Data Privacy in Hong Kong: What Businesses Must Do Under PDPO in 2026
Every business that handles personal data in Hong Kong must comply with the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles. A common myth is that you must report a data breach to the Privacy Commissioner within a fixed deadline. In fact, PDPO Hong Kong 2026 still imposes no mandatory breach-notification deadline (notification is voluntary but recommended, and reform is under discussion). Direct marketing has strict consent rules, doxxing is a criminal offence, and using personal data to build or run AI systems must still satisfy every Data Protection Principle.
Introduction
If your business collects a customer's name, a job applicant's CV, an employee's HKID or a user's behavioural data, you are a "data user" under Hong Kong law, and the rules apply to you whatever your size. This guide sets out, in plain English, what data privacy law HK businesses must do in 2026: the structure of the Personal Data (Privacy) Ordinance (Cap. 486) (the PDPO), the six principles at its heart, the truth about what happens when businesses suffer a data breach, and a practical compliance checklist. It also tackles the question no competitor has answered clearly: how personal data protection HK obligations apply when you feed data into AI tools.
PDPO overview
The PDPO is enforced by the Privacy Commissioner for Personal Data (PCPD), an independent regulator with investigation, enforcement and (for doxxing) prosecution powers. Its core mechanism is simple: under section 4, a data user must not do an act that contravenes a Data Protection Principle (DPP) unless the Ordinance otherwise permits it.
Key concepts:
● Personal data is information relating to a living individual from which it is practicable to identify them.
● Data user is the person who controls the collection, holding, processing or use of the data, which is usually your business.
● Data processor is a third party (such as a cloud or payroll vendor) that handles data on your behalf. You remain responsible for what they do with it.
Two enforcement features matter especially for companies. Direct marketing is tightly regulated (Part VIA of the PDPO): you must notify individuals and obtain their consent before using their personal data to market to them, and breaches are criminal offences carrying heavy fines. And since the Personal Data (Privacy) (Amendment) Ordinance 2021, doxxing, meaning the disclosure of someone's personal data without consent with intent to cause harm, is a specific criminal offence, with the PCPD empowered to investigate and issue cessation notices.
The six Data Protection Principles
The six DPPs are set out in Schedule 1 to the PDPO:
1. DPP1 (collection). Collect personal data only for a lawful purpose directly related to your function or activity, take no more than is necessary, and collect it by fair and lawful means. Tell people, at or before collection, the purpose and to whom the data may be transferred (typically via a Personal Information Collection Statement, or PICS).
2. DPP2 (accuracy and retention). Keep data accurate and do not keep it longer than is necessary for the purpose.
3. DPP3 (use). Use personal data only for the purpose it was collected for, or a directly related purpose. Anything else needs the individual's fresh, voluntary consent.
4. DPP4 (security). Take practicable steps to protect data against unauthorised or accidental access, loss or use.
5. DPP5 (openness). Be transparent about your policies and practices on personal data (your privacy policy).
6. DPP6 (access and correction). Let individuals access and correct their own data, subject to limited exceptions.
The PDPO also contains exemptions (for example for certain employment, news, and crime-prevention purposes) and limits on transferring data outside Hong Kong. Note that section 33, which would restrict cross-border transfers, has been enacted but is not yet in force. The PCPD has nonetheless issued recommended model contractual clauses, and well-run businesses build cross-border safeguards into their vendor contracts now.
AI and data: the new compliance frontier
Generative AI and analytics tools are where Hong Kong businesses most often stumble, because the PDPO applies to AI just as it applies to a spreadsheet. There is simply no AI carve-out.
● Training and input data (DPP1, DPP3). Feeding customer records, CVs or chat logs into an AI model is a use of personal data. If the original purpose did not cover AI processing, you likely need fresh consent, and you should minimise the data you expose.
● "Anonymised" data may not be anonymous (DPP1, DPP4). If individuals can be re-identified from supposedly anonymised datasets, a real risk with rich AI models, the data is still personal data and remains regulated. De-anonymisation is a growing enforcement concern.
● Accuracy and automated decisions (DPP2). AI outputs can be wrong or biased; using inaccurate personal data, or making consequential decisions on it, creates both legal and reputational risk.
● Vendors and cross-border processing (DPP4). Many AI tools process data on overseas servers, so you must impose contractual safeguards on processors and understand where data flows.
The PCPD has published practical guidance, including an AI Model Personal Data Protection Framework and guidance on the ethical development and use of AI, which together set out governance expectations such as board-level oversight, risk assessment, and human review. Aligning your AI use with that framework is the clearest way to show compliance.
A short worked example shows the risk. Suppose a retailer uploads years of customer purchase histories into a third-party generative-AI tool to "find sales patterns". Three problems can arise at once: the data was collected to fulfil orders, not to train an external model (a DPP3 use issue needing fresh consent); the records sit on overseas servers the retailer has not vetted (a DPP4 security and cross-border issue); and the "anonymised" dataset may still allow individuals to be re-identified from unusual purchase combinations (a DPP1 issue). The fix is not to abandon AI, but to minimise the personal data exposed, obtain the right consents, contract properly with the vendor, and document the decision. Treat every AI project that touches personal data as a privacy project from day one.
Breach notification: the truth
Here is the correction every business should note: Hong Kong does not currently impose a mandatory data-breach notification duty or a fixed deadline under the PDPO. If you suffer a breach, notifying the PCPD and affected individuals is voluntary but strongly recommended, and the PCPD publishes guidance on doing so promptly. Reform to introduce mandatory notification (and other tightening of the PDPO) has been the subject of active discussion, so this is an area to watch. But in 2026 the position is voluntary notification, good incident response, and prompt remedial action, not a statutory countdown. Do not assume an overseas "72-hour" rule applies here; equally, do not treat a breach casually, as poor handling can itself breach DPP4.
In practice, a sensible breach response looks the same whether or not notification is compulsory: contain the incident, assess what data and how many people are affected, notify the PCPD and affected individuals where there is a real risk of harm, and remediate so it cannot recur. Keep a written record of what happened and what you did. If the regulator does ask questions later, a calm, documented response is your best protection, and it positions you well if mandatory notification is introduced.
Compliance checklist
● Map what personal data you hold, why, and where it flows.
● Publish a clear privacy policy (DPP5) and issue a PICS at each collection point (DPP1).
● Obtain consent before any direct marketing use, and honour opt-outs.
● Minimise collection and set retention limits; delete or anonymise data you no longer need (DPP2).
● Lock down security, including access controls, encryption and vendor due diligence (DPP4).
● Put data-processor agreements in place with cloud, payroll and AI vendors.
● Build cross-border transfer safeguards into contracts (anticipating section 33).
● Adopt an AI governance policy aligned to the PCPD's model framework.
● Prepare a breach response plan (even though notification is voluntary).
● Train staff and review annually.
FAQ
1. Does the PDPO apply to small businesses?
Yes. It applies to any data user, regardless of size, that controls personal data in Hong Kong.
2. Must I report a data breach within a set time?
No. There is currently no mandatory deadline. Notification to the PCPD and affected people is voluntary but recommended, and reform is being discussed.
3. Can I use customer data to train an AI tool?
Only if it is compatible with the purpose you collected it for, or you obtain fresh consent, and you must keep it secure and minimise exposure.
4. What are the penalties for misusing data in direct marketing?
Direct-marketing offences under the PDPO carry substantial fines and possible imprisonment, with higher penalties for providing data to others for gain.
5. Is doxxing illegal in Hong Kong?
Yes. Since the Personal Data (Privacy) (Amendment) Ordinance 2021, doxxing is a specific criminal offence, and the PCPD can investigate and order the removal of doxxing content.
6. What rights do individuals have over their data?
Under DPP6, individuals can ask to access and correct the personal data you hold about them. You must respond within the time the PDPO allows and can only refuse on limited grounds.
7. Are we responsible for what our cloud or AI vendor does with the data?
Largely yes. As the data user you remain accountable, so you must use contracts and oversight to ensure any data processor protects the data and uses it only as instructed.
When to contact a solicitor
Get advice before launching an AI or analytics project involving personal data, after any significant security incident, when transferring data overseas at scale, or if the PCPD contacts you. Early legal input is far cheaper than an enforcement action or a class of unhappy customers.
Talk to ask.legal Hong Kong
Need a PDPO health-check or an AI data-governance review? Contact ask.legal Hong Kong to be matched with a qualified Hong Kong data-protection solicitor and get compliant before it becomes a problem.
Sources and further reading
● Personal Data (Privacy) Ordinance (Cap. 486), including Schedule 1 (the six DPPs) and Part VIA (direct marketing); Personal Data (Privacy) (Amendment) Ordinance 2021 (doxxing).
● Office of the Privacy Commissioner for Personal Data (PCPD), guidance and media statements: https://www.pcpd.org.hk/english/news_events/media_statements/press_20260519.html
About the author: prepared by the ask.legal Hong Kong editorial team.
Last updated: June 2026.
This article is general information about the law of Hong Kong as at 2026, not legal advice. For advice on your circumstances, consult a qualified Hong Kong legal practitioner.