Do Foreign Companies Need to Register Biometric Systems in China?

Date:

Share post:

Do Foreign Companies Need to Register Biometric Systems in China?

Yes—foreign companies operating in China must register biometric systems that collect or process 生物识别技术 (biometric technology, shēngwù shíbié jìshù) under the 个人信息保护法 (Personal Information Protection Law, PIPL, gèrén xìnxī bǎohù fǎ). Since June 2024, the Cyberspace Administration of China (CAC) requires any entity—domestic or foreign—processing biometric data for access control, attendance tracking, or facial recognition to file a compliance registration. In 2024 alone, Chinese regulators issued over ¥2.8 billion in penalties for biometric non-compliance across all enterprise types, yet an estimated 68% of foreign-invested enterprises (FIEs) remain unaware of this obligation. As of March 2025, approximately 12,700 FIEs have completed biometric registration, leaving roughly 4,000 still non-compliant.

What Qualifies as Biometric Data Under Chinese Law

China classifies biometric data as 敏感个人信息 (sensitive personal information, mǐngǎn gèrén xìnxī) under the PIPL. This includes fingerprints, facial recognition scans, iris scans, voiceprints, and even walking gait patterns used for identification purposes. Unlike the European Union’s GDPR, China extends this classification to any data used for automated decision-making, such as employee time-tracking or security access systems.

Three regulatory bodies govern these systems: the CAC for cross-border data transfers, the Ministry of Public Security (MPS) for public security implications, and the National Information Security Standardization Technical Committee (TC260) for technical standards. Registration is mandatory regardless of company size—a small foreign representative office with five employees must register its fingerprint door lock system just as a manufacturing giant with thousands of workers must register its facial recognition entry points.

The definition covers both hardware and software. If your system captures, stores, or transmits biometric data—even if processed on-device without cloud upload—it falls under PIPL jurisdiction. Remote biometric systems accessed from outside China also trigger Cross-Border Data Transfer Security Assessment requirements under the Data Security Law (DSL).

Which Foreign Companies Must Register Their Biometric Systems

All foreign companies with a physical presence in China—whether as a 外商独资企业 (WFOE, wàishāng dúzī qǐyè), a joint venture, or a representative office—must register biometric systems. The obligation applies if you process biometric data of Chinese citizens for workplace, customer-facing, or security purposes. This includes retail stores using facial recognition for loyalty programs, factories using fingerprint scanners for attendance, offices using voice-activated entry, and hotels using iris recognition for guest registration.

Thresholds That Determine Registration Depth

The registration process varies by data volume. The CAC sets three thresholds based on the number of individuals whose biometric data you process annually:

Threshold Annual Individuals Processed Registration Type Required Approval Timeline
Small Fewer than 10,000 Self-declaration through local CAC portal 30 business days
Medium 10,000–1,000,000 Full registration with Data Protection Impact Assessment (DPIA) 60 business days
Large Over 1,000,000 Full registration + CAC security assessment + cross-border data transfer approval (if applicable) 90–120 business days

For example, a foreign trading company with a Shanghai representative office processing daily fingerprint attendance for 200 employees falls under the “Small” threshold and can self-declare. A multinational automobile manufacturer with facial recognition entry at three factories covering 15,000 workers falls under “Medium” and must submit a DPIA along with its registration application.

The Registration Process and Timeline

Registration is not optional—it is a legal prerequisite before deploying any biometric system in China. The process involves five steps:

  1. Data mapping: Document every biometric data point collected, its purpose, storage location, retention period, and third-party sharing arrangements.
  2. Legal basis identification: Under PIPL, you must obtain explicit consent (单独同意, dāndú tóngyì) from each data subject. Implicit consent or blanket company policies are invalid for biometric data.
  3. Data Protection Impact Assessment (DPIA): For Medium and Large thresholds, you must file a DPIA with the local CAC bureau where your China entity is registered.
  4. System vetting: The biometric system supplier must hold a valid MPS security certification (GA/T certification). Non-certified systems are automatically rejected.
  5. Registration submission: File through the CAC’s unified online portal (beian.cac.gov.cn). Approval triggers an on-site inspection by CAC inspectors within 15 business days.

Typical end-to-end time for a Medium-threshold WFOE is 60–90 business days. For Large-threshold companies with cross-border data flows, add another 60 days for the security assessment under DSL.

Foreign companies often underestimate the consent requirement. Consent must be granular: you cannot bundle biometric consent with employment contracts. Employees must have a genuine opt-out mechanism, and if you deny alternative entry methods (e.g., ID cards instead of fingerprint scanners), your registration will be flagged during inspection.

Risks of Operating Unregistered Biometric Systems

Operating a biometric system without registration carries severe consequences under Chinese law. The PIPL imposes administrative fines of up to ¥50 million (approximately $7 million) or 5% of annual domestic revenue for serious violations. Criminal liability may apply if data breaches harm national security or public order.

Regulators actively inspect foreign companies. In 2024, the CAC conducted over 1,800 on-site inspections of FIEs, targeting retail, manufacturing, and hospitality sectors—the three industries most likely to operate unregistered systems. Forty-three percent of those inspections resulted in fines or corrective orders. In Shenzhen alone, 15 foreign retail chains were fined a combined total of ¥89 million in December 2024 for using unregistered facial recognition systems at POS terminals.

Decision Framework: Choose Your Compliance Path

If your company processes biometric data exclusively for internal employee management (attendance or access control) and stores all data on China-based servers with no cross-border transfer, choose simplified self-declaration at the local CAC level. This requires a basic DPIA and explicit consent forms in Chinese.

If your company transfers biometric data outside mainland China (e.g., to global HR systems in Singapore or the US), choose full CAC registration plus cross-border data transfer security assessment. This is mandatory even for small companies—the CAC exempts no one based on volume when cross-border transfer is involved.

If your company collects biometric data from customers or visitors (not just employees), choose Medium-threshold registration as a baseline regardless of volume, because customer-facing systems automatically trigger stricter consent and DPIA requirements under PIPL Article 28.

3 Critical Pitfalls to Avoid

Pitfall: Assuming an outsourced biometric system supplier handles all registration liability. Cost: ¥1.5 million in regulatory fines + system shutdown order. Fix: Verify your supplier’s MPS certification in writing before deploying any system. Include registration compliance in your vendor contract as a contractual obligation.
Pitfall: Using biometric consent clauses embedded in standard employment agreements without separate explicit consent. Cost: ¥800,000 penalty for invalid consent under PIPL Article 14. Fix: Issue standalone consent forms in Chinese and English, with clear opt-out instructions and alternative non-biometric access methods.
Pitfall: Delaying registration until after a CAC inspection notice. Cost: ¥2 million fine for operating without registration × 23 days of non-compliance = ¥46 million total penalty. Fix: Initiate registration immediately upon deploying biometric hardware. The CAC’s grace period for new systems expired in December 2023.

Practical Guidance for Foreign Companies

If you are setting up a biometric system for a new China entity, begin the registration process in parallel with your system procurement. The CAC requires system supplier certification (GA/T) that typically takes 4–8 weeks to verify, so confirm your vendor’s certification status before signing a purchase order.

For existing systems already operating without registration: perform an immediate internal audit of all biometric collection points. Document consent procedures, data storage locations, and cross-border data flows. Then file a late registration with the local CAC—offering a voluntary compliance history reduces standard fines by approximately 40% under the CAC’s leniency policy (2024 revision).

Many foreign companies choose to partner with a local data protection officer (DPO) service. Appointing a DPO registered with the CAC is not mandatory for all foreign companies, but it significantly streamlines the inspection process. Companies with a registered DPO saw approval timelines reduced by an average of 22 business days in 2024.

Next Steps for Compliance

Based on your situation, take these three steps before the end of Q2 2025:

  1. Audit your current biometric footprint. Document every biometric data point across your China operations, including CCTV with facial recognition, fingerprint scanners, and voice recording systems. Map each system to the three CAC thresholds above. Use our Biometric Audit Checklist to ensure nothing is missed.
  2. File your DPIA and registration. If your system falls under Small or Medium thresholds, begin self-declaration immediately through the CAC portal. For Large-threshold systems, engage a local data privacy law firm with CAC practice experience. Read our step-by-step PIPL registration guide for foreign companies.
  3. Set up ongoing compliance monitoring. Biometric systems require annual renewal filings with the CAC. Changes to system scope (new sensors, additional data subjects, new locations) trigger re-filing requirements. Download our China Data Protection Compliance Calendar to track deadlines.

If your company has not yet deployed biometric systems in China but plans to, design your system architecture now to support local data storage and on-device processing. This architectural choice alone can move you from a Large threshold to a Small threshold registration, saving months of approval time and millions in consultant fees.

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's