Understanding Hong Kong Data Privacy Laws

15/05/2026  | 

Personal Data (Privacy) Ordinance (PDPO)

Enacted in 1996 and amended multiple times since, the PDPO is Hong Kong’s primary data protection legislation. It applies to the collection, holding, use, and disclosure of personal data by both public and private sector organisations.

Key Principles

The PDPO establishes 8 Data Protection Principles (DPPs):

  1. Purpose and Manner of Collection: Personal data must be collected lawfully and by fair means, only for specified purposes directly related to the organisation’s functions.
  2. Quality of Data: Data should be accurate, complete, and not misleading.
  3. Retention: Data should only be retained as long as necessary for the original purpose or a directly related purpose.
  4. Security: Organisations must take practical steps to protect personal data from loss, unauthorised access, or disclosure.
  5. Use and Disclosure: Data should only be used for the purpose for which it was collected, unless the individual consents to additional uses.
  6. Right of Access: Individuals have the right to request access to their personal data held by an organisation.
  7. Right to Correction: Individuals can request correction of inaccurate personal data.
  8. Accountability: Organisations must be able to demonstrate compliance with all other principles.

Role of the Privacy Commissioner

The Privacy Commissioner for Personal Data (PCPD) is responsible for administering the PDPO, investigating complaints, and providing guidance on data protection matters.

Compliance Steps for Businesses

  1. Conduct a personal data audit to identify what data you collect and how it’s used
  2. Implement appropriate technical and organisational security measures
  3. Establish procedures for handling data subject access requests
  4. Train staff on data protection requirements
  5. Review and update privacy policies regularly
  6. Notify the PCPD of any personal data breach within a reasonable timeframe