HKLII Hong Kong Ordinances

[Index] [Table] [Search] [Notes] [Noteup] [Previous] [Next] [Download (Current & Past)] [Download (Current only)] [繁體中文] [Help]

PERSONAL DATA (PRIVACY) ORDINANCE - SECT 20

Circumstances in which data user shall or may refuse to comply with data access request

(1) A data user shall refuse to comply with a data access request-

   (a)  if the data user is not supplied with such information as the
        data user may reasonably require-

        (i)    in order to satisfy the data user as to the identity of the
               requestor;

        (ii)   where the requestor purports to be a relevant person, in order
               to satisfy the data user- (A) as to the identity of the
               individual in relation to whom the requestor purports to be
               such a person; and (B) that the requestor is such a person in
               relation to that individual;

   (b)  subject to subsection (2), if the data user cannot comply with the
        request without disclosing personal data of which any other individual
        is the data subject unless the data user is satisfied that the other
        individual has consented to the disclosure of the data to the
        requestor; or

   (c)  in any other case, if compliance with the request is for the time
        being prohibited under this Ordinance.

(2) Subsection (1)(b) shall not operate-

   (a)  so that the reference in that subsection to personal data of which any
        other individual is the data subject includes a reference to
        information identifying that individual as the source of the
        personal data to which the data access request concerned relates
        unless that information names or otherwise explicitly identifies that
        individual;

   (b)  so as to excuse a data user from complying with the data access 
        request concerned to the extent that the request may be complied with
        without disclosing the identity of the other individual, whether by
        the omission of names, or other identifying particulars, or otherwise.

(3) A data user may refuse to comply with a data access request if-

   (a)  the request is not in writing in the Chinese or English language;

   (b)  the data user is not supplied with such information as the data  user
        may reasonably require to locate the personal data to which the
        request relates;

   (c)  the request follows 2 or more similar requests made by-

        (i)    the individual who is the data subject in respect of the
               personal data to which the request relates;

        (ii)   one or more relevant persons on behalf of that individual; or

        (iii)  any combination of that individual and those relevant persons,
               and it is unreasonable in all the circumstances for the
               data user to comply with the request;

   (d)  subject to subsection (4), any other data user controls the use of the
        data in such a way as to prohibit the first-mentioned data user from
        complying (whether in whole or in part) with the request;

   (e)  the form in which the request shall be made has been specified under
        section 67 and the request is not made in that form; or

   (f)  in any other case, compliance with the request may for the time being
        be refused under this Ordinance, whether by virtue of an exemption
        under Part VIII or otherwise.

(4) Subsection (3)(d) shall not operate so as to excuse a data user from
complying with the data access request concerned-

   (a)  in so far as the request relates to section 18(1)(a), to any extent;

   (b)  in so far as the request relates to section 18(1)(b), to any extent
        that the data user can comply with the request without contravening
        the prohibition concerned. (Enacted 1995)



[Index] [Table] [Search] [Notes] [Noteup] [Previous] [Next] [Download (Current & Past)] [Download (Current only)] [繁體中文] [Help]