Back to news

Legal Updates

April 21, 2025

China Introduces New Regulations on Facial Recognition Technology

Analysis of China’s new Facial Recognition Security Management Measures, highlighting regulatory scope and operational compliance duties.

On 21 March 2025, the Cyberspace Administration of China and the Ministry of Public Security jointly announced the release of the Security Management Measures for the Application of Facial Recognition Technology (the “<span class="news-text_medium">Measures</span>”), which will take effect on 1 June 2025. Below is a summary of the scope and key requirements outlined in these Measures.

Scope of the Measures

The Measures apply to the use of facial recognition technology for processing facial data to identify individuals within China. However, they do not cover activities involving facial recognition technology used for research or algorithm development purposes. Facial information refers to biometric data related to an individual's facial features, which can be captured electronically or through other methods and pertains to an identified or identifiable person, excluding any anonymised data. Facial recognition technology refers to biometric systems that use facial data to identify a person.

Specific Processing Requirements for Facial Recognition Technology

The Measures set out specific requirements that must be followed when facial recognition technology is used. These include:

  • <span class="news-text_medium">Storage:</span> Facial data must be stored within the facial recognition device and cannot be transmitted over the internet, unless explicit consent is obtained from the individual or allowed by applicable laws and regulations.
  • <span class="news-text_medium">Privacy Impact Assessment (“PIA”):</span> Data handlers must conduct a PIA before processing facial data.
  • <span class="news-text_medium">Public Spaces:</span> Facial recognition devices can be installed in public areas, but only if the data handler can demonstrate the necessity for maintaining public security. Additionally, the data handler must clearly define the area for facial data collection and prominently display warning signs.
  • <span class="news-text_medium">Restriction:</span> Data handlers should not rely solely on facial recognition for verification if other technologies can achieve the same goal or meet the business requirements.
  • <span class="news-text_medium">Filing Requirement:</span> If a data handler processes facial data of more than 100,000 individuals, they must file with the relevant Cyberspace authority at the provincial or higher level within 30 business days once that threshold is reached. The filing should include basic details about the data handler, the purpose and method of processing facial data, security measures and a copy of the PIA. If any substantial changes occur, the filing must be updated within 30 business days. If facial recognition use is discontinued, the filing must be cancelled within 30 business days and the facial data must be handled in accordance with the law.
Address
London:
2 Eaton Gate
London SW1W 9BJ
New York:
295 Madison Ave 12th Floor
New York City, NY 10017
Paris:
56 Avenue Kléber,
75116 Paris
BELGRAVIA LAW LIMITED is registered with the Solicitors Regulation Authority with SRA number 8004056 and is a limited company registered in England & Wales with company number 14815978. The firm’s registered office is at 2 Eaton Gate, Belgravia, London SW1W 9BJ.

‘Belgravia Law’ (c) 2025. All rights reserved.
By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts. View our Privacy Policy and Cookie Policy for more information.