Personal Data Protection Policy

個人資料保護政策

最後更新 Last updated:2026年7月 · July 2026

本政策訂明九南資產管理有限公司(9South Asset Management Co., Limited,以下簡稱「九南」、「本機構」)在收集、持有、處理及使用個人資料時所遵循的原則與內部規範。本政策依照香港法例第486章《個人資料(私隱)條例》(下稱「《私隱條例》」)及其附表1所載的六項保障資料原則制定,適用於本機構全體人員,以及所有於業務過程中收集或持有的個人資料。本政策與《私隱政策》相輔而行:《私隱政策》向資料當事人説明我們的對外做法,本政策則訂明我們的內部標準。 This Policy sets out the principles and internal standards that 9South Asset Management Co., Limited ("9South", "the Firm") follows when collecting, holding, processing and using personal data. It is prepared in accordance with the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) (the "PDPO") and the six Data Protection Principles ("DPPs") in Schedule 1 thereto. It applies to all personnel of the Firm and to all personal data collected or held in the course of our business. It operates alongside our Privacy Policy: the Privacy Policy explains our practices to data subjects; this Policy sets our internal standards.

1原則一:收集目的及方式DPP1 — Purpose and Manner of Collection

  • 個人資料只可為與本機構職能或活動直接有關的合法目的而收集,收集方式須合法、公平,且資料不得超乎適度;
  • 於收集個人資料時或之前,須以切實可行的方法告知資料當事人:收集目的、資料可能移轉予的人士類別、提供資料屬自願或強制、不提供資料的後果,以及查閲和改正資料的權利與聯絡途徑;
  • 透過網站表單、電郵、會議或名片交換收集資料時,僅收集處理有關事務所必需的最少資料。

Personal data shall be collected only for lawful purposes directly related to a function or activity of the Firm; the means of collection must be lawful and fair, and the data adequate but not excessive. On or before collection, data subjects shall be informed, by practicable means, of: the purpose of collection; the classes of persons to whom the data may be transferred; whether supply is voluntary or obligatory and the consequences of not supplying; and their rights and the contact for access and correction. Only the minimum data necessary shall be collected via website forms, email, meetings or business-card exchange.

2原則二:準確性及保留期間DPP2 — Accuracy and Duration of Retention

  • 採取切實可行的步驟,確保所持個人資料準確無誤;發現資料不準確時,須及時改正、補充或停止使用;
  • 個人資料的保留時間,不得超過達成原定目的(或直接相關目的)實際所需的期間;
  • 各類資料的具體保留期限,按本機構檔案管理制度及適用法律(如反洗錢法規所要求的紀錄保存期)確定;期限屆滿後,須以安全方式刪除或銷毀;
  • 聘用資料處理者(如外判文件儲存或資訊科技服務)時,須以合約方式防止資料保留過久。

All practicable steps shall be taken to ensure personal data are accurate; inaccurate data shall be corrected, supplemented or withdrawn from use without delay. Personal data shall not be kept longer than necessary for the fulfilment of the purpose (or a directly related purpose); specific retention periods follow the Firm's records-management rules and applicable law (e.g. record-keeping periods under AML regulations), after which data shall be securely erased or destroyed. Where data processors are engaged (e.g. outsourced storage or IT services), contractual means shall be adopted to prevent excessive retention.

3原則三:資料的使用DPP3 — Use of Personal Data

  • 個人資料只可用於收集時述明的目的或直接相關目的;任何新目的均須先取得資料當事人自願給予的訂明同意;
  • 未經資料當事人同意,不得向第三方披露個人資料,法律規定或本政策第5節所列情形除外;
  • 於協調獨立專業機構(律師、會計師、税務顧問等)時,僅在客户明確指示的範圍內流轉所需資料。

Personal data shall be used only for the purpose stated at collection or a directly related purpose; any new purpose requires the voluntary and prescribed consent of the data subject. Data shall not be disclosed to third parties without consent, save as required by law or as set out in Section 5. When coordinating independent professionals (lawyers, accountants, tax advisers), only the data needed shall be circulated, strictly within the scope of the client's express instructions.

4原則四:資料保安DPP4 — Security of Personal Data

  • 實體保安:文件分類存放、上鎖保管;辦公區域訪客管理;桌面清理要求;
  • 技術保安:裝置密碼與加密、權限分級、重要系統雙重認證、定期備份、安全傳輸渠道;
  • 管理保安:按「有需要方可知悉」原則授權存取;全體人員簽署保密承諾;離職人員即時撤銷權限;
  • 聘用資料處理者時,須以合約方式要求其採取同等保安措施,防止未獲准許或意外的查閲、處理、刪除、喪失或使用。

Physical security: classified and locked filing, visitor control and a clear-desk practice. Technical security: device passwords and encryption, tiered access rights, two-factor authentication for key systems, regular backups and secure transmission channels. Administrative security: access on a need-to-know basis, confidentiality undertakings by all personnel, and immediate revocation of access upon departure. Data processors shall be bound by contract to adopt equivalent safeguards against unauthorised or accidental access, processing, erasure, loss or use.

5原則五:透明度DPP5 — Openness

本機構公開其個人資料政策及常規,包括所持個人資料的類別及主要使用目的。本政策及《私隱政策》長期登載於本網站,任何人士均可查閲;如有查詢,可透過第9節所列方式聯絡資料保障主任。The Firm makes its personal data policies and practices publicly available, including the kinds of personal data held and the main purposes of use. This Policy and the Privacy Policy are published on this website for inspection by any person; enquiries may be directed to the Data Protection Officer per Section 9.

6原則六:查閲與改正DPP6 — Access and Correction

  • 資料當事人有權查詢本機構是否持有其個人資料、要求取得資料複本,並要求改正不準確的資料;
  • 查閲或改正要求須以書面提出;本機構須在收到要求後40日內作出回應;如未能於期限內依從,須在期限內以書面通知並説明理由;
  • 處理查閲要求可按《私隱條例》收取合理費用,改正要求則不收費;
  • 如拒絕依從查閲或改正要求,須按《私隱條例》述明理由,並將有關要求及理由記錄存檔。

A data subject may ascertain whether the Firm holds their personal data, request a copy, and require correction of inaccurate data. Requests shall be made in writing; the Firm shall respond within 40 days of receipt, and where unable to comply within that period shall so notify the requester in writing with reasons. A reasonable fee may be charged for a data access request as permitted by the PDPO; no fee applies to correction requests. Refusals shall state reasons in accordance with the PDPO and be logged with the request.

7直接促銷Direct Marketing

本機構目前不進行直接促銷活動。如日後擬將個人資料用於直接促銷(例如發送刊物或活動通知),將嚴格遵守《私隱條例》第6A部:事先告知擬使用的資料類別及促銷標的、取得資料當事人的同意或表示不反對,並在每次通訊中提供免費的拒收途徑;資料當事人任何時候均可要求停止,本機構須立即照辦,不得收費。The Firm currently conducts no direct marketing. Should personal data ever be used for direct marketing (e.g. circulating publications or event notices), the Firm will strictly comply with Part 6A of the PDPO: informing the data subject in advance of the kinds of data to be used and the classes of marketing subjects, obtaining consent or an indication of no objection, and providing a cost-free opt-out channel in every communication. A data subject may require cessation at any time, which the Firm shall honour immediately and without charge.

8跨境資料轉移與外洩事故處理Cross-border Transfer and Data Breach Handling

  • 如需將個人資料轉移至香港以外地區(例如按客户指示對接海外專業機構),須事先評估接收方所在地的資料保障水平,並以合約或其他方式確保資料獲得不低於本政策標準的保障;
  • 發現或懷疑發生資料外洩事故時,經辦人員須立即通報資料保障主任;由其評估影響範圍與風險、採取補救及遏制措施、記錄事故經過,並在適當情況下通知受影響的資料當事人及香港個人資料私隱專員公署;
  • 事故處理完成後,須檢討成因並改進相關制度與措施。

Before transferring personal data outside Hong Kong (e.g. liaising with overseas professionals on a client's instructions), the level of data protection in the recipient jurisdiction shall be assessed and safeguards no less stringent than this Policy secured by contract or otherwise. Upon discovery or suspicion of a data breach, staff shall immediately report to the Data Protection Officer, who shall assess the scope and risks, take remedial and containment measures, document the incident, and where appropriate notify affected data subjects and the Office of the Privacy Commissioner for Personal Data ("PCPD"). A post-incident review shall follow to improve controls.

9職責、培訓與政策檢討Responsibility, Training and Review

  • 本機構委任資料保障主任,負責監督本政策的執行、處理查閲及改正要求、統籌事故應對及回應查詢;
  • 全體人員入職時須接受個人資料保障培訓,並定期複訓;違反本政策者將按內部紀律制度處理;
  • 本政策至少每年檢討一次,並因應法例、監管指引或業務變化及時修訂。

如對本政策有任何查詢,或認為本機構處理個人資料的方式有欠妥當,請聯絡:資料保障主任,九南資產管理有限公司,香港金鐘金鐘道89號力寶中心第一座23樓2308室;電郵 Contact@menalink.fund;電話 +86 130 9533 3688。資料當事人亦有權向香港個人資料私隱專員公署(www.pcpd.org.hk)作出查詢或投訴。

The Firm appoints a Data Protection Officer to oversee implementation of this Policy, handle access and correction requests, coordinate incident response and answer enquiries. All personnel receive personal-data protection training on joining and periodic refreshers; breaches of this Policy are dealt with under internal disciplinary procedures. This Policy is reviewed at least annually and updated for changes in law, regulatory guidance or business practice. Enquiries or concerns may be addressed to: Data Protection Officer, 9South Asset Management Co., Limited, Office 2308, 23rd Floor, Tower One, Lippo Centre, No. 89 Queensway, Hong Kong; email Contact@menalink.fund; tel +86 130 9533 3688. Data subjects may also enquire or complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).

本政策以繁體中文及英文兩種文字提供,如有歧義,概以繁體中文版本為準。This Policy is provided in Traditional Chinese and English. In case of any discrepancy, the Traditional Chinese version shall prevail.