Privacy Policy Statement
1. Our Policy
We respect personal data privacy and it is our policy to commit to fully implementing and complying with the data protection principles and all relevant provisions of the Personal Data (Privacy) Ordinance (“PDPO”). We strive to ensure that our staff members comply with the policies and practices set out in this Statement and maintain appropriate standards of security and confidentiality in meeting such commitment.
2. Our Practices
2.1 Business Counterparts Records
A. Types of Personal Data:
We collect or obtain, and hold, the personal data of persons who serve as officers, agents or representatives of CMU Members, government or regulatory bodies, potential and actual vendors/ suppliers, subscribers to newsletters, email alerts or other communications, and potential and actual business counterparts (collectively “Business Contacts”). Such personal data may include but is not limited to identification information, contact details, and information as regards Business Contacts’ official capacity and employment status.
B. Uses of the Personal Data:
We use Business Contacts’ personal data mainly for the following purposes:
(a) managing our business and regulatory relationships;
(b) communicating on business, administrative, logistical and/or promotional arrangements in relation to our services and/or any function and activity related thereto;
(c) handling CMU Membership related matters;
(d) procurement and supply of goods or services;
(e) sending newsletters and other communications;
(f) handling any feedback, requests, claims, enquiries or complaints;
(g) statistical analysis;
(h) service monitoring;
(i) compliance with any disclosure, reporting, filing or notification or other similar obligation pursuant to any judicial, statutory or regulatory requirement including compliance with applicable laws, regulations and guidelines; and
(j) any other incidental or associated purposes relating to any of the above purposes.
Such personal data held by us will be kept confidential but we may disclose or transfer such information to the following parties for the purposes set out above:
(a) any professional services providers / consultants and other service providers; and
(b) any court, tribunal or administrative, governmental or regulatory body in relation to the purposes set out in 2.1B(i) above.
2.2 Personnel Records
We collect or obtain, and hold, the personal data of persons who are (i) job applicants; (ii) employees and secondees; (iii) directors and advisors; (iv) hired or engaged to provide services to us under other contract or form of arrangement; (v) prospective staff; (vi) family members of staff; and (vii) emergency contacts of staff. Such personal data include but is not limited to name, HKID number/copy, date of birth, marital status, contact details, health or medical records, CV, employment and compensation data, educational and professional qualifications, training records, bank accounts, appraisal information and references as well as relationship with our staff.
B. Uses of the Personal Data:
We use personal data in personnel records mainly for the following purposes:
(b) finance operations e.g. verification for initial payee account set up or update in finance platform, and expenses reimbursement etc;
(c) compliance with any disclosure, reporting, filing or notification or other similar obligation pursuant to any judicial, statutory or regulatory requirement, as well as any internal policies, rules and guidelines; and
(d) any other incidental or associated purposes relating to any of the above purposes.
C. Disclosure of Personal Data:
Such personal data held by us will be kept confidential but we may disclose or transfer such information to the following parties for the purposes above:
(b) any organisation where a secondment agreement is in place with the Company;
(c) any bank or financial institution in relation to compensation and benefits arrangements;
(d) any professional services providers / consultants and other service providers;
(e) any court, tribunal, administrative, governmental or regulatory body or law enforcement agency in relation to the purposes set out in 2.2B(c) above; and
(f) any person with the data subject’s consent (including any potential future employer).
2.3 Retail Bond Applicants Records
A. Types of Personal Data:
In relation to new issuances of retail bonds lodged with the CMU, issuers / CMU Members which are placing institutions etc. may transfer to the Company personal data of retail bond applicants. Such personal data may include name and HKID.
B. Uses of the Personal Data:
We use the personal data of retail bond applicants for the following purposes:
(b) verifying the validity of the application;
(c) enabling compliance with all applicable laws, rules and regulations, codes and practices binding on or applicable to the Company in connection with the retail bond issuance, or an order of a court of any competent jurisdiction (including making required disclosures); and
(d) any other incidental or associated purposes relating to any of the above purposes.
C. Disclosure of Personal Data:
Such personal data held by us will not be disclosed or transferred to other parties.
3. Information Collected When You Visit Our Website
Save as provided for in Section 2 above, when you visit our website, we record your visit only as a "hit", which may show your Internet Protocol (IP) address and the pages you have visited. We do not collect any personally identifiable information under this circumstance. The information is used for the purposes of compiling statistical records, and for maintaining and improving our website.
When you browse our website, you should be aware that cookies are used. Cookies are data files stored on your computer's hard drive. Our website automatically installs and uses cookies on your browser when you access it. The types of cookies used on our website are session cookies and persistent cookies. The purpose of using cookies is to help us improve website performance and user's experience.
The cookies used in connection with our website do not collect or store personally identifiable information. You may refuse to accept cookies on your browser by modifying the settings in your browser or internet security software. However, if you do so, you may not be able to utilise or activate certain functions available on our website.
4. Outsourcing Arrangements
Our internal information technology (IT) systems and websites are developed and maintained by our staff and other service provider(s). The service provider(s) does/do not have access to personal data stored in our IT systems and websites except when carrying out maintenance/ checking/trouble shooting supervised by our staff.
Where we engage an external party to handle or process information, we use contractual or other reasonably practicable steps to prevent unauthorised or accidental access, processing, erasure, loss or use of any personal data and, where applicable, require such data processor not to keep the relevant data longer than is necessary for processing of the data.
5. Protection Measures
We take appropriate steps to protect personal data we hold against unauthorised or accidental access, processing, erasure, loss or use (which includes disclosure or transfer).
6. Retention
Different retention periods apply to the various kinds of personal data collected and held by us. We take all reasonably practicable steps to ensure that personal data will not be kept longer than is necessary for the fulfilment of the purposes (or any directly related purpose) for which the data is or is to be used, unless the retention is otherwise permitted or required by law.
7. Data Access, Data Correction and Enquiries
You have the right to request access to and correction of your personal data held by us in accordance with the provisions of the PDPO. All requests should be made using the Data Access Request Form specified by the Privacy Commissioner for Personal Data.
When handling a data access or correction request, we will check the identity of the requestor to ensure that he/she is the person legally entitled to make the data access or correction request.
We may charge a fee which is not excessive for processing any data access request, to the extent permitted pursuant to applicable laws or regulations.
Any enquiries regarding personal data, or requests for access to or correction of personal data, can be made to the Data Privacy Officer of the Company by post or email.
Address: CMU OmniClear Limited, 89th Floor, International Commerce Centre, 1 Austin Road West, West Kowloon, Hong Kong
Email: cmuwebmaster@hkma.gov.hk
Personal Information Collection Statement