World Watch/Hong Kong/Data & Privacy

Data & Privacy · Hong Kong

Data & Privacy - Hong Kong

Comprehensive lawPersonal Data (Privacy) Ordinance (Cap. 486) ('PDPO'), enforced by the Office of the Privacy Commissioner for Personal Data ('PCPD')

Hong Kong has a comprehensive, technology-neutral data-protection law, the Personal Data (Privacy) Ordinance (Cap. 486), in force since 1996 and pre-dating the GDPR. It is built on six Data Protection Principles covering the full data lifecycle and is enforced by an independent statutory regulator, the Privacy Commissioner for Personal Data. The regime was strengthened by 2012 (direct-marketing) and 2021 (anti-doxxing) amendments, and a further package—including mandatory breach notification and administrative fines—is under active review but not yet enacted.

Comprehensive statute

The PDPO (Cap. 486), in operation since December 1996, is a cross-sector law applying to any 'data user' that collects, holds, processes or uses personal data, structured around six Data Protection Principles in Schedule 1 (collection, accuracy/retention, use, security, transparency, and data access/correction).

Supervisory authority

The Office of the Privacy Commissioner for Personal Data (PCPD), established under s.5(1) of the Ordinance, is an independent statutory body that investigates complaints, issues enforcement notices, publishes codes of practice and promotes compliance.

Data subject rights

Individuals have rights of access to and correction of their personal data, and may require a data user to cease using their data for direct marketing; the 2012 amendment added an explicit opt-out/consent regime for direct marketing.

Anti-doxxing regime (2021)

Amendments effective 8 October 2021 criminalised doxxing in a two-tier structure (up to HK$1,000,000 fine and 5 years' imprisonment on indictment) and gave the Commissioner powers to conduct criminal investigations, prosecute, and issue cessation notices—including to non-Hong Kong platform operators.

Cross-border transfers (Section 33 not in force)

Section 33, intended to restrict transfers of personal data outside Hong Kong absent adequacy safeguards, has never been brought into operation; there are currently no statutory cross-border restrictions, only voluntary PCPD best-practice guidance.

Reform under review

Following a comprehensive review, the government and PCPD have proposed enhancements—mandatory data-breach notification, data-retention policy requirements, administrative fines, and direct regulation of data processors. These were debated in LegCo in July 2025 but, as of May 2026, remain proposals rather than enacted law.

Machine-assisted translation · verified 5/23/2026 · orientation, not legal advice. English version →