Companies and Business operators shall comply with the 6 principles in relation to Personal Data Protection:
- Personal data must be collected for a lawful purpose.
- One must ensure that the data held are accurate and up-to-date, date should not keep the data any longer than is necessary.
- Data must not be used for any purpose other than the one mentioned at the time the data were collected, except with ” Prescribed consent”
- One must take appropriate security measures to protect personal data.
- One shall disclose to public the kind (not the content) of personal data held by them and their policies and practices on how they handle personal data, such as a ” Privacy Policy Statement”.
- Data subject is entitled to ask a data user whether or not the data user holds any of his/her personal data, and to request a copy of such personal data held by that user.
Please be reminded that person violating the Personal Data (Privacy) Ordinance are subjected to fine and imprisonment!