Data Protection in Hong Kong, SAR

Data protection laws in Hong Kong, SAR

The Personal Data (Privacy) Ordinance (Cap. 486) (Ordinance) regulates the collection and handling of personal data. The Ordinance has been in force since 1996, but in 2012/2013 was significantly amended (notably with regard to direct marketing). The Personal Data (Privacy) (Amendment) Ordinance (Amendment Ordinance) came into force in October 2021 and introduced new offences of doxxing and corresponding penalties.

At Bill stage, the Amendment Ordinance had originally included a number of other proposed amendments to the Ordinance (as per the January 2020 Consultation Paper), e.g. introducing a mandatory data breach notification mechanism, requiring data users to formulate a data retention policy, empowering the Office of the Privacy Commissioner for Personal Data (PCPD) to impose administrative fines linked to annual turnover and regulating data processors directly (Proposed Amendments). According to its report to the Legislative Council in February 2023 (PCPD’s Report), the PCPD is studying the Proposed Amendments with the Government to strengthen personal data protection and to address challenges including those posed by internet technology developments. The summary of the Panel on Constitutional Affairs Meeting held in February 2024 (Panel Meeting Summary) further reinforced that the PCPD has plans to implement the Proposed Amendments and is in the process of formulating a concrete proposal, but media reports in Autumn 2024 suggested that some or all of the Proposed Amendments have been put on hold.

In addition, the Government released the Protection of Critical Infrastructures (Computer Systems) Bill in December 2024 (Bill). The Bill aims to protect critical infrastructure (CI), which include (inter alia) infrastructure which substantially affects the maintenance of critical societal or economic activities in Hong Kong in the event of a data breach. Under the Bill, CI operators would be required (inter alia) to implement a cybersecurity management plan and conducting security risk assessments. The Bill is currently passing through the Legislative Counsel.

Continue reading

  • no results

Back to top