Skip to content Skip to footer

Protecting Personal Data Privacy When Using Instant Messaging Apps in Human Resources (“HR”) Management: Recommendations from the Office of the Privacy Commissioner for Personal Data

Protecting Personal Data Privacy When Using Instant Messaging Apps in Human Resources (“HR”) Management: Recommendations from the Office of the Privacy Commissioner for Personal Data

The “Human Resource Management: Common Questions” Leaflet

 

To help employers and HR practitioners understand their roles in protecting personal data privacy and to facilitate their compliance with the requirements under the PDPO in handling personal data relating to human resource management, the PCPD has updated the information leaflet on “Human Resource Management: Common Questions”. The content covers frequently asked questions relating to the application of the PDPO to HR management. Organisations are encouraged to make use of this valuable resource to enhance their data protection practices and ensure compliance with privacy regulations.

In today’s digital world, the use of instant messaging in HR management is prevalent. Instant messaging is a real-time and direct channel for HR-related discussions and updates and enables efficient communication within and outside organisations. However, the increasing reliance on instant messaging apps in HR management raises concerns about the protection of personal data privacy.

 

Accordingly, this article highlights the importance of protecting personal data privacy when using instant messaging apps; outlines recommendations for HR practitioners concerning their roles in protecting personal data privacy; and introduces our recently updated information leaflet, “Human Resource Management: Common Questions,”1 which aims to promote good practice by HR practitioners to better protect personal data privacy at work.

 

The Need to Protect Personal Data in Instant Messaging Apps

 

Personal data are a valuable asset of every organisation that require protection to ensure privacy and prevent misuse. Instant messaging apps often contain a wealth of personal information, such as contact details and conversations, and may contain sensitive data, such as medical data. Therefore, it is essential for all HR practitioners to place a strong emphasis on the protection of personal data in instant messaging apps.

 

Compliance with Data Protection Regulations

 

Organisations are obliged to comply with the requirements under the Personal Data (Privacy) Ordinance (the PDPO), including in the use of instant messaging apps in HR contexts.

 

A recent report2 published by the Office of the Privacy Commissioner for Personal Data (the PCPD) notes that two organisations were found to have contravened the requirements under the PDPO. Specifically, the organisations had disclosed their staff members’ personal data in instant messaging app chat groups for new purposes different from the original purpose of collection and without the relevant staff members’ consent. As a result, these organisations have been served enforcement notices that direct them to remedy the breaches and prevent the recurrence of their respective contraventions. Failure to comply with an enforcement notice is an offence and is liable on conviction to imprisonment for 2 years and a fine.

 

Due to the ease and convenience of their use, instant messaging apps are frequently used by organisations. Moreover, the exchange of messages and information via instant messaging apps in organisations is on the rise, such that the risk of personal data leakage via these apps is also significantly increasing. Therefore, HR practitioners should exercise due care in deploying instant messaging apps to mitigate potential penalties or legal repercussions.

 

Data Breach Prevention

 

Instant messaging apps may exhibit vulnerabilities that can be exploited by cybercriminals seeking to gain unauthorised access to personal data. However, by implementing robust security measures, such as end-to-end encryption, two-factor authentication, access controls, and regular security audits, HR practitioners can significantly reduce the risk of unauthorised access to sensitive employee information.

 

Specifically, by proactively implementing the above-mentioned protective measures, organisations create a secure environment for employee personal data in instant messaging apps. This reduces the likelihood of data breaches and unauthorised disclosure of sensitive information, allowing organisations to safeguard employee privacy, maintain regulatory compliance, and protect their reputation.

 

Employee Privacy and Trust

 

HR practitioners are responsible for handling sensitive employee information, such as performance evaluations, medical records, and payroll details. Ensuring the confidentiality and security of these data in instant messaging conversations helps maintain trust between HR and employees. Employees who are confident that their personal information is handled securely are more willing to engage in open and honest communication with HR practitioners. Such trust is crucial for maintaining a positive work environment and strong employee relations.

 

Privacy Commissioner’s recommendations for HR practitioners

 

The PCPD recognises the importance of data protection in the workplace. Below are several recommendations for HR practitioners seeking to enhance personal data privacy protection when utilising instant messaging apps.

 

Establish Clear Policies

 

Organisations are advised to develop clear policies and guidelines regarding the use of instant messaging apps in the workplace. These policies should comprehensively explain the relevant legislative requirements, describe the data protection measures and procedures adopted by organisations, outline employees’ responsibilities in protecting personal data, and provide clear guidance on the secure usage of personal data.

 

Foster Transparency and Open Communication

 

Organisations should ensure that employees are fully informed about and provided with clear explanations of the collection and processing of their personal data through instant messaging apps. It is important that employees understand the purpose and scope of data collection and how their data will be used. In addition, organisations should adopt a data minimisation approach, that is, collect only necessary personal data through instant messaging apps. Unnecessary data should not be collected or stored in such apps, thereby reducing the risks associated with data breaches and unauthorised access.

 

Think Twice Before Sharing

 

HR practitioners should think twice before sharing or disclosing personal data through instant messaging apps, thereby mitigating the risk of unintended disclosure. Once personal data have been disclosed, they may be forwarded to other irrelevant parties and permanently retained by others, leading to a loss of control over data access. As such, it is essential to carefully consider the sensitivity and relevance of data being shared to ensure compliance with data protection regulations.

 

________________________________________

1https://www.pcpd.org.hk/english/resources_centre/publications/files/Some_Common_Question_Eng.pdf

2https://www.pcpd.org.hk/english/enforcement/commissioners_findings/files/r23_18465_e.pdf

?
Join as member
to enjoy exclusive discount

條款和條件

  1. 會籍有效期由4月1日至3月31日(會員可選擇一年或兩年,而「專業途徑為基礎」的資深會員、專業會員、副會員需符合 持續專業發展(CPD)的要求。)
  2. 本會可隨時調整入會費及會員年費,而無需事先通知。
  3. 本會每年3月以郵寄及電郵形式通知會員續會,會員收到發票後,可按照付款方式繳交續會年費。於早鳥優惠期間成功繳交續會年費可享早鳥優惠價,及本年度續會之會員可獲得相應金額的電子代用券。
  4. 升級之會籍有效期由4月1日至3月31日,並按照會員所選之續會年期計算 (一年或兩年)。
  5. 會員持有有效的會籍及符合會籍升級之條件,可申請會籍升級。有關申請安排可與會員服務部聯絡。
  6. 年滿60歲且已退休的會員可電郵本會申報。會員年費可獲半價優惠。
  7. 會員可選擇重新續回自2010年4月1日新會籍制度後終止的會籍,並有機會:
    。 繳付復原費用及於會籍終止其間所欠交的會員年費;及
    。 提供有關會籍終止期間內已符合續專業發展 (CPD) 要求的紀錄(如適用)。
  8. 本會保留酌情處理的權利,並就每項申請擁有最終決定權。有關費用不可取消且不可退還。

 

如果您對會籍有任何疑問,歡迎致電會員服務部 (2837 3814 / 2837 3813) 
發送電子郵件至  membership@hkihrm.org

世界大型企業聯合會(TCB)亞洲理事會會籍

會員專享優惠 –世界大型企業聯合會(TCB)亞洲理事會會籍

作為香港人力資源管理學會(HKIHRM)的資深會員或專業會員,您可享高達20%的折扣,加入世界大型企業聯合會(TCB)的亞洲理事會會籍,獲取前瞻性見解。

世界大型企業聯合會(TCB)亞洲理事會會籍為您提供同行網絡、思想領導力資源以及專家支援,協助您應對工作挑戰,提升團隊及組織績效。透過匯聚全球領先企業的高級管理人員,理事會將引領您參與深度且以解決方案為導向的對話。

亞洲理事會會籍包括:

  • 每年兩至三次的實體會議
  • 專屬理事會網站
  • 理事會基準調查及專屬團隊支援

申請資格:

  • 有效的學會資深會員或專業會員會籍
  • 以個人名義申請
  • 申請需經TCB審核及批准

首年會籍折扣優惠

  • 1年會籍: 美金 9,000 (美金 7,200)

申請及查詢:
Brendan Moran先生
電郵:Brendan.moran@conference-board.org;電話:+65 6645 4696

與海外會籍及資格相互認可之安排

香港人力資源管理學會(HKIHRM)與加拿大卑詩省的The Chartered Professionals in Human Resources of British Columbia and YukonCPHR BC & Yukon)已達成專業會員會籍相互承認的安排

學會的資深會員F.I.H.R.M.(HK) 及專業會員M.I.H.R.M.(HK)均可成為加拿大CPHR BC & Yukon’s Chartered Professional in Human Resources Designation (CPHRTM) 的專業會員。此共識是基於雙方有關會籍之專業性及認受性達致相同水平而作出的互相承認。

  • 如欲成為香港人力資源管理學會之專業會員M.I.H.R.M.(HK),請按此了解更多;申請表格請按此(只有英文版本)。
  • 如欲成為加拿大CPHR BC & Yukon之CPHRTM專業會員,請 按此了解更多;申請表格請按此(只有英文版本)。

查詢:

香港人力資源管理學會:+(852) 2837 3814,membership@hkihrm.org 

CPHR BC & Yukon:請將您的申請直接電郵至  cphr@cphrbc.cahttps://cphrbc.ca/cphr/i-am-a-cphr/cphr-mutual-recognition/

    Pesonal Information

    Training Information

    Need assistance? Interested in joining us? Or just have a question?

    We’re here to help! Reach out via message, and our team will respond as quickly as possible.

        Asia Council Membership

        HKIHRM Members’ Privilege – Asia Council Membership of The Conference Board (TCB)

        As a HKIHRM Fellow and Professional Member, you are entitled to a 20% discount for joining the Asia Council Membership of TCB, an international think tank that delivers trusted insights for what’s ahead.

        TCB of Asia Council package offers a peer network, a portfolio of thought leadership, and access to experts to help address your job challenges and strengthen your team and organisation’s performance. By bringing together select senior executives from the world’s leading companies, the Council engages you in an immersive, solutions-focused conversation.

        The Asia Council Membership includes:

        • Two to three in-person meetings a year
        • Private Council website
        • Council bench-marking surveys and dedicated support from your Council team

        Eligibility:

        • Active HKIHRM Fellow and Professional Members
        • Individual basis
        • The application is subject to TCB’s vetting and approval

        Discounted Offer (1st year of membership only)

        • Year 1: USD 9,000 (USD 7,200)

        Application & Enquiry:
        Mr Brendan Moran
        Email: Brendan.moran@conference-board.org Tel: +65 6645 4696

        Reciprocal Membership

        Mutual Recognition of Professional Membership between HKIHRM and Canada-based CPHR British Colombia & Yukon

        HKIHRM has established mutual recognition of Professional Membership with the Chartered Professionals in Human Resources of British Columbia and Yukon CPHR British Colombia & Yukon since 2015. This understanding is based on a recognition of ‘substantial equivalency’ of the F.I.H.R.M.(HK) or M.I.H.R.M.(HK) designation to those of the CPHRTM designation, a CPHR British Colombia & Yukon’s Chartered Professional in Human Resources designation. HKIHRM Fellow Members and Professional Members are eligible to obtain the CPHRTM designation from CPHR British Colombia & Yukon.

        • To become a Professional Member M.I.H.R.M.(HK) of HKIHRM, please click HERE  for more information. Application form can be downloaded HERE .
        • To become a CPHRTM member of CPHR British Colombia & Yukon, please click HERE for more information. Application form can be downloaded HERE.

        Enquiry:

        HKIHRM: +(852) 2837 3814, membership@hkihrm.org 

        CPHR British Colombia & Yukon: Please send your application directly to cphr@cphrbc.ca, https://cphrbc.ca/cphr/i-am-a-cphr/cphr-mutual-recognition/

        Terms and Conditions

        1. Membership fee is charged for members joining between 1 April and 31 March for one-year or two-year subscription. (and subject to meeting mandatory CPD requirement for Professional-route-based Membership  only for renewed Fellow, Professional and Associate Members)
        2. Entrance and annual subscription fees are subject to review by the Institute without prior notice.
        3. HKIHRM will notify members to renew their membership via mail and email every year in March. Members can settle renewal fee by different payment methods marked in the invoice and enjoy the discount rate if the renewal fee is settled before the early bird period. E-vouchers will be provided if the renewal fee is settled.
        4. The upgraded membership fee is charged for members joining between 1 April and 31 March for one year or two years subscription (Same as selected membership renewal period).
        5. Member must have a valid membership and meet the upgrade requirements in order to apply for a membership upgrade. For assistance with the application process, please contact Member Services Team.
        6. Those aged 60 or above AND on permanent retirement may notify HKIHRM by email to enjoy 50% discount on the individual membership fee.
        7. Members can apply for membership reinstatement after their membership has been suspended since the introduction of new membership scheme on 1 April 2010 by:
          • paying a reinstatement fee (all the outstanding annual membership fee since his / her suspension); and
          • providing CPD records for the year(s) showing you have met the CPD requirement since you have ceased to be a member (if applicable)
        8. HKIHRM shall has absolute discretion in respect of each application to decide conclusively whether he / she has fulfilled the conditions applicable to his / her case or not. The decision of the HKIHRM is final and shall not be subject to any appeal. Membership fee is non-cancellable and non-refundable.


        If you have any enquiry on membership, please contact
        Member Services Team (2837 3814 / 2837 3813) or email at membership@hkihrm.org.