PDPO Compliance: How to Review Privacy Documentation Under Hong Kong's Data Protection Law
Hong Kong's PDPO requires specific privacy documentation — from PICS to data breach response plans. Here's what to document, common PCPD findings, and how to review for compliance.
The Personal Data (Privacy) Ordinance (Cap. 486) is Hong Kong's primary data protection legislation. With the Privacy Commissioner for Personal Data (PCPD) increasing enforcement activity — including direct criminal prosecution powers for doxxing offences and growing attention to cross-border data transfers — documentation requirements are tightening.
Unlike GDPR, the PDPO doesn't prescribe a specific list of mandatory documents. Instead, it establishes six Data Protection Principles (DPPs) that require organisations to demonstrate compliance through documentation. The challenge: determining what documentation is "sufficient" when the law doesn't provide a checklist.
The Six Data Protection Principles
| DPP | Principle | Documentation Implication |
|---|---|---|
| DPP1 | Purpose and manner of collection | Personal Information Collection Statements (PICS) for every collection point |
| DPP2 | Accuracy and retention | Retention policies, data accuracy procedures |
| DPP3 | Use of personal data | Consent records, purpose limitation documentation |
| DPP4 | Security of personal data | Security policies, access controls, breach response plans |
| DPP5 | Information availability | Privacy Policy Statement (PPS), transparency documentation |
| DPP6 | Access and correction | Data access request procedures, response records |
Required Privacy Documentation
1. Personal Information Collection Statement (PICS)
Required under DPP1 at or before every point of personal data collection. The PICS is Hong Kong's equivalent of a privacy notice at the point of collection.
Must include:
- Purpose of collection (specific, not vague)
- Whether provision is obligatory or voluntary
- Consequences of not providing the data
- Classes of persons to whom data may be transferred
- Right to access and correct data
- Contact details for data access requests
Common failures:
- Generic PICS used across all collection points instead of context-specific statements
- Missing from specific collection channels (mobile apps, chatbots, event registrations)
- Purposes described too broadly ("business operations") instead of specifically
- Not provided at or before the time of collection
2. Privacy Policy Statement (PPS)
Required under DPP5. The organisation's general privacy policy, typically published on the website.
Should cover:
- Types of personal data held
- Main purposes for which data is used
- Data retention policies
- Data security practices
- Rights of data subjects
- Complaint procedures
- Cross-border transfer practices
3. Data Retention Policy
DPP2(2) requires that personal data is not kept longer than necessary for the purpose for which it was collected.
| Element | What to Document |
|---|---|
| Retention schedule | Specific retention periods by data type and purpose |
| Justification | Rationale for each retention period (legal requirement, business need) |
| Deletion procedures | How data is securely deleted when retention period expires |
| Review mechanism | How retention periods are periodically reviewed |
4. Data Security Documentation
DPP4 requires practical steps to protect personal data against unauthorised access, processing, erasure, loss, or use.
| Document | Purpose |
|---|---|
| Information security policy | Overall security framework |
| Access control procedures | Who can access what data, and how access is managed |
| Data breach response plan | Detection, assessment, containment, notification, post-incident review |
| Encryption standards | How data is protected in transit and at rest |
| Third-party security requirements | Standards for data processors and service providers |
| Incident register | Record of all data security incidents |
5. Cross-Border Transfer Documentation
Section 33 of the PDPO (not yet fully in force, but the PCPD has issued guidance recommending compliance) restricts transfers of personal data outside Hong Kong.
| Document | Purpose |
|---|---|
| Transfer impact assessment | Assessment of the jurisdiction's data protection adequacy |
| Contractual clauses | Data protection terms in agreements with overseas recipients |
| Consent records | Where consent is relied upon for cross-border transfers |
| Transfer register | Record of cross-border transfers, recipients, and safeguards |
6. Data Access Request (DAR) Procedures
DPP6 gives data subjects the right to access and correct their personal data. Organisations must respond within 40 days.
| Document | Purpose |
|---|---|
| DAR handling procedures | Step-by-step process for receiving, verifying, and responding to DARs |
| Response templates | Standard response formats for compliance and refusal |
| DAR register | Log of all requests received, response dates, and outcomes |
| Fee schedule | If applicable — fees must not be excessive |
Common PCPD Investigation Findings
Finding 1: Inadequate PICS
The most common compliance failure. PICS that are too generic, missing from specific collection channels, or not provided at the time of collection. The PCPD has consistently emphasised that PICS must be specific to the collection context.
Finding 2: Excessive Data Collection
Collecting more personal data than necessary for the stated purpose (DPP1(1)). Common in online forms that require fields not relevant to the service being provided.
Finding 3: Inadequate Security Measures
Data breaches resulting from insufficient security measures — weak access controls, unencrypted data, lack of monitoring. The PCPD assesses security adequacy based on the sensitivity of the data and the size/resources of the organisation.
Finding 4: Non-Compliance with Data Access Requests
Failure to respond within 40 days, excessive fees, or improper refusals. The PCPD views DAR non-compliance seriously as it directly affects individuals' rights.
Finding 5: Retention Beyond Necessity
Keeping personal data after the purpose for which it was collected has been fulfilled, without a documented justification. Organisations that "keep everything forever" are non-compliant with DPP2.
Reviewing PDPO Documentation
PICS Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Coverage | 3 | PICS present at every personal data collection point |
| Specificity | 3 | Purposes are specific to the collection context, not generic |
| Completeness | 2 | All DPP1 required elements present |
| Timing | 2 | Provided at or before collection (not after) |
| Plain language | 1 | Written clearly for the intended audience |
Privacy Policy Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | All recommended elements present |
| Currency | 2 | Reflects current data practices, not historical |
| Accuracy | 2 | Statements about data handling match actual practices |
| Accessibility | 2 | Easy to find, clearly written, available in relevant languages |
| Consistency | 1 | Aligns with PICS and other privacy documentation |
Data Breach Response Plan Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | Covers detection, assessment, containment, notification, and review |
| Roles and responsibilities | 3 | Clear assignment of responsibilities for each stage |
| PCPD notification | 2 | Procedures for notifying the PCPD (voluntary but recommended) |
| Affected individual notification | 2 | Criteria and procedures for notifying affected data subjects |
| Testing evidence | 1 | Plan has been tested and results documented |
Frequently Asked Questions
Is PDPO compliance mandatory for all Hong Kong organisations?
Yes. The PDPO applies to any data user (organisation or individual) that controls the collection, holding, processing, or use of personal data in Hong Kong. There are limited exemptions (e.g., domestic purposes, news activities) but the vast majority of organisations are covered.
How does the PDPO compare to GDPR?
The PDPO predates GDPR (enacted 1996, amended periodically). Key differences: PDPO doesn't have a formal lawful basis framework like GDPR's six bases, doesn't require Data Protection Officers, doesn't have mandatory data breach notification (though voluntary notification to the PCPD is strongly recommended), and Section 33 (cross-border transfer restrictions) is not yet fully in force. However, the PCPD's guidance increasingly aligns with international standards.
Do we need a Data Protection Officer under the PDPO?
The PDPO does not require a DPO. However, the PCPD recommends that organisations appoint a person responsible for data protection compliance. Larger organisations and those handling sensitive data typically appoint a privacy officer or equivalent role.
What are the penalties for PDPO non-compliance?
The PCPD can issue enforcement notices requiring compliance. Failure to comply with an enforcement notice is a criminal offence (fine up to HK$50,000 and imprisonment for 2 years). For doxxing offences, penalties are up to HK$1,000,000 and 5 years' imprisonment. The PCPD can also refer matters for prosecution.
Can AI review help with PDPO compliance documentation?
AI review can check PICS and privacy policies for completeness (all required elements present), specificity (purposes are detailed, not generic), consistency (PICS aligns with the PPS), plain language, and coverage (PICS present at identified collection points). Legal adequacy assessment requires qualified privacy professionals.
Key Takeaways
- The PDPO establishes six Data Protection Principles — each creates documentation obligations even without a prescriptive document list.
- PICS at every collection point is the most critical (and most commonly failed) requirement.
- Specificity matters — generic purpose statements and boilerplate policies are common PCPD findings.
- Data retention documentation must include specific periods with justification — "keep everything forever" is non-compliant.
- Cross-border transfer documentation should be prepared even though Section 33 is not yet fully in force — the PCPD recommends compliance.
- AI review checks completeness, specificity, consistency, and plain language — legal adequacy requires qualified professional review.
- Review documentation annually and whenever data practices change significantly.
This article is for informational purposes only. The PDPO is subject to amendment and the PCPD's guidance evolves over time. Consult a qualified privacy professional or legal adviser for guidance specific to your organisation's data handling practices.