0% found this document useful (0 votes)
20 views3 pages

Data Protection Principles Overview

The document outlines the definition of personal data and establishes six Data Protection Principles (DPP) that govern the collection, accuracy, use, security, availability, and access to personal data. It emphasizes the need for lawful and fair collection, accuracy and timely retention, consent for new uses, security measures against unauthorized access, transparency in data practices, and the rights of data subjects to access and correct their data. Additionally, it includes guidelines for direct marketing practices and penalties for non-compliance.

Uploaded by

wongs8077
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
20 views3 pages

Data Protection Principles Overview

The document outlines the definition of personal data and establishes six Data Protection Principles (DPP) that govern the collection, accuracy, use, security, availability, and access to personal data. It emphasizes the need for lawful and fair collection, accuracy and timely retention, consent for new uses, security measures against unauthorized access, transparency in data practices, and the rights of data subjects to access and correct their data. Additionally, it includes guidelines for direct marketing practices and penalties for non-compliance.

Uploaded by

wongs8077
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Personal data means any data relating directly or indirectly to a living individual; from which it is practicable for the

identity of the individual to be directly or indirectly ascertained; and in a form in which access to or processing of the
data is practicable or which are likely to come into possession of the data controller.

6 Data Protection Principles (“DPP”)

Principle 1 – Purpose and manner of collection of personal data


DPP1(1) Personal data shall not be collected unless:
(a) the data are collected for a lawful purpose directly related to a function/activity of the data user
(b) the collection of the data is necessary for / directly related to that purpose
(c) the data are adequate and not excessive
DPP1(2) Personal data shall be collected by means which are lawful and fair
DPP1(3) All practicable steps shall be taken to ensure that:
(a) he is explicitly/implicitly informed, on or before collecting the data, of
(i) whether it’s obligatory/voluntary for him to supply the data;
(ii) where it’s obligatory for him to supply the data; the consequences if he fails to supply the data.
(b) he is explicitly informed:
(i) the purpose for which the data is to be used; and the classes of persons to whom the data may be
transferred;
(ii) on or before first use of the data, his rights to request access to and correction of the data.

Principle 2 – Accuracy and duration of retention of personal data


DPP2(1) All practicable steps shall be taken to ensure that
(a) personal data are accurate having regard to the purpose;
(b) if personal data are inaccurate, such data are not used or the data are erased;
(c) inform third party of any inaccuracy.
DPP2(2) Personal data shall not be kept longer than is necessary
DPP2(3) If a data user engages a data processor to process personal data on the data user’s behalf, the data user must
adopt contractual/other means to prevent any personal data transferred to the data processor from being
kept longer than is necessary.
DPP2(4) Data processors mean processes personal data on behalf of another person; and does not process the data for
any of the person’s own purposes.

Principle 3 – Use of personal data


DPP3(1) Personal data shall not, without the prescribed consent of the data subject, be used for a new purpose.
DPP3(2) A relevant person in relation to a data subject may, on his/her behalf, give the prescribed consent required
for using his/her personal data for a new purpose.
DPP3(3) A data user must not use the personal data of a data subject for a new purpose even if the prescribed consent
for so using that data has been given unless the data user has reasonable grounds for believing that the use
of that data for the new purpose is clearly in the interest of the data subject.

Principle 4 – Security of personal data


DPP4(1) All practicable steps shall be taken to ensure that the personal data are protected against
unauthorized/accidental access, processing, erasure or other use with regard to
(a) the kind of data and the harm that could result if any of those things should occur;
(b) the physical location where the data are stored;
(c) any security measures incorporated into any equipment in which data are stored;
(d) any measures taken for ensuring integrity, prudence and competence of persons having access to the
data;
(e) any measure to secure transmission of data.
DPP4(2) if a data users engages a data processor to process personal data on the data user’s behalf, the data user must
adopt contractual/other means to prevent unauthorized or accidental access, process, erasure, loss or use of
the data transferred to the data processor for processing.

Principle 5 – Information to be generally available


DPP5 All practicable steps shall be taken to ensure that a person can:
(a) ascertain a data user’s policies and practices in relation to personal data;
(b) be informed of the kind of personal data held by a data user;
(c) be informed of the main purposes for which data are held.
Eg. Privacy Policy Statement applies to the organization’s collection, holding & use of recorded info about
individuals;
Details of the policy can be provided via the Co’s profile or website

Principle 6 – Access to personal data


DPP6 A data subject shall be entitled to:
(a) ascertain whether a data user holds data;
(b) request access to data within a reasonable time, not excessive fee, in a reasonable manner;
(c) be given reason for refusal;
(d) object to a refusal;
(e) request the correction of data.

Best practice – Policy guideline


1. Data are obtained & processed fairly and lawfully, for specified purposes
2. Personal data shall be adequate, relevant & not excessive in relation to the purpose for which it’s processed
3. Ensure that they are accurate & up-to-date
4. Erase personal data which are no longer necessary
5. Kept no longer than necessary
6. Personal data shall be obtained only for 1 or more specified purpose
7. Process data in a secure environment
8. Take all reasonable steps to ensure that personal data are protected against unauthorized/accidental access
9. Ensure that a persona can be informed of the kind of personal data & the main purpose the Co are to be used
10. Allow data subject to access & correct personal data
11. In accordance with the individuals’ rights

Use of personal data for direct marketing


1. Consent = indication of No Objection
2. “Opt-in” approach – right to raise objection once personal data is collected
3. Written Notification & Written Consent
4. Easily understandable and readable wording
5. If oral consent, the data user should send a written confirmation to the individual within 14 days
6. Existing obligation to inform individual of opt-out right
7. Maximum penalty for breach – HK$500,000 and imprisonment for up to 3 years
Maximum penalty for provision of personal data to another for direct marketing:
Sale - HK$1,000,000 and imprisonment for up to 5 years;
Provision – HK$500,000 and imprisonment for up to 3 years.

Grandfather arrangement
In order to exempt from the requirement to provide written information and response facility for written consent for
direct marketing purpose before the commencement of new law, the data user has to satisfy the following conditions:
1. The data user had informed explicitly the data subject in an easily & understandable manner;
2. The data user had used the individual’s data for direct marketing;
3. The data subject had not required the data user to stop to use any of the data;
4. The data user had not contravened the PDPO in relation to the use of data.

Common questions

Powered by AI

Data processors handle personal data on behalf of data users without processing it for their own purposes. Data users who engage data processors must implement contractual or other measures to prevent unauthorized or accidental data access, retention, or use. This role delineation ensures accountability, as data users remain responsible for personal data's security and compliance with data protection principles, even when the data is processed externally. Ensuring these precautions mitigates risks associated with third-party data handling .

The 'opt-in' approach in direct marketing means that an individual's consent is proactively obtained by requiring them to express their agreement to receive marketing materials. This differs from 'opt-out' methods, where consent is presumed unless an individual actively declines. The significance of the 'opt-in' method lies in ensuring that consent is informed and deliberate, thereby respecting individual autonomy and reducing privacy infringements. It enhances transparency and control for the data subject over their personal data in direct marketing contexts .

Unauthorized data use for direct marketing can lead to severe legal consequences, including fines and imprisonment. The maximum penalty for unauthorized use or sale of personal data for direct marketing is up to HK$1,000,000 and five years' imprisonment for sale, and HK$500,000 and three years for provision. These stringent penalties are designed to deter misuse of personal data, ensuring that data users comply with legal standards for consent and transparency .

The required measures to ensure personal data's security include protecting against unauthorized or accidental access, processing, erasure, or other use. This involves safeguarding data based on the type of data and potential harm, securing the physical location and storage equipment, and ensuring the integrity of personnel with data access. Critical measures also include securing data transmission and using contractual means with data processors. These measures are crucial to prevent data breaches, maintain confidentiality, and uphold trust between data users and subjects .

The six Data Protection Principles (DPPs) provide a comprehensive framework for personal data protection. Principle 1 ensures personal data is collected for lawful and relevant purposes, reasonably obtained, and transparently communicated to the data subject. Principle 2 mandates accuracy and limits the retention duration of data. Principle 3 restricts the use of data for new purposes without the subject's consent. Principle 4 establishes security measures against unauthorized access or use of data. Principle 5 requires transparency regarding data policies and the types and purposes of data held. Principle 6 grants individuals rights to access and correct their data. Together, these principles ensure data is managed lawfully, securely, and transparently, respecting individuals' rights .

Personal data may be used for a new purpose without explicit consent if the data user has reasonable grounds to believe that using the data for the new purpose is clearly in the interest of the data subject. This provision ensures flexibility in specific contexts where the new use could benefit the data subject, thereby accommodating unforeseen situations while maintaining data protection standards .

A data user must consider the purpose for which personal data was collected, ensuring that the retention duration aligns with fulfilling that purpose. Factors include the type of data, legal obligations, data subjects' rights, potential harm of extended retention, ongoing relevance, and accuracy of the data. Retention should not extend longer than necessary, requiring regular review and erasure of data that is no longer needed, thereby balancing operational requirements with privacy standards .

The 'grandfather arrangement' exempts data users from newly instituted written consent requirements for direct marketing, provided certain conditions are met. These include having previously informed the data subject clearly and used their data for direct marketing, without request from the subject to cease usage, and without contravening the pre-existing laws. This arrangement was likely designed to create a transition for businesses who already had direct marketing agreements under earlier laws, balancing regulatory compliance with operational continuity .

Non-compliance with data retention and accuracy principles can lead to significant legal and financial ramifications, including penalties and potential data breaches. Inaccurate or unnecessarily retained data not only violates the data subject's rights but also increases the risk of misuse or unauthorized access. This can result in fines, reputational damage, and loss of customer trust. These principles are designed to ensure data minimization and precision, mitigating risks and protecting privacy .

Providing written notification and obtaining written consent in direct marketing is necessary to ensure transparency and accountability. It provides a clear record of consent given by the data subject, which can protect both the data user and the subject in legal and compliance contexts. Written documentation ensures clarity about the terms of consent, helps prevent misunderstandings, and upholds the individual's right to be informed and to control their data. This practice is part of a robust data protection framework that prioritizes informed consent and accountability .

You might also like