22
PCPD News
私隱專員公署通訊
•
Issue no. 32
詞彙
Glossary
收集個人資料聲明
Personal Information Collection Statement (“PICS”)
《收集個人資料聲明》(「聲明」)是指資
料使用者為依從《個人資料(私隱)條例》
(「條例」)第
1(3)
原則規定而作出的聲明。
雖然條例沒有規定要作出書面通知,但
為了提高透明度及避免雙方可能產生誤
會,良好的行事方式是以書面向資料當
事人提供必要的資訊。
《收集個人資料聲明》應包括:
a.
個人資料被收集後會用於甚麼目
的;
b.
資料當事人是否有責任或可自願提
供其個人資料、以及若不提供資料
的後果;
c.
所收集資料有可能會向甚麼類別的
人轉移或披露;
d.
資料當事人要求查閱及改正資料使
用者所持有其個人資料的權利,以
及;
e.
負責處理查閱及改正資料要求的人
的姓名(或職銜)及其聯絡資料。
無論在現實環境或在網上收集個人資
料,資料使用者均需要向資料當事人提
供簡潔易明的聲明。收集目的聲明不應
過於含糊及範圍太廣;就特定的收集目
的應使用特定的《收集個人資料聲明》;
以及包括保安措施聲明,亦即資料使用
者應交代其處理個人資料所採取的保安
措施,尤其在網上收集個人資料,如信
用卡號碼,應列明在網上交易過程中所
採用的特定保安措施。
公署曾出版一份《擬備收集個人資料聲
明及私隱政策聲明指引》,詳細解釋如
何撰寫個人資料聲明及私隱政策聲明,
詳情可參閱
www.pcpd.org.hk//tc_chi/resources_centre/publications/files/GN_picspps_
c.pdf
A PICS is a statement given by a data
user for the purpose of complying with
the notification requirements under Data
Protection Principle 1(3) of the Personal
Data (Privacy) Ordinance (“Ordinance”).
While the Ordinance does not require
the notification to be given in writing,
it is good practice for the requisite
information to be provided to the data
subjects in writing in the interests of
transparency and to avoid possible
misunderstanding between the parties.
A PICS should include:
a. Purposes for which personal data
will be used following collection;
b. Whether it is obligatory or voluntary
for a data subject to supply his
personal data and consequences of
failure to supply the data;
c. Classes of persons to whom personal
data collected from the data subjects
may be transferred or disclosed;
d. Data subjects’ right to request access
to and correction of his personal
data held by the data users; and
e. Name (or job title) and contact
details of the individual who is
responsible for handling any data
access and data correction requests.
The need for an easily readable and
understandable PICS applies to the
collection of information in both
the physical world and the online
environment. The purpose statement
should not be too vague and too wide
in scope. A specific PICS should be used
for a specific collection purpose. A PICS
may include a notice about the security
measures adopted by the data user in the
handling of personal data, in particular
if the personal data is collected online,
the specific security measures that are
applied to online transactions such as
collection of credit card numbers.
PCPD has issued a guidance note
entitled “Guidance on Preparing Personal
Information Collection Statement and
Privacy Policy Statement” to serve as a
general reference for preparing PICS and
Privacy Policy Statement. For details,
please visit PCPD’s website at
www.pcpd.org.hk//english/resources_centre/publications/files/GN_picspps_
e.pdf
.