Hong Kong SAR
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Hong Kong's privacy law contains a cross-border transfer ban that has never been switched on. It was written in 1995 and, thirty years later, still has no start date. So under the general law you can send personal data anywhere with no paperwork at all. The privacy regulator is busy and prosecutes people, but it cannot fine you directly.
Eight questions about Hong Kong SAR
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Hong Kong SAR's rules apply to my company?
Yes, it can reach you with no office in Hong Kong. The privacy law bites on whoever controls the collection, holding, use or processing of personal data in or from Hong Kong, so a foreign company running a Hong Kong-facing service is caught. There is no revenue or headcount threshold to fall below, no register to join, and no requirement to appoint a local representative. The anti-doxxing powers go further still: the regulator can order an overseas platform to take material down.
The Personal Data (Privacy) Ordinance (Cap. 486) has applied since 20 December 1996 to both the private and the public sector. The obligations attach to a 'data user' - the party that controls the data - rather than to an establishment in Hong Kong. Unlike the European Union's General Data Protection Regulation, there is no Article 27-style duty to appoint a representative, no data protection officer requirement, and no registration or notification scheme. The clearest statutory reach beyond Hong Kong is in the doxxing provisions added in 2021: the Privacy Commissioner may serve a cessation notice on a service provider whether or not the person is in Hong Kong and whether or not the disclosure was made in Hong Kong. Note the mirror-image trap in the dormant section 33: were it ever commenced, it would also catch a transfer between two places outside Hong Kong where a Hong Kong data user controls it.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Personal Data (Privacy) Ordinance at a Glance
pcpd.org.hk
“one of Asia's longest standing comprehensive data protection laws”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataAnti-doxxing regime - powers, offences and enforcement figures
pcpd.org.hk
“regardless of whether the disclosure is made in Hong Kong or not”
Link checked 18 August 2026
Can I store my users' data outside Hong Kong SAR?
Under the general privacy law, yes - freely, with nothing to sign. The one section that would have restricted transfers abroad was written into the law in 1995 and has never been brought into operation, so today there is no legal control on personal data leaving Hong Kong. Industry rules are where the real limits sit, and there are fewer of them than people expect: the securities regulator is the main one, and government departments have their own restriction.
Sector by sector, checked on 18 August 2026. SECURITIES AND FUTURES - a hard conditional wall. A licensed corporation may keep its regulatory records only outside Hong Kong if the markets regulator approves the premises, and it must appoint two Managers-In-Charge ordinarily resident in Hong Kong who can get at the records on demand. Rating: conditional. GOVERNMENT AND PUBLIC SECTOR - departments are instructed to refrain from storing sensitive and personal information on public cloud platforms. Rating: conditional. BANKING AND PAYMENTS - no localisation rule found. The bank regulator supervises outsourcing and cloud use and expects to be able to reach the data and records, but we could not open its policy manual in this run, so this is rated low confidence rather than asserted as clear. Rating: conditional, low confidence. INSURANCE - no localisation rule found on the regulator's own site, which blocked automated access; low confidence. HEALTH - the electronic health record sharing system is built around patient consent, and a 2025 bill would let a person authorise a healthcare provider outside Hong Kong to see or deposit records. No prohibition on records leaving found. Rating: open. TELECOM, EDUCATION, GAMING, MAPPING AND GEOSPATIAL, DEFENCE - no data localisation rule found on government sources, checked 18 August 2026; treat as open with medium confidence rather than as proven. CRITICAL INFRASTRUCTURE - a new law in force since 1 January 2026 imposes security and reporting duties on designated operators; we found no requirement that their computer systems or data sit in Hong Kong, but we could not read the statute text. THE DIRECTION THAT ACTUALLY BITES is inbound: moving personal information from mainland China into Hong Kong is restricted by mainland law, and the Greater Bay Area standard contract exists precisely to make that legal.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataGuidance on Personal Data Protection in Cross-border Data Transfer
pcpd.org.hk
“Although section 33 is not yet effective, this Guidance serves as a practical guide for data users to prepare for the implementation of section 33 of the Ordinance.”
Link checked 18 August 2026
- Official sourceSecurities and Futures CommissionFrequently asked questions on the use of external electronic data storage
sfc.hk
“an undertaking from each of the two MICs appointed”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeProtection of Data Security - requirements on government bureaux and departments
digitalpolicy.gov.hk
“refraining from storing sensitive and personal information on public cloud platforms”
Link checked 18 August 2026
- Official sourceHealth Bureau, HKSAR GovernmentElectronic Health Record Sharing System (Amendment) Bill 2025 to be gazetted
info.gov.hk
Link checked 18 August 2026
What do I need in place before data leaves Hong Kong SAR?
Nothing. There is no approval to seek, no standard contract to sign and no government list to check before personal data leaves Hong Kong. The model on paper is an allowlist - the regulator would publish a list of approved destinations - but because the section was never switched on, that list has never been issued and is empty. The regulator does publish a voluntary guide and encourages firms to build the safeguards now, but that is advice, not law.
If section 33 were ever commenced, a transfer out of Hong Kong would need one of six gateways: the destination is on a white list of places the Commissioner has decided have substantially similar law; the data user has reasonable grounds to believe such a law is in force there; the person has consented in writing; the transfer avoids adverse action against the person and written consent is impracticable; a Part VIII exemption applies; or the data user has taken all reasonable precautions and exercised all due diligence. Two features make it stricter than it looks. First, it would catch transfers between two places outside Hong Kong controlled by a Hong Kong data user. Second, the due-diligence gateway is a standard of conduct, not a document you file, so it cannot be discharged by signing a template. Going the other way, from mainland China into Hong Kong, the Greater Bay Area Standard Contract was announced on 13 December 2023 under a memorandum signed on 29 June 2023, and from 1 November 2024 the facilitation measures were extended to cover all sectors in Hong Kong. It is a voluntary simplified route, not a Hong Kong legal requirement.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataGuidance on Personal Data Protection in Cross-border Data Transfer - the six section 33 gateways
pcpd.org.hk
“Regardless of when section 33 will take effect, data users are encouraged to adopt the practices recommended in this Guidance as part of their corporate governance responsibility to protect personal data.”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Personal Information Protection Law of the Mainland and the Greater Bay Area Standard Contract
pcpd.org.hk
“are extended to cover all sectors in Hong Kong”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeFacilitating Cross-boundary Data Flow within the Greater Bay Area
digitalpolicy.gov.hk
Link checked 18 August 2026
Who enforces the rules in Hong Kong SAR, and what can they do?
The Privacy Commissioner for Personal Data, and it is genuinely busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms to take down 33,743 doxxing messages, opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk picture completely: the Commissioner cannot impose a fine for breaking the privacy principles. It serves a notice telling you to fix the problem, and only ignoring that notice is a crime.
Rated active rather than aggressive for a structural reason. Hong Kong has no administrative fining power of the European kind - no percentage-of-turnover penalty, no headline nine-figure decisions. The enforcement route is: investigate, serve an enforcement notice, and prosecute if the notice is ignored (up to HK$50,000, about $6,400, and two years in prison for a first conviction). The teeth are elsewhere. Direct marketing breaches are criminal offences carrying up to HK$500,000 (about $64,000) and three years, rising to HK$1,000,000 (about $128,000) and five years where data was passed on for gain. Doxxing carries up to HK$1,000,000 and five years on indictment. Sector regulators enforce separately and are fully operational: the Securities and Futures Commission licenses and disciplines intermediaries, the Hong Kong Monetary Authority supervises banks, and the Insurance Authority supervises insurers. A separate Commissioner's office for critical infrastructure computer-system security began work when that law took effect on 1 January 2026.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataAnti-doxxing enforcement statistics as at 31 December 2025
pcpd.org.hk
“2,104 cessation notices to 57 online platforms, requesting them to remove 33,743 doxxing messages”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Ordinance at a Glance - offences and penalties
pcpd.org.hk
Link checked 18 August 2026
How long do I have to keep the data?
There is a hard ceiling and almost no floor in the privacy law itself. You must erase personal data once it is no longer needed for the purpose you collected it for, and failing to do so is a criminal offence carrying a fine of up to HK$10,000 (about $1,300). The privacy law sets no minimum keeping periods; those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins, and you delete once it expires.
The ceiling sits in the second Data Protection Principle (accuracy and retention) and in the standalone erasure duty. The Privacy Commissioner's position is that retention must be tied to purpose, not to a fixed calendar. Hong Kong publishes no general log-retention mandate equivalent to India's 180-day rule or the European Union's telecoms retention regimes. The floors that matter in practice sit outside the privacy law - business records under tax law, accounting records under company law, and customer due diligence records under the anti-money-laundering regime - and we were not able to open a government source for those specific periods during this run, so they are listed in the unconfirmed array rather than stated here as fact. Licensed securities firms have their own record-keeping obligations enforced by the markets regulator, including daily backups and an access map showing where records are held.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Ordinance at a Glance - erasure duty and the HK$10,000 offence
pcpd.org.hk
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Six Data Protection Principles - DPP2 Accuracy and Retention
pcpd.org.hk
Link checked 18 August 2026
- Official sourceSecurities and Futures CommissionSFC FAQs - access map, daily backups and record accessibility
sfc.hk
Link checked 18 August 2026
What happens if there is a breach?
For a normal data breach there is no deadline, because there is no duty. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong - the regulator asks you to do it as good practice and gives you a form, but no law compels it. That is unusual and it is changing: since 1 January 2026 operators of designated critical infrastructure must report computer-system security incidents, so those firms now have a real clock while everyone else has none.
Two clocks, one of which is empty. CLOCK ONE, general breach: none. The Commissioner's own page states plainly that it is not a statutory requirement to inform the office about a data breach. Voluntary notification is recommended as soon as practicable, and the Commissioner publishes a notification form. Individuals should be told where there is a real risk of harm, again as a recommendation. CLOCK TWO, critical infrastructure: the Protection of Critical Infrastructures (Computer Systems) Ordinance took effect on 1 January 2026 and requires designated operators to report incidents to the new Commissioner's office. The reported deadlines are 12 hours for serious incidents and 48 hours for others; we could not open the statute text on a government site during this run, so those specific hour figures are flagged in the unconfirmed array and are deliberately not asserted in the rule as verified. Separately, listed companies have disclosure duties to the stock exchange, and licensed intermediaries are expected to report material incidents to the markets regulator.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataData Breach Notification - voluntary, not a statutory requirement
pcpd.org.hk
“It is not a statutory requirement on data users to inform the PCPD about a data breach incident”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataUnderstanding the Protection of Critical Infrastructures (Computer Systems) Ordinance to Enhance Data Security - seminar, 5 February 2026
pcpd.org.hk
“came into effect on 1 January 2026”
Link checked 18 August 2026
What trips people up in Hong Kong SAR?
Five things that catch people out. First, marketing mistakes are crimes here, not fines - using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you, so people assume the risk is low and miss the criminal exposure entirely. Third, Hong Kong sets no age at which a child can consent, so there is no simple number to code into a sign-up flow. Fourth, licensed securities firms need written permission before their records live only on overseas servers, and two named people who live in Hong Kong must be able to unlock them. Fifth, the dormant transfer section, if ever switched on, would also catch data moving between two foreign countries when a Hong Kong company controls it.
(1) Direct marketing sits in a separate part of the law with its own criminal offences: up to HK$500,000 (about $64,000) and three years, and up to HK$1,000,000 (about $128,000) and five years where personal data was provided to another person for gain. This is the single most prosecuted commercial exposure. (2) The absence of an administrative fine is widely misread as an absence of risk. The realistic exposures are prosecution, an enforcement notice that forces a system change, and reputational damage from a published investigation report. (3) No statutory age of digital consent was found in the privacy law, checked 18 August 2026 - the regulator runs children's privacy education instead. That means no safe harbour and no bright line, so a global under-13 or under-16 gate is a design choice, not compliance. (4) The markets regulator requires two Managers-In-Charge ordinarily resident in Hong Kong who hold, or can procure, all digital certificates, keys, passwords and tokens needed to give the regulator access - an in-country personnel requirement dressed as a records rule. (5) Section 33 would reach a transfer between two places outside Hong Kong where a Hong Kong data user controls it, which is a structure most multinationals use without thinking about it.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Ordinance at a Glance - direct marketing offences and penalties
pcpd.org.hk
Link checked 18 August 2026
- Official sourceSecurities and Futures CommissionSFC FAQs - Managers-In-Charge ordinarily resident in Hong Kong and their undertakings
sfc.hk
“all digital certificates, keys, passwords and tokens”
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataCross-border guidance - section 33 reaches transfers between two places outside Hong Kong
pcpd.org.hk
“transfers of personal data between two other jurisdictions where the transfer is controlled by a Hong Kong data user”
Link checked 18 August 2026
What is changing soon in Hong Kong SAR?
Nothing is scheduled to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026, and the government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. It is a switch the government has held for thirty years: the cross-border transfer section can be brought into force by a simple commencement notice, with no consultation and no new vote.
DORMANT SWITCHES, in order of how much damage they would do. (1) Section 33. It is on the statute book, fully drafted, and needs only a commencement notice from the Secretary. The day it commences, Hong Kong flips overnight from having no transfer rules to having an allowlist regime with an empty allowlist - because the white list of approved destinations has never been published. Every routine offshore flow would need to fall back on written consent or a due-diligence defence. (2) The wider privacy law review. The government has been reviewing the ordinance since 2020, with mandatory breach notification and a statutory retention period among the ideas discussed; the last completed step we could verify on a government site is the 2021 anti-doxxing amendment, and we found no bill in progress as at 18 August 2026. (3) The Greater Bay Area standard contract arrangement is administrative, so its scope can be widened or narrowed by announcement - it was already extended to all Hong Kong sectors from 1 November 2024. (4) National security legislation gives the authorities powers to require assistance from service providers; we could not open the operative text on a government site in this run, so it is recorded here as a flagged uncertainty rather than a described rule. LEGISLATION IN PROGRESS: the Electronic Health Record Sharing System (Amendment) Bill 2025 was gazetted on 21 March 2025 with first reading on 26 March 2025; we could not confirm whether it has since passed.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataCritical infrastructure ordinance in effect from 1 January 2026
pcpd.org.hk
Link checked 18 August 2026
- Official sourceDigital Policy OfficePolicies, Laws, Guidelines and Technical Standards - Generative AI guideline April 2025, revised December 2025
digitalpolicy.gov.hk
Link checked 18 August 2026
- Official sourceConstitutional and Mainland Affairs BureauPrivacy - Personal Data (Privacy) (Amendment) Bill 2021 and related documents
cmab.gov.hk
Link checked 18 August 2026
- Official sourceHealth Bureau, HKSAR GovernmentElectronic Health Record Sharing System (Amendment) Bill 2025 - gazettal and first reading dates
info.gov.hk
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
3 rules here
Layer 3
Contract-imposed rule
Binds you because you signed something, typically a government contract.
1 rule here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules5 rules
Personal Data (Privacy) Ordinance
Act of parliament · Cap. 486
Hong Kong's general privacy law, in force since 1996 and applying to the private and public sectors alike. It is light on paperwork - no registration, no data protection officer, no mandatory breach reporting and no transfer approvals - but the enforcement route is criminal rather than administrative. It is marked partly in force because its cross-border transfer section has never been commenced.
Enforced by Office of the Privacy Commissioner for Personal Data
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Tell people what you doTell people, on or before collection, what the data is for and to whom it may be transferred.
- Secure the data
- Let people see their data — within 960 hoursA data access request must be answered within 40 days.
- Let people correct their data — within 960 hours
- Delete data after a periodErase personal data once it is no longer needed for the purpose of collection. Failure is an offence.
- Written vendor contractA data user stays responsible for a processor and must use contractual or other means to prevent over-retention and unauthorised access.
- Get consentConsent is required to use data for a new purpose, and separately for direct marketing.
What it costs if you get it wrong
- Criminal liability: HK$50,000 and 2 years imprisonment — about $6 thousandFailing to comply with an enforcement notice served by the Privacy Commissioner
- Criminal liability: HK$500,000 and 3 years imprisonment — about $64 thousandUsing personal data in direct marketing without complying with the direct marketing rules
- Criminal liability: HK$1,000,000 and 5 years imprisonment — about $128 thousandProviding personal data to another person for gain in direct marketing without consent
- Criminal liability: HK$10,000 — about $1 thousandFailing to erase personal data no longer required
- Claims by individualsAn individual who suffers damage, including injury to feelings, may claim compensation
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Personal Data (Privacy) Ordinance at a Glance
pcpd.org.hk
Link checked 18 August 2026
- Official sourceOffice of the Privacy Commissioner for Personal DataThe Six Data Protection Principles
pcpd.org.hk
Link checked 18 August 2026
- Official sourceDepartment of Justice, Hong Kong e-LegislationPersonal Data (Privacy) Ordinance (Cap. 486), consolidated text
elegislation.gov.hk
Link checked 18 August 2026
Personal Data (Privacy) Ordinance, section 33 - prohibition against transfer of personal data to place outside Hong Kong except in specified circumstances
Act of parliament · Cap. 486 s.33
The single most misread provision in Hong Kong law. A full cross-border transfer regime, drafted in 1995, sitting on the statute book and never brought into operation. A naive reading of the ordinance reports Hong Kong as a restricted jurisdiction; in reality nothing here binds anyone today. It can be commenced by notice at any time, and on that day the allowlist would be empty.
Enforced by Office of the Privacy Commissioner for Personal Data
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Standard contract clauses
What it makes you do
- Put a transfer safeguard in placeNot yet applicable. No commencement date has ever been set, and the white list of approved destinations has never been published.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataGuidance on Personal Data Protection in Cross-border Data Transfer
pcpd.org.hk
“Although section 33 is not yet effective, this Guidance serves as a practical guide for data users to prepare for the implementation of section 33 of the Ordinance.”
Link checked 18 August 2026
Personal Data (Privacy) (Amendment) Ordinance 2021 - anti-doxxing provisions
Act of parliament · Cap. 486 ss.64, 66D-66K
Hong Kong's most actively used data power. The Privacy Commissioner can order any service provider, in Hong Kong or abroad, to remove doxxing content, and can investigate and arrest. Over two thousand such orders had been issued by the end of 2025. This is what makes Hong Kong's enforcement rating active despite the absence of administrative fines.
Enforced by Office of the Privacy Commissioner for Personal Data
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataA platform served with a cessation notice must take the specified content down, wherever it or the content is located.
What it costs if you get it wrong
- Criminal liability: HK$100,000 and 2 years imprisonment — about $13 thousandDisclosing personal data without consent with intent or recklessness as to causing specified harm (summary offence)
- Criminal liability: HK$1,000,000 and 5 years imprisonment — about $128 thousandThe same, where specified harm is actually caused (indictable offence)
- Daily fine until fixed: HK$50,000 plus HK$1,000 per day, rising to HK$100,000 plus HK$2,000 per day on a later conviction — about $6 thousandFailing to comply with a cessation notice
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataDoxxing offences, cessation notices and enforcement statistics as at 31 December 2025
pcpd.org.hk
“regardless of whether the disclosure is made in Hong Kong or not”
Link checked 18 August 2026
- Official sourceConstitutional and Mainland Affairs BureauPersonal Data (Privacy) (Amendment) Bill 2021
cmab.gov.hk
Link checked 18 August 2026
Standard Contract for the Cross-boundary Flow of Personal Information Within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Hong Kong)
Government policy document · Memorandum of Understanding signed 29 June 2023; facilitation measure announced 13 December 2023
This is the direction that actually restricts data in Hong Kong, and the restriction comes from mainland China rather than from Hong Kong law. Moving personal information from the mainland into Hong Kong normally needs a mainland security assessment or standard contract; the Greater Bay Area arrangement is a lighter voluntary route covering nine mainland cities. Hong Kong itself imposes nothing on the outbound leg.
Enforced by Digital Policy Office
Transfer model: Approval each time · Accepted routes: Standard contract clauses, Security review needed
What it makes you do
- Put a transfer safeguard in placeVoluntary simplified route. Covers flows between nine mainland Greater Bay Area cities - Guangzhou, Shenzhen, Zhuhai, Foshan, Huizhou, Dongguan, Zhongshan, Jiangmen and Zhaoqing - and Hong Kong. Extended to all Hong Kong sectors from 1 November 2024.
- Written vendor contract
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataPersonal Information Protection Law of the Mainland and the Greater Bay Area Standard Contract
pcpd.org.hk
“are extended to cover all sectors in Hong Kong”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeFacilitating Cross-boundary Data Flow within the Greater Bay Area
digitalpolicy.gov.hk
Link checked 18 August 2026
- Official sourceInnovation, Technology and Industry Bureau and Office of the Government Chief Information OfficerPolicy Statement on Facilitating Data Flow and Safeguarding Data Security in Hong Kong, December 2023
itib.gov.hk
Link checked 18 August 2026
Artificial Intelligence: Model Personal Data Protection Framework
Regulator guideline · Artificial intelligence
Voluntary guidance for organisations buying or deploying artificial intelligence that touches personal data. It sets no geographic limit on where models or training data sit, but tells organisations to check the rules of any jurisdiction whose data centres process their data, including on sending the data back. Persuasive only - the binding law remains the privacy ordinance.
Enforced by Office of the Privacy Commissioner for Personal Data
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Assess high-risk projectsRecommended, not required: risk assessment proportionate to the impact of the system, with human oversight.
- Check your algorithms
- Tell people what you doRecommended transparency and explainability to affected people.
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataArtificial Intelligence: Model Personal Data Protection Framework, June 2024
pcpd.org.hk
“ascertain if there are any restrictions or regulations pertaining to cross-border transfers of data back to the data user from the jurisdiction where the data are processed”
Link checked 18 August 2026
Industry rules3 rules
Circular to Licensed Corporations on the use of external electronic data storage
Regulator directive · Securities and Futures Ordinance (Cap. 571) s.130; SFC circular of 31 October 2019 · Securities
The real cross-border wall in Hong Kong. A licensed securities or futures firm may put its records in an overseas cloud, but if Hong Kong copies are not kept it needs written approval of the storage premises, plus two named people living in Hong Kong who can hand the regulator the keys on demand. It is an access-and-personnel rule rather than a data residency rule, but it has the same effect on architecture.
Enforced by Securities and Futures Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Register or notifyWhere regulatory records are kept only outside Hong Kong, the storage premises must be approved by the regulator. A firm already doing this without approval must apply as soon as practicable.
- Appoint a local representativeTwo Managers-In-Charge ordinarily resident in Hong Kong, each able to procure all digital certificates, keys, passwords and tokens needed to give the regulator access.
- Written vendor contractAn undertaking from the external electronic data storage provider to the regulator, or undertakings from the two Managers-In-Charge instead.
- Keep records of processingMaintain an access map showing where records are kept, and take daily backups.
- Secure the data
What it costs if you get it wrong
- Loss of your licenceBreach of licensing conditions and record-keeping requirements can lead to disciplinary action, suspension or revocation of a licence
Sources
- Official sourceSecurities and Futures CommissionFrequently asked questions on the use of external electronic data storage
sfc.hk
“approach the SFC forthwith to discuss its situation and seek approval under section 130 of the SFO”
Link checked 18 August 2026
Supervisory Policy Manual module SA-2 'Outsourcing'
Regulator guideline · HKMA Supervisory Policy Manual, SA-2 · Banking
No banking data localisation rule was found for Hong Kong, checked 18 August 2026. Banks may use overseas cloud and overseas processors, subject to the bank regulator's outsourcing and technology risk supervision, which centres on the regulator retaining access to records rather than on where the servers sit. Confidence is low because the regulator's website blocked automated retrieval throughout this run.
Enforced by Hong Kong Monetary Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Written vendor contractSupervisory expectation that outsourcing arrangements preserve the regulator's ability to access records and supervise the bank. Not verified against the source text in this run.
- Secure the data
Sources
- Official sourceLink may be brokenHong Kong Monetary AuthoritySupervisory Policy Manual SA-2 - Outsourcing
hkma.gov.hk
Link checked 18 August 2026
Protection of Critical Infrastructures (Computer Systems) Ordinance
Act of parliament
Hong Kong's newest security law, in effect since 1 January 2026, applying only to operators designated as running critical infrastructure. We found no requirement that their computer systems or data be located in Hong Kong. The exact incident reporting clocks could not be verified from a government source and are flagged as uncertain.
Enforced by Security Bureau and the Commissioner's Office for critical infrastructure computer-system security
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataDesignated operators of critical infrastructure must adopt appropriate measures to protect their computer systems so that essential services are not disrupted by cyberattack.
- Report cyber incidentsIncident reporting to the new Commissioner's office. Reported deadlines of 12 hours for serious incidents and 48 hours otherwise could NOT be verified against the statute in this run - see the unconfirmed list. Do not plan to those hours without checking.
- Independent audit
Sources
- Official sourceOffice of the Privacy Commissioner for Personal DataUnderstanding the Protection of Critical Infrastructures (Computer Systems) Ordinance to Enhance Data Security - seminar of 5 February 2026
pcpd.org.hk
“came into effect on 1 January 2026”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeInfoSec portal listing the critical infrastructure ordinance among current data security topics
infosec.gov.hk
Link checked 18 August 2026
Contract-imposed rule1 rule
IT Security Standards and Best Practices, and the Practice Guide on Data Centre Security, applied to bureaux and departments
Government policy document · Government
Government departments are told to keep sensitive and personal information off public cloud platforms, encrypt data at rest and in transit, and run regular audits. This is an internal policy binding through procurement rather than a statute, so it reaches suppliers through their contracts. It is the closest thing Hong Kong has to a public-sector residency rule.
Enforced by Digital Policy Office
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Secure the dataEncrypt data in transit and in storage; do not store sensitive and personal information on public cloud platforms.
- Independent auditRegular security risk assessments and audits of information technology infrastructure; pre-launch testing of large-scale and high-risk projects.
Sources
- Official sourceDigital Policy OfficeProtection of Data Security
digitalpolicy.gov.hk
“refraining from storing sensitive and personal information on public cloud platforms”
Link checked 18 August 2026
- Official sourceDigital Policy OfficeInfoSec - IT security standards and best practices portal
infosec.gov.hk
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact incident reporting deadlines under the Protection of Critical Infrastructures (Computer Systems) Ordinance, widely reported as 12 hours for serious incidents and 48 hours otherwise
Hong Kong e-Legislation blocks automated retrieval through its robots file, and the Commissioner's office website could not be located or opened on 18 August 2026. We verified only that the ordinance took effect on 1 January 2026, from the Privacy Commissioner's own seminar page.
Whether that ordinance requires a designated operator to keep a computer-system security management unit, or its computer systems, physically in Hong Kong
Same reason. No localisation requirement was found, but absence of evidence here is weak evidence of absence because we could not read the statute.
The Hong Kong Monetary Authority's outsourcing and cloud requirements for banks, including whether customer data may be processed offshore and on what conditions
Every attempt to fetch hkma.gov.hk returned an empty document, including the Supervisory Policy Manual PDF. The rule is recorded at low confidence with the government link marked unreachable, and no localisation claim is asserted.
Whether the Insurance Authority imposes any data storage, outsourcing or localisation requirement on insurers
The Insurance Authority's guidelines pages returned an access-denied response to automated retrieval. No insurance sector rule is recorded, which should not be read as confirmation that none exists.
Minimum retention floors in Hong Kong tax, company and anti-money-laundering law, commonly described as seven years for business and accounting records and five years for customer due diligence records
The Inland Revenue Department and Companies Registry pages we tried returned not-found errors on 18 August 2026, so no figure is asserted in the retention answer.
Whether any minimum age applies to a child's consent under the privacy ordinance
No age threshold was found in the regulator's published material, checked 18 August 2026. We could not read the statute directly to prove the negative.
Whether the Electronic Health Record Sharing System (Amendment) Bill 2025 has been passed and commenced
We verified only its gazettal on 21 March 2025 and first reading on 26 March 2025 from the government press release. No later government record was located.
The scope of national security powers to compel service providers to hand over identification records, assist with decryption or remove content
The government's national security legislation pages we tried returned not-found errors. This is listed as a dormant switch in the eighth answer rather than described as a rule.
Whether the Privacy Commissioner has published any investigation report or enforcement notice in 2026
The enforcement and investigation report index pages returned not-found errors. The enforcement rating relies on the doxxing statistics published to 31 December 2025, which are robust, rather than on 2026 activity.
The number of Greater Bay Area standard contract registrations filed by Hong Kong organisations
Neither the Privacy Commissioner nor the Digital Policy Office publishes a figure we could retrieve. The arrangement's existence and its extension to all Hong Kong sectors from 1 November 2024 are confirmed.
The exact dates the privacy ordinance was passed (given here as 3 August 1995) and commenced (given here as 20 December 1996), and the date the Protection of Critical Infrastructures (Computer Systems) Ordinance was passed
Hong Kong e-Legislation, the official consolidated statute source, blocks automated retrieval. The regulator confirms the law was enacted in 1995 and that the critical infrastructure ordinance took effect on 1 January 2026, but the precise passage and commencement dates were not read from an official text in this run.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Hong Kong SAR versus Argentina
- Hong Kong SAR versus Armenia
- Hong Kong SAR versus Australia
- Hong Kong SAR versus Austria
- Hong Kong SAR versus Azerbaijan
- Hong Kong SAR versus Brazil
- Hong Kong SAR versus Bulgaria
- Hong Kong SAR versus Cambodia
- Hong Kong SAR versus Canada
- Hong Kong SAR versus China
- Hong Kong SAR versus Croatia
- Hong Kong SAR versus Cyprus
- Hong Kong SAR versus Estonia
- Hong Kong SAR versus France
- Hong Kong SAR versus Georgia
- Hong Kong SAR versus Germany
- Hong Kong SAR versus Greece
- Hong Kong SAR versus Hungary
- Hong Kong SAR versus Iceland
- Hong Kong SAR versus India
- Hong Kong SAR versus Indonesia
- Hong Kong SAR versus Ireland
- Hong Kong SAR versus Israel
- Hong Kong SAR versus Italy
- Hong Kong SAR versus Japan
- Hong Kong SAR versus Latvia
- Hong Kong SAR versus Lithuania
- Hong Kong SAR versus Luxembourg
- Hong Kong SAR versus Malta
- Hong Kong SAR versus Mexico
- Hong Kong SAR versus Mongolia
- Hong Kong SAR versus Nepal
- Hong Kong SAR versus Netherlands
- Hong Kong SAR versus Poland
- Hong Kong SAR versus Russia
- Hong Kong SAR versus Saudi Arabia
- Hong Kong SAR versus Serbia
- Hong Kong SAR versus Singapore
- Hong Kong SAR versus Slovakia
- Hong Kong SAR versus Slovenia
- Hong Kong SAR versus South Korea
- Hong Kong SAR versus Spain
- Hong Kong SAR versus Sri Lanka
- Hong Kong SAR versus Sweden
- Hong Kong SAR versus Switzerland
- Hong Kong SAR versus Taiwan
- Hong Kong SAR versus Thailand
- Hong Kong SAR versus Turkey
- Hong Kong SAR versus Ukraine
- Hong Kong SAR versus United Arab Emirates
- Hong Kong SAR versus United Kingdom
- Hong Kong SAR versus United States
- Hong Kong SAR versus Uzbekistan