PCO Office of the Privacy Commissioner for Personal Data, Hong Kong imagebanner image
Privacy Policy StatementSearchSite DirectoryText Only VersionChinese  
image
About PCPD
image
The Ordinance
image
Review of the Ordinance
image
PCPD Activities
image
Information Centreimage
Privacy Zone for Youngsters
image
Publications and Videos
image
Enquiries and Complaints
image
Case Notes
image
Contact Us
image
Search Case Notesimage
image

Case Notes
Complaint & Enquiry Cases

 

 

Notes on Complaint & Enquiry Cases related to DPP4 - security of personal data

Case No.: 2002008

Identity card number as default password

A mobile phone service company provided an Internet billing service to its customers through its website. A customer has to log into the system by entering his mobile phone number and password to gain access to his account information, which also include detailed call records made by the customer. However, the password was defaulted to the first six digits of the customer's identity card number. A customer complained that a debt collector accessed to his call records through the Internet billing service and caused nuisance to him and his friends.

The use of a customer¡¦s identity card number as the default password should be handled with special caution since an individual's identity card number may, for various reasons, be disclosed and known to others. Given the sensitive nature of the data and the potential risk arising from any misuse of the data, a service provider who chooses to set its customers' access password by using their identity card numbers should take additional steps to safeguard the security of the data. Such steps may include ensuring that all customers are fully aware of the default password arrangement and at the same time remind them of the importance of changing the password to a number of their choice to prevent unauthorized access to customers' accounts.


Back to top


  imageNotice/ Copyright 2001 Office of the Privacy Commissioner for Personal Data, Hong Kong. All rights reserved. Disclaimer