Portal:Office of the Privacy Commissioner for Personal Data, Hong Kong

Biographical details

Portal:Office of the Privacy Commissioner for Personal Data, Hong Kong Unauthorised Access to Credit Data in the TE Credit Reference System (2023)

Data Protection Principle 2 (2) of the Ordinance provides that personal data should not be kept longer than the period that is necessary for the fulfilment of the purpose for which the data are or are to be used. Paragraphs 3.3, 3.3.1 and 3.3.2 of the Code provide that credit reference agencies can only retain account repayment data in their database for five years after the date of final settlement or the date of discharge from bankruptcy, whichever is earlier. Softmedia clearly did not meet the requirements of the Code or implement a policy of credit record deletion after repayments.
Source: Wikisource

Portal:Office of the Privacy Commissioner for Personal Data, Hong Kong Improper Collection, Retention… (2022)

When it comes to posting of notices containing personal data, generally speaking, property management companies have a duty to inform property owners of the issues which may affect their interests. Public display of notices for discharge of the above duty is related to building management. However, property management companies should carefully consider and assess the necessity of publishing information containing an individual's personal data and the amount of data involved, especially when sensitive personal data is involved.
Source: Wikisource

Portal:Office of the Privacy Commissioner for Personal Data, Hong Kong Ransomware Attack on the Servers of The Hong Kong Institute of Bankers (2023)

Through this report, the Commissioner would like to make the following recommendations to organisations that handle personal data with the use of information and communications technology (ICT) :- Stay Vigilant to Prevent Hacker Attacks: In the wake of different security vulnerabilities, organisations should always stay vigilant, and conduct regular risk assessments to review the potential impact of hacking on their systems, and enhance the protection of the systems which contain personal data such as servers, customer databases, etc.
Source: Wikisource

Get perspective with Kwize: daily news enlightened by great literature