Portal:Office of the Privacy Commissioner for Personal Data, Hong Kong, Unauthorised Access to Credit Data in the TE Credit Reference System (2023)
“ Data Protection Principle 2 (2) of the Ordinance provides that personal data should not be kept longer than the period that is necessary for the fulfilment of the purpose for which the data are or are to be used. Paragraphs 3.3, 3.3.1 and 3.3.2 of the Code provide that credit reference agencies can only retain account repayment data in their database for five years after the date of final settlement or the date of discharge from bankruptcy, whichever is earlier. Softmedia clearly did not meet the requirements of the Code or implement a policy of credit record deletion after repayments. ”
