#
Core regulator/statute framework is well-established (green-equivalent), but material and territorial scope diverge substantially from GDPR baseline, and a registration/filing sub-module could not be evidenced, warranting amber overall.
Sub-modules (5)
Regulator And AuthorityGreen
PCPD is the statutory regulator headed by the Privacy Commissioner, with investigative and enforcement powers under the PDPO.
Claims (1):
- The Office of the Privacy Commissioner for Personal Data (PCPD) is the main body responsible for overseeing enforcement of the PDPO and is headed by the Privacy Commissioner for Personal Data.
Act And InstrumentsGreen
PDPO Cap. 486 (in force since 1996) is the principal instrument, materially amended in 2012 (direct marketing) and 2021 (anti-doxxing).
Claims (1):
- The Personal Data (Privacy) Ordinance (Cap. 486) came into force on 20 December 1996 and was significantly amended by the 2012 Amendment Ordinance (direct marketing) and the 2021 Amendment Ordinance (anti-doxxing).
Material ScopeAmber
PDPO scope centers on Data Protection Principles (DPPs) governing collection, holding, processing and use of personal data by 'data users'.
Claims (1):
- Data Protection Principle 1(1) requires that only necessary, adequate and not excessive personal data be collected for a lawful purpose, forming part of PDPO's core material-scope obligations on data users.
Territorial ScopeAmber
PCPD has clarified PDPO has no extraterritorial scope; it applies where the data user's principal place of business is in Hong Kong.
Claims (1):
- The PDPO is unclear on its territorial scope on its face, but the PCPD has clarified that the PDPO does not have extraterritorial scope, in contrast to the GDPR's extraterritorial application.
Regulator Registration And FilingRed
No evidence located of a general controller registration/filing obligation to PCPD akin to EU-style DPA registers.
Absence provenance: unavailable. Searched: PCPD registration requirement data user Hong Kong, PDPO controller notification filing obligation.
Regulator & Framework
Hong Kong's data-protection framework continues to rest on the Personal Data (Privacy) Ordinance, supervised by the Privacy Commissioner for Personal Data. The Privacy Commissioner, not mainland China's Cyberspace Administration, is confirmed as the supervisory authority for this Ordinance, with the two regimes operating entirely separately under the 'one country, two systems' constitutional arrangement — a standing baseline fact with no change this cycle.
The material development this cycle is the commencement of a separate, adjacent instrument: the Protection of Critical Infrastructures (Computer Systems) Ordinance came into full force on 1 January 2026. This Ordinance establishes a cybersecurity-for-critical-infrastructure regime that is structurally distinct from, and sits alongside, the Personal Data (Privacy) Ordinance rather than amending or extending it. Organisations that qualify as operators of critical infrastructure computer systems now face obligations under this new Ordinance in addition to, not instead of, their existing Personal Data (Privacy) Ordinance obligations where personal data is involved. This is an escalating regulatory-framework trajectory for Hong Kong: the jurisdiction's regulatory perimeter for computer-systems and data-related obligations is widening even though the Personal Data (Privacy) Ordinance itself has not been amended this cycle.
No change to the Personal Data (Privacy) Ordinance's own statutory text, its lawful-processing basis, or the Privacy Commissioner's core supervisory mandate under that Ordinance was evidenced this cycle.
Outlook
The item to watch is how the Protection of Critical Infrastructures (Computer Systems) Ordinance's obligations interact in practice with Personal Data (Privacy) Ordinance compliance for organisations that qualify as critical-infrastructure operators and also process personal data, since this cycle's evidence establishes the new Ordinance's commencement but not yet how overlapping compliance obligations will be reconciled or supervised in practice.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (4)
- ProbableDataGuidance — The Office of the Privacy Commissioner for Personal Data (PCPD) is the main body responsible for overseeing enforcement of the PDPO and is headed by the Privacy Commissioner for Personal Data.observed
- ProbableDataGuidance — The Personal Data (Privacy) Ordinance (Cap. 486) came into force on 20 December 1996 and was significantly amended by the 2012 Amendment Ordinance (direct marketing) and the 2021 Amendment Ordinance (anti-doxxing).observed
- ProbableIAPP — Data Protection Principle 1(1) requires that only necessary, adequate and not excessive personal data be collected for a lawful purpose, forming part of PDPO's core material-scope obligations on data users.observed
- ProbableDataGuidance — The PDPO is unclear on its territorial scope on its face, but the PCPD has clarified that the PDPO does not have extraterritorial scope, in contrast to the GDPR's extraterritorial application.observed