Skip to content
TB
TeamBenchResources

PDPO Compliance: How to Review Privacy Documentation Under Hong Kong's Data Protection Law

Hong Kong's PDPO requires specific privacy documentation — from PICS to data breach response plans. Here's what to document, common PCPD findings, and how to review for compliance.

TeamBench· Content Quality PlatformFebruary 9, 20269 min read

The Personal Data (Privacy) Ordinance (Cap. 486) is Hong Kong's primary data protection legislation. With the Privacy Commissioner for Personal Data (PCPD) increasing enforcement activity — including direct criminal prosecution powers for doxxing offences and growing attention to cross-border data transfers — documentation requirements are tightening.

Unlike GDPR, the PDPO doesn't prescribe a specific list of mandatory documents. Instead, it establishes six Data Protection Principles (DPPs) that require organisations to demonstrate compliance through documentation. The challenge: determining what documentation is "sufficient" when the law doesn't provide a checklist.

The Six Data Protection Principles

DPPPrincipleDocumentation Implication
DPP1Purpose and manner of collectionPersonal Information Collection Statements (PICS) for every collection point
DPP2Accuracy and retentionRetention policies, data accuracy procedures
DPP3Use of personal dataConsent records, purpose limitation documentation
DPP4Security of personal dataSecurity policies, access controls, breach response plans
DPP5Information availabilityPrivacy Policy Statement (PPS), transparency documentation
DPP6Access and correctionData access request procedures, response records

Required Privacy Documentation

1. Personal Information Collection Statement (PICS)

Required under DPP1 at or before every point of personal data collection. The PICS is Hong Kong's equivalent of a privacy notice at the point of collection.

Must include:

  • Purpose of collection (specific, not vague)
  • Whether provision is obligatory or voluntary
  • Consequences of not providing the data
  • Classes of persons to whom data may be transferred
  • Right to access and correct data
  • Contact details for data access requests

Common failures:

  • Generic PICS used across all collection points instead of context-specific statements
  • Missing from specific collection channels (mobile apps, chatbots, event registrations)
  • Purposes described too broadly ("business operations") instead of specifically
  • Not provided at or before the time of collection

2. Privacy Policy Statement (PPS)

Required under DPP5. The organisation's general privacy policy, typically published on the website.

Should cover:

  • Types of personal data held
  • Main purposes for which data is used
  • Data retention policies
  • Data security practices
  • Rights of data subjects
  • Complaint procedures
  • Cross-border transfer practices

3. Data Retention Policy

DPP2(2) requires that personal data is not kept longer than necessary for the purpose for which it was collected.

ElementWhat to Document
Retention scheduleSpecific retention periods by data type and purpose
JustificationRationale for each retention period (legal requirement, business need)
Deletion proceduresHow data is securely deleted when retention period expires
Review mechanismHow retention periods are periodically reviewed

4. Data Security Documentation

DPP4 requires practical steps to protect personal data against unauthorised access, processing, erasure, loss, or use.

DocumentPurpose
Information security policyOverall security framework
Access control proceduresWho can access what data, and how access is managed
Data breach response planDetection, assessment, containment, notification, post-incident review
Encryption standardsHow data is protected in transit and at rest
Third-party security requirementsStandards for data processors and service providers
Incident registerRecord of all data security incidents

5. Cross-Border Transfer Documentation

Section 33 of the PDPO (not yet fully in force, but the PCPD has issued guidance recommending compliance) restricts transfers of personal data outside Hong Kong.

DocumentPurpose
Transfer impact assessmentAssessment of the jurisdiction's data protection adequacy
Contractual clausesData protection terms in agreements with overseas recipients
Consent recordsWhere consent is relied upon for cross-border transfers
Transfer registerRecord of cross-border transfers, recipients, and safeguards

6. Data Access Request (DAR) Procedures

DPP6 gives data subjects the right to access and correct their personal data. Organisations must respond within 40 days.

DocumentPurpose
DAR handling proceduresStep-by-step process for receiving, verifying, and responding to DARs
Response templatesStandard response formats for compliance and refusal
DAR registerLog of all requests received, response dates, and outcomes
Fee scheduleIf applicable — fees must not be excessive

Common PCPD Investigation Findings

Finding 1: Inadequate PICS

The most common compliance failure. PICS that are too generic, missing from specific collection channels, or not provided at the time of collection. The PCPD has consistently emphasised that PICS must be specific to the collection context.

Finding 2: Excessive Data Collection

Collecting more personal data than necessary for the stated purpose (DPP1(1)). Common in online forms that require fields not relevant to the service being provided.

Finding 3: Inadequate Security Measures

Data breaches resulting from insufficient security measures — weak access controls, unencrypted data, lack of monitoring. The PCPD assesses security adequacy based on the sensitivity of the data and the size/resources of the organisation.

Finding 4: Non-Compliance with Data Access Requests

Failure to respond within 40 days, excessive fees, or improper refusals. The PCPD views DAR non-compliance seriously as it directly affects individuals' rights.

Finding 5: Retention Beyond Necessity

Keeping personal data after the purpose for which it was collected has been fulfilled, without a documented justification. Organisations that "keep everything forever" are non-compliant with DPP2.

Reviewing PDPO Documentation

PICS Review Criteria

CriterionWeightWhat to Check
Coverage3PICS present at every personal data collection point
Specificity3Purposes are specific to the collection context, not generic
Completeness2All DPP1 required elements present
Timing2Provided at or before collection (not after)
Plain language1Written clearly for the intended audience

Privacy Policy Review Criteria

CriterionWeightWhat to Check
Completeness3All recommended elements present
Currency2Reflects current data practices, not historical
Accuracy2Statements about data handling match actual practices
Accessibility2Easy to find, clearly written, available in relevant languages
Consistency1Aligns with PICS and other privacy documentation

Data Breach Response Plan Review Criteria

CriterionWeightWhat to Check
Completeness3Covers detection, assessment, containment, notification, and review
Roles and responsibilities3Clear assignment of responsibilities for each stage
PCPD notification2Procedures for notifying the PCPD (voluntary but recommended)
Affected individual notification2Criteria and procedures for notifying affected data subjects
Testing evidence1Plan has been tested and results documented

Frequently Asked Questions

Is PDPO compliance mandatory for all Hong Kong organisations?

Yes. The PDPO applies to any data user (organisation or individual) that controls the collection, holding, processing, or use of personal data in Hong Kong. There are limited exemptions (e.g., domestic purposes, news activities) but the vast majority of organisations are covered.

How does the PDPO compare to GDPR?

The PDPO predates GDPR (enacted 1996, amended periodically). Key differences: PDPO doesn't have a formal lawful basis framework like GDPR's six bases, doesn't require Data Protection Officers, doesn't have mandatory data breach notification (though voluntary notification to the PCPD is strongly recommended), and Section 33 (cross-border transfer restrictions) is not yet fully in force. However, the PCPD's guidance increasingly aligns with international standards.

Do we need a Data Protection Officer under the PDPO?

The PDPO does not require a DPO. However, the PCPD recommends that organisations appoint a person responsible for data protection compliance. Larger organisations and those handling sensitive data typically appoint a privacy officer or equivalent role.

What are the penalties for PDPO non-compliance?

The PCPD can issue enforcement notices requiring compliance. Failure to comply with an enforcement notice is a criminal offence (fine up to HK$50,000 and imprisonment for 2 years). For doxxing offences, penalties are up to HK$1,000,000 and 5 years' imprisonment. The PCPD can also refer matters for prosecution.

Can AI review help with PDPO compliance documentation?

AI review can check PICS and privacy policies for completeness (all required elements present), specificity (purposes are detailed, not generic), consistency (PICS aligns with the PPS), plain language, and coverage (PICS present at identified collection points). Legal adequacy assessment requires qualified privacy professionals.

Key Takeaways

  • The PDPO establishes six Data Protection Principles — each creates documentation obligations even without a prescriptive document list.
  • PICS at every collection point is the most critical (and most commonly failed) requirement.
  • Specificity matters — generic purpose statements and boilerplate policies are common PCPD findings.
  • Data retention documentation must include specific periods with justification — "keep everything forever" is non-compliant.
  • Cross-border transfer documentation should be prepared even though Section 33 is not yet fully in force — the PCPD recommends compliance.
  • AI review checks completeness, specificity, consistency, and plain language — legal adequacy requires qualified professional review.
  • Review documentation annually and whenever data practices change significantly.

This article is for informational purposes only. The PDPO is subject to amendment and the PCPD's guidance evolves over time. Consult a qualified privacy professional or legal adviser for guidance specific to your organisation's data handling practices.

pdpo-compliancehong-kong-privacydata-protectionpdpo-documentationpcpdpersonal-data-privacy

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required