The University of Hong KongThe University of Hong Kong
University Central Facilities
Interdisciplinary and Core Research Facilities

Personal Data Privacy Policy Statement

The Hong Kong University (HKU) is committed to upholding internationally recognised standards of personal data privacy protection and ensuring compliance with the requirements of the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486).

As a unit under HKU, the University Central Facilities (UCF) adheres fully to all relevant University policies on personal data protection. UCF is dedicated to ensuring that all staff members observe the highest standards of data security, confidentiality, and integrity in the handling of personal data.

Reference to HKU’s overarching policy can be found at:

http://hku.hk/about/policies_reports/privacy_policy.html

Purpose of Personal Data Collection and Use

Personal data collected by UCF shall be used solely for legitimate and lawful purposes, including but not limited to:

Such data may include student records, training records, and communication details necessary for operational purposes.

All personal data collected will be handled exclusively by authorised UCF personnel. Where personal data are used for research or statistical analysis, they will be presented in aggregated or anonymised form to ensure that no individual data subject can be identified.

Rights of Data Subjects

In accordance with the Personal Data (Privacy) Ordinance, individuals have the right to:

Requests for access or correction should be made in writing and directed to the UCF Personal Data Protection Coordinator via the following channels:

UCF will handle all such requests in compliance with the applicable legal requirements.

Codes of Practice for Personal Data Handling

To ensure proper governance and protection of personal data, the following practices shall be strictly observed within UCF:

  1. Purpose Limitation
  2. Personal data collected by UCF shall be limited strictly to purposes related to user registration and statistical analysis.

  3. Data Access Control
  4. All personal data must be accessed and processed solely within designated UCF computer systems. Unauthorised copying, transfer, or external storage of personal data is strictly prohibited.

  5. Data Export Control
  6. The data extraction or “data dumping” function is restricted and may only be performed using authorised systems under the control of the UCF Personal Data Protection Coordinator.

  7. Information Security Measures
  8. All staff computers within the UCF laboratory environment must have Data Loss Prevention (DLP) software installed as provided or approved by the University’s Information Technology Services (ITS).

  9. Incident Reporting
  10. Any of the following incidents must be reported immediately to the UCF Personal Data Protection Coordinator:

    • Suspected or confirmed data breach
    • Loss or leakage of personal data
    • Security incidents
    • Complaints related to personal data handling

    Prompt reporting is essential to ensure timely investigation and mitigation of any risks.

Compliance

All UCF staff and users are required to comply with this policy. Non-compliance may result in disciplinary actions in accordance with University regulations.

Review and Updates

This policy shall be reviewed periodically to ensure continued compliance with legal requirements and HKU policies. Updates will be issued as necessary.

Last update: 11 JUN 2026