17
PCPD News
私隱專員公署通訊
•
Issue no. 29
場景
Scenario
6
招聘及僱傭活動
Recruitment and Human Resources Activities
場景
Scenario
7
手機應用程式
Mobile Apps
商店經理在招募售貨員的第一輪面試
中,要求影印求職者的身份證,以作紀
錄和辨識求職者身份。
A shop manager collects a copy of the
ID card of a job applicant in the first
round of interviews for the post of retail
clerk for the purpose of recording and
checking the identity of the candidate.
保障私隱錦囊
•
除非求職者已受聘,否則僱主不可過
早收集求職人士的身份證副本。一般
而言,僱主可收集僱員的身份證副
本,作為已遵從《入境條例》(第
115
章)
第
17J
的證明。
•
只向求職者收集足以遴選用的個人資料。
•
落選者的個人資料,保存時間不應超
過兩年。
•
現職員工的個人資料,只可用於僱傭
目的。
Tips for data privacy
• Employers should not collect ID card
copies of job applicants during the
recruitment process unless and until
the candidate has accepted an offer of
employment. Generally speaking, an
employer may collect the ID card copy
of an employee as proof of compliance
by the employer with section 17J of the
Immigration Ordinance (Cap 115).
• Employers should collect only the
personal data which is necessary for
recruitment selection.
• Employers should not keep longer
than two years the personal data of
candidates not employed.
• Employers should use the personal
data of current employees only for
employment purposes.
Tips for data privacy
• Unless there is a strong justification,
the company cannot install covert
recording devices in its shop.
• Overt means such as CCTV may
be used for purposes such as theft
prevention.
• A prominent notice should be placed
at the shop entrance and in the
surveillance area to remind customers
and staff that they are subject to
surveillance, and inform them of the
purpose of the monitoring.
• No CCTV surveillance can be installed
in places where customers and staff
expect a relatively high degree of
privacy, such as in restrooms or
changing rooms.
某食肆推出外賣的智能電話應用程式,
消費者用手機點選食品,然後輸入地址
發送訂單,便可享用送遞上門的食品。
A restaurant has launched a food delivery
mobile app, which allows customers
to choose the food from a menu, key
in their address, and have the food
delivered.
保障私隱錦囊
•
在用戶安裝程式前提供清楚的個人資
料收集聲明。
•
程式的讀取資料權限聲明,不能
代替個人資料收集聲明或私隱政
策聲明。
•
收集的資料只限用於處理外賣訂單,
而不應用作其他目的。做好保安措
施,防止訂單的個人資料外洩。
•
就目的而言不再需要的顧客資料,便
應刪除。
•
如要用已收集的顧客資料發放宣傳推
廣資訊,應事先取得顧客同意,和限
於用作推銷顧客已同意的產品和服務
類別。
Tips for data privacy
• The restaurant must clearly display its
PICS to its customers before they install
the app.
• The restaurant cannot substitute the
declaration for data accessing rights of
the app for its PICS or Privacy Policy
Statement.
• The restaurant cannot use the data
collected for any purpose other than
processing orders for delivery, and it
should have proper safety precautions
in place to prevent data leakage.
• The restaurant should delete customers’
details that are no longer necessary for
the prescribed purposes.
• Th e r e s t a u r a n t mu s t ob t a i n i t s
customers’ consent before using the
collected data in promotional activities,
and ensure the products or services
promoted are only those agreed to by
its customers.