Cloud computing is widely used by companies and individuals nowadays. Although, there is no universally accepted definition of cloud computing cloud computing generally refers to the delivery of computing services which includes servers, storage, databases, networking, software, analytics, and intelligence over the Internet to offer faster innovation, flexible resources, and economies of scale. Users for cloud service typically pay only for the cloud services selected which enable them to control their operating costs, run infrastructure more efficiently and scale in according with their business particular needs and changes.

 

When processing personal data under cloud service, a data user shall comply with the requirements under Personal Data (Privacy) Ordinance (Chapter 486 of the Laws of Hong Kong) (the “Ordinance”) including the data protection principles (“DPP(s)”) in Schedule 1. According toDPP2(3), DPP3, DPP4 and section 65(2) under Ordinance, it is the duties for the data users to protect and prevent the misuse of personal data entrusted to them by data subjects regardless of whether such personal data is stored within the data users’ premises, or is outsourced to cloud providers.

 

As defined in the Ordinance:-

Data user, in relation to personal data, means a person who, either alone or jointly or in common with other persons, controls the collection, holding, processing or use of the data.

Data processor, in relation to personal data, means a person who:-

(a) processes personal data on behalf of another person; and

(b) does not process the data for any of the person’s own purposes.

For instance, a restaurant obtaining customers’ person data for marketing purpose is regarded as a data use and the mobile network operator engaged by the restaurant to transfer and storage the personal data will be regarded as a data processor in this regard.

 

DPP2(3) states that when a data user engages a data processor, to process personal data on the data user’s behalf (whether within or outside Hong Kong) the data user must adopt contractual or other means to prevent any personal data transferred to the data processor from being kept longer than is necessary for processing of the data.

 

DPP3 provides that personal data should not be used for a new purpose unless prescribed express and voluntary consent is obtained from the data subject or his/her “relevant person” as defined under the Ordinance.

 

DPP4(1) requires a data user to take all reasonably practicable steps to ensure that personal data held by it is protected against unauthorised or accidental access, processing, erasure, loss or use, having regard to:-

(a) the kind of data and the harm that could result if any of those things should occur;

(b) the physical location where the data is stored;

(c) any security measures incorporated (whether by automated means or otherwise) into any equipment in which the data is stored;

(d) any measures taken for ensuring the integrity, prudence and competence of persons having access to the data; and

(e) any measures taken for ensuring the secure transmission of the data.

 

DPP4(2) provides that if a data user engages a data processor (whether within or outside Hong Kong) to process personal data on the data user’s behalf, the data user must adopt contractual or other means to prevent unauthorised or accidental access, processing, erasure, loss or use of the data transferred to the data processor for processing.

 

Furthermore, Section 65(2) of the Ordinance provides that any data breach or misuse of personal data by a data user’s contractor (such as a cloud provider) will be treated as performed by the data user as well as by his contractor. Therefore, a data user will be liable for the acts done by its contractor.

 

For cloud providers that have data centers in multiple jurisdictions, personal data storage by them may flow from one jurisdiction to another to optimizes the use of the cloud providers’ storage and processing resources. Data users should review control-related characteristics of the cloud computing business model with regard to personal data privacy protection in selection of data processors, including:- 1. rapid transborder data flow; 2. loose outsourcing arrangements; 3. terms of standard services and controls and 4. Service and deployment models. .

 

Section 33 of the Ordinance regarding the restriction against the transfer of personal data to places outside Hong Kong has not come into effect. However, if data users located in Hong Kong allow personal data collected by them to be transferred to places outside Hong Kong, they should ensure that such data is treated with a similar level of protection (as if it resides in Hong Kong) in order to meet the expectation of data subjects who entrust their personal data to them. Furthermore, data subjects who entrust personal data to them should be made aware of the transborder arrangement with regard to how their personal data is protected.

 

In summary, data users using cloud services are advised to obtain satisfactory assurance from the cloud providers to address these concerns before they entrust personal data to them.

 

Please feel free to contact us at enquiry@hksunlawyers.com for further enquiries.

CategoryKnowledge