Compare with different regulatory event:


Consultation opened on draft Information Security Technology Face Recognition Data Security Requirements

On 23 April 2021, China's National Information Security Standardisation Technical Committee (TC260) published and opened a consultation on the draft Information Security Technology Face Recognition Data Security Requirements, which proposes rules on the collection, processing, and storage of facial data. The Requirements identify three scenarios involving facial recognition: face verification, face recognition, and face analysis, with the first two scenarios being subject to the Requirements. Aside from general data processing and security standards, the Requirements stipulate that means of identification without facial recognition must be provided, that minors under the age of fourteen should not be identified using facial recognition, that the data subject's informed consent must be obtained, and that the data may not be used for purposes other than identification. The Requirements also limit the retention of face recognition data and stipulate that face images should be deleted immediately after verification or identification. The consultation will close on 22 June 2021.

Original source


Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
Implementation Level
Government Branch
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
in consultation

On 23 April 2021, China's National Information Security Standardisation Technical Committee (TC260)…

processing consultation

On 22 June 2021, China's National Information Security Standardisation Technical Committee (TC260) …


On 14 October 2022, China's National Information Security Standardisation Technical Committee (TC26…

in force

On 1 May 2023, China's National Information Security Standardisation Technical Committee (TC260) im…

Key regulatory dimensions

Regulated subjects

The businesses, government agencies or individuals affected by this policy or regulatory change.
producer / supplier
Type Any
Economic activity cross-cutting
Category All

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.
personal data: biometric: data processing
Regulatory tool
Preventive security requirement
Purpose/processing limitation
User notification requirement
Regulated subjects
personal data: biometric: data collection
Regulatory tool
Preventive security requirement
User notification requirement
Regulated subjects
personal data: biometric: storage (any form)

Policy change by business practice

The detailed activities within the scope of this policy or regulatory change.

personal data: biometric: data processing

personal data: biometric: data collection

personal data: biometric: storage (any form)