Skip to the content
Global Data RulesData governance rules, country by country

Hong Kong SAR

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Hong Kong's privacy law contains a cross-border transfer ban that has never been switched on. It was written in 1995 and, thirty years later, still has no start date. So under the general law you can send personal data anywhere with no paperwork at all. The privacy regulator is busy and prosecutes people, but it cannot fine you directly.

Eight questions about Hong Kong SAR

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Hong Kong SAR's rules apply to my company?

Yes, it can reach you with no office in Hong Kong. The privacy law bites on whoever controls the collection, holding, use or processing of personal data in or from Hong Kong, so a foreign company running a Hong Kong-facing service is caught. There is no revenue or headcount threshold to fall below, no register to join, and no requirement to appoint a local representative. The anti-doxxing powers go further still: the regulator can order an overseas platform to take material down.

High confidenceNational rulesController

Can I store my users' data outside Hong Kong SAR?

Under the general privacy law, yes - freely, with nothing to sign. The one section that would have restricted transfers abroad was written into the law in 1995 and has never been brought into operation, so today there is no legal control on personal data leaving Hong Kong. Industry rules are where the real limits sit, and there are fewer of them than people expect: the securities regulator is the main one, and government departments have their own restriction.

High confidenceDepends on your industryNo restriction

What do I need in place before data leaves Hong Kong SAR?

Nothing. There is no approval to seek, no standard contract to sign and no government list to check before personal data leaves Hong Kong. The model on paper is an allowlist - the regulator would publish a list of approved destinations - but because the section was never switched on, that list has never been issued and is empty. The regulator does publish a voluntary guide and encourages firms to build the safeguards now, but that is advice, not law.

High confidenceNothing requiredNo restrictionStandard contract clauses

Who enforces the rules in Hong Kong SAR, and what can they do?

The Privacy Commissioner for Personal Data, and it is genuinely busy. By the end of December 2025 it had issued 2,104 orders to 57 online platforms to take down 33,743 doxxing messages, opened 519 criminal investigations and arrested 81 people. But there is a catch that changes the risk picture completely: the Commissioner cannot impose a fine for breaking the privacy principles. It serves a notice telling you to fix the problem, and only ignoring that notice is a crime.

High confidenceActiveCriminal liability

How long do I have to keep the data?

There is a hard ceiling and almost no floor in the privacy law itself. You must erase personal data once it is no longer needed for the purpose you collected it for, and failing to do so is a criminal offence carrying a fine of up to HK$10,000 (about $1,300). The privacy law sets no minimum keeping periods; those come from tax, company and anti-money-laundering law instead. Where the two pull against each other, the specific keeping duty in the other law wins, and you delete once it expires.

Medium confidenceDelete data after a periodKeep records of processing

What happens if there is a breach?

For a normal data breach there is no deadline, because there is no duty. Telling the Privacy Commissioner about a breach is voluntary in Hong Kong - the regulator asks you to do it as good practice and gives you a form, but no law compels it. That is unusual and it is changing: since 1 January 2026 operators of designated critical infrastructure must report computer-system security incidents, so those firms now have a real clock while everyone else has none.

High confidenceReport breaches to the regulatorReport cyber incidents

What trips people up in Hong Kong SAR?

Five things that catch people out. First, marketing mistakes are crimes here, not fines - using someone's data for direct marketing without the right consent can mean five years in prison. Second, the regulator cannot fine you, so people assume the risk is low and miss the criminal exposure entirely. Third, Hong Kong sets no age at which a child can consent, so there is no simple number to code into a sign-up flow. Fourth, licensed securities firms need written permission before their records live only on overseas servers, and two named people who live in Hong Kong must be able to unlock them. Fifth, the dormant transfer section, if ever switched on, would also catch data moving between two foreign countries when a Hong Kong company controls it.

Medium confidenceCriminal liabilityAppoint a local representativeRegister or notify

What is changing soon in Hong Kong SAR?

Nothing is scheduled to land in the next twelve months that we could confirm. The critical infrastructure security law already started on 1 January 2026, and the government's guideline for generative artificial intelligence was revised in December 2025. The thing to watch is not a new bill. It is a switch the government has held for thirty years: the cross-border transfer section can be brought into force by a simple commencement notice, with no consultation and no new vote.

Medium confidencePassed, not yet fully in forceIn force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    3 rules here

  3. Layer 3

    Contract-imposed rule

    Binds you because you signed something, typically a government contract.

    1 rule here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules5 rules

Personal Data (Privacy) Ordinance

Act of parliament · Cap. 486

Partly in forceYes — store it anywhere

Hong Kong's general privacy law, in force since 1996 and applying to the private and public sectors alike. It is light on paperwork - no registration, no data protection officer, no mandatory breach reporting and no transfer approvals - but the enforcement route is criminal rather than administrative. It is marked partly in force because its cross-border transfer section has never been commenced.

In force since 20 December 1996

Enforced by Office of the Privacy Commissioner for Personal Data

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Personal Data (Privacy) Ordinance, section 33 - prohibition against transfer of personal data to place outside Hong Kong except in specified circumstances

Act of parliament · Cap. 486 s.33

Passed, not yet fully in forceYes, with paperwork

The single most misread provision in Hong Kong law. A full cross-border transfer regime, drafted in 1995, sitting on the statute book and never brought into operation. A naive reading of the ordinance reports Hong Kong as a restricted jurisdiction; in reality nothing here binds anyone today. It can be commenced by notice at any time, and on that day the allowlist would be empty.

Enforced by Office of the Privacy Commissioner for Personal Data

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Explicit consent, Standard contract clauses

High confidence

Personal Data (Privacy) (Amendment) Ordinance 2021 - anti-doxxing provisions

Act of parliament · Cap. 486 ss.64, 66D-66K

In forceYes — store it anywhere

Hong Kong's most actively used data power. The Privacy Commissioner can order any service provider, in Hong Kong or abroad, to remove doxxing content, and can investigate and arrest. Over two thousand such orders had been issued by the end of 2025. This is what makes Hong Kong's enforcement rating active despite the absence of administrative fines.

In force since 8 October 2021

Enforced by Office of the Privacy Commissioner for Personal Data

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules3 rules

Circular to Licensed Corporations on the use of external electronic data storage

Regulator directive · Securities and Futures Ordinance (Cap. 571) s.130; SFC circular of 31 October 2019 · Securities

In forceYes, with paperwork

The real cross-border wall in Hong Kong. A licensed securities or futures firm may put its records in an overseas cloud, but if Hong Kong copies are not kept it needs written approval of the storage premises, plus two named people living in Hong Kong who can hand the regulator the keys on demand. It is an access-and-personnel rule rather than a data residency rule, but it has the same effect on architecture.

In force since 1 January 2020

Enforced by Securities and Futures Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Supervisory Policy Manual module SA-2 'Outsourcing'

Regulator guideline · HKMA Supervisory Policy Manual, SA-2 · Banking

In forceYes, with paperwork

No banking data localisation rule was found for Hong Kong, checked 18 August 2026. Banks may use overseas cloud and overseas processors, subject to the bank regulator's outsourcing and technology risk supervision, which centres on the regulator retaining access to records rather than on where the servers sit. Confidence is low because the regulator's website blocked automated retrieval throughout this run.

Enforced by Hong Kong Monetary Authority

Transfer model: No restriction · Accepted routes: Nothing required

Low confidence

Protection of Critical Infrastructures (Computer Systems) Ordinance

Act of parliament

In forceYes — store it anywhere

Hong Kong's newest security law, in effect since 1 January 2026, applying only to operators designated as running critical infrastructure. We found no requirement that their computer systems or data be located in Hong Kong. The exact incident reporting clocks could not be verified from a government source and are flagged as uncertain.

In force since 1 January 2026

Enforced by Security Bureau and the Commissioner's Office for critical infrastructure computer-system security

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

Contract-imposed rule1 rule

IT Security Standards and Best Practices, and the Practice Guide on Data Centre Security, applied to bureaux and departments

Government policy document · Government

In forceYes, with paperwork

Government departments are told to keep sensitive and personal information off public cloud platforms, encrypt data at rest and in transit, and run regular audits. This is an internal policy binding through procurement rather than a statute, so it reaches suppliers through their contracts. It is the closest thing Hong Kong has to a public-sector residency rule.

In force since 1 February 2024

Enforced by Digital Policy Office

Transfer model: Approval each time · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • 個人資料私隱專員公署

    The Personal Data (Privacy) Ordinance across the private and public sectors, including doxxing and direct marketing

    Fully staffed and visibly active. As at 31 December 2025 it had issued 2,104 cessation notices to 57 online platforms covering 33,743 doxxing messages, started 519 criminal investigations and arrested 81 people. Its structural limit is that it cannot impose administrative fines: it serves enforcement notices and prosecutes.

  • 證券及期貨事務監察委員會

    Licensed corporations, securities and futures markets, record keeping and external data storage

    Active. Approves storage premises under the Securities and Futures Ordinance and disciplines licensed corporations.

  • 香港金融管理局

    Banks and stored value payment facilities, outsourcing and technology risk

    Active supervisor. Its website blocked automated retrieval throughout this run, so its outsourcing and cloud requirements are recorded at low confidence.

  • 保險業監管局

    Insurers and insurance intermediaries

    Active. Its guidelines pages returned an access-denied response to automated retrieval on 18 August 2026, so no insurance rule is asserted here.

  • 數字政策辦公室

    Government data governance, information technology security standards, cross-boundary data flow facilitation

    Operational. Successor to the Office of the Government Chief Information Officer; publishes the data governance principles and the government's security standards.

  • 保安局

    Protection of Critical Infrastructures (Computer Systems) Ordinance

    The ordinance took effect on 1 January 2026 and the supervising office began operating with it. We could not open the office's own website during this run, so its published procedures are unverified.

  • 政制及內地事務局

    Policy responsibility for the privacy ordinance and its amendment

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact incident reporting deadlines under the Protection of Critical Infrastructures (Computer Systems) Ordinance, widely reported as 12 hours for serious incidents and 48 hours otherwise

    Hong Kong e-Legislation blocks automated retrieval through its robots file, and the Commissioner's office website could not be located or opened on 18 August 2026. We verified only that the ordinance took effect on 1 January 2026, from the Privacy Commissioner's own seminar page.

  • Whether that ordinance requires a designated operator to keep a computer-system security management unit, or its computer systems, physically in Hong Kong

    Same reason. No localisation requirement was found, but absence of evidence here is weak evidence of absence because we could not read the statute.

  • The Hong Kong Monetary Authority's outsourcing and cloud requirements for banks, including whether customer data may be processed offshore and on what conditions

    Every attempt to fetch hkma.gov.hk returned an empty document, including the Supervisory Policy Manual PDF. The rule is recorded at low confidence with the government link marked unreachable, and no localisation claim is asserted.

  • Whether the Insurance Authority imposes any data storage, outsourcing or localisation requirement on insurers

    The Insurance Authority's guidelines pages returned an access-denied response to automated retrieval. No insurance sector rule is recorded, which should not be read as confirmation that none exists.

  • Minimum retention floors in Hong Kong tax, company and anti-money-laundering law, commonly described as seven years for business and accounting records and five years for customer due diligence records

    The Inland Revenue Department and Companies Registry pages we tried returned not-found errors on 18 August 2026, so no figure is asserted in the retention answer.

  • Whether any minimum age applies to a child's consent under the privacy ordinance

    No age threshold was found in the regulator's published material, checked 18 August 2026. We could not read the statute directly to prove the negative.

  • Whether the Electronic Health Record Sharing System (Amendment) Bill 2025 has been passed and commenced

    We verified only its gazettal on 21 March 2025 and first reading on 26 March 2025 from the government press release. No later government record was located.

  • The scope of national security powers to compel service providers to hand over identification records, assist with decryption or remove content

    The government's national security legislation pages we tried returned not-found errors. This is listed as a dormant switch in the eighth answer rather than described as a rule.

  • Whether the Privacy Commissioner has published any investigation report or enforcement notice in 2026

    The enforcement and investigation report index pages returned not-found errors. The enforcement rating relies on the doxxing statistics published to 31 December 2025, which are robust, rather than on 2026 activity.

  • The number of Greater Bay Area standard contract registrations filed by Hong Kong organisations

    Neither the Privacy Commissioner nor the Digital Policy Office publishes a figure we could retrieve. The arrangement's existence and its extension to all Hong Kong sectors from 1 November 2024 are confirmed.

  • The exact dates the privacy ordinance was passed (given here as 3 August 1995) and commenced (given here as 20 December 1996), and the date the Protection of Critical Infrastructures (Computer Systems) Ordinance was passed

    Hong Kong e-Legislation, the official consolidated statute source, blocks automated retrieval. The regulator confirms the law was enacted in 1995 and that the critical infrastructure ordinance took effect on 1 January 2026, but the precise passage and commencement dates were not read from an official text in this run.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.