Six data protection principles - Family CLIC (2024)

Any person or organization collecting, holding, processing or using personal data must comply with the six data protection principles laid down insection 4andschedule 1of thePersonal Data (Privacy) Ordinance. (Note: The person from whom personal data are or will be collected is called the“data subject”, and the person or organization that is collecting the personal data is called the ”“data user”.)

The Privacy Commissioner’s Office (PCO)may issue an enforcement notice to the person or company who committed the breach, with intent to direct that wrongdoer to stop violating the data collection principles and take any necessary remedial action. Non-compliance with the PCO’s enforcement notice is an offence and is liable to a fine or imprisonment. The victim who suffers damage, including injury to feelings, as a result of such violation may also be entitled to compensation from the wrongdoer through civil proceedings.

Principle 1 – purpose and manner of collection of personal data

Personal data must be collected for a lawful purpose. The purpose of collection must be directly related to a function or activity of the data user. The data collected should be adequate but not excessive in relation to that purpose.

Personal data should also be collected by lawful and fair means. Unauthorized access to another person’s bank account records or credit card information is an example of unlawful means of collecting personal data. If a person/organization intentionally uses a misleading way to collect personal data, this amounts to an unfair means of data collection. A company collecting the personal data of job applicants by means of recruitment activities when in fact they are not really recruiting any one is an example of unfair means of collecting personal data.

When personal data are collected from an individual, that person (the data subject) must be provided with the following information, which includes:

  • the purpose for which the data are to be used;
  • the classes of persons to whom the data may be transferred;
  • whether it is obligatory or voluntary for the data subject to supply the data;
  • the consequences arising if the data subject fails to supply the data; and
  • the data subject has the right to request access to and correction of the data.

Principle 2 – accuracy and duration of retention of personal data

Data users must ensure that the data held are accurate and up-to-date. If there is doubt as to the accuracy of the data, data users should stop using the data immediately. They should not keep the data any longer than is necessary for the purpose for which the data were collected.

Principle 3 – use of personal data

Unless personal data are used with the prescribed consent of the data subject, the data must not be used for any purpose other than the one mentioned at the time the data were collected (or a directly related purpose). “Prescribed consent” means the express consent given voluntarily by the data subject.

Principle 4 – security of personal data

Data users must take appropriate security measures to protect personal data. They must ensure that personal data are adequately protected against unauthorized or accidental access, processing, erasure, or use by other people without authority.

Principle 5 – information to be generally available

Data users must publicly disclose the kind (not the content) of personal data held by them and their policies and practices on how they handle personal data.

The best practice is to formulate a “Privacy Policy Statement” that encompasses information such as the accuracy, retention period, security and use of the data as well as measures taken regarding data access and data correction requests.

Principle 6 – access to personal data

A data subject is entitled to ask a data user whether or not the data user holds any of his/her personal data, and to request a copy of such personal data held by that user. If it is found that the data contained therein is inaccurate, the data subject has the right to request the data user to correct the record.

The data user must accede to the access and correction requests within a statutory period of 40 days. If the data user could not process the request within the period specified, it must provide a reply and state its reasons within 40 days.

Individuals/data subjects who wish to make data access requests may download theData Access Request Form (OPS003)from the Privacy Commissioner’s Office and send the completed form to the company which holds the personal data. It should be noted that the Ordinance permits data users, in complying with the data access requests, to charge a reasonable fee. However, the data users concerned should not charge more than the direct cost of complying with the requests.

For more details of the six principles, please go to thePersonal Data Privacy Liberal Studiesprovided by The Office of the Privacy Commissioner of Personal Data (PCPD).

A. Exemptions

In some situations, data users may be exempt from the restrictions imposed by the Ordinance or thesix Data Protection Principles(DPP). The Personal Data (Privacy) (Amendment) Ordinance 2012 (the Ordinance) introduces further new exemptions. Some examples are summarised below:

Household affairs or recreational purposes

According tosection 52of the Ordinance, personal data for household affairs or recreational purposes is exempt from“DPP 4and5, and Ordinancesections 36and38(b). Keeping the phone numbers of your family members for daily communication or keeping the phone numbers of your friends to arrange leisure activities are examples in this category.

Employment-related purposes

Under certain circ*mstances, data users may be exempt from some (but not ALL) of the restrictions of thesix DPPs.Sections 53,54,55and56of the Ordinance state that personal data used for employment-related purposes is exempt from the provisions of data-access requests.DPP 6andsection 18(1)(b)of the Ordinance require data users to supply the personal data they hold to the data subject. Such data includes, for example:

  • personal data relating to staff planning proposals;
  • personal data which is the subject of certain evaluative processes prior to the decision being taken and where an appeal can be made against such a decision, including the processes of recruitment, promotion, awarding, removal or disciplinary action; or
  • a personal reference for an appointment up to the time when the position is filled.

Health grounds

Undersection 59of the Ordinance, personal data relating to the physical or mental health of a data subject is exempt from the provisions of data access requests (DPP 6andsection 18(1)(b)of the Ordinance) and restrictions on data use (DPP3) if the application of those provisions would be likely to cause serious harm to the physical or mental health of the data subject or any other individual.

In addition, according tosection 59(2), enacted in 2012, if the application of restrictions on data use would be likely to cause serious harm to the physical or mental health of a data subject or any other individual, personal data relating to the identity or location of the data subject would also be exempt fromDPP 3.

Care and guardianship

Personal data in relation to a minor which is transferred or disclosed to the minor’s parent or guardian by the Hong Kong Police Force or the Customs and Exercise Department is exempt from the restrictions on personal data use (DPP 3) if the transfer or disclosure is in the interest of the minor and would facilitate proper care and guardianship of the minor. (section 59A, enacted in 2012)

News activities

Undersection 61, if personal data is held for the purpose of news activities, such data may be exempt from the provision in respect of data-access requests (DPP 6;sections 18(1)(b),38(i),36and38(b)), unless and until the data is published or broadcast. If the data user is of the view that the disclosure of the personal data is in the public interest, then such disclosure may also be exempt from the restrictions on use (DPP 3).

In an appeal case reported by the Privacy Commissioner for Personal Data (PCPD) concerning the issue of public interest in news activities, the principal of an academic institute disclosed personal data of his staff to newspaper reporters in order to defend the reputation of the institute in response to accusations made by the complainant. It was held by the PCPD that such disclosure was in the public interest in facilitating fair and balanced reporting (please refer toComplaint Case Notesfor full details).

Human embryos

Undersection 63, personal data which consists of information showing that an identifiable individual was or may have been born in consequence of a reproductive technology procedure is exempt from the provisions ofDPP 6 andsection 18(1)(b), provided that its disclosure under those provisions is made in accordance withsection 33of theHuman Reproductive Technology Ordinance(Cap 561).

Emergency situations

Undersection 63C, enacted in 2012, personal data is exempt from the restrictions on the collection of data (DPP 1(3)) and on the use of data (DPP 3) if the application of those provisions would be likely to prejudice the identification of an individual involved in a life-threatening situation, informing the individual’s immediate family members of his situation, the carrying out of emergency rescue operations, or the provision of emergency relief services.

B. Outsourced processing of personal data

It is an increasingly common practice for data users to outsource and entrust personal data processing to third parties. There have also been an increasing number of personal data leakage incidents which have occurred during the outsourced processing of personal data, which may have caused substantial and irreparable damage to the affected data subjects.

All the data protection principles apply to the processing of personal data by a third party. Under the Ordinance, where personal data is entrusted to a data processor, a data user is liable as the principal for any act done by its authorised data processor.

The Amendment Ordinance 2012 provides enhanced protection by amendingDPP 2andDPP 4. With effect from 1 October 2012, additional obligations are imposed on a data user which engages a data processor, whether within or outside Hong Kong, to carry out data processing on that user’s behalf. The data user must adopt contractual or other means to prevent any personal data transferred to the data processor from being kept longer than necessary for processing the data (DPP2(3)) and to prevent unauthorised or accidental access, processing, erasure, loss or other inappropriate use of the data (DPP 4(2)).

Under the amended Ordinance, data processor means a person who:

  1. processes personal data on behalf of another person; and
  2. does not process the data for any of the person’s own purposes.

Please read the PCPD’sleafletfor more details on the new obligations.

With the rapid advancement in information and communication technologies (ICT) and the popularization of outsourcing the processing of personal data, the collection (other than from the data subject directly) and dissemination of personal data has become much easier. This also makes it easier for data subjects to suffer damage if a person, whether or not entrusted by the data user, intentionally discloses the personal data obtained from a data user. In view of the seriousness of any intrusions into personal data privacy and the gravity of the harm that may be caused to the data subjects, the Amendment Ordinance 2012 creates a new offence to combat the disclosure of personal data obtained without the consent of the data user under certain conditions.

Undersection 64, it is an offence for any person to disclose any personal data of a data subject obtained from a data user without the data user’s consent:

  1. with the intent to obtain gain in money or other property, whether for the benefit of the person or another person;
  2. with the intent to cause loss in money or other property to the data subject; or
  3. irrespective of his intent, with the disclosure causing psychological harm to the data subject.

The maximum penalty is a fine of $1,000,000 and imprisonment for five years.

Please read the PCPD’sleafletfor more details on the new offence and its justification.

Six data protection principles - Family CLIC (2024)

FAQs

What are the 6 main data protection principles? ›

At a glance
  • Lawfulness, fairness and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Accuracy.
  • Storage limitation.
  • Integrity and confidentiality (security)
  • Accountability.
May 19, 2023

What is the data protection principle 6 data access request? ›

Principle 6 – access to personal data

If it is found that the data contained therein is inaccurate, the data subject has the right to request the data user to correct the record. The data user must accede to the access and correction requests within a statutory period of 40 days.

Which of the following is among the six principles of GDPR? ›

The data protection principles that would be impacted include 1 – lawful, fair and transparent; 2 – limited for its purpose and 6 – integrity and confidentiality.

What are the principles of personal data protection? ›

Lawfulness, fairness, and transparency: Any processing of personal data should be lawful and fair. It should be transparent to individuals that personal data concerning them are collected, used, consulted, or otherwise processed and to what extent the personal data are or will be processed.

What are the 6 data quality principles? ›

What are the Six Data Quality Dimensions? The six data quality dimensions are Accuracy, Completeness, Consistency, Uniqueness, Timeliness, and Validity.

What are the 6 lawful bases of GDPR? ›

Article 6 of the General Data Protection Regulation (GDPR) sets out what these potential legal bases are, namely: consent; contract; legal obligation; vital interests; public task; or legitimate interests.

What does storage limitation in the 6 key data protection principles cover? ›

What is the storage limitation principle? So, even if you collect and use personal data fairly and lawfully, you cannot keep it for longer than you actually need it. There are close links here with the data minimisation and accuracy principles.

How many data protection principles are there in total? ›

Six Data Protection Principles (DPP)

Personal data must be collected in a lawful and fair way, for a purpose directly related to a function /activity of the data user. Data subjects must be notified of the purpose and the classes of persons to whom the data may be transferred.

What are the 7 golden rules of data protection? ›

Necessary, proportionate, relevant, accurate, timely and secure. Check these key words. Is it the right information for the purpose?

What are the six data subject's rights in the GDPR? ›

The GDPR has a chapter on the rights of data subjects (individuals) which includes the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object and the right not to be subject to a decision based solely on automated ...

What are the main GDPR rules? ›

The GDPR lays out the following seven basic principles on which it bases its regulations and rules of compliance related to personal data:
  • Lawfulness, fairness and transparency. ...
  • Purpose limitation. ...
  • Data minimization. ...
  • Accuracy. ...
  • Storage limitation. ...
  • Integrity and confidentiality. ...
  • Accountability.

What are the principles of data? ›

Data are sensitive and must therefore be protected and kept confidential. We must ensure that the privacy and confidentiality of data subjects is protected throughout the full data lifecycle. Those providing data should be made aware of confidentiality procedures and rights at point of collection.

What are the 6 principles of data protection? ›

Lawfulness, fairness, and transparency; ▪ Purpose limitation; ▪ Data minimisation; ▪ Accuracy; ▪ Storage limitation; ▪ Integrity and confidentiality; and ▪ Accountability. These principles are found right at the outset of the GDPR, and inform and permeate all other provisions of that legislation.

What are the 7 core principles of GDPR? ›

The Seven Principles
  • Lawfulness, fairness and transparency.
  • Purpose limitation.
  • Data minimisation.
  • Accuracy.
  • Storage limitation.
  • Integrity and confidentiality (security)
  • Accountability.

What is the first data protection principle? ›

What is the first principle about? The first data protection principle says that any processing for the law enforcement purposes must be lawful and fair. Lawfulness and fairness are well established requirements of data protection law.

What are the 7 principles of data security? ›

If your company handles personal data, it's important to understand and comply with the 7 principles of the GDPR. The principles are: Lawfulness, Fairness, and Transparency; Purpose Limitation; Data Minimisation; Accuracy; Storage Limitations; Integrity and Confidentiality; and Accountability.

What are the six principles of security management? ›

The Six Principles of Information Security Management • The fundamental principles of information security include: • Confidentiality • Privacy • Quality • Availability • Trustworthiness • Integrity (Twomey, 2010).

What are the 8 key principles of data protection? ›

What Are the Eight Principles of the Data Protection Act?
  • Fair and Lawful Use, Transparency. The principle of this first clause is simple. ...
  • Specific for Intended Purpose. ...
  • Minimum Data Requirement. ...
  • Need for Accuracy. ...
  • Data Retention Time Limit. ...
  • The right to be forgotten. ...
  • Ensuring Data Security. ...
  • Accountability.
Dec 12, 2022

Top Articles
How often can you buy I bonds?
Buying a Treasury Marketable Security — TreasuryDirect
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Geoffrey Lueilwitz

Last Updated:

Views: 6066

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Geoffrey Lueilwitz

Birthday: 1997-03-23

Address: 74183 Thomas Course, Port Micheal, OK 55446-1529

Phone: +13408645881558

Job: Global Representative

Hobby: Sailing, Vehicle restoration, Rowing, Ghost hunting, Scrapbooking, Rugby, Board sports

Introduction: My name is Geoffrey Lueilwitz, I am a zealous, encouraging, sparkling, enchanting, graceful, faithful, nice person who loves writing and wants to share my knowledge and understanding with you.