Previous Page  9 / 32 Next Page
Information
Show Menu
Previous Page 9 / 32 Next Page
Page Background

9

PCPD News

私隱專員公署通訊

Issue no. 30

過度收集個人資料

Personal Data Excessively

Collected

出生日期及身份證號碼

DOB and ID Number

資料使用者

Data User

翱翔遊

(1)

負責處理「縱橫遊」程式收集的個人資料

(2)

程式是在翱翔遊操作的電腦系統及伺服器中運作

Worldwide Travel who is responsible for the collection and processing of personal data through the App, and the

App operates on the computer system and servers of the Programme run by Worldwide Package.

翱翔遊聲稱的收集目的

Collection Purpose Stated by

Worldwide Travel

核實會員身份

To verify a member’s identity

公署觀察資料

PCPD’s Observations

翱翔遊實際上(親身及熱線查詢)只需使用私隱敏感度較低的個人資料(例如姓名及聯絡資料),便能可靠地核實會員身份

雖然每名會員都獲編配會員編號,以辨識會員身份,但用戶介面卻沒有欄目以輸入會員編號

查詢積分餘額是相對較不重要的事,收集出生日期及身份證號碼以核實會員身份的做法屬不必要及超乎適度

• For in-person and hotline enquiry, Worldwide Package was able to authenticate reliably the identity of a member by merely using less

sensitive personal data, such as his name and contact information.

• Membership number was not made a data field in the customer interface under the App notwithstanding a member is always able to check

his account through in-person or hotline enquiries by just quoting his membership number.

• Enquiry about reward points balance was a relatively inconsequential matter, collection of DOB and ID was unnecessary and excessive.

功能

Function

資料使用者

Data User

網上訂購

Online

Purchase

翱翔遊及縱橫遊

Worldwide Travel and Package Tours

處理銷售旅遊產品時,共用同一個電腦系統及資料庫

翱翔遊負責接收及確認程式發送的網上訂單

縱橫遊負責向航空公司購買機票及團體旅遊保險

• Both Worldwide Travel and Package Tours share the same database and computer

system for managing the sale of the travel products.

• Worldwide Travel is responsible for receiving and acknowledging online purchase orders

made through mobile devices via the App.

• Package Tours is responsible for flight tickets issuance with airlines and purchase of

group travel insurance.

積分查詢

Reward Points

Enquiry

翱翔遊

Worldwide Travel

見上表「積分查詢」功能

See the table above

Reward Points Enquiry

Function

公署觀察資料

PCPD’s Observations

「網上訂購」及「積分查詢」功能均會收集個人資料,但卻沒有提供以下資訊

: -

收集個人資料的目的

資料承轉人的類別

用戶要求查閱及改正資料的權利

處理查閱及改正資料要求的人士的姓名或職銜及地址

Both functions collect personal data but do not provide the following information: -

• the purpose for which the data is to be collected

• the classes of persons to whom the data may be transferred

• user’s right to request access to and correction of the data

• the name or job title, and address, of the individual who is to handle any such request.

違反相關的保障資料原則及說明

Contravention of the relevant DPPs and description

縱橫遊

Package Tours

翱翔遊

Worldwide Package

保障資料

1(1)

原則

DPP1(1)

「翱翔天地」的申請過程過度收集申請人的出生日期及身份證號碼

Excessive collection of DOB and ID number for verifying members’ identity during

Programme application

不適用

N/A

應用程式「積分查詢」功能過度收集會員的出生日期及身份證號碼

Excessive collection of DOB and ID number through Reward Points Enquiry under the App

保障資料

1(3)(b)

原則

DPP1(3)(b)

應用程式「網上訂購」功能沒有通知程式用戶相關資訊

Failed to inform the users of the relevant information during Online Purchase on the App

應用程式「積分查詢」功能沒有通知程式用戶相關資訊

Failed to inform the users of the relevant information during Reward Points Enquiry on the App

不適用

N/A

收集過度的會員個人資料:「積分查詢」功能

Excessive Collection of Personal Data - “Reward Points Enquiry” Function

透過「縱橫遊」程式收集個人資料:沒有提供通知

Failure to Provide Notification to App users

調查結果

Contraventions by Package Tours and Worldwide Package