(iii) in a reasonable manner; and
(iv) in a form that is intelligible;
(c) be given reasons if a request referred to in paragraph (b) is refused;
(d) object to a refusal referred to in paragraph (c); . . .
In addition, Part 5 of the Ordinance contains detailed provisions and procedural
requirements regarding how a data subject may make, and how a data user complies
with, a data access request. Failure to comply with a data access request in
accordance with the requirements under the Ordinance without reasonable excuse
may constitute an offence and render the offender liable on conviction to a fine.
addition to the grounds provided under Part 5 which prescribe when a data user shall or
may refuse to comply with a data access request, there are exemption provisions in Part
8 of the Ordinance which, when properly invoked, may exempt the data user from
complying with a data access request.
There are stringent provisions under Part 5 of the Ordinance on the manner and the
procedure of complying with a data access request that a data user has to observe.
Thus, when a data access request is received, the data user shall handle it according to
the relevant provisions in complying with or refusing to comply with, the data access
Salient points on the making of a data access request by a data subject or his relevant
and on the handling and responding to such a request by the data user are set
out below. The Guidance Note on Proper Handling of Data Access Request and
Charging of Data Access Request Fee by Data Users issued by the Commissioner
provides general guidance on compliance with a data access request.
What Constitutes a Data Access Request?
The first question to consider is what constitutes a data access request under the
Ordinance. In this connection, “data access request” is defined in section 2(1) as “a
request under section 18”.
Section 18(1)
provides as follows:
(1) An individual, or a relevant person on behalf of an individual, may make a request –
(a) to be informed by a data user whether the data user holds personal data of which
the individual is the data subject;
(b) if the data user holds such data, to be supplied by the data user with a copy of
such data.
A level three fine, see section 64A(1).
As defined under sections 2(1) and 17A of the Ordinance.
Available on the Website: