The use and disclosure of personal data for direct marketing purposes is strictly regulated in Hong Kong with more severe consequences for non-compliance than other breaches of Hong Kong privacy law, and is often found to be significantly more onerous than in other jurisdictions. This article summarises some of the key elements of Hong Kong’s direct marketing regime.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
The article provides a brief overview of the legal framework relating to data protection and privacy and discusses the provisions of relevant data protection and data privacy laws in India. It also discusses proposed legislative changes in India to strengthen and improve the existing data protection regime.
In this, the third of a series of articles, Pauline C. Reich examines how Asian countries are approaching the thorny issue of cybercrime and the interception of data. The author takes a look at two Southeast Asian countries in particular, Cambodia and the Philippines.
Are individuals more likely to allow use of their data when it’s ‘for the greater good’ – even if permission is not sought? It may be that they don’t have a choice. Even as data protection measures increase and regulatory bodies increase their ability to punish bad behaviour by data custodians, there are still some thorny issues when it comes to the moral and legal obligations governing the sharing of Big Data and personal information.
Living in the age of Big Data, consumers are slowly awakening half in doubt regarding the ownership of the data which they generated. As more enterprises start utilising user-generated data for so-called target marketing, more consumers begin questioning about unfairness in sharing the profit earned by commercialising that data. This question motivates us to think about the essence of privacy. Is privacy just about the right to be let alone? Or might it include the right to sell the users' own data?
In this, the second of a series of articles, Professor Reich examines the implications of the battle between Apple and the U.S. government for other jurisdictions worldwide.
In the first part we examined whether a balance can be struck between business imperatives and employee privacy. In this second and final part of the article we delve into just how privacy issues have been treated under the law and delve further into the rights and responsibilities of both employer and employee.
In the first part of a three part series of articles, Pauline C. Reich, Professor and Director of the Asia-Pacific Cyberlaw, Cybercrime and Internet Security Research Institute at Waseda University School of Law in Tokyo, Japan gives some context to the recent US v. Apple case.
In part I of an ongoing series of articles Teresa Troester-Falk examined how the evolution of the concept of Accountability as a privacy and data protection principle. In this article, part II she looks at accountability in practice, and how to achieve accountability through structured privacy management.
It's not quite the world of George Orwell's 1984, but employers and employees are still searching for a meeting of minds when it comes to privacy. Can a balance be struck between business imperatives and employee privacy? In part one of a two-part article we examine just how technology is contributing to a steady erosion of employee privacy and how both employer and employee must each bear some of the burden when it comes to privacy issues.










