以实际使用为依据提交申请时,需要在申请的同时提交商标已使用声明,并在每个类别提交使用证据,说明申请人如何在商业经营当中使用该商标。 如果申请商标尚未在美国实际投入使用,申请人也可以选择以意图使用为依据提交申请。此种方式提交申请时无需提交使用证据,但需要基于其在商业中使用商标的真实意图。在商标经过实质审查被核准后的6个月内,申请人需要像1(a)申请一样提交使用声明,并且同时提交使用证据。用此种依据提交美国申请,有助于商标权利人在商业经营当中更早地进行商标申请,也有更多的准备时间将商标投入使用。 其他申请依据通...
  • 点击次数: 1000003
    2024 - 06 - 21
    作者:陈巴特【基本案情】2019年1月,B公司作为承包人,与发包人A公司签订了《建设工程施工合同》,约定由B公司承包A公司发包的某项目工程施工。合同对工期、总价款、工程款的结算和支付、质量标准、违约责任等诸多事项进行了详细约定。自然人C某在项目所在地多年承包工程施工,具有较强的施工能力及经济实力。C某欲承包该项工程,找到B公司,请求B公司将该项工程全部转包给C某施工,B公司同意以“内部承包”的方式将该项工程转包。随后,C某委托自然人D某与B公司签订了《施工项目内部管理目标责任书》(以下简称《目标责任书》),约定双方权利义务,并约定C某安排D某作为该工程项目负责人具体组织施工。在施工过程中,管理人员及劳务队均由C某聘用,前期垫资均由C某通过财务人员支出。但C某因有其他工程项目需要亲自管理,极少到该工程施工现场,更没有和B公司、A公司相关人员直接对接联系。D某作为项目负责人,则常与B公司、A公司相关人员直接对接联系。在精心组织下,该项目工程在工期内顺利完工,并于2020年10月通过竣工验收合格,依法在当地建设管理中心备案。2021年11月,发包人A公司委托第三方对该项目工程造价进行结算审核。经审核,结算造价为人民币850万余元。2023年5月,因尚有285万余元的工程款长时间未支付,且多次主张权利未果的情况下,C某以实际施工人名义,作为原告,将A公司和B公司列为共同被告,一纸诉状诉至项目所在地人民法院。在诉讼过程中,B公司为推卸责任,主张C某不具备诉讼主体资格,实际施工人应是D某和C某,并安排其财务人员及D某出庭作证。财务人员证明其一直和D某对接联系,并未见过C某,D某是实际施工人。D某本人则出庭作证,陈述自己和C某合伙,享有15%合伙份额,是共同的实际施工人,D某无权单独提起诉讼。但C某同时表示自己从未投入资金,亦未有书面合伙协议证实。【争议焦点】本案在工程价款、质量等其他问...
× 扫一扫,关注微信公众号
北京市铭盾律师事务所 www.mdlaw.cn
Copyright© 2008 - 2020北京市铭盾律师事务所京ICP备09063742号-1犀牛云提供企业云服务
X
1

QQ设置

3

SKYPE 设置

4

阿里旺旺设置

5

电话号码管理

6

二维码管理

展开