DCC summary, not a translation. GB/T 41807-2022 is a copyrighted national standard. The structured summary below is DCC’s own paraphrase. Editor’s note: the PDF in DCC’s reference library uses a private-use font encoding that defeats text extraction, so the clause-level content below is reconstructed from the standard’s published table of contents, its scope statement and the drafting pattern of the TC260 biometric series rather than verified against the text. Verify specific clauses against the published standard before relying on them.
Published by: State Administration for Market Regulation and Standardization Administration of China; drafted under the National Information Security Standardization Technical Committee (TC260).
Published October 12, 2022. Implemented May 1, 2023. Recommended national standard.
Scope
GB/T 41807-2022 specifies the security requirements for voiceprint recognition data (声纹识别数据) throughout its lifecycle — collection, storage, use, transmission and provision, and deletion — together with the management requirements that support them. “Voiceprint recognition data” covers the original voice recordings collected for recognition, the voiceprint features and templates extracted from them, and the results of comparison, insofar as they are used to identify or verify a natural person. The standard applies to organizations that build or operate voiceprint recognition systems and to processors of voiceprint data, and is intended to guide the design, development and operation of such systems and the assessment of their security. It is one of a series of TC260 biometric-data standards alongside those for facial recognition data (GB/T 41819-2022), gait recognition data (GB/T 41773-2022) and genetic recognition data (GB/T 41806-2022), all published together in 2022.
Key contents
Reading the table of contents against the series pattern, the standard is organized as follows.
General requirements. Voiceprint data is biometric information and therefore sensitive personal information under PIPL Article 28; processing requires a specific purpose and sufficient necessity, strict protective measures, and the individual’s separate consent. The standard expresses the series’ standing preferences: use voiceprint recognition only where other, less intrusive means cannot achieve the purpose; prefer verification (1:1) over identification (1:N); and do not make voiceprint recognition the sole means of authentication where an alternative can reasonably be offered.
Collection. Collect only for the identified purpose and only the voice data necessary; inform the individual clearly and obtain separate consent before capture; do not collect voice covertly or from persons who have not enrolled; where feasible, extract features on the device and discard the raw recording; handle minors’ data only with guardian consent.
Storage. Store voiceprint features and templates encrypted; store them separately from the individual’s identity information and from other personal information, linked only by identifiers; apply template-protection techniques so that a leaked template cannot be replayed or reversed to a voice; do not retain raw voice recordings beyond what the enrolment or purpose requires; prefer local storage on the user’s device, and where central storage is necessary apply strict access control and logging.
Use. Use voiceprint data only for the declared recognition purpose; do not use it to infer health, emotional state, ethnicity or other attributes unrelated to identity; set and document matching thresholds and false-accept and false-reject rates; deploy liveness detection and anti-spoofing against replay, synthesis and voice conversion attacks; and record recognition operations.
Transmission and provision. Transmit voiceprint data only over encrypted channels; do not provide voiceprint features or templates to third parties without the individual’s separate consent and a necessity justification; where provision is unavoidable, prefer providing results rather than templates; and treat cross-border transfer as subject to the PIPL Chapter III regime.
Deletion. Delete voiceprint data when the purpose is achieved, when the retention period expires, when the individual withdraws consent or closes the account, or on the individual’s request, and ensure deletion extends to backups and derived templates.
Management. Designate responsibility for voiceprint data security; conduct a personal information protection impact assessment before deployment and periodically thereafter; train and restrict personnel; log and audit access; prepare incident-response plans; and assess third-party recognition-service providers. Informative annexes describe typical application scenarios — payment and financial verification, account login, customer-service identity checks, smart speakers and vehicles, attendance and access control — and a security-analysis framework listing threats at each lifecycle stage.
How it fits the regime
The standard is the voice counterpart of the facial-recognition rules that the CAC and MPS later hardened into the Facial Recognition Technology Application Security Management Measures: it converts the PIPL’s sensitive-information duties — separate consent, necessity, impact assessment, enhanced security — into controls specific to voiceprints, and it anticipates the 2025 sensitive-information standard GB/T 45574, which now sets the general baseline that this standard particularizes. For overseas companies, its practical significance is in customer-service voice verification, banking and payment apps, voice assistants and in-vehicle systems that enrol Chinese users’ voiceprints: the standard’s expectations on on-device feature extraction, template protection, separation from identity data and non-repurposing are what regulators and certification bodies test against. Consent mechanics follow GB/T 42574, and identification of voiceprints as sensitive personal information follows the TC260 sensitive-information identification guide.