Data hk is information that has been compiled, stored and processed in order to produce output. It can be numbers or text or a combination of both. It is normally gathered for reference and analysis, whether to support decision-making or to provide information to the public. It may be as simple as counting product sales or taking an electricity meter reading, or as complex as analysing the profitability of particular services or businesses.

Increasingly, data is being used as a tool to drive business value. This has led to a greater focus on the management and security of data. This has been aided by the advent of cloud computing, which provides a cost-effective way to store and manage data securely. The PCPD has published guidance on this topic, including recommended model clauses that can be incorporated into contracts for data transfer arrangements. The clauses are designed to address two scenarios: (1) the transfer of personal data from a Hong Kong entity to an entity outside Hong Kong; and (2) the transfer of personal data between entities both of which are outside Hong Kong when the transfers are controlled by a Hong Kong data user.

The PCPD has also developed a set of principles and guidelines on the use of data analytics, which can help organisations to identify and respond to data risks. The Principles and Guidelines set out the minimum standards that organisations should comply with to minimise their data risks. They can be accessed on the PCPD’s website.

A key challenge to data privacy is the need to transfer data across businesses in order to operate effectively. This is especially important where business processes involve the processing of personal data. In this article, Padraig Walsh from the Data Privacy practice group of Tanner De Witt discusses the application of the data transfer provisions in Hong Kong’s PDPO to such business transfers.

The data transfer provisions in Hong Kong’s DPPO have been met with some resistance from the business community. This is mainly due to concerns about the perceived impact on business operations and difficulties in complying with the requirements of the provision. However, it looks increasingly likely that the provision will be brought into operation in the future, particularly given increased cross-border data flow and the development of the Mainland under the “one country, two systems” principle. To facilitate efficient compliance, it is therefore necessary for businesses to understand how to implement the provisions of DPPO section 33. This can be done by understanding the interpretation of the key data privacy concepts in Hong Kong and the use of contracts to protect personal data in data transfers in these circumstances.

