视点|个人生物识别信息权利风险及保护路径探析


Published:

2024-12-23

On April 9, 2021, the first case involving facial recognition technology concluded with a victory for the plaintiff. However, discussions regarding the protection of personal rights brought about by the application of facial recognition technology have never ceased. Despite the security of this technology not being fully verified, it has gradually permeated various application scenarios such as public security, finance, transportation, and real estate. Individuals are caught in an endless holographic link of biometric data, akin to a runaway horse, challenging the existing personal rights protection system. This article adheres to the concept of promoting technology for good through legal means, delving into the concerns that the current use of facial recognition technology poses for personal rights protection. Drawing on relevant regulations and judicial practices from Western legal countries, it proposes the establishment of a "three rights" system centered on the rights to be informed, self-determination, and remedy regarding personal biometric information. This aims to more comprehensively constrain the collection and processing of personal biometric information and explore a Chinese paradigm for the protection of rights related to personal biometric information.

Content Summary:On April 9, 2021, the first case of facial recognition ended with the plaintiff's victory, but the discussion on the personal rights protection issues brought about by the application of facial recognition technology has never ceased. In the absence of sufficient evidence for the safety of facial recognition technology, it has gradually penetrated various application scenarios such as public security, finance, transportation, and real estate, pulling individuals into an infinite holographic link of biometric feature data, like a runaway wild horse, impacting the existing personal rights protection system. This article adheres to the concept of promoting technology for good through legal means, deeply explores the hidden concerns brought by the current application of facial recognition technology to personal rights protection, and proposes the construction of a "three rights" system centered on the right to know, the right to self-determination, and the right to remedy regarding personal biometric information, attempting to more comprehensively constrain the collection and processing of personal biometric information, and exploring a Chinese paradigm for the protection of personal biometric information rights.

 

Keywords:Personal biometric information; facial recognition; three rights

 

Introduction

 

Since the promotion and application of facial recognition technology, the controversies arising from it have never ceased. Typical cases include the opposition of homeowners to the mandatory implementation of facial recognition in community access control, the illegal use of vulnerabilities in facial recognition systems of payment software, and the illegal acquisition of customer information by sales offices through facial recognition technology, among others. Such news is frequently reported. The reckless promotion of facial recognition technology seems to have opened Pandora's box, tearing and impacting existing social relationships at different levels and in different fields, exacerbating the opposition between specific groups. Indeed, the application of this technology has, to some extent, improved the level and efficiency of social management and facilitated people's work and life. However, the double-edged sword of technology is also vividly displayed in facial recognition technology; while it benefits people, it also infringes on personal rights to a certain extent. In the face of the hunting of personal rights by facial recognition, rights protection should no longer fall into the trap of "pollution first, governance later". Instead, it should take advantage of the momentum created by the Personal Rights section of the Civil Code, and seize the opportunity of the formal implementation of the Personal Information Protection Law to intervene early, layout in advance, and clarify from the level of legal norms, thereby limiting the legitimacy boundaries of facial recognition.

 

I. Rights Concerns Under the Camera

 

Facial feature information is highly personal and difficult to truly achieve de-identification. Due to its inherent fragility, facial recognition technology poses more hidden and intrusive damage to personal rights compared to other technologies. This is specifically reflected in the following aspects:

 

(1) Threat to Personal Information Security

The data economy spawned by the information age presents the value of data in a quantifiable and visual manner. Personal information is extracted, integrated, and analyzed in the data flood, forming a complete data package (chain) that enters the market in a commodified form. For example, in the real estate sales field, once potential homebuyers enter the sales office, their facial information will be captured by cameras distributed everywhere. Using facial recognition and big data technology, their information traces left intentionally or unintentionally in different scenarios, such as phone numbers, ID card numbers, personal resumes, etc., are integrated to form a complete personal information chain, causing potential homebuyers to present themselves in a full and naked image to the sales side, thus providing a reference and basis for the sales side to adopt targeted sales strategies. At the same time, this data can also be sold to peers or other related industries for a fee, leading to the uncontrolled and infinite spread of personal information, which has resulted in phenomena such as being bombarded by different merchants' calls and messages in real life due to interest in a certain consumption point, posing a significant threat to personal information security.
 

 

Furthermore, when facial recognition technology is combined with augmented reality (AR) technology, its destructive impact on personal rights is further amplified, achieving predictions about personal information. American scholars Alessa and Acquisti, Ralph Gross, and Fred Stutzman conducted three famous experiments in 2010 to identify strangers, combining facial recognition with data mining, integrating online and offline data to infer personal sensitive information. The experimental results showed that through personal facial feature information and using AR technology, it is possible to identify and predict other sensitive information about individuals in real time. Over a decade has passed, and the current technological development has far surpassed the past. The seamless connection of online and offline data has further enhanced the accuracy and comprehensiveness of personal information predictions, continuously escalating the potential threats and actual infringements on personal information.

 

(2) Undermining the Foundation of Social Trust

Trust is the cornerstone and foundation of social interaction. With the progress and development of social civilization, trust has transcended the scope of personal relationships, evolving into a social relationship rooted in all aspects of social life. Luhmann (1979) defined trust from a new functionalist theoretical perspective, stating that trust is a mechanism used to reduce the complexity of social interactions. Its social function lies in its ability to summarize expectations of certain behaviors beyond existing information, thus providing a sense of security to compensate for the information needed. From Luhmann's definition of trust, it can be inferred that trust is established based on information equality, which brings a sense of security to both parties. However, with the support of facial recognition technology, one party in the interaction may have cracked the digital identity of the other party, creating an information advantage over the other. In this case, the general and approximate attitudes and predictable behavior patterns become blurred, breaking the foundation of trust between both parties. In specific application scenarios, such as facial recognition payments, facial recognition access, and facial recognition authentication, the risk of trust imbalance is further amplified, and the continuous emergence of illegal criminal behaviors undermines the trust foundation of the entire society.
 

 

(3) Restricting Personal Negative Freedom

American legal scholar Friedman vividly depicted the sense of strangeness: "When we walk down the street, strangers protect us, like the police; or threaten us, like criminals. Strangers extinguish our fires, educate our children, build our houses, and invest our money. Strangers tell us the news of the world on the radio, television, or newspapers. When we travel by bus, train, or plane, our lives are in the hands of strangers. If we fall ill and go to the hospital, strangers cut open our bodies, clean us, care for us, kill us, or heal us. If we die, strangers will bury us." Indeed, in a society of strangers, we have almost given everything to others. Compared to traditional society, modern society offers humanity an important gift—the sense of strangeness, which carries the negative freedom of individuals not being interfered with. Even if we unintentionally hide our whereabouts, appearance, and other personal information, we still have a reasonable expectation that others will be oblivious to us. It is this reasonable expectation that allows individuality to flourish, making society more inclusive and diverse, and avoiding discrimination against individuals due to differences in behavior, appearance, ethnicity, gender, etc. Moreover, this reasonable expectation has gradually evolved into a basic social paradigm of "polite non-attention" between people in public areas.
 

 

The promotion and application of facial recognition technology undoubtedly destroys this sense of unfamiliarity. The disappearance of this unfamiliarity has not brought about the sense of security described by Mr. Fei Xiaotong in a society of acquaintances; instead, it has caused social unrest and anxiety. This is like a community without police, which may indeed be dangerous, but a community where police are everywhere may be even more dangerous. Facial recognition technology breaks through the limitations of memory in a strange society, where personal facial information is digitized and retained. The longer it is retained, the greater the risk of misuse, and this risk will continue to exist, thus forming an invisible constraint on negative freedom.

 

II. Regulating the Extraterritorial Reflection of Facial Recognition Technology

 

"The stone from another mountain can be used to polish jade." Facial recognition technology originated abroad and matured domestically. Western countries generally hold a cautious attitude towards the application of this technology. For example, in December 2019, the European Union's "White Paper on Artificial Intelligence (Draft)" explicitly stated that the use of facial recognition technology in public places would be prohibited for 3 to 5 years. Although the European Commission ultimately removed this ban, it imposed strict restrictions on the use of facial monitoring and other remote biometric systems. In the United States, in May 2019, San Francisco became the first city to prohibit police and other government agencies from using facial monitoring, followed by Somerville in Massachusetts, Oakland, and San Diego in California actively following suit. In June 2020, in the context of nationwide protests triggered by the Minneapolis police killing of George Floyd, IBM, Amazon, and Microsoft successively announced a suspension of facial recognition technology used for monitoring. Amazon's suspension period is one year, while Microsoft stated that its suspension period is indefinite until legal regulations are enacted. To address the impact of facial recognition technology on personal rights, Western countries have not only imposed technical restrictions but have also sought to regulate it from a legal perspective, with the United States and the European Union being typical examples.

 

(1) Illinois Biometric Information Privacy Act

At the legislative level, the United States relies on the national legal norm established by the "Privacy Act" of 1974 for the legislative regulation of facial recognition technology, incorporating it into the category of biometric information protection. Although there is no specific federal legislation regulating this, various states have conducted a series of legislative activities regarding the protection of biometric information, such as the "Biometric Information Law" in Washington D.C., the "Biometric Information Privacy Act" in Illinois, and the "Biometric Information Acquisition and Use Act" in Texas, among which the Illinois "Biometric Information Privacy Act" (hereinafter referred to as "BIPA") is the most typical. BIPA comprehensively regulates the rights and obligations of parties involved in the collection of biometric information, restrictive provisions on information collection and processing, exemption clauses, and rights remedies. It follows the principle of "self-determination of rights" for the rights and obligations of relevant parties, granting biometric information subjects the rights to be informed, consent, and self-determination. It also imposes corresponding obligations, such as the obligation to inform about information collection and the obligation to ensure information security, on the information collection parties. In the restrictive provisions on information collection and processing, three prohibitive behaviors are set: the prohibition of trading personal biometric information, the prohibition of profit-making by private parties, and the prohibition of information processing without consent. To balance private interests and public interests, BIPA sets three exemption clauses: with the consent of the personal information identification subject, according to legal norms, and court judicial requirements. In terms of rights remedies, BIPA clarifies two paths for relief: damage compensation and injunctions, where damage compensation does not require the premise of substantial damage caused by the rights subject. As long as the personal biometric information collection and processing subject violates the above procedures or prohibitions, it can be deemed a "breach of contract" and bear compensation liability.
 

 

In judicial practice, in the case of Rosenbach V. Six Flags Entertainment Corporation that occurred in Illinois, the defendant Six Flags was sued in court for violating BIPA procedural regulations by obtaining the personal biometric information of the plaintiff's 14-year-old son. The Illinois Supreme Court held that although Six Flags' actions did not cause substantial damage to the plaintiff's son, based on the irreversibility of personal information infringement in the internet age, its violation of BIPA essentially constituted a threat or deprivation of the legal rights of the personal biometric information subject. Therefore, the court ruled that the defendant should bear compensation liability. In this case, the Illinois court further clarified that no matter how much cost a business incurs to comply with BIPA requirements, these costs are insignificant compared to the substantial and irreparable damage suffered by individuals due to insufficient protection of biometric information. This case is a manifestation of the legislative spirit of BIPA and a declaration that personal rights protection takes precedence over commercial behavior.

 

(2) EU General Data Protection Regulation

The EU has always been at the forefront of technology and legislation, hoping that facial recognition technology can benefit society while also seeking a balance with personal rights protection. Currently, the EU does not have specific legislation to regulate the use of facial recognition technology but relies on the "General Data Protection Regulation" (hereinafter referred to as "GDPR"), which constructs a comprehensive legislative model that spans different legal departments such as civil law, criminal law, and administrative law. The specific content covers the concept, attributes, protection principles, supervision, and relief channels of personal biometric information. Compared to BIPA, there are certain commonalities between the two, such as the statutory principles, voluntary principles, and prohibition of processing principles established by GDPR, which are also reflected in BIPA. Both seek a balance between personal rights protection and public interest maintenance, and both grant personal biometric information subjects the right to claim damages in terms of rights remedies, with the exercise of rights not requiring the premise of causing substantial damage.
 

 

Of course, GDPR has its own characteristics. First, based on the theoretical foundation and legislative practice of personal information protection, the EU classifies personal information into general information and sensitive information according to the degree of sensitivity, adopting different levels of legislative protection measures for different levels of sensitivity. For example, religious beliefs, racial information, and political tendencies are prohibited from being identified and processed as highly sensitive information. Personal biometric information is included in the category of special sensitive personal information, receiving high-level protection, which also responds to the social discrimination caused by facial recognition technology that constrains personal negative freedom mentioned above. Secondly, in terms of rights remedies, GDPR is more comprehensive and complete, not only providing judicial relief channels for personal biometric information subjects but also clarifying administrative complaint channels. It grants personal biometric information subjects the right to relief and also gives personal biometric information users the right to defense. Without relief, there are no rights. A relatively complete rights relief system better protects the personal rights of personal biometric information subjects.

 

In judicial practice, the GDPR has also been strictly implemented, particularly in the case of the facial recognition attendance experiment at Anderstorps High School in Sweden. In this case, Anderstorps High School implemented facial recognition technology for attendance after obtaining consent from students and their parents, which resulted in a fine of 20,000 euros imposed by the Swedish Data Inspection Authority. The Swedish Data Inspection Authority mainly based its decision on GDPR Art. 5 (1) c), GDPR Art. 9, GDPR Art. 35, and GDPR Art. 36, which include the principle of minimization, regulations on the processing of special categories of data, data impact assessments, and prior consultations. The authority found that Anderstorps High School violated the principle of minimization by collecting and using special data in prohibited areas without prior communication with the inspection authority and without conducting a data impact assessment. Although consent was obtained from students and their parents, the unequal relationship between the two parties did not meet the GDPR requirement that "consent must be freely given," thus rendering the consent flawed and lacking a legal basis. This case elevates the protection of rights under facial recognition technology to a new level, imposing strict protection responsibilities on the rights holders.

 

3. Exploration of Legal Regulation of Facial Recognition Technology

 

Facial recognition technology primarily involves the abuse of personal biometric information, and the rights of the owners of personal biometric information pertain to the right to personal biometric information. To provide comprehensive protection for the right to personal biometric information, it is essential to clarify its legal nature. Currently, there is no consensus in the academic community regarding the legal nature of personal biometric information. Article 111 of the Civil Code proclaims the protection of personal information rights, while Article 1034 includes biometric information within the scope of personal information protection. However, the debate over whether personal biometric information constitutes civil rights or civil interests continues. Even among those who advocate for civil rights, there are disputes regarding property rights, personal rights, privacy rights, and personal information rights. Due to space limitations, this article will not delve into its legal nature. Based on the theoretical support from Professor Chen Xu, Professor Yang Lixin, and others regarding personal information rights, as well as the practical opportunity presented by the implementation of the Personal Information Protection Law of the People's Republic of China on November 1, 2021, this article adopts the view that biometric information is a type of personal information right.

 

The legal regulation of facial recognition technology should follow a Chinese paradigm, drawing on legislative practices and experiences from abroad, especially the relevant content of the GDPR and BIPA. This article attempts to outline a "three rights" framework based on the right to know, centered on the right to self-determination, and underpinned by the right to remedy, thereby forming a closed loop for the operation of rights and providing relatively comprehensive protection for rights holders.

 

(1) Right to Know

The right to know, as the primary right in the personal biometric information rights protection system, establishes the foundation for the protection of personal biometric information rights. The realization of other rights is based on the right to know, which gives rise to more detailed and comprehensive protective rights. The right to know starts from the logical point of personal dignity, respecting individual existence and value, and fully reflects the people-centered legal concept. The right to know regarding personal biometric information refers to the right to be informed through written, verbal, or other means about the collection, use, and processing of personal biometric information. In the process of realizing this right, the rights holder is often in a relatively passive state, mainly relying on the obligor to ensure protection through actions or inactions.
 

 

The protection of the right to know can be divided into two levels: first, explicit protection of the right to know, where rights holders can directly and clearly learn about the objective facts of the collection, use, or processing of personal biometric information through various means. For example, a bank may explicitly inform customers in the lobby that indoor cameras are collecting customer information and state the purpose of use; second, implicit protection of the right to know, where rights holders cannot directly and clearly learn about the objective facts of the collection, use, or processing of personal biometric information but are presumed to have been informed based on their actions, such as information hidden in customer agreements or other documents that are not easily discovered by rights holders, and are passively informed through consent rules. For the former, legislation should clarify the obligation of information collection entities to inform, solidifying the responsibility of those collecting, using, or processing information to maintain the rights holders' right to know, and should specify the time, place, manner, and scope of notification to ensure that rights holders can conveniently and clearly learn about the objective facts of information collection. For the latter, protection mainly relies on existing consent rules, with implicit protection of the right to know serving as a bridge through consent rules, allowing rights holders to learn about the collection, use, or processing of personal biometric information. China's consent rules derive from normative documents such as the Cybersecurity Law, the Consumer Rights Protection Law, and the Information Security Technology Personal Information Security Specification. However, in practice, there are instances of passive consent and forced consent. To avoid repeating the mistakes regarding the right to know of personal biometric information rights holders, it is necessary to establish a "separate and fully explicit" notification procedure and eliminate situations of "presumed consent" and "implied consent" that effectively deprive information rights holders of their right to know.

 

(2) Right to Self-Determination

The right to self-determination is the core right within the personal biometric information protection system. Broadly, the right to self-determination includes the consent to allow others to obtain, use, or process personal biometric information mentioned in the right to know. Here, the analysis focuses solely on the narrow definition of the right to self-determination, excluding the consent rules. Accordingly, the right to self-determination regarding personal biometric information refers to the rights of the rights holder to decide the nodes, methods, and timing of personal information uploads or acquisitions, as well as the rights to selectively modify, delete, and transfer already uploaded information. As an extension of the right to know regarding personal biometric information, the connotation and extension of the right to self-determination are richer and broader compared to the right to know, and the subjects involved are more diverse.
 

 

The protection of citizens' right to self-determination regarding personal biometric information requires protection from both positive and negative aspects. Firstly, regarding the positive empowerment of rights holders, legal norms should grant rights holders the authority to intervene in and make decisions at all stages of the collection, storage, use, processing, and dissemination of personal biometric information, and impose certain constraints on the rights counterparties regarding these interventions and decisions, especially concerning constraints on automated decision-making. With the continuous application of artificial intelligence, the capacity for automated processing of information is constantly increasing, and the probability of automated decision-making in the collection, use, and processing of personal biometric information is rising. The automated decision-making stage is a critical area for the leakage, alteration, and diffusion of personal biometric information. Therefore, sufficient self-determination rights should be granted to information rights holders regarding automated decision-making, which can be realized through rights such as refusal and revocation.

 

Secondly, regarding the reverse responsibility of rights counterparties, the protection of citizens' right to self-determination regarding personal biometric information requires not only positive legal empowerment for rights holders but also reverse responsibility for rights counterparties. The reverse responsibility of rights counterparties can be approached from two aspects:

 

First, at the technical level. The essence behind personal biometric information collection technologies such as facial recognition relies on algorithms. Controlling the algorithms from the source essentially completes the main task of legal rules. Collectors and processors of personal biometric information should submit algorithm guarantees when collecting or processing information, isolating or encrypting different categories of personal information in storage or classification algorithms. It is prohibited for enterprises and institutions to cross-match the collected biometric feature information with other information through databases, turning citizens into "transparent people" or "calculating people," which could lead to ethical and legal crises in facial recognition. At the same time, regarding the social discrimination issues arising from the collection and application of personal biometric information, a legal regulation path that enhances algorithm transparency can be adopted. Algorithm transparency can quickly identify the root causes of algorithmic discrimination, allowing for scientific assessment and analysis of the affected groups, so that relevant parties can timely update and improve algorithm models.

 

Second, at the purpose level. Personal biometric information has been given a new mission in the commercial wave and exhibits different commercial values in different business fields. In some commercial areas, personal biometric information has become a major factor in achieving commercial purposes, while in others, it is not. For the former, software like Meitu and Douyin relies on the collection of rights holders' personal biometric information as the main means to achieve their commercial objectives. For the protection of rights under such business models, a certain period of responsibility freeze should be set after personal information is collected. Once the period expires, the responsibility should be unfrozen, and the rights holder should immediately take on the responsibility of deleting the relevant personal biometric information to ensure that the rights holder's personal information is not misused. The reason for imposing the responsibility of periodically deleting personal biometric information on the rights holder (mostly institutions) is mainly based on human inertia considerations. In daily life, most people lack sufficient attention and concern for personal information, especially in the context of rampant facial recognition technology, where few can remain unaffected, and even fewer treat personal biometric information with caution. Therefore, imposing the responsibility of periodically deleting personal biometric information on the rights holder reflects the humanization of legislation.

 

Of course, the right to self-determination is not an absolute right. Excessive indulgence of self-determination rights will inevitably lead to conflicts or confrontations between private demands and the freedoms or public interests of others. It is necessary to reasonably allocate rights and obligations among individuals, others, and the state, and to leave sufficient legal space for later corrections and adjustments, enhancing the flexible factors of rights.

 

(3) Right to Remedy

Without remedy, there are no rights. The right to remedy is a fundamental right in the personal biometric information rights system, derived from the aforementioned right to know and right to self-determination, aimed at remedying the damaged original rights. The protection of personal biometric information rights can be achieved from two levels.
 

 

First, administrative remedy. Administrative remedy well meets the urgent requirements for the protection of personal biometric information rights. Smooth administrative remedy channels for rights holders are a prerequisite for the realization of the right to remedy. Drawing on the practices of BIPA, China can designate the National Internet Information Office (hereinafter referred to as "Cyberspace Administration") as the complaint authority for the protection of personal biometric information rights, with an internal "Biometric Information Supervision Department" specifically responsible for complaints regarding the protection of personal biometric information rights. Using the relevant provisions of the Civil Code as legislative basis, the Cyberspace Administration can formulate and issue the "Interim Measures for the Protection of Personal Biometric Information Rights," clarifying the subject qualifications, complaint procedures, and punitive measures for administrative remedies, while also specifying that the Cyberspace Administration has administrative powers such as investigation, licensing, seizure, and punishment, providing power support for better remedying personal biometric information rights.

 

Second, judicial remedy. Judicial remedy is the most powerful and final channel for the protection of personal biometric information rights. Given the particularity of personal biometric information rights protection, the existing judicial system cannot be fully applied to the remedy of this right and needs to be moderately reformed to increase the compatibility between the two.

 

Regarding the qualification of litigation subjects, personal biometric information rights holders are naturally the subjects of personal litigation, and they have the right to sue for actions that harm their personal rights. However, in reality, the victims of illegal collection, leakage, or other harmful actions of personal biometric information are often unspecified subjects. Collective lawsuits arising from this not only occupy judicial resources but also reduce litigation efficiency. Therefore, referring to the provisions of BIPA and combining with judicial practices in areas such as environmental pollution and food and drug safety in China, the collective protection of personal biometric information rights can be included in the scope of public interest litigation, granting the procuratorial organs the qualification to be litigation subjects to sue for public interest.

 

In terms of identifying damage facts, once the rights holder's information is collected and enters cyberspace, it loses control. During the process of information dissemination, who caused what kind of damage at what time and in what manner remains unknown. Moreover, the speed of information dissemination in cyberspace is extremely fast, and due to the uniqueness of personal biometric information, once infringement occurs, it can lead to irreversible serious consequences. If the occurrence of damage results is used as the node for the rights holder to safeguard their rights, it will be too late. The value and significance of judicial remedy will no longer exist. Therefore, drawing on the practices of GDPR and BIPA, it is proposed not to require the occurrence of substantial damage as a constitutive element for the rights holder to claim tort liability, nor does the rights holder need to prove the facts of damage.

 

In terms of subjective fault determination, since personal biometric information carries important values such as human dignity and privacy, it has a high degree of specificity and confidentiality, directly related to the individual's most secret physiological characteristics, and has the quality of representing and highlighting personal identity. Therefore, the information collection subject should adhere to the principle of prudence and properly preserve and use the relevant information from the very beginning of personal biometric information collection, imposing strict liability on the information collector from the source of information. If the information is misused, the subjective fault of the information collector should be presumed according to the principle of fault presumption.

 

Conclusion

 

Truck drivers kidnapped by the Beidou system, passengers forced off the bus by health codes, and everyone monitored by cameras may become victims of the game between technological advancement and rights protection. Technology is cold; being human requires a touch of warmth. Legal professionals should bear the pressure and uphold a people-centered philosophy, properly addressing personal rights protection issues under facial recognition technology. This not only concerns the "face" of countless people but also involves the "face" of every legal professional. This article attempts to construct a "three rights" system based on the right to know, the right to self-determination, and the right to remedy, aiming to make personal biometric information rights more three-dimensional and rich, with a wider range of applicable scenarios. It also seeks to provide a more rational and composed approach for the state and society in handling the relationship between technology and law, enhancing the modernization of the national and social governance system and governance capabilities in a multi-level and multi-faceted manner.

Key words:


Related News


Address: Floor 55-57, Jinan China Resources Center, 11111 Jingshi Road, Lixia District, Jinan City, Shandong Province

Baidu
map