Navigating PDPO Compliance: Practical Steps for Hong Kong SMEs
Hong Kong's Personal Data (Privacy) Ordinance applies to all businesses, not just large corporations. This guide breaks down the six core data protection principles and gives SMEs a practical, compliance-focused action plan grounded in the law and PCPD guidance.
In this article
Navigating PDPO Compliance: Practical Steps for Hong Kong SMEs
Hong Kong's Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") applies to every organisation that collects, holds, processing or uses personal data — regardless of size. For SMEs, the risk is not theoretical: the Privacy Commissioner for Personal Data (PCPD) can issue enforcement notices, and non-compliance can result in fines and reputational damage. This post sets out the practical steps your business should take, mapped directly to the six Data Protection Principles (DPPs) in the Ordinance.
The Six Data Protection Principles: Your Compliance Backbone
The PDPO is built on six Data Protection Principles (DPPs) contained in Schedule 1 of the Ordinance. These are not abstract ideals; they are legally binding obligations. If your SME collects a customer's name and email address, you are already subject to them.
The six principles cover: (1) purpose and manner of collection, (2) accuracy and retention, (3) use of personal data, (4) security of personal data, (5) openness and transparency, and (6) data access and correction. Each one translates into a concrete operational step. Below, we walk through each principle and give you the specific action to take.
DPP 1: Collect Data for a Lawful Purpose — and Tell People Why
The first principle requires you to collect personal data only for a lawful purpose directly related to your function, and to inform the data subject of the purpose and the classes of transferees before collection. This is not optional paperwork; it is the foundation of consent.
The PCPD's guidance is explicit on this point. In its Guidance on the Proper Handling of Customers' Personal Data, the PCPD states:
"Data users should collect personal data only if it is necessary for, and directly related to, a purpose which is lawful and directly related to the function or activity of the data user."
Practical step: Draft a Personal Information Collection Statement (PICS) in both English and Chinese. It must state: (a) your identity, (b) the purpose of collection, (c) the classes of persons to whom the data may be transferred, and (d) the data subject's rights to access and correct the data. Provide this PICS at the point of collection — on your website form, at the point of sale, or in your onboarding paperwork. Do not bury it in terms and conditions; make it visible.
DPP 2: Accuracy and Retention — Keep Data Fresh, Then Delete It
The second principle requires you to ensure personal data is accurate, and to delete data once it is no longer needed for the stated purpose. For an SME, this often means cleaning up old customer lists and CRM records.
The PCPD's Guidance on Data Retention is clear: data should not be kept longer than necessary. The guidance notes that retention periods should be "no longer than is necessary for the fulfilment of the purpose (including any directly related purpose) for which the data were collected."
Practical step: Create a simple data retention policy. For example, retain customer transaction records for the statutory limitation period of six years (under the Limitation Ordinance, Cap. 347) for contractual claims, but delete marketing contact lists once a customer opts out or after a defined period of inactivity. Assign one staff member responsibility for periodic data cleansing — quarterly is a reasonable cadence for most SMEs.
DPP 3: Use of Personal Data — The "New Purpose" Trap
The third principle restricts you from using personal data for a new purpose without prescribed consent. If you collected data for order fulfilment, you cannot suddenly use it for a marketing newsletter without fresh consent.
This is the most common compliance failure among SMEs. A customer who buys a product from you has not automatically consented to receiving promotional emails. The PCPD's Guidance on the Use of Personal Data in Direct Marketing is unambiguous: separate, explicit consent is required for marketing use.
Practical step: Implement a dual-consent model. On your collection form, include a separate, unticked checkbox for marketing communications. If the box is not ticked, do not send marketing material. If you already hold data collected before you implemented this, you must obtain fresh opt-in consent before using it for marketing — there is no grandfathering under the PDPO.
DPP 4: Security — The Principle Most SMEs Get Wrong
The fourth principle requires you to take "all reasonably practicable steps" to protect personal data against unauthorised or accidental access, processing, erasure, loss or use. The standard is not perfection; it is reasonableness relative to the sensitivity of the data and the harm that could result.
The PCPD's Guidance Note on Data Security Measures for the Handling of Personal Data lists specific measures, including encryption, access control, and staff training. For an SME, "reasonably practicable" might mean:
- Encrypting laptops and mobile devices that hold customer data
- Using two-factor authentication for any system containing personal data
- Restricting database access to named staff only
- Ensuring your cloud provider offers encryption at rest and in transit
Practical step: Conduct a simple data security audit. List every place personal data is stored — email inboxes, spreadsheets, CRM systems, cloud drives. For each, ask: who has access, is it encrypted, and is access logged? Fix the highest-risk gaps first. Document your security measures in writing; if a data breach occurs, the PCPD will ask what steps you took.
DPP 5: Openness and Transparency — Publish Your Privacy Policy
The fifth principle requires you to be open about your personal data policies and practices. This means having a publicly available privacy policy that describes how you handle personal data.
The PCPD's Guidance on Preparing a Privacy Policy Statement recommends that the policy cover: the types of personal data held, the main purposes for which the data is used, and the classes of transferees. It does not need to be a legal treatise — a clear, plain-language policy is more effective.
Practical step: Publish a privacy policy on your website and make it available at your physical premises. Review it annually, or whenever you change how you handle data. Ensure it matches what you actually do — a policy that promises more than you deliver is worse than no policy at all.
DPP 6: Access and Correction — Respond Within 40 Days
The sixth principle gives data subjects the right to access and correct their personal data, and requires you to respond to such requests within 40 days. This is a hard statutory deadline.
Section 19 of the PDPO requires you to comply with a data access request within 40 days of receiving it. You may charge a reasonable fee, but you cannot refuse without a lawful basis. The PCPD's Guidance on Data Access Requests is clear that the 40-day period is a statutory obligation.
Practical step: Designate one person as the data access request handler. Create a simple log to track requests and their deadlines. Prepare a standard response template. If you receive a request, verify the requester's identity, locate the data, and respond within the statutory period. If you cannot comply, you must provide written reasons.
Data Breach Notification: Not Mandatory, But Expected
Hong Kong does not currently have a mandatory data breach notification law, but the PCPD's Guidance on Data Breach Handling and the Giving of Breach Notifications strongly recommends voluntary notification. The PCPD expects data users to notify affected individuals and the Commissioner "as soon as practicable" after a breach.
The guidance states:
"The PCPD recommends that data users should, as soon as practicable after a data breach has come to their knowledge, notify the affected data subjects and the PCPD."
Practical step: Prepare a simple data breach response plan. It should cover: (1) containing the breach, (2) assessing the risk to affected individuals, (3) notifying affected parties and the PCPD where warranted, and (4) documenting lessons learned. Even without a legal mandate, having a plan demonstrates good governance and will mitigate regulatory and reputational damage.
Practical Compliance Checklist for Your SME
Ongoing Compliance Execution
Ongoing statutory obligations are handled seamlessly through Captime's dedicated Hong Kong company secretary service, providing a licensed local representative and automated annual return management.
Here is a distilled checklist you can action this week:
- Draft a PICS in English and Chinese and display it at every collection point.
- Separate marketing consent from transactional consent with an unticked opt-in box.
- Write a data retention policy and assign someone to enforce it quarterly.
- Encrypt devices and databases that hold personal data; enable two-factor authentication.
- Publish a privacy policy that matches your actual practices.
- Designate a data access request handler and prepare a response template.
- Write a one-page breach response plan and brief your team on it.
The Takeaway: Compliance Is a Process, Not a Project
PDPO compliance is not a one-off exercise; it is an ongoing operational discipline. The PCPD's enforcement approach focuses on whether you have taken "reasonably practicable" steps, which means the bar is set by your own documented efforts. An SME that can show a written policy, staff training records, and a breach response plan is in a far stronger position than one that has done nothing.
Start with the checklist above, document everything you do, and review your practices annually or whenever you change how you handle data. If you are unsure whether your current practices meet the standard, the PCPD's website offers free, detailed guidance notes on every principle discussed here.
If you are setting up a new business entity and want to ensure your data handling practices are built on a compliant foundation from day one, our HSIC Code Finder at /hsic-finder can help you classify your business activities correctly for your registration — a small but important step in getting your corporate housekeeping in order.
This guide is part of HK Company Guide's free resource library for Hong Kong entrepreneurs. Use the HSIC Code Finder to look up your specific code.
More Posts
Hong Kong's Beneficial Ownership Rules: What Has Changed?
Hong Kong's beneficial ownership regime has evolved significantly, with the Companies Registry (CR) now requiring companies to maintain a Register of Significant Controllers (RSC) under the Companies Ordinance (Cap. 622). This post explains the current obligations, recent enforcement updates, and practical steps for compliance.
How to Prepare for a Companies Registry Inspection in Hong Kong
A Companies Registry inspection is rare but serious. This guide explains what triggers one, what documents you must produce, and how to respond within statutory deadlines under the Companies Ordinance (Cap. 622).
Understanding Hong Kong's New Anti-Money Laundering Requirements
Hong Kong's AML regime has tightened significantly, with new customer due diligence, record-keeping, and reporting duties under the AMLO. This post breaks down the key obligations for company secretaries, designated non-financial businesses, and corporate service providers, and explains what you must do to stay compliant.