TOP
月月讀書金,登入即領,滿600現折50!!
HyRead
Personal Data (Privacy) Law in Hong Kong:A Practical Guide on Compliance (Third Edition)(電子書)

Personal Data (Privacy) Law in Hong Kong:A Practical Guide on Compliance (Third Edition)(電子書)

商品資訊

定價
:NT$ 2514 元
閱讀器:Hyread電子書
下單可得紅利積點 :75 點
商品簡介
目錄

商品簡介

With an increasing concern of personal data privacy in Hong Kong and around the world, the Office...

目錄

Foreword25
Preface | Ada CHUNG Lai-ling27
Preface | Guobin ZHU31
Acknowledgments35
Chapter 1 Introduction37
Regulatory Approach39
Disclaimer42
Abbreviations Used in This Book42
Chapter 2 The Meaning of “Personal Data”45
Introduction — Meaning of the Term “Data”46
Definition of “Personal Data”47
Paragraph (a) — “Relating Directly or Indirectly to a Living Individual”47
Paragraph (b) — “From which it is Practicable for the Identity of the Individual to be Directly or Indirectly Ascertained”50
Paragraph (c) — “In a Form in which Access to or Processing of the Data is Practicable”52
Consideration of Certain Types of Information54
Physical Tracking and Monitoring through Electronic Devices61
Identifiability of an Individual — Existing Issues and a Possible Way Forward62
Chapter 3 The Meaning of “Collect”69
The Eastweek Case70
The Meaning of “Collect”71
When Does the Use of CCTV for Security or Monitoring Purposes Amount to the Collection of Personal Data?74
Information Privacy and Other Privacy Interests77
Chapter 4 The Meaning of “Data User”83
Meaning of “Data User” with Reference to the Eastweek Case84
Meaning of “Data User” with Reference to AAB Cases85
Section 2(12)87
Meaning of “Person” in the Context of Data User89
Joint Data Users91
What is the Relationship between a Data User and a Data Processor?93
Section 494
Chapter 5 Data Protection Principle 197
Overview98
The General Requirements of DPP198
Collection of HKID Card Numbers and Copies of HKID Cards100
Collection of HKID Card Numbers for Customer Loyalty Programmes107
Collection of HKID Card Numbers by the Property Management Sector109
Collection of HKID Card Numbers through Mobile Apps110
Collection of Personal Data for Direct Marketing Purposes110
Collection of Employees’ Health Data111
Collection of Health Data during the COVID-19 Pandemic113
Collection of the Criminal Records of Prospective Employees114
Collection of a Person’s Whereabouts115
DPP1(2)116
Collection of Personal Data through Blind Recruitment Advertisements118
Collection of Personal Data by Covert Means119
Collection of the Activities of Individuals that Take Place inside a Private Residence by Systematic Surveillance and Using a Long-focus Lens122
Passive Collection of the Whereabouts of Individuals124
Employees Providing Past Medical Records and Consequential Disciplinary Action124
Giving Misleading Information to Obtain a Credit Report from a Credit Reference Agency125
Collection of Personal Data from the Public Domain126
Collection of Biometric Personal Data and Consent127
DPP1(3)130
Application of DPP1(3)131
Obligation Not Absolute — “All Practicable Steps”132
Notification Requirements134
Purposes of Data Use135
The Classes of Persons to Whom the Data May be Transferred137
The Right to Request Access to and Correction of the Data139
Transparency and Explainability140
Requirements on Notification when Collecting Personal Data for Direct Marketing Purposes142
Chapter 6 Data Protection Principle 2143
Overview144
DPP2(1)144
DPP2(2) and Section 26149
Requirements under DPP2(3) and (4): Personal Data Transferred to a “Data Processor”159
Data Retention Period — Existing Issues and a Possible Way Forward160
Regulation of Data Processors — Existing Issues and a Possible Way Forward162
Chapter 7 Data Protection Principle 3163
Overview164
The General Requirements of DPP3164
What Does “Use” Mean?164
What is a “New Purpose”?164
The Original Purpose of Collection166
The Purposes of Collection Stated in the PICS167
The Lawful Functions and Activities of the Data User169
Restrictions of Use Imposed upon Data Users by Data Providers or Data Subjects170
Transferring Personal Data between Data Users172
Personal Data Collected from the Public Domain173
Purposes Directly Related to the Original Purpose of Collection179
Avoidance of Disclosing Unnecessary and Excessive Personal Data183
Is the Sale of Personal Data a Directly Related Purpose of Use?189
Prescribed Consent191
Prescribed Consent Given by a Relevant Person194
Requirements on Consent for Use when Collecting Personal Data for Direct Marketing Purposes196
Chapter 8 Data Protection Principle 4197
Overview198
The General Requirements of DPP4198
Data Breaches206
Application of DPP4: Storage and Transmission of Data226
Outsourcing the Processing of Personal Data to Data Processors227
Regulation of “Data Processors” — Existing Issues and a Possible Way Forward230
Chapter 9 Data Protection Principle 5231
Overview232
The General Requirements of DPP5232
What Should a PPS Include?233
PPS Should be Made Generally Available234
Other Information to be Made Available237
Exercise of the Commissioner’s Enforcement Powers under Section 50238
Chapter 10 Data Protection Principle 6(a) to (d) and the Data Access Provisions in Part 5239
Overview240
The Basis of a Data Access Request240
What Constitutes a Data Access Request?241
Who May Make a Data Access Request?243
How to Make a Data Access Request245
How and When to Comply with a Data Access Request247
Broad and Generic Requests for Personal Data249
Steps to be Taken on Failure to Comply with a Data Access Request within the Statutory Period253
Language and Format when Responding to a Data Access Request254
Data Access Request Made to the Hong Kong Police Force for Criminal Conviction Records256
Requested Data Comprising Personal Data of Another Individual257
Charge for Complying with a Data Access Request259
When Must a Data User Refuse to Comply with a Data Access Request?263
When May a Data User Refuse to Comply with a Data Access Request?265
Steps to Take in Refusing to Comply with a Data Access Request268
Proper Exercise of the Right to Access Personal Data270
Chapter 11 Data Protection Principle 6(e) to (g) and the Data Correction Provisions in Part 5275
The Relationship between a Data Correction Request and a Data Access Request276
Who Can Make a Data Correction Request and How Should it be Made?277
Compliance with a Data Correction Request278
Circumstances in which a Data User Shall or May Refuse to Comply with a Data Correction Request281
Steps to Take in Refusing to Comply with a Data Correction Request285
Chapter 12 Exemption Provisions in Part 8289
Overview291
Introduction291
Exemptions in General292
Section 51A — Performance of Judicial Functions294
Section 52 — Domestic Purposes295
Sections 53 and 54 — Staff Planning and Employment297
Section 55 — Relevant Process298
Section 56 — Personal References299
Section 57 — Security, etc. in Respect of Hong Kong300
Section 58 — Crime, etc.302
Section 58A — Protected Product and Relevant Records under Interception of Communications and Surveillance Ordinance312
Section 59 — Health313
Section 59A — Care and Guardianship of Minors316
Section 60 — Legal Professional Privilege317
Section 60A — Self-incrimination319
Section 60B — Legal Proceedings, etc.320
Section 61 — News325
Section 62 — Statistics and Research330
Section 63 — Exemption from Section 18(1)(a)331
Section 63A — Human Embryos, etc.332
Section 63B — Due Diligence Exercise332
Section 63C — Emergency Situations335
Section 63D — Transfer of Records to Government Records Service335
Chapter 13 The Commissioner’s Statutory Duties in Investigations337
Introduction338
The Commissioner’s Statutory Duties of Investigation338
Lodging a “Complaint”340
Restrictions on Investigations Initiated by a “Complaint”345
Discretion of the Commissioner349
The Commissioner’s Decision Whether to Carry Out an Investigation357
Chapter 14 Data Breach Handling and Notifications361
What is a Data Breach?362
What Should be Done to Prepare for a Data Breach?362
How Should a Data Breach be Handled?363
What is a Data Breach Notification?367
To Whom Should the Notification be Given?368
What Should be Included in the Data Breach Notification?368
When Should a Data Breach Notification be Given?369
How Should a Data Breach Notification be Given?370
Lesson Learnt: Preventing Recurrence371
Good Data Breach Handling Makes Good Business Sense372
Steps Taken by the Commissioner372
Data Breach Handling and Notifications — Existing Issues and a Possible Way Forward374
Chapter 15 Criminal Offences375
Overview376
Direct Marketing Offences376
Offences Relating to the Commissioner’s Enforcement Power393
Contravention of DPPs — Current Issues and a Possible Way Forward398
Offences Relating to the Commissioner’s Investigation Power399
Other Offences400
Cyber-bullying406
Chapter 16 Doxxing409
Introduction410
Elements of the Offence — Section 64(1) of the Ordinance414
Elements of the Offence — Sections 64(3A) and (3C) of Elements of the Offence — Sections 64(3A) and (3C) of415
Onward-forwarding of Doxxing Posts420
Criminal Investigation and Prosecution Powers420
The Commissioner’s Powers to Serve Cessation Notices and Apply for Injunctions425
Enforcement Actions Taken by the PCPD after the Amendment Ordinance 2021 Came into Operation435
Overseas Experiences and Developments437
Chapter 17 Cross-border Transfers of Personal Data from Hong Kong439
Overview440
Regulation under the Ordinance440
Cross-boundary Flow of Personal Information within the Guangdong-Hong Kong-Macao Greater Bay Area446
Chapter 18 An Overview of the Mainland’s Personal Information Protection Regime449
Introduction450
Key Definitions453
Principles for Processing Personal Information454
Legal Bases for Processing Personal Information456
Obligations of Personal Information Processors458
Rights of Individuals460
Other Specific Requirements462
Cross-border Transfer of Personal Information464
Enforcement and Legal Liability474
The Cybersecurity Law477
The Data Security Law479
Appendix I Selected Case Notes on Court Judgments481
1. Cathay Pacific Airways Limited v. Administrative Appeals Board & Another [2008] 5 HKLRD 539 (HCAL 50/2008)483
2. Chan Chuen Ping v. The Commissioner of Police [2014] 1 HKLRD 142 (HCMP 2741/2013)486
3. Chan Yim Wah Wallace v. New World First Ferry Services Limited (HCPI 820/2013, Date of Decision: 8 May 2015)489
4. Dr Alice Li Miu-ling v. The Hong Kong Polytechnic University (DCEO 1/2004, Date of Judgment: 1 November 2012)494
5. Eastweek Publisher Limited & Another v. Privacy Commissioner for Personal Data [2000] 2 HKLRD 83 (CACV 331/1999)498
6. HKSAR v. Hong Kong Broadband Network Limited [2018] 2 HKLRD 1049 (HCMA 624/2015, Date of Judgment: 26 January 2017) (on appeal from TWS 6311/2015)501
7. HKSAR v. Leung Chun-kit Brandon (HCMA 49/2016, Date of Judgment: 2 June 2017) (on appeal from ESS 24178/2015)508
8. Junior Police Officers’ Association of the Hong Kong Police Force & Another v. Electoral Affairs Commission & Others [2020] HKCA 352 (CACV 73/2020, Date of Judgment: 21 May 2020)516
9. Lily Tse Lai Yin & Others v. The Incorporated Owners of Albert House & Others (HCPI 828/1997, Date of Decision: 10 December 1998)521
10. M v. M (FCMC 1425/1988, Date of Judgment: 10 June 1997)523
11. Ng Shek Wai v. Medical Council of Hong Kong [2015] 2 HKLRD 121 (HCAL 167/2013)526
12. Oriental Press Group Ltd v. Inmediahk.net Ltd [2012] 2 HKLRD 1004 (HCA 1253/2010)530
13. Secretary for Justice v. Persons unlawfully and wilfully conducting themselves in any of the acts prohibited under paragraph 1(a) and (b) in the indorsement of claim and the Internet Society of Hong Kong Limited [2019] HKCFI 2809 (HCA 2007/2019)533
14. Secretary for Justice & Commissioner of Police v. Persons unlawfully and wilfully conducting themselves in any of the acts prohibited under paragraph 1(A), (B) or (C) in the indorsement of claim [2019] HKCFI 2773 (HCA 1957 of 2019)537
15. Sham Wing Kan v. Commissioner of Police [2020] HKCA 186 (CACV 270/2017, Date of Judgment: 2 April 2020)541
16. Tsang Po Mann v. Tsang Ka Kit and Another [2021] 1 HKLRD 1301545
17. Tso Yuen Shui v. Administrative Appeals Board (HCAL 1050/2000, Date of Decision: 16 November 2000)547
18. Wu Kit Ping v. Administrative Appeals Board [2007] 4 HKLRD 849 (HCAL 60/2007)550
Appendix II Major Differences between the PIPL, the GDPR and the PDPO552
Appendix III Checklist for Data Users in Ensuring Compliance with the Ordinance561
Appendix IV Data Subject’s Rights when his Personal Data Privacy is Infringed565
Conciliation with the Data User565
Lodging of a Complaint with the Commissioner under Section 37565
Appeal to the Administrative Appeals Board under Section 9 of the Administrative Appeals Board Ordinance (Cap. 442)566
Civil Remedies567
Index569
List of Court Cases and Administrative Appeals Board Decisions587

購物須知

為了保護您的權益,「三民網路書店」提供會員七日商品鑑賞期(收到商品為起始日)。

若要辦理退貨,請在商品鑑賞期內寄回,且商品必須是全新狀態與完整包裝(商品、附件、發票、隨貨贈品等)否則恕不接受退貨。

定價:100 2514
閱讀器:Hyread電子書

暢銷榜

客服中心

收藏

會員專區