Personal Data (Privacy) Ordinance (PDPO)
Enacted in 1996 and amended multiple times since, the PDPO is Hong Kong’s primary data protection legislation. It applies to the collection, holding, use, and disclosure of personal data by both public and private sector organisations.
Key Principles
The PDPO establishes 8 Data Protection Principles (DPPs):
- Purpose and Manner of Collection: Personal data must be collected lawfully and by fair means, only for specified purposes directly related to the organisation’s functions.
- Quality of Data: Data should be accurate, complete, and not misleading.
- Retention: Data should only be retained as long as necessary for the original purpose or a directly related purpose.
- Security: Organisations must take practical steps to protect personal data from loss, unauthorised access, or disclosure.
- Use and Disclosure: Data should only be used for the purpose for which it was collected, unless the individual consents to additional uses.
- Right of Access: Individuals have the right to request access to their personal data held by an organisation.
- Right to Correction: Individuals can request correction of inaccurate personal data.
- Accountability: Organisations must be able to demonstrate compliance with all other principles.
Role of the Privacy Commissioner
The Privacy Commissioner for Personal Data (PCPD) is responsible for administering the PDPO, investigating complaints, and providing guidance on data protection matters.
Compliance Steps for Businesses
- Conduct a personal data audit to identify what data you collect and how it’s used
- Implement appropriate technical and organisational security measures
- Establish procedures for handling data subject access requests
- Train staff on data protection requirements
- Review and update privacy policies regularly
- Notify the PCPD of any personal data breach within a reasonable timeframe
Hong Kong operator checklist
- Confirm whether the systems, vendors, or practices described apply to your estate.
- Assign an owner and a review date — do not leave findings as unread newsletter content.
- Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
- Brief leadership with a dated one-page note when residual risk remains high.
What “good” looks like
- Controls are operated, not only documented
- Privileged access uses phishing-resistant MFA where feasible
- Detection and response paths are exercised at least annually
- Third-party dependencies have an owner and an exit plan
Sources and further reading
- HKISG Security Bulletins
- Assessment Methodology
- Governance & Integrity
- Online Education
- External: HKCERT · PCPD
Editorial note
This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.
Frequently asked questions
Who should read this?
Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.
Does this change any public HKISG rating?
No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.
How often is this content reviewed?
HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.