EnglishZH-HK
Hong Kong flag

Hong Kong

Hong Kong Data Privacy Laws: Complete PDPO Compliance Guide (2026)

By Recording Law Editorial TeamReviewed May 19, 202626 min read
Hong Kong Data Privacy Laws: Complete PDPO Compliance Guide (2026)

Frequently Asked Questions

What is the PDPO and when did it take effect?

The Personal Data (Privacy) Ordinance (PDPO, Cap. 486) is Hong Kong's comprehensive data privacy statute. It was enacted in 1995 and took effect on December 20, 1996, making it one of Asia's earliest data privacy laws. It has been significantly amended twice: in 2012 (direct marketing provisions) and in 2021 (anti-doxxing and expanded PCPD enforcement powers).

Does Hong Kong restrict cross-border data transfers?

No, not currently. Section 33 of the PDPO was enacted to restrict cross-border transfers but has never been brought into force. As of mid-2026, there is no statutory prohibition on transferring personal data outside Hong Kong. The PCPD's 2022 Recommended Model Contractual Clauses are best practice but not legally required. The reform proposals under consultation in 2026 include the possible activation of Section 33.

Is data breach notification mandatory in Hong Kong?

No. The PDPO does not currently require organisations to notify the PCPD or affected individuals when a personal data breach occurs. Notification is voluntary. The PCPD's guidance recommends prompt voluntary notification for significant breaches. As of early 2026, the government is consulting lawmakers on introducing a mandatory breach notification requirement as part of a broader reform package. The proposed framework would require notification within five business days for breaches posing a real risk of significant harm.

What are the penalties for doxxing under Hong Kong law?

The 2021 amendments created two tiers. First-tier: disclosing personal data without consent with intent to cause specified harm carries a maximum fine of HK$100,000 and 2 years' imprisonment. Second-tier: where the disclosure actually causes the specified harm, the maximum penalty is a fine of HK$1,000,000 and 5 years' imprisonment. Non-compliance with a PCPD cessation notice also carries HK$100,000 and 2 years.

How does the PDPO differ from the GDPR?

The PDPO uses a principles-based framework (6 DPPs) without requiring a specific legal basis for every processing activity, while the GDPR is rights-based and mandates one of six legal bases. Key PDPO gaps relative to the GDPR: no mandatory breach notification, no administrative fines, no right to erasure or data portability, no formal sensitive data category, and no mandatory DPO requirement. The PDPO also does not currently restrict cross-border transfers (Section 33 is not in force), whereas the GDPR requires adequacy decisions or standard contractual clauses.

What rights do data subjects have under the PDPO?

Data subjects have: the right to access their personal data held by a data user (Data Access Request, to be answered within 40 days); the right to correct inaccurate data (Data Correction Request, within 40 days); the right to withdraw consent for direct marketing use at any time and without charge; and the right to seek compensation through civil proceedings for PDPO contraventions, including for injured feelings. There is no right to erasure, portability, or objection to automated decision-making under current law.

Is a Data Protection Officer required in Hong Kong?

No. The PDPO does not require organisations to appoint a Data Protection Officer. However, the PCPD recommends that larger organisations or those processing significant volumes of personal data designate a responsible individual or team for data protection compliance. This is particularly advisable for organisations also subject to mainland China's PIPL, which does require a personal information protection officer in certain circumstances.

How does the PDPO handle AI and machine learning?

The PDPO's six DPPs apply to AI systems that process personal data, but the Ordinance contains no AI-specific provisions. The PCPD has filled this gap with guidance: the June 2024 AI Model Personal Data Protection Framework, the March 2025 GenAI employee checklist, 2025 guidance on agentic AI risks, and a May 2025 report from compliance checks on 60 organisations. Legislative reform proposals include AI regulation as a potential new element of the PDPO.

How does the PDPO relate to mainland China's PIPL?

They are separate frameworks. Hong Kong operates under one country, two systems. China's PIPL does not automatically apply to organisations operating solely in Hong Kong. Organisations with operations in both jurisdictions must comply with both the PDPO and the PIPL independently. The PIPL imposes significantly stricter requirements: mandatory breach notification, mandatory PIPO for certain processors, strict cross-border transfer controls, and fines of up to 50 million RMB or 5% of annual revenue.

What is the PCPD's enforcement record on doxxing?

From October 2021 through December 2025: 2,104 cessation notices to 57 platforms; 33,743 doxxing messages removed; over 96% platform compliance; 519 criminal investigations; 150 cases referred to Police; 81 arrests; 55 prosecutions; 43 convictions. Annual doxxing cases have declined from a peak of 756 in 2023 to 442 in 2024 and 308 in 2025, suggesting a deterrence effect from visible enforcement.

Updates

Expanded to ~6,200 words. Added 2025 PCPD annual enforcement statistics (4,228 complaints, 246 breach notifications, cumulative doxxing record). Added 2026 breach notification reform revival. Expanded AI guidance section (2024 Model Framework, 2025 GenAI checklist, agentic AI guidance, May 2025 compliance checks). Expanded cross-border transfer section (Section 33 status, 2022 RMCs, GBA standard contract). Added DPO/data protection officer practice section. Added comprehensive PDPO vs [GDPR](/world-laws/world-data-privacy-laws) vs PIPL comparison table. Expanded compliance checklist.

Initial publication.

Sources and References

  1. Hong Kong e-Legislation - Personal Data (Privacy) Ordinance (Cap. 486)(elegislation.gov.hk).gov
  2. Hong Kong e-Legislation - Personal Data (Privacy) (Amendment) Ordinance 2021(elegislation.gov.hk).gov
  3. PCPD - The Six Data Protection Principles(pcpd.org.hk).gov
  4. PCPD - The Personal Data (Privacy) Ordinance at a Glance(pcpd.org.hk).gov
  5. PCPD - About the Privacy Commissioner for Personal Data(pcpd.org.hk).gov
  6. PCPD - Privacy Commissioner Reports on Work in 2025(pcpd.org.hk).gov
  7. PCPD - Privacy Commissioner Reports on Work in 2024 (January 2025)(pcpd.org.hk).gov
  8. PCPD - Data Breach Notification Guidance(pcpd.org.hk).gov
  9. PCPD - Guidance on Cross-Border Data Transfer (Section 33)(pcpd.org.hk).gov
  10. PCPD - Guidance on Recommended Model Contractual Clauses for Cross-border Transfers (2022)(pcpd.org.hk).gov
  11. PCPD - Artificial Intelligence: Model Personal Data Protection Framework (June 2024)(pcpd.org.hk).gov
  12. PCPD - AI Guidance and Publications(pcpd.org.hk).gov
  13. PCPD - Compliance Checks on AI Security Completed (May 2025)(pcpd.org.hk).gov
  14. PCPD - Guidance on Direct Marketing (April 2023)(pcpd.org.hk).gov
  15. PCPD - AI Compliance Checks Report 2025(pcpd.org.hk).gov
Share: