Act 1995
Personal Data (Privacy) Ordinance (Cap. 486)
Issued by Privacy Commissioner for Personal Data
Effective: 20 Dec 1996
Last amended: 18 Jul 2025
Plain-English summary
The Personal Data (Privacy) Ordinance (Cap. 486) can be referred to as the law in the Hong Kong jurisdiction concerning the privacy of individuals regarding personal data. It is overseen by the PCPD, and there are six Data Protection Principles (DPPs), which include collection of personal data, accuracy of personal data, retention of personal data, use of personal data, security of personal data, and openness of personal data. The rights of the data subject involve access to and modification of personal data under the law, do not allow the use of personal data for direct marketing without consent, and give the Privacy Commissioner substantial powers to audit firms regarding data breaches and doxxing operations.
Who it applies to
Banking · Insurance · Telecom & Tech
Topics
Data Protection & Privacy
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| Lawful basis, notice and data subject rights | Ongoing | PCPD | source | |
In terms of the lawful basis, notice, and data subject rights in Hong Kong, the model is a hybrid one, which includes event triggered, ongoing, and retention requirements and is governed by the Personal Data (Privacy) Ordinance (PDPO). The notice requirement is entirely event triggered, in the sense that it requires the display of Personal Information Collection Statement (PICS) at the point in time when the information is collected, while Data Access Requests (DARs) result in a strict, non-repeating 40-day statutory period of compliance. Ingested data is subject to an ongoing requirement to ensure continuous accuracy and non-excessiveness of data, with respect to its initial business purpose and a strict retention requirement that requires personal data not to be retained any longer than needed. However, the privacy deletion mandate is regularly superseded by the Anti-Money Laundering Ordinance (AMLO), which legally requires data to be stored for 5 to 7 years after the account or transaction closure. |
||||
| Personal data breach notification | Deadline Event-based | PCPD | source | |
The breach notification requirement for personal data in Hong Kong is an event-driven and voluntarily followed best practice guided by the Personal Data (Privacy) Ordinance (PDPO) and not a hard-and-fast statute . The regime only kicks into gear when the company realizes there has been a data breach which creates the risk of serious damage to the data subjects and thus triggers the voluntary notification of both the regulatory body and the individuals "as soon as practicable." While the generic response timeframe for such notification is a flexible administrative guideline and not a set calendar count down (typically averaging about 12 days for prompt response), companies are required to provide immediate and provisional notification without waiting for the completion of long forensic audits. The voluntary timeframe changes to an obligatory one should the data breach be related to critical infrastructure or HKMA licensed banks and the failure to resolve the security loophole that precipitated such a breach may even lead to the issuance of a statutory Enforcement Notice by the privacy regulator. |
||||
| No obligations match these filters. | ||||
Latest news
No related news yet. We publish updates as regulators act.