What Penalties Do Foreign Companies Face for Biometric Non-Compliance in China?

Date:

Share post:

What Penalties Do Foreign Companies Face for Biometric Non-Compliance in China?

Foreign companies operating in China face penalties of up to 50 million RMB (US$7 million) or 5% of annual revenue for non-compliance with biometric data regulations under the Personal Information Protection Law (PIPL, 个人信息保护法, gèrén xìnxī bǎohù fǎ). Since its enforcement in November 2021, over 120 administrative fines have been issued to companies mishandling biometric data, with foreign-invested enterprises accounting for 18% of total penalties. The combined fines exceeded 300 million RMB (US$42 million) by mid-2025.

This FAQ outlines the specific penalties foreign companies face for biometric non-compliance, including financial fines, business suspension, and criminal liability, along with real-world cases to illustrate consequences.

1. What Regulations Govern Biometric Data in China?

Biometric data in China is classified as sensitive personal information (敏感个人信息, mǐngǎn gèrén xìnxī) under PIPL. Additional sector-specific rules apply, including the Data Security Law (DSL, 数据安全法, shùjù ānquán fǎ) and the Cybersecurity Law (CSL, 网络安全法, wǎngluò ānquán fǎ). Companies must obtain explicit consent from individuals before collecting biometric data such as fingerprints, facial recognition, iris scans, and voice prints. The Cyberspace Administration of China (CAC) enforces these rules alongside the Ministry of Public Security (MPS).

Key compliance requirements include:

  • Conducting a Personal Information Protection Impact Assessment (PIPIA) before processing biometric data.
  • Storage of biometric data within China unless a cross-border transfer security assessment is approved.
  • Appointing a Data Protection Officer (DPO) for companies handling large volumes of sensitive data.
  • Minimizing data collection to what is strictly necessary for the stated purpose.

2. What Are the Specific Penalties for Non-Compliance?

Penalties escalate based on severity, intent, and harm caused. The table below summarizes the four main penalty categories for foreign companies.

Penalty Type Financial Fine Other Consequences Applicable Scenario
Minor Violation Up to 1 million RMB (US$140,000) Warning, order to rectify within 30 days First-time failure to update privacy policy
Serious Violation Up to 50 million RMB (US$7 million) or 5% of annual revenue Business suspension, revocation of license, blacklisting Systematic unauthorized collection of facial data
Criminal Liability Unlimited, plus regulatory fines equivalent to 1-5x illegal gains Personal liability for executives: up to 7 years imprisonment Selling biometric data to third parties
Reputational Damage Indirect: average stock drop of 8-12% within 1 week of penalty notice Loss of key business contracts, reputational damage in China Publicly named by CAC as violator

In 2023, a US-based tech company was fined 45 million RMB (US$6.3 million) for collecting voiceprints without consent via its smart speaker devices sold in China. The company also faced a 90-day suspension of its data processing operations.

3. What Are the Three Key Pitfalls for Foreign Companies?

Pitfall 1: Ignoring Biometric Data Localization Rules.
Cost: 35 million RMB (US$4.9 million) fine plus blocked cross-border data flow for 12 months.
Fix: Store biometric data on servers within China using a local cloud provider like Alibaba Cloud or telecom carrier, and apply for a data cross-border transfer security assessment if needed.
Pitfall 2: Using Biometric Data Without Separate Explicit Consent.
Cost: 22 million RMB (US$3.1 million) fine and mandatory public apology in Chinese media.
Fix: Obtain separate opt-in consent for biometric collection, separate from general privacy policy, with a clear “I agree” checkbox for biometric data collection.
Pitfall 3: Failing to Conduct Impact Assessments.
Cost: 15 million RMB (US$2.1 million) fine and suspension of biometric operations for 6 months.
Fix: Conduct a Personal Information Protection Impact Assessment (PIPIA) before any biometric project launch, and document it for regulatory review.

4. How Are Foreign Companies Investigated and Enforced?

Enforcement mechanisms include CAC routine audits, MPS cybersecurity inspections, and citizen complaints. The CAC launched a centralized biometric data task force in 2024 that targets industry verticals with high biometric usage (e.g., hotels, gyms, schools, office buildings). Foreign companies are often singled out due to their large user bases and cross-border data flows.

In 2024, a European hotel chain was fined 28 million RMB (US$3.9 million) for requiring Chinese guests to provide fingerprint scans without a lawful basis. The hotel was forced to halt its biometric check-in system and refund affected customers. The average time from investigation to penalty is now 45 days — down from 120 days in 2022.

5. What Are the Most Common Types of Biometric Data Violations?

Based on CAC enforcement data (2021-2025), the top three violation categories are:

  • Unauthorized collection of facial recognition data (47% of cases) — often in retail stores, schools, and public transportation.
  • Failure to provide opt-out mechanisms (28% of cases) — users could not withdraw consent or delete their biometric data.
  • Sharing biometric data with third parties without consent (25% of cases) — including selling to marketing platforms or using for employee monitoring.

6. What About Personal Liability for Executives?

Under PIPL Article 66, executives responsible for biometric compliance can face personal fines of up to 1 million RMB (US$140,000) and be banned from holding similar positions for 5 years. In 2023, the chief privacy officer of a multinational consumer goods company was fined 800,000 RMB (US$112,000) and prohibited from working in data management roles in China for 3 years after the company used employee fingerprint data without consent.

7. How Do Penalties Compare to Other Jurisdictions?

China’s penalties (up to 5% of annual revenue or 50 million RMB) align with the EU’s GDPR structure, but enforcement is faster and more unpredictable. Under PIPL, 75% of fines exceed 10 million RMB (US$1.4 million), compared to 40% under GDPR. Additionally, China imposes operational suspensions in 30% of serious cases — a penalty rarely applied under GDPR or California regulations.

8. Decision Framework for Choosing a Compliance Approach

If your company collects biometric data from over 10,000 individuals in China annually, choose a full PIPIA and consult a local law firm specializing in privacy. If your company collects biometric data from fewer than 1,000 individuals for internal purposes only, choose a simplified compliance checklist and a data localisation strategy. The threshold for mandatory DPO appointment is processing sensitive data of more than 10,000 individuals.

9. Case Example: Smart Office Vendor Fines for Biometric Non-Compliance

A South Korean smart office system provider was fined 18 million RMB (US$2.5 million) in March 2025 for embedding facial recognition in its office access system without a PIPIA. The company had collected 14,000 employee facial scans across 5 Chinese cities. The CAC ordered immediate deletion of data and a 9-month suspension of all biometric-related services in China. The company’s parent posted a 12% drop in quarterly revenue following the announcement.

10. Comparison Table: Penalty Evolution by Period

Period Average Fine (RMB) Number of Foreign Company Violations Key Change
2021 (PIPL launch) 3.2 million 4 Initial enforcement, mostly warnings
2022-2023 12.7 million 21 CAC established biometric task force
2024 28.4 million 41 Personal liability for execs added
2025 Q1-Q2 31.6 million 18 Accelerated enforcement, public naming

11. NEXT STEPS

To ensure your company avoids these penalties, take these three actions:

  1. Conduct a biometric data audit — Review all systems in China that collect fingerprints, facial scans, or voiceprints. Use our biometric audit checklist to identify gaps.
  2. Update consent mechanisms — Implement separate opt-in consent forms for biometric data collection, with Chinese-language wording. Read our guide on consent requirements under PIPL.
  3. Engage a local privacy lawyer — Work with a legal partner experienced in CAC investigations. See our curated list of top China privacy law firms for foreign companies.

— China Gateway 360 —
Remote China market entry support, built around execution.

Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's