| PROTECTION OF PRIVACY | |
| PERSONAL INFORMATION COLLECTION STATEMENT | |
| PROTECTION OF CONFIDENTIALITY STATEMENT | |
|
PROTECTION OF PRIVACY 1. INTRODUCTION Protection of privacy of the individuals' personal data is governed by the Personal Data (Privacy) Ordinance (Cap.486) (the "Ordinance"). Digi-Sign Certification Services Limited ("Digi-Sign") is a data user in terms of the provisions of the Ordinance. Digi-Sign is committed to complying with the Ordinance, and to upholding the data protection principles. Digi-Sign's mission is to service its customers, business partners, Government of the Hong Kong Special Administrative Region and the business community, contributing to their endeavours and success. 2. PRIVACY POLICY Digi-Sign adopts a framework for protecting the privacy of individuals' personal data. This framework addresses the requirements of the Ordinance, and provides Digi-Sign personnel with clear and practical guidelines in their role of ensuring the confidentiality, security, proper use and handling of personal data. 3. STATEMENT OF PRACTICES For the purpose of processing subscriber applications for ID-Cert (the product name of the electronic certificate issued by Digi-Sign), Digi-Sign requires the applicant to provide details, some of which are personal identity information for disclosure in the ID-Cert. The personal identity information that an applicant is called upon to provide includes the following: - Family
name and other name(s) Digi-Sign will not be in a position to complete the processing of a subscriber application, if the personal identity information is incomplete. Once a subscriber application is received, Digi-Sign will retain in a secure manner the information in a subscriber database. In accordance with its commitment, Digi-Sign will observe the data protection principles of the Ordinance when using and handling the subscriber information. Use of such information will encompass, among others, communication with the ID-Cert holders for the purpose of: - Dissemination
of updates and responses;
The key points relating to the Digi-Sign's privacy practices are outlined below: Collection of Personal Identification Information
Collection of Information from Individuals On-line
Retention
of Personal Information
Disclosure of
Personal Information
Accuracy
of Personal Information
4. SECURITY OF PERSONAL INFORMATION Protection of the subscribers' personal information is a priority for Digi-Sign. Every reasonable and practical step will be taken to protect the security and confidentiality of the personal information. In particular, there are security measures in place to safeguard against loss, misuse and unauthorized access or alteration. Subscriber information is protected in accordance with the Digi-Sign information security policy, guidelines and practices. 5. DIRECT MARKETING Digi-Sign has ongoing programs, including working in conjunction with its business partners, to inform subscribers of the product and service offers and bulletins. For any subscriber who wishes to opt-out of these programs, please send a request in writing and address it to the Chief Executive Officer, who is the Personal Data Administrator, using the contact details in section 6. 6. CONTACT DETAILS For further details about this Privacy Policy, access or correction of personal information, please contact the Chief Executive Officer, who is the Personal Data Administrator, contact details are as follows: Digi-Sign
Certification Services Limited Digi-Sign reserves its right to ask that a request to access or correct personal information be in writing. Digi-Sign may charge reasonable fee to cover the relevant administrative expenses. But there will be no charge to correct information. It is Digi-Sign's service pledge that all requests will be dealt with promptly. If there is any complaint or objection to the handling of a request, please contact the Chief Executive Officer, who is the Personal Data Administrator. 7. NOTIFICATION OF CHANGES As part of its ongoing improvement program, Digi-Sign keeps its policies, guidelines and practices, including this Privacy Policy, under review. As and when change is necessary, Digi-Sign will display a revised version on its Website and, where appropriate, will also include the necessary details in the correspondence addressed to all subscribers. 8. NOTICE TO ALL SUBSCRIBERS Whilst
Digi-Sign undertakes due care and skill, and implements necessary security
measures in the protection of personal information, Digi-Sign is committed
only to reasonable care and skill, and commercially viable security measures.
|
|
|
PERSONAL INFORMATION COLLECTION STATEMENT PURPOSE STATEMENT: Digi-Sign Certification Services Limited ("Digi-Sign") is committed to using the personal information collected from subscribers and other parties for legitimate and lawful purpose. This use will be in connection with processing the subscriber applications and management of the subscriber database. Digi-Sign will collect information by lawful and fair means. STATEMENT OF POSSIBLE TRANSFERS Personal
information will remain within Digi-Sign. There will be no disclosure
or transfer of personal information to another party, in a form that would
identify an individual person, unless such disclosure is done with prior
consent of the person from whom the information was originally collected. Digi-Sign acknowledges that the person from whom the information was collected has right of access to the information held by Digi-Sign, and also the right to request correction of the personal information. Individuals who have provided personal information to Digi-Sign may request in writing to access or correct their personal information kept by Digi-Sign. Please
refer to the Digi-Sign Privacy Policy and in particular, the Statement
of Practices, regarding request to access or correct personal information.
|
|
|
PROTECTION OF CONFIDENTIALITY STATEMENT PURPOSE STATEMENT: Digi-Sign Certification Services Limited ("Digi-Sign") recognizes the responsibility to safeguard the information and data entrusted to it by subscribers and others. Digi-Sign is committed to complying with the relevant legislative provisions and in particular, the Personal Data (Privacy) Ordinance (Cap.486), and section 46 of the Electronic Transactions Ordinance (Cap.553). Digi-Sign acknowledges that all its personnel, including employees, contractors and agents, will undertake to honour their commitment and duty regarding protection of confidentiality. CONFIDENTIAL INFORMATION For the purpose of this Protection of Confidentiality Statement, the term "confidential information" includes: - Information
collected for processing subscriber applications, encompassing, among
others, the following: - Information
contained in or related to an ID-Cert, encompassing, among others, the
following: No document, record or information kept by Digi-Sign will be released to law enforcement agencies, or Government officials, except where the release is in accordance with the law, a subpoena or a court order. DISCLOSURE REQUEST The data subject, as defined in the Personal Data (Privacy) Ordinance, has right of access to the information kept by Digi-Sign for subscribers only when: - A
formal authorization is provided to Digi-Sign, and this may be done electronically
and signed by a valid digital signature, or For further information, please contact the Chief Executive Officer, who is the Personal Data Administrator, using the contact details in section 6 of the Digi-Sign Privacy Policy. INFORMATION NOT CLASSIFIED AS CONFIDENTIAL For the purpose of this Protection of Confidentiality Statement, the terms "confidential information" will exclude: - ID-Cert
information published in the ID-Cert directory, encompassing, among others,
the following: - Information
published by Digi-Sign, encompassing, among others, the following: |
|