Data Protection in Hong Kong, SAR

Security in Hong Kong, SAR

Data users are required by the Ordinance to take all practical steps to ensure that personal data is protected against unauthorized or accidental access, processing, erasure, loss or use, having regard to factors including the nature of the personal data and the harm that could result if data breaches or leaks were to occur.

Where the data user engages a data processor to process personal data on its behalf, the data user must use contractual or other means to:

  • prevent unauthorized or accidental access, processing, erasure, or loss of use of the personal data; and
  • ensure that the data processor does not retain the personal data for longer than necessary.

The January 2020 Consultation Paper proposed to require organizations to formulate and publish a clear data retention policy specifying retention period(s) for personal data collected. The PCPD’s Report issued in February 2023 and the Panel Meeting Summary published in February 2024 also referred to this as an amendment direction.

Continue reading

  • no results

Previous topic
Back to top