🇭🇰Hong Kong

HK-PDPO

Personal Data (Privacy) Ordinance

Office of the Privacy Commissioner for Personal Data

Hong Kong overview

Hong Kong's data compliance framework is built around the PDPO and six Data Protection Principles

Hong Kong's personal data regime is anchored by the Personal Data (Privacy) Ordinance, Cap. 486. The Ordinance protects privacy in relation to personal data and establishes the Privacy Commissioner for Personal Data as the regulator. Its operating model is different from GDPR-style laws: instead of a list of lawful bases, the Ordinance regulates data users through six Data Protection Principles that govern collection, accuracy, retention, use, security, openness, access and correction.

This makes Hong Kong compliance highly practical. The central question is not whether the organisation has selected the correct lawful basis from a menu. The central question is whether the organisation can show that its personal data practices are necessary, fair, transparent, purpose-limited, secure and responsive to individual rights.

The three pillars to understand first

The Personal Data (Privacy) Ordinance, Cap. 486 answers the legal question: who is responsible for personal data and what duties attach to that responsibility? The core regulated actor is the data user - the person who controls the collection, holding, processing or use of personal data. A person processing data only on behalf of another, and not for their own purposes, is not treated as the data user for that data, but the data user must still control processor retention and security risks through contractual or other means.

Schedule 1 Data Protection Principles answer the operational question: what must the organisation actually do? The principles require lawful and fair collection, collection that is necessary and not excessive, notice at collection, accuracy, retention limitation, no new-purpose use without prescribed consent, security safeguards, transparency about personal data policies and practices, and access and correction rights.

The Privacy Commissioner for Personal Data answers the enforcement question: who supervises the framework? The Commissioner monitors and supervises compliance, promotes codes of practice, carries out inspections and investigations, issues enforcement notices, and has enhanced powers in relation to harmful disclosure and doxxing-related offences under the 2021 amendments.

How these elements work together

A Hong Kong privacy programme should be organised around data flows. At collection, the data user must identify the lawful purpose, confirm that the data is necessary and not excessive, and provide the required notice. During use, the data user must ensure that personal data is used only for the original or directly related purpose unless prescribed consent for a new purpose has been obtained. During storage and processing, the data user must protect the data and control processors. At the end of the lifecycle, data must not be kept longer than necessary.

Direct marketing requires a separate workflow. Before using personal data for direct marketing, the data user must give prescribed information about the intended use, identify the kinds of data and classes of marketing subjects, and provide a free channel for consent. If personal data is provided to another person for that person's direct marketing, the provision rules apply separately. Cessation requests must be honoured without charge.

Cross-border transfers require careful wording. Section 33 contains a detailed transfer restriction, but the Ordinance marks it as not yet in operation. Even so, overseas transfers are not risk-free. They still need to be consistent with the notified purpose, purpose limitation, security requirements, processor controls and any consent commitments made to the data subject.

What organisations should prioritise

Start with a personal data inventory mapped to purpose. For each category of data, identify the data user, the collection purpose, the notice given to the individual, the classes of transferees, retention period, processor arrangements and access/correction workflow. Then test every secondary use - analytics, profiling, internal investigations, marketing, group sharing, vendor use and cross-border hosting - against Principle 3's new-purpose rule.

For organisations using personal data in marketing, build a dedicated Part 6A compliance process. General privacy notice language is not enough. The process must capture the intended marketing use, kinds of personal data, classes of marketing subjects, whether data will be provided to another person, whether that provision is for gain, the consent channel and the mechanism to honour opt-out or cessation requests.

For organisations using vendors, cloud platforms or offshore service centres, processor control is the main operational issue. Contracts should cover retention limits, access controls, security measures, deletion or return obligations, breach escalation, audit cooperation and restrictions on further use. Hong Kong's framework makes the data user responsible for adopting contractual or other means; a generic vendor agreement will often be too weak.

Key Hong Kong Laws

Personal Data (Privacy) Ordinance, Cap. 486 - the core personal data protection law governing data users and establishing the Privacy Commissioner for Personal Data.

Schedule 1 Data Protection Principles - the operational rules for collection, accuracy, retention, use, security, openness, access and correction.

Part 6A Direct Marketing Provisions - specific rules for using personal data in direct marketing and providing personal data to another person for direct marketing.

Section 64 and Part 9A - harmful disclosure and doxxing-related offences, together with investigation powers, cessation notices and injunctions introduced through the 2021 amendments.

Part 8 Exemptions - targeted exemptions for areas such as domestic purposes, crime, health, legal professional privilege, legal proceedings, news activity, statistics and research, due diligence and emergency situations.

What this means for you

Hong Kong compliance is an operating discipline. The organisation must know why it collects each item of personal data, what it told the individual, how the data is used, who receives it, how long it is retained, how vendors are controlled, and how access and correction requests are handled. The law-specific writeup explains the PDPO in detail; the country controls should translate that into data inventory, purpose mapping, direct marketing controls, processor contracts, retention rules and rights-response workflows.