Personal Information Collection Statement Pertaining to Employment and Engagement of Other Services
This statement is to advise the following persons on the collection and use of the personal data ("data") received by or made available to the Bank under the relevant context and their rights with regard to such data under the Personal Data (Privacy) Ordinance (Cap 486, laws of Hong Kong) (the "Ordinance"):
(a) all employees, prospective employees, job applicants, secondees, dual hatted persons, (intra-group or external) transferees, officers, and candidates of specific or prospective position of Sumitomo Mitsui Banking Corporation (Incorporated in Japan with limited liability) (the "Bank") and other kind of individuals serving or acting for or on behalf of Bank as the Bank's representatives; and
(b) to the extent applicable and relevant, the persons who are engaged by the Bank, the Bank's head office in Japan and/or any of its branches and/or the Bank's holding company, Sumitomo Mitsui Financial Group, Inc. and each of the subsidiaries, associated companies and/or affiliates, whether within or outside Hong Kong, of each of the Bank and Sumitomo Mitsui Financial Group, Inc. (each a "Bank's group company" and collectively "Bank's group companies") for providing services to the Bank and any Bank's group company (collectively referred to as "data subjects" and each a "data subject"). In this statement, "Hong Kong" refers to the Hong Kong Special Administrative Region of the People's Republic of China.
(1) Throughout the course of the data subject's employment with and/or service to the Bank, it is necessary for the Bank to obtain and maintain data about the data subjects ("Personnel Records") and/or such data about the data subjects are being made available to, collected, used and held by the Bank and/or any Bank's group company and its or their respective service providers or agents, for various purposes including but not limited to the following (as the case may be):
a) daily operation of the Bank;
b) recruitment exercise, processing employment, service engagement and/or onboarding applications, various on-going human resources management purposes including without limitation assessing performance and suitability of continuance in employment with, service to and/or other engagement or arrangement with the Bank and/or any Bank's group companies;
c) determining and reviewing salaries, bonuses, compensation and other benefits (if applicable);
d) consideration for promotion, training, staff development, job posting (including but not limited to secondment, transfer to/from or otherwise dual hatting with any Bank’s group companies) and better employees or personnel engagement;
e) provision of intra-group services or implementation of any kind of business collaboration among the Bank's group companies, and/or establishing or maintaining business relationship or arrangements with the Bank or any Bank's group company;
f) exploring the possibility of entering into business, contractual or other kind of relationship or arrangements with the individuals and/or entities relating to the individuals and/or conducting due diligence therefor;
g) assessing, monitoring and evaluating the ability and/or suitability of the entities relating to the individuals to be agents, service providers or business partners of the Bank;
h) arranging training, and administering and processing training records and results;
i) global budget and expenses management, planning and development of business and operational strategies;
j) consideration of eligibility for and administration of staff loans, compensation, awards and other benefits and entitlements (if applicable);
k) administering payroll, allowances, reimbursements, insurance, provident fund scheme, tax returns, leave applications and other benefits (if applicable);
l) transferring to any of the Bank's group companies and any authorised service providers, contractors and/or agencies of the Bank or any of the relevant Bank's group companies for conducting pre-employment and/or pre-engagement screening, vetting, background and other ongoing checks (the "Checks") on the relevant data subjects before and during employment with the Bank and/or service engagement with the Bank or any Bank's group companies. The Checks may include seeking further references from the data subject's previous employer(s) and/or principals and verifying all relevant records with other relevant persons, third parties and/or institution(s);
m) providing employment and/or other kind of relevant engagement references (which may include all or any part of the Personnel Records in relation to a data subject maintained by the Bank and/or from any of the relevant Bank's group companies from time to time) pursuant to any request of the prospective employers or principals who wish to employ and/or engage the services of that data subject or otherwise in accordance with the legal and regulatory requirements applicable to the Bank or any of the Bank's group companies;
n) user identification or verification for accessing and using any facilities, premises, equipment and/or systems provided by the Bank and/or any Bank's group company (including but not limited to remote access system or access to premises);
o) safeguarding employees' health and that of the other data subjects, occupants, visitors or any other individuals at the Bank's offices or premises during pandemic, emergency or contingent situation or where necessary, deploying epidemic prevention and control or any other applicable or necessary emergency or contingency measures in the workplace or premises and making suitable business and operational arrangements;
p) monitoring for quality or security control and/or for compliance with legal, regulatory and professional standards and the internal policies, procedures and rules of the Bank and any relevant Bank's group companies;
q) detecting and/or investigating breaches of any relevant law or regulation;
r) complying with the obligations, requirements or arrangements for disclosing and using data that apply to the Bank and/or any Bank's group company or that it is expected to comply according to (i) any laws, rules or regulations binding or applying to it within or outside Hong Kong existing currently and in the future, (ii) any policies, codes, circulars, directives, guidelines, guidance or any other similar documents given or issued by any legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers within or outside Hong Kong existing currently and in the future, and/or (iii) any present or future contractual or other commitment with local or foreign legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers that is assumed by or imposed on the Bank and/or any Bank's group company by reason of its financial, commercial, business or other interests or activities in or related to the jurisdiction of the relevant local or foreign legal, regulatory, governmental, tax, law enforcement or other authority, or self-regulatory or industry bodies or associations;
s) complying with any obligations, requirements, policies, procedures, measures or arrangements for sharing data and information among the Bank and the Bank's group companies and/or any other use of data and information in accordance with any group-wide programmes for compliance with any relevant laws and regulations and/or for enhancing employees and/or other personnel engagement or group sharing of resources or personnel; and;
t) all other incidental and associated purposes relating to the above;
Failure to supply or update such data will result in the Bank being unable to process further the matter concerned with respect to the aforementioned purposes, or to continue the business collaboration, servicing, business and/or contractual relationship or arrangement with the entity relating to the data subject.
(2) Personnel Records herein include all records and/or files containing information and/or personal data provided by the data subjects or otherwise to the Bank (including any of their family members as applicable and the case may be) relating to employment and/or engagement applications, the employment and/or engagement, health data, human or other resources management and/or monitoring or security control of any facility, premises, equipment or system. Personal data in the Personnel Records may include (without limitation to) the following:-
a) personal particulars (e.g. name, address, contact details, date of birth, nationality and/or identity card and/or passport details);
b) employment and/or engagement details (e.g. employer, position and nature of position);
c) education and professional qualifications and other information required by the Bank to satisfy the requirements under applicable laws, rules, regulations, policies, codes, circulars, directives, guidelines, guidance and other similar documents;
d) references obtained from current or former employers and/or principals (either directly or via any agent conducting Checks for and on behalf of the Bank and/or any Bank's group company) or other sources;
e) records of remuneration and benefits, job postings, transfer and training, employee surveys, medical checks, leave, medical claims, performance review reports and/or disciplinary records;
f) conduct related information (including but not limited to (i) breach of legal or regulatory requirements; (ii) incidents which cast doubt on the individual's honesty and integrity; (iii) misconduct reports filed with regulators; (iv) internals or external disciplinary actions raising from conduct matters; and (v) ongoing internal investigations) ;
g) relevant health and vaccination status (including but not limited to relevant vaccination proof and related records, proof of medical exemption for relevant vaccination, particular test requirements and results, and relevant infection records), travel histories, quarantine requirements, relevant location information and other relevant close contact information;
h) biometric data (e.g. facial images, fingerprints or otherwise), or data in digital or other format (including, without limitation, records of access to the Bank's premises, computers and/or system servers;
i) provident fund schemes participation (if applicable);
j) tax and insurance information and;
k) other operational and administrative records that contain personal data.
(3) In addition, all Personnel Records may include records and/or files containing information and data provided by (i) any of the Bank's group companies and (ii) suppliers, contractors, sub-contractors, agents, professional advisors, third party service providers, business partners, landlords, tenants, visitors and other contractual` counterparties of the Bank and any Bank's group companies (including the employees and other representatives of the abovementioned parties (as applicable)) in connection with the provision of supplies or services to support the Bank's or any Bank's group company's business, operations and office administration, and the provision of operational, administrative and/or other service support by the Bank or any Bank's group company in the course of business collaboration amongst the Bank and/or the Bank's group companies.
(4) Data held by the Bank on all Personnel Records will be kept confidential but the Bank may provide the same to the following parties, whether within or outside Hong Kong for the purposes set out in paragraph (1) above:-
a) any agent, contractor or third-party service provider who provides administrative, telecommunications, computer, data processing, storage and/or disposal, cloud computing solutions, training, human resources management or any other services to the Bank and/or any Bank's group company in connection with the operation of its or their business or the implementation of the purposes stated in paragraph (1) above;
b) persons seeking employment references in respect of current and former employees with prescribed consent of the employee concerned in accordance with the Ordinance, relevant regulatory requirements and industry guidelines;
c) any other person under a duty of confidentiality to the Bank including any Bank's group company which has undertaken to keep such information confidential;
d) any financial institution, any insurance agent and any medical practitioner providing medical cover for employees and their family members for purposes mentioned in paragraph (1)k) above;
e) any Bank's group company, whether in Hong Kong or elsewhere;
f) any person to whom the Bank or any Bank's group company is required to make disclosure as referred to in paragraphs (1)r) and s) above; and
g) any actual or proposed purchaser of all or part of the business of the Bank or, in the case of any merger, acquisition or other public offering, the purchaser or subscriber for shares in the Bank.
Information disclosed pursuant to the above may be subject to further disclosure by the recipient of such information to other parties (including without limitation auditors and professional advisers) in accordance with the relevant laws and regulations.
(5) Unless otherwise expressly specified, data about a data subject may be retained for a maximum period of seven years from the date when the employment, service and/or other arrangement in relation to the data subject is terminated with the Bank, and for a longer period if there is a subsisting reason that obliges the Bank to do so; and/or the data are necessary for the Bank to fulfill its contractual, legal, compliance, internal audit or regulatory obligations or purposes. The Bank will also retain the Personnel Records in relation to a data subject for additional periods if it is required by any law or regulation to do so, or where the data is required for the Bank and/or any relevant Bank's group company to assert or defend against any legal claims, regulatory review or otherwise in defending the Bank's rights in the use and possession of the information and/or data. In such case, the Bank will retain and use the information and/or data until the end of the relevant retention period or until the claims, review or any action in question have been settled and/or completed to the reasonable satisfaction of the Bank.
(6) Under the Ordinance, a data subject has a right to request access to, and to request correction of, his/her personal data in relation to his/her employment, service and/or other engagement or arrangement with the Bank by making an appropriate written request to the Head of Human Resources of the Bank at 8/F., One International Finance Centre, 1 Harbour View Street, Central, Hong Kong. In accordance with the terms of the Ordinance, the Bank has a right to charge a reasonable fee for the processing of any data access request.