How to Comply with Biometrics Laws in China: 2026 Guide for Foreign Businesses

Date:

Share post:






How to Comply with Biometrics Laws in China: 2026 Guide for Foreign Businesses


How to Comply with Biometrics Laws in China: 2026 Guide for Foreign Businesses

Introduction: The Rapidly Evolving Landscape of Biometrics Regulation in China

China has one of the world’s most extensive and rapidly evolving legal frameworks governing the collection, storage, processing, and use of biometric data. With the widespread adoption of facial recognition, fingerprint scanning, voiceprint authentication, iris recognition, and other biometric technologies across industries — from financial services and healthcare to smart buildings, retail, and transportation — foreign businesses operating in China face a complex and often overlapping set of regulatory requirements that differ significantly from privacy frameworks in Europe, North America, and other Asian markets.

In 2026, China’s biometrics regulatory landscape is shaped by several key laws and regulations, most notably the Personal Information Protection Law (PIPL), which came into effect in 2021, and the more recent Regulations on the Management of Biometric Information (《生物识别信息管理规定》) issued by the Cyberspace Administration of China (CAC) in 2024. Together with industry-specific regulations from the People’s Bank of China (PBOC), Ministry of Public Security (MPS), and the Ministry of Industry and Information Technology (MIIT), these rules create a compliance environment that requires careful navigation.

This guide provides foreign businesses with a comprehensive overview of China’s biometrics laws, practical steps for achieving compliance, and strategies for managing the risks associated with biometric data processing in the Chinese market.

Key Statistic: By 2026, China is estimated to operate over 400 million surveillance cameras with facial recognition capabilities, and biometric authentication is used by over 1 billion mobile payment users daily. The regulatory framework has evolved rapidly in response to this unprecedented scale of biometric data processing.

1. The Legal Framework for Biometrics in China

1.1 The Personal Information Protection Law (PIPL)

The Personal Information Protection Law (个人信息保护法) is the foundational data privacy law in China and the primary legal instrument governing biometric data. PIPL classifies biometric information as “sensitive personal information” (敏感个人信息), which triggers enhanced protection requirements. Under PIPL, sensitive personal information is defined as information that, once leaked or illegally used, may infringe upon the personal dignity of natural persons or harm their personal or property safety.

Key PIPL provisions affecting biometric data include:

  • Separate consent requirement: Biometric data collection requires explicit, separate, informed consent from the data subject — blanket consent buried in general terms and conditions is not valid
  • Purpose limitation: Biometric data may only be processed for specifically stated, legitimate purposes directly related to the product or service being provided
  • Data minimization: Only the minimum amount of biometric data necessary to achieve the stated purpose may be collected
  • Impact assessment: A Personal Information Protection Impact Assessment (PIPIA) must be conducted before processing biometric data
  • Local storage requirement: As a general rule, biometric data collected in China must be stored within China (see Section 5 for cross-border transfer rules)
  • Security measures: Enhanced technical and organizational security measures are required, including encryption, access controls, and breach notification procedures

1.2 The Regulations on the Management of Biometric Information (2024)

In 2024, the CAC issued dedicated Regulations on the Management of Biometric Information, which provide detailed rules specifically for biometric data processing. Key provisions include:

  • Definition expansion: Biometric information is defined broadly to include facial features, fingerprints, palm prints, iris patterns, voiceprints, gait patterns, keystroke dynamics, and any other biological or behavioral characteristics that can identify a specific individual
  • Prohibition of covert collection: Biometric data cannot be collected without the data subject’s knowledge or through deception
  • Restrictions on public places: Biometric collection devices in public places must be clearly marked with visible signage; alternative non-biometric identification methods must be offered
  • Data retention limitation: Biometric data must be deleted once the processing purpose is achieved, unless retention is required by law
  • Mandatory data protection officer (DPO): Businesses processing biometric data of more than 100,000 individuals annually must appoint a DPO with specific qualifications
  • Registration requirement: Large-scale biometric data processing systems must be registered with the CAC

1.3 Industry-Specific Regulations

Beyond the general framework, several industry-specific regulations impose additional biometrics compliance requirements:

  • Financial sector (PBOC): Banks, payment institutions, and fintech companies must comply with PBOC regulations on biometric authentication for financial transactions, including specific requirements for liveness detection, encryption standards, and anti-spoofing measures
  • Telecommunications and internet (MIIT): Internet platforms and telecom operators must comply with MIIT regulations on user identity verification, which increasingly permit biometric authentication but require enhanced data protection measures
  • Public security (MPS): Security system operators, including those using facial recognition for access control or surveillance, must register their systems with local public security bureaus and comply with MPS technical standards
  • Healthcare (NHC): Healthcare providers using biometric data for patient identification or treatment must comply with NHC regulations on medical data protection, which impose additional confidentiality and security requirements
  • Residential property management: New regulations restrict the use of facial recognition for access control in residential communities, requiring consent and alternative entry methods

2. Key Compliance Requirements for Foreign Businesses

2.1 Consent and Notice Requirements

Obtaining valid consent for biometric data processing is the cornerstone of PIPL compliance. Foreign businesses must ensure their consent mechanisms meet the following standards:

  • Separate consent: Biometric consent must be obtained separately from the general terms and conditions or privacy policy. A checkbox or pop-up specifically dedicated to biometric data collection is required.
  • Informed consent: Data subjects must be informed in clear, plain language about: the types of biometric data being collected, the purpose of collection, the retention period, how the data will be processed and stored, whether it will be shared with third parties, and their rights to access, correct, and delete their biometric data.
  • Opt-in, not opt-out: Consent must be affirmative — pre-checked boxes or consent-by-silence is not valid. Users must actively indicate their agreement.
  • Right to withdraw: Data subjects must be able to withdraw consent at any time without negative consequences for the core service being provided.
  • Separate consent for each purpose: If biometric data is collected for multiple purposes (e.g., access control and attendance tracking), separate consent must be obtained for each purpose.

2.2 Data Minimization and Purpose Limitation

PIPL’s data minimization principle requires that you collect only the minimum biometric data necessary for the stated purpose. For example:

  • If facial recognition is used for building access control, you should not also use the same system for emotion analysis or behavior tracking unless separately justified and consented to
  • Fingerprint data collected for time and attendance purposes should not be used for identity verification in other systems
  • Biometric templates should be stored in irreversible hash form where possible, rather than raw biometric images

2.3 Personal Information Protection Impact Assessment (PIPIA)

Before commencing any biometric data processing activity, foreign businesses must conduct a PIPIA. The assessment must include:

  1. A description of the processing purpose and methods
  2. An evaluation of the potential impact on the rights and interests of data subjects
  3. An assessment of the risks to individual privacy and data security
  4. Proposed measures to mitigate identified risks

The PIPIA report must be kept on file and made available to the CAC upon request. There is no mandatory submission requirement for most cases, but failure to produce a PIPIA during a regulatory inspection can result in significant penalties.

2.4 Security Measures

Technical and organizational security measures for biometric data must meet the following standards:

  • Encryption: Biometric data must be encrypted both at rest and in transit using state-approved encryption algorithms (SM2, SM3, SM4 are recommended or required for certain applications)
  • Access controls: Role-based access controls with granular permissions; biometric data access should be limited to the minimum number of personnel necessary
  • Audit logging: Comprehensive audit logs of all access to and processing of biometric data, retained for at least 6 months (1 year for financial sector)
  • Liveness detection: For facial recognition and fingerprint systems, liveness detection technology must be deployed to prevent presentation attacks (photos, videos, masks, silicone fingers)
  • Template protection: Biometric templates should be stored in a cancellable biometric format where possible, allowing revocation and reissuance if compromised
  • Incident response plan: A documented incident response plan addressing biometric data breaches specifically, with notification procedures for affected individuals and regulators

3. Biometric Data Collection in Specific Contexts

3.1 Workplace Biometrics

Using biometric systems for employee time and attendance monitoring, facility access control, or workplace security is common in China but increasingly regulated. Key requirements include:

  • Employers must obtain explicit consent from employees — consent cannot be implied from the employment contract alone
  • Labor unions or employee representative bodies must be consulted before implementing biometric systems in the workplace
  • Alternative non-biometric access methods (access cards, PIN codes) must be available for employees who do not wish to provide biometric data
  • Biometric data of employees must not be shared with third parties (including HR outsourcing providers) without separate consent
  • Upon termination of employment, the employee’s biometric data must be deleted within a reasonable period (typically 30 days)

3.2 Customer-Facing Biometrics

Businesses that collect biometric data from customers — for example, for payment authentication, loyalty program identification, or personalized services — face additional requirements:

  • Clear signage: Visible notices must be posted at all points where biometric data is collected, informing customers of the collection
  • Alternative service channels: Customers must be able to access the same service without providing biometric data, without being penalized with worse service or longer wait times
  • Minor protection: Collecting biometric data from minors under 14 requires the consent of their parents or guardians
  • Prohibition on forced collection: Biometric collection cannot be a mandatory condition for receiving a product or service unless it is strictly necessary for the provision of that service

3.3 Public Spaces and Smart Buildings

For businesses operating smart buildings, retail spaces, or venues in China that deploy biometric systems:

  • Facial recognition cameras must be accompanied by clear, conspicuous signage indicating that biometric data is being collected
  • Footage retention must be limited to what is necessary (generally 30 days unless longer retention is legally required)
  • Biometric data collected for security purposes cannot be repurposed for marketing, analytics, or other commercial uses
  • Residential communities have special restrictions — facial recognition for access control requires majority consent from residents and alternative entry methods (key fobs, QR codes) must be provided

4. Cross-Border Transfer of Biometric Data

One of the most challenging compliance issues for foreign businesses is the cross-border transfer of biometric data. China imposes strict conditions on transferring biometric information outside its borders:

4.1 The Legal Basis for Cross-Border Transfers

Cross-border transfer of biometric data collected in China is permitted only under one of the following mechanisms:

Mechanism Applicable To Requirements Processing Time
CAC Security Assessment CII operators; processors handling ≥1M persons’ data; data transferred abroad cumulatively since Jan 1 of prior year covering ≥100K persons’ sensitive data Full security assessment by CAC; detailed documentation including data mapping, purpose justification, and foreign recipient assessment 3–9 months
Standard Contractual Clauses (SCCs) Processors below CAC assessment thresholds File CAC-approved SCCs with provincial CAC office; conduct PIPIA; notify data subjects; 30-day filing period before transfers begin 1–3 months
Certification Processors below CAC assessment thresholds Obtain certification from CAC-accredited certification body; subject to periodic audits 3–6 months

In practice, most foreign businesses handling biometric data of Chinese data subjects will need to use either the CAC Security Assessment (for larger processing operations) or the SCC route (for smaller-scale processing). Both options require significant compliance investment.

4.2 Data Localization

Given the complexity of cross-border transfer mechanisms, many foreign businesses choose to localize biometric data storage and processing within China. This can be achieved through:

  • Establishing data processing infrastructure within China (either self-managed or through a local cloud provider such as Alibaba Cloud, Huawei Cloud, or Tencent Cloud)
  • Engaging a Chinese data processor who stores and processes biometric data locally while providing access to the foreign business through secure interfaces
  • Using a joint venture or WFOE structure where biometric data is processed and stored by the China-based legal entity

Data localization does not eliminate all compliance obligations, but it does avoid the need for cross-border transfer approvals, significantly simplifying the overall compliance burden.

5. Enforcement and Penalties

Non-compliance with China’s biometrics regulations can result in severe penalties:

  • Administrative fines: Under PIPL, fines for serious violations can reach up to RMB 50 million (approximately USD 7 million) or 5% of the company’s previous year’s annual revenue, whichever is higher
  • Suspension of business: CAC and relevant regulators can order suspension of biometric data processing activities, suspension of related business operations, or revocation of business licenses
  • Personal liability: Directors, officers, and directly responsible personnel can face personal fines of up to RMB 1 million and potential prohibition from holding management positions
  • Civil liability: Affected individuals can bring class-action-style lawsuits seeking damages for privacy violations
  • Reputational damage: CAC maintains a public list of companies that have violated data protection regulations, which can severely damage market reputation

Enforcement has intensified significantly since 2024. In 2025 alone, CAC and its provincial offices conducted over 300 enforcement actions related to biometric data violations, with total fines exceeding RMB 200 million.

6. Building a Biometrics Compliance Program

Foreign businesses should establish a comprehensive biometrics compliance program covering the following elements:

  1. Data mapping and inventory. Document every instance of biometric data collection, processing, storage, and sharing within your China operations. Include the legal basis, purpose, retention period, security measures, and data flows for each processing activity.
  2. Conduct PIPIAs. For each biometric data processing activity, conduct a formal PIPIA following CAC guidelines. Document and retain all assessment reports.
  3. Update privacy notices and consent mechanisms. Ensure your Chinese-language privacy policy and consent mechanisms meet PIPL requirements for sensitive personal information. Implement separate consent workflows for biometric data.
  4. Implement technical security measures. Deploy encryption (preferably using Chinese national cryptographic standards), access controls, audit logging, and liveness detection appropriate to the risk level of your biometric processing activities.
  5. Establish a data protection officer (DPO). Appoint a DPO with knowledge of Chinese data protection law and biometrics regulations. The DPO should be based in China or have formal representation in China.
  6. Prepare cross-border transfer documentation. If biometric data crosses borders, prepare the appropriate legal mechanism (SCCs or CAC assessment application) and maintain supporting documentation including PIPIA, data mapping, and foreign recipient assessments.
  7. Develop incident response procedures. Create a biometric data breach response plan that complies with PIPL’s 72-hour notification requirement and addresses the specific risks of biometric data exposure.
  8. Monitor regulatory developments. China’s biometrics regulations continue to evolve. Subscribe to regulatory intelligence services and maintain relationships with China-based privacy law advisors who can alert you to new requirements.

Conclusion

Compliance with China’s biometrics laws is a complex but manageable challenge for foreign businesses. The regulatory framework, while stringent, provides clear guidance on what is required: separate consent, purpose limitation, data minimization, impact assessments, robust security measures, and careful management of cross-border data transfers.

The businesses that invest in proper biometrics compliance gain more than just regulatory safety. They also build trust with Chinese consumers, employees, and business partners — a trust that is increasingly valuable in a market where data privacy awareness is rising rapidly. As China continues to refine and enforce its biometrics regulations, early investment in compliance will become a competitive advantage that separates successful market entrants from those who struggle with regulatory hurdles.


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's