We, The Hong Kong Chartered Governance Institute ("HKCGI") and the Hong Kong/China Division of The Chartered Governance Institute ("CGI") from time to time collect personal identifiable information from current, past and prospective members, students and employees as well as other interested persons (collectively the "Data Subject") for the purposes of our administration and management; membership admission, registration, maintenance and administration; enforcement of members' compliance of the provisions of the Charter and Byelaws of CGI and the Articles of Association of HKCGI for the time being in force and related matters; communications; assessment of qualifications and experience; examinations; continuous professional development; surveys, analysis, research and development; promotion of the profession, CGI and HKCGI; and marketing and provision of services and benefits and organising activities to members, graduates and students (collectively, the "Purposes").
Our policy is to build on the trust and confidence the Data Subject placed on us. Accordingly, we have a duty to the Data Subject to keep information about them, and their personal data confidential, secured and protected.
The personal data of the Data Subject is classified as confidential and can only be disclosed by us where permitted by the Personal Data (Privacy) Ordinance (Chapter 486) (the "Ordinance") or otherwise legally compelled to do so.
Statement of Practices
Data Protection Principles
In addition to our duty of confidentiality to you as the Data Subject, we will at all times fully observe the Ordinance in collecting, maintaining and using your personal data. In particular, we observe the following principles, save otherwise appropriately agreed by you:
- collection of personal data from you shall be for purposes relating to the business of HKCGI and CGI and related services;
- all practical steps will be taken to ensure that personal data are accurate and will not be kept longer than necessary or will be destroyed in accordance with the internal retention period;
- personal data will not be used for any purposes other than the data that were to be used at the time of collection or purposes directly related thereto;
- personal data will be protected against unauthorised or accidental access, processing or erasure;
- you have the right of access to and for correction of your personal data held by us and that your request for access or correction will be dealt with in accordance with the Ordinance.
Types of Personal Data Collected
We may collect the following (without limitation) types of personal information from you:
- Title, name, date of birth, age, identity document number, nationality, gender, email and postal addresses and home and work telephone numbers,
- Employment details
- Registration status
- Membership number
- Education and professional qualifications
- User name/ID and password
- Preference in terms of personal interest and types of information to be received
- Credit card number and expiry date
- Information relating to use of our website
- Information relating to the participation to Institute's events
Transfer of Personal Data
We will disclose personal data when required by law including, without limitation, the Ordinance, a court order or a request of law enforcement agency or regulatory authorities.
We may transfer your personal data to third parties such as our related companies or associates, group sister associations, agents, contractors business associates or service providers, or other professional bodies, government bodies or regulators, as may be necessary for any of the Purposes.
When personal data is provided to a third party, the personal data will only be transferred to such a third party that respects privacy and is under a duty of confidentiality to us and/or who has undertaken to keep such information confidential.
If transfer of personal data outside Hong Kong is needed in order to carry out the Purposes or directly related purposes, for which the personal data were collected, the transfer will be performed in a manner in full compliance with the requirements under the Ordinance.
Accuracy of Personal Data
We have systems and procedures in place to maintain personal data at a reasonable level of accuracy, completeness, relevancy and up-datedness for the purpose for which the personal data is to be used. However, we rely on you to inform us of all relevant information and any errors, omissions or changes in such information.
You may amend your personal data as stated in the “Access and Correction of Personal Data" section below.
Retention of Personal Data
It is our policy to retain personal data for a period which is no longer than is required to fulfil the purpose(s) (and/or any directly related purpose(s)) for which the data was to be collected or used, subject to requirements mandating the retention of such data imposed by law, statutes, and law enforcement or regulatory authorities.
Security of Personal Data
We adopt appropriate physical, mechanical, electronic and/or management measures precautions and safeguard to protect personal data against unauthorised or accidental access, processing, modification, erasure or other use.
We may use your personal data including name, email address and correspondence address to inform you of or send you material on our news and development, CPD and ECPD activities, members' benefits, goods, services, facilities and events organised or sponsored by us or other organisations.
If you do not wish your personal data to be used for the above purposes, you may send a request to our Privacy Officer by email at email@example.com or in writing to 3/F, Hong Kong Diamond Exchange Building, 8 Duddell Street, Central, Hong Kong notifying us that you do not wish your personal data to be used for such purposes. If a member/graduate wishes to opt out, please email to firstname.lastname@example.org with the subject 'Opt out'.
Personal Data Collected Through Website
We may collect personal data through your use of our website including (without limitation) member or/ student ID number, password and email address. Certain information about your or the user's computer may also be collected when you visit our website, such as the type of the internet browser and operating system of your computer and where applicable your IP address and information relating to your internet service provider. You are not required by law to provide your personal data for the purpose of visiting our website but we may be unable to provide you with the information, services and facilities you may require unless you provide us with the requested personal data for administration, security or other reasons.
We are not responsible for the contents available on, or the set-up of, or the personal data or information collected (if any) by, any other websites linked to our website. Linking or access to and use of such other websites is at the user's own risk and subject to any terms and conditions applicable to such access or use.
Use of Personal Data Collected Through Website
We use the personal data collected through our website primarily for provisioning of our services and facilities you require; to respond to your inquiries or requests; to know about your interests and needs; to perform statistical analysis on website usage and users' requirements, interests and preferences; direct marketing activities; and for notification to you of the activities, events, news, seminars, publications and development of the Institute and changes to our website or our services Updated in January 2022 Page 3 of 3 or facilities which may affect you.
We will not collect any personal information that identifies a visitor to our website individually unless specified otherwise. Your visit to our website will record only the “domain name server” part of your email address and of the pages visited. Such information will be used to prepare aggregate information about the number of visitors to the site and general statistics on usage patterns.
Some of the web pages on our website contain "cookies" to enhance your experience of our website. A cookie is a small piece of data sent from a website and stored in a user's web browser while the user is browsing that website. Every time the user loads the website, the browser sends the cookie back to the website server to notify the website of the user's previous activities, preferences and browsing patterns.
Access and Correction of Personal Data
You can request for access to personal data and or update or correct your personal data by sending a request to our Privacy Officer by email at email@example.com in writing to 3/F, Hong Kong Diamond Exchange Building, 8 Duddell Street, Central, Hong Kong.
We will take reasonable steps to verify your identity before granting access or making corrections to your personal data to protect your privacy and identity.
In accordance with the terms of the Ordinance, the Institute has the right to charge a reasonable fee for the processing of any data access request.
No Limitation of Rights
Nothing in this Statement shall limit your rights under the Ordinance.
Notice to Interested Persons and Others Relating to the Ordinance
From time to time, it is necessary for interested persons to supply us with data in connection with our provision of services. Failure to supply such data may result in our being unable to provide any services.
Change to Statement on Personal Data Protection
We may change this Statement from time to time. We encourage you to check our Statement on Personal Data Protection occasionally to ensure that you are aware of the most recent version.
How to Contact Us
If you have any questions or concerns about the Institute's Statement on Personal Data Protection including our data policies and practices, you may contact our Data Protection Officer by email at firstname.lastname@example.org or in writing to 3/F, Hong Kong Diamond Exchange Building, 8 Duddell Street, Central, Hong Kong.
IMPORTANT: By accessing this web site and/or any of its pages, you are agreeing to the terms of our Statement on Personal Data Protection set out above.