01
We start not with a cookie banner, but with a data map
The PDPO regulates personal data related directly or indirectly to a living person who is practically identifiable. The company describes the categories of persons, data, sources, goals, recipients, systems, storage periods and international transfers.
KYC, contacts, contracts, communications and transaction history.
Recruitment, payroll, performance, immigration and monitoring.
Cookies, analytics, forms, CCTV and access logs.
Identity, ownership, screening and regulatory disclosures.
02
Six DPPs form a single life cycle
- DPP 1
- Lawful and fair collection; data adequate, but not excessive
- DPP 2
- Accuracy and storage no longer than necessary
- DPP 3
- Use for original or compatible purpose or with prescribed consent
- DPP 4
- Practical security measures, including processors
- DPP 5
- Public privacy policies and practices
- DPP 6
- Access and correction rights of the subject
03
Privacy notice must coincide with real goals
At the collection point, the purpose, mandatory data, consequences of refusal, classes of transferees and access rights/ correction. For a new target, compatibility is checked either prescribed consent. The fallback formula “for any business purpose” is not replaces the specific description of the processing.
Forms, cookies, analytics, pixels and third-party embeds.
Identity, UBO, source of wealth/funds and screening.
Candidate notice, employee policy and monitoring boundaries.
Registration, photography, attendee lists and follow-up marketing.
04
Transfer to the contractor does not transfer responsibility
Data user uses contractual or other means to The processor complied with retention and security requirements. Vendor due diligence covers locations, subprocessors, access, encryption, deletion, incident notification, audit evidence and exit support.
- Cloud
- Region, resilience, keys, admin access and subprocessors
- Payroll / HR
- Employee confidentiality, retention and secure transfer
- KYC provider
- Data sources, matching logic, false positives and evidence
- CRM / marketing
- Permissions, exports, suppression lists and deletion
- Exit
- Return, migration, deletion certificate and residual backups
05
Direct marketing has a separate procedure
Before using personal data in a direct marketing company communicates the information required by law, receives appropriate consent and provides a clear opt-out. Selling or transferring data to another party for marketing requires separate analysis and more strict consent route.
Purpose, channel, class of products/services and identity marketer are fixed; opt-out applies without a fee and is synchronized across all systems.
06
Access and correction are processed as a legal process
The company identifies the applicant, finds data in all relevant systems, applies permissible restrictions, conducts correspondence and responds in the prescribed manner. Policy in advance assigns owner, terms, evidence and escalation to counsel.
07
Security depends on harm, not just on IT standard
DPP 4 requires practical steps taking into account the type of data, potential harm, location, technical measures, competence people and safe transmission. Controls include least privilege, MFA, encryption, logging, backups, secure disposal and regular access check.
- Classify the data and determine the owner of each set.
- Limit access to role, term, and business necessity.
- Protect transfers, endpoints, privileged accounts and backups.
- Check vendors, permissions and inactive users.
- Conduct a tabletop exercise on leakage and recovery.
08
Leakage begins with containment and harm assessment
The command preserves evidence, stops unauthorized access, identifies data and individuals, analyzes misuse risk and accepts notification decision. As of the date of the inspection, PCPD was not notified is a general statutory requirement, but PCPD recommends it as good practice; Notification of affected persons depends on the risk and measures they can take.
A bank, listed issuer, mainland processor, overseas entity or customer agreement may require a separate notification rather than a general PDPO approach.
09
Cross-border transfer is being documented today
Section 33 PDPO contains a special out-of-bounds transmission mode Hong Kong, but not yet in force at the date of inspection. At the same time DPP 1, 3 and 4 continue to apply and PCPD recommends due diligence, transparency and contractual safeguards, including Recommended Model Contractual Clauses.
- Data route
- Sender, recipient, hosting, remote access and onward transfer
- Purpose
- Same as notice/consent and is not excessive
- Contract
- Use limits, security, breach, rights, audit, return and deletion
- Foreign law
- The requirements of the sender, recipient and subjects countries are checked separately
10
Hong Kong and Mainland China - two different modes
Data from mainland China is verified by PIPL, Data Security Law, Cybersecurity Law and applicable cross-border mechanism. The recipient in Hong Kong must comply with the contractual and local PDPO obligations. Remote access from Hong Kong to the mainland system also analyzed as a cross-border scenario.
Security assessment, standard contract, certification or applicable exemption.
Facilitation mechanism between Hong Kong and nine mainland GBA cities.
Does not cover critical data and does not allow onward transfer outside the GBA.
Personal information protection impact assessment before transfer.
11
Minimum privacy management program
- Assign an accountable owner and approve data inventory.
- Update privacy notices, consent and direct-marketing workflow.
- Set retention schedule and defensible deletion.
- Enter processor and cross-border clauses.
- Set up access/correction and complaint handling.
- Conduct security review and breach exercise.
- Separately register Mainland China and GBA data routes.
- Review the program for a new product, vendor or country.
Sources
Normative support
The status of section 33 and mainland transfer rules is checked before each new data flow is started.
Six DPPs, including security, transparency and access.
Practical measures and model contractual approach; section 33 status.
Approach to breach assessment, containment and voluntary notification.
PIPL, mainland transfer mechanisms and GBA Standard Contract.
Conditions and boundaries of the mechanism for Hong Kong and nine mainland GBA cities.
Hong Kong Privacy Desk
We will design the data before launching the product
We will compile a data map, update notices and contracts, check vendors, international transfers and Mainland China route, prepare an incident response.
Discuss data processing
+7 (495) 221 31 46