Control
Editing a person's biometric (face/voice) without their consent
A deep-synthesis/face-voice-editing function must notify the person whose biometric is being edited and obtain their independent consent.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Reach
Law in force in China (CN).
The guard to add
Prompt the user to notify the person being edited and store that person's own separate consent, keyed to the sample, before any face-swap or voice-clone call runs.
In the face or voice editing flow, the upload step tells the user to notify the person whose face or voice will be edited and collects that person's separate consent (their own confirmation, for example through a link sent to them, not the uploader ticking a box on their behalf), stored as a subject_consent record keyed to the uploaded sample. The service function that calls the swap or clone model (inswapper, FaceFusion, SimSwap, voices.ivc.create, speaker_wav=) looks up that record for the sample's hash and refuses to run when it is missing or withdrawn. Editing the user's own face or voice goes through the same notice and consent step.
Where it goes: 1 application source code, 2 data models, 14 user-facing text.
What reviewers look for: a notice in the upload UI asking the user to notify the edited person (a notify_subject step); a stored consent record (subject_consent, 单独同意 or 授权) given by that person and keyed to the specific sample; a lookup of that record on the same path before the swap or clone call that fails closed when it is missing or withdrawn.
Example (FastAPI + insightface), before:
@app.post('/swap')
async def swap(target: UploadFile, face: UploadFile):
tgt, src = load_image(await target.read()), load_image(await face.read())
out = swapper.get(tgt, analyzer.get(tgt)[0], analyzer.get(src)[0], paste_back=True)
return image_response(out)After:
@app.post('/swap')
async def swap(target: UploadFile, face: UploadFile, consent_id: str = Form(...)):
src_bytes = await face.read()
consent = subject_consents.get(consent_id)
if (consent is None or consent.withdrawn
or consent.sample_sha256 != hashlib.sha256(src_bytes).hexdigest()):
raise HTTPException(403, 'the person in this face image has not consented to editing')
tgt, src = load_image(await target.read()), load_image(src_bytes)
out = swapper.get(tgt, analyzer.get(tgt)[0], analyzer.get(src)[0], paste_back=True)
return image_response(out)Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Binding law — in force (1)
- China (CN)
- Editing a person's face or voice requires their independent consent (China Deep Synthesis) 互联网信息服务深度合成管理规定 第十四条 (Art. 14)