WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

Hong Kong Privacy & Data Protection Laws

Every regime below can apply to a business handling Hong Kong residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

December 20, 1996; doxxing offences and PCPD enforcement powers added October 8, 2021
Personal Data (Privacy) Ordinance
PDPO
Verify details

Hong Kong's PDPO applies to a data user who, alone or jointly, controls the collection, holding, processing or use of personal data 'in or from Hong Kong' — a control-and-location test rather than a GDPR targeting test, so the trigger below is modeled on established presence only; a foreign business directing services at Hong Kong residents from wholly outside the territory is not automatically caught. Two features surprise businesses used to GDPR: section 33, the cross-border transfer restriction, was enacted in 1995 but has never been brought into force, so outbound transfers are governed by guidance rather than a statutory bar; and there is still no general mandatory breach-notification duty (notification to the PCPD is voluntary, though strongly encouraged). The 2021 amendments criminalized doxxing and gave the Privacy Commissioner investigation and takedown powers with extraterritorial effect for those specific offences.

Cap. 486, s. 39 (application); anti-doxxing amendments by Ordinance No. 22 of 2021Read regulation →

Other Asia-Pacific jurisdictions