Digital Assets & Virtual Assets
CARF in Hong Kong: What the Crypto-Asset Reporting Framework Means from 2027
A practical guide to the Personal Data (Privacy) Ordinance (PDPO) for businesses operating in Hong Kong, covering data protection principles, PICS requirements, cross-border transfers, PCPD enforcement, and compliance best practices.
Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) has been in force since 1996. It was a pioneering piece of legislation in the Asia-Pacific region, but the explosive growth of digital commerce, cloud computing, and data-driven business models has placed increasing pressure on businesses to rethink how they collect, use, store, and transfer personal data.
The PDPO was significantly amended in 2021 to introduce a mandatory data breach notification regime (effective September 2024), strengthen provisions against doxxing, and expand the enforcement powers of the Office of the Privacy Commissioner for Personal Data (PCPD). These changes, combined with a notable uptick in PCPD investigations and enforcement actions, make PDPO compliance a business-critical priority.
The PDPO defines “personal data” as any data: (a) relating directly or indirectly to a living individual; (b) from which the individual can be directly or indirectly identified; and (c) in a form in which access to or processing of the data is practicable.
This is a broad definition. It covers names, HKID numbers, passport numbers, email addresses, phone numbers, IP addresses, biometric data, CCTV footage, employee records, customer transaction data, and any other data that can be linked to an identifiable individual. Anonymised data (data from which all identifying information has been irreversibly removed) falls outside the definition.
The PDPO establishes six Data Protection Principles (DPPs) with which data users must comply. Data users are businesses and individuals who control the collection, holding, processing, or use of personal data.
Personal data may only be collected for a lawful purpose directly related to a function or activity of the data user. The data collected must be adequate but not excessive for that purpose. The data subject must be informed, on or before collection, of: the purposes for which the data will be used, the classes of persons to whom the data may be transferred, whether the provision of the data is obligatory or voluntary, and the consequences of failing to supply it. This is the purpose and notification requirement.
Data users must take all practicable steps to ensure that personal data is accurate and, where necessary, updated. Data should not be retained longer than is necessary for the fulfilment of the purpose for which it was collected. A retention policy, specifying how long different categories of data are retained and the basis for that retention period, is a key compliance document.
Personal data may only be used for the purpose for which it was collected, or a directly related purpose, without the voluntary and explicit consent of the data subject. This is the “use limitation” principle and is frequently engaged when businesses wish to use customer data collected for service delivery purposes for marketing or secondary analytics.
Data users must take all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use. This DPP requires businesses to implement technical and organisational security measures proportionate to the nature and sensitivity of the data held. Relevant measures include encryption, access controls, regular penetration testing, employee security training, and incident response procedures.
Data users must make available to the public, in general terms, the kinds of personal data held, the main purposes for which the data is held, and the policies and practices regarding personal data. This is typically satisfied through a Privacy Policy Statement published on the business’s website.
Data subjects have the right to request access to their personal data held by a data user (a Data Access Request or DAR) and to request correction of inaccurate data (a Data Correction Request or DCR). Data users must respond to a DAR within 40 days. The maximum fee chargeable for a DAR is currently HK$100. Refusal to comply with a valid DAR is an offence.
A PICS is the notice required to be given to data subjects at or before the point of data collection, satisfying the notification requirements of DPP 1(3). A well-drafted PICS specifies: the types of personal data being collected, the purpose(s) for collection and use, the classes of persons to whom the data may be transferred (including overseas recipients), whether provision is obligatory or voluntary, and the data subject’s access and correction rights.
The PICS should be provided in the language used to communicate with the data subject (Chinese and English for Hong Kong businesses with a mixed customer base). It must be intelligible and written in plain language, not buried in legal boilerplate.
The PDPO contains specific provisions governing the use of personal data for direct marketing. Direct marketing is defined as offering goods, services, facilities, or land, or inviting persons to subscribe, donate, or participate in any activity, through direct communication. Key requirements:
Non-compliance with direct marketing provisions is a criminal offence, and fines can be significant for systematic violations.
Section 33 of the PDPO would restrict the transfer of personal data to a place outside Hong Kong unless one of a prescribed set of conditions is met. It has never been brought into force. Enacted in 1996, it remains uncommenced as at the date of this article, so there is currently no general statutory restriction on transferring personal data out of Hong Kong and section 33 imposes no binding obligation on data users.
That is not the end of the analysis. The PCPD has issued a non-binding guidance note on cross-border transfers together with recommended model contractual clauses, and expects data users to follow them. More importantly, the six Data Protection Principles continue to apply to all personal data held by a Hong Kong data user regardless of where that data is sent, so DPP2 on retention, DPP3 on use and DPP4 on security travel with the data. Our guide to cross-border data transfers covers the position in detail.
In practice, businesses with cross-border data flows should: document the jurisdictions to which personal data is transferred, assess the adequacy of the data protection regime in the destination jurisdiction, and consider implementing data transfer agreements (DTAs) incorporating the PCPD’s recommended model clauses. Businesses operating under GDPR (for European operations or European data subjects) should also ensure their Hong Kong data practices are consistent with GDPR requirements where applicable.
The 2021 amendments introduced mandatory data breach notification. Where a data breach occurs (i.e., unauthorised access, collection, use, disclosure, loss, or disposal of personal data) that is likely to result in real risk of significant harm to the affected data subjects, the data user must notify the PCPD and the affected data subjects as soon as reasonably practicable.
The notification to the PCPD must include: a description of the breach, the categories and approximate numbers of personal data and data subjects concerned, the likely consequences, and the measures taken or proposed to address the breach.
Failure to notify is a civil contravention rather than a criminal offence (at least for a first violation), but the PCPD has significant powers to investigate, issue enforcement notices, and impose financial penalties.
The PCPD can investigate complaints and initiate its own investigations. Following an investigation, the PCPD may issue an Enforcement Notice requiring a data user to remedy a contravention. Non-compliance with an Enforcement Notice is a criminal offence attracting a fine of up to HK$50,000 and imprisonment for up to 2 years.
For direct marketing offences and doxxing offences, the PCPD can refer matters directly to the Police for prosecution. Doxxing offences, which involve disclosing personal data with intent to intimidate, harass, or cause harm to others, carry penalties of up to HK$1 million and 5 years imprisonment.
PDPO compliance is not a one-off exercise but an ongoing programme. With the PCPD’s enforcement posture becoming increasingly assertive, and with mandatory data breach notification now law, businesses that have not yet invested in a structured compliance programme face real regulatory and reputational risk.
The good news is that PDPO compliance need not be burdensome for smaller businesses: a well-drafted PICS, a clear Privacy Policy, a sensible data retention schedule, and a basic incident response plan go a long way towards satisfying the core requirements.
Alan Wong LLP advises businesses on data privacy compliance, PDPO obligations, and regulatory investigations in Hong Kong. Contact us to assess your data privacy posture.
To discuss how this affects your business, please get in touch.
Disclaimer: This article is provided for general information only and does not constitute legal advice. It should not be relied upon as a substitute for specific legal advice on any particular matter. No solicitor-client relationship is created by your access to or use of this article. The law may change, and its application will depend on the specific facts and circumstances of each case. To the fullest extent permitted by law, we accept no responsibility for any loss or damage arising from reliance on this article.

Hong Kong's 2026 Bill rewrites the Unified Fund Exemption, carried interest and FIHV regimes. What it relaxes, the new substance and reporting duties, and the caps most notes get wrong.

How the IRD tests a Hong Kong settlement or re-invoicing entity: source of profits, the offshore claim, substance, transfer pricing and FSIE.