Hong Kong
6 regulators · 7 instruments · 6 obligations
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | JFIU | Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) | source | |
Anti-money laundering regime in Hong Kong as stipulated in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance requires the adoption of risk-based compliance programs, which include Customer Due Diligence, transaction monitoring, and record keeping for a period of six years. Organizations are supposed to have a Compliance Officer and a Money Laundering Reporting Officer responsible for ensuring internal controls and filing Suspicious Transaction Reports to the Joint Financial Intelligence Unit, with penalties for not complying of HK$10 million and seven years' imprisonment. |
|||||
| AML record retention | Retention period 5 years | JFIU | Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) | source | |
With respect to the timing of the AML document retention rule of Hong Kong, a rigid statutory period of at least five years should be set forth, wherein the trigger factor of the period depends solely on the category of the document to be stored [AMLO Cap 615 Hong Kong]. In terms of Customer Due Diligence (CDD) documents and account opening documents, the five-year period starts on the exact date when the business relationship is ended. Meanwhile, in the case of transaction documents, the five-year period commences on the date when the transaction is completed, no matter what status the account is having [AMLO Cap 615 Hong Kong]. In practice, the time periods may go beyond five years due to other regulatory mandates of different sectors (such as the Customs and Excise Department), as well as the Hong Kong Companies Ordinance, not to mention the indefinite period of those files linked to an ongoing JFIU investigation. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | JFIU | Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) | source | |
The CDD/KYC requirement in Hong Kong is a risk-based preventative statutory obligation which acts as a strict gatekeeper for financial crime [AMLO Cap 615 Hong Kong]. The requirement makes it a total responsibility of the institutions and compliance officers to identify the identity of customers before any business relation or transaction can be made, totally disallowing any anonymity or false accounts [AMLO Cap 615 Hong Kong]. This obligation is not a strict checklist but rather a requirement where the institutions will have to make a risk-based approach – conducting EDD on risky accounts as well as looking through corporate structures to expose any ultimate beneficial owners who hold over 25% stake. In summary, if the institution fails to meet these requirements, the legal mandate requires them to block the transaction and end the business relations while considering the necessity of filing a suspicious activity report. |
|||||
| Suspicious transaction reporting | Deadline Event-based | JFIU | Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) | source | |
The temporal value of the HK’s obligation regarding suspicious transaction reporting requires that a report should be submitted "as soon as is reasonably practicable." Since this requirement is an immediate statutory obligation, there is no pre-established schedule or multi-day period of grace. Instead, regulators anticipate prompt internal notification of the MLRO and reporting directly to the JFIU. When the suspicion is generated before the execution of a transaction, the timeliness of reporting becomes vital since the company needs to freeze the transaction instantly in order to receive "Authorized Consent" from the JFIU, as handling of suspicious funds before submitting a report is the primary form of money laundering offense. Moreover, when a report is made, the typical five-seven-year cycle of data deletion is suspended and the records need to be kept forever until the case is closed by the law enforcement agency. |
|||||
| Telecom & Tech | |||||
| Lawful basis, notice and data subject rights | Ongoing | PCPD | Personal Data (Privacy) Ordinance (Cap. 486) | source | |
In terms of the lawful basis, notice, and data subject rights in Hong Kong, the model is a hybrid one, which includes event triggered, ongoing, and retention requirements and is governed by the Personal Data (Privacy) Ordinance (PDPO). The notice requirement is entirely event triggered, in the sense that it requires the display of Personal Information Collection Statement (PICS) at the point in time when the information is collected, while Data Access Requests (DARs) result in a strict, non-repeating 40-day statutory period of compliance. Ingested data is subject to an ongoing requirement to ensure continuous accuracy and non-excessiveness of data, with respect to its initial business purpose and a strict retention requirement that requires personal data not to be retained any longer than needed. However, the privacy deletion mandate is regularly superseded by the Anti-Money Laundering Ordinance (AMLO), which legally requires data to be stored for 5 to 7 years after the account or transaction closure. |
|||||
| Personal data breach notification | Deadline Event-based | PCPD | Personal Data (Privacy) Ordinance (Cap. 486) | source | |
The breach notification requirement for personal data in Hong Kong is an event-driven and voluntarily followed best practice guided by the Personal Data (Privacy) Ordinance (PDPO) and not a hard-and-fast statute . The regime only kicks into gear when the company realizes there has been a data breach which creates the risk of serious damage to the data subjects and thus triggers the voluntary notification of both the regulatory body and the individuals "as soon as practicable." While the generic response timeframe for such notification is a flexible administrative guideline and not a set calendar count down (typically averaging about 12 days for prompt response), companies are required to provide immediate and provisional notification without waiting for the completion of long forensic audits. The voluntary timeframe changes to an obligatory one should the data breach be related to critical infrastructure or HKMA licensed banks and the failure to resolve the security loophole that precipitated such a breach may even lead to the issuance of a statutory Enforcement Notice by the privacy regulator. |
|||||
| No obligations match these filters. | |||||