Hong Kong Special Administrative Region Identity Card Project
Total Page:16
File Type:pdf, Size:1020Kb
Hong Kong Special Administrative Region Identity Card Project Initial Privacy Impact Assessment Report Submitted September 2000 Revised after Client comments, November 2000 Pacific Privacy Pty Ltd 12A Kelvin Grove Nelson Bay NSW 2315 Australia (02) 4981 0828 Hong Kong SAR Identity Card Project - Privacy impact Assessment (Abridged Version) Pacific Privacy Pty Ltd p 2 November 2000 CONTENTS EXECUTIVE SUMMARY ......................................................................................................5 PART I – GENERAL BACKGROUND & CONTEXT........................................................7 CONTEXT................................................................................................................................7 PRIVACY IMPACT ASSESSMENTS .........................................................................................7 THE ROLE OF A PIA FOR THE HK ID CARD.........................................................................8 UNDERLYING CONCEPTS........................................................................................................9 Human Identification..........................................................................................................9 Authentication...................................................................................................................10 Anonymity .........................................................................................................................10 Pseudonymity....................................................................................................................11 Privacy..............................................................................................................................11 Privacy-Enhancing Technologies (PETs).........................................................................12 Privacy-Invasive Technologies (the PITs)........................................................................12 Smart Cards......................................................................................................................12 Digital Signatures.............................................................................................................13 Biometrics.........................................................................................................................13 PART II – SPECIFIC BACKGROUND - THE EXISTING HK ID CARD SYSTEM ...15 BRIEF HISTORY OF THE REGISTRATION OF PERSONS AND ISSUING OF IDENTITY CARDS IN HONG KONG .........................................................................................................................15 BRIEF OVERVIEW OF THE EXISTING HK ID CARD SCHEME ...............................................16 The Card and Its Contents................................................................................................16 The Contents of the ROP Database..................................................................................18 The Contents of the Microfilm Archives...........................................................................21 The Circumstances of Application for, and Issue of, the Card.........................................22 The Process of Application for the Card..........................................................................23 Authentication Procedures ...............................................................................................24 The Process of Card Issue................................................................................................25 The Production of Microfilm Records..............................................................................26 Security Measures.............................................................................................................26 The Processing of Notifications of Changes of Personal Data........................................27 The Circumstances of Use of the Card.............................................................................28 The Process of Use of the Card........................................................................................29 The Card Number and the Circumstances of Its Use .......................................................29 The Circumstances of Use of, and Disclosure from, the Microfilm Archive....................31 The Circumstances of Use of, and Disclosure from, the ROP Database .........................33 Access by Persons to Personal Data Concerning Themselves.........................................35 Underlying Infrastructure.................................................................................................35 Special Arrangements.......................................................................................................35 PART III THE HKSAR ID CARD PROJECT ...................................................................37 CONTEXT & HISTORY..........................................................................................................37 THE PROPOSED NEW SYSTEM ............................................................................................39 Salient Differences Between the Existing and Proposed Schemes ...................................39 Hong Kong SAR Identity Card Project - Privacy impact Assessment (Abridged Version) Pacific Privacy Pty Ltd p 3 November 2000 The Contents of the Card..................................................................................................42 Generic Functions of the Card .........................................................................................43 Generic Functions of Card-Receiving Devices ................................................................44 Applications of the Card and Card-Receiving Devices....................................................45 The Contents of the ROP Database..................................................................................46 The Contents of the Microfilm Archives...........................................................................46 The Functions of the ROP Database ................................................................................47 Additional Elements of the Scheme ..................................................................................47 The Card Issue Processes under the New Identity Card System.....................................48 Infrastructure to support Re-registration and Card-issue ...............................................49 The Circumstances of Application for, and Issue of, the Card.........................................50 Authentication Procedures ...............................................................................................50 Security Measures.............................................................................................................51 The Circumstances of Use of the Card.............................................................................52 The Circumstances of Use of the Card-Number...............................................................53 The Circumstances of Use of, and Disclosure from, the ROP Database .........................53 The Circumstances of Subject Access to the Card Data and the ROP Database.............54 Underlying Infrastructure.................................................................................................54 Special Arrangements.......................................................................................................54 PART IV – CONTEXTUAL ANALYSIS ............................................................................55 LEGAL ANALYSIS .................................................................................................................55 Authority for disclosure of information from the Microfilm records and ROP Database56 Data Matching..................................................................................................................57 STAKEHOLDER ANALYSIS ...................................................................................................57 PUBLIC ATTITUDES ANALYSIS.............................................................................................58 INTERNATIONAL EXPERIENCE.............................................................................................59 PART V - PRIVACY IMPACTS ANALYSIS .....................................................................61 BRIEF OVERVIEW OF THE PRIVACY IMPACTS OF THE NEW HKSAR ID CARD SCHEME ...61 GENERAL PRIVACY IMPLICATIONS ......................................................................................62 Objectives of the Scheme ..................................................................................................62 Legislative framework ......................................................................................................63 Population Registration....................................................................................................63 Multiple applications........................................................................................................64 Card management.............................................................................................................64 SPECIFIC PRIVACY IMPLICATIONS........................................................................................65 The Contents of the Card..................................................................................................65 The Functions of the Card................................................................................................67