Skip to main content
PTS Managed Services

PTS Managed Services · Hong Kong

The Hong Kong PDPO compliance checker

If your business holds any personal data — customers, staff, even job applicants — the Personal Data (Privacy) Ordinance applies to you. Pick what best describes your business and the checker shows which duties actually apply, what the penalties are, what the revived reform would change — and turns your answers into an assessment you can keep as a PDF or send to PTS.

Your business

Pick your situation, then answer the basics on the Overview tab — the whole checker tailors itself as you go.

Your business
We serve consumers
customers, members or patients — personal data at volume
What applies
6 principles + 5
further duties, 5 to watch — see What applies
Direct marketing
In scope
Part 6A — offences to HK$500,000, no warning shot
Breach notification
Voluntary today
mandatory notification is in the revived reform package
Readiness
0 of 14
confirmed on the checklist tab

Start here

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

The Personal Data (Privacy) Ordinance has been Hong Kong law since 1996, and it binds every business that holds any personal data — one employee's file is enough. Most of it is manageable once someone owns it. Answer the basics and the checker tailors itself to we serve consumers.

Tell us the basics30 seconds — everything below tailors itself as you answer.
People in Hong Kong
Personal data you hold (select all)
What you're looking to do (select all)
Applies to you
6 principles + 5 duties
Direct marketing rules · Access & correction requests · The duty to delete · Answering for your vendors · Data leaving Hong Kong
Enforced by
The PCPD
4,228 complaints and 246 breach reports in 2025 — both up sharply
The sharp edges
Marketing · DARs
direct offences with no enforcement-notice warning — HK$500,000 territory
What's changing
Reform revived
mandatory breach notification and HK$10M administrative fines proposed — not law yet
Consumer-facing

Volume is your exposure: customer databases, loyalty lists, CCTV, maybe health or payment details — plus Part 6A the moment you market to any of them. The pattern in PCPD breach reports is consumer businesses with more data than anyone remembered collecting. Your first three moves are the data map, the deletion habit and marketing-consent records that would survive a complaint.

Next: the compliance checklist →

How PTS helps

PTS has run IT and security for Hong Kong businesses for over two decades — ISO/IEC 27001 and ISO/IEC 20000 certified, with engineers in Hong Kong, Singapore and mainland China.

A grounded start for we serve consumers

  • A PDPO readiness review against everything in this checker — data map, access, retention, vendors, breach readiness — with a prioritised plan
  • The DPP4 controls implemented, not just recommended: MFA, access control, encryption, monitoring, backup
  • Microsoft 365 retention and search set up so deletion promises and 40-day access requests are enforced by the platform
  • Ongoing managed IT and security for firms without their own department

Your compliance checklist

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

Answer from what you actually know — "Not sure" is a perfectly good answer and usually the honest one. Your answers build the assessment on the next tab and stay in this browser unless you send them.

Foundations

You could list, today, what personal data you hold and which systems it lives in (email, CRM, HR files, shared drives, paper)Why it mattersEvery PDPO duty starts from knowing what you hold — and it's the first thing the PCPD asks after a breach
When you collect personal data, people are told what it's for and who it may go to (a collection statement on forms, sign-ups and contracts)Why it mattersDPP1 requires the notice on or before collection — purpose can't be retro-fitted later
A privacy policy is published — and it matches what you actually doWhy it mattersDPP5 requires openness; a template that doesn't match reality reads as evidence against you
Someone could say how long you keep customer and staff data — and old data actually gets deletedWhy it mattersKeeping data past its purpose is a standing offence (s. 26) and enlarges every future breach
One named person owns privacy — questions, requests and incidents all land on their deskWhy it mattersNo DPO is required by law, but 40-day clocks and breach decisions need an owner before the day they start running

Security

Staff can only open the personal data their job needs — HR files and customer exports aren't on an open shared driveWhy it mattersDPP4's "practicable steps" start with access control; open shares turn one phished account into a full breach
Every account that touches personal data (email, CRM, HR, accounting) requires multi-factor authenticationWhy it mattersStolen credentials sit behind most hacking breaches the PCPD investigates; MFA is the named first fix
Work laptops and phones are encrypted and can be locked or wiped if they walk offWhy it mattersA lost unencrypted laptop is a data breach; a lost encrypted one is usually just lost hardware
Every outside firm that touches your personal data (payroll, IT, mailing, recruiters, cloud apps) is under a contract requiring protection and deletionWhy it mattersDPP2(3) and DPP4(2) make you answerable for your processors — by contract or not at all

People & process

If someone demanded their file tomorrow, you know the 40-day clock, what a valid request looks like, and who handles itWhy it mattersIgnoring a request is an offence — and the clock runs whether or not anyone recognises the letter
There's a written plan for a data breach — who decides, who gets notified, and how to reach the PCPDWhy it mattersNotification is voluntary today, but the reform on the table makes it mandatory — and the first 72 hours decide the damage either way
Marketing lists record that each person was told and didn't object before the first message — and opt-outs take effect immediatelyWhy it mattersPart 6A offences reach HK$500,000 and 3 years, and unlike the principles they need no enforcement notice first
Staff who handle personal data are trained on what the PDPO expects — including what never goes into public AI toolsWhy it mattersMost investigated breaches start with one person's mistake; since 2025 the PCPD expects a written staff AI policy too
You know which systems put personal data outside Hong Kong, and contracts or group policies protect it thereWhy it mattersSection 33 isn't in force, but the principles travel with the data — and clients, auditors and the GBA contract all expect this answered

See your assessment →

Your PDPO compliance assessment

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

We serve consumers · 11–50 people · holding Customers / clients, Staff & job applicants · no goals selected yet

Confirmed
0 of 14
nothing answered yet — the checklist tab takes three minutes
Position
Not yet assessed
answer the checklist to see where you stand
Worth checking
14
answered "not sure" — the first things a readiness review confirms

What you'll likely need

Built from the shape of your business and your goals — each item says why it's there. This is a starting scope, not a quote: PTS validates it in the free readiness review.

Security controls that satisfy DPP4

MFA everywhere, access control that matches job roles, encrypted devices, patching and monitoring — the "practicable steps" the PCPD cites in every breach report.

Because you told us: DPP4 applies to every data user, and it's the principle enforcement actually turns on.

Cross-border data-flow mapping

Which systems put personal data outside Hong Kong, what contracts cover it, and — where the mainland is involved — which Chinese rules apply on the other side.

Because you told us: personal data already sits in systems outside Hong Kong.

Managed IT with compliance built in

For firms without an IT department: the DPP4 controls, retention mechanics and breach response above, run as an ongoing service rather than a project.

Because you told us: at your size, data protection is usually an outsourced function done well or an internal one done late.

Opens your browser's print dialog — choose "Save as PDF". Includes your situation, the duties that apply, your readiness picture and likely needs. Nothing is sent to PTS unless you submit below.

Get your PDPO readiness review — free, engineer-led

Send this to PTS and within two business days we'll come back to arrange a free readiness conversation — an engineer reading your answers the way the PCPD would, then a costed, prioritised plan. Your situation and answers are attached automatically.

Free readiness conversation · Costed plan · No obligation · Goes to our inbox, not a database

What the PDPO asks of you, in plain English

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

Six always-on principles bind every data user, and a second layer of duties switches on with what you actually do — marketing, vendors, offshore systems, HKID copies. Marked applies or watch for your situation. For the legal backdrop see our PDPO explainer and the China & Hong Kong data laws guide.

The six Data Protection Principles — always on

DPP1applies

Collect fairly, for a purpose

Collect personal data lawfully and fairly, only what you actually need, and tell people — on or before collection — what it's for and who it may be passed to. That notice is the Personal Information Collection Statement (PICS).

In practiceEvery form, sign-up page and employment contract that takes personal data needs the statement.

DPP2applies

Keep it accurate — then delete it

Keep personal data accurate, and no longer than the purpose needs. Section 26 backs this with an offence: failing to take practicable steps to erase data you no longer need is itself punishable.

In practiceRetention periods someone can actually recite — and old data that genuinely gets deleted.

DPP3applies

Use it only for that purpose

Use personal data only for the purpose it was collected for (or one directly related). Anything new needs fresh, voluntary consent from the person — the Ordinance calls it prescribed consent.

In practiceThe client list built for delivery can't quietly become a marketing list — that trips DPP3 and the direct marketing rules at once.

DPP4applies

Keep it secure

Take "all practicable steps" to protect personal data against unauthorised access, loss or use — scaled to how sensitive it is. This is the principle the PCPD cites in almost every breach investigation it publishes.

In practiceAccess control, MFA, encryption, patched systems, vendor oversight — DPP4 is where privacy law becomes an IT project.

DPP5applies

Be open about what you do

Make your policies and practices on personal data publicly available — what you hold, what for, how it's protected. In practice: a privacy policy that matches what your business actually does.

In practiceA copied template that says things you don't do is evidence against you, not protection.

DPP6applies

Let people see and correct their data

Anyone can ask for a copy of their personal data and have errors corrected. Part 5 turns this into a machine with a 40-day clock and offences for non-compliance.

In practiceThe Access requests tab covers the clock, the fee rules and the systems reality of finding one person's data.

Further duties for your situation

Part 6A · since 2013applies

Direct marketing rules

Before personal data is first used for direct marketing you must tell the person what data and what kinds of offers are involved, and receive a response indicating no objection — silence is not consent. The first message must offer a free opt-out, and every opt-out binds immediately and permanently. These are direct criminal offences — up to HK$500,000 and 3 years' imprisonment, rising to HK$1,000,000 and 5 years where data is passed to others for gain — with no enforcement-notice warning shot first.

Part 5 · ss. 18–28applies

Access & correction requests

Any individual — customer, employee, ex-employee, complainant — can demand a copy of their personal data. You have 40 calendar days, may charge only costs directly related to and necessary for compliance, and ignoring a request without lawful excuse is an offence. The clock starts when the request arrives, not when someone in the office recognises what it is.

s. 26 + DPP2applies

The duty to delete

When personal data is no longer needed for its purpose, you must take all practicable steps to erase it. Unusually, this one is a standing offence (fine at HK$10,000) rather than principle-only — and every record you keep past its purpose enlarges the breach you might one day have to explain.

DPP2(3) & DPP4(2)applies

Answering for your vendors

The PDPO doesn't regulate data processors directly — it makes YOU answerable for them. When a payroll bureau, IT provider, mailing house or cloud service handles personal data for you, you must use contractual or other means to prevent over-retention and unauthorised access. If your vendor leaks your customer list, the PCPD's questions come to you.

s. 33 · never commencedapplies

Data leaving Hong Kong

Hong Kong has no blanket transfer ban in force — Section 33 was enacted in 1995 and has never been commenced. But the six principles travel with the data: people must be told (DPP1), it must stay secure wherever it sits (DPP4), and offshore processors must be bound by contract. The PCPD publishes recommended model clauses, clients and auditors increasingly expect them — and commencing s.33 is on the revived reform menu.

Worth watching

Code of Practice on the Identity Card Numberwatch

HKID numbers & copies

HKID numbers and card copies have their own PCPD code: collect them only where a statute requires it or the code permits, offer alternatives where practicable, mark copies as copies, and store them with tighter access than ordinary records. Blanket "send us your HKID" onboarding is one of the classic complaint generators.

Voluntary today · reform pendingwatch

Breach handling & notification

There is no general mandatory breach-notification duty in force — notification to the PCPD is voluntary and recommended "as soon as practicable". The revived reform package would change that (notification within around five business days for breaches carrying a real risk of significant harm, backed by administrative fines). Regulated firms often already have reporting clocks from the HKMA, SFC or Insurance Authority; contracts and overseas laws can bind you too.

2021 Amendment · s. 64watch

Doxxing & unlawful disclosure

Since 2021, disclosing someone's personal data to threaten, intimidate or harm them is a criminal offence — up to HK$1,000,000 and 5 years — and the PCPD can investigate, arrest and prosecute. For a business the live risk is usually a staff member weaponising data they had access to, or personal data republished in a dispute. Access control and awareness are the defences.

PCPD guidancewatch

CCTV & employee monitoring

Cameras, door logs and staff monitoring collect personal data like anything else: notices where people can see them, coverage proportionate to a stated purpose, short retention, and restraint with anything covert. Surveillance is a steady stream in the PCPD's complaint statistics — mostly from staff and neighbours, not strangers.

PCPD framework 2024 · checklist 2025watch

AI tools at work

The PCPD's Model Personal Data Protection Framework (June 2024) and its checklist on staff use of generative AI (March 2025) set the expected baseline: know which AI tools are in use, keep personal data out of public models, and put a written policy in front of staff. Pasting a client list into a chatbot is a disclosure — treat it like one.

How PTS helps

Turning duties into a worklist

  • The data map every duty starts from: what you hold, where it lives, who can open it, when it dies
  • DPP4 made real — access control, MFA, encryption and monitoring implemented across your systems
  • Retention and deletion enforced by the platform (Microsoft 365 policies), not by good intentions
  • Working alongside your lawyers where the legal calls sit — we bring the systems reality

Direct marketing: the rules with teeth

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

Part 6A is where the PDPO stops being principles and becomes criminal offences — added in 2013 after the Octopus scandal, and unusual in needing no enforcement-notice warning first. It covers any offer of goods or services aimed at individuals: email, SMS, WhatsApp, calls and post alike.

Step 1 · Before first use

Tell them, specifically

Before personal data is first used for direct marketing, the person must be told what kinds of their data will be used and what kinds of goods or services will be marketed — and given a free way to say no. Burying it in page nine of the terms doesn't meet the "understandable" bar.

Step 2 · Consent

Get a response — silence isn't one

You need the person's response indicating no objection before the first message. Non-response is not consent, and a pre-ticked box proves nothing. Keep the record: who was told what, when, and how they responded — that record is the entire defence.

Step 3 · First message

Offer the exit, free

The first marketing use must inform the person they can opt out at any time, without charge. From then on every opt-out binds immediately and permanently — across channels, not just the one they replied on.

The top tier

Never pass data on for gain

Providing personal data to another business for their marketing requires written consent, and doing it for gain without the steps is the Ordinance's heaviest marketing offence: HK$1,000,000 and 5 years. List-selling, "partner offers" and data-for-commission referrals all live here.

The traps that actually catch businesses

Marketing to existing customers without the steps ("they know us"); B2B campaigns to named individuals ("it's a company email"); the opt-out that was noted in someone's head but not the system; and the CRM built for orders quietly becoming the campaign list — a DPP3 breach and a Part 6A offence in one move. Prosecutions have followed single ignored opt-outs.

How PTS helps

Consent your systems can prove

  • CRM and marketing-platform setup where consent status, source and date live on the record — and exports respect them
  • Suppression lists that actually suppress, across email, SMS and WhatsApp tooling
  • Migration clean-ups: establishing what the inherited list can lawfully be sent before the next campaign goes out

Data breaches: what Hong Kong actually requires

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

Today, notifying the PCPD is voluntary — Hong Kong is one of the last major economies without a general mandatory duty. That is the trap: the reform package on the table makes notification mandatory, regulated firms already have their own clocks, and the PCPD publishes what it finds when it investigates. Build the readiness now and the rule change is a non-event.

PCPD, 2025
246 breach reports
+21% on 2024 — a third involved hacking
Today's rule
Voluntary
notify "as soon as practicable" via the PCPD's e-Data Breach Notification form — recommended, not required
Proposed rule
~5 business days
mandatory notification for breaches with a real risk of significant harm — proposed, not law
Already mandatory for some
Regulated firms
HKMA, SFC and Insurance Authority expectations run on their own clocks — and contracts or GDPR/PIPL can bind you regardless

The first 72 hours, in order

  1. Contain. Isolate the affected system, disable compromised accounts, revoke sessions — and preserve logs and images. Wiping and reinstalling destroys the evidence you'll need for every later decision.
  2. Assess. What data, whose, how many people, how sensitive, still ongoing? "We don't know yet" is a finding — it means logging was the gap.
  3. Decide notifications with facts in hand. The PCPD (voluntary today; prompt notification is regarded favourably and gets you guidance), affected people where there's real risk of harm, your regulator if you have one, your insurer, the Police if it's criminal.
  4. Record everything. Times, decisions, reasons. If the PCPD investigates, the contemporaneous record is the difference between "handled well" and adverse findings.
  5. Fix the cause, not the symptom. The published reports repeat the same roots: unpatched systems, no MFA, flat access, no monitoring. Closing them is cheaper than starring in the next report.
Why notify when it's voluntary?

Because silence has a price: affected people can complain (which starts an investigation anyway), s. 66 lets them claim compensation, and a breach discovered later — by journalists, regulators or the dark web — reads far worse unreported. The PCPD's own guidance and its published reports consistently treat prompt notification as the mitigating factor.

How PTS helps

Readiness you can test

  • An incident response plan written for your actual systems and people — then rehearsed, not filed
  • Monitoring and alerting that spots credential misuse and mass access early
  • Backups that survive ransomware (offline or immutable copies, tested restores)
  • Engineer-led response when something does happen — containment, forensics preservation, recovery

Access requests: the 40-day machine

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

Anyone can demand a copy of their personal data — customer, employee, ex-employee, the counterparty in a dispute. DPP6 grants the right; Part 5 turns it into a process with a 40-calendar-day clock and offences attached. Most requests arrive exactly when relations are worst, so the time to build the process is before one lands.

The ruleWhat it means in practice
40 calendar daysFrom the day the request arrives — not from when someone recognises the letter, and weekends count. If you genuinely can't comply in time you must say so in writing within the 40 days and then comply as soon as practicable.
Fees: cost recovery onlyYou may charge only costs directly related to and necessary for compliance — no commercial or deterrent pricing. Excessive fees are themselves a complaint the PCPD upholds.
Redact, don't refuseLimited exemptions exist — other people's data, legal privilege, some employment evaluations. The expected move is to redact the exempt material and supply the rest, with reasons, not to refuse wholesale.
Form and formalitiesThe PCPD publishes a specified request form (OPS003), but treat any clear written request as live from day one — and take advice before refusing on formalities, because the refusal must be communicated with reasons inside the clock.
Correction requestsSame machine: 40 days to correct proven inaccuracies or annotate disputes, with the same offence exposure for silence.
If you ignore itNon-compliance without lawful excuse is an offence (s. 64A), the person can complain to the PCPD, and s. 66 gives them a compensation route — all for a letter that was never answered.
The real difficulty is search, not law

One person's data is scattered across mailboxes, the CRM, HR files, chat, shared drives, backups and paper. Finding all of it, excluding other people's data, and exporting something readable within 40 days is a systems capability — the firms that struggle aren't unwilling, they're unable. Retention policies that delete on schedule shrink the haystack for every future request.

How PTS helps

A DAR-ready estate

  • Microsoft 365 content search and export set up — one person's data across mail, files, Teams and SharePoint in hours
  • Retention policies that make your deletion promises real (and each future search smaller)
  • A response runbook: validate, clock, search, redact, deliver — so the 40 days are spent working, not deciding

Data leaving Hong Kong: freer than you think — with strings

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

Hong Kong's cross-border restriction (Section 33) was enacted in 1995 and has never been brought into force — so there is no blanket ban on storing personal data offshore, and the global cloud is lawful. What remains is everything the principles already require, wherever the data sits.

Still applies offshore

The principles travel with the data

People must be told where their data may go (DPP1), it must stay secure in the offshore system exactly as at home (DPP4), and an overseas processor must be bound by contract (DPP2(3), DPP4(2)). "It's in the cloud" changes the geography, not the duty.

The expected paperwork

PCPD model clauses

The PCPD's Recommended Model Contractual Clauses (2022) cover both transfer shapes — to another data user, and to a processor. Not mandatory, but they're what clients, auditors and due-diligence questionnaires now ask for, and adopting them early is cheap insurance against s. 33 ever commencing.

Mainland China, southbound

The GBA standard contract

For personal data flowing from the mainland's Greater Bay Area cities into Hong Kong, a dedicated GBA Standard Contract has applied across all sectors since November 2024 — a far lighter path than PIPL's full transfer mechanisms.

Mainland China, northbound

A different rulebook entirely

Sending or hosting personal data INTO the mainland puts you under China's PIPL, CSL and transfer regime — consent-based, threshold-driven and much stricter. If China touches your operation, run our China IT Navigator for that side of the border.

Watch: s. 33 is back on the menu

Commencing the transfer restriction is part of the reform discussion revived in early 2026. Nothing is decided — but a business that already knows its data flows and has model clauses in place would feel a commencement as paperwork, not a project.

How PTS helps

The wider two-regime picture — mainland in, Hong Kong out — is in our guide to China & Hong Kong data laws.

Cross-border flows, mapped and secured

  • A data-flow map: which systems put personal data outside Hong Kong, to whom, under what contract
  • Microsoft 365 and cloud data-residency options weighed on facts — what can stay regional, what genuinely can't
  • The China side handled with our mainland entity and the China IT Navigator's rulebook

Penalties & enforcement: how it actually bites

Showing for We serve consumers · direct marketing · data offshore · vendors in the loop

The PDPO enforces in layers. Breaching a principle brings an enforcement notice — a direction to fix, with a deadline — and defying that notice is the crime. But a second set of duties skips the warning shot entirely: marketing, erasure, access requests and doxxing are direct offences. And running alongside all of it is the register: the PCPD names the businesses it investigates.

What happenedMaximum penaltyWorth knowing
Breaching a Data Protection PrincipleEnforcement notice firstNot directly criminal — the PCPD directs you to fix it, with a deadline. Ignoring that is the offence.
Contravening an enforcement notice (s. 50A)HK$50,000 + 2 years, and HK$1,000/daySecond conviction: HK$100,000 + 2 years, and HK$2,000/day.
Direct marketing without the Part 6A steps (ss. 35C–35L)HK$500,000 + 3 yearsApplies per failure — notice, consent, opt-out info, or an ignored opt-out.
Providing data to others for gain, for their marketingHK$1,000,000 + 5 yearsThe top tier of Part 6A — selling or trading lists.
Failing to erase data no longer needed (s. 26)HK$10,000A standing offence — no enforcement notice needed first.
Not complying with a data access request (s. 64A)HK$10,000Plus the complaint file the PCPD opens, and possible compensation under s. 66.
Doxxing — disclosure intending or causing harm (s. 64)Up to HK$1,000,000 + 5 yearsCriminal; the PCPD itself investigates and prosecutes.
Misusing personal data received in deal due diligence (s. 63B)HK$50,000 + 2 yearsData shared for a transaction must be used for that purpose, then returned or destroyed.
Proposed: administrative fines for serious contraventionsUp to HK$10,000,000 or 10% of turnoverPart of the reform package revived in early 2026 — proposed, not law.

Figures from the PCPD's published table of offences under the Ordinance, checked at 26 August 2026. Individuals — directors, marketers, the employee who took the list — can be prosecuted personally, not just the company.

The register: names the PCPD has published

  • Octopus (2010). Customer data of some two million cardholders passed to business partners for marketing gain — the scandal that produced Part 6A and its HK$1M offences.
  • Cathay Pacific (2019). Enforcement notice over the 2018 breach affecting ~9.4 million passengers — the reference case for what "all practicable steps" (DPP4) is held to mean.
  • Worldcoin (2024). The PCPD found collecting iris images for crypto tokens unnecessary and unfair, and its enforcement notice shut the Hong Kong operation down.
  • Oxfam Hong Kong (2025). Published investigation into a ransomware breach — DPP4 findings on the unglamorous basics: patching, credentials, detection.
  • Yau Yat Chuen Garden City Club (2026). A private club's member data breached and publicly reported on — proof the register reaches well beyond big corporates.

In 2025 the PCPD handled 4,228 complaints (+23% year on year) and 246 breach notifications — enforcement pressure is rising, not falling, while the reform package would add administrative fines on top.

How PTS helps

The fixes enforcement notices order

  • Every published breach report orders the same things: MFA, access control, patching, monitoring, retention discipline — implementing them before the notice is the whole game
  • Evidence on tap: when a questionnaire, auditor or investigator asks, the answers exist in writing
  • A free readiness review that reads your business the way the PCPD would — then a prioritised plan

The questions we're actually asked

Short, factual answers to the PDPO confusions that reach our inbox — from SMEs, regional offices and firms mid-way through a client questionnaire.

Does the PDPO really apply to a small business like ours?

Yes. The Ordinance applies to every "data user" — anyone who controls the collection, holding or use of personal data in Hong Kong. There is no small-business exemption and no registration threshold: one employee's HR file, one customer database or one CCTV camera is enough. What scales with size is the risk, not the duty.

Do we need consent to collect personal data?

Generally no — and this surprises people who know GDPR or China's PIPL. The PDPO is notification-based: you must collect data fairly, for a stated purpose, and tell people that purpose on or before collection. Consent enters in two places: using data for a genuinely new purpose (DPP3) and direct marketing (Part 6A), where you need a response indicating no objection before the first message.

Is data breach notification mandatory in Hong Kong?

Not yet, as a general rule — notifying the PCPD is voluntary, done through its e-Data Breach Notification form, and recommended as soon as practicable. But the reform package revived in early 2026 proposes making notification mandatory within around five business days for breaches carrying a real risk of significant harm. Regulated firms often already have reporting duties from the HKMA, SFC or Insurance Authority, and contracts or overseas laws (GDPR, PIPL) can require notification regardless.

Can we store customer data in the cloud outside Hong Kong?

Yes. The PDPO's cross-border restriction (Section 33) has never been brought into force, so there is no blanket ban on offshore storage. The six principles still apply wherever the data sits: tell people in your PICS, keep it secure (DPP4), and bind the provider by contract (DPP4(2)). For flows into mainland China the direction matters — China's own rules apply, which is a different and stricter story.

What are the actual penalties?

Layered. Breaching a principle brings an enforcement notice; ignoring that notice is an offence (HK$50,000 and 2 years, plus daily fines, doubling on repeat). Direct marketing breaches are immediate offences at HK$500,000 and 3 years — HK$1,000,000 and 5 years if data was passed to others for gain. Failing to erase unneeded data or to answer an access request are offences too, and doxxing reaches HK$1,000,000 and 5 years. The reform package proposes adding administrative fines up to HK$10 million or 10% of turnover for serious cases — proposed, not yet law.

Can we send marketing emails to our existing customers?

Only if the Part 6A steps happened: they were told, before first use, what data of theirs would be used and for what kinds of offers, they responded indicating no objection, the first message offered a free opt-out, and opt-outs are honoured immediately. "They're already a customer" is not an exemption, and prosecutions have followed single ignored opt-outs. If your list can't show who consented to what, fix that before the next campaign.

Can we ask customers or staff for a copy of their HKID?

Only where the PCPD's Code of Practice on the Identity Card Number allows it — typically where a statute requires identification or the code specifically permits it (employment is one, once someone is actually being engaged). Offer less intrusive alternatives where practicable, mark any copy as a copy, restrict who can open it, and never use HKID numbers as customer reference numbers.

Someone has demanded a copy of all their data. Do we have to comply?

Almost certainly yes, within 40 calendar days. You may charge only costs directly related to and necessary for compliance — not a deterrent fee — and you may redact other people's data and genuinely exempt material rather than refuse wholesale. Non-compliance without lawful excuse is an offence, so treat any clear written request as live from the day it arrives and take advice before refusing on formalities.

Do we need a Data Protection Officer?

The PDPO doesn't require one — but it does require things that fail without an owner: 40-day access-request clocks, erasure duties, breach decisions. The PCPD recommends a Privacy Management Programme with someone responsible. For most SMEs the honest answer is one named owner inside the business, with the technical controls run by whoever runs your IT.

Does GDPR or China's PIPL apply to us as well?

Possibly both. GDPR reaches Hong Kong businesses offering goods or services to people in the EU or monitoring them; PIPL reaches you if you sell into the mainland or analyse people there — and data flowing between your Hong Kong and mainland operations has its own transfer mechanics, eased within the Greater Bay Area by a standard contract. If China touches your business, our China IT Navigator maps that side properly.

What should we do in the first hour of a suspected breach?

Contain first: isolate the affected system, disable compromised accounts, preserve logs — don't wipe and reinstall the evidence. Then assess: what data, whose, how many, how sensitive. Then decide notifications with the facts in hand: the PCPD (voluntary today, favourably regarded), affected people where there's real risk, your regulator if you have one, insurers, and the Police if it's criminal. Write everything down as you go — the record you keep is the difference between an incident and an investigation finding.

How PTS helps

Ask us the one that isn't here

  • A thirty-minute conversation with an engineer who builds these controls every week — not a sales call
  • The answer is usually a short list of what to check first

Sources

  1. Personal Data (Privacy) Ordinance (Cap. 486) and the six Data Protection Principles: PCPD, The Ordinance at a Glance and the six DPPs.
  2. Penalty figures: PCPD, Table of criminal offences under the Ordinance (maximum fines and sentences, including Part 6A and s. 50A).
  3. Breach handling: PCPD, Data Breach Notification (e-DBN form) and the Guidance on Data Breach Handling and Data Breach Notifications (revised June 2023).
  4. 2025 caseload: PCPD, media statement, 3 February 2026 — 246 data breach notifications (+21%), 4,228 complaints (+23%).
  5. Reform package (mandatory breach notification, administrative fines, sensitive-data category, possible s. 33 commencement — proposed, not law): summaries by HFW and DataGuidance.
  6. Access requests: PCPD, Proper Handling of Data Access Request and Charging of Data Access Request Fee (40-day clock, cost-recovery-only fees, form OPS003).
  7. HKID handling: PCPD, Code of Practice on the Identity Card Number and other Personal Identifiers.
  8. Cross-border: PCPD guidance on s. 33 and the Mainland law / GBA Standard Contract pages; Hong Kong transfer position summarised by DLA Piper.
  9. AI: PCPD, Artificial Intelligence: Model Personal Data Protection Framework (11 June 2024) and the Checklist on Guidelines for the Use of Generative AI by Employees (31 March 2025).
  10. PTS guides: Hong Kong's PDPO explained · China & Hong Kong data laws · Cybersecurity services · Microsoft 365 security · China IT Navigator.

The PDPO Compliance Checker is a technology and operations reference prepared by PTS Managed Services Limited. It is not legal advice; the reform proposals it describes are not yet law, and the Ordinance's application turns on specifics — verify against current sources and engage qualified Hong Kong counsel before acting. References current at 26 August 2026.

Call Request a proposal