๐ ๐ณ ๐๐ฒ๐ ๐๐ฎ๐๐ฎ ๐ฃ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป ๐ฃ๐ฟ๐ถ๐ป๐ฐ๐ถ๐ฝ๐น๐ฒ๐ ๐ณ๐ผ๐ฟ ๐ฃ๐ฟ๐ผ๐๐ฒ๐ฐ๐๐ถ๐ป๐ด ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐
The EU General Data Protection Regulation (GDPR) came into force on ๐ฎ๐ฑ ๐ ๐ฎ๐ ๐ฎ๐ฌ๐ญ๐ด, which is the one of the world's strictest privacy laws. It aims to standardize data protection rules across the digital single market, enhance individual control over personal information, and adapt governance due to the technological developments and digitalization.
The GDPR introduces 7 key data protection principles to ensure organizations handle data legally, securely, and with full transparency and responsibility:
โจ๐๐ฎ๐๐ณ๐๐น๐ป๐ฒ๐๐, ๐๐ฎ๐ถ๐ฟ๐ป๐ฒ๐๐, ๐ง๐ฟ๐ฎ๐ป๐๐ฝ๐ฎ๐ฟ๐ฒ๐ป๐ฐ๐: Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.
โจ๐ฃ๐๐ฟ๐ฝ๐ผ๐๐ฒ ๐๐ถ๐บ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป: Personal data can only be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
โจ๐๐ฎ๐๐ฎ ๐ ๐ถ๐ป๐ถ๐บ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป: Processing should be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
โจ๐๐ฐ๐ฐ๐๐ฟ๐ฎ๐ฐ๐: Personal data must be accurate and, where necessary, kept up to date with reasonable steps taken to erase or rectify inaccuracies.
โจ๐ฆ๐๐ผ๐ฟ๐ฎ๐ด๐ฒ ๐๐ถ๐บ๐ถ๐๐ฎ๐๐ถ๐ผ๐ป: Personal data should be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
โจ๐๐ป๐๐ฒ๐ด๐ฟ๐ถ๐๐ ๐ฎ๐ป๐ฑ ๐๐ผ๐ป๐ณ๐ถ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น๐ถ๐๐: Personal data must be processed in a manner that ensures security of the personal data using appropriate technical or organisational measures.
โจ๐๐ฐ๐ฐ๐ผ๐๐ป๐๐ฎ๐ฏ๐ถ๐น๐ถ๐๐: The controller shall be responsible for, and be able to demonstrate compliance with the principles.
The GDPR extends its reach beyond the EU by explicitly requiring compliance from organizations established outside the EU in certain situations. Given the variety of business and transaction models, it is essential for the businesses in Hong Kong to assess whether the GDPR applies to them and to stay informed about ongoing regulatory developments.
๐ก ๐ฃ๐ฟ๐ถ๐๐ฎ๐ฐ๐ ๐ฐ๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ ๐ถ๐ ๐ป๐ผ ๐น๐ผ๐ป๐ด๐ฒ๐ฟ ๐ผ๐ฝ๐๐ถ๐ผ๐ป๐ฎ๐น โ ๐ถ๐โ๐ ๐ฎ ๐ฏ๐๐๐ถ๐ป๐ฒ๐๐ ๐ถ๐บ๐ฝ๐ฒ๐ฟ๐ฎ๐๐ถ๐๐ฒ.