HKCWA Information Security & Data Privacy Guidelines (English Only)
- Statutory Framework Strictly complies with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong and its Six Data Protection Principles (DPPs).
- Application of Data Protection Principles (DPPs)
- DPP 1 (Purpose): Personal data (HKID, passports, medical info, performance scores) collected solely for registration, selection, safety, insurance, and anti-doping.
- DPP 2 (Accuracy & Retention): Data retained only as long as necessary, then securely destroyed.
- DPP 3 (Use): Data used strictly for specified purposes without unauthorized disclosure.
- DPP 4 (Security): Data protected against unauthorized access or loss via role-based controls and encryption.
- DPP 5 & 6 (Transparency & Access): Publicly accessible policy; data subjects can request data access via info@waterski.org.hk.
- Technical & Operational Safeguards
- Access Control: Role-based access restricted to authorized personnel (Hon. Treasurer, Hon. Secretary, Team Manager).
- Electronic Security: Mandatory Multi-Factor Authentication (MFA) and encryption for HKCWA cloud storage. Storing sensitive data on unencrypted personal USB drives is prohibited.
- Physical Security: Physical files locked at the registered office.
- Social Media & Media Handling Prohibits releasing personal contacts, medical details, or passport info of athletes publicly. Prohibits disclosing non-public selection deliberations or tactical strategies on personal social media accounts.
- Data Breach Response Suspected/confirmed data breaches must be reported to the Data Protection Officer within 12 hours. If high risk is identified, HKCWA will notify the Privacy Commissioner (PCPD) and affected individuals within 48 hours.