HKUST Business School Magazine

Biz@HKUST Biz@HKUST 8 9 // Cover // Thought Leader Personal Data Privacy Matters The Office of the Privacy Commissioner for Personal Data aims to inspire citizens to be more careful about how they use their personal data online. But this involves challenges, says the Privacy Commissioner Ada CHUNG. When it comes to developing a culture of privacy, protection and respect for personal data, Ada Chung, the Privacy Commissioner for Personal Data (Privacy Commissioner) in Hong Kong, has a massive job on her hands. As an independent watchdog, the Office of the Privacy Commissioner for Personal Data (PCPD) is designed to monitor, supervise, promote and enforce compliance in relation to the Personal Data (Privacy) Ordinance (PDPO), which came into effect in 1996. Aside from supervising and enforcing protection of personal data privacy, the PCPD provides guidance, public education and best practice notes on the lawful and responsible use of personal data. In today’s digital world, this is no easy task. The rise of technology and the growing use of social media and apps are driving a proliferation of data, and online activities have increased dramatically, especially during the pandemic. Consequently, the PCPD has its hands full putting out fires while trying its best to educate the public and businesses about respecting and safeguarding personal data. According to the results of a survey released by the PCPD in January 2021, over 85 per cent of Hong Kong citizens are active users of social media, and share personal information online, Chung says. This information often includes their date of birth, residential address, and health information. Ominously, most online users are unaware that they are sharing these details. “This is dangerous,” Chung says. “If personal data is leaked, it can be misused, and that can lead to the perpetration of crimes or fraud. In Hong Kong, in the past two years, doxxing has become rampant, which has caused serious and long-lasting effects on its victims.” Doxxing is the act of disclosing the personal data of a data subject without the relevant consent of the data subject, and the discloser is being reckless or has an intent to cause harm to the data subject or any family member of the data subject. There has been a notable rise in doxxing in Hong Kong in recent years. The privacy watchdog noted that over 5,800 doxxing cases were handled between June 2019 and June 2021. Data breaches are also becoming more frequent worldwide. The number of high-profile data breaches which have affected a huge number of individuals has been increasing. One recent example occurred in April 2021, when networking data associated with 500 million LinkedIn users was posted on a forum on the Dark Web. Hong Kong citizens were certainly among those affected. “In the past few years, the scale of this has been unprecedented,” Chung says, noting that things may get worse. Fundamental Human Rights For this reason, the PCPD plays an increasingly important role when it comes to protection of personal data privacy. Hong Kong recently made amendments to its privacy laws which gave significant powers to the Privacy Commissioner to remove doxxing messages. This legislation also carries extra-territorial powers, so the Privacy Commissioner can serve cessation notice to internet service providers having a place of business in Hong Kong, or operators of overseas social media platforms which are outside of Hong Kong, to take down any information that is deemed to be doxxing, within a designated timeframe. “Privacy is a fundamental human right. Protection of personal data is indispensable in protecting individuals’ privacy,” Chung says. “Protection of personal data is particularly important in a digital era where anyone’s personal data can be widely shared in a split second.” Given the boundless nature of the internet, and the global increase in digitalization, the PCPD will not be able to achieve its mission alone. Chung says that everyone must play a part to protect personal data privacy. This is the key message that the PCPD has been promoting to the public. Chung emphasizes that the development of mobile applications and data-driven technology mean that businesses and individuals who are data users have an equal responsibility to meet the legal requirements that are set out in the PDPO. They are required to comply with the six Data Protection Principles when collecting, holding, processing and using personal data, Chung says. Part of the PCPD’s job is to ensure that everyone is familiar with the PDPO and knows how to apply them. That includes Ada Chung Privacy Commissioner for Personal Data

RkJQdWJsaXNoZXIy MzUzMDg=