Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
HK PDPO 2021 Doxxing Amendment
Personal Data (Privacy) (Amendment) Ordinance 2021 introduced Hong Kong anti-doxxing regime targeting disclosure of personal data without consent with intent or recklessness causing specified harm. Two-tier criminal offences: Section 64(3A) basic offence (disclosure without consent + intent + reckless as to causing any specified harm) HKD 100,000 + 2 years imprisonment; Section 64(3C) aggravated offence (disclosure + intent or reckless + harm actually caused) HKD 1,000,000 + 5 years imprisonment. Specified harm: harassment + molestation + pestering + threat + intimidation + bodily harm + psychological harm + harm to reasonable use or enjoyment of property + serious financial loss. Section 64C cessation notices: PCPD power to issue written notice to person to take cessation action (remove or restrict disclosure) within specified period. Section 64D applies extraterritorially: notice may b
- Doxxing risk register + classification of platforms + user-generated content channels
- Cessation notice intake + triage + removal + audit playbook with 24h target
- Extraterritorial Section 64D readiness for non-HK platforms + global compliance team coordination
- Section 66A-M investigation + search + arrest cooperation procedures
- Anti-Doxxing Division liaison contact + escalation path
- Two-tier offence training for content moderation + customer service + legal
- No cessation notice intake or playbook (Section 64C)
- Extraterritorial Section 64D ignored for non-HK platforms
- Slow takedown beyond reasonable time triggering Section 66J non-compliance
- No documentation of harm assessment when balancing free expression
- Missing arrest + search warrant cooperation procedure (Sections 66A-M)
HK PDPO Coordination + 2024-2025 Pipeline
HK PDPO operates under One Country Two Systems separation from mainland China data protection regime (PIPL + DSL + CSL all verified separately in this corpus). Coordination interfaces: Greater Bay Area (GBA) Standard Contract Pilot for HK-mainland cross-border transfers (2024) reducing CAC Standard Contract burden for participating GBA organisations; APEC Cross-Border Privacy Rules (CBPR) participation maintained through APEC + Global CBPR Forum (verified separately); coordination with Macao Law 8/2005 Personal Data Protection Act. PCPD Model Personal Data Protection Framework for Generative AI June 2024 establishes 4 areas: governance + risk assessment + customisation + training + maintenance + management + communication; recommends generative AI PIA, transparency on AI use in PPS, AI training data DPP1 evaluation, AI output accuracy DPP2 + bias, AI security DPP4. Pending 2024-2025 PDPO
- Coordination matrix HK PDPO + China PIPL + Macao 8/2005 + APEC CBPR + Global CBPR Forum
- GBA Standard Contract Pilot enrolment + participation evidence
- Generative AI PIA + risk assessment + training + monitoring per PCPD June 2024 framework
- Pending 2025 mandatory breach regime readiness assessment + tabletop
- Administrative fine readiness + insurance + risk register update
- PCPD DPO Club + Privacy Awareness Week + sectoral engagement participation
- Treating HK PDPO + China PIPL as identical (One Country Two Systems ignored)
- Missing GBA Standard Contract Pilot enrolment for HK-mainland transfers
- Generative AI deployed without PCPD June 2024 framework PIA
- No tabletop for pending mandatory breach regime
- Stale coordination with APEC CBPR + Global CBPR Forum
HK PDPO Cross-Border
Section 33 PDPO restricting cross-border transfer of personal data to places outside Hong Kong has been enacted in 1995 but is the only PDPO section not yet brought into force (over 28 years). Section 33 would prohibit transfer to a place outside Hong Kong unless: PCPD has specified the place as having data protection law substantially similar to PDPO; data user has reasonable grounds to believe transferred data will be afforded such protection; data subject has consented in writing; data user has reasonable grounds to believe transfer is for avoidance or mitigation of adverse action against data subject; data is exempt under Part 8. PCPD has issued Guidance on Personal Data Protection in Cross-border Data Transfer 2014 + revised 2022 recommending data users voluntarily comply with Section 33 standards: assess legal regime of destination, use Recommended Model Contractual Clauses (RMCCs)
- Cross-border transfer register: destination + data category + legal basis + safeguards
- Voluntary Section 33 compliance assessment + destination legal regime evaluation
- PCPD Recommended Model Contractual Clauses (RMCCs) executed with overseas recipients
- GBA Standard Contract Pilot participation + CAC notification (for HK-mainland transfers)
- China PIPL coordination matrix (CAC Standard Contract + Security Assessment + Certification)
- APEC CBPR + Global CBPR Forum participation evidence (if applicable)
- Cross-border transfers without Section 33 voluntary assessment
- Missing PCPD RMCCs with overseas recipients
- Treating HK-mainland transfers same as offshore without GBA Pilot benefit
- No China PIPL CAC Standard Contract for non-GBA mainland transfers
- Missing onward transfer + accountability clauses
HK PDPO DPP1 Purpose + Collection + PICS
Schedule 1 DPP1 Data Collection Principle requires personal data shall not be collected unless for a lawful purpose directly related to a function or activity of the data user, the data is adequate not excessive relevant to that purpose, and the means of collection are lawful and fair. At or before collection, the data user must explicitly take all practicable steps to ensure data subject is informed of: purpose of collection, classes of persons to whom data may be transferred, whether collection is obligatory or voluntary, consequences of non-supply if obligatory, name + title + address of individual to handle data access requests. This is operationalised through a Personal Information Collection Statement (PICS) typically presented at or before collection (forms, websites, applications, customer onboarding, employee onboarding, registration, surveys). PICS components: identification of
- PICS template register (forms, web, app, employee, marketing)
- Purpose register tying each collection point to function or activity
- Adequacy + necessity assessment per data category
- Fairness assessment for covert + sensor + AI-scraping contexts
- DAR contact point register published in each PICS
- Voluntary or obligatory designation per data field
- Missing PICS at collection point (mobile apps + IoT + AI training)
- Generic boilerplate PICS not tying to specific purpose
- Excessive data collection beyond stated purpose
- Missing classes of transferees disclosure
- Missing DAR contact identification + title + address
HK PDPO DPP2 Accuracy + Retention + Records
Schedule 1 DPP2 Accuracy and Retention Principle requires all practicable steps shall be taken to ensure that personal data is accurate having regard to the purpose for which it is to be used, and is not kept longer than is necessary for the fulfilment of the purpose. If a data user engages a data processor whether within or outside Hong Kong to process personal data on its behalf, the data user must adopt contractual or other means to prevent personal data being kept longer than necessary by the processor. PDPO Section 26 imposes specific duty to erase personal data no longer required for the purpose for which it was collected, unless legal exemption applies. Operationalised through: data accuracy verification on intake + periodic refresh, retention schedule per category aligned to lawful purpose, statutory or regulatory retention overrides (e.g. SFO record-keeping, IRO tax records, emp
- Data accuracy verification procedures + logs
- Retention schedule per data category + lawful basis + statutory override
- Periodic retention review evidence + erasure logs
- Section 26 erasure exception documentation
- Processor contracts with retention + return + destruction clauses
- Data inventory + register tying retention to DPP1 purpose
- Indefinite retention without purpose tie
- Missing periodic retention review evidence
- Processor contracts silent on retention + destruction
- No erasure under Section 26 when purpose extinguished
- Missing destruction certificates for sensitive data
HK PDPO DPP3 Use + Direct Marketing
Schedule 1 DPP3 Data Use Principle requires personal data shall not without prescribed consent of the data subject be used for a new purpose (any purpose other than the original purpose for which it was collected or a directly related purpose). 2012 amendments introduced Part 6A Direct Marketing regime (Sections 35A-N) imposing additional layer on use of personal data for direct marketing. Before using personal data in direct marketing, data user must: provide notification (kinds of data to be used + classes of marketing subjects) in easily understandable + readable manner, obtain explicit indication of consent (opt-in style not opt-out), provide channel to withdraw consent at any time without charge, cease use upon receiving opt-out within reasonable time. Before transferring personal data to another person for use in direct marketing, additional notification + written consent + record-
- Direct marketing notification + consent register (Section 35C/35F)
- Easily understandable notification text + class of marketing subjects per channel
- Opt-in consent log + opt-out log + cessation evidence
- Section 35J/35K third party transfer notification + written consent + record
- Direct marketing data class register per Section 35C
- Compatible vs. new purpose decision register under DPP3
- Bundled consent buried in T&Cs failing easily understandable test
- Opt-out without immediate cessation
- Section 35J transfer for marketing without separate written consent
- Missing record keeping for marketing transfers (Section 35K)
- Incompatible secondary use without prescribed consent
HK PDPO DPP4 Security + Processor + Breach
Schedule 1 DPP4 Data Security Principle requires all practicable steps shall be taken to ensure that personal data held by a data user is protected against unauthorised or accidental access, processing, erasure, loss or use. Practicable steps consider: kind of data + harm if compromised, physical location, security measures incorporated in equipment, measures for ensuring integrity prudence + competence of persons with access, measures for ensuring secure transmission. If a data user engages a data processor (within or outside Hong Kong) to process data on its behalf, the data user must adopt contractual or other means to prevent unauthorised + accidental access + processing + erasure + loss + use of the data transferred to the processor. PCPD Guidance on Data Security 2022 + 2024 supplement updates: encryption + access control + network security + endpoint + vulnerability + patching + b
- Information security policies + standards + procedures mapped to PCPD Data Security Guidance 2022
- Processor due diligence + contracts with security + audit + breach clauses
- Voluntary breach notification playbook + PCPD notification template + affected subject notification template
- Incident response + containment + forensics + lessons-learned register
- Vulnerability + patch + access review + privileged access + MFA evidence
- Pending mandatory breach regime readiness assessment (consultation 2024)
- Breach notification not done because regime currently voluntary (best practice still expected)
- Processor contracts silent on breach notification + audit + return
- Generic security baseline not adjusted for sensitivity of data
- Missing privileged access + MFA on critical data systems
- No tabletop or readiness for pending mandatory breach regime
HK PDPO DPP5 Openness
Schedule 1 DPP5 Openness Principle requires a data user to take all practicable steps to ensure that a person can ascertain the data user policies and practices in relation to personal data, the kinds of personal data held, and the main purposes for which personal data held by the data user are or are to be used. Operationalised through Privacy Policy Statement (PPS) published in a place easily accessible to data subjects (typically website footer, mobile app settings, customer service + lobby notices). PCPD recommends PPS components: identity + contact of data user, kinds of data + purposes + transferees, security measures + retention, DAR + DCR procedures + contact, complaints procedure, cross-border transfer (best practice), use of cookies + tracking (best practice), use of AI + automated decision-making (PCPD 2024 Generative AI guidance). PPS distinct from PICS: PPS is the organisati
- Privacy Policy Statement on public website + mobile app + customer service
- PPS version control + effective date + change history
- Bilingual (English + Traditional Chinese + Simplified Chinese) PPS versions
- Annual PPS review evidence + post-change update procedures
- AI + automated decision-making disclosure section per PCPD 2024 Generative AI guidance
- Accessibility AA evidence for digital PPS
- PPS only in English on HK-facing service
- Buried PPS link not easily accessible
- Stale PPS not reflecting current practices or 2021 doxxing or 2024 AI guidance
- No annual review + version control
- Missing AI + automated decision disclosure
HK PDPO DPP6 Access + Correction + Complaints
Schedule 1 DPP6 Data Access and Correction Principle establishes a data subject right to (a) ascertain whether a data user holds personal data of which he is the subject, (b) request access to personal data within reasonable time + fee + form + manner, and (c) request correction of inaccurate personal data. Operationalised through statutory Data Access Request (DAR) regime under Sections 18-28A: prescribed form (DAR Form OPS003), 40-day response timeframe, prescribed fee not exceeding cost of compliance, compliance period extendable in limited cases, statutory exemptions (security + immigration + crime + legal professional privilege + statistical research + judicial + emergency). Data Correction Request (DCR) regime under Sections 22-25: request correction of inaccurate data, 40-day response, refusal grounds + reasons in writing + log statement attached to data if correction refused. Com
- DAR + DCR procedures + forms + intake + tracking + response register
- 40-day SLA evidence + extension procedures + audit trail
- Fee schedule + calculation methodology
- Statutory exemption decision register + reasons + Section 58/59/60/61 evidence
- Complaints register + escalation flow + PCPD liaison + AAB readiness
- DCR refusal log statement attached to relevant data
- No 40-day SLA evidence or breaches
- Excessive fee charged beyond cost of compliance
- Misapplied statutory exemption without documented reasoning
- No log statement attached on DCR refusal
- Missing complaint escalation procedure + PCPD liaison
HK PDPO Enforcement + PCPD Powers
Privacy Commissioner for Personal Data (PCPD) is the independent statutory regulator with full investigation + inspection + enforcement powers. Investigation may be triggered by complaint or own-motion. Inspection power to inspect any personal data system (Section 36). Compliance Check + Compliance Audit. Enforcement Notice power (Section 50) requiring data user to remedy contravention + steps + timeframe; non-compliance is criminal offence (HKD 50,000 + 2 years first offence; HKD 100,000 + 2 years + HKD 1,000 per day continuing offence on repeat). Specific criminal penalties: DPP3 use without prescribed consent for direct marketing Section 35E (HKD 500,000 + 3 years); transfer for gain Section 35J (HKD 1,000,000 + 5 years); ignoring opt-out Section 35L (HKD 500,000); doxxing basic Section 64(3A) (HKD 100,000 + 2 years); doxxing aggravated Section 64(3C) (HKD 1,000,000 + 5 years); cessat
- PCPD investigation cooperation playbook + legal liaison + evidence preservation
- Compliance Check + Compliance Audit readiness materials
- Enforcement Notice tracker + remediation evidence + timeframe + audit
- Criminal penalty risk register per Section (35E/35J/35L/64/66J)
- Anti-Doxxing Division 24/7 contact + 24-hour takedown SLA target
- AAB + court appeal procedures + retained external counsel + insurance
- No PCPD cooperation playbook or legal liaison
- Missing Enforcement Notice remediation evidence + timeframe + audit
- Direct marketing penalty risk not quantified
- Slow doxxing takedown beyond 24h target risking Section 66J liability
- No AAB appeal procedure or retained external counsel
HK PDPO Governance + PMP + DPO + DPIA
PCPD Best Practice Guide on Privacy Management Programme (PMP) 2014 + 2018 + 2024 updates establishes accountability-based governance expectations for data users: top management commitment + dedicated personal data privacy officer or function + reporting line to top management + personal data inventory + privacy policies + risk assessment processes + training + breach handling + communication + complaint handling + monitoring + review + continuous improvement. While DPO is not statutorily required by PDPO, PCPD strongly recommends a Data Protection Officer or Privacy Lead and PCPD PMP Manual provides DPO function description. Privacy Impact Assessment (PIA) recommended for new programmes + systems + technologies including AI + biometric + cloud + cross-border + IoT + analytics. PCPD PIA Information Leaflet + Template + Annexes. Records of processing activities (RoPA-style) + personal dat
- PMP Manual + governance charter + top management commitment evidence + reporting line
- DPO appointment + role description + reporting line to top management + independence
- PIA methodology + register + template + completed PIAs for AI + biometric + cloud + cross-border
- Personal data inventory + records of processing + lawful basis + retention + safeguards
- Annual mandatory training + role-based modules + attendance + assessment + refresh
- Management review + internal audit + continuous improvement evidence
- No PMP framework or appointed DPO function
- PIA only at IT level not covering AI or biometric or cross-border
- No personal data inventory or stale inventory
- Generic privacy training not adjusted to PDPO + 2021 doxxing + 2024 AI
- No management review or internal audit of PMP
HK PDPO Scope + Coverage + History
Personal Data (Privacy) Ordinance Cap 486 of Hong Kong SAR is one of Asia oldest comprehensive data protection laws (passed 1995, in force December 1996). It applies to data users who control collection holding processing or use of personal data (broadly defined) about identifiable living individuals in or from Hong Kong, regardless of medium. Origins: 1994 Law Reform Commission Report Reform of the Law Relating to the Protection of Personal Data, based on OECD Privacy Guidelines 1980. Establishes Privacy Commissioner for Personal Data (PCPD) as independent statutory authority. Six Data Protection Principles (DPPs) in Schedule 1 form the normative core covering full data lifecycle. Major 2012 amendments introduced direct marketing prescribed consent regime (Sections 35A-N), creation of data protection officer recommendation, criminal penalties for misuse, processor oversight obligations.
- PDPO Cap 486 register of applicability
- Mapping of data user data subject data processor roles to PDPO definitions
- Schedule 1 DPPs implementation matrix
- 2012 Direct Marketing register
- 2021 Doxxing risk register + PCPD cessation notice readiness
- PCPD guidance subscription + 2024 Generative AI framework mapping
- Coordination matrix with China PIPL + APEC CBPR + Macao 8/2005
- Missing 2012 direct marketing prescribed consent register
- Missing 2021 doxxing risk assessment + cessation notice playbook
- Conflating PDPO with PRC PIPL despite One Country Two Systems separation
- Stale PCPD guidance references
- Missing Section 33 cross-border transfer impact assessment
HK PDPO Sensitive + CCTV + Workplace + Children
PDPO does not have GDPR-style special categories of sensitive data definition, but PCPD has issued codes of practice and sectoral guidance treating certain data categories with heightened expectations: Code of Practice on Human Resources Management (covering recruitment, current employment, former employment, monitoring), Code of Practice on Consumer Credit Data, Guidance on CCTV + Drones (2015 + 2024 updates), Guidance on Collection + Use of Personal Data + Use of Mobile Apps, Guidance on Personal Data of Customers + Members + Subscribers. CCTV expectations: PIA + necessity + proportionality + signage + retention 30-90 days typical + processor or operator due diligence + access logs + privacy zones + facial recognition + AI analytics impact assessment. Workplace monitoring: PCPD Code of Practice on Human Resources Management + Privacy Guidelines on Monitoring and Personal Data Privacy a
- Sensitive data register + classification mapped to PCPD sectoral codes
- CCTV PIA + signage + retention + access log + facial recognition assessment
- Workplace monitoring 3-A test evidence + Privacy Guidelines on Monitoring
- Children data PIA + age verification + EdTech operator due diligence
- Health data eHRSS framework alignment + biometric Guidance on Fingerprint Data 2015 assessment
- Code of Practice on HR Management + Consumer Credit Data adoption evidence
- CCTV without signage or PIA
- Workplace monitoring without 3-A test (assessment alternative accountability)
- Facial recognition + AI analytics without separate PIA
- Children data without age verification + parental notification
- Health + biometric data treated as ordinary without heightened controls
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) framework page.