Provisions on Security Management of Facial Recognition Technology Application
人脸识别技术应用安全管理办法 issued jointly by the Cyberspace Administration of China and the Ministry of Public Security, signed 13 March 2025, effective 1 June 2025
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 June 2025.
A biometric privacy rule binding public and private bodies.
As of 23 August 2026.
What it requires
- These duties bind the deployment and use of facial recognition; Article 2 exempts facial-recognition R&D and algorithm-training activities from the Measures. Obtain separate, explicit, informed, voluntary consent before collecting or using facial recognition data, with guardian consent for anyone under 14, and use the method with the least impact on individual rights available.
- Store captured facial information only on the recognition device itself; do not transmit it over the internet unless a legal exception applies or the individual has separately consented.
- Retain facial information no longer than the minimum time necessary for the stated purpose.
- Offer a non-facial-recognition verification alternative whenever one exists; do not make facial recognition the sole means of identity verification.
- Do not install facial recognition devices inside hotel rooms, public bathhouses, public changing rooms, or public restrooms.
- File with the provincial-level cyberspace administration once the stored facial-information count reaches 100,000 individuals.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
China's first dedicated facial-recognition regulation requires voluntary, explicit, separately-obtained consent before capturing facial information, with guardian consent for a minor under 14, and requires using the method with the least impact on individual rights available.
It mandates that facial data be stored on the collecting device rather than transmitted over the internet absent a legal exception or separate consent, caps retention at the minimum necessary period, bars facial recognition as the sole identity-verification method wherever another method exists, bans facial recognition devices inside private spaces within public venues such as hotel rooms and changing rooms, and requires a processor holding facial data on 100,000 or more people to file with the provincial cyberspace authority.
No comparably dedicated voiceprint regulation exists; a January 2026 CAC draft for public comment would extend this same on-device-storage approach to fingerprint and voiceprint data, but it had not been finalized as of the date shown and is not authored as its own instrument here. Article 2 carves facial-recognition R&D and algorithm-training activities out of the Measures' scope, so the duties below bind deployment and use, not model training (第二条: 不适用本办法的规定).
When LexLint raises it
processes_biometricshigh_risk_decisions
Read the law
official CAC-published regulation text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.