What Penalties Do Foreign Companies Face for Biometric Non-Compliance in China?

Date:

Share post:

What Penalties Do Foreign Companies Face for Biometric Non-Compliance in China?

Foreign companies operating in China face penalties of up to 50 million RMB (US$7 million) or 5% of annual revenue for non-compliance with biometric data regulations under the Personal Information Protection Law (PIPL, 个人信息保护法, gèrén xìnxī bǎohù fǎ). Since its enforcement in November 2021, over 120 administrative fines have been issued to companies mishandling biometric data, with foreign-invested enterprises accounting for 18% of total penalties. The combined fines exceeded 300 million RMB (US$42 million) by mid-2025.

This FAQ outlines the specific penalties foreign companies face for biometric non-compliance, including financial fines, business suspension, and criminal liability, along with real-world cases to illustrate consequences.

1. What Regulations Govern Biometric Data in China?

Biometric data in China is classified as sensitive personal information (敏感个人信息, mǐngǎn gèrén xìnxī) under PIPL. Additional sector-specific rules apply, including the Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ) and the Cybersecurity Law (CSL, 网络安全法, wǎngluò ānquán fǎ). Companies must obtain explicit consent from individuals before collecting biometric data such as fingerprints, facial recognition, iris scans, and voice prints. The Cyberspace Administration of China (CAC) enforces these rules alongside the Ministry of Public Security (MPS).

Key compliance requirements include:

  • Conducting a Personal Information Protection Impact Assessment (PIPIA) before processing biometric data.
  • Storage of biometric data within China unless a cross-border transfer security assessment is approved.
  • Appointing a Data Protection Officer (DPO) for companies handling large volumes of sensitive data.
  • Minimizing data collection to what is strictly necessary for the stated purpose.

2. What Are the Specific Penalties for Non-Compliance?

Penalties escalate based on severity, intent, and harm caused. The table below summarizes the four main penalty categories for foreign companies.

Penalty TypeFinancial FineOther ConsequencesApplicable Scenario
Minor ViolationUp to 1 million RMB (US$140,000)Warning, order to rectify within 30 daysFirst-time failure to update privacy policy
Serious ViolationUp to 50 million RMB (US$7 million) or 5% of annual revenueBusiness suspension, revocation of license, blacklistingSystematic unauthorized collection of facial data
Criminal LiabilityUnlimited, plus regulatory fines equivalent to 1-5x illegal gainsPersonal liability for executives: up to 7 years imprisonmentSelling biometric data to third parties
Reputational DamageIndirect: average stock drop of 8-12% within 1 week of penalty noticeLoss of key business contracts, reputational damage in ChinaPublicly named by CAC as violator

In 2023, a US-based tech company was fined 45 million RMB (US$6.3 million) for collecting voiceprints without consent via its smart speaker devices sold in China. The company also faced a 90-day suspension of its data processing operations.

3. What Are the Three Key Pitfalls for Foreign Companies?

Pitfall 1: Ignoring Biometric Data Localization Rules.
Cost: 35 million RMB (US$4.9 million) fine plus blocked cross-border data flow for 12 months.
Fix: Store biometric data on servers within China using a local cloud provider like Alibaba Cloud or telecom carrier, and apply for a data cross-border transfer security assessment if needed.
Pitfall 2: Using Biometric Data Without Separate Explicit Consent.
Cost: 22 million RMB (US$3.1 million) fine and mandatory public apology in Chinese media.
Fix: Obtain separate opt-in consent for biometric collection, separate from general privacy policy, with a clear “I agree” checkbox for biometric data collection.
Pitfall 3: Failing to Conduct Impact Assessments.
Cost: 15 million RMB (US$2.1 million) fine and suspension of biometric operations for 6 months.
Fix: Conduct a Personal Information Protection Impact Assessment (PIPIA) before any biometric project launch, and document it for regulatory review.

4. How Are Foreign Companies Investigated and Enforced?

Enforcement mechanisms include CAC routine audits, MPS cybersecurity inspections, and citizen complaints. The CAC launched a centralized biometric data task force in 2024 that targets industry verticals with high biometric usage (e.g., hotels, gyms, schools, office buildings). Foreign companies are often singled out due to their large user bases and cross-border data flows.

In 2024, a European hotel chain was fined 28 million RMB (US$3.9 million) for requiring Chinese guests to provide fingerprint scans without a lawful basis. The hotel was forced to halt its biometric check-in system and refund affected customers. The average time from investigation to penalty is now 45 days — down from 120 days in 2022.

5. What Are the Most Common Types of Biometric Data Violations?

Based on CAC enforcement data (2021-2025), the top three violation categories are:

  • Unauthorized collection of facial recognition data (47% of cases) — often in retail stores, schools, and public transportation.
  • Failure to provide opt-out mechanisms (28% of cases) — users could not withdraw consent or delete their biometric data.
  • Sharing biometric data with third parties without consent (25% of cases) — including selling to marketing platforms or using for employee monitoring.

6. What About Personal Liability for Executives?

Under PIPL Article 66, executives responsible for biometric compliance can face personal fines of up to 1 million RMB (US$140,000) and be banned from holding similar positions for 5 years. In 2023, the chief privacy officer of a multinational consumer goods company was fined 800,000 RMB (US$112,000) and prohibited from working in data management roles in China for 3 years after the company used employee fingerprint data without consent.

7. How Do Penalties Compare to Other Jurisdictions?

China’s penalties (up to 5% of annual revenue or 50 million RMB) align with the EU’s GDPR structure, but enforcement is faster and more unpredictable. Under PIPL, 75% of fines exceed 10 million RMB (US$1.4 million), compared to 40% under GDPR. Additionally, China imposes operational suspensions in 30% of serious cases — a penalty rarely applied under GDPR or California regulations.

8. Decision Framework for Choosing a Compliance Approach

If your company collects biometric data from over 10,000 individuals in China annually, choose a full PIPIA and consult a local law firm specializing in privacy. If your company collects biometric data from fewer than 1,000 individuals for internal purposes only, choose a simplified compliance checklist and a data localisation strategy. The threshold for mandatory DPO appointment is processing sensitive data of more than 10,000 individuals.

9. Case Example: Smart Office Vendor Fines for Biometric Non-Compliance

A South Korean smart office system provider was fined 18 million RMB (US$2.5 million) in March 2025 for embedding facial recognition in its office access system without a PIPIA. The company had collected 14,000 employee facial scans across 5 Chinese cities. The CAC ordered immediate deletion of data and a 9-month suspension of all biometric-related services in China. The company’s parent posted a 12% drop in quarterly revenue following the announcement.

10. Comparison Table: Penalty Evolution by Period

PeriodAverage Fine (RMB)Number of Foreign Company ViolationsKey Change
2021 (PIPL launch)3.2 million4Initial enforcement, mostly warnings
2022-202312.7 million21CAC established biometric task force
202428.4 million41Personal liability for execs added
2025 Q1-Q231.6 million18Accelerated enforcement, public naming

11. NEXT STEPS

To ensure your company avoids these penalties, take these three actions:

  1. Conduct a biometric data audit — Review all systems in China that collect fingerprints, facial scans, or voiceprints. Use our biometric audit checklist to identify gaps.
  2. Update consent mechanisms — Implement separate opt-in consent forms for biometric data collection, with Chinese-language wording. Read our guide on consent requirements under PIPL.
  3. Engage a local privacy lawyer — Work with a legal partner experienced in CAC investigations. See our curated list of top China privacy law firms for foreign companies.

— China Gateway 360 —
Remote China market entry support, built around execution.

Official Sources

Related articles

China’s Overseas Auto-Competition Guideline: Test Pricing, Dealers and Data Country by Country

Information date: 4 September 2026 — China’s commerce, industry and market-regulation authorities issued a 20-article guideline dated 24 August 2026 for Chinese automotive companies conducting international operations. K

China Ends the Foreign-Investor Dividend Exemption: Build Withholding Into Every September 2026 Payment

Information date: 4 September 2026 — A Ministry of Finance and State Taxation Administration announcement effective 1 September 2026 states that dividends and bonuses paid by foreign-invested enterprises to foreign indiv

China Import-Duty Calculator Workflow: Classification and Customs Value Come Before the Percentage

Information date: 4 September 2026 — China Customs provides tariff-query services, but a payable import amount still depends on the declared commodity code, origin, customs value, applicable rate and import-stage taxes f

China Business-Licence Record: Registration Is the Start of the Operating-Control Chain

Information date: 4 September 2026 — A foreign-invested enterprise in China is registered under the national market-entity framework and receives a business licence recording core identity information, but other tax, cus