According to the “Recommended Procedures for IT Practitioners on Personal Data Handling”[1], information users should not release information that contains confidential information to any IT contractors or third-party users unless it is absolutely necessary for them to complete the task. Under this situation, non-disclosure agreement should be used to govern the responsibility of the contractors or third-party users in maintaining the privacy of information and to protect the reputation and legal position of the University.
[1] The procedures are jointly published by Office of the Privacy Commissioner for Personal Data, ISACA Hong Kong Chapter, Internet Professional Association and The Hong Kong Institution of Engineers.
The abbreviations and terms used in this document shall have the following meaning:
[1] The definition is sated based on the definition of “data user” in Personal Data (Privacy) Ordinance: https://www.pcpd.org.hk/english/data_privacy_law/ordinance_at_a_Glance/ordinance.html
[2] Definition is quoted from Personal Data (Privacy) Ordinance: https://www.pcpd.org.hk/english/data_privacy_law/ordinance_at_a_Glance/ordinance.html
Non-disclosure agreements should address the requirement to protect confidential information using legally enforceable terms. These agreements should comply with all applicable laws and regulations for the jurisdiction to which they apply. To identify requirements for non-disclosure agreements, the following elements should be considered:
Based on your security requirements, other elements may be needed in a non-disclosure agreement. Two samples of non-disclosure agreement are attached for your reference. You may need to modify the samples or design your own non-disclosure agreements for different circumstances.
When you prepare the non-disclosure agreement, please note that if the receiving party is an individual, you should check his/her HKID to verify the HKID number as written on the agreement. If the receiving party is a company, you are advised to:
Last but not least, you should familiarize yourself with the “Data Protection Principles” and the “Recommended Procedures for IT Practitioners on Personal Data Handling” in order to know how to deal with personal data and to ensure compliance with the law and regulations in Hong Kong.
Departments can download the NDA samples for reference.
This document is written by referring to ISO17799:2005 (06.01.5 Confidentiality agreements and 07.2.1 Classification guidelines). In addition, the following documents are also used as references:
For any enquiries, please email to infosec@cuhk.edu.hk .
Published on: Feb 2009
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |