Hong Kong International Corporate Secretaries

Meeting PDPO Compliance Obligations for Your Hong Kong Business

Understand the six data protection principles under Hong Kong's PDPO and how they apply to your business.

PDPO Compliance for Hong Kong Businesses

The Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) governs the collection, use and handling of personal data in Hong Kong. For any business operating in the territory, hong kong pdpo compliance is a legal requirement enforced by the Office of the Privacy Commissioner for Personal Data (PCPD).

The Six Data Protection Principles

The PDPO is built around six data protection principles (DPPs). Each principle imposes a specific obligation on a data user, the person or organisation that controls the collection, holding, processing or use of personal data. A data subject is the individual to whom the data relates.

Data Protection Principle 1 - Purpose and Manner of Collection

Personal data must be collected for a lawful purpose directly related to a function or activity of the data user. The collection must be necessary and adequate but not excessive. The data user must inform the data subject of the purpose, whether the data is obligatory or voluntary, and the consequences of failing to provide it.

Practical example: A Hong Kong retailer collecting a customer’s name and email address for a loyalty programme must state on the sign-up form that the data is voluntary and will be used only for that programme. If the retailer also wants to send promotional offers, it must collect separate consent.

Data Protection Principle 2 - Accuracy and Retention

Personal data must be accurate and kept up to date. It must not be kept longer than necessary for the purpose for which it was collected. A data user must take reasonably practicable steps to ensure accuracy and must delete data once the purpose is fulfilled.

Practical example: An employer holding former employee records for payroll or tax purposes should set a retention schedule. Once the statutory retention period under the Inland Revenue Ordinance expires, the employer should securely destroy the data. Retaining it indefinitely without a valid purpose breaches DPP 2.

Data Protection Principle 3 - Use of Personal Data

Personal data may be used only for the purpose for which it was collected or a directly related purpose, unless the data subject has given prescribed consent. This principle governs internal analytics, sharing with third parties, and any onward transfer.

Practical example: A Hong Kong bank that collects a customer’s income data for a loan application cannot later use that data to market insurance products without the customer’s consent. Any change of use requires a fresh Personal Information Collection Statement (PICS) and consent.

Data Protection Principle 4 - Security of Personal Data

A data user must take all reasonably practicable steps to protect personal data from unauthorised or accidental access, processing, erasure, loss or use. This includes physical, technical and organisational measures.

Practical example: A Hong Kong e-commerce company must encrypt customer payment data, restrict employee access to the database, and have a breach response plan. A failure to patch software or use strong passwords could lead to enforcement action by the PCPD.

Data Protection Principle 5 - Openness

A data user must make publicly available its policies and practices in relation to personal data. This typically takes the form of a privacy policy posted on the company’s website or displayed at its premises.

Practical example: A Hong Kong restaurant that collects customer names and phone numbers for reservations must have a privacy notice explaining what data is collected, why, and how it is protected. The notice should be available at the counter or on the restaurant’s website.

Data Protection Principle 6 - Access and Correction

A data subject has the right to request access to their personal data held by a data user and to request correction of any inaccuracy. The data user must comply with a data access request within 40 days and may charge a reasonable fee. Refusal must be justified under the PDPO.

Practical example: A customer who believes a Hong Kong telecom company holds incorrect billing data can submit a data access request. The company must provide the data or explain why it cannot. If the customer requests a correction, the company must make it or state the grounds for refusal.

Personal Information Collection Statement (PICS)

A PICS is a mandatory notice that a data user must give to a data subject at or before the time of collecting personal data. It must state:

  • The purpose of collection
  • Whether the data is obligatory or voluntary
  • The consequences of failing to provide the data
  • The classes of persons to whom the data may be transferred
  • The data subject’s rights to access and correct the data
  • The name and address of the person handling access requests

Practical example: A Hong Kong gym that collects a member’s health information for fitness assessments must provide a PICS on the membership form. The PICS should explain that the data is voluntary, that it will be shared only with the gym’s trainers, and that the member can request a copy at any time.

Direct Marketing Obligations

The PDPO imposes specific rules on direct marketing. A data user must inform the data subject of the intention to use their data for direct marketing and must obtain consent. The data subject may opt out at any time. The data user must comply without charge.

Practical example: A Hong Kong online retailer that wants to send promotional emails to customers must first obtain their consent. The retailer must include an opt-out mechanism in every email, such as an unsubscribe link. If a customer opts out, the retailer must stop using their data for marketing immediately.

Data Retention and Deletion

Data retention is governed by DPP 2. A data user must not keep personal data longer than necessary. The PCPD recommends that businesses establish a data retention policy specifying retention periods for different categories of data and procedures for secure deletion.

Practical example: A Hong Kong accounting firm that holds client tax records should retain them for seven years under the Inland Revenue Ordinance. After that period, the firm should securely destroy the records. Keeping them indefinitely without a legal basis is a breach.

Data Access Requests

A data subject may submit a data access request to a data user. The data user must respond within 40 days. The request may be made in writing. The data user may charge a fee not exceeding the prescribed amount and must provide a copy of the data or explain why it cannot.

Practical example: A former employee of a Hong Kong company can request access to their personnel file. The company must provide the file within 40 days, redacting any third-party data that is not subject to the request. If the company refuses, it must state the reason under the PDPO.

Enforcement and Penalties

The PCPD can investigate complaints, issue enforcement notices, and prosecute offences. A breach of an enforcement notice is a criminal offence punishable by a fine and imprisonment. The PCPD also has the power to conduct inspections and audits.

Practical example: If a Hong Kong hotel fails to secure guest data and a breach occurs, the PCPD may issue an enforcement notice requiring the hotel to implement specific security measures. Failure to comply could result in prosecution.

Practical Steps for Compliance

  • Appoint a data protection officer or designate a responsible person
  • Conduct a data inventory to map what personal data you hold and why
  • Draft and publish a privacy policy and PICS
  • Train staff on data handling and security
  • Establish a data retention and deletion schedule
  • Implement procedures for handling data access requests and opt-out requests
  • Review and update policies regularly

Further Information

The PCPD website (pcpd.org.hk) provides guidance notes, templates, and a complaint procedure. The Intellectual Property Department (ipd.gov.hk) handles trade mark, patent, and registered design matters, but does not administer the PDPO. For questions about copyright, which arises automatically without registration, refer to the IPD’s copyright page.

The core obligations under the PDPO are set out above. For specific rules on direct marketing consent and opt-out obligations, cross-border data transfers, or service agreements, see the dedicated pages on this site.

Sources

More on ip, contracts & data.

Common questions

What happens if I use customer data for a different purpose?

You may only use personal data for the purpose it was collected for or a directly related one. Using it for a new purpose, like marketing, requires the data subject's prescribed consent. A bank cannot use loan application data for insurance marketing without fresh consent and a new Personal Information Collection Statement.

How long can I keep personal data?

You must not keep personal data longer than necessary for the purpose it was collected. The PDPO recommends establishing a data retention policy. For example, an accounting firm should destroy client tax records after the statutory retention period expires, as keeping them indefinitely without a valid purpose breaches the rules.

What do I need to tell people when I collect their data?

You must provide a Personal Information Collection Statement (PICS) at or before collection. It must state the purpose, whether providing data is obligatory, the consequences of not providing it, who may receive the data, and the data subject's access and correction rights. A gym must include this on its membership form.

What does a customer have to do to see their data?

A data subject can submit a written data access request. You must respond within 40 days, providing the data or explaining why you cannot. You may charge a reasonable fee. For example, a former employee can request their personnel file, and you must comply within the statutory timeframe.

Find a solicitor for this

Trade marks, contracts and data protection are legal work. We list Hong Kong solicitors by practice area, and we do not take a fee for an introduction - the Solicitors' Practice Rules do not permit it.

Browse solicitors