🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
HK · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 16 sources retrieved model claude-sonnet-5 ·

Hong Kong

HK schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 48 claims · 16 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
48Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core regulator/statute framework is well-established (green-equivalent), but material and territorial scope diverge substantially from GDPR baseline, and a registration/filing sub-module could not be evidenced, warranting amber overall.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486)
Traffic-light rationale — AmberCore regulator/statute framework is well-established (green-equivalent), but material and territorial scope diverge substantially from GDPR baseline, and a registration/filing sub-module could not be evidenced, warranting amber overall.

Sub-modules (5)

Regulator And AuthorityGreen

PCPD is the statutory regulator headed by the Privacy Commissioner, with investigative and enforcement powers under the PDPO.

Claims: CLM-HK-a1b2c301

Act And InstrumentsGreen

PDPO Cap. 486 (in force since 1996) is the principal instrument, materially amended in 2012 (direct marketing) and 2021 (anti-doxxing).

Claims: CLM-HK-a1b2c302

Material ScopeAmber

PDPO scope centers on Data Protection Principles (DPPs) governing collection, holding, processing and use of personal data by 'data users'.

Claims: CLM-HK-a1b2c303

Territorial ScopeAmber

PCPD has clarified PDPO has no extraterritorial scope; it applies where the data user's principal place of business is in Hong Kong.

Claims: CLM-HK-a1b2c304

Regulator Registration And FilingRed

No evidence located of a general controller registration/filing obligation to PCPD akin to EU-style DPA registers.

Absence provenance: not recorded. Searched: PCPD registration requirement data user Hong Kong, PDPO controller notification filing obligation.

Category narrative75 words

Hong Kong's data protection regime is anchored in the Personal Data (Privacy) Ordinance (Cap. 486), a comprehensive omnibus statute enforced by the Privacy Commissioner for Personal Data (PCPD). The PDPO has no extraterritorial reach and applies to data users with a principal place of business in Hong Kong. Unlike GDPR-model regimes, PDPO does not impose a general registration/filing obligation on data users; no direct evidence of such a regime was found in this research pass.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe Office of the Privacy Commissioner for Personal Data (PCPD) is the main body responsible for overseeing enforcement of the PDPO and is headed by the Privacy Commissioner for Personal Data.
  2. ConfirmedDataGuidanceThe Personal Data (Privacy) Ordinance (Cap. 486) came into force on 20 December 1996 and was significantly amended by the 2012 Amendment Ordinance (direct marketing) and the 2021 Amendment Ordinance (anti-doxxing).
  3. ConfirmedIAPPData Protection Principle 1(1) requires that only necessary, adequate and not excessive personal data be collected for a lawful purpose, forming part of PDPO's core material-scope obligations on data users.
  4. ConfirmedDataGuidanceThe PDPO is unclear on its territorial scope on its face, but the PCPD has clarified that the PDPO does not have extraterritorial scope, in contrast to the GDPR's extraterritorial application.

#

Functional equivalents exist via DPPs and guidance, but the absence of enumerated lawful bases and a codified special-category regime is a material structural gap versus GDPR.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486) — Data Protection Principles
Supervisory authorityPCPD
Traffic-light rationale — AmberFunctional equivalents exist via DPPs and guidance, but the absence of enumerated lawful bases and a codified special-category regime is a material structural gap versus GDPR.

Sub-modules (4)

Lawful BasesAmber

DPPs (esp. DPP1 collection limitation) function as the lawful-processing framework rather than an Art.6-style enumerated list.

Claims: CLM-HK-b2c3d401

Special CategoriesAmber

No enumerated special/sensitive-category regime exists in statute; PCPD guidance flags HKID numbers, biometric data and consumer credit data for heightened caution.

Claims: CLM-HK-b2c3d403

Pseudonymisation And AnonymisationAmber

PDPO does not statutorily define pseudonymised or anonymised data; PCPD's 2011 Guidance on Personal Data Erasure and Anonymisation addresses the anonymisation threshold.

Claims: CLM-HK-b2c3d404

Category narrative53 words

PDPO does not use an enumerated GDPR Art.6-style lawful-basis list; instead, its six Data Protection Principles govern collection and use. There is no statutory special/sensitive-category regime; PCPD instead issues category-specific guidance (HKID numbers, biometric data, consumer credit data). Pseudonymisation and anonymisation are not defined in the statute, though PCPD guidance addresses anonymisation thresholds.

Sources and claims (4)
  1. ConfirmedIAPPData Protection Principle 1(1) provides that only necessary, adequate and not excessive personal data is to be collected for a lawful purpose, operating as PDPO's functional lawful-basis analogue.
  2. ConfirmedIAPPBefore using or providing personal data for direct marketing, a data user must inform the individual and obtain consent or an indication of no objection, and the individual may opt out at any time irrespective of prior consent.
  3. ConfirmedDataGuidanceThe PCPD has published guidelines flagging Hong Kong identity card numbers, biometric data and consumer credit data as categories requiring special caution in collection and use, in the absence of a codified statutory special-category regime.
  4. ConfirmedDataGuidanceThe PDPO does not address sensitive personal data, anonymisation, or pseudonymisation in the statute itself, though the PCPD has clarified aspects of anonymisation through non-binding guidance.

#

Access/rectification rights are well-defined and binding (green-equivalent), but erasure and portability rights are absent, and restriction/objection is narrow — pulling the module to amber overall.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486)
Supervisory authorityPCPD
Traffic-light rationale — AmberAccess/rectification rights are well-defined and binding (green-equivalent), but erasure and portability rights are absent, and restriction/objection is narrow — pulling the module to amber overall.

Sub-modules (5)

Access RightGreen

Data subjects may request access; if refused, the data user must inform the requestor within 40 calendar days and explain the refusal.

Claims: CLM-HK-c3d4e501

Rectification And ErasureAmber

Correction requests must be honored within 40 days; however, PDPO does not provide a general right to erasure/deletion, only a duty not to retain data beyond necessity.

Claims: CLM-HK-c3d4e502, CLM-HK-c3d4e503

Restriction And ObjectionAmber

No general restriction-of-processing right exists; the closest analogue is the standing direct-marketing opt-out right.

Claims: CLM-HK-c3d4e504

Data PortabilityRed

No evidence of a statutory data-portability right was located in this research pass.

Absence provenance: not recorded. Searched: Hong Kong PDPO data portability right, PCPD portability guidance.

Deadlines And Response WindowsGreen

A uniform 40-calendar-day statutory response window applies to both access and correction requests.

Claims: CLM-HK-c3d4e501, CLM-HK-c3d4e502

Category narrative35 words

PDPO grants access and correction rights with a 40-calendar-day statutory response window, but does not provide a general right to erasure/be forgotten, nor a data-portability right. Objection-type rights are largely confined to the direct-marketing opt-out.

Sources and claims (4)
  1. ConfirmedDataGuidanceIf a data user rejects or denies a data access request, it must inform the requestor within 40 calendar days from receipt of the request and explain why it cannot comply.
  2. ConfirmedDataGuidanceA data correction request must be complied with, and a copy of the corrected personal data provided, within 40 calendar days from receipt under Section 23(1) of the PDPO.
  3. ConfirmedDataGuidanceUnlike the GDPR, the PDPO does not provide data subjects with a general right to request erasure or deletion of their personal data; only general requirements exist relating to erasure once data is no longer required for its original purpose.
  4. ConfirmedIAPPAn individual is entitled to opt out of direct marketing at any time irrespective of having previously given consent, functioning as PDPO's principal objection-type right.

#

Multiple GDPR-equivalent accountability pillars (DPIA, DPO, ROPA, mandatory breach notification) are absent from binding law; only security and retention principles and processor-supervision duties are binding.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486) — DPP2, DPP4; PCPD Privacy Management Programme (non-binding)
Supervisory authorityPCPD
Traffic-light rationale — RedMultiple GDPR-equivalent accountability pillars (DPIA, DPO, ROPA, mandatory breach notification) are absent from binding law; only security and retention principles and processor-supervision duties are binding.

Sub-modules (7)

Accountability And DpiaRed

PDPO does not explicitly set out accountability requirements or require DPIAs; the PCPD advocates a voluntary Privacy Management Programme (PMP) as a best-practice accountability framework.

Claims: CLM-HK-d4e5f601

Dpo RequirementsRed

PDPO does not require DPO appointment; the PMP best-practice guide recommends one.

Claims: CLM-HK-d4e5f602

Ropa RequirementsRed

PDPO does not require maintenance of general processing records; only a log book for access/correction requests is mandated.

Claims: CLM-HK-d4e5f603

Joint Controller ArrangementsAmber

The 2012 Amendment Ordinance imposed express duties on data users to supervise their data processors contractually and otherwise.

Claims: CLM-HK-d4e5f604

Security MeasuresAmber

DPP4 imposes a general, non-prescriptive security-of-processing duty; PCPD's 2023 recommendations urge specific technical/organisational measures as best practice.

Claims: CLM-HK-d4e5f605, CLM-HK-d4e5f606

Breach NotificationRed

PDPO imposes no mandatory breach-notification obligation; PCPD guidance recommends prompt voluntary notification, and a 2020 consultation proposed mandatory notification but remains unenacted.

Claims: CLM-HK-d4e5f607, CLM-HK-d4e5f608

Retention And DisposalGreen

DPP2(2)/Section 26 requires personal data not be kept longer than necessary for the purpose (including any directly related purpose).

Claims: CLM-HK-d4e5f609

Category narrative43 words

PDPO imposes a general security principle (DPP4) and post-2012 processor-supervision duties, retention limitation (DPP2(2)/s.26), but does not mandate DPIAs, DPO appointments, general records of processing (ROPA), or breach notification — all addressed only via non-binding PCPD guidance (Privacy Management Programme) or unenacted proposals.

Sources and claims (9)
  1. ConfirmedDataGuidanceThe PDPO does not explicitly set out accountability requirements for data users and processors; the PCPD instead advocates the Privacy Management Programme, a non-binding strategic framework for building privacy infrastructure, including DPO appointment as best practice.
  2. ConfirmedDataGuidanceUnlike the GDPR, the PDPO does not require Data Protection Officer appointments; the PCPD's Privacy Management Programme guide (as updated 2019) recommends appointment as best practice only.
  3. ConfirmedDataGuidanceUnlike the GDPR, the PDPO does not require that general data-processing records be maintained; it only requires a log book be maintained in relation to data subject access and correction requests.
  4. ConfirmedIAPPThe 2012 Amendment Ordinance imposes express obligations on a data user to supervise, through contractual and other means, its data processors to ensure PDPO compliance.
  5. ConfirmedDataGuidanceThe PDPO does not stipulate mandatory specific security measures; Data Protection Principle 4 sets only a general, non-prescriptive security-of-processing duty on data users.
  6. ConfirmedDataGuidanceIn September 2023, the PCPD issued non-binding recommendations urging organizations to conduct regular data-security risk assessments and adopt measures such as firewalls, encryption, and the least-privilege principle in compliance with DPP4.
  7. ConfirmedDataGuidanceThe PDPO does not provide for mandatory data breach notifications; the PCPD has instead published non-binding guidance on data breach handling.
  8. ProbableIAPPIn a 2020 consultation paper, the Privacy Commissioner and the Constitutional and Mainland Affairs Bureau proposed introducing mandatory data breach notification requirements and data retention periods, with no confirmed timeframe for formal introduction.
  9. ConfirmedDataGuidanceUnder DPP2(2) and Section 26 of the PDPO, all practicable steps must be taken to ensure personal data is not kept longer than necessary for the fulfilment of the purpose for which it is or is to be used.

#

The central transfer-restriction mechanism is dormant; only voluntary guidance exists, and adequacy/TIA sub-modules could not be evidenced.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486), Section 33 (not yet in force)
Supervisory authorityPCPD
Traffic-light rationale — RedThe central transfer-restriction mechanism is dormant; only voluntary guidance exists, and adequacy/TIA sub-modules could not be evidenced.

Sub-modules (6)

Transfer MechanismsRed

Section 33 (transfer restriction) remains dormant; PCPD guidance outlines prospective mechanisms (consent, white list, due diligence) that would apply if commenced.

Claims: CLM-HK-e5f6a701, CLM-HK-e5f6a702, CLM-HK-e5f6a703

Adequacy ReceivedRed

No evidence located of any foreign regime granting Hong Kong an adequacy-equivalent determination.

Absence provenance: not recorded. Searched: Hong Kong EU adequacy decision, Hong Kong PDPO adequacy determination received.

Adequacy GrantedRed

Since Section 33's white-list mechanism has never been activated, Hong Kong has not granted adequacy-equivalent status to any other jurisdiction.

Claims: CLM-HK-e5f6a701

Sccs And BcrsRed

Section 33, even if brought into force, does not provide for mechanisms such as BCRs, SCCs, or codes of conduct.

Claims: CLM-HK-e5f6a704

Transfer Impact AssessmentRed

No formal transfer-impact-assessment requirement was identified; PCPD guidance recommends general due diligence only.

Absence provenance: not recorded. Searched: Hong Kong PDPO transfer impact assessment requirement.

Data LocalisationAmber

No general PDPO data-localisation mandate exists; sector regulators (e.g., HKMA) impose data-residency/outsourcing controls on regulated entities.

Claims: CLM-HK-e5f6a705

Category narrative61 words

Section 33 of the PDPO — the sole cross-border transfer restriction provision — has never been commenced since the Ordinance's 1995/1996 enactment, so no binding transfer restriction currently applies. PCPD has issued non-binding guidance recommending voluntary compliance with Section 33's conditions (consent, a prospective 'white list', due diligence) as best practice. No adequacy decisions received/granted or formal TIA requirement were identified.

Sources and claims (5)
  1. ConfirmedDataGuidanceCurrently, there are no restrictions in effect concerning the cross-border transfer of personal data from Hong Kong, as Section 33 of the PDPO has never been brought into force.
  2. ConfirmedIAPPThe PCPD has issued a non-binding Guidance on Personal Data Protection in Cross-Border Data Transfer, recommending voluntary compliance with Section 33 as best practice and signalling a possible future commencement of the transfer restriction.
  3. ConfirmedDataGuidanceNo timetable has been announced for the implementation of Section 33; it remains the only section of the PDPO yet to come into effect.
  4. ConfirmedDataGuidanceSection 33 of the PDPO does not provide for mechanisms such as binding corporate rules, standard contractual clauses, or codes of conduct, even if it were to come into force.
  5. ConfirmedDataGuidanceThe Outsourcing module (SA-2) of the Hong Kong Monetary Authority's Supervisory Policy Manual requires all authorised institutions to implement proper controls for protection of customer data when entering into an outsourcing arrangement.

#

Financial-sector overlay is well-evidenced; health, telecoms/ePrivacy, employment, and education sub-modules are thin or unevidenced.

Primary frameworkPDPO overlaid by HKMA/Insurance Authority/SFC sectoral guidelines
Supervisory authorityPCPD
Traffic-light rationale — AmberFinancial-sector overlay is well-evidenced; health, telecoms/ePrivacy, employment, and education sub-modules are thin or unevidenced.

Sub-modules (7)

Financial Sector OverlayAmber

HKMA, Insurance Authority, and SFC issue customer-data circulars/guidelines applicable to licensed institutions, overlaying general PDPO duties.

Claims: CLM-HK-f6a7b801, CLM-HK-f6a7b802

Health Sector OverlayRed

No dedicated health-sector data-privacy statute (e.g., HIPAA-equivalent) was identified in this research pass.

Absence provenance: not recorded. Searched: Hong Kong health data privacy sectoral law, Hong Kong medical data protection statute.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-style cookie-and-communications-specific statute was identified.

Absence provenance: not recorded. Searched: Hong Kong ePrivacy telecoms data law, Hong Kong cookie law telecoms.

Employment DataAmber

Retention limitation rules require employee personal data not be kept beyond the period necessary after termination of employment absent a subsisting reason.

Claims: CLM-HK-f6a7b803

Credit And ScoringAmber

PCPD guidance flags consumer credit data as a category requiring heightened caution in collection and use.

Claims: CLM-HK-f6a7b804

EducationRed

No dedicated education-sector data-privacy rules were identified in this research pass.

Absence provenance: not recorded. Searched: Hong Kong education sector data privacy rules PCPD.

InsuranceAmber

The Insurance Authority requires authorised insurers to implement cybersecurity frameworks protecting policyholder personal data.

Claims: CLM-HK-f6a7b805

Category narrative40 words

Hong Kong has no standalone sectoral data-privacy statutes; instead, sector regulators (HKMA, Insurance Authority, SFC) issue circulars and guidelines overlaying the PDPO for regulated entities' customer data, and PCPD issues category-specific guidance for sensitive data types including consumer credit data.

Sources and claims (5)
  1. ConfirmedDataGuidanceThere are no sectoral data privacy laws as such in Hong Kong, but certain industry-specific requirements are imposed by relevant regulators in respect of customer data held by regulated entities.
  2. ConfirmedDataGuidanceThe Hong Kong Monetary Authority has issued several circulars and guidelines relating to protection and confidentiality of customer data applicable to all licensed banks under the Banking Ordinance (Cap. 155).
  3. ConfirmedDataGuidanceUnder DPP2(2)/Section 26, employee personal data must not be kept longer than necessary after the end of employment, unless a subsisting reason requires the employer to hold the data longer.
  4. ConfirmedDataGuidanceThe PCPD has published guidelines on the collection and use of consumer credit data, requiring caution and setting practical guidance on proper collection and use.
  5. ConfirmedDataGuidanceThe Insurance Authority has issued a Guideline on Cybersecurity requiring authorised insurers to implement robust cybersecurity frameworks to protect the personal data of existing or potential policyholders.

#

Direct marketing is green-level binding law; the remaining five sub-modules are unevidenced gaps in a jurisdiction with no dedicated ePrivacy/cookie statute.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486), Part VIA (Direct Marketing)
Supervisory authorityPCPD
Traffic-light rationale — AmberDirect marketing is green-level binding law; the remaining five sub-modules are unevidenced gaps in a jurisdiction with no dedicated ePrivacy/cookie statute.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent statute was identified distinct from general PDPO principles.

Absence provenance: not recorded. Searched: Hong Kong cookie consent law PDPO, Hong Kong ePrivacy cookies.

Dark PatternsAmber

PCPD guidance criticizes 'bundled consent' application-form designs that force customers to choose between service and direct-marketing data use.

Claims: CLM-HK-a7b8c901

Opt Out SignalsRed

No evidence of a Global-Privacy-Control-style universal opt-out signal regime was identified.

Absence provenance: not recorded. Searched: Hong Kong Global Privacy Control opt-out signal law.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room rules were identified.

Absence provenance: not recorded. Searched: Hong Kong data clean room regulation PDPO.

Cross Context AdvertisingRed

No CPRA-style 'sale'/'share' cross-context-advertising regime was identified.

Absence provenance: not recorded. Searched: Hong Kong cross-context advertising data sale law.

Direct MarketingGreen

Part VIA requires informed consent/no-objection before use of data in direct marketing, an unconditional opt-out right, and criminalises non-compliant use with fines up to HK$500,000 and up to 3 years' imprisonment.

Claims: CLM-HK-a7b8c902, CLM-HK-a7b8c903

Category narrative41 words

Direct marketing is the best-developed strand of PDPO's commercial-privacy regime (Part VIA), with binding consent/opt-out duties and criminal penalties, plus PCPD guidance against 'bundled consent' dark patterns. No dedicated cookie/tracker law, opt-out-signal regime, clean-room rules, or cross-context-advertising ('sale'/'share') regime was identified.

Sources and claims (3)
  1. ConfirmedIAPPPCPD guidance states it would be unfair for service application forms to force customers to choose between providing personal data for direct marketing or forgoing the service ('bundled consent'), requiring separate voluntary indications instead.
  2. ConfirmedIAPPPart VIA of the PDPO requires a data user to inform individuals, in an easily understandable and readable manner, of an intention to use or provide their data for direct marketing, specifying the data and marketing types, and to obtain consent or no-objection via a free response channel.
  3. ConfirmedIAPPSection 35E of the PDPO provides for a fine of up to HK$500,000 and up to three years' imprisonment where personal data is used for direct marketing purposes without the individual's informed consent.

#

AI governance is active but entirely soft-law; national-security carve-outs materially limit PCPD's supervisory reach; profiling/ADM-transparency/genetic-data sub-modules are unevidenced.

Primary frameworkPCPD Artificial Intelligence: Model Personal Data Protection Framework (2024, non-binding); PDPO general principles
Supervisory authorityPCPD
Traffic-light rationale — AmberAI governance is active but entirely soft-law; national-security carve-outs materially limit PCPD's supervisory reach; profiling/ADM-transparency/genetic-data sub-modules are unevidenced.

Sub-modules (6)

Profiling RestrictionsRed

No Art.22-style statutory profiling restriction was identified in the PDPO.

Absence provenance: not recorded. Searched: Hong Kong PDPO profiling restriction automated decision.

Automated Decision Making TransparencyRed

No statutory ADM-transparency or explanation right was identified beyond general AI governance guidance.

Absence provenance: not recorded. Searched: Hong Kong PDPO automated decision-making transparency right.

Ai Risk AssessmentsAmber

PCPD's AI compliance-check programme and Model Framework recommend (non-binding) risk assessments, governance structures, and audits for AI systems.

Claims: CLM-HK-b8c9d001, CLM-HK-b8c9d002, CLM-HK-b8c9d003

Biometric RegimeAmber

PCPD guidance flags biometric data, alongside HKID numbers and credit data, as requiring heightened caution, without a codified statutory biometric regime.

Claims: CLM-HK-b8c9d004

Genetic DataRed

No dedicated genetic-data regime was identified in this research pass.

Absence provenance: not recorded. Searched: Hong Kong genetic data protection law PDPO.

State Surveillance CarveoutsRed

The PCPD's ability to supervise and regulate authorities' actions under the National Security Law appears fairly limited, as the NSL expressly takes precedence over inconsistent local laws.

Claims: CLM-HK-b8c9d005

Category narrative56 words

Hong Kong has no binding AI-specific statute; the PCPD's June 2024 AI Model Personal Data Protection Framework and 2021 Ethical AI Guidance are non-binding best-practice instruments. PCPD conducts periodic AI compliance checks. Biometric data attracts special-caution guidance but no codified regime. State-surveillance carve-outs exist under the National Security Law, which the PCPD's supervisory reach cannot override.

Sources and claims (5)
  1. ConfirmedDataGuidanceOn 11 June 2024, the PCPD published the Artificial Intelligence: Model Personal Data Protection Framework, providing recommendations and best practices for AI governance covering procurement, implementation, and use of AI systems including generative AI, building on its 2021 Guidance on the Ethical Development and Use of AI.
  2. ConfirmedIAPPThe PCPD's 2024-25 Annual Report describes the AI Model Framework as one of the first explicit regional frameworks for regulating AI, reflecting the Commissioner's stated aim to balance innovation and security in AI.
  3. ConfirmedIAPPPCPD compliance checks on 60 organizations found 80% used AI in daily operations (a 5% increase from 2024), with the PCPD recommending AI governance structures, comprehensive risk assessments, and regular audits as best practice.
  4. ConfirmedDataGuidanceThe PCPD has published guidelines regarding the collection and use of biometric data, alongside Hong Kong identity cards and consumer credit data, highlighting the need for caution absent a codified statutory biometric regime.
  5. ConfirmedDataGuidanceIn relation to the exercise of authorities' powers under the National Security Law, the PCPD's ability to supervise and regulate compliance with the PDPO appears fairly limited, as the NSL expressly takes precedence over inconsistent provisions of other Hong Kong laws.

#

This is a legitimate regulatory gap: no comprehensive children/vulnerable-groups regime exists in the PDPO beyond passing references to minors.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486) — no dedicated minors regime
Supervisory authorityPCPD
Traffic-light rationale — RedThis is a legitimate regulatory gap: no comprehensive children/vulnerable-groups regime exists in the PDPO beyond passing references to minors.

Sub-modules (5)

Age VerificationRed

No statutory age-verification requirement was identified.

Absence provenance: not recorded. Searched: Hong Kong PDPO age verification requirement minors.

Minor Profiling BansRed

No minor-specific profiling ban was identified.

Absence provenance: not recorded. Searched: Hong Kong PDPO minors profiling ban.

Education SettingsRed

No education-setting-specific data rules were identified.

Absence provenance: not recorded. Searched: Hong Kong PDPO education sector minors data rules.

Dependent AdultsRed

No dependent-adult-specific protections were identified.

Absence provenance: not recorded. Searched: Hong Kong PDPO dependent adults elderly mentally incapacitated data protection.

Category narrative32 words

PDPO makes passing reference to 'minors' but does not codify a specific age of consent, parental-consent mechanism, or minor-specific profiling ban comparable to GDPR Art.8. No education-setting-specific or dependent-adult-specific rules were identified.

Sources and claims (1)
  1. ProbableDataGuidanceThe PDPO makes references to 'minors' but is less clear than the GDPR regarding consent from guardians and privacy notices aimed at minors, and does not define a specific age of consent threshold.

#

Enforcement powers and penalties are robust and binding (green-level for that sub-module), but collective redress and regulator-capacity sub-modules are unevidenced gaps, pulling the module to amber.

Primary frameworkPersonal Data (Privacy) Ordinance (Cap. 486)
Supervisory authorityPCPD
Traffic-light rationale — AmberEnforcement powers and penalties are robust and binding (green-level for that sub-module), but collective redress and regulator-capacity sub-modules are unevidenced gaps, pulling the module to amber.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

PCPD can investigate, issue enforcement notices, and (since 2021) conduct criminal investigations/prosecutions for doxxing, with tiered penalties up to HK$1,000,000 and 5 years' imprisonment.

Claims: CLM-HK-d0e1f201, CLM-HK-d0e1f202, CLM-HK-d0e1f203, CLM-HK-d0e1f204

Enforcement Activity IndexAmber

Documented enforcement activity includes multiple doxxing arrests since the 2021 anti-doxxing law and the first PDPO imprisonment for misleading the PCPD during an investigation.

Claims: CLM-HK-d0e1f205, CLM-HK-d0e1f206

Regulator Funding And CapacityRed

No regulator funding or headcount data was identified in this research pass.

Absence provenance: not recorded. Searched: PCPD annual budget headcount staffing capacity.

Collective Redress And Class ActionsRed

No dedicated class-action mechanism for data subjects was identified beyond the individual legal-assistance scheme.

Absence provenance: not recorded. Searched: Hong Kong PDPO class action collective redress data subjects.

Private Right Of ActionAmber

The 2012 Amendment Ordinance introduced a legal-assistance scheme enabling aggrieved individuals to pursue compensation claims arising from PDPO contraventions.

Claims: CLM-HK-d0e1f207

Recent Developments 180DAmber

The PCPD's 2024-25 Annual Report continues to emphasize AI governance, data security, and digital trust as regulatory priorities.

Claims: CLM-HK-d0e1f208

Category narrative59 words

The PCPD holds investigative, enforcement-notice, and (post-2021) criminal investigation/prosecution powers for doxxing, with a two-tier anti-doxxing offence carrying fines up to HK$1,000,000 and imprisonment up to 5 years. Direct-marketing breaches carry fines up to HK$500,000 and 3 years' imprisonment. A legal-assistance scheme for aggrieved individuals was introduced in 2012. No dedicated collective-redress/class-action mechanism or regulator funding/headcount data was identified.

Sources and claims (8)
  1. ConfirmedDataGuidanceThe PCPD has various investigative powers, including the right to undertake investigations and inquiries and issue enforcement notices in the event of PDPO contraventions.
  2. ConfirmedIAPPThe 2021 Amendment Ordinance removed the prior requirement that an enforcement notice could only be issued where the offending act was likely to continue or repeat, and increased penalties for data users breaching multiple or repeated enforcement notices.
  3. ConfirmedDataGuidanceThe 2021 anti-doxxing regime creates a two-tier offence: a Tier 1 summary offence carrying up to two years' imprisonment and a HK$100,000 fine, and a Tier 2 indictable offence, where actual harm is caused, carrying up to five years' imprisonment and a HK$1,000,000 fine.
  4. ConfirmedDataGuidanceThe PCPD has the power to conduct criminal investigations and institute prosecutions for doxxing cases, and to issue cessation notices to Hong Kong or non-Hong Kong persons or service providers to demand removal of doxxing content.
  5. ConfirmedIAPPThe PCPD announced the first prison sentence under Section 50B(1)(c)(i) of the PDPO for knowingly making a false or misleading statement to the Commissioner during an investigation.
  6. ConfirmedIAPPThe PCPD arrested an individual for posting personal information of three people on social media in a commercial dispute, marking the second arrest under the anti-doxxing legislation approved in September 2021.
  7. ConfirmedIAPPThe 2012 Amendment Ordinance introduced, among other measures, a legal assistance scheme for aggrieved individuals seeking to bring proceedings arising from PDPO contraventions.
  8. ConfirmedIAPPThe PCPD's 2024-25 Annual Report, 'Leveraging Artificial Intelligence for a New Digital Privacy Era,' concentrates on AI's impacts on data security and digital trust as a continuing regulatory priority.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Hong Kong
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 48 claim(s), 16 source(s) in the cumulative register.