Skip to main content
PTS Managed Services

· Updated · 6 min read · cybersecurity · By

Hong Kong Privacy Laws PDPO

Understand Hong Kong's Personal Data (Privacy) Ordinance (PDPO): the six data protection principles and what businesses must do to stay compliant.

On this page

Hong Kong Privacy Laws PDPO

Hong Kong, Personal Data (Privacy) Ordinance (PDPO)

The Personal Data (Privacy) Ordinance (Cap. 486) has governed how Hong Kong organisations collect, hold, use and secure personal data since 1996. It is enforced by the Privacy Commissioner for Personal Data (PCPD), and every organisation that controls personal data is a “data user” bound by it. For an IT team the practical question is not what the law says in the abstract but which systems and controls each duty lands on. That is what this guide sets out.

The six Data Protection Principles

Schedule 1 of the Ordinance sets out six Data Protection Principles (DPPs). Breaching a DPP is not itself an offence, but the PCPD can issue an enforcement notice, and ignoring one is. The six are:

  1. DPP1: Purpose and manner of collection. Collect personal data only for a lawful purpose directly related to your activities, collect no more than you need, and tell people at or before collection what it is for and who it may be passed to (the “Personal Information Collection Statement”).
  2. DPP2: Accuracy and duration of retention. Keep data accurate and hold it no longer than the purpose requires. Data users are also answerable for how long their processors keep it.
  3. DPP3: Use of personal data. Use it only for the purpose it was collected for, or a directly related one, unless the person gives fresh, voluntary consent.
  4. DPP4: Security of personal data. Take all practicable steps to protect it against unauthorised or accidental access, processing, erasure or loss, scaled to how sensitive it is. Processors must be bound by contract to the same standard.
  5. DPP5: Openness (information available). Publish your policies and practices on personal data, what kinds you hold and what you use them for. In practice, a privacy policy that matches what you actually do.
  6. DPP6: Access and correction. Individuals may ask whether you hold data about them, obtain a copy, and have errors corrected. Access requests must be answered within 40 days.

Two things people often assume are principles are not. Cross-border transfer restrictions sit in section 33 of the Ordinance, which was enacted in 1995 but has never been brought into force; the PCPD instead publishes recommended model contract clauses. And the direct-marketing rules are a separate part of the Ordinance (Part 6A) with their own offences, not a DPP.

These principles bind every data user in Hong Kong, but they weigh heaviest where personal data is most concentrated and sensitive — much of the work of family office IT support in Hong Kong, for example, is engineering these six obligations into everyday systems.

Free interactive tool

Reading up on the PDPO? Check where your business actually stands

The PDPO Compliance Checker turns this article into action: pick your situation, see which duties apply — marketing rules, access requests, breach handling, the real penalty figures — and self-assess with a Yes/No/Not-sure checklist you can keep as a PDF. Practical guidance, not legal advice.

Open the PDPO Checker →

What each principle means for IT

The Ordinance does not prescribe technology, so the IT team’s job is to map each principle to a control it can evidence. This is how we approach it, and it is not legal advice; your legal adviser owns the interpretation.

  1. Collection (DPP1): know every point where personal data enters the estate, from web forms and CRM to HR onboarding, and make sure a collection statement sits at each one. Database and form design matter here: fields you cannot justify are data you should not be collecting.
  2. Retention (DPP2): set retention periods per data type and make systems enforce them. Microsoft 365 retention labels, mailbox archive policies and scheduled purges of old HR and customer records turn a policy into something a regulator can see working.
  3. Use (DPP3): keep data in the system it was collected for. The delivery database becoming the marketing list is the classic DPP3 breach, so access to exports and integrations between systems should be deliberate, not open by default.
  4. Security (DPP4): this is where most enforcement action lands. Access control and least privilege, multi-factor authentication, encryption at rest and in transit, patching, backup, logging, and vendor oversight are the baseline. Regular security audits and, for Microsoft 365 users, a Microsoft 365 security review check these controls against what the PCPD has held “all practicable steps” to mean in published investigations.
  5. Openness (DPP5): the published privacy policy has to describe what the systems actually do. When IT changes how data is stored or processed, the policy needs to change with it, which means legal and IT reviewing it together.
  6. Access and correction (DPP6): be able to find every record about one person across mailboxes, file shares, CRM and backups, and produce it within 40 days. Content search in Microsoft 365 and a clean data map make this routine; without them, the first access request is a scramble.

Two cross-cutting points sit above the six. Data flow mapping, especially where data leaves Hong Kong to cloud regions or mainland offices, tells you which contracts and clauses you need. And training: every administrator and technician who can touch personal data needs to understand these duties, because the PCPD’s published breach investigations almost always trace back to basic practice rather than exotic attacks.

PDPO and the Future of IT in Hong Kong

As global attention shifts towards data protection, with regulations like the GDPR in Europe setting precedents, the PDPO is likely to undergo further refinements. It is also worth understanding how the PDPO fits with mainland China’s laws, which apply very differently across the border. IT departments must remain agile, anticipating changes and staying ahead of the curve.

Moreover, there’s an undeniable reputation factor. In an age where data breaches make headlines, adherence to the PDPO isn’t just about legal compliance. It’s a testament to a business’s commitment to ethical practices, fostering trust among clients and stakeholders. Nowhere is that sharper than in professions built on confidentiality — for a law firm the PDPO is only the floor, which is why IT for law firms treats matter confidentiality, not just compliance, as the design centre.

The PDPO as a Catalyst for IT Innovation

While the challenges posed by the PDPO are numerous, they also open doors for innovation. The demand for compliant IT tools and platforms spurs innovation, creating avenues for startups and tech giants to introduce groundbreaking solutions tailored to the PDPO’s mandates.

Moreover, as IT departments delve deeper into data management strategies, they often uncover inefficiencies in existing systems, paving the way for optimisation and modernisation.

Concluding Thoughts

The Personal Data (Privacy) Ordinance is not just a legislative document; it’s a vision for a digital Hong Kong where data privacy isn’t an afterthought but a foundational principle. For IT professionals, this is both a challenge and an opportunity. By wholeheartedly embracing the PDPO, they’re not just ensuring compliance but steering Hong Kong’s IT landscape towards a future that’s secure, efficient, and above all, respectful of individual privacy.

If you need help or advice related to this topic please get in touch with us here.

Tags:

cybersecuritycloudit-procurementmanaged-itcompliancehong-kong

Relevant service

IT for Law Firms

Confidentiality-first IT for Hong Kong law firms — matter security, document management and multi-office connectivity.

Explore IT for Law Firms →

Related reading

Want practical help on this?

Tell us what you're trying to do. We'll come back with practical advice and, where it helps, a costed proposal — no sales pitch.

Talk to PTS

No obligation · Prefer a quick call? +852 3658 5000

Call Request a proposal