Mandatory scheme
Personal Data (Privacy) Ordinance compliance
Personal Data (Privacy) Ordinance compliance — mandatory scheme, Hong Kong SAR China. It binds data users in Hong Kong.
- Jurisdiction
- Hong Kong SAR China
- Record class
- Mandatory scheme
- Last verified
Where this applies
This record is scoped to Hong Kong SAR China. Scope is part of the claim: a rule that binds one part of a country does not bind the whole of it, and this library states the scope its sources state.
Instrument
Personal Data (Privacy) Ordinance (Cap. 486)
Who it binds
Data users in Hong Kong
What it requires
Cap. 486 (enacted 1995, in force December 1996) sets six Data Protection Principles: lawful collection purpose, accuracy and retention limits, use limitation, security, openness, and data-subject access/correction rights. The 2021 doxxing amendment (in force 8 October 2021) created an offence for unauthorised disclosure of personal data intended or likely to cause specified harm: on summary conviction, a fine of HK$100,000 and imprisonment for 2 years; where actual specified harm resulted, on indictment, a fine of HK$1,000,000 and imprisonment for 5 years. The Office of the Privacy Commissioner for Personal Data (PCPD) is the regulator.
Route to the authority
Further sources cited on this page
Last verified:
Related records and requirements
- Personal Information Protection and Electronic Documents Act (PIPEDA) (Canada) — PIPEDA is Canada's federal general-compliance data-protection law, binding organisations that collect, use or disclose personal information in the course of commercial activity.
- Act Respecting the Protection of Personal Information in the Private Sector (Québec) (Canada) — Québec's own private-sector privacy law is the general-compliance regime for private-sector businesses handling personal information within Québec — it takes the place of PIPEDA for that in-province activity.
- Privacy Act 1988 — Australian Privacy Principles (Australia) — The Privacy Act 1988 binds Australian government agencies and covered organisations to 13 Australian Privacy Principles — the small-business turnover exemption has documented exceptions.
- Act on the Protection of Personal Information (APPI) compliance (Japan) — APPI's general obligations (Art. 21(1) purpose notification, Art. 23 security-management measures) bind business operators handling personal information in Japan.
- Personal data protection compliance (Vietnam) — Vietnam's Decree 13/2023 and, from 1 January 2026, Law 91/2025 bind organisations processing personal data in Vietnam to a general data-protection compliance regime.
- Federal personal data protection compliance (Mexico) — Mexico's federal private-sector data-protection law, replaced in full on 20 March 2025, binds private-sector personal-data processing nationwide.
- Personal Data Protection Law (PDPL) compliance (Saudi Arabia) — Saudi Arabia's PDPL (Royal Decree M/19) binds entities processing personal data in Saudi Arabia to a general data-protection compliance law.
- Federal personal data protection compliance (United Arab Emirates) — The UAE's federal PDPL (Federal Decree-Law No. 45 of 2021) binds organisations processing personal data inside or outside the UAE where the processing relates to the UAE — separate from DIFC's and ADGM's own free-zone regimes.
This page is for information only; it is not legal advice, and it does not establish whether this record applies to your business. Verify current status through the official source above.