Skip to content

Codes of Practice/ Guidelines

Code of Practice on the Identity Card Number and other Personal Identifiers

Appendix I

Personal Data (Privacy) Ordinance
Cap. 486
(Schedule 1)
DATA PROTECTION PRINCIPLES


1. Principle 1 - purpose and manner of collection of personal data

  1. A data user shall erase personal data held by the data user where the data are no longer required for the purpose (including any directly related purpose) for which the data were used unless -
    1. the data are collected for a lawful purpose directly related to a function or activity of the data user who is to use the data;
    2. subject to paragraph (c), the collection of the data is necessary for or directly related to that purpose; and
    3. the data are adequate but not excessive in relation to that purpose.
       
  2. Personal data shall be collected by means which are
    1. lawful; and
    2. fair in the circumstances of the case.
       
  3. Where the person from whom personal data are or are to be collected is the data subject, all practicable steps shall be taken to ensure that
    1. he is explicitly or implicitly informed, on or before collecting the data, of-
      1. whether it is obligatory or voluntary for him to supply the data; and
      2. where it is obligatory for him to supply the data, the consequences for him if he fails to supply the data; and
    2. he is explicitly informed-
      1. on or before collecting the data, of-
        (A) the purpose (in general or specific terms) for which the data are to be used; and
        (B) the classes of persons to whom the data may be transferred; and
      2. on or before first use of the data for the purpose for which they were collected, of-
        (A) his rights to request access to and to request the correction of the data, and
        (B) the name and address of the individual to whom any such request may be made,

unless to comply with the provisions of this subsection would be likely to prejudice the purpose for which the data were collected and that purpose is specified in Part VIII of this Ordinance as a purpose in relation to which personal data are exempt from the provisions of data protection principle 6.

Previous Page | Next Page