PCPD News
私隱專員公署通訊
•
Issue no. 29
24
PCPD in Action
公署動態
Mark Your Diary
活動日誌
Resources Updates
資源快訊
Statistics
統計
Glossary
詞彙
Technology Updates
科技新知
公署跟進傳媒報道,調查警務處兩宗涉
嫌經
Foxy
共享軟件洩漏個人資料的事
故,調查結果確定事件屬於人為錯失,
警務處未有違反條例規定。
但鑑於外洩文件載有重要和敏感的個人
資料,私隱專員敦請警務處採取預防措
施,避免同類事件再次發生。例如:
(i)
加強宣傳,鼓勵警務人員使用部門提供
的「個人電腦清洗」程式。
(ii)
設立諮詢
熱線,為有需要的人員以不記名方式提
供支援。
(iii)
促進警務人員之間的個案
分享及經驗交流,以增進對保障個人資
料的認知和明白網上資訊外洩的嚴重後
果等。
私隱專員提醒公眾人士:「檔案一旦經
過
Foxy
網絡外洩,基本上無法把資料挽
回。雖然
Foxy
的開發商經已結業,但全
球至少有
40
萬人的電腦仍啟動著
Foxy
軟
件,用家需了解其
Foxy
版本如何運作,
並加以適當的設定,以保護資料檔案。」
他忠告市民,下載這軟件,是非常危險
的事,因為在非官方渠道下載的版本有
機會是惡意程式或遭加工,可能招致無
法控制的資料外洩事故。
調查報告:
www.pcpd.org.hk/chinese/publications/files/R13_15218_c.pdf
資料經
Foxy
外洩後患無窮
Us of Foxy Culminated in Data Leakage which Got
Out of Control
T h e PCPD h a s p r o b e d i n t o t wo
i n c i d e n t s o f a l l e g e d l e a k a g e o f
internal documents by the Hong Kong
Police Force (“HKPF”) via Foxy after
they were reported in the press. The
investigation concluded that the two
incidents were attributed to human
error, and found no contravention on
the part of the HKPF.
Con s i de r i ng t he impo r t anc e and
s e n s i t i v i t y o f t h e p e r s o n a l d a t a
contained in the police documents,
Privacy Commissioner has urged the
HKPF to take preventative measures
t o ( i ) p r o m o t e t h e u s e o f t h e
HKPF’s personal computer cleaning
programme for checking and deleting
personal data/confidential data on
personal computers, (ii) set up an
enquiry hotline to support police
officers on an anonymous basis, and
(iii) promote case and experience
s ha r i ng among po l i ce o f f i ce r s t o
enhance the awareness of personal
d a t a p r o t e c t i o n a n d t h e s e r i o u s
consequences that may result from
data leakages on the Internet.
Privacy Commissioner has warned
the public that there is practically no
effective recovery means once a data
file is leaked through the Foxy network.
Though the developer of Foxy has
ceased business, Foxy is still operating
on 400,000 or more computers around
the world. Whoever wants to download
this software for use will have to resort to
unofficial channels and may thus obtain
a copy which contains malware or which
has been altered, thus running the risk of
uncontrollable data sharing.
Investigation Report
:
www.pcpd.org.hk/english/publications/files/
R13_15218_e.pdf
學生資助辦事處個人資料系統視察報告
Inspection Report of the Personal Data System of
Student Financial Assistance Schemes
公署視察過學生資助辦事處用作處理四
項中小學生資助計劃的個人資料系統,
包括學校書簿津貼計劃、學生車船津貼
計劃、上網費津貼計劃和考試費減免計
劃。結果顯示該系統的資料保障措施大
致令人滿意,惟某些方面,例如沒有明
文指引規範職員向電話查詢者披露有關
申請的個人資料,仍需檢討和改善。
視察報告:
www.pcpd.org.hk/chinese/publications/files/R14_3771_c.pdf
The PCPD has conducted an inspection
on the Student Financial Assistance
Agency’s personal data system in respect
of four of its financial assistance schemes
for primary and secondary students. The
schemes include the School Textbook
Assistance Scheme, Student Travel
Subsidy Scheme, Subsidy Scheme for
Internet Access Charges and Examination
Fee Remission Scheme. The inspection
concluded that the data protection
measures in the personal data system
inspected were reasonably satisfactory.
However, certain areas such as the
lack of written guidelines as to which
information in application records may
or may not be disclosed to callers require
review and improvement.
Inspection Report:
www.pcpd.org.hk/english/publications/files/R14_3771_e.pdf