WorldPrivacyAtlas
Laws by country

Comprehensive Privacy Law

Personal Data (Privacy) Ordinance

PDPO

Hong Kong · December 20, 1996; doxxing offences and PCPD enforcement powers added October 8, 2021

Verify details

Hong Kong's PDPO applies to a data user who, alone or jointly, controls the collection, holding, processing or use of personal data 'in or from Hong Kong' — a control-and-location test rather than a GDPR targeting test, so the trigger below is modeled on established presence only; a foreign business directing services at Hong Kong residents from wholly outside the territory is not automatically caught. Two features surprise businesses used to GDPR: section 33, the cross-border transfer restriction, was enacted in 1995 but has never been brought into force, so outbound transfers are governed by guidance rather than a statutory bar; and there is still no general mandatory breach-notification duty (notification to the PCPD is voluntary, though strongly encouraged). The 2021 amendments criminalized doxxing and gave the Privacy Commissioner investigation and takedown powers with extraterritorial effect for those specific offences.

Cap. 486, s. 39 (application); anti-doxxing amendments by Ordinance No. 22 of 2021Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.