Hong Kong
6 regulators · 7 instruments · 6 obligations
Hong Kong is one of the most developed special administrative regions of China and still one of the main centers of the world economy and finance.
Regulatory pulse · 90 days
Laws & circulars Enforcement NewsOverview
VERIFIED 23 SEP 2026Hong Kong is one of the most developed special administrative regions of China and still one of the main centers of the world economy and finance. Geographically, Hong Kong is situated in East Asia and acts as an access point not only for China but also for the whole area of the Greater Bay, which includes Guangdong, Hong Kong, and Macau. With the principle of “one country, two systems,” Hong Kong has preserved its distinctive legal, financial, and border status, including its own currency of the Hong Kong Dollar and its own system of common law.
Macroeconomic financial risks continue to be quite healthy and strong for this territory based on huge current account surpluses, low public debt below 15% of GDP, and an excellent structural business environment. Nevertheless, there are considerable structural weaknesses associated with geographic and economic concentration, making the territory’s financial system very vulnerable to fluctuations in trade relations and demand in mainland China. From a political point of view, there are now much tighter conditions after the adoption of the National Security Law (NSL) and local national security frameworks. Although these measures prevent any potential internal political instabilities, at the same time they increase the geopolitical risks.
Corporate regulation with regard to governance still conforms to international standards that are very advanced. HKEX implements the Corporate Governance Code with a “comply or explain” approach, necessitating independent boards. Regulatory efficiency and anti-corruption performance by public institutions are very competitive. On the other hand, the HKMA is harmonizing local regulatory requirements to fit international standards in light of the Basel III changes and IMF financial sector assessments.
Compliance and AML have reached an era of quick modernization. With the AMLO regime, regulatory authorities have been making significant efforts to address governance gaps and shortcomings in record-keeping. The compliance approach is transitioning from fixed text-based screening to complex behavior-based monitoring. From an operational perspective, the roll-out of the mandatory STREAMS 2 system necessitates regulated institutions to file highly digitized suspicious transaction reports. Meanwhile, there are new regimes being developed for the implementation of a stringent, securities-equivalent regime for virtual asset dealing and custody.
In the realm of sanctions, Hong Kong is subject to a dual-threat situation. At the local level, the Hong Kong government applies the decisions of the United Nations Security Council through the United Nations Sanctions Ordinance, where strict targeted measures are imposed against listed terrorist organizations as well as rogue states. But at the same time, with rising tension in geopolitics, the global financial institutions of Hong Kong find themselves highly exposed to unilateral Western systems such as U.S. OFAC, UK, and EU sanctions systems.
Key laws & regulations
All Laws & Regulations →| Instrument | Type | Year | Regulator | Source |
|---|---|---|---|---|
| SFC Guidelines for Virtual Asset Trading Platform Operators | Guideline | 2023 | SFC | official |
| Payment Systems and Stored Value Facilities Ordinance (Cap. 584) | Act | 2015 | HKMA | official |
| Companies Ordinance (Cap. 622) | Act | 2012 | CR | official |
| Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) | Act | 2011 | JFIU | official |
| Securities and Futures Ordinance (Cap. 571) | Act | 2002 | SFC | official |
| No instruments match these filters. | ||||
Industry compliance
Essential obligations
All obligations →| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | JFIU | source | |
Anti-money laundering regime in Hong Kong as stipulated in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance requires the adoption of risk-based compliance programs, which include Customer Due Diligence, transaction monitoring, and record keeping for a period of six years. Organizations are supposed to have a Compliance Officer and a Money Laundering Reporting Officer responsible for ensuring internal controls and filing Suspicious Transaction Reports to the Joint Financial Intelligence Unit, with penalties for not complying of HK$10 million and seven years' imprisonment. |
||||
| AML record retention | 5 years | JFIU | source | |
With respect to the timing of the AML document retention rule of Hong Kong, a rigid statutory period of at least five years should be set forth, wherein the trigger factor of the period depends solely on the category of the document to be stored [AMLO Cap 615 Hong Kong]. In terms of Customer Due Diligence (CDD) documents and account opening documents, the five-year period starts on the exact date when the business relationship is ended. Meanwhile, in the case of transaction documents, the five-year period commences on the date when the transaction is completed, no matter what status the account is having [AMLO Cap 615 Hong Kong]. In practice, the time periods may go beyond five years due to other regulatory mandates of different sectors (such as the Customs and Excise Department), as well as the Hong Kong Companies Ordinance, not to mention the indefinite period of those files linked to an ongoing JFIU investigation. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | JFIU | source | |
The CDD/KYC requirement in Hong Kong is a risk-based preventative statutory obligation which acts as a strict gatekeeper for financial crime [AMLO Cap 615 Hong Kong]. The requirement makes it a total responsibility of the institutions and compliance officers to identify the identity of customers before any business relation or transaction can be made, totally disallowing any anonymity or false accounts [AMLO Cap 615 Hong Kong]. This obligation is not a strict checklist but rather a requirement where the institutions will have to make a risk-based approach – conducting EDD on risky accounts as well as looking through corporate structures to expose any ultimate beneficial owners who hold over 25% stake. In summary, if the institution fails to meet these requirements, the legal mandate requires them to block the transaction and end the business relations while considering the necessity of filing a suspicious activity report. |
||||
| Suspicious transaction reporting | Event-based | JFIU | source | |
The temporal value of the HK’s obligation regarding suspicious transaction reporting requires that a report should be submitted "as soon as is reasonably practicable." Since this requirement is an immediate statutory obligation, there is no pre-established schedule or multi-day period of grace. Instead, regulators anticipate prompt internal notification of the MLRO and reporting directly to the JFIU. When the suspicion is generated before the execution of a transaction, the timeliness of reporting becomes vital since the company needs to freeze the transaction instantly in order to receive "Authorized Consent" from the JFIU, as handling of suspicious funds before submitting a report is the primary form of money laundering offense. Moreover, when a report is made, the typical five-seven-year cycle of data deletion is suspended and the records need to be kept forever until the case is closed by the law enforcement agency. |
||||
| Lawful basis, notice and data subject rights | Ongoing | PCPD | source | |
In terms of the lawful basis, notice, and data subject rights in Hong Kong, the model is a hybrid one, which includes event triggered, ongoing, and retention requirements and is governed by the Personal Data (Privacy) Ordinance (PDPO). The notice requirement is entirely event triggered, in the sense that it requires the display of Personal Information Collection Statement (PICS) at the point in time when the information is collected, while Data Access Requests (DARs) result in a strict, non-repeating 40-day statutory period of compliance. Ingested data is subject to an ongoing requirement to ensure continuous accuracy and non-excessiveness of data, with respect to its initial business purpose and a strict retention requirement that requires personal data not to be retained any longer than needed. However, the privacy deletion mandate is regularly superseded by the Anti-Money Laundering Ordinance (AMLO), which legally requires data to be stored for 5 to 7 years after the account or transaction closure. |
||||
| Personal data breach notification | Event-based | PCPD | source | |
The breach notification requirement for personal data in Hong Kong is an event-driven and voluntarily followed best practice guided by the Personal Data (Privacy) Ordinance (PDPO) and not a hard-and-fast statute . The regime only kicks into gear when the company realizes there has been a data breach which creates the risk of serious damage to the data subjects and thus triggers the voluntary notification of both the regulatory body and the individuals "as soon as practicable." While the generic response timeframe for such notification is a flexible administrative guideline and not a set calendar count down (typically averaging about 12 days for prompt response), companies are required to provide immediate and provisional notification without waiting for the completion of long forensic audits. The voluntary timeframe changes to an obligatory one should the data breach be related to critical infrastructure or HKMA licensed banks and the failure to resolve the security loophole that precipitated such a breach may even lead to the issuance of a statutory Enforcement Notice by the privacy regulator. |
||||
| No obligations match these filters. | ||||





