#
Core regulator/statute framework is well-established (green-equivalent), but material and territorial scope diverge substantially from GDPR baseline, and a registration/filing sub-module could not be evidenced, warranting amber overall.
Sub-modules (5)
Regulator And AuthorityGreen
PCPD is the statutory regulator headed by the Privacy Commissioner, with investigative and enforcement powers under the PDPO.
Claims: CLM-HK-a1b2c301
Act And InstrumentsGreen
PDPO Cap. 486 (in force since 1996) is the principal instrument, materially amended in 2012 (direct marketing) and 2021 (anti-doxxing).
Claims: CLM-HK-a1b2c302
Material ScopeAmber
PDPO scope centers on Data Protection Principles (DPPs) governing collection, holding, processing and use of personal data by 'data users'.
Claims: CLM-HK-a1b2c303
Territorial ScopeAmber
PCPD has clarified PDPO has no extraterritorial scope; it applies where the data user's principal place of business is in Hong Kong.
Claims: CLM-HK-a1b2c304
Regulator Registration And FilingRed
No evidence located of a general controller registration/filing obligation to PCPD akin to EU-style DPA registers.
Absence provenance: not recorded. Searched: PCPD registration requirement data user Hong Kong, PDPO controller notification filing obligation.
Sources and claims (4)
- ConfirmedDataGuidance — The Office of the Privacy Commissioner for Personal Data (PCPD) is the main body responsible for overseeing enforcement of the PDPO and is headed by the Privacy Commissioner for Personal Data.
- ConfirmedDataGuidance — The Personal Data (Privacy) Ordinance (Cap. 486) came into force on 20 December 1996 and was significantly amended by the 2012 Amendment Ordinance (direct marketing) and the 2021 Amendment Ordinance (anti-doxxing).
- ConfirmedIAPP — Data Protection Principle 1(1) requires that only necessary, adequate and not excessive personal data be collected for a lawful purpose, forming part of PDPO's core material-scope obligations on data users.
- ConfirmedDataGuidance — The PDPO is unclear on its territorial scope on its face, but the PCPD has clarified that the PDPO does not have extraterritorial scope, in contrast to the GDPR's extraterritorial application.