🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
HK v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing16 sources retrieved model claude-sonnet-5 · 2026-08-03

Not every instrument is backed by its official text yet. At least one law or rulebook covered here has no official source (tier 1) retrieved for it yet. No finding on this page is shown with confidence above “Probable” until stronger sources are retrieved.

Hong Kong

HK schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 48 claims · 25 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
48Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Hong Kong's data-protection-adjacent regulatory architecture expanded this cycle with the commencement of a distinct cybersecurity instrument, even as the core Personal Data (Privacy) Ordinance regime itself did not change. The Protection of Critical Infrastructures (Computer Systems) Ordinance came into full force on 1 January 2026, establishing a cybersecurity-for-critical-infrastructure regime that sits alongside, but separately from, the Personal Data (Privacy) Ordinance overseen by the Privacy Commissioner for Personal Data. The Privacy Commissioner, not mainland China's Cyberspace Administration, remains the supervisory authority for Hong Kong's data-protection regime, the two operating as separate systems under the 'one country, two systems' constitutional arrangement.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator/statute framework is well-established (green-equivalent), but material and territorial scope diverge substantially from GDPR baseline, and a registration/filing sub-module could not be evidenced, warranting amber overall.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486)
Traffic-light rationale — AmberCore regulator/statute framework is well-established (green-equivalent), but material and territorial scope diverge substantially from GDPR baseline, and a registration/filing sub-module could not be evidenced, warranting amber overall.

Sub-modules (5)

Regulator And AuthorityGreen

PCPD is the statutory regulator headed by the Privacy Commissioner, with investigative and enforcement powers under the PDPO.

Claims (1):

  • The Office of the Privacy Commissioner for Personal Data (PCPD) is the main body responsible for overseeing enforcement of the PDPO and is headed by the Privacy Commissioner for Personal Data.

Act And InstrumentsGreen

PDPO Cap. 486 (in force since 1996) is the principal instrument, materially amended in 2012 (direct marketing) and 2021 (anti-doxxing).

Claims (1):

  • The Personal Data (Privacy) Ordinance (Cap. 486) came into force on 20 December 1996 and was significantly amended by the 2012 Amendment Ordinance (direct marketing) and the 2021 Amendment Ordinance (anti-doxxing).

Material ScopeAmber

PDPO scope centers on Data Protection Principles (DPPs) governing collection, holding, processing and use of personal data by 'data users'.

Claims (1):

  • Data Protection Principle 1(1) requires that only necessary, adequate and not excessive personal data be collected for a lawful purpose, forming part of PDPO's core material-scope obligations on data users.

Territorial ScopeAmber

PCPD has clarified PDPO has no extraterritorial scope; it applies where the data user's principal place of business is in Hong Kong.

Claims (1):

  • The PDPO is unclear on its territorial scope on its face, but the PCPD has clarified that the PDPO does not have extraterritorial scope, in contrast to the GDPR's extraterritorial application.

Regulator Registration And FilingRed

No evidence located of a general controller registration/filing obligation to PCPD akin to EU-style DPA registers.

Absence provenance: unavailable. Searched: PCPD registration requirement data user Hong Kong, PDPO controller notification filing obligation.

Category narrative75 words

Hong Kong's data protection regime is anchored in the Personal Data (Privacy) Ordinance (Cap. 486), a comprehensive omnibus statute enforced by the Privacy Commissioner for Personal Data (PCPD). The PDPO has no extraterritorial reach and applies to data users with a principal place of business in Hong Kong. Unlike GDPR-model regimes, PDPO does not impose a general registration/filing obligation on data users; no direct evidence of such a regime was found in this research pass.

Periodic update · new data 2026-09-28

Regulator & Framework

Hong Kong's data-protection framework continues to rest on the Personal Data (Privacy) Ordinance, supervised by the Privacy Commissioner for Personal Data. The Privacy Commissioner, not mainland China's Cyberspace Administration, is confirmed as the supervisory authority for this Ordinance, with the two regimes operating entirely separately under the 'one country, two systems' constitutional arrangement — a standing baseline fact with no change this cycle.

The material development this cycle is the commencement of a separate, adjacent instrument: the Protection of Critical Infrastructures (Computer Systems) Ordinance came into full force on 1 January 2026. This Ordinance establishes a cybersecurity-for-critical-infrastructure regime that is structurally distinct from, and sits alongside, the Personal Data (Privacy) Ordinance rather than amending or extending it. Organisations that qualify as operators of critical infrastructure computer systems now face obligations under this new Ordinance in addition to, not instead of, their existing Personal Data (Privacy) Ordinance obligations where personal data is involved. This is an escalating regulatory-framework trajectory for Hong Kong: the jurisdiction's regulatory perimeter for computer-systems and data-related obligations is widening even though the Personal Data (Privacy) Ordinance itself has not been amended this cycle.

No change to the Personal Data (Privacy) Ordinance's own statutory text, its lawful-processing basis, or the Privacy Commissioner's core supervisory mandate under that Ordinance was evidenced this cycle.

Outlook

The item to watch is how the Protection of Critical Infrastructures (Computer Systems) Ordinance's obligations interact in practice with Personal Data (Privacy) Ordinance compliance for organisations that qualify as critical-infrastructure operators and also process personal data, since this cycle's evidence establishes the new Ordinance's commencement but not yet how overlapping compliance obligations will be reconciled or supervised in practice.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ProbableDataGuidance — The Office of the Privacy Commissioner for Personal Data (PCPD) is the main body responsible for overseeing enforcement of the PDPO and is headed by the Privacy Commissioner for Personal Data.observed
  2. ProbableDataGuidance — The Personal Data (Privacy) Ordinance (Cap. 486) came into force on 20 December 1996 and was significantly amended by the 2012 Amendment Ordinance (direct marketing) and the 2021 Amendment Ordinance (anti-doxxing).observed
  3. ProbableIAPP — Data Protection Principle 1(1) requires that only necessary, adequate and not excessive personal data be collected for a lawful purpose, forming part of PDPO's core material-scope obligations on data users.observed
  4. ProbableDataGuidance — The PDPO is unclear on its territorial scope on its face, but the PCPD has clarified that the PDPO does not have extraterritorial scope, in contrast to the GDPR's extraterritorial application.observed

#

Functional equivalents exist via DPPs and guidance, but the absence of enumerated lawful bases and a codified special-category regime is a material structural gap versus GDPR.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486) — Data Protection Principles
Supervisory authorityPCPD
Traffic-light rationale — AmberFunctional equivalents exist via DPPs and guidance, but the absence of enumerated lawful bases and a codified special-category regime is a material structural gap versus GDPR.

Sub-modules (4)

Lawful BasesAmber

DPPs (esp. DPP1 collection limitation) function as the lawful-processing framework rather than an Art.6-style enumerated list.

Claims (1):

  • Data Protection Principle 1(1) provides that only necessary, adequate and not excessive personal data is to be collected for a lawful purpose, operating as PDPO's functional lawful-basis analogue.

Special CategoriesAmber

No enumerated special/sensitive-category regime exists in statute; PCPD guidance flags HKID numbers, biometric data and consumer credit data for heightened caution.

Claims (1):

  • The PCPD has published guidelines flagging Hong Kong identity card numbers, biometric data and consumer credit data as categories requiring special caution in collection and use, in the absence of a codified statutory special-category regime.

Pseudonymisation And AnonymisationAmber

PDPO does not statutorily define pseudonymised or anonymised data; PCPD's 2011 Guidance on Personal Data Erasure and Anonymisation addresses the anonymisation threshold.

Claims (1):

  • The PDPO does not address sensitive personal data, anonymisation, or pseudonymisation in the statute itself, though the PCPD has clarified aspects of anonymisation through non-binding guidance.
Category narrative53 words

PDPO does not use an enumerated GDPR Art.6-style lawful-basis list; instead, its six Data Protection Principles govern collection and use. There is no statutory special/sensitive-category regime; PCPD instead issues category-specific guidance (HKID numbers, biometric data, consumer credit data). Pseudonymisation and anonymisation are not defined in the statute, though PCPD guidance addresses anonymisation thresholds.

Sources and claims (4)
  1. ProbableIAPP — Data Protection Principle 1(1) provides that only necessary, adequate and not excessive personal data is to be collected for a lawful purpose, operating as PDPO's functional lawful-basis analogue.observed
  2. ProbableIAPP — Before using or providing personal data for direct marketing, a data user must inform the individual and obtain consent or an indication of no objection, and the individual may opt out at any time irrespective of prior consent.observed
  3. ProbableDataGuidance — The PCPD has published guidelines flagging Hong Kong identity card numbers, biometric data and consumer credit data as categories requiring special caution in collection and use, in the absence of a codified statutory special-category regime.observed
  4. ProbableDataGuidance — The PDPO does not address sensitive personal data, anonymisation, or pseudonymisation in the statute itself, though the PCPD has clarified aspects of anonymisation through non-binding guidance.observed

#

Access/rectification rights are well-defined and binding (green-equivalent), but erasure and portability rights are absent, and restriction/objection is narrow — pulling the module to amber overall.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486)
Supervisory authorityPCPD
Traffic-light rationale — AmberAccess/rectification rights are well-defined and binding (green-equivalent), but erasure and portability rights are absent, and restriction/objection is narrow — pulling the module to amber overall.

Sub-modules (5)

Access RightGreen

Data subjects may request access; if refused, the data user must inform the requestor within 40 calendar days and explain the refusal.

Claims (1):

  • If a data user rejects or denies a data access request, it must inform the requestor within 40 calendar days from receipt of the request and explain why it cannot comply.

Rectification And ErasureAmber

Correction requests must be honored within 40 days; however, PDPO does not provide a general right to erasure/deletion, only a duty not to retain data beyond necessity.

Claims (2):

  • A data correction request must be complied with, and a copy of the corrected personal data provided, within 40 calendar days from receipt under Section 23(1) of the PDPO.
  • Unlike the GDPR, the PDPO does not provide data subjects with a general right to request erasure or deletion of their personal data; only general requirements exist relating to erasure once data is no longer required for its original purpose.

Restriction And ObjectionAmber

No general restriction-of-processing right exists; the closest analogue is the standing direct-marketing opt-out right.

Claims (1):

  • An individual is entitled to opt out of direct marketing at any time irrespective of having previously given consent, functioning as PDPO's principal objection-type right.

Data PortabilityRed

No evidence of a statutory data-portability right was located in this research pass.

Absence provenance: unavailable. Searched: Hong Kong PDPO data portability right, PCPD portability guidance.

Deadlines And Response WindowsGreen

A uniform 40-calendar-day statutory response window applies to both access and correction requests.

Claims (2):

  • If a data user rejects or denies a data access request, it must inform the requestor within 40 calendar days from receipt of the request and explain why it cannot comply.
  • A data correction request must be complied with, and a copy of the corrected personal data provided, within 40 calendar days from receipt under Section 23(1) of the PDPO.
Category narrative35 words

PDPO grants access and correction rights with a 40-calendar-day statutory response window, but does not provide a general right to erasure/be forgotten, nor a data-portability right. Objection-type rights are largely confined to the direct-marketing opt-out.

Sources and claims (4)
  1. ProbableDataGuidance — If a data user rejects or denies a data access request, it must inform the requestor within 40 calendar days from receipt of the request and explain why it cannot comply.observed
  2. ProbableDataGuidance — A data correction request must be complied with, and a copy of the corrected personal data provided, within 40 calendar days from receipt under Section 23(1) of the PDPO.observed
  3. ProbableDataGuidance — Unlike the GDPR, the PDPO does not provide data subjects with a general right to request erasure or deletion of their personal data; only general requirements exist relating to erasure once data is no longer required for its original purpose.observed
  4. ProbableIAPP — An individual is entitled to opt out of direct marketing at any time irrespective of having previously given consent, functioning as PDPO's principal objection-type right.observed

#

Multiple GDPR-equivalent accountability pillars (DPIA, DPO, ROPA, mandatory breach notification) are absent from binding law; only security and retention principles and processor-supervision duties are binding.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486) — DPP2, DPP4; PCPD Privacy Management Programme (non-binding)
Supervisory authorityPCPD
Traffic-light rationale — RedMultiple GDPR-equivalent accountability pillars (DPIA, DPO, ROPA, mandatory breach notification) are absent from binding law; only security and retention principles and processor-supervision duties are binding.

Sub-modules (7)

Accountability And DpiaRed

PDPO does not explicitly set out accountability requirements or require DPIAs; the PCPD advocates a voluntary Privacy Management Programme (PMP) as a best-practice accountability framework.

Claims (1):

  • The PDPO does not explicitly set out accountability requirements for data users and processors; the PCPD instead advocates the Privacy Management Programme, a non-binding strategic framework for building privacy infrastructure, including DPO appointment as best practice.

Dpo RequirementsRed

PDPO does not require DPO appointment; the PMP best-practice guide recommends one.

Claims (1):

  • Unlike the GDPR, the PDPO does not require Data Protection Officer appointments; the PCPD's Privacy Management Programme guide (as updated 2019) recommends appointment as best practice only.

Ropa RequirementsRed

PDPO does not require maintenance of general processing records; only a log book for access/correction requests is mandated.

Claims (1):

  • Unlike the GDPR, the PDPO does not require that general data-processing records be maintained; it only requires a log book be maintained in relation to data subject access and correction requests.

Joint Controller ArrangementsAmber

The 2012 Amendment Ordinance imposed express duties on data users to supervise their data processors contractually and otherwise.

Claims (1):

  • The 2012 Amendment Ordinance imposes express obligations on a data user to supervise, through contractual and other means, its data processors to ensure PDPO compliance.

Security MeasuresAmber

DPP4 imposes a general, non-prescriptive security-of-processing duty; PCPD's 2023 recommendations urge specific technical/organisational measures as best practice.

Claims (2):

  • The PDPO does not stipulate mandatory specific security measures; Data Protection Principle 4 sets only a general, non-prescriptive security-of-processing duty on data users.
  • In September 2023, the PCPD issued non-binding recommendations urging organizations to conduct regular data-security risk assessments and adopt measures such as firewalls, encryption, and the least-privilege principle in compliance with DPP4.

Breach NotificationRed

PDPO imposes no mandatory breach-notification obligation; PCPD guidance recommends prompt voluntary notification, and a 2020 consultation proposed mandatory notification but remains unenacted.

Claims (2):

  • The PDPO does not provide for mandatory data breach notifications; the PCPD has instead published non-binding guidance on data breach handling.
  • In a 2020 consultation paper, the Privacy Commissioner and the Constitutional and Mainland Affairs Bureau proposed introducing mandatory data breach notification requirements and data retention periods, with no confirmed timeframe for formal introduction.

Retention And DisposalGreen

DPP2(2)/Section 26 requires personal data not be kept longer than necessary for the purpose (including any directly related purpose).

Claims (1):

  • Under DPP2(2) and Section 26 of the PDPO, all practicable steps must be taken to ensure personal data is not kept longer than necessary for the fulfilment of the purpose for which it is or is to be used.
Category narrative43 words

PDPO imposes a general security principle (DPP4) and post-2012 processor-supervision duties, retention limitation (DPP2(2)/s.26), but does not mandate DPIAs, DPO appointments, general records of processing (ROPA), or breach notification — all addressed only via non-binding PCPD guidance (Privacy Management Programme) or unenacted proposals.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (9)
  1. ProbableDataGuidance — The PDPO does not explicitly set out accountability requirements for data users and processors; the PCPD instead advocates the Privacy Management Programme, a non-binding strategic framework for building privacy infrastructure, including DPO appointment as best practice.observed
  2. ProbableDataGuidance — Unlike the GDPR, the PDPO does not require Data Protection Officer appointments; the PCPD's Privacy Management Programme guide (as updated 2019) recommends appointment as best practice only.observed
  3. ProbableDataGuidance — Unlike the GDPR, the PDPO does not require that general data-processing records be maintained; it only requires a log book be maintained in relation to data subject access and correction requests.observed
  4. ProbableIAPP — The 2012 Amendment Ordinance imposes express obligations on a data user to supervise, through contractual and other means, its data processors to ensure PDPO compliance.observed
  5. ProbableDataGuidance — The PDPO does not stipulate mandatory specific security measures; Data Protection Principle 4 sets only a general, non-prescriptive security-of-processing duty on data users.observed
  6. ProbableDataGuidance — In September 2023, the PCPD issued non-binding recommendations urging organizations to conduct regular data-security risk assessments and adopt measures such as firewalls, encryption, and the least-privilege principle in compliance with DPP4.observed
  7. ProbableDataGuidance — The PDPO does not provide for mandatory data breach notifications; the PCPD has instead published non-binding guidance on data breach handling.observed
  8. ProbableIAPP — In a 2020 consultation paper, the Privacy Commissioner and the Constitutional and Mainland Affairs Bureau proposed introducing mandatory data breach notification requirements and data retention periods, with no confirmed timeframe for formal introduction.observed
  9. ProbableDataGuidance — Under DPP2(2) and Section 26 of the PDPO, all practicable steps must be taken to ensure personal data is not kept longer than necessary for the fulfilment of the purpose for which it is or is to be used.observed

#

The central transfer-restriction mechanism is dormant; only voluntary guidance exists, and adequacy/TIA sub-modules could not be evidenced.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486), Section 33 (not yet in force)
Supervisory authorityPCPD
Traffic-light rationale — RedThe central transfer-restriction mechanism is dormant; only voluntary guidance exists, and adequacy/TIA sub-modules could not be evidenced.

Sub-modules (6)

Transfer MechanismsRed

Section 33 (transfer restriction) remains dormant; PCPD guidance outlines prospective mechanisms (consent, white list, due diligence) that would apply if commenced.

Claims (3):

  • Currently, there are no restrictions in effect concerning the cross-border transfer of personal data from Hong Kong, as Section 33 of the PDPO has never been brought into force.
  • The PCPD has issued a non-binding Guidance on Personal Data Protection in Cross-Border Data Transfer, recommending voluntary compliance with Section 33 as best practice and signalling a possible future commencement of the transfer restriction.
  • No timetable has been announced for the implementation of Section 33; it remains the only section of the PDPO yet to come into effect.

Adequacy ReceivedRed

No evidence located of any foreign regime granting Hong Kong an adequacy-equivalent determination.

Absence provenance: unavailable. Searched: Hong Kong EU adequacy decision, Hong Kong PDPO adequacy determination received.

Adequacy GrantedRed

Since Section 33's white-list mechanism has never been activated, Hong Kong has not granted adequacy-equivalent status to any other jurisdiction.

Claims (1):

  • Currently, there are no restrictions in effect concerning the cross-border transfer of personal data from Hong Kong, as Section 33 of the PDPO has never been brought into force.

Sccs And BcrsRed

Section 33, even if brought into force, does not provide for mechanisms such as BCRs, SCCs, or codes of conduct.

Claims (1):

  • Section 33 of the PDPO does not provide for mechanisms such as binding corporate rules, standard contractual clauses, or codes of conduct, even if it were to come into force.

Transfer Impact AssessmentRed

No formal transfer-impact-assessment requirement was identified; PCPD guidance recommends general due diligence only.

Absence provenance: unavailable. Searched: Hong Kong PDPO transfer impact assessment requirement.

Data LocalisationAmber

No general PDPO data-localisation mandate exists; sector regulators (e.g., HKMA) impose data-residency/outsourcing controls on regulated entities.

Claims (1):

  • The Outsourcing module (SA-2) of the Hong Kong Monetary Authority's Supervisory Policy Manual requires all authorised institutions to implement proper controls for protection of customer data when entering into an outsourcing arrangement.
Category narrative61 words

Section 33 of the PDPO — the sole cross-border transfer restriction provision — has never been commenced since the Ordinance's 1995/1996 enactment, so no binding transfer restriction currently applies. PCPD has issued non-binding guidance recommending voluntary compliance with Section 33's conditions (consent, a prospective 'white list', due diligence) as best practice. No adequacy decisions received/granted or formal TIA requirement were identified.

Sources and claims (5)
  1. ProbableDataGuidance — Currently, there are no restrictions in effect concerning the cross-border transfer of personal data from Hong Kong, as Section 33 of the PDPO has never been brought into force.observed
  2. ProbableIAPP — The PCPD has issued a non-binding Guidance on Personal Data Protection in Cross-Border Data Transfer, recommending voluntary compliance with Section 33 as best practice and signalling a possible future commencement of the transfer restriction.observed
  3. ProbableDataGuidance — No timetable has been announced for the implementation of Section 33; it remains the only section of the PDPO yet to come into effect.observed
  4. ProbableDataGuidance — Section 33 of the PDPO does not provide for mechanisms such as binding corporate rules, standard contractual clauses, or codes of conduct, even if it were to come into force.observed
  5. ProbableDataGuidance — The Outsourcing module (SA-2) of the Hong Kong Monetary Authority's Supervisory Policy Manual requires all authorised institutions to implement proper controls for protection of customer data when entering into an outsourcing arrangement.observed

#

Financial-sector overlay is well-evidenced; health, telecoms/ePrivacy, employment, and education sub-modules are thin or unevidenced.

Primary frameworkPDPO overlaid by HKMA/Insurance Authority/SFC sectoral guidelines
Supervisory authorityPCPD
Traffic-light rationale — AmberFinancial-sector overlay is well-evidenced; health, telecoms/ePrivacy, employment, and education sub-modules are thin or unevidenced.

Sub-modules (7)

Financial Sector OverlayAmber

HKMA, Insurance Authority, and SFC issue customer-data circulars/guidelines applicable to licensed institutions, overlaying general PDPO duties.

Claims (2):

  • There are no sectoral data privacy laws as such in Hong Kong, but certain industry-specific requirements are imposed by relevant regulators in respect of customer data held by regulated entities.
  • The Hong Kong Monetary Authority has issued several circulars and guidelines relating to protection and confidentiality of customer data applicable to all licensed banks under the Banking Ordinance (Cap. 155).

Health Sector OverlayRed

No dedicated health-sector data-privacy statute (e.g., HIPAA-equivalent) was identified in this research pass.

Absence provenance: unavailable. Searched: Hong Kong health data privacy sectoral law, Hong Kong medical data protection statute.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style cookie-and-communications-specific statute was identified.

Absence provenance: unavailable. Searched: Hong Kong ePrivacy telecoms data law, Hong Kong cookie law telecoms.

Employment DataAmber

Retention limitation rules require employee personal data not be kept beyond the period necessary after termination of employment absent a subsisting reason.

Claims (1):

  • Under DPP2(2)/Section 26, employee personal data must not be kept longer than necessary after the end of employment, unless a subsisting reason requires the employer to hold the data longer.

Credit And ScoringAmber

PCPD guidance flags consumer credit data as a category requiring heightened caution in collection and use.

Claims (1):

  • The PCPD has published guidelines on the collection and use of consumer credit data, requiring caution and setting practical guidance on proper collection and use.

EducationRed

No dedicated education-sector data-privacy rules were identified in this research pass.

Absence provenance: unavailable. Searched: Hong Kong education sector data privacy rules PCPD.

InsuranceAmber

The Insurance Authority requires authorised insurers to implement cybersecurity frameworks protecting policyholder personal data.

Claims (1):

  • The Insurance Authority has issued a Guideline on Cybersecurity requiring authorised insurers to implement robust cybersecurity frameworks to protect the personal data of existing or potential policyholders.
Category narrative40 words

Hong Kong has no standalone sectoral data-privacy statutes; instead, sector regulators (HKMA, Insurance Authority, SFC) issue circulars and guidelines overlaying the PDPO for regulated entities' customer data, and PCPD issues category-specific guidance for sensitive data types including consumer credit data.

Sources and claims (5)
  1. ProbableDataGuidance — There are no sectoral data privacy laws as such in Hong Kong, but certain industry-specific requirements are imposed by relevant regulators in respect of customer data held by regulated entities.observed
  2. ProbableDataGuidance — The Hong Kong Monetary Authority has issued several circulars and guidelines relating to protection and confidentiality of customer data applicable to all licensed banks under the Banking Ordinance (Cap. 155).observed
  3. ProbableDataGuidance — Under DPP2(2)/Section 26, employee personal data must not be kept longer than necessary after the end of employment, unless a subsisting reason requires the employer to hold the data longer.observed
  4. ProbableDataGuidance — The PCPD has published guidelines on the collection and use of consumer credit data, requiring caution and setting practical guidance on proper collection and use.observed
  5. ProbableDataGuidance — The Insurance Authority has issued a Guideline on Cybersecurity requiring authorised insurers to implement robust cybersecurity frameworks to protect the personal data of existing or potential policyholders.observed

#

Direct marketing is green-level binding law; the remaining five sub-modules are unevidenced gaps in a jurisdiction with no dedicated ePrivacy/cookie statute.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486), Part VIA (Direct Marketing)
Supervisory authorityPCPD
Traffic-light rationale — AmberDirect marketing is green-level binding law; the remaining five sub-modules are unevidenced gaps in a jurisdiction with no dedicated ePrivacy/cookie statute.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent statute was identified distinct from general PDPO principles.

Absence provenance: unavailable. Searched: Hong Kong cookie consent law PDPO, Hong Kong ePrivacy cookies.

Dark PatternsAmber

PCPD guidance criticizes 'bundled consent' application-form designs that force customers to choose between service and direct-marketing data use.

Claims (1):

  • PCPD guidance states it would be unfair for service application forms to force customers to choose between providing personal data for direct marketing or forgoing the service ('bundled consent'), requiring separate voluntary indications instead.

Opt Out SignalsRed

No evidence of a Global-Privacy-Control-style universal opt-out signal regime was identified.

Absence provenance: unavailable. Searched: Hong Kong Global Privacy Control opt-out signal law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules were identified.

Absence provenance: unavailable. Searched: Hong Kong data clean room regulation PDPO.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising regime was identified.

Absence provenance: unavailable. Searched: Hong Kong cross-context advertising data sale law.

Direct MarketingGreen

Part VIA requires informed consent/no-objection before use of data in direct marketing, an unconditional opt-out right, and criminalises non-compliant use with fines up to HK$500,000 and up to 3 years' imprisonment.

Claims (2):

  • Part VIA of the PDPO requires a data user to inform individuals, in an easily understandable and readable manner, of an intention to use or provide their data for direct marketing, specifying the data and marketing types, and to obtain consent or no-objection via a free response channel.
  • Section 35E of the PDPO provides for a fine of up to HK$500,000 and up to three years' imprisonment where personal data is used for direct marketing purposes without the individual's informed consent.
Category narrative41 words

Direct marketing is the best-developed strand of PDPO's commercial-privacy regime (Part VIA), with binding consent/opt-out duties and criminal penalties, plus PCPD guidance against 'bundled consent' dark patterns. No dedicated cookie/tracker law, opt-out-signal regime, clean-room rules, or cross-context-advertising ('sale'/'share') regime was identified.

Sources and claims (3)
  1. ProbableIAPP — PCPD guidance states it would be unfair for service application forms to force customers to choose between providing personal data for direct marketing or forgoing the service ('bundled consent'), requiring separate voluntary indications instead.observed
  2. ProbableIAPP — Part VIA of the PDPO requires a data user to inform individuals, in an easily understandable and readable manner, of an intention to use or provide their data for direct marketing, specifying the data and marketing types, and to obtain consent or no-objection via a free response channel.observed
  3. ProbableIAPP — Section 35E of the PDPO provides for a fine of up to HK$500,000 and up to three years' imprisonment where personal data is used for direct marketing purposes without the individual's informed consent.observed

#

AI governance is active but entirely soft-law; national-security carve-outs materially limit PCPD's supervisory reach; profiling/ADM-transparency/genetic-data sub-modules are unevidenced.

Primary frameworkPCPD Artificial Intelligence: Model Personal Data Protection Framework (2024, non-binding); PDPO general principles
Supervisory authorityPCPD
Traffic-light rationale — AmberAI governance is active but entirely soft-law; national-security carve-outs materially limit PCPD's supervisory reach; profiling/ADM-transparency/genetic-data sub-modules are unevidenced.

Sub-modules (6)

Profiling RestrictionsRed

No Art.22-style statutory profiling restriction was identified in the PDPO.

Absence provenance: unavailable. Searched: Hong Kong PDPO profiling restriction automated decision.

Automated Decision Making TransparencyRed

No statutory ADM-transparency or explanation right was identified beyond general AI governance guidance.

Absence provenance: unavailable. Searched: Hong Kong PDPO automated decision-making transparency right.

Ai Risk AssessmentsAmber

PCPD's AI compliance-check programme and Model Framework recommend (non-binding) risk assessments, governance structures, and audits for AI systems.

Claims (3):

  • On 11 June 2024, the PCPD published the Artificial Intelligence: Model Personal Data Protection Framework, providing recommendations and best practices for AI governance covering procurement, implementation, and use of AI systems including generative AI, building on its 2021 Guidance on the Ethical Development and Use of AI.
  • The PCPD's 2024-25 Annual Report describes the AI Model Framework as one of the first explicit regional frameworks for regulating AI, reflecting the Commissioner's stated aim to balance innovation and security in AI.
  • PCPD compliance checks on 60 organizations found 80% used AI in daily operations (a 5% increase from 2024), with the PCPD recommending AI governance structures, comprehensive risk assessments, and regular audits as best practice.

Biometric RegimeAmber

PCPD guidance flags biometric data, alongside HKID numbers and credit data, as requiring heightened caution, without a codified statutory biometric regime.

Claims (1):

  • The PCPD has published guidelines regarding the collection and use of biometric data, alongside Hong Kong identity cards and consumer credit data, highlighting the need for caution absent a codified statutory biometric regime.

Genetic DataRed

No dedicated genetic-data regime was identified in this research pass.

Absence provenance: unavailable. Searched: Hong Kong genetic data protection law PDPO.

State Surveillance CarveoutsRed

The PCPD's ability to supervise and regulate authorities' actions under the National Security Law appears fairly limited, as the NSL expressly takes precedence over inconsistent local laws.

Claims (1):

  • In relation to the exercise of authorities' powers under the National Security Law, the PCPD's ability to supervise and regulate compliance with the PDPO appears fairly limited, as the NSL expressly takes precedence over inconsistent provisions of other Hong Kong laws.
Category narrative56 words

Hong Kong has no binding AI-specific statute; the PCPD's June 2024 AI Model Personal Data Protection Framework and 2021 Ethical AI Guidance are non-binding best-practice instruments. PCPD conducts periodic AI compliance checks. Biometric data attracts special-caution guidance but no codified regime. State-surveillance carve-outs exist under the National Security Law, which the PCPD's supervisory reach cannot override.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableDataGuidance — On 11 June 2024, the PCPD published the Artificial Intelligence: Model Personal Data Protection Framework, providing recommendations and best practices for AI governance covering procurement, implementation, and use of AI systems including generative AI, building on its 2021 Guidance on the Ethical Development and Use of AI.observed
  2. ProbableIAPP — The PCPD's 2024-25 Annual Report describes the AI Model Framework as one of the first explicit regional frameworks for regulating AI, reflecting the Commissioner's stated aim to balance innovation and security in AI.observed
  3. ProbableIAPP — PCPD compliance checks on 60 organizations found 80% used AI in daily operations (a 5% increase from 2024), with the PCPD recommending AI governance structures, comprehensive risk assessments, and regular audits as best practice.observed
  4. ProbableDataGuidance — The PCPD has published guidelines regarding the collection and use of biometric data, alongside Hong Kong identity cards and consumer credit data, highlighting the need for caution absent a codified statutory biometric regime.observed
  5. ProbableDataGuidance — In relation to the exercise of authorities' powers under the National Security Law, the PCPD's ability to supervise and regulate compliance with the PDPO appears fairly limited, as the NSL expressly takes precedence over inconsistent provisions of other Hong Kong laws.observed

#

This is a legitimate regulatory gap: no comprehensive children/vulnerable-groups regime exists in the PDPO beyond passing references to minors.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486) — no dedicated minors regime
Supervisory authorityPCPD
Traffic-light rationale — RedThis is a legitimate regulatory gap: no comprehensive children/vulnerable-groups regime exists in the PDPO beyond passing references to minors.

Sub-modules (5)

Age VerificationRed

No statutory age-verification requirement was identified.

Absence provenance: unavailable. Searched: Hong Kong PDPO age verification requirement minors.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: unavailable. Searched: Hong Kong PDPO minors profiling ban.

Education SettingsRed

No education-setting-specific data rules were identified.

Absence provenance: unavailable. Searched: Hong Kong PDPO education sector minors data rules.

Dependent AdultsRed

No dependent-adult-specific protections were identified.

Absence provenance: unavailable. Searched: Hong Kong PDPO dependent adults elderly mentally incapacitated data protection.

Category narrative32 words

PDPO makes passing reference to 'minors' but does not codify a specific age of consent, parental-consent mechanism, or minor-specific profiling ban comparable to GDPR Art.8. No education-setting-specific or dependent-adult-specific rules were identified.

Sources and claims (1)
  1. ProbableDataGuidance — The PDPO makes references to 'minors' but is less clear than the GDPR regarding consent from guardians and privacy notices aimed at minors, and does not define a specific age of consent threshold.observed

#

Enforcement powers and penalties are robust and binding (green-level for that sub-module), but collective redress and regulator-capacity sub-modules are unevidenced gaps, pulling the module to amber.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486)
Supervisory authorityPCPD
Traffic-light rationale — AmberEnforcement powers and penalties are robust and binding (green-level for that sub-module), but collective redress and regulator-capacity sub-modules are unevidenced gaps, pulling the module to amber.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

PCPD can investigate, issue enforcement notices, and (since 2021) conduct criminal investigations/prosecutions for doxxing, with tiered penalties up to HK$1,000,000 and 5 years' imprisonment.

Claims (4):

  • The PCPD has various investigative powers, including the right to undertake investigations and inquiries and issue enforcement notices in the event of PDPO contraventions.
  • The 2021 Amendment Ordinance removed the prior requirement that an enforcement notice could only be issued where the offending act was likely to continue or repeat, and increased penalties for data users breaching multiple or repeated enforcement notices.
  • The 2021 anti-doxxing regime creates a two-tier offence: a Tier 1 summary offence carrying up to two years' imprisonment and a HK$100,000 fine, and a Tier 2 indictable offence, where actual harm is caused, carrying up to five years' imprisonment and a HK$1,000,000 fine.
  • The PCPD has the power to conduct criminal investigations and institute prosecutions for doxxing cases, and to issue cessation notices to Hong Kong or non-Hong Kong persons or service providers to demand removal of doxxing content.

Enforcement Activity IndexAmber

Documented enforcement activity includes multiple doxxing arrests since the 2021 anti-doxxing law and the first PDPO imprisonment for misleading the PCPD during an investigation.

Claims (2):

  • The PCPD announced the first prison sentence under Section 50B(1)(c)(i) of the PDPO for knowingly making a false or misleading statement to the Commissioner during an investigation.
  • The PCPD arrested an individual for posting personal information of three people on social media in a commercial dispute, marking the second arrest under the anti-doxxing legislation approved in September 2021.

Regulator Funding And CapacityRed

No regulator funding or headcount data was identified in this research pass.

Absence provenance: unavailable. Searched: PCPD annual budget headcount staffing capacity.

Collective Redress And Class ActionsRed

No dedicated class-action mechanism for data subjects was identified beyond the individual legal-assistance scheme.

Absence provenance: unavailable. Searched: Hong Kong PDPO class action collective redress data subjects.

Private Right Of ActionAmber

The 2012 Amendment Ordinance introduced a legal-assistance scheme enabling aggrieved individuals to pursue compensation claims arising from PDPO contraventions.

Claims (1):

  • The 2012 Amendment Ordinance introduced, among other measures, a legal assistance scheme for aggrieved individuals seeking to bring proceedings arising from PDPO contraventions.

Recent Developments 180DAmber

The PCPD's 2024-25 Annual Report continues to emphasize AI governance, data security, and digital trust as regulatory priorities.

Claims (1):

  • The PCPD's 2024-25 Annual Report, 'Leveraging Artificial Intelligence for a New Digital Privacy Era,' concentrates on AI's impacts on data security and digital trust as a continuing regulatory priority.
Category narrative59 words

The PCPD holds investigative, enforcement-notice, and (post-2021) criminal investigation/prosecution powers for doxxing, with a two-tier anti-doxxing offence carrying fines up to HK$1,000,000 and imprisonment up to 5 years. Direct-marketing breaches carry fines up to HK$500,000 and 3 years' imprisonment. A legal-assistance scheme for aggrieved individuals was introduced in 2012. No dedicated collective-redress/class-action mechanism or regulator funding/headcount data was identified.

Periodic update · new data 2026-09-28

Enforcement & Redress

Hong Kong's data-protection enforcement and redress picture intensified this cycle in observed volume even as the underlying statutory architecture remained unchanged. Personal data breach notifications and detections rose to 217 cases in 2024, a marked increase from a stable baseline of roughly 100 cases per year in prior years, according to a January 2025 government reply to the Legislative Council. This is a confirmed, primary-sourced government figure and represents more than a doubling of the prior stable baseline.

This rise in observed breach activity has occurred despite the Personal Data (Privacy) Ordinance still lacking a mandatory personal data breach notification regime. The Privacy Commissioner for Personal Data responded to this gap through non-binding guidance rather than legislation: updated 'Guidance on Data Breach Handling and Data Breach Notifications' was issued in 2026, clarifying the Commissioner's expectations for breach handling without creating a statutory notification duty. The Personal Data (Privacy) Ordinance also continues to lack a direct administrative fining power for the Privacy Commissioner of the kind available under the European Union's General Data Protection Regulation; reform proposals addressing mandatory notification, processor regulation and administrative fines remain under study rather than enacted.

A supporting judgment drawn from this cycle's evidence assesses that Hong Kong's enforcement posture is intensifying in observed practice even as the binding statutory gaps — no mandatory notification duty, no direct administrative fining power — remain unresolved, widening the gap between observed breach volume and the regulator's binding legal powers to compel disclosure or penalise non-compliance.

It remains unconfirmed whether any amendment bill addressing mandatory breach notification, processor regulation, or administrative fining powers has been introduced to the Legislative Council since reports from autumn 2024 indicated the reform effort had been placed on hold; this is recorded as an open gap rather than an assertion that no such bill exists.

Outlook

The central question to watch is whether the stalled reform package — covering mandatory breach notification, processor regulation and administrative fining powers — is revived and introduced to the Legislative Council, particularly given that observed breach volume more than doubled in 2024 relative to the prior stable baseline. Until such a bill is introduced, organisations will continue to operate under the Privacy Commissioner's non-binding guidance rather than a statutory notification duty, and confirmation of the current legislative status of any reform bill would materially sharpen this cycle's assessment.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (8)
  1. ProbableDataGuidance — The PCPD has various investigative powers, including the right to undertake investigations and inquiries and issue enforcement notices in the event of PDPO contraventions.observed
  2. ProbableIAPP — The 2021 Amendment Ordinance removed the prior requirement that an enforcement notice could only be issued where the offending act was likely to continue or repeat, and increased penalties for data users breaching multiple or repeated enforcement notices.observed
  3. ProbableDataGuidance — The 2021 anti-doxxing regime creates a two-tier offence: a Tier 1 summary offence carrying up to two years' imprisonment and a HK$100,000 fine, and a Tier 2 indictable offence, where actual harm is caused, carrying up to five years' imprisonment and a HK$1,000,000 fine.observed
  4. ProbableDataGuidance — The PCPD has the power to conduct criminal investigations and institute prosecutions for doxxing cases, and to issue cessation notices to Hong Kong or non-Hong Kong persons or service providers to demand removal of doxxing content.observed
  5. ProbableIAPP — The PCPD announced the first prison sentence under Section 50B(1)(c)(i) of the PDPO for knowingly making a false or misleading statement to the Commissioner during an investigation.observed
  6. ProbableIAPP — The PCPD arrested an individual for posting personal information of three people on social media in a commercial dispute, marking the second arrest under the anti-doxxing legislation approved in September 2021.observed
  7. ProbableIAPP — The 2012 Amendment Ordinance introduced, among other measures, a legal assistance scheme for aggrieved individuals seeking to bring proceedings arising from PDPO contraventions.observed
  8. ProbableIAPP — The PCPD's 2024-25 Annual Report, 'Leveraging Artificial Intelligence for a New Digital Privacy Era,' concentrates on AI's impacts on data security and digital trust as a continuing regulatory priority.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct12.5
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Hong Kong
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 48 claim(s) (48 category placement(s)), 25 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (14 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 13-22Data Subject Rightsaccess right
Art. 32-34Controller/Processor Dutiessecurity measures
Art. 37-39Controller/Processor Dutiesdpo requirements
Art. 44-49Cross-Border & Adequacytransfer mechanisms
Art. 77-84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. Strong T1/T2/T3 coverage for regulator_and_framework, controller_processor_duties (gaps affirmatively evidenced as absences), cross_border_and_adequacy (Section 33 dormancy well-documented), adtech/direct_marketing, and algorithmic/AI governance (PCPD's 2024 Model AI Framework and 2025 compliance-check data). Weaker or gap-only coverage (T3/absent_field_provenance) for: regulator registration/filing, data portability, adequacy received/granted, transfer impact assessment, health/telecoms/education sectoral overlays, cookies/opt-out-signals/clean-rooms/cross-context-advertising, profiling/ADM-transparency/genetic-data, and most of children_and_vulnerable_groups and regulator funding/collective-redress sub-modules — these are treated as legitimate regulatory gaps under GAP DISCIPLINE rather than fabricated obligations.

Unresolved questions (5):

  • No confirmed timeline exists for commencement of PDPO Section 33 (cross-border transfer restriction); operator should confirm current LegCo/PCPD status.
  • Status of the mandatory data-breach-notification and data-retention-period amendments proposed in the 2020 consultation paper is unclear — no confirmation whether a bill has since been formally introduced.
  • No source located confirming or denying any foreign jurisdiction's adequacy assessment of Hong Kong, or vice versa.
  • No confirmed source on PCPD funding, headcount, or budget for capacity assessment.
  • Unclear whether any codified age-of-consent or parental-consent threshold has been proposed for PDPO 'minors' provisions.

Escalate to primary-source review: yes