Jurisdiction Guides / Asia-Pacific
Hong Kong Privacy & Data Protection Laws
Every regime below can apply to a business handling Hong Kong residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Hong Kong's PDPO applies to a data user who, alone or jointly, controls the collection, holding, processing or use of personal data 'in or from Hong Kong' — a control-and-location test rather than a GDPR targeting test, so the trigger below is modeled on established presence only; a foreign business directing services at Hong Kong residents from wholly outside the territory is not automatically caught. Two features surprise businesses used to GDPR: section 33, the cross-border transfer restriction, was enacted in 1995 but has never been brought into force, so outbound transfers are governed by guidance rather than a statutory bar; and there is still no general mandatory breach-notification duty (notification to the PCPD is voluntary, though strongly encouraged). The 2021 amendments criminalized doxxing and gave the Privacy Commissioner investigation and takedown powers with extraterritorial effect for those specific offences.
Other Asia-Pacific jurisdictions