Law note · China
Provisions on Security Management of Facial Recognition Technology Application
China's first dedicated facial-recognition regulation requires voluntary, explicit, separately-obtained consent before capturing facial information, with guardian consent for a minor under 14, and requires using the method with the least impact on individual rights available.
It mandates that facial data be stored on the collecting device rather than transmitted over the internet absent a legal exception or separate consent, caps retention at the minimum necessary period, bars facial recognition as the sole identity-verification method wherever another method exists, bans facial recognition devices inside private spaces within public venues such as hotel rooms and changing rooms, and requires a processor holding facial data on 100,000 or more people to file with the provincial cyberspace authority.
No comparably dedicated voiceprint regulation exists; a January 2026 CAC draft for public comment would extend this same on-device-storage approach to fingerprint and voiceprint data, but it had not been finalized as of this research date and is not authored as its own instrument here. Article 2 carves facial-recognition R&D and algorithm-training activities out of the Measures' scope, so the duties below bind deployment and use, not model training (第二条: 不适用本办法的规定).
What it asks of an app
- These duties bind the deployment and use of facial recognition; Article 2 exempts facial-recognition R&D and algorithm-training activities from the Measures. Obtain separate, explicit, informed, voluntary consent before collecting or using facial recognition data, with guardian consent for anyone under 14, and use the method with the least impact on individual rights available.
- Store captured facial information only on the recognition device itself; do not transmit it over the internet unless a legal exception applies or the individual has separately consented.
- Retain facial information no longer than the minimum time necessary for the stated purpose.
- Offer a non-facial-recognition verification alternative whenever one exists; do not make facial recognition the sole means of identity verification.
- Do not install facial recognition devices inside hotel rooms, public bathhouses, public changing rooms, or public restrooms.
- File with the provincial-level cyberspace administration once the stored facial-information count reaches 100,000 individuals.
When LexLint raises it
Declared activities: processes_biometrics, high_risk_decisions
Primary source: official CAC-published regulation text