Yu Runze
Facial recognition information, as a category of sensitive personal information, is subject under Article 29 of the Personal Information Protection Law of the People’s Republic of China to the heightened requirement of separate consent. Nevertheless, the application of this rule encounters pronounced dilemmas in practice: the criteria for identifying separateness remain ambiguous; consent becomes increasingly formalized; static consent mechanisms are detached from the dynamic and cross-contextual realities of facial recognition technology; and principle-based legislation sits in tension with technologically complex scenarios. Drawing on contextual integrity theory, this article proposes several improvement pathways: clarifying the operational standards of separate consent in terms of interface independence, targeted disclosure, and express manifestation of consent; shifting from static consent to a dynamic consent mechanism featuring layered notice, continuous choice, and real-time updating; applying the rule in a differentiated manner according to specific contexts; and strengthening the coordinated safeguards of administrative supervision and judicial relief, including the presumption of fault and public interest litigation. Only through such a dynamic balance can the protection of facial recognition information and the rational utilization of technology be reconciled, so that every act of face scanning truly rests upon the autonomous, informed, and effective consent of the data subject.
Facial Recognition Information; Separate Consent; Sensitive Personal Information; Dynamic Consent; Contextual Integrity; Personal Information Protection Law