Skip to content

Case Notes

Case Notes

This case related to DPP1 - Purpose and manner of collection of personal data

Case No.:2025C05

A service provider company mandatorily required customers to register as members for warranty services

The Complaint

The complainant previously purchased a USB storage device (“the USB”) from an online electronics store. Following the instructions provided on the USB label, the complainant visited the website of the warranty service provider (“the Provider”) to register for warranty services. Upon clicking on a webpage tab labelled “Warranty Registration” (“the Tab”), the complainant was redirected to a “Member Login” interface.

Under the “Register as a New Member” section of the interface, the following statement was displayed: “Register now as a member of [the Provider] to enjoy more exclusive offers and conveniently register for warranty services”. When the complainant clicked the “New Member Registration” link, he was required to provide his last name, first name, email address, date of birth (optional), gender (optional), and password to complete the registration process. The complainant considered that the Provider collected the above personal data in an unfair manner for registering warranty services for the USB.

Outcome

The Provider clarified that customers were, in fact, not required to register as members for the warranty services. Customers were only required to retain the product warranty card together with the original invoice to enjoy the warranty services.

Upon the PCPD’s intervention, the Provider updated the wording on the Tab, changing it from “Warranty Registration” to “Member Login”. Furthermore, the Provider revised the warranty terms on the relevant tab to explicitly remind customers that they are not required to register as members or provide any personal data for registration of the warranty services, so as to prevent any misunderstanding among customers. The PCPD also issued a warning letter to the Provider in response to the incident.

Lesson learnt

Prior to collecting personal data from customers, data users should clearly inform them of the purpose and necessity of such collection to minimize misunderstanding and enhance transparency. In the present case, when customers attempted to register for warranty services on the website and clicked on the “Warranty Registration” link, they were redirected immediately to a “Member Login” interface requiring them to log in as a member or register as a new member. Furthermore, certain wordings on the interface (such as “conveniently register for warranty services”) might have misled customers to believe that membership registration was mandatory for enjoying the warranty services.

The PCPD considers that customers should have the autonomy to decide whether to register as members. Data users should avoid providing any information that could be perceived as misleading so as to ensure that customers provide their personal data in a fair manner.

(Uploaded in March 2026)


Category : Provisions/DPPs/COPs/Guidelines : Topic/Subject Matter :