Skip to content
Case Notes
Case Notes
year
--Year--
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
1997
Category
--Category--
Appeal case
Complaint case
Compliance case
Enquiry case
By Provisions/DPPs/COPs/Guidelines
--By Provisions/DPPs/COPs/Guidelines--
DPP1 - Purpose and manner of collection of personal data
DPP2 - Accuracy and duration of retention of personal data
DPP3 - Use of personal data
DPP4 - Security of personal data
DPP5 - Information to be generally available
DPP6 - Access to personal data
Code of Practice on Consumer Credit Data
Code of Practice on Human Resource Management
Code of Practice on the Identity Card Number & Other Personal Identifiers
exemptions
Privacy Guidelines: Monitoring and Personal Data Privacy at Work
provisions on direct marketing
Proper Handling of Data Access Request and Charging of Data Access Request Fee by Data Users
N/A
Section 2 of the Ordinance – definition of “personal data”
Section 37 of the Ordinance
Section 38 of the Ordinance
Section 64 - disclosing personal data
Section 39 of the Ordinance
Section 26 – erasure of personal data
By Topic/Subject Matter
--By Topic/Subject Matter--
Biometrics data
Blind-ad
Complaint Handling Policy
Consumer credit data
Customer data
Data Access Request Fee
Debt collection
E-mail
Education
Election
Employment
Hong Kong Identity Card number / Hong Kong Identity Card copy
Human resources
Installation of CCTV
Internet
Jurisdiction of Personal Data (Privacy) Ordinance
Marketing
Media
Medical data
Monitoring
N/A
Personal Information Collection Statement (PICS)
Public Domain
Public register
Social services
Spamming
Transfer of data outside Hong Kong
keyword:
Case No.:2022DB02
Unauthorised photo-taking in a hospital – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2022DB01
Unauthorised access to a clinical centre’s customer personal data system – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2021C01
Accessing a patient's electronic health record for non-medical purposes – DPP 3 – use of personal data
... <more>
Areas of Concern:
DPP3
Case No.:2020A09
This case related to DPP4 – Security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2019C09
This case related to DPP4 - Security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2019C01
This page only provides Chinese version temporarily
... <more>
Areas of Concern:
DPP3
,
DPP4
,
Exemptions
Case No.:2017DB02
IT system containing over 11,000 unencrypted patients’ records being hacked – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2015C03
This case related to DPP4 - Security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2014A03
This case related to DPP3 - Use of personal data , exemptions , Proper Handling of Data Access Request and Charging of Data Access Request Fee by
... <more>
Areas of Concern:
DPP3
,
Exemptions
,
Section 28(3)
Case No.:2014A01
This page only provides Chinese version temporarily
... <more>
Areas of Concern:
DPP4
Case No.:2013C05
Excessive fee imposed for compliance with data access request by a private hospital
... <more>
Areas of Concern:
DPP6
Case No.:2010C04
A medical institution sending email to patients must ensure that the email does not contain other people's personal data
... <more>
Areas of Concern:
DPP4
1
2
3