Skip to content

Face recognition in China

Under China's Personal Information Protection Law, biometric data is sensitive personal information. Processing it requires separate consent, a specific purpose and demonstrated necessity, plus a prior impact assessment. Article 26 additionally limits image capture and identification equipment in public places to public security purposes, with prominent signage.

What does PIPL require for face data?

The Personal Information Protection Law, in force since November 2021, defines sensitive personal information as information that, if leaked or unlawfully used, could readily lead to infringement of personal dignity or harm to personal or property safety. Biometric data is named in that category.

  1. Establish a specific purpose and sufficient necessity for processing the biometric data.
  2. Obtain separate consent β€” distinct from any general consent to a privacy policy β€” and written consent where other law requires it.
  3. Inform the person of the necessity and the effect on their rights before obtaining it.
  4. Carry out a personal information protection impact assessment in advance, and retain the record.
  5. Adopt strict protective measures proportionate to the sensitivity of the data.

Separate consent is a term of art. Consent bundled into acceptance of a general privacy policy does not satisfy it: the biometric processing needs its own consent action.

Can face recognition be used in public places in China?

Article 26 of PIPL restricts it. Image collection and personal identification equipment installed in public places may be installed only as required to safeguard public security, must comply with relevant state regulations, and must be accompanied by prominent indicating signs. Personal images and identification information so collected may only be used for the purpose of safeguarding public security, unless separate consent is obtained.

That is a narrower permission than a commercial operator usually wants. A retailer wishing to use face recognition for anything other than public security in a publicly accessible area is relying on separate consent, and has to be able to show how it was obtained.

Does face data have to stay in China?

For some operators, yes. Critical information infrastructure operators, and personal information handlers processing volumes above thresholds set by the Cyberspace Administration of China, must store personal information collected in China within the territory. Where such data needs to leave, one of the prescribed routes must be used.

  • A security assessment organised by the Cyberspace Administration of China.
  • Personal information protection certification by a recognised body.
  • The Chinese standard contract for cross-border transfer, filed as required.
  • Or no transfer at all, which is what an on-premise or air-gapped deployment produces.

Ayonix face recognition runs on the operator's own hardware, so detection, template extraction, storage and matching happen inside the operator's facility. Where there is no export of personal information, the cross-border mechanisms do not need to be engaged at all.

What should a buyer in China establish before deployment?

  • How separate consent is obtained and recorded, and what the person is told before giving it.
  • Whether the deployment is in a public place, and if so what public security purpose it serves.
  • That the required signage is in place and visible.
  • Whether the operator is a critical information infrastructure operator, which changes the localisation analysis.
  • That the personal information protection impact assessment is complete and retained.
  • Where the template database sits, and whether any component transmits outside the facility.

Export control and import rules apply to software and hardware independently of data protection law, and change over time. They are a separate assessment made against the rules in force at the time of supply.

This page describes what the named laws require, with each instrument cited so it can be checked. It is not legal advice, and it is not a statement that any particular deployment complies: that assessment belongs to your own counsel and your data protection authority.

Frequently asked questions

Is face recognition legal in China?
It is regulated rather than prohibited. Under the Personal Information Protection Law biometric data is sensitive personal information requiring separate consent, a specific purpose, demonstrated necessity and a prior impact assessment. Public places carry the additional restriction in Article 26.
What is 'separate consent' under PIPL?
Consent given specifically for the sensitive processing, distinct from general acceptance of a privacy policy. Bundling biometric consent into a broad policy acceptance does not meet the requirement; the processing needs its own consent action, preceded by an explanation of its necessity and effect.
Does personal information collected in China have to stay in China?
For critical information infrastructure operators and handlers above the thresholds set by the Cyberspace Administration of China, yes. Others may transfer abroad using a CAC security assessment, certification, or the Chinese standard contract. An on-premise deployment avoids the question by not transferring.
Can a shop in China use face recognition on customers?
In a publicly accessible place, Article 26 limits installed identification equipment to public security purposes with prominent signage. Use for any other purpose relies on separate consent from the individual, which the operator must be able to evidence.
Can Ayonix run entirely inside a facility in China?
Yes. Ayonix face recognition runs on the operator's own hardware, including the ATLAS BOX appliance and edge devices, so templates are created, stored and matched on site. An air-gapped configuration has no network route out at all.
Who regulates personal information in China?
The Cyberspace Administration of China is the principal regulator, working with sector authorities. The Personal Information Protection Law, the Data Security Law and the Cybersecurity Law operate together rather than separately.

Jan Mocary β€” Chief Technology Officer, Ayonix AI

Leads engineering for Ayonix face recognition and the ATLAS agent platform, including their on-premise and air-gapped deployment modes.