Previous Page  8 / 32 Next Page
Information
Show Menu
Previous Page 8 / 32 Next Page
Page Background

8

PCPD News

私隱專員公署通訊

Issue no. 30

專題報道

Cover Story

個案:翱翔旅遊的流動應用程式 

未有提供私隱政策並收集過度個人資料

Case: Excessive Collection of Personal Data through Mobile Application by

Worldwide Package Travel Service Operating with No Privacy Policy

公署另一份調查報告指,翱翔旅遊有限

公司(「翱翔遊」)在顧客

(i)

參加客戶獎

賞計劃「翱翔天地」(「該計劃」)及

(ii)

於流動應用程式(「該程式」)查詢該計

劃的積分時,收集過量的個人資料。該

程式由縱橫旅遊有限公司(「縱橫遊」)

開發及由翱翔遊營運。另外,翱翔遊和

縱橫遊兩間公司均沒有透過私隱政策、

應用程式供應平台上的敍述或其他溝通

渠道,向該程式的用戶解釋收集資料的

用途。兩間公司均違反了條例附表一保

障資料第

1

原則。

縱橫遊是一間批發旅遊產品的本地旅行

社,翱翔遊是縱橫遊的指定銷售代理。

該計劃是由翱翔遊獨自管理。顧客購買

旅遊產品後,可以加入成為該計劃會

員。顧客填寫申請表格時要提供姓出生

日期及身份證號碼等個人資料,不過在

三萬名登記會員中,約有二千人沒有提

供出生日期,三千人沒有提供身份證號

碼,但申請仍然被翱翔遊接納。申請經

接受後,顧客會獲發一個會員編號。

The PCPD published another investigation

report concerning the excessive collection

of personal data by Worldwide Package

Travel Service Limited ("Worldwide

Travel") from customers when they

enrolled for the company's loyalty

programme ("Programme") and when

making online enquiries about the

reward points under the Programme

using the mobile application ("App")

developed by Package Tours (Hong

Kong) Limited ("Package Tours") and

operated by Worldwide Travel. Further,

both Worldwide Travel and Package

Tours did not explain to the App users

the purpose of use of the customers'

pe r s ona l da t a t hey co l l ec t ed v i a

a privacy policy, app marketplace

description or other communication

mean s . The two compan i e s have

contravened the Data Protection Principle

("DPP") 1 in Schedule 1 to the Ordinance.

Package Tours is a local travel agent

providing wholesale travel products

and Worldwide Travel is its designated

s a l e s a g e n t . Th e P r o g r amme i s

exclusively administered by Worldwide

Travel. Customers after having made

a purchase of the company's travel

products may join the Programme. In

completing the Programme application

f o rm, t h e c u s t ome r s upp l i e s h i s

personal data including date of birth

("DOB") and identity ("ID") number.

There were about 30,000 registered

memb e r s und e r t h e P r o g r amme .

Of these, around 2,000 and 3,000

members did not provide their DOB and

ID number respectively but Worldwide

Travel still accepted the application.

Upon enrolment, the customer is

assigned a membership number.

過度收集的個人資料

Personal Data Excessively

Collected

出生日期及身份證號碼

DOB and ID Number

資料使用者

Data User

翱翔遊

獨自營運及管理「翱翔天地」,以及其電腦系統及資料庫

Worldwide Travel who solely manages and operates the Programme

翱翔遊聲稱的收集目的

Collection Purpose Stated

byWorldwide Travel

為提供服務時(包括會員查詢其帳戶資料、查詢/換取積分),核實會員身份

To identify the applicants/members when providing services under the Programme

公署觀察資料

PCPD’s Observations

即使申請人沒有在申請表提供出生日期或身份證號碼,翱翔遊仍然接納其申請

會員親身及致電熱線查詢時,只須提供會員編號、姓名、電郵地址及/或流動電話號碼,亦足以辨識其身份

出生日期及身份證號碼在「翱翔天地」的電腦系統中並非會員資料的搜尋準則

2013

5

月修訂申請表,取消收集身份證號碼,但卻沒有落實生效日期,並容許分行繼續使用舊申請表:可能繼續超乎適度地收集身份證

號碼

• Worldwide Travel accepted the application when the applicants did not provide their DOB or ID number on the application forms.

• For in-person and hotline enquiry, a member’s membership number or his name, email address and/or mobile phone number would suffice

for identification.

• DOB and ID number are not made search criteria in the computer system for the Programme.

• Worldwide Package revised the application form and stopped collecting applicants’ ID Number in May 2013, but it did not specify an

effective date for the new form and allowed the old forms to be used until stock depletion. This may lead to prolonged excessive collection of

ID number.

收集過度的個人資料:「翱翔天地」

Excessive Collection of Personal Data – the Programme