Compliance Node Overview
Hong Kong's Personal Data (Privacy) Ordinance (PDPO) - Cap. 486 of the Laws of Hong Kong - was enacted by the Legislative Council in 1995 and came into operation on 20 December 1996, making Hong Kong one of the first jurisdictions in Asia to enact comprehensive personal data protection legislation. The PDPO continues in force as Hong Kong law under the 'one country, two systems' constitutional arrangement, which preserves Hong Kong's distinct common law legal system and independent regulatory institutions under the Basic Law. The enforcement authority is the Office of the Privacy Commissioner for Personal Data (PCPD), an independent statutory body established under the PDPO. Privacy Commissioner Ada Chung Lai-ling was appointed in October 2020 and reappointed in 2023. The PDPO has been amended significantly twice: the 2012 amendments (Personal Data (Privacy) (Amendment) Ordinance 2012) introduced direct marketing restrictions requiring opt-in consent for sensitive personal data marketing, data processor accountability obligations, and enhanced PCPD enforcement powers including administrative fines; and the 2021 amendments (Personal Data (Privacy) (Amendment) Ordinance 2021) introduced criminal doxxing offences, cessation notices empowering the PCPD to compel platforms and service providers to remove doxxing content, and significantly enhanced criminal penalties. Key features of Hong Kong PDPO: (1) Six Data Protection Principles (DPPs) - the PDPO prescribes six principles for all personal data processing: DPP 1 (Purpose and manner of collection of personal data - data must be collected for a lawful purpose, limited to what is necessary, and collected by fair and lawful means with the data subject's knowledge); DPP 2 (Accuracy and retention - data must be accurate, not retained longer than necessary for the purpose); DPP 3 (Use of personal data - data may only be used for the purpose for which it was collected or a directly related purpose, unless the data subject has voluntarily provided written consent); DPP 4 (Security of personal data - data controllers must take practicable steps to protect personal data against unauthorised or accidental access, use, or disclosure); DPP 5 (Information to be generally available - data controllers must make a privacy policy available); DPP 6 (Access to personal data - data subjects have the right to access and correct personal data held about them); (2) Direct marketing - use of personal data for direct marketing requires: opt-out notification at first contact; explicit opt-in consent for sensitive personal data (including health, financial, and certain biometric data) used for direct marketing; data controllers must inform data subjects of their right to opt out at no charge; (3) Data processor obligations - data controllers must adopt contractual or other means to prevent unauthorised or accidental access, processing, or disclosure by data processors; data processors are subject to criminal liability for certain breaches; (4) Doxxing offences - the 2021 amendments created specific criminal offences for doxxing (disclosing personal data of a data subject without consent with intent to cause harm): penalties up to HKD 1 million and 5 years imprisonment; the PCPD may issue cessation notices requiring platforms to remove doxxing content; (5) Enforcement notices - the PCPD may issue enforcement notices requiring data controllers to cease or remedy contravention; non-compliance with an enforcement notice is a criminal offence; (6) Data subject rights - data subjects may access personal data using a data access request (PCPD Form OPS003) and request correction of inaccurate personal data; data controllers must respond within 40 days; (7) Criminal penalties - specific offences under the PDPO carry criminal penalties including fines and imprisonment; (8) Cross-border data transfer - the PDPO empowers the PCPD to specify countries or territories to which personal data may not be transferred; the PCPD may issue prohibition notices for transfers to jurisdictions without adequate protection. Hong Kong's PCPD is an active regulator, issuing investigation reports, codes of practice (including the Employee Monitoring Code, the Credit Reference Agency Code), and guidance on emerging topics including AI, cloud computing, and children's privacy.
Pillar: Cybersecurity · Authority: Office of the Privacy Commissioner for Personal Data (PCPD, Hong Kong) · Version: 1.0.0 · Last updated:
Primary source: https://www.pcpd.org.hk/
SHA-256 integrity: 514f696d0d30934a60b37c8f72e6cafbc3e9a7d4bcf41331a1002c01630f5bfb
Primary Citations — 7 traced to source
- Personal Data (Privacy) Ordinance (PDPO, Cap. 486, Laws of Hong Kong) - in operation 20 December 1996; six Data Protection Principles (DPPs): DPP 1 (purpose and manner of collection including Personal Information Collection Statement), DPP 2 (accuracy and retention), DPP 3 (use limited to collection purpose), DPP 4 (security safeguards), DPP 5 (openness - privacy policy), DPP 6 (data subject access and correction rights within 40 days using PCPD Form OPS003); data controller accountability for data processors; enforcement notices; criminal penalties for doxxing and PDPO offences; cross-border transfer prohibition powers
- Personal Data (Privacy) (Amendment) Ordinance 2012 (Hong Kong) - introduced direct marketing restrictions: opt-out at first contact, explicit opt-in for sensitive personal data marketing, prohibition on data provision to third parties for direct marketing without consent, prohibition on data sale; data processor accountability obligations: data controllers must adopt contractual controls over processors; enhanced PCPD enforcement powers; criminal liability extended to data processors for unlawful disclosure
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access