Deconstructing the CCPLet the world understand the CCP. The CCP ≠ the Chinese people.

Mechanism

How Bodies Become Identity Leads: The Five-Layer Biometric Identification Stack

Face, voiceprint, gait, and vehicle systems use different signals. Procurement shows requested interfaces, while law sets boundaries; neither proves actual accuracy.

Contents

Visual Guide

A Five-Layer Framework from Signal to Public-Security Action

The first four layers describe technical processing. The fifth is an accountability safeguard that should precede public-security action, not a universal technical step documented in every deployment. Procurement records usually cover only part of this chain.

Capture SampleObtain an image, voice segment, or video sequence and check quality
Generate TemplateConvert comparable features into a machine-processable representation
Link and StoreLink the template to person, vehicle, or case fields
Match and List CandidatesRun one-to-one verification or one-to-many search and return similarity candidates
Accountability Before Public-Security ActionBefore public-security action, reviewers check the underlying signal and independent evidence

A camera may capture a face and a microphone may record a voice, but neither produces an identity directly. The signal still passes through quality screening, feature extraction, enrollment, and comparison; public-security action requires an additional accountability stage. Faces, voiceprints, gait, license plates, and vehicle appearance can enter a similar workflow, but their signals and failure conditions differ. Calling them all “biometric identification” can hide what each step identifies.

Problem and Importance: Why Four Signals Are Not One Algorithm

Face recognition processes a facial region from a photograph or video frame and creates a template from computable facial-image features. Voiceprint recognition processes an audio segment and needs a sample long enough to analyze. Gait recognition depends on a person's body outline and movement across consecutive frames, so a single photograph cannot provide the same information. License-plate recognition reads characters. Vehicle-appearance recognition uses visible features such as vehicle type and color. It identifies the vehicle, not the bodily characteristics of the people inside it.

These differences determine collection conditions. Occlusion, camera angle, and lighting affect a facial image. Background noise and recording length affect a voice sample. Gait requires continuous, usable video. On page 35, a Hohhot smart-traffic tender lists algorithmic analysis of faces, human bodies, motor vehicles, non-motor vehicles, and gait. Page 37 separately lists face, human-body, and vehicle images and structured data for delivery to third-party platforms, as well as alarm-plan management. Page 38 lists vehicle-attribute recognition and vehicle-trajectory analysis, while page 39 details gait analysis, search, and comparison. These are distinct data types and service capabilities that can connect through one platform, not outputs of one general-purpose algorithm. [5]

How It Works: A Five-Layer Framework from Raw Sample to Public-Security Action

The first layer is collection. Equipment obtains an image, audio recording, or video and determines whether the sample is usable. The second is template generation, which converts the sample into a feature representation that can be compared. A template is not a person's legal identity. It is not the original photograph or recording, and it is not simply a duplicate of either one.

The third layer is enrollment into a database. The sample must be linked to a person field, a vehicle field, or case information. A voiceprint-terminal procurement in Mawei requires connection to a personnel basic-information collection system and organization of personnel fields and sample fields according to national criminal-investigation voiceprint database specifications. The public document therefore shows a standardized database interface. It does not by itself show how the entire database operates. [6]

The fourth layer is comparison. A one-to-one comparison asks whether a sample matches a specified record. A one-to-many search looks for nearby records in a database and produces a candidate list according to similarity scores and thresholds. The fifth layer is an accountability stage for public-security action, not a technical layer shown to exist in every identification deployment. Before a candidate result is used to contact, check, watchlist, or otherwise act against a person, human reviewers should examine the underlying image or recording, retrieve other records, and retain the option to take no action. NIST's face-algorithm testing distinguishes one-to-one and one-to-many tasks. It describes human adjudication in some investigative workflows while also discussing applications, such as automated access decisions, that do not depend on case-by-case human review. [9]

Key Facts: How Local Systems Connect

The “Qingcheng Smart Traffic” tender requires connection to social video resources. Page 37 requires delivery of face, human-body, and vehicle images and structured data to a third-party platform, and separately lists alarm-plan management. Page 38 lists vehicle-attribute recognition and vehicle-trajectory analysis. Page 39 lists gait analysis, search, and comparison. [5] Data parsed from front-end video can therefore move across modules and platforms. The tender does not establish that every capability passed acceptance testing, reveal real-world error rates, or show that any person was sanctioned because of a gait or face result.

The Mawei project shows a different interface. Its terminal must send personnel information and voice samples, in specified fields, into a basic-information system. [6] This shows voiceprints being designed as searchable criminal-investigation data. The document does not publish the number of people sampled, retention periods, database scale, or cross-region query records.

The Personal Information Protection Law classifies biometric identification information as sensitive personal information. It requires processing for a specific purpose, with sufficient necessity and strict protective measures. Government agencies must also process personal information within their statutory authority, procedures, and the scope necessary to perform their duties. [4] These principles apply to data processing generally. A single procurement document cannot determine whether a particular public-security use was lawful.

The 2025 Measures for the Security Management of Face Recognition Technology Applications further specify purpose limitation, data minimization, notice or separate consent, the shortest necessary retention period, and prior impact assessment. Where another method is available, face recognition may not be used as the sole means of verification. Storage of face information reaching 100,000 people also requires filing. [1] These requirements define governance boundaries. They do not prove that an existing public-security system has implemented every requirement in practice.

A 2021 judicial interpretation by the Supreme People's Court includes face information within biometric identification information and identifies situations such as alleged unlawful use in public places, unclear purposes, insufficient consent, and inadequate security measures as rights-infringing circumstances. It also preserves an exception for safeguarding public security as provided by law. [2] The interpretation primarily addresses civil liability. It is not a criminal accusation or conviction of a particular person, and it cannot replace review of a public-security agency's jurisdiction, procedure, and necessity.

The 2025 regulation on public-security video-image information systems covers system construction, collection, transmission, storage, use, and supervision. [3] Installing cameras, collecting images, operating recognition, and using a result are therefore different stages. Evidence of one stage cannot substitute for evidence of another.

Consequences: The Risks After the List

Recognition systems normally require thresholds. Changing a threshold changes the trade-off between missed matches and false alerts. One-to-many searches can also produce different results as the candidate database and task conditions change. NIST found differences in error rates among algorithms and demographic groups. [9] That test did not examine a specific Chinese local system, so it cannot be used to assign a direct accuracy label to the Hohhot project. It does show why a tender's stated capabilities cannot replace local testing in real operating conditions.

The institutional risk appears when a candidate list is handed to the next stage. If staff see only rankings and similarity scores, without checking the original image, recording quality, and independent evidence, an algorithmic error can become a search or continuing-surveillance decision. Conversely, documented human review, reasons for rejecting a candidate, and channels for correcting records can stop an error from spreading. The public procurement materials do not provide these operating records. They establish an interface, but not whether review was sufficient. [9][5]

Evidence Boundaries: What Investigation and Sanctions Prove

Human Rights Watch's 2017 report brought together police reports, procurement documents, and public technical materials. It said that police in some regions collected voiceprints alongside other biometric information and investigated real-time voiceprint-recognition pilots. [7] This indicates that voiceprint collection and automated-recognition pilots appeared in more than one local context. It does not justify saying that every region had one unified, real-time national system.

The U.S. Treasury Department's 2021 sanctions decision identified several Chinese technology companies as involved in biometric surveillance directed at Uyghurs and other predominantly Muslim ethnic minorities. [8] This is an administrative sanctions determination, not a court judgment. It does not independently prove that every product or every local deployment by each company produced the same outcome. Procurement, investigation, and sanctions separately establish demand, investigative findings, and an administrative determination. They cannot be combined into a case-specific conclusion without supporting records.

Accountability Requires Opening the Interface After the List

Procurement documents usually do not reveal five pieces of information that the public needs: the actual size of the template database; how long original samples and templates are stored separately; which units may query across databases; the real one-to-many false-positive rate; and how a person wrongly placed on a candidate list learns of the error and corrects the record. The face-recognition measures require the shortest retention period, impact assessment, and filing at a specified scale. The Personal Information Protection Law requires government processing to remain within authority and necessity. [1][4] But the existence of a rule does not mean a system's execution records have been disclosed.

The relevant questions are who reviewed what, on what basis, whether candidate lists were retained, how errors were traced, and whether an action can be separated from the algorithmic output. The public-security video regulation's separation of construction, collection, transmission, storage, use, and supervision indicates that responsibility belongs at each stage. [3]

Until those interfaces are public, the strongest defensible conclusion remains limited: public materials can confirm that some capabilities were procured and that some rules were enacted. They cannot establish the real-world accuracy of each capability, nor automatically attribute any specific action to a recognition algorithm.

Sources

  • Measures for the Security Management of Face Recognition Technology Applications [1]
  • Supreme People's Court judicial interpretation on face recognition [2]
  • Regulation on Public-Security Video-Image Information System Management [3]
  • Personal Information Protection Law of the People's Republic of China [4]
  • “Qingcheng Smart Traffic” tender [5]
  • Mawei police voiceprint-collection equipment procurement document [6]
  • Human Rights Watch investigation of voice biometrics in China [7]
  • U.S. Treasury Department biometric-surveillance sanctions decision [8]
  • NIST demographic-effects testing of face-recognition algorithms [9]

Key evidence

What the available sources establish

Sources

  1. Measures for the Security Management of Facial Recognition Technology Applicationsprimary-recordUnchecked
  2. SPC Provisions on Civil Cases Involving Facial Recognition and Personal Informationjudicial-recordUnchecked
  3. Regulation on Public Security Video Image Information Systemsprimary-recordLive
  4. Personal Information Protection Law of the PRCprimary-recordUnchecked
  5. Qingcheng Smart Traffic Management Public Tenderprimary-recordUnchecked
  6. Mawei Police Voiceprint Collection Equipment Procurement Noticeprimary-recordUnchecked
  7. China: Voice Biometric Collection Threatens Privacyhuman-rights-reportUnchecked
  8. Treasury Sanctions on Biometric Surveillance Technologyofficial-findingLive
  9. Face Recognition Vendor Test Part 3: Demographic Effectstechnical-researchUnchecked

Related Reading