Hong Kong SAR
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Hong Kong SAR — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send personal data out of Hong Kong freely. The privacy law does contain a section banning transfers abroad. That section has never been brought into force. It was written in 1995 and still has no start date thirty years later. So under the general law you need no paperwork to send data out. The privacy regulator is busy and does prosecute people. But it cannot fine you directly.
Data governance in Hong Kong SAR
The eight things that decide how you handle data about people in Hong Kong SAR. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Hong Kong's privacy law can reach you even if you have no office there. It applies to whoever controls the collecting, holding or use of personal data in or from Hong Kong. So a foreign company running a Hong Kong-facing service is covered. There is no revenue or staff-count limit to fall below. There is no register to join. You do not need to appoint a local representative. The anti-doxxing powers go further. The regulator can order a platform based abroad to take material down.
The Personal Data (Privacy) Ordinance (Cap. 486) has applied since 20 December 1996. It covers private companies and the public sector alike. The duties fall on the 'data user', meaning the party that controls the data. They do not depend on having a Hong Kong office. Europe's General Data Protection Regulation makes foreign companies appoint a representative in Europe. Hong Kong has no equivalent rule. There is no data protection officer requirement either. There is no registration and nothing to notify. The clearest reach beyond Hong Kong is in the anti-doxxing rules added in 2021. The Privacy Commissioner can order a service provider to stop, whether or not that provider is in Hong Kong. It applies whether or not the material was published in Hong Kong. There is a mirror image of this in the unused transfer section. If that section were ever brought into force, it would reach wider than you expect. It would cover a transfer between two places outside Hong Kong, when a Hong Kong company controls it.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Personal Data (Privacy) Ordinance at a Glance
pcpd.org.hk
“one of Asia's longest standing comprehensive data protection laws”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataAnti-doxxing regime - powers, offences and enforcement figures
pcpd.org.hk
“regardless of whether the disclosure is made in Hong Kong or not”
Link checked 18 August 2026
Where the data is allowed to live
Yes. Under the general privacy law you can send data abroad freely, with nothing to sign. One section would have restricted transfers abroad. It was written into the law in 1995 and has never been brought into force. So today no law stops personal data leaving Hong Kong. The real limits come from industry rules, and there are fewer of them than people expect. The securities regulator is the main one. Government departments have their own restriction.
Here is the position industry by industry, checked on 18 August 2026. SECURITIES AND FUTURES: the strictest case. A licensed firm may keep its official records only outside Hong Kong if the markets regulator approves the storage site. It must also appoint two Managers-In-Charge who normally live in Hong Kong and can get at the records on demand. Rated conditional. GOVERNMENT AND PUBLIC SECTOR: departments are told not to store sensitive and personal information on public cloud platforms. Rated conditional. BANKING AND PAYMENTS: we found no rule that data must stay in Hong Kong. The bank regulator supervises outsourcing and cloud use. It expects to be able to reach the data and the records. We could not open its policy manual, so we rate this low confidence rather than treat it as settled. Rated conditional, low confidence. INSURANCE: we found no rule that data must stay in Hong Kong on the regulator's own site, which blocked our access. Low confidence. HEALTH: the electronic health record sharing system is built around patient consent. A 2025 bill would let a person authorise a healthcare provider outside Hong Kong to see or add records. We found no ban on records leaving. Rated open. TELECOM, EDUCATION, GAMING, MAPPING AND GEOSPATIAL, DEFENCE: we found no rule on government sources that data must stay in Hong Kong, checked 18 August 2026. Treat these as open with medium confidence, not as proven. CRITICAL INFRASTRUCTURE: a new law in force since 1 January 2026 gives named operators security and reporting duties. We found no requirement that their computer systems or data sit in Hong Kong, but we could not read the text of the law. The direction that really restricts data is inbound. Moving personal information from mainland China into Hong Kong is restricted by mainland law. The Greater Bay Area standard contract exists to make that legal.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataGuidance on Personal Data Protection in Cross-border Data Transfer
pcpd.org.hk
“Although section 33 is not yet effective, this Guidance serves as a practical guide for data users to prepare for the implementation of section 33 of the Ordinance.”
Link checked 18 August 2026
- Official sourceSecurities and Futures CommissionFrequently asked questions on the use of external electronic data storage
sfc.hk
“an undertaking from each of the two MICs appointed”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeProtection of Data Security - requirements on government bureaux and departments
digitalpolicy.gov.hk
“refraining from storing sensitive and personal information on public cloud platforms”
Link checked 18 August 2026
- Official sourceHealth Bureau, HKSAR GovernmentElectronic Health Record Sharing System (Amendment) Bill 2025 to be gazetted
info.gov.hk
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Nothing. There is no approval to seek before personal data leaves Hong Kong. There is no standard contract to sign and no government list to check. On paper the law would let you send data only to approved countries. But that section was never brought into force, so the list of approved countries has never been published. It is empty. The regulator does publish a voluntary guide and encourages firms to build safeguards now. That is advice, not law.
- Ways to send data out:
- Nothing required · Standard contract clauses
If the unused transfer section were ever brought into force, sending data out of Hong Kong would need one of six routes. The destination is on a list of places the Commissioner has decided have a substantially similar law. Or you have reasonable grounds to believe such a law is in force there. Or the person has agreed in writing. Or the transfer will not harm the person and written consent is impractical. Or an exemption in Part VIII of the law applies. Or you took all reasonable precautions and did all due diligence. Two features make it stricter than it looks. First, it would cover transfers between two places outside Hong Kong that a Hong Kong data user controls. Second, the due diligence route is a standard of behaviour, not a document you file. You cannot satisfy it by signing a template. Going the other way, from mainland China into Hong Kong, there is the Greater Bay Area Standard Contract. It was announced on 13 December 2023 under a memorandum signed on 29 June 2023. From 1 November 2024 the easier route was extended to every industry in Hong Kong. It is a voluntary simpler route. Hong Kong law does not require it.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataGuidance on Personal Data Protection in Cross-border Data Transfer - the six section 33 gateways
pcpd.org.hk
“Regardless of when section 33 will take effect, data users are encouraged to adopt the practices recommended in this Guidance as part of their corporate governance responsibility to protect personal data.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Personal Information Protection Law of the Mainland and the Greater Bay Area Standard Contract
pcpd.org.hk
“are extended to cover all sectors in Hong Kong”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeFacilitating Cross-boundary Data Flow within the Greater Bay Area
digitalpolicy.gov.hk
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Privacy Commissioner for Personal Data enforces the law, and it is busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms. Those orders covered 33,743 doxxing messages. It had opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk completely. The Commissioner cannot fine you for breaking the privacy principles. It serves a notice telling you to fix the problem. Only ignoring that notice is a crime.
- What it costs if you get it wrong:
- Criminal liability
We rate enforcement active rather than aggressive, for a structural reason. Hong Kong has no European-style power to fine you. There is no percentage-of-turnover penalty and no nine-figure decisions. The route is to investigate, serve a notice to fix the problem, then prosecute if you ignore the notice. A first conviction carries up to HK$50,000 (about 6,400 US dollars) and two years in prison. The real teeth are elsewhere. Direct marketing breaches are crimes. They carry up to HK$500,000 (about 64,000 US dollars) and three years. That rises to HK$1,000,000 (about 128,000 US dollars) and five years where data was passed on for gain. Doxxing carries up to HK$1,000,000 and five years for the more serious cases. Industry regulators enforce separately and are fully up and running. The Securities and Futures Commission licenses and disciplines brokers. The Hong Kong Monetary Authority supervises banks. The Insurance Authority supervises insurers. A separate Commissioner's office covers computer-system security for critical infrastructure. It began work when that law took effect on 1 January 2026.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataAnti-doxxing enforcement statistics as at 31 December 2025
pcpd.org.hk
“2,104 cessation notices to 57 online platforms, requesting them to remove 33,743 doxxing messages”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Ordinance at a Glance - offences and penalties
pcpd.org.hk
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a maximum but almost no minimum. You must erase personal data once you no longer need it for the purpose you collected it for. Failing to do so is a crime. The fine is up to HK$10,000 (about 1,300 US dollars). The privacy law sets no minimum keeping periods. Those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins. You delete once that period runs out.
- What you have to do here:
- Delete data after a period · Keep records of how you use data
The maximum comes from the second data protection principle, on accuracy and keeping data, and from a separate duty to erase. The Privacy Commissioner says how long you keep data must follow the purpose, not a fixed calendar. Hong Kong has no general rule on how long to keep logs. India has a 180-day rule and the European Union has telecoms keeping rules. Hong Kong has nothing like them. The minimum periods that matter sit outside the privacy law. They are business records under tax law, accounting records under company law, and customer due diligence records under anti-money-laundering law. We could not open a government source for those specific periods. So they are listed in the unconfirmed list rather than stated here as fact. Licensed securities firms have their own record-keeping duties, enforced by the markets regulator. Those include daily backups and a map showing where records are held.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Ordinance at a Glance - erasure duty and the HK$10,000 offence
pcpd.org.hk
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Six Data Protection Principles - DPP2 Accuracy and Retention
pcpd.org.hk
Link checked 18 August 2026
- Official sourceSecurities and Futures CommissionSFC FAQs - access map, daily backups and record accessibility
sfc.hk
Link checked 18 August 2026
What to do: Set an automatic deletion job so data does not sit past its deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
For a normal data breach there is no deadline, because there is no duty to report. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong. The regulator asks you to do it as good practice and gives you a form. No law makes you. That is unusual, and it is changing. Since 1 January 2026 operators of named critical infrastructure must report computer-system security incidents. Those firms now have a real deadline. Everyone else has none.
- What you have to do here:
- Report breaches to the regulator · Report cyber incidents
There are two deadlines and one of them does not exist. GENERAL BREACH: no deadline. The Commissioner's own page says plainly that telling the office about a data breach is not required by law. It recommends you tell them as soon as you can, and it publishes a form. It also recommends telling the people affected where there is a real risk of harm. CRITICAL INFRASTRUCTURE: the Protection of Critical Infrastructures (Computer Systems) Ordinance took effect on 1 January 2026. Named operators must report incidents to the new Commissioner's office. The reported deadlines are 12 hours for serious incidents and 48 hours for others. We could not open the text of the law on a government site. So those hour figures are flagged in the unconfirmed list and are not stated as verified. Separately, listed companies must disclose to the stock exchange. Licensed brokers are expected to report serious incidents to the markets regulator.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataData Breach Notification - voluntary, not a statutory requirement
pcpd.org.hk
“It is not a statutory requirement on data users to inform the PCPD about a data breach incident”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataUnderstanding the Protection of Critical Infrastructures (Computer Systems) Ordinance to Enhance Data Security - seminar, 5 February 2026
pcpd.org.hk
“came into effect on 1 January 2026”
Link checked 18 August 2026
What to do: Your breach process has to reach Hong Kong SAR's regulator inside the deadline above.
What catches people out
Five things catch people out. First, marketing mistakes are crimes here, not fines. Using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you. People assume the risk is low and miss the criminal side entirely. Third, Hong Kong sets no age at which a child can consent. So there is no simple number to build into a sign-up flow. Fourth, licensed securities firms need written permission before their records sit only on overseas servers. Two named people who live in Hong Kong must be able to unlock them. Fifth, the unused transfer section would also cover data moving between two foreign countries when a Hong Kong company controls it.
- What it costs if you get it wrong:
- Criminal liability
(1) Direct marketing sits in its own part of the law and has its own crimes. Penalties run to HK$500,000 (about 64,000 US dollars) and three years. They rise to HK$1,000,000 (about 128,000 US dollars) and five years where personal data was given to another person for gain. This is the most prosecuted business risk in Hong Kong. (2) People read the lack of fines as a lack of risk. The realistic risks are prosecution, a notice that forces you to change your systems, and damage from a published investigation report. (3) We found no minimum age for consent in the privacy law, checked 18 August 2026. The regulator runs children's privacy education instead. So there is no safe number and no clear line. A global under-13 or under-16 gate is a design choice, not compliance. (4) The markets regulator requires two Managers-In-Charge who normally live in Hong Kong. Each must hold, or be able to get, all the digital certificates, keys, passwords and tokens the regulator needs for access. It looks like a records rule but it is really a staffing rule. (5) The unused transfer section would reach a transfer between two places outside Hong Kong that a Hong Kong data user controls. Most multinationals are set up that way without thinking about it.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Ordinance at a Glance - direct marketing offences and penalties
pcpd.org.hk
Link checked 18 August 2026
- Official sourceSecurities and Futures CommissionSFC FAQs - Managers-In-Charge ordinarily resident in Hong Kong and their undertakings
sfc.hk
“all digital certificates, keys, passwords and tokens”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataCross-border guidance - section 33 reaches transfers between two places outside Hong Kong
pcpd.org.hk
“transfers of personal data between two other jurisdictions where the transfer is controlled by a Hong Kong data user”
Link checked 18 August 2026
What's changing next
Nothing is due to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026. The government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. The government has held an unused power for thirty years. It can bring the cross-border transfer section into force with a simple notice. There is no consultation and no new vote.
UNUSED POWERS, in order of how much damage they would do. (1) The cross-border transfer section. It is in the law, fully written, and needs only a commencement notice from the Secretary. The day it starts, Hong Kong goes from having no transfer rules to letting you send data only to approved countries. The list of approved countries has never been published, so it would be empty. Every routine flow abroad would have to fall back on written consent or a due diligence defence. (2) The wider privacy law review. The government has been reviewing the ordinance since 2020. Ideas discussed include compulsory breach reporting and a set keeping period. The last completed step we could verify on a government site is the 2021 anti-doxxing change. We found no bill in progress as at 18 August 2026. (3) The Greater Bay Area standard contract arrangement is administrative. Its scope can be widened or narrowed by announcement. It was already extended to every Hong Kong industry from 1 November 2024. (4) National security legislation gives the authorities powers to demand help from service providers. We could not open the operative text on a government site. So it is recorded here as an uncertainty, not as a described rule. LEGISLATION IN PROGRESS: the Electronic Health Record Sharing System (Amendment) Bill 2025 was published in the gazette on 21 March 2025. Its first reading was on 26 March 2025. We could not confirm whether it has since passed.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataCritical infrastructure ordinance in effect from 1 January 2026
pcpd.org.hk
Link checked 18 August 2026
- Official sourceDigital Policy OfficePolicies, Laws, Guidelines and Technical Standards - Generative AI guideline April 2025, revised December 2025
digitalpolicy.gov.hk
Link checked 18 August 2026
- Official sourceConstitutional and Mainland Affairs BureauPrivacy - Personal Data (Privacy) (Amendment) Bill 2021 and related documents
cmab.gov.hk
Link checked 18 August 2026
- Official sourceHealth Bureau, HKSAR GovernmentElectronic Health Record Sharing System (Amendment) Bill 2025 - gazettal and first reading dates
info.gov.hk
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Cloud and outsourcing rules
Official name: Circular to Licensed Corporations on the use of external electronic data storage · Securities and Futures Ordinance (Cap. 571) s.130; SFC circular of 31 October 2019 · Regulator directive
The real limit on sending data abroad in Hong Kong. A licensed securities or futures firm may put its records in a cloud abroad. But if it keeps no copies in Hong Kong, it needs written approval of the storage site. It also needs two named people who live in Hong Kong and can hand the regulator the keys on demand. This is about access and staff, not about where data must sit. It shapes your systems the same way.
Enforced by Securities and Futures Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Register or notifyIf you keep official records only outside Hong Kong, the regulator must approve the storage site. If you already do this without approval, apply as soon as you can.
- Appoint a representativeTwo Managers-In-Charge who normally live in Hong Kong. Each must be able to get all the digital certificates, keys, passwords and tokens the regulator needs for access.
- Written vendor contractThe outside data storage provider must give the regulator a written promise. The two Managers-In-Charge can give that promise instead.
- Keep records of how you use dataKeep a map showing where records are held. Take daily backups.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceBreach of licensing conditions and record-keeping requirements can lead to disciplinary action, suspension or revocation of a licence
Sources
- Official sourceSecurities and Futures CommissionFrequently asked questions on the use of external electronic data storage
sfc.hk
“approach the SFC forthwith to discuss its situation and seek approval under section 130 of the SFO”
Link checked 18 August 2026
Cloud and outsourcing rules (Banking)
Official name: Supervisory Policy Manual module SA-2 'Outsourcing' · HKMA Supervisory Policy Manual, SA-2 · Regulator guideline
We found no rule that banking data must stay in Hong Kong, checked 18 August 2026. Banks may use cloud services and suppliers abroad. The bank regulator supervises outsourcing and technology risk. Its focus is on keeping its own access to records, not on where the servers sit. Confidence is low because the regulator's website blocked our access.
Enforced by Hong Kong Monetary Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Written vendor contractThe regulator expects outsourcing deals to keep its ability to reach records and supervise the bank. We could not check this against the source text.
- Secure the data
Sources
- Official sourceLink may be brokenHong Kong Monetary AuthoritySupervisory Policy Manual SA-2 - Outsourcing
hkma.gov.hk
Link checked 18 August 2026
Breach reporting rules (2026)
Official name: Protection of Critical Infrastructures (Computer Systems) Ordinance · Act of parliament
Hong Kong's newest security law, in effect since 1 January 2026. It applies only to operators named as running critical infrastructure. We found no requirement that their computer systems or data be in Hong Kong. We could not check the exact incident reporting deadlines against a government source, so they are flagged as uncertain.
Enforced by Security Bureau and the Commissioner's Office for critical infrastructure computer-system security
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataNamed operators of critical infrastructure must take suitable steps to protect their computer systems. The aim is that essential services are not disrupted by a cyberattack.
- Report cyber incidentsReport incidents to the new Commissioner's office. The reported deadlines are 12 hours for serious incidents and 48 hours otherwise. We could NOT check those against the law. See the unconfirmed list. Do not plan around those hours without checking.
- Independent audit
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataUnderstanding the Protection of Critical Infrastructures (Computer Systems) Ordinance to Enhance Data Security - seminar of 5 February 2026
pcpd.org.hk
“came into effect on 1 January 2026”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeInfoSec portal listing the critical infrastructure ordinance among current data security topics
infosec.gov.hk
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Breach reporting rules
Official name: Personal Data (Privacy) Ordinance · Cap. 486 · Act of parliament
Hong Kong's general privacy law, in force since 1996. It applies to private companies and the public sector alike. There is little paperwork: no registration, no data protection officer, no compulsory breach reporting and no transfer approvals. But enforcement is criminal rather than by fines. It is marked partly in force because its cross-border transfer section has never started.
Enforced by Office of the Privacy Commissioner for Personal Data
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Tell people what you doTell people, on or before collection, what the data is for and to whom it may be transferred.
- Secure the data
- Let people see their data — within 960 hoursA data access request must be answered within 40 days.
- Let people correct their data — within 960 hours
- Delete data after a periodErase personal data once it is no longer needed for the purpose of collection. Failure is an offence.
- Written vendor contractYou stay responsible for any supplier that handles data for you. Use contracts or other means to stop them keeping data too long or letting the wrong people see it.
- Get consentConsent is required to use data for a new purpose, and separately for direct marketing.
What it costs if you get it wrong
- Criminal liability: HK$50,000 and 2 years imprisonment — about $6 thousandFailing to comply with an enforcement notice served by the Privacy Commissioner
- Criminal liability: HK$500,000 and 3 years imprisonment — about $64 thousandUsing personal data in direct marketing without complying with the direct marketing rules
- Criminal liability: HK$1,000,000 and 5 years imprisonment — about $128 thousandProviding personal data to another person for gain in direct marketing without consent
- Criminal liability: HK$10,000 — about $1 thousandFailing to erase personal data no longer required
- Claims by individualsAn individual who suffers damage, including injury to feelings, may claim compensation
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Personal Data (Privacy) Ordinance at a Glance
pcpd.org.hk
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Six Data Protection Principles
pcpd.org.hk
Link checked 18 August 2026
- Official sourceDepartment of Justice, Hong Kong e-LegislationPersonal Data (Privacy) Ordinance (Cap. 486), consolidated text
elegislation.gov.hk
Link checked 18 August 2026
Rules for sending data abroad
Official name: Personal Data (Privacy) Ordinance, section 33 - prohibition against transfer of personal data to place outside Hong Kong except in specified circumstances · Cap. 486 s.33 · Act of parliament
A full set of cross-border transfer rules, written in 1995. It sits in the law and has never been brought into force. Nothing in it binds anyone today. A quick read of the ordinance makes Hong Kong look restricted, and it is not. The government can bring the rules into force by notice at any time. On that day, the list of approved destinations would be empty.
Enforced by Office of the Privacy Commissioner for Personal Data
How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Standard contract clauses
What you have to do
- Put a transfer safeguard in placeDoes not apply yet. No start date has ever been set. The list of approved destinations has never been published.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataGuidance on Personal Data Protection in Cross-border Data Transfer
pcpd.org.hk
“Although section 33 is not yet effective, this Guidance serves as a practical guide for data users to prepare for the implementation of section 33 of the Ordinance.”
Link checked 18 August 2026
General data protection law
Official name: Personal Data (Privacy) (Amendment) Ordinance 2021 - anti-doxxing provisions · Cap. 486 ss.64, 66D-66K · Act of parliament
Hong Kong's most used data power. The Privacy Commissioner can order any service provider, in Hong Kong or abroad, to remove doxxing content. It can also investigate and arrest. It had issued over two thousand such orders by the end of 2025. This is why we rate Hong Kong's enforcement active, even though it cannot fine you.
Enforced by Office of the Privacy Commissioner for Personal Data
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataA platform that gets a takedown notice must remove the content. This applies wherever the platform or the content sits.
What it costs if you get it wrong
- Criminal liability: HK$100,000 and 2 years imprisonment — about $13 thousandDisclosing personal data without consent with intent or recklessness as to causing specified harm (summary offence)
- Criminal liability: HK$1,000,000 and 5 years imprisonment — about $128 thousandThe same, where specified harm is actually caused (indictable offence)
- Daily fine until fixed: HK$50,000 plus HK$1,000 per day, rising to HK$100,000 plus HK$2,000 per day on a later conviction — about $6 thousandFailing to comply with a cessation notice
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataDoxxing offences, cessation notices and enforcement statistics as at 31 December 2025
pcpd.org.hk
“regardless of whether the disclosure is made in Hong Kong or not”
Link checked 18 August 2026
- Official sourceConstitutional and Mainland Affairs BureauPersonal Data (Privacy) (Amendment) Bill 2021
cmab.gov.hk
Link checked 18 August 2026
Data rules
Official name: Standard Contract for the Cross-boundary Flow of Personal Information Within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Hong Kong) · Memorandum of Understanding signed 29 June 2023; facilitation measure announced 13 December 2023 · Government policy document
This is the direction that really restricts data in Hong Kong. The restriction comes from mainland China, not from Hong Kong law. Moving personal information from the mainland into Hong Kong normally needs a mainland security assessment or standard contract. The Greater Bay Area arrangement is a lighter voluntary route covering nine mainland cities. Hong Kong itself puts no limit on data going out.
Enforced by Digital Policy Office
How this country controls where data goes: Approval each time · Accepted routes: Standard contract clauses, Security review needed
What you have to do
- Put a transfer safeguard in placeVoluntary simpler route. Covers flows between nine mainland Greater Bay Area cities - Guangzhou, Shenzhen, Zhuhai, Foshan, Huizhou, Dongguan, Zhongshan, Jiangmen and Zhaoqing - and Hong Kong. Extended to every Hong Kong industry from 1 November 2024.
- Written vendor contract
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataPersonal Information Protection Law of the Mainland and the Greater Bay Area Standard Contract
pcpd.org.hk
“are extended to cover all sectors in Hong Kong”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeFacilitating Cross-boundary Data Flow within the Greater Bay Area
digitalpolicy.gov.hk
Link checked 18 August 2026
- Official sourceInnovation, Technology and Industry Bureau and Office of the Government Chief Information OfficerPolicy Statement on Facilitating Data Flow and Safeguarding Data Security in Hong Kong, December 2023
itib.gov.hk
Link checked 18 August 2026
AI rules
Official name: Artificial Intelligence: Model Personal Data Protection Framework · Regulator guideline
Voluntary guidance if you buy or use artificial intelligence that touches personal data. It sets no limit on where models or training data sit. It does tell you to check the rules of any country whose data centres handle your data. That includes the rules on sending the data back. This is advice only. The binding law is still the privacy ordinance.
Enforced by Office of the Privacy Commissioner for Personal Data
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Assess high-risk projectsRecommended, not required. Assess the risk in line with how much the system affects people. Keep a human in the loop.
- Check your algorithms
- Tell people what you doRecommended. Be open with the people affected and explain how the system reaches its decisions.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataArtificial Intelligence: Model Personal Data Protection Framework, June 2024
pcpd.org.hk
“ascertain if there are any restrictions or regulations pertaining to cross-border transfers of data back to the data user from the jurisdiction where the data are processed”
Link checked 18 August 2026
Applies only if you signed a contract1 rule
Usually a government or enterprise contract that adds rules of its own.
Cloud and outsourcing rules (Government)
Official name: IT Security Standards and Best Practices, and the Practice Guide on Data Centre Security, applied to bureaux and departments · Government policy document
Government departments are told to keep sensitive and personal information off public cloud platforms. They must encrypt data at rest and in transit and run regular audits. This is internal policy, not a law. It reaches suppliers through their contracts. It is the closest Hong Kong gets to a rule that public-sector data must stay in the country.
Enforced by Digital Policy Office
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Secure the dataEncrypt data in transit and in storage. Do not store sensitive and personal information on public cloud platforms.
- Independent auditRun regular security risk assessments and audits of your computer systems. Test large and high-risk projects before launch.
Sources
- Official sourceDigital Policy OfficeProtection of Data Security
digitalpolicy.gov.hk
“refraining from storing sensitive and personal information on public cloud platforms”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeInfoSec - IT security standards and best practices portal
infosec.gov.hk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact incident reporting deadlines under the Protection of Critical Infrastructures (Computer Systems) Ordinance, widely reported as 12 hours for serious incidents and 48 hours otherwise
We could not confirm these deadlines against the text of the law. Hong Kong's official legislation website blocks automated access. If you run critical infrastructure, ask the Commissioner's office for the exact deadlines before you rely on them.
Whether that ordinance requires a designated operator to keep a computer-system security management unit, or its computer systems, physically in Hong Kong
We found no requirement that systems stay in Hong Kong, but we could not read the text of the law. If you run critical infrastructure, check this before you rely on it.
The Hong Kong Monetary Authority's outsourcing and cloud requirements for banks, including whether customer data may be processed offshore and on what conditions
We could not reach the Hong Kong Monetary Authority's website, including its Supervisory Policy Manual. So we state no rule that banking data must stay in Hong Kong. If you are a bank, confirm the outsourcing and cloud rules with the regulator.
Whether the Insurance Authority imposes any data storage, outsourcing or localisation requirement on insurers
The Insurance Authority's guidelines pages refused us access. We record no insurance rule, which does not mean none exists. If you are an insurer, check with the regulator.
Minimum retention floors in Hong Kong tax, company and anti-money-laundering law, commonly described as seven years for business and accounting records and five years for customer due diligence records
We could not confirm these minimum keeping periods against a government source, so the retention answer states no figure. Check the tax, company and anti-money-laundering rules that apply to you.
Whether any minimum age applies to a child's consent under the privacy ordinance
We found no minimum age in the regulator's published material, checked 18 August 2026. We could not read the law itself to be sure. Do not assume a set age applies.
Whether the Electronic Health Record Sharing System (Amendment) Bill 2025 has been passed and commenced
We confirmed the bill was published in the gazette on 21 March 2025 and had its first reading on 26 March 2025. We could not confirm what happened after that. Check the current status before you rely on it.
The scope of national security powers to compel service providers to hand over identification records, assist with decryption or remove content
We could not open the government's national security legislation pages. This is listed as an unused power in the eighth answer rather than described as a rule.
Whether the Privacy Commissioner has published any investigation report or enforcement notice in 2026
We could not open the enforcement and investigation report pages. Our enforcement rating uses the doxxing figures published to 31 December 2025, which are solid. It does not rely on 2026 activity.
The number of Greater Bay Area standard contract registrations filed by Hong Kong organisations
Neither the Privacy Commissioner nor the Digital Policy Office publishes a number we could retrieve. The arrangement does exist, and its extension to every Hong Kong industry from 1 November 2024 is confirmed.
The exact dates the privacy ordinance was passed (given here as 3 August 1995) and commenced (given here as 20 December 1996), and the date the Protection of Critical Infrastructures (Computer Systems) Ordinance was passed
Hong Kong's official consolidated law website blocks automated access. The regulator confirms the law was enacted in 1995. It confirms the critical infrastructure ordinance took effect on 1 January 2026. We did not read the exact passing and start dates from an official text.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.