中文

Insight · Risk & Compliance

Getting ready for a PDPO data-handling review

A first review is less about technology than about producing a written record of what personal data you hold, why, and when it goes away.

21 September 2026Risk & Compliance6 min read
This article is general information about the Personal Data (Privacy) Ordinance (Cap. 486) and is not legal advice. The Ordinance and the guidance issued under it are the authoritative sources; where a specific decision matters, take professional advice.

Most Hong Kong organisations we meet do not have a data protection problem because they are careless. They have one because nobody has written down what personal data they hold, why they hold it, or when it goes away. A first review is less about technology than about producing that written record.

The Personal Data (Privacy) Ordinance (Cap. 486) is principle-based: the six Data Protection Principles sit in Schedule 1 and are supplemented by specific provisions elsewhere in the Ordinance. Reviewing against them in order gives you a structure that a regulator, an auditor or a client questionnaire can follow.

DPP1 — purpose and manner of collection

For each collection point — forms, emails, HR records, contracts, website enquiries — write down the lawful purpose the data serves, and satisfy yourself the data collected is necessary and adequate but not excessive for it. The practical test is subtraction: what breaks if this field is removed? The Ordinance also requires that individuals be told, at collection, whether giving the data is obligatory or voluntary, the purpose of use, the classes of persons to whom it may be transferred, and their right and means to request access and correction. If that notice exists only inside a 12-page policy nobody opens, it is not doing its job.

DPP2 — accuracy and retention

Produce a retention schedule with a named owner and a real trigger: "24 months after last contact", not "as long as necessary". This matters more than it looks, because separate from DPP2 there is section 26 of the Ordinance, which requires a data user to take all practicable steps to erase personal data that is no longer required for the purpose for which it is used, unless erasure is prohibited by law or is not in the public interest. Contravening section 26 is an offence, punishable by a fine of up to HK$10,000 — a small fine attached to a much larger habit of keeping everything indefinitely.

DPP3 — use, and the direct marketing rules

Check whether any data is used for a purpose unrelated to the one it was collected for. Where it is, the Ordinance requires the data subject's express and voluntary consent, and consent can be withdrawn by written notice.

Direct marketing carries its own regime and its own penalties: consent must be informed, silence cannot constitute consent, and the data user must give the prescribed information — the intention to use or provide the data for direct marketing, that it cannot do so without consent, the kinds of data, the classes of marketing subjects, the classes of recipients, and the right to opt out. Failing to comply is an offence punishable by a fine of HK$500,000 and imprisonment for 3 years, rising to HK$1,000,000 and 5 years where the data is provided to a third party for gain. This is the part of the Ordinance where we most often find inherited practices — a list bought years ago, a "partners" clause in a form — that nobody has revisited.

DPP4 — security, including your processors

Security is judged by whether all practicable steps were taken, having regard to the nature of the data and the harm that would follow a breach. Two practical points: access should be limited to people whose role requires it, and where you use a data processor, the Ordinance holds you — not them — responsible for ensuring by contractual or other means that they meet the applicable requirements. A processor agreement without security terms and an audit or assurance right does not discharge that.

DPP5 — openness

The Ordinance requires openness about your policies and practices, the kinds of personal data you hold and the main purposes for holding it. In practice: a current privacy policy statement, and a collection statement at the point of collection. Both should describe what you actually do, not what a template says.

DPP6 — access and correction

Confirm you can actually respond to a data access request and a data correction request, and that you know who handles them and how the timeframe works. Part 5 of the Ordinance deals with the manner and timeframe for compliance, the circumstances in which a request may be refused, and the requirement to keep a log book of refusals. An organisation that has never handled a request will find this hard to improvise on the day it receives one.

What the output should look like

A first review does not need to be a project. It needs to produce four things: a data inventory that says what is held, where and why; a retention schedule with owners; a gap list tied to each principle with a severity and an owner; and a one-page record of decisions made, so the next person does not have to reconstruct them. Everything after that — policies, training, monitoring — builds on those four.

Talk to us about a data handling review