If these amendments seem familiar, they are – many of these proposals reflect GDPR provisions that have come into effect, and, indeed, the discussion paper itself acknowledges that it has referred to the GDPR and other comparable jurisdictions in formulating its proposals. The reference to GDPR is to be welcomed. We see no reason why data subjects in Hong Kong would have a lower expectation for the protection of their personal data when compared with data subjects in the EU. Furthermore, Hong Kong's largely globalised economy could benefit from having less divergence between the PDPO and comparable legislation overseas – such as the GDPR.
The discussion around anti-doxxing measures is perhaps more topical to Hong Kong than in other jurisdictions. The discussion paper indicates that the Constitutional and Mainland Affairs Bureau is "deeply concerned" about the significant volume of doxxing cases recently reported in Hong Kong. There have been more than 4,700 doxxing-related cases identified by the privacy commissioner since 14 June last year. More than 1,400 of those cases were referred to the police for further investigation, and there have so far been eight arrests. Actions taken to address the problem thus far include the privacy commissioner requesting the removal of more than 2,500 links from online platforms and that the platforms publish warnings that doxxing might constitute a breach of the PDPO, while the Hong Kong government has also gone to court in a bid to stop doxxing targeted at police officers.
Anti-doxxing measures in any jurisdiction and at any time are to be welcomed. Given the rise in doxxing cases over the past few months in Hong Kong, the current round of proposed amendments for the PDPO seems the appropriate time to deal with the problem.
What else might we expect to see?
As comprehensive as the discussion paper is, it is only the first step in a long journey to updating the PDPO. We do not yet know how the Legislative Council Panel on Constitution Affairs will respond to the discussion paper, nor how the broader community and the relevant stakeholders will receive it. Nevertheless, we can expect three issues to surface as the discussion paper gains traction:
- Regulations on cross-border transfers of personal data: under section 33 of the PDPO, a data user is prohibited from transferring personal data outside of Hong Kong unless a series of conditions or exemptions are met – for example, by securing the data subject's informed consent or by demonstrating that the destination jurisdiction for the personal data contains adequate data protection laws of its own. However, section 33 is not currently in force in Hong Kong, and there is no timetable for it to come into force. While the discussion paper does not refer to section 33, we think it is only a matter of time before the issue is raised. Regulations on cross-border transfers are important for protecting data subjects and by now a widely acknowledged norm in a variety of data protection legislation across the world. Hong Kong remains an outlier for not enforcing similar restrictions.
- Measures that target the use of automated decision-making and profiling: the use of artificial intelligence for data processing has become increasingly common - and while convenient, such automated processing of data can give rise to ethical concerns such as whether decisions generated by automated processing are procedurally sound, sufficiently transparent or explainable, particularly when such decisions affect the rights, freedoms and interests of data subjects. Article 22 of the GDPR takes the first steps in addressing this issue by providing data subjects with a right not to be subject to a decision based solely on automated processing, including profiling. Given the strength of data-hungry innovations such as fintech, infratech and smart cities in Hong Kong, we can expect measures dealing with automated decision-making would be relevant in the city too. Addressing these issues in amendments to the PDPO would reassure data subjects and provide regulatory certainty to data users.
- A greater focus on 'consent': an important issue dealt with by the GDPR is ‘consent fatigue’ - to put simply, the tendency of data subjects to simply click ‘accept’ and consent to use of their personal data without carefully scrutinising the relevant terms or policies. The legal standard for 'consent' under the GDPR is high. It, for example, places restrictions on consent bundling and an emphasis on the need for consent to be granular. The GDPR also provides alternative legal bases for the collection and processing of personal data, such as by reference to contractual obligations between the parties and by reference to the legitimate interests of the data controller. Since ‘consent fatigue’ is not an issue exclusive to the EU and can be every bit as applicable in Hong Kong, we would likewise welcome discussions as to how the PDPO should provide greater detail on the use of consent going forward.
Engagement is important
It will take time for the discussion paper to be developed into a set of concrete amendments for the PDPO. The proposed amendments provide a valuable opportunity to update Hong Kong's data protection laws both to reflect international standards, and to apply the lessons learnt in the implementation of other data protection laws elsewhere in the world. For data users, there is much to be gained in being well informed on the changes to the PDPO – both by contributing to the consultation process and in being well-prepared to respond operationally to such changes.
Paul Haswell, Jennifer Wu and Thomas Ho are Hong Kong-based experts in data protection law at Pinsent Masons, the law firm behind Out-Law.