Binding law — in force
Editing a person's face or voice requires their independent consent (China Deep Synthesis)
Under China's Deep Synthesis Provisions Art. 14, a provider offering functions that edit biometric information such as faces and voices must prompt users to notify the individual whose biometric information is being edited and obtain that individual's independent consent. Also mandates training-data security + PIPL compliance where training data includes personal information. Detect a face/voice-editing or -swapping path with no consent capture from the person whose biometric identity is synthesized.
Who it applies to
- Duty falls on: provider
- Systems covered: limited risk
- Deep synthesis service providers and technical supporters operating in China that offer face/voice biometric-editing functions. Effective 2023-01-10.
The guard to add
Prompt the user to notify the person being edited and store that person's own separate consent, keyed to the sample, before any face-swap or voice-clone call runs.
In the face or voice editing flow, the upload step tells the user to notify the person whose face or voice will be edited and collects that person's separate consent (their own confirmation, for example through a link sent to them, not the uploader ticking a box on their behalf), stored as a subject_consent record keyed to the uploaded sample. The service function that calls the swap or clone model (inswapper, FaceFusion, SimSwap, voices.ivc.create, speaker_wav=) looks up that record for the sample's hash and refuses to run when it is missing or withdrawn. Editing the user's own face or voice goes through the same notice and consent step.
Where it goes: 1 application source code, 2 data models, 14 user-facing text.
Example (FastAPI + insightface), before:
@app.post('/swap')
async def swap(target: UploadFile, face: UploadFile):
tgt, src = load_image(await target.read()), load_image(await face.read())
out = swapper.get(tgt, analyzer.get(tgt)[0], analyzer.get(src)[0], paste_back=True)
return image_response(out)After:
@app.post('/swap')
async def swap(target: UploadFile, face: UploadFile, consent_id: str = Form(...)):
src_bytes = await face.read()
consent = subject_consents.get(consent_id)
if (consent is None or consent.withdrawn
or consent.sample_sha256 != hashlib.sha256(src_bytes).hexdigest()):
raise HTTPException(403, 'the person in this face image has not consented to editing')
tgt, src = load_image(await target.read()), load_image(src_bytes)
out = swapper.get(tgt, analyzer.get(tgt)[0], analyzer.get(src)[0], paste_back=True)
return image_response(out)Control: Editing a person's biometric (face/voice) without their consent. The same guard addresses 1 item with binding law in 1 jurisdiction. Engineering guidance, not legal advice.
Rule id cn-deep-synthesis.biometric-editing-consent · review status: primary source derived