What is the Personal Data Protection Policy (PDPO)?
A statutory body in Hong Kong whose mission is to promote and enforce adherence to the Personal Data Protection Policy (PDPO). It is modeled after international data protection laws and the European Union’s General Data Protection Regulation (GDPR). The PCPD works closely with privacy authorities around the world to ensure that Hong Kong’s data processing activities are consistent with global best practices.
The PDPO mandates six Data Protection Principles that must be followed by all data users in the Hong Kong SAR, including those located outside the territory. These principles include purpose and consent, the safeguarding of personal information, transparency and accountability, lawfulness, fairness and security. They also stipulate that personal data must not be collected for purposes unrelated to the original purpose, and that individuals’ rights to erasure and portability are guaranteed.
One of the most critical aspects of PDPO is its requirement that businesses conduct an impact assessment prior to transfering personal data abroad. This assessment must include a thorough review of the target jurisdiction’s legal environment and laws, national security considerations, and the privacy rights of individuals. It should also include an evaluation of the proposed data flow. The impact assessment is intended to ensure that any potential negative impacts on data protection are mitigated.
Another important aspect of PDPO is its provisions regarding data breaches. It requires data users to report any breaches of personal information to the PCPD and affected individuals. This obligation serves to underscore the importance of ethical data handling practices and strengthens accountability within organizations. It is also intended to discourage data abuse and bolster privacy awareness among employees and customers.
Similarly, the PDPO imposes strict limits on the sharing of an individual’s personal information. For example, a staff member’s name and HKID number should not be displayed together in public or made available to anyone other than those who need it for their work. This protects an employee’s privacy and helps them avoid the risk of being a victim of identity theft or fraud.
A successful data governance program involves a diverse group of people from various functions and levels of the organization. Often, this group includes business stewards who act as liaisons between business and IT. These people are responsible for translating data governance decisions into business processes and actions. They should have a solid grasp of IT and an excellent understanding of the business. An experienced project manager is a good choice for this role, as they can manage the schedules and resources needed to achieve success.