Hong Kong International Corporate Secretaries

Understanding Cross-Border Data Transfer Obligations Under Hong Kong Law

Understand how Hong Kong's PDPO governs cross-border data transfers and what obligations apply.

Hong Kong Cross-Border Data Transfer Rules

The Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) does not contain a specific provision that directly prohibits or restricts the transfer of personal data outside Hong Kong. However, the six data protection principles apply extraterritorially, meaning a data user in Hong Kong remains responsible for personal data once it is transferred overseas. Understanding the hong kong cross-border data transfer obligations requires examining how the data protection principles operate when data leaves the jurisdiction. A data user must ensure that the overseas recipient handles the data in a manner that would comply with the PDPO if the recipient were in Hong Kong.

Hong Kong Data Transfer Overseas

When a data user transfers personal data to a recipient outside Hong Kong, the data user remains the party accountable under the PDPO. The data protection principle on security (principle 4) requires a data user to take all reasonably practicable steps to ensure that personal data is protected against unauthorised or accidental access, processing, erasure, loss or use. This obligation extends to the overseas recipient. A data user should therefore assess whether the recipient has adequate security measures in place, and should consider contractual clauses that require the recipient to maintain equivalent safeguards.

The data protection principle on use (principle 3) also applies. Personal data may only be used for the purpose for which it was collected, or a directly related purpose, unless the data subject has given prescribed consent. If the overseas recipient intends to use the data for a different purpose, the data user must obtain the data subject's consent before the transfer.

Cross-Border Personal Data Hong Kong

The PDPO does not require a data user to notify the Privacy Commissioner before transferring personal data overseas, nor does it impose a mandatory data transfer agreement regime similar to the European Union's General Data Protection Regulation. Instead, the obligation is practical: the data user must take steps that are reasonable in the circumstances to ensure the overseas recipient complies with the data protection principles.

Common scenarios include cloud storage services where a Hong Kong company stores customer data on servers located in another jurisdiction. In such cases, the data user should review the cloud provider's security certifications, data location policies, and contractual terms. If the provider subcontracts data processing to another party, the data user should ensure that the contract imposes equivalent obligations on any subcontractor.

Another scenario is intra-group data sharing, where a Hong Kong subsidiary transfers employee or customer data to a parent company abroad. The data user should document the purpose of the transfer, confirm that the overseas entity has appropriate security measures, and obtain consent from data subjects if the use of the data differs from the original collection purpose.

PDPO Data Transfer Restrictions

Although the PDPO lacks a specific cross-border transfer restriction, the data protection principles create indirect restrictions. Principle 1 (collection) requires that personal data be collected for a purpose directly related to the function or activity of the data user, and that the means of collection be fair. If a data user collects data with the intention of transferring it overseas for a purpose that is not directly related to its own function, the collection may breach principle 1.

Principle 2 (accuracy and retention) requires that personal data be accurate and not kept longer than necessary. A data user transferring data overseas should ensure that the recipient does not retain the data beyond the period required for the original purpose. The data user should include a data retention clause in the agreement with the overseas recipient.

Principle 5 (openness) requires a data user to make available its policies and practices in relation to personal data. A data user that transfers data overseas should disclose this practice in its privacy policy.

Data Protection Principle and Extraterritorial Application

The PDPO applies to a data user that controls the collection, holding, processing or use of personal data in or from Hong Kong. The Office of the Privacy Commissioner for Personal Data (PCPD) has stated that the Ordinance applies to a data user that transfers personal data outside Hong Kong, because the data user continues to exercise control over the data. The data user must therefore take steps to ensure that the overseas recipient complies with the data protection principles.

The PCPD has issued guidance on cross-border data transfers, recommending that data users conduct a due diligence assessment of the overseas recipient, enter into a written data transfer agreement, and implement measures to monitor the recipient's compliance. The guidance is not legally binding but represents the PCPD's interpretation of the PDPO.

Personal Information Collection Statement and Consent

A data user must provide a Personal Information Collection Statement (PICS) to a data subject at or before the time of collection. The PICS must state the purpose of collection, the classes of persons to whom the data may be transferred, and whether the data subject may request access to or correction of the data. If the data user intends to transfer the data overseas, the PICS should identify the jurisdictions to which the data may be transferred and the purpose of the transfer.

Consent is required if the data user intends to use the data for a new purpose that is not directly related to the original collection purpose. For example, if a data user collects customer data for order fulfilment and later wishes to transfer the data to an overseas marketing affiliate, the data user must obtain the data subject's prescribed consent. The consent must be freely given and specific to the new purpose.

Direct Marketing and Opt-Out Obligations

The PDPO contains specific provisions on direct marketing. A data user must inform the data subject of its intention to use the data for direct marketing, provide the data subject with an opportunity to opt out, and obtain the data subject's consent if the data user intends to transfer the data to a third party for direct marketing. These obligations apply regardless of whether the direct marketing activity occurs in Hong Kong or overseas. A data subject may require the data user to cease using the data for direct marketing at any time, and the data user must comply without charge.

Intellectual Property Department and Related Considerations

The Intellectual Property Department (IPD) administers trade marks, patents and registered designs in Hong Kong. While the IPD does not regulate data transfers, a data user that holds personal data relating to intellectual property matters, such as trade mark applicants or patent filers, must comply with the PDPO when transferring that data overseas. For example, if a trade mark agent transfers client data to a foreign associate for filing purposes, the agent must ensure that the overseas associate handles the data in accordance with the data protection principles.

Copyright protection in Hong Kong arises automatically upon creation. There is no registration system and no register to search. A data user that transfers copyright-related personal data, such as author information or licensing records, must still comply with the PDPO.

Practical Steps for Compliance

A data user transferring personal data overseas should take the following steps:

  1. Identify all overseas recipients and the purposes of the transfer.
  2. Conduct a due diligence assessment of each recipient's data security measures.
  3. Enter into a written agreement that requires the recipient to comply with the data protection principles.
  4. Include a data retention clause specifying the period after which the data must be deleted or returned.
  5. Update the privacy policy and PICS to disclose the transfer.
  6. Obtain consent from data subjects if the transfer involves a new use of the data.
  7. Monitor the recipient's compliance through periodic audits or reports.

The PCPD provides guidance and sample clauses on its website. A data user should consult the guidance and, where appropriate, seek legal advice on the specific transfer arrangement.

Sources

More on ip, contracts & data.

Common questions

Can I transfer personal data outside Hong Kong?

Yes, the Personal Data (Privacy) Ordinance does not directly prohibit cross-border data transfers. However, you remain responsible for the data under the six data protection principles. You must ensure the overseas recipient handles the data in a way that complies with the Ordinance, including taking reasonable security steps and using the data only for its original purpose.

Do I need consent to send data to my parent company overseas?

Consent is required only if the overseas entity will use the data for a new purpose not directly related to the original collection. If the purpose remains the same, you do not need new consent. You should still document the transfer, ensure the parent company has adequate security measures, and update your privacy policy to disclose the practice.

What should I put in my privacy policy about overseas transfers?

Your privacy policy must disclose that you transfer personal data overseas. Under principle 5 (openness), you should make your policies available. Your Personal Information Collection Statement should also state the jurisdictions to which data may be transferred and the purpose of the transfer, informing data subjects at the time of collection.

What happens if I use data for overseas direct marketing?

You must inform the data subject of your intention to use their data for direct marketing and provide an opt-out opportunity. If you transfer the data to a third party for this purpose, you must obtain the data subject's consent. These obligations apply whether the marketing occurs in Hong Kong or overseas, and you must comply with opt-out requests without charge.

Find a solicitor for this

Trade marks, contracts and data protection are legal work. We list Hong Kong solicitors by practice area, and we do not take a fee for an introduction - the Solicitors' Practice Rules do not permit it.

Browse solicitors