Hong Kong Privacy Code on Human Resource Management

Slides:



Advertisements
Similar presentations
Principles of Recruitment & Selection Efficient Effective Fair.
Advertisements

The Role of the IRB An Institutional Review Board (IRB) is a review committee established to help protect the rights and welfare of human research subjects.
PRIVACY ACT OF 1974 OVERVIEW. FAIR INFORMATION PRACTICES The Privacy Act is primarily concerned with fair information practices. The Privacy Act is primarily.
Procedural Safeguards
HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
Documentation and Maintenance of Records What You Should Know and Why Program Training For Medicaid Providers of Home and Community Care Services Home.
Overview of the Privacy Act
Data Protection Information Management / Jody McKenzie.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
The Data Protection (Jersey) Law 2005.
Sizewise Code of Ethics, Conflict of Interest and Disclosure HR-CECID.
Data Protection.
Department of Navy Labor Standards Training (FAR 22.12) Nondisplacement of Qualified Workers under Service Contracts Patricia Myers Contract Industrial.
INDIANA UNIVERSITY OFFICE OF THE VICE PRESIDENT AND GENERAL COUNSEL Indiana Access to Public Records Act (APRA) Training.
Presentation by Mark Grady Vancouver Island University June 13, 2012.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
The role of the Office of the Privacy Commissioner in telecommunications Andrew Solomon Director, Policy.
Legal Ethics for Social Services Attorneys Institute of Government 2006.
SEMINAR NAIC/ASSAL/SVS REGULATION & SUPERVISION OF MARKET CONDUCT © 2014 National Association of Insurance Commissioners Complaint Handling.
Data Protection Recruitment Process
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
1 University Privacy Campaign Introduction to the Personal Data (Privacy) Ordinance.
Data Protection Overview
Protecting information rights –­ advancing information policy Privacy law reform for APP entities (organisations)
\presentation4 PRE-EMPLOYMENT SCREENING Christine Jenner Partner, DAC Beachcroft LLP.
1 Introduction to the Personal Data (Privacy) Ordinance.
Overview of Engagement – Under the terms of this engagement, the Advisor will provide advice in the areas checked below. Investment Management – Develop.
HIPAA PRIVACY AND SECURITY AWARENESS.
Data Protection and You Your Rights & The Law Registration Basics Other Activities Disclaimer: This presentation only provides an introductory info. Please.
DATA PROTECTION OFFICE {PMO} “OVERVIEW OF THE FUNDAMENTAL ASPECTS OF THE RIGHT OF ACCESS“ Presented by The Commissioner Mrs D. Madhub To Mutual Aid Association.
1 Office of the Privacy Commissioner for Personal Data Hong Kong SAR Tony LAM Deputy Privacy Commissioner for Personal Data Asian Personal Data Privacy.
“What’s Ethics Got To Do With It” Presentation to the Canberra Evaluation Forum Gary Kent Head Governance Australian Institute of Health and Welfare.
Investigating Rights and Responsibilities at work
ALARM SOUTH EAST Employment Seminar AGE DISCRIMINATION DAVID KNAPP JAMES MAJOR.
Privacy and the Civil Commitment Process Allyson K. Tysinger Assistant Attorney General June 4-5, 2008.
Data Protection Act AS Module Heathcote Ch. 12.
Medical Law and Ethics, Third Edition Bonnie F. Fremgen Copyright ©2009 by Pearson Education, Inc. Upper Saddle River, New Jersey All rights reserved.
Family Educational Rights and Privacy Act (FERPA) UNION COLLEGE.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
Session Title: FERPA: What You Need To Know Presented By: Jeffery Loggins Institution: Mississippi Valley State University September 15, 2015.
UMBC POLICY ON ESH MANAGEMENT & ENFORCEMENT UMBC Policy #VI
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
Data Protection Guidance for Principals and Deputy Principals Anne Lyne Partner & Breda O’Malley Partner Kilkenny - 3 October 2015.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
1 Office of the Privacy Commissioner for Personal Data Hong Kong SAR Tony LAM Deputy Privacy Commissioner for Personal Data Briefing to Asian Data Privacy.
Data Protection - Rights & Responsibilities Information Commissioner’s Office Orkney Practice Forum 4 th July 2007.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
HIPAA Privacy Rule Implementation Status Report Richard M. Campanelli, J.D. Director, Office for Civil Rights Before the The Tenth National HIPAA Summit.
TOP 10 DHS IT SECURITY & PRIVACY BEST PRACTICES #10 Contact The Office of Systems & Technology for appropriate ways to proceed if you need access to.
© University of Reading Lee Shailer 06 June 2016 Data Protection the basics.
Can you share? Yes you can!! Angus Council Adult Protection Maureen H Falconer, Senior Policy Officer Information Commissioner’s Office.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
Disclaimer This presentation is intended only for use by Tulane University faculty, staff, and students. No copy or use of this presentation should occur.
Data Protection Laws in the European Union John Armstrong CMS Cameron McKenna.
HIPAA Training Workshop #3 Individual Rights Kaye L. Rankin Rankin Healthcare Consultants, Inc.
The Data Protection Act 1998
HIPAA CONFIDENTIALITY
APP entities (organisations)
The Data Protection Act 1998
Data Protection Legislation
Privacy & Access to Information
Disability Services Agencies Briefing On HIPAA
Presentation transcript:

Hong Kong Privacy Code on Human Resource Management Tony LAM Deputy Privacy Commissioner for Personal Data Hong Kong SAR Asian Data Privacy Forum March 27 2000 Privacy Commissioner’s Office, Hong Kong SAR

Employment-related Complaints Out of 2,015 complaints received by PCO up to 28 February 2001, 226 cases (11%) related to alleged practices of employers that may be in breach of the Personal Data (Privacy) Ordinance 75 cases were found substantiated. Of these, 25 cases (33%) relate to the employer’s failure to comply with data access requests made by staff Three enforcement notices and 37 warning notices were issued as a result of investigation

Coverage of the Code Provide practical guidance to employers and human resource practitioners on the application of the Personal Data (Privacy) Ordinance relating to employment-related personal data Apply to employers in their management of personal data in three stages of the employment process: Recruitment, Current employment and Former employees’ matters

Effective Date of the Code Approved by the Privacy Commissioner and was notified in the Gazette of the Hong Kong SAR Government on 22 September 2000 Requirements of the Code to take effect on 1st April 2001 Non-compliance with the Code will give rise to a presumption against the employer in any proceedings involving an alleged breach of the Ordinance

Key Compliance Requirements - Recruitment - Current Employment - Former Employees’ Matters

Recruitment Advertisement Should not use a “blind” advertisement, e.g. that gives only a PO Box number, to solicit personal data directly from job applicants Alternatives Request applicants to write to the PO Box to obtain an application form that bears the employer’s identity Use a recruitment agency identified in the recruitment advertisement to receive resumes of job applicants

Examples of “blind” Advertisement Company Assistant - Form 5 or above - Knowledge of company secretarial duties Please send resume to PO Box 100 Company Assistant - Form 5 or above - Knowledge of company secretarial duties Interested parties please contact Miss Chan on 2808-xxxx Submission of personal data by job applicants No identity of the employer provided No notification of purpose of use of the data Job applicants are denied of data access rights No submission of personal data by job applicants Contact person provided from whom applicants: - may seek to identify the employer - may seek information about purpose statement

Notification in Recruitment Advertisements Recruitment advertisements that directly ask job applicants to provide their personal data should include a Personal Information Collection Statement (“PICS”) Alternatives Invite job applicants to respond by filling in the employer’s job application form that prescribed the PICS notification Give a contact person from whom applicants may obtain a copy of the PICS

Other Requirements during Recruitment Should not collect a copy of the applicant’s identity card unless and until the individual has accepted an offer of employment Should limit original job application to data relevant for identifying suitable candidates, e.g. work experience, competencies, job skills, academic/professional qualifications, and other relevant attributes May collect supplementary information about potential candidates that are relevant to the nature of the job, e.g. to establish security credentials or integrity

Other Requirements during Recruitment May collect the health condition of a selected candidate by means of a pre-employment medical examination if the data directly relate to the inherent requirements of the job the employment is conditional upon the fulfillment of the medical examination Must obtain an applicant’s consent before seeking references from his/her current or former employers or other sources May retain personal data of unsuccessful applicants for a period of up to two years

Current Employment Should provide employees with a Personal Information Collection Statement (“PICS”) pertaining to employment e.g. at the earliest opportunity when the employee accepts the offer of employment Should not issue staff card that bears the employees’ ID card number and name together

Current Employment Employees and their family members for purposes directly related to the employment, e.g. claim of compensation or benefits, declaration of conflict of interest, health condition for assessment of continuance in employment to fulfil lawful requirements that regulate the affairs of the employer Disciplinary proceedings, performance appraisal or promotion planning for purposes directly related to the process concerned should not be disclosed to a third party unless the third party has legitimate reasons for gaining access to the data

Current Employment Should not disclose employment-related data of an employee to a third party unless the employee has consented the disclosure is directly related to the employment required by law or by statutory authorities there is an applicable exemption under the PD(P)O Where disclosure to a third party is permitted avoid disclosure of data in excess of that necessary for the purpose of use by the third party implement measures to ensure the third party protects the data

Former Employees’ Matters Relevant personal data of a former employee may be retained for a period of up to seven years from the date the employee ceases employment unless deletion of the data is prohibited by law there are contractual or legal obligations on the part of the employer, e.g ongoing litigation, administration of retirement plan it is in the public interest for the data not to be deleted the employee has given consent for the data to be retained beyond seven years

Former Employees’ Matters In any termination notice about a former employee having left employment, an employer should not disclose the identity card number of the employee should include only the minimum information required to identify the employee concerned Before providing a reference concerning a former employee to a third party, an employer should obtain the prior consent of the employee; or satisfy itself that the third party requesting the reference has obtained the consent of the employee

Employer’s Liability Should take all practicable steps to ensure staff handling employment-related data are well trained, have the appropriate qualities of integrity, prudence and competence adequate security measures are implemented so that all personal data are collected, processed and stored securely its Privacy Policy Statement concerning personal data management practices can be made available to all staff Must comply with a data access/correction requests within 40 days upon receipt of the request provide the requestor reasons of refusal within 40 days

Employer’s Liability An employer is liable in civil proceedings for any act or practice relating to personal data that is undertaken by its employees in the course of their employment that is contrary to the provisions of the PD(P)O, even if the employees undertook the act or engaged in the practice without the employer’s knowledge or approval An employer is liable in civil proceedings for any wrongful acts or practices done by a third party where the third party is engaged as an agent acting with authority