Get Apps
Get Apps
Get Apps
點新聞-dotdotnews
Through dots,we connect.

EMSD leaks data of 17,000 tested individuals, falling short of public expectations

Hong Kong
2024.12.09 13:13
X
Wechat
Weibo
The Office of the Privacy Commissioner for Personal Data has released the investigation results regarding a data breach incident involving the Electrical and Mechanical Services Department (EMSD). (DDN)

The Office of the Privacy Commissioner for Personal Data has released the investigation results regarding a data breach incident involving the Electrical and Mechanical Services Department (EMSD). The suspected leaked personal data pertains to individuals tested during the "Restriction-testing Declaration" Operations amid the pandemic two years ago, including names, addresses, identity card numbers, and phone numbers, affecting over 17,000 people.

The Office determined that the EMSD did not take all practicable steps to ensure that data retention did not exceed the time necessary for actual use, nor did it take all practicable steps to ensure that the involved personal data was protected from unauthorized or accidental access, in violation of the Personal Data (Privacy) Ordinance.

The report noted that the EMSD conducted 14 "Restriction-testing Declaration" Operations from March to July 2022, after which the data was uploaded to a cloud platform. In April of this year, it was discovered that the relevant data could be accessed on the cloud platform without requiring an account or password. On the same day, the department requested the contractor to remove the data from the platform and notify the Office. The report indicated that the EMSD believed that after the contract expired, the account for that electronic platform would become inactive, and the relevant data would be automatically deleted.

Privacy Commissioner Ada Chung believes that the main reason for the incident is that the EMSD did not establish a written policy regarding the retention period of the relevant personal data, failing to provide clear criteria for data retention and deletion. She stated that the practices clearly did not meet the requirements of the Personal Data (Privacy) Ordinance and fell short of the public's reasonable expectations.

The Privacy Commissioner has issued an enforcement notice to the EMSD, instructing it to take measures to rectify the violations and prevent similar incidents from occurring in the future.

Related News:

Watch This | EMSD embraces smart construction

EMSD urges public to stop using model of IKEA ÅSKSTORM 40W USB charger

Tag:·EMSD· Office of the Privacy Commissioner for Personal Data· personal data leakage· Ada Chung

Comment

< Go back
Search Content 
Content
Title
Keyword
New to old 
New to old
Old to new
Relativity
No Result found
No more
Site Map
Close
Light Dark