ENFORCEMENT OF PDPO Flashcards

1
Q

What is the role of the Office of the Privacy Commissioner for Personal Data (PCPD)?

A

The PCPD enforces and oversees compliance with the PDPO - including conducting investigations - providing guidance - and raising public awareness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the key roles of the PCPD?

A

Investigation - guidance - and public education.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What types of rules does the Privacy Commissioner issue?

A

Codes of Practice and Administrative Instructions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What was the outcome of the Octopus Rewards Ltd. case?

A

Octopus Rewards Ltd. was required to cease unauthorized data transfer and improve data protection measures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The Octopus Rewards case was a breach of which data protection principles under the PDPO?

A

Data collection and data use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the role of the Personal Data (Privacy) Advisory Committee?

A

Advises the Privacy Commissioner on policy development and public consultation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How must organizations manage consent and opt-out mechanisms?

A

Consent mechanisms must be clear - accessible - and easy to use. Fresh consent is needed for new purposes - and accurate records of consents and withdrawals must be kept.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is an enforcement notice?

A

An enforcement notice is issued by the Privacy Commissioner to a data user who has contravened the PDPO - requiring rectification and preventive measures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the PCPD do in terms of policy development and implementation?

A

Issues new guidelines - provides training - and proposes law reforms to enhance data protection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the Third-Party Benefit Exception?

A

A proposal to review and possibly amend the law to regulate data sharing for third-party benefits more strictly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are recent trends in commissioner expectations?

A

Emphasis on proactive data protection measures - higher levels of transparency - and accountability of senior management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the consequences of breaching an enforcement notice in HK?

A

Fine of HK$50 -000 on first conviction and HK$100 -000 on subsequent conviction and imprisonment for two years.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the penalties for direct marketing contraventions in HK?

A

If the data user provided data for gain: fine of up to HK$1 million and imprisonment for up to five years. If otherwise than for gain: fine of up to HK$500 -000 and imprisonment for up to three years. If it fails to stop using data for direct marketing: punishable for a fine of up to HK$500 -000 and imprisonment for up to three years.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What can a HK complainant appeal to AAB?

A

A complainant may appeal to the Administrative Appeals Board (AAB) against a decision of the Privacy Commissioner not to issue an enforcement notice following an investigation into a complaint.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the two HK consultative advisory committees?

A

Personal Data (Privacy) Advisory Committee and the Standing Committee on Technological Developments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the penalties for breaching the PDPO?

A

Fines of HK$500 -000 to HK$1 million and 3-5 years in jail.

17
Q

What is the significance of the Do No Evil Mobile App case in HK?

A

The issue was aggregating data from publicly available sources. The Commissioner ruled that using personal data obtained from the public domain for due diligence review and background check was inconsistent with the original purpose of data collection by the Judiciary - ORO - and Companies Registry.

18
Q

Can a complainant appeal the decision of the AAB in HK?

A

There is no appeal against the decision to court - but aggrieved parties can seek judicial review of the AAB decision.