PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Privacy Commissioner Releases Two Reports and Encourages Organizations to Nurture the Culture of “Protect and Respect Personal Data Privacy”

Posted on December 18, 2017June 25, 2025 by Dissent

The Privacy Commissioner for Personal Data, Hong Kong (the Privacy Commissioner) Mr Stephen Kai-yi WONG released two reports, namely “2017 Study Report on User Control over Personal Data in Customer Loyalty and Reward Programmes” and “Inspection Report: Personal Data System of An Estate Agency in Hong Kong”.

(I) 2017 Study Report on User Control over Personal Data in Customer Loyalty and Reward Programmes

The Privacy Commissioner for Personal Data, Hong Kong (PCPD) examined 30 customer loyalty and reward programmes from six sectors (i.e. retail, hotel, catering, airlines, cinema and gasoline) in late May 2017.   The examination was part of the global Privacy Sweep exercise of the Global Privacy Enforcement Network (GPEN).   This is the fifth consecutive year for the PCPD to participate in the Privacy Sweep.  The theme of the Privacy Sweep 2017 is “User Control over Personal Information”.  It aimed to examine privacy policies and practices of data users with a view to evaluating user controls over personal data.  PCPD decided to examine customer loyalty and reward programmes because of their popularity in the local market and their potential to collect substantial amount of personal data from large number of individuals.

The findings showed that most the privacy policies of the examined programmes lacked transparency. Customers were unable to provide meaningful consent to the collection and use of their personal data. They were unable to exercise effective control over their personal data in aspects of data deletion, data sharing and profiling either. Many programmes indicated in their privacy policies their intention to use personal data for big data analytics, profiling and/or automated decision making, which may lead to excessive collection and amassment of personal data. In view of these findings, the report proposed recommendations for improving privacy practices of the programmes.

The Privacy Commissioner urged operators of customer loyalty and reward programmes to explain to customers frankly about their privacy policies and practices, respect the customers’ right to personal data privacy and provide the customers with control over their own personal data.  He also advised individuals to read the privacy policy carefully to understand the possible use and sharing of their data, and assess the related privacy risks before joining customer loyalty and reward programmes.

(II) Inspection Report: Personal Data System of An Estate Agency in Hong Kong

Noting that the property market continued to boom, and with the vast volume and broad range of personal data (including sensitive data such as name, contact information and Hong Kong Identity Card number) that estate agents have to handle, the Privacy Commissioner considered that it was in the public interest to review the industry’s regime in data privacy protection. An inspection of the personal data system of a leading estate agency (the Agency) was hence carried out, pursuant to section 36 of the Personal Data (Privacy) Ordinance (the Ordinance).

The findings of the inspection report showed that the Agency had made reasonably good efforts generally to ensure proper management of clients’ data, and no material deficiencies were found on the part of the Agency in privacy protection matters. In particular, the Privacy Commissioner was satisfied that the Agency had top management commitment to data privacy protection by designating a senior management officer to oversee and monitor the compliance of the personal data system, setting a role model for the estate agency industry to integrate the idea of data privacy protection into the organisation’s governance. On the technical side, the Privacy Commissioner appreciated that the Agency prudently segmented the authorities and controlled the access rights of their database systems on a need-to-know basis, which minimised the risk of unauthorised access or leakage of clients’ data.

Based on the elements of a comprehensive privacy management programme, the Privacy Commissioner proposed a number of recommendations and good practices on personal data protection, such as a comprehensive privacy policies, compliance audit system, data breach reporting mechanism and guidelines, training and education, etc., to assist the industry in ensuring compliance with the requirements under the Ordinance as well as nurturing the culture of “protect and respect personal data privacy”.

The Privacy Commissioner took the view that personal data protection could not be managed effectively if an organisation treated it merely as a legal compliance issue. Instead, organisations should embrace personal data protection as part of their corporate governance responsibilities and apply them as a business imperative throughout the organisation, starting from the board room. He strongly encouraged estate agencies to develop their own Privacy Management Programme, which would not only effectively manage their customers’ personal data, but also facilitate their compliance with the requirements under the Ordinance, build trust with clients and enhance their reputation as well as goodwill.

The two reports are available at the PCPD’s website, PCPD.org.hk, for public viewing:
1.      2017 Study Report on User Control over Personal Data in Customer Loyalty and Reward Programmes
2.      Inspection Report: Personal Data System of An Estate Agency in Hong Kong

 

Source: Privacy Commissioner for Personal Data, Hong Kong

Related posts:

  • 2013 saw a 48% Increase in Privacy Complaints in Hong Kong
  • HK: Privacy: From Principles to Practice” – Privacy Awareness Week 2018 
  • HK: Promoting “Respect Personal Data” Culture Across Campus
Category: Non-U.S.

Post navigation

← DNA tests a hot holiday item despite privacy concerns
Data transfer from WHATSAPP to FACEBOOK: CNIL publicly serves formal notice for lack of legal basis →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Slovenian officials weaponize data-privacy laws against investigative journalism
  • End-of-Year 2025 State and Federal Developments in Minors’ Privacy
  • Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
  • Oh Great, Smart Glasses That Record Everything You Say
  • CBP Agents Held This U.S. Citizen for Hours Until He Agreed To Let Them Search His Electronic Devices
  • U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
  • ANNOUNCEMENT: EFF Launches Age Verification Hub as Resource Against Misguided Laws

RSS Recent Posts at DataBreaches.net

  • ANNOUNCE: A new resource to help small and mid-sized HIPAA-regulated entities
  • Askul says 740,000 sets of data breached in cyberattack
  • Google and Apple roll out emergency security updates after zero-day attacks
  • Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data
  • Virginia Urology Silent on Possible Data Breach as Purported Patient Data Begins to Leak
©2025 PogoWasRight.org. All rights reserved.