Hong Kong’s Personal Data (Privacy) Ordinance Compliance: A Guide for Businesses
LOGON Software Asia offers complete cybersecurity and data protection solutions to help organizations in Hong Kong and across Asia safeguard their data and systems
Contact us today for your PDPO consultation
The Personal Data (Privacy) Ordinance (PDPO), Cap. 486, is one of Asia’s longest-standing comprehensive data protection laws, in force since 1996. It establishes a robust framework for protecting the privacy of individuals with respect to personal data, giving statutory effect to internationally recognized data protection principles.
For organizations operating in Hong Kong, understanding and complying with the PDPO is not just a legal obligation—it’s a cornerstone of business integrity and customer trust. The ordinance applies to both the public and private sectors and is enforced by the Office of the Privacy Commissioner for Personal Data (PCPD)
Overview of the PDPO
The PDPO regulates the collection, holding, processing, and use of personal data. It applies to any data relating directly or indirectly to a living individual, from which it is practicable to ascertain the individual’s identity, and which is in a form where access or processing is practicable.
Who Must Comply?
The PDPO applies to:
-
Data Users:Â Entities (public or private) that control the collection, holding, processing, or use of personal data in or from Hong Kong.
-
Data Processors:Â Entities processing data on behalf of data users, who must be contractually bound to meet applicable PDPO requirements.
Proposed Amendments (Currently Under Review)
According to the PCPD’s ongoing review, the following amendments are being considered:
-
A mandatory data breach notification mechanism with a reporting timeline of not more than five business days.
-
Direct regulation of data processors.
-
Administrative fines linked to annual turnover.
-
Requirement for data users to formulate express data retention policies.

The Six Data Protection Principles (DPPs)
The PDPO is structured around six Data Protection Principles (DPPs) that outline how data users should collect, handle, and use personal data.
DPP1: Purpose and Manner of Collection
-
Personal data must be collected for a lawful purpose directly related to a function or activity of the data user.
-
Collection must be necessary, adequate, but not excessive for that purpose.
-
The means of collection must be lawful and fair.
-
Data subjects must be informed on or before collection of:
-
Whether data supply is obligatory or voluntary
-
The purposes for which data will be used
-
The persons to whom data may be transferred
-
Their rights to request access to and correction of their data
-
DPP2: Accuracy and Duration of Retention
-
Data users must take all practicable steps to ensure personal data is accurate and up-to-date.
-
Data must not be kept longer than is necessary for the purpose for which it is used.
-
Section 26 of the PDPO makes it an offence (punishable by a fine of up to HK$10,000) to fail to erase personal data no longer required.
DPP3: Use of Data
-
Personal data may only be used for the purposes for which it was collected or a directly related purpose.
-
Use for a “new purpose” requires the prescribed consent of the data subject.
-
Consent can be withdrawn by the data subject via written notice.
DPP4: Data Security (The Security Principle)
-
Data users must take “all practicable steps” to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use.
-
Particular regard must be given to:
-
The kind of data and the potential harm from a breach
-
The physical location where data is stored
-
Security measures incorporated into equipment
-
Measures for ensuring the integrity, prudence, and competence of persons with access
-
Measures for ensuring secure transmission of data
-
-
If engaging a data processor, the data user must adopt contractual or other means to ensure the processor complies with the security requirement.
DPP5: Openness and Transparency
-
Data users must take all practicable steps to ensure openness of their personal data policies and practices.
-
This includes providing general information about the kinds of personal data held and the main purposes for which it is used.
DPP6: Access and Correction
-
Data subjects have the right to request access to and correction of their personal data.
-
Data users must comply with data access and correction requests within the timeframe set out in the PDPO.
-
Data users are required to maintain a log book to record all refusals of access/correction requests.
Key Definitions
| Term | Definition |
|---|---|
| Personal Data | Information relating to a living individual, from which it is practicable to identify that individual directly or indirectly, in a form where access/processing is practicable. |
| Data Subject | The living individual to whom the personal data relates. |
| Data User | An entity that controls the collection, holding, processing, or use of personal data. |
| Data Processor | An entity processing personal data on behalf of a data user, not for its own purposes. |
Key Compliance Requirements
Collection and Processing
-
Data users must provide a Personal Information Collection Statement (PICS) to data subjects on or before collection.
-
Collection must be for a lawful purpose and limited to what is necessary.
-
Data must not be excessive for the stated purpose.
Transfer of Personal Data
-
Use or transfer of personal data for any new purpose requires the data subject’s express and voluntary consent.
-
For direct marketing, specific consent requirements apply under Part 6A of the PDPO.
Security Safeguards
-
“All practicable steps” must be taken to secure personal data.
-
Organizations should implement:
-
Access controls and role-based permissions
-
Encryption for data at rest and in transit
-
Audit logging and monitoring
-
Security risk assessments
-
Data retention and destruction policies
-
Breach Notification (Currently Recommended, Not Mandatory)
-
While not currently a statutory requirement, the PCPD strongly recommends prompt breach handling and notification.
-
The PCPD’s Guidance on Data Breach Handling suggests notifying the PCPD and affected individuals as soon as practicable, particularly if the breach is likely to result in a real risk of harm.
Direct Marketing
-
Data users must obtain informed consent before using personal data for direct marketing or transferring it to a third party for direct marketing.
-
Failure to comply is an offence, punishable by a fine of up to HK$500,000 and imprisonment for 3 years, or up to HK$1,000,000 and 5 years if data is transferred for gain.
Doxxing Offences (2021 Amendment)
-
Two-tier offences were introduced:
-
Disclosing personal data without consent with intent to cause specified harm: up to HK$100,000 fine and 2 years imprisonment.
-
Where specified harm is actually caused: up to HK$1,000,000 fine and 5 years imprisonment.
-
-
The PCPD has powers to issue cessation notices demanding removal of doxxing content and conduct criminal investigations.
Enforcement and Penalties
The PCPD is the designated data privacy regulator with the following enforcement powers:
| Enforcement Action | Description |
|---|---|
| Investigation | May investigate suspected contraventions, publish reports, and make recommendations. |
| Enforcement Notice | May issue notices directing remedial/preventive steps. Contravention is an offence punishable by a fine of up to HK$50,000 and 2 years imprisonment (daily penalty of HK$1,000). |
| Criminal Prosecution | May conduct criminal investigations and prosecute offences (notably doxxing offences). |
| Legal Assistance | May provide legal assistance to data subjects seeking compensation through civil action. |
Offence Penalties Summary:
| Offence | Maximum Penalty |
|---|---|
| Contravention of Enforcement Notice | HK$50,000 + 2 years imprisonment |
| Failure to Erase Personal Data (Section 26) | HK$10,000 fine |
| Doxxing (First Tier) | HK$100,000 + 2 years imprisonment |
| Doxxing (Second Tier) | HK$1,000,000 + 5 years imprisonment |
| Direct Marketing Violations | HK$500,000 + 3 years (or HK$1,000,000 + 5 years for gain) |
How LOGON Software Asia Can Help Different Industries in Hong Kong
The PDPO imposes significant obligations on organizations of all sizes and sectors. LOGON Software Asia’s specialized solutions and services are designed to help your business meet these requirements effectively.
Banking, Financial Services & Insurance (BFSI)
BFSI organizations handle vast amounts of highly sensitive personal data. They are subject to intense regulatory scrutiny and are prime targets for cyberattacks.
How LOGON Can Help:
- Data Classification & Discovery: Technologies to automatically discover, classify, and map personal data across complex IT environments, databases, and cloud storage.
- Identity & Access Management (IAM): Implementing our leading IAM solutions to ensure only authorized personnel can access sensitive data, meeting DPP4 requirements.
- Encryption & Data Masking: Applying strong encryption for data at rest and in transit, along with data masking for non-production environments.
- Audit & Compliance Reporting: Automated tools to generate comprehensive audit trails and reports for the PCPD, demonstrating compliance.
Healthcare & Pharmaceuticals
Healthcare data is extremely sensitive and subject to strict confidentiality requirements. The 2021 doxxing amendments are particularly relevant to healthcare providers.
How LOGON Can Help:
- Advanced Threat Detection: Deploying security monitoring and analytics to detect and respond to threats proactively.
- Data Loss Prevention (DLP): Implementing our leading DLP solutions to prevent unauthorized disclosure of patient data.
- Secure Data Sharing: Implementing secure platforms and protocols for sharing medical data between providers, researchers, and insurers while maintaining compliance.
- Incident Response: Establishing incident response frameworks and technologies to ensure rapid detection and containment of breaches.
E-commerce, Retail & Consumer Goods
These businesses rely heavily on customer data for marketing, personalization, and loyalty programs. Direct marketing consent requirements (Part 6A) are a key compliance area.
How LOGON Can Help:
- Consent Management Platforms: Technologies to capture, manage, and maintain auditable consent records for direct marketing purposes.
- Data Subject Access Request (DSAR) Automation: Solutions to automate the receipt, verification, and response to access and correction requests.
- Lifecycle Management: Automated data retention and deletion policies to comply with DPP2 and Section 26.
- Data Security Posture Management: Tools to continuously monitor data flows and prevent unauthorized access.
Technology & IT Services
Tech companies process massive volumes of personal data and often use complex, multi-cloud environments with extensive third-party integrations.
How LOGON Can Help:
- Data Discovery & Mapping: Automated discovery and classification of personal data across the IT ecosystem.
- Security Automation: Implementing solutions for vulnerability scanning, security responses, and continuous monitoring.
- Vendor Risk Management: Establishing controls and assessment frameworks to ensure third-party processors are PDPO-compliant.
Government & Critical Infrastructure
Government entities and critical infrastructure operators are subject to both the PDPO and the new Protection of Critical Infrastructures (Computer Systems) Ordinance (CIO)
How LOGON Can Help:
- Integrated Compliance: Solutions that address both PDPO and CIO requirements simultaneously.
- Security Risk Assessments: Technologies and expertise to conduct mandated security risk assessments and implement cybersecurity management plans.
- Data Governance Framework: Establishing the technical and organizational framework for data governance aligned with both laws.
- Threat Intelligence & Monitoring: Cutting-edge tools to detect and neutralize threats before they can cause harm.