Hong Kong · Privacy & Data

Data follows
behind the business process

We build a privacy framework based on PDPO and design the transfer separately data to mainland China, other countries, banks, cloud and intragroup service centers.

6 DPPbasis for personal data protection
Section 33cross-border restriction has not yet been implemented
9 citiesmainland GBA are included in the GBA SC mechanism
Voluntarynotification to PCPD of leak as of inspection date

01

We start not with a cookie banner, but with a data map

The PDPO regulates personal data related directly or indirectly to a living person who is practically identifiable. The company describes the categories of persons, data, sources, goals, recipients, systems, storage periods and international transfers.

Clients

KYC, contacts, contracts, communications and transaction history.

Employees

Recruitment, payroll, performance, immigration and monitoring.

Visitors

Cookies, analytics, forms, CCTV and access logs.

UBO / directors

Identity, ownership, screening and regulatory disclosures.

02

Six DPPs form a single life cycle

DPP 1
Lawful and fair collection; data adequate, but not excessive
DPP 2
Accuracy and storage no longer than necessary
DPP 3
Use for original or compatible purpose or with prescribed consent
DPP 4
Practical security measures, including processors
DPP 5
Public privacy policies and practices
DPP 6
Access and correction rights of the subject

03

Privacy notice must coincide with real goals

At the collection point, the purpose, mandatory data, consequences of refusal, classes of transferees and access rights/ correction. For a new target, compatibility is checked either prescribed consent. The fallback formula “for any business purpose” is not replaces the specific description of the processing.

Website

Forms, cookies, analytics, pixels and third-party embeds.

KYC

Identity, UBO, source of wealth/funds and screening.

HR

Candidate notice, employee policy and monitoring boundaries.

Events

Registration, photography, attendee lists and follow-up marketing.

04

Transfer to the contractor does not transfer responsibility

Data user uses contractual or other means to The processor complied with retention and security requirements. Vendor due diligence covers locations, subprocessors, access, encryption, deletion, incident notification, audit evidence and exit support.

Cloud
Region, resilience, keys, admin access and subprocessors
Payroll / HR
Employee confidentiality, retention and secure transfer
KYC provider
Data sources, matching logic, false positives and evidence
CRM / marketing
Permissions, exports, suppression lists and deletion
Exit
Return, migration, deletion certificate and residual backups

05

Direct marketing has a separate procedure

Before using personal data in a direct marketing company communicates the information required by law, receives appropriate consent and provides a clear opt-out. Selling or transferring data to another party for marketing requires separate analysis and more strict consent route.

A contact from a business card does not equal consent to any mailing.

Purpose, channel, class of products/services and identity marketer are fixed; opt-out applies without a fee and is synchronized across all systems.

06

Access and correction are processed as a legal process

The company identifies the applicant, finds data in all relevant systems, applies permissible restrictions, conducts correspondence and responds in the prescribed manner. Policy in advance assigns owner, terms, evidence and escalation to counsel.

07

Security depends on harm, not just on IT standard

DPP 4 requires practical steps taking into account the type of data, potential harm, location, technical measures, competence people and safe transmission. Controls include least privilege, MFA, encryption, logging, backups, secure disposal and regular access check.

  1. Classify the data and determine the owner of each set.
  2. Limit access to role, term, and business necessity.
  3. Protect transfers, endpoints, privileged accounts and backups.
  4. Check vendors, permissions and inactive users.
  5. Conduct a tabletop exercise on leakage and recovery.

08

Leakage begins with containment and harm assessment

The command preserves evidence, stops unauthorized access, identifies data and individuals, analyzes misuse risk and accepts notification decision. As of the date of the inspection, PCPD was not notified is a general statutory requirement, but PCPD recommends it as good practice; Notification of affected persons depends on the risk and measures they can take.

Other regimes may impose a mandatory deadline

A bank, listed issuer, mainland processor, overseas entity or customer agreement may require a separate notification rather than a general PDPO approach.

09

Cross-border transfer is being documented today

Section 33 PDPO contains a special out-of-bounds transmission mode Hong Kong, but not yet in force at the date of inspection. At the same time DPP 1, 3 and 4 continue to apply and PCPD recommends due diligence, transparency and contractual safeguards, including Recommended Model Contractual Clauses.

Data route
Sender, recipient, hosting, remote access and onward transfer
Purpose
Same as notice/consent and is not excessive
Contract
Use limits, security, breach, rights, audit, return and deletion
Foreign law
The requirements of the sender, recipient and subjects countries are checked separately

10

Hong Kong and Mainland China - two different modes

Data from mainland China is verified by PIPL, Data Security Law, Cybersecurity Law and applicable cross-border mechanism. The recipient in Hong Kong must comply with the contractual and local PDPO obligations. Remote access from Hong Kong to the mainland system also analyzed as a cross-border scenario.

General route

Security assessment, standard contract, certification or applicable exemption.

GBA SC

Facilitation mechanism between Hong Kong and nine mainland GBA cities.

Limits

Does not cover critical data and does not allow onward transfer outside the GBA.

Assessment

Personal information protection impact assessment before transfer.

11

Minimum privacy management program

  1. Assign an accountable owner and approve data inventory.
  2. Update privacy notices, consent and direct-marketing workflow.
  3. Set retention schedule and defensible deletion.
  4. Enter processor and cross-border clauses.
  5. Set up access/correction and complaint handling.
  6. Conduct security review and breach exercise.
  7. Separately register Mainland China and GBA data routes.
  8. Review the program for a new product, vendor or country.

Sources

Normative support

The status of section 33 and mainland transfer rules is checked before each new data flow is started.

Hong Kong Privacy Desk

We will design the data before launching the product

We will compile a data map, update notices and contracts, check vendors, international transfers and Mainland China route, prepare an incident response.

Discuss data processing
WAWhatsAppTGTelegram