Skip to content
Case Notes
Case Notes
year
--Year--
2024
2023
2022
2021
2020
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008
2007
2006
2005
2004
2003
2002
2001
2000
1999
1998
1997
Category
--Category--
Appeal case
Complaint case
Compliance case
Enquiry case
By Provisions/DPPs/COPs/Guidelines
--By Provisions/DPPs/COPs/Guidelines--
DPP1 - Purpose and manner of collection of personal data
DPP2 - Accuracy and duration of retention of personal data
DPP3 - Use of personal data
DPP4 - Security of personal data
DPP5 - Information to be generally available
DPP6 - Access to personal data
Code of Practice on Consumer Credit Data
Code of Practice on Human Resource Management
Code of Practice on the Identity Card Number & Other Personal Identifiers
exemptions
Privacy Guidelines: Monitoring and Personal Data Privacy at Work
provisions on direct marketing
Proper Handling of Data Access Request and Charging of Data Access Request Fee by Data Users
N/A
Section 2 of the Ordinance – definition of “personal data”
Section 37 of the Ordinance
Section 38 of the Ordinance
Section 64 - disclosing personal data
Section 39 of the Ordinance
Section 26 – erasure of personal data
By Topic/Subject Matter
--By Topic/Subject Matter--
Biometrics data
Blind-ad
Complaint Handling Policy
Consumer credit data
Customer data
Data Access Request Fee
Debt collection
E-mail
Education
Election
Employment
Human resources
ID number/ ID copy
Installation of CCTV
Internet
Jurisdiction of Personal Data (Privacy) Ordinance
Marketing
Media
Medical data
Monitoring
N/A
Personal Information Collection Statement (PICS)
Public Domain
Public register
Social services
Spamming
Transfer of data outside Hong Kong
keyword:
Case No.:2022C02
An employer posted a list containing the personal data of staff who were to undergo virus testing – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
,
Human Resources
Case No.:2021DB04
Unencrypted personal data transmitted in mobile applications – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2021DB03
Loss of notebook computer containing work files – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2021DB02
Inadvertent disclosure of students’ personal data via email by a university – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2021DB01
Unauthorised access to an international fashion chain’s customer personal data system – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2021A01
New!
This case related to DPP3 – Use of personal data; DPP4 – Security of personal data
... <more>
Areas of Concern:
DPP3
,
DPP4
Case No.:2020DB02
A staff member transferred personal data held by his employer to his personal computer without authorisation – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2020DB01
Unauthorised access of personal data held by public schools via a web-based application system – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2020A09
New!
This case related to DPP4 – Security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2019DB03
Recruitment platform wrongfully sent out emails containing CV information – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2019DB02
Unauthorised circulation of confidential documents containing personal data in social media network – DPP 4 – security of personal data
... <more>
Areas of Concern:
DPP4
Case No.:2019C10
This case related to DPP3 - Use of personal data , DPP4 - Security of personal data
... <more>
Areas of Concern:
DPP3
,
DPP4
1
2
3
4
5
6