Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen...

13
Personal Data (Privacy) Personal Data (Privacy) Ordinance Ordinance Hong Kong Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong SAR The Tenth International World Wide Web Conference May 1 - 5, 2001, Hong Kong Hong Kong Convention & Exhibition Centre

Transcript of Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen...

Page 1: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Personal Data (Privacy) OrdinancePersonal Data (Privacy) OrdinanceHong KongHong Kong

byStephen Lau

Privacy Commissioner for Personal DataHong Kong SAR

The Tenth International World Wide Web ConferenceMay 1 - 5, 2001, Hong Kong

Hong Kong Convention & Exhibition Centre

Page 2: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

2000 Community Opinion Survey Importance of social policy issues in Hong Kong

8.75

7.587.407.37 7.25

7.957.64

6.44

8.427.63

7.46

6.80

8.30

6.66

8.21 8.10 7.63

7.26 6.79

0

1

2

3

4

5

6

7

8

9

10

air pollution unemployment privacy food hygiene health services care for theelderly

sexdiscrimination

Mea

n va

lue

of r

espo

nses

1997

1998

1999

2000

0 = not important at all10 = very important

2

Page 3: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Hong KongHong Kong

Objectives ofObjectives ofPersonal Data (Privacy) OrdinancePersonal Data (Privacy) Ordinance

• to protect the individual’s right to privacy with respect to personal data

• to safeguard the free flow of personal data to Hong Kong from restrictions by countries that already have data protection laws

3

Page 4: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

The Personal Data (Privacy) Ordinance

• Enacted 3 August 1995

• Commenced operation 20 December 1996

• Based on internationally accepted data protection principles

• Apply to personal data of individuals

• Govern private sector and public sector

• Established the Privacy Commissioner’s Office

4

Page 5: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Data Protection Principles

Principle 1 - Purpose and manner of collection -• this provides for the lawful and fair collection of personal

data and sets out the information a data user must give to a data subject when collecting personal data from the subject.

Principle 2 - Accuracy and duration of retention -• this provides that personal data should be accurate, up-to-

date and kept no longer than necessary.

5

Page 6: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Data Protection Principles

Principle 3 - Use of personal data -• this provides that unless the data subject gives consent

otherwise personal data should be used for the purposes for which they were collected or a directly related purpose.

Principle 4 - Security of personal data -• this requires appropriate security measures to be applied to

personal data (including data in a form in which access to or processing of the data is not practicable).

6

Page 7: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Data Protection Principles

Principle 5 - Information to be generally available -• this provides for openness by data users about the kinds of

personal data they hold and the main purposes for which personal data are used.

Principle 6 - Access to personal data - • this provides for data subjects to have rights of access to and

correction of their personal data.

7

Page 8: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

PrivateSectors70%

Personal10%

PublicSectors20%

Data Privacy Complaints in Hong KongData Privacy Complaints in Hong Kong

8

Page 9: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Code of PracticeCode of Practice

• Hong Kong Identity Card 1998

• Consumer Credit Data 1999

• Human Resource Management 2000

• Workplace Surveillance 2001

9

Page 10: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Internet-RelatedInternet-Related

• Privacy guidelines for users 1998

• Privacy guidelines for websites 1998

• Privacy policy and purposes statements 1999

• Spamming Code (HK ISP Association) 2000

• e-Privacy for e-commerce 2001

10

Page 11: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Improved customer relations

Improved employee relations

Better record management & information systems practices

More effective planning More effective operations

BENEFITS OF COMPLIANCEBENEFITS OF COMPLIANCE

11

Page 12: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

49.7

81.0

59.4

48.1

71.068.3

77.1

62.167.5

74.970.8

82.479.1

85.2

77.581.7

86.482.9 80.2

78.8

0

10

20

30

40

50

60

70

80

90

100

public image oforgainzation

personal datamanagement

customerrelationship

employeerelationship

accuracy of datarecords

Per

cent

age

of r

espo

nses

1997

1998

1999

2000

Hong Kong 2000 Community Opinion SurveyLong term benefits of the Ordinance: Strongly agree / agree

12

Page 13: Personal Data (Privacy) Ordinance Hong Kong Personal Data (Privacy) Ordinance Hong Kong by Stephen Lau Privacy Commissioner for Personal Data Hong Kong.

Privacy Commissioner for Personal DataPrivacy Commissioner for Personal DataHong Kong SARHong Kong SAR

Website: http://www.pco.org.hk

13