e-Commerce Laws in China and Hong Kong:
Integration or Separation?


Appendix 5


Guidelines for users of personal data on the Internet

  1. Where personal information is collected through a webpage, the identity of the organization behind the page should be made clear.
  2. Organizations with web sites should have their privacy policy statements either accessible or downloadable by their web users (including use of cookies and the policy on spamming);
  3. Each page where personal information is collected should include a link to a 'personal information collection statement'. The statement should set out the purposes for which the personal data will be used (among other things). If public display of the information is intended or use for direct marketing, this should be made clear when the information is collected.
  4. Only use the data for the purpose for which is was collected, as set out in the personal information collection statement.
  5. Use encryption when transmitting sensitive information, or provide a warning that transmission may be insecure.
  6. Direct marketing emails should contain an express 'opt-out' choice to the individual.
  7. ISPs should inform their customers of the purposes for using 'click trails' information.
  8. An automated comparison of databases containing personal data ('data matching') should not be carried out where:
    • each database contains personal data that has been collected for different purposes;
    • the comparison involves personal data of 10 or more people; and the end result of the comparison may be used to take adverse action against any of those people.