Skip to the content
Global Data RulesData governance rules, country by country

Hong Kong SAR

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Hong Kong SAR — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

You can send personal data out of Hong Kong freely. The privacy law does contain a section banning transfers abroad. That section has never been brought into force. It was written in 1995 and still has no start date thirty years later. So under the general law you need no paperwork to send data out. The privacy regulator is busy and does prosecute people. But it cannot fine you directly.

Data governance in Hong Kong SAR

The eight things that decide how you handle data about people in Hong Kong SAR. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Hong Kong's privacy law can reach you even if you have no office there. It applies to whoever controls the collecting, holding or use of personal data in or from Hong Kong. So a foreign company running a Hong Kong-facing service is covered. There is no revenue or staff-count limit to fall below. There is no register to join. You do not need to appoint a local representative. The anti-doxxing powers go further. The regulator can order a platform based abroad to take material down.

Where the data is allowed to live

Yes. Under the general privacy law you can send data abroad freely, with nothing to sign. One section would have restricted transfers abroad. It was written into the law in 1995 and has never been brought into force. So today no law stops personal data leaving Hong Kong. The real limits come from industry rules, and there are fewer of them than people expect. The securities regulator is the main one. Government departments have their own restriction.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Nothing. There is no approval to seek before personal data leaves Hong Kong. There is no standard contract to sign and no government list to check. On paper the law would let you send data only to approved countries. But that section was never brought into force, so the list of approved countries has never been published. It is empty. The regulator does publish a voluntary guide and encourages firms to build safeguards now. That is advice, not law.

Ways to send data out:
Nothing required · Standard contract clauses

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Privacy Commissioner for Personal Data enforces the law, and it is busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms. Those orders covered 33,743 doxxing messages. It had opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk completely. The Commissioner cannot fine you for breaking the privacy principles. It serves a notice telling you to fix the problem. Only ignoring that notice is a crime.

What it costs if you get it wrong:
Criminal liability

How long you must keep it — and when to delete it

There is a maximum but almost no minimum. You must erase personal data once you no longer need it for the purpose you collected it for. Failing to do so is a crime. The fine is up to HK$10,000 (about 1,300 US dollars). The privacy law sets no minimum keeping periods. Those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins. You delete once that period runs out.

What you have to do here:
Delete data after a period · Keep records of how you use data

What to do: Set an automatic deletion job so data does not sit past its deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

For a normal data breach there is no deadline, because there is no duty to report. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong. The regulator asks you to do it as good practice and gives you a form. No law makes you. That is unusual, and it is changing. Since 1 January 2026 operators of named critical infrastructure must report computer-system security incidents. Those firms now have a real deadline. Everyone else has none.

What you have to do here:
Report breaches to the regulator · Report cyber incidents

What to do: Your breach process has to reach Hong Kong SAR's regulator inside the deadline above.

What catches people out

Five things catch people out. First, marketing mistakes are crimes here, not fines. Using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you. People assume the risk is low and miss the criminal side entirely. Third, Hong Kong sets no age at which a child can consent. So there is no simple number to build into a sign-up flow. Fourth, licensed securities firms need written permission before their records sit only on overseas servers. Two named people who live in Hong Kong must be able to unlock them. Fifth, the unused transfer section would also cover data moving between two foreign countries when a Hong Kong company controls it.

What it costs if you get it wrong:
Criminal liability
Not fully verified — see “What we're not sure about” below.

What's changing next

Nothing is due to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026. The government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. The government has held an unused power for thirty years. It can bring the cross-border transfer section into force with a simple notice. There is no consultation and no new vote.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Securities

Cloud and outsourcing rules

Official name: Circular to Licensed Corporations on the use of external electronic data storage · Securities and Futures Ordinance (Cap. 571) s.130; SFC circular of 31 October 2019 · Regulator directive

In forceYes, with paperwork

The real limit on sending data abroad in Hong Kong. A licensed securities or futures firm may put its records in a cloud abroad. But if it keeps no copies in Hong Kong, it needs written approval of the storage site. It also needs two named people who live in Hong Kong and can hand the regulator the keys on demand. This is about access and staff, not about where data must sit. It shapes your systems the same way.

In force since 1 January 2020

Enforced by Securities and Futures Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Banking

Cloud and outsourcing rules (Banking)

Official name: Supervisory Policy Manual module SA-2 'Outsourcing' · HKMA Supervisory Policy Manual, SA-2 · Regulator guideline

In forceYes, with paperwork

We found no rule that banking data must stay in Hong Kong, checked 18 August 2026. Banks may use cloud services and suppliers abroad. The bank regulator supervises outsourcing and technology risk. Its focus is on keeping its own access to records, not on where the servers sit. Confidence is low because the regulator's website blocked our access.

Enforced by Hong Kong Monetary Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Breach reporting rules (2026)

Official name: Protection of Critical Infrastructures (Computer Systems) Ordinance · Act of parliament

In forceYes — store it anywhere

Hong Kong's newest security law, in effect since 1 January 2026. It applies only to operators named as running critical infrastructure. We found no requirement that their computer systems or data be in Hong Kong. We could not check the exact incident reporting deadlines against a government source, so they are flagged as uncertain.

In force since 1 January 2026

Enforced by Security Bureau and the Commissioner's Office for critical infrastructure computer-system security

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Breach reporting rules

Official name: Personal Data (Privacy) Ordinance · Cap. 486 · Act of parliament

Partly in forceYes — store it anywhere

Hong Kong's general privacy law, in force since 1996. It applies to private companies and the public sector alike. There is little paperwork: no registration, no data protection officer, no compulsory breach reporting and no transfer approvals. But enforcement is criminal rather than by fines. It is marked partly in force because its cross-border transfer section has never started.

In force since 20 December 1996

Enforced by Office of the Privacy Commissioner for Personal Data

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Rules for sending data abroad

Official name: Personal Data (Privacy) Ordinance, section 33 - prohibition against transfer of personal data to place outside Hong Kong except in specified circumstances · Cap. 486 s.33 · Act of parliament

Passed, not yet fully in forceYes, with paperwork

A full set of cross-border transfer rules, written in 1995. It sits in the law and has never been brought into force. Nothing in it binds anyone today. A quick read of the ordinance makes Hong Kong look restricted, and it is not. The government can bring the rules into force by notice at any time. On that day, the list of approved destinations would be empty.

Enforced by Office of the Privacy Commissioner for Personal Data

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Standard contract clauses

General data protection law

Official name: Personal Data (Privacy) (Amendment) Ordinance 2021 - anti-doxxing provisions · Cap. 486 ss.64, 66D-66K · Act of parliament

In forceYes — store it anywhere

Hong Kong's most used data power. The Privacy Commissioner can order any service provider, in Hong Kong or abroad, to remove doxxing content. It can also investigate and arrest. It had issued over two thousand such orders by the end of 2025. This is why we rate Hong Kong's enforcement active, even though it cannot fine you.

In force since 8 October 2021

Enforced by Office of the Privacy Commissioner for Personal Data

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies only if you signed a contract1 rule

Usually a government or enterprise contract that adds rules of its own.

Government

Cloud and outsourcing rules (Government)

Official name: IT Security Standards and Best Practices, and the Practice Guide on Data Centre Security, applied to bureaux and departments · Government policy document

In forceYes, with paperwork

Government departments are told to keep sensitive and personal information off public cloud platforms. They must encrypt data at rest and in transit and run regular audits. This is internal policy, not a law. It reaches suppliers through their contracts. It is the closest Hong Kong gets to a rule that public-sector data must stay in the country.

In force since 1 February 2024

Enforced by Digital Policy Office

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • 個人資料私隱專員公署

    The Personal Data (Privacy) Ordinance across the private and public sectors, including doxxing and direct marketing

    Fully staffed and visibly active. As at 31 December 2025 it had issued 2,104 takedown notices to 57 online platforms. Those covered 33,743 doxxing messages. It had started 519 criminal investigations and arrested 81 people. It cannot fine you. It serves notices to fix problems, then prosecutes.

  • 證券及期貨事務監察委員會

    Licensed corporations, securities and futures markets, record keeping and external data storage

    Active. Approves storage sites under the Securities and Futures Ordinance and disciplines licensed firms.

  • 香港金融管理局

    Banks and stored value payment facilities, outsourcing and technology risk

    Active supervisor.

  • 保險業監管局

    Insurers and insurance intermediaries

    Active. Its guidelines pages refused us access on 18 August 2026, so we state no insurance rule here.

  • 數字政策辦公室

    Government data governance, information technology security standards, cross-boundary data flow facilitation

    Up and running. It replaced the Office of the Government Chief Information Officer. It publishes the data governance principles and the government's security standards.

  • 保安局

    Protection of Critical Infrastructures (Computer Systems) Ordinance

    The ordinance took effect on 1 January 2026 and the supervising office started work with it. We could not open the office's own website, so its published procedures are unverified.

  • 政制及內地事務局

    Policy responsibility for the privacy ordinance and its amendment

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact incident reporting deadlines under the Protection of Critical Infrastructures (Computer Systems) Ordinance, widely reported as 12 hours for serious incidents and 48 hours otherwise

    We could not confirm these deadlines against the text of the law. Hong Kong's official legislation website blocks automated access. If you run critical infrastructure, ask the Commissioner's office for the exact deadlines before you rely on them.

  • Whether that ordinance requires a designated operator to keep a computer-system security management unit, or its computer systems, physically in Hong Kong

    We found no requirement that systems stay in Hong Kong, but we could not read the text of the law. If you run critical infrastructure, check this before you rely on it.

  • The Hong Kong Monetary Authority's outsourcing and cloud requirements for banks, including whether customer data may be processed offshore and on what conditions

    We could not reach the Hong Kong Monetary Authority's website, including its Supervisory Policy Manual. So we state no rule that banking data must stay in Hong Kong. If you are a bank, confirm the outsourcing and cloud rules with the regulator.

  • Whether the Insurance Authority imposes any data storage, outsourcing or localisation requirement on insurers

    The Insurance Authority's guidelines pages refused us access. We record no insurance rule, which does not mean none exists. If you are an insurer, check with the regulator.

  • Minimum retention floors in Hong Kong tax, company and anti-money-laundering law, commonly described as seven years for business and accounting records and five years for customer due diligence records

    We could not confirm these minimum keeping periods against a government source, so the retention answer states no figure. Check the tax, company and anti-money-laundering rules that apply to you.

  • Whether any minimum age applies to a child's consent under the privacy ordinance

    We found no minimum age in the regulator's published material, checked 18 August 2026. We could not read the law itself to be sure. Do not assume a set age applies.

  • Whether the Electronic Health Record Sharing System (Amendment) Bill 2025 has been passed and commenced

    We confirmed the bill was published in the gazette on 21 March 2025 and had its first reading on 26 March 2025. We could not confirm what happened after that. Check the current status before you rely on it.

  • The scope of national security powers to compel service providers to hand over identification records, assist with decryption or remove content

    We could not open the government's national security legislation pages. This is listed as an unused power in the eighth answer rather than described as a rule.

  • Whether the Privacy Commissioner has published any investigation report or enforcement notice in 2026

    We could not open the enforcement and investigation report pages. Our enforcement rating uses the doxxing figures published to 31 December 2025, which are solid. It does not rely on 2026 activity.

  • The number of Greater Bay Area standard contract registrations filed by Hong Kong organisations

    Neither the Privacy Commissioner nor the Digital Policy Office publishes a number we could retrieve. The arrangement does exist, and its extension to every Hong Kong industry from 1 November 2024 is confirmed.

  • The exact dates the privacy ordinance was passed (given here as 3 August 1995) and commenced (given here as 20 December 1996), and the date the Protection of Critical Infrastructures (Computer Systems) Ordinance was passed

    Hong Kong's official consolidated law website blocks automated access. The regulator confirms the law was enacted in 1995. It confirms the critical infrastructure ordinance took effect on 1 January 2026. We did not read the exact passing and start dates from an official text.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.