Pandectes GDPR Compliance - 3,000+ Verified ⭐⭐⭐⭐⭐ 5/5 Reviews Worldwide - #1 on Shopify 🏅

Hong Kong Personal Data (Privacy) Ordinance (PDPO) Compliance

Pandectes GDPR Compliance helps Shopify stores meet PDPO requirements by giving clear notice about cookies, scanning and classifying cookies, and keeping consent records.

Start Free
PDPO Hong Kong

The #1 cookie consent app for Shopify, trusted by 185k stores

  • Nike Strength
  • Reebok
  • Ted Baker
  • Juicy Couture
  • Aje
  • Casely
  • Oracle Red Bull Racing
  • KFC
  • Flying Tiger Copenhagen
  • Sennheiser
  • Susanne Kaufmann
  • Aldo
  • Victoria Beckham
  • Scalpers
  • UGREEN

What is PDPO?

The Personal Data (Privacy) Ordinance (PDPO), Chapter 486 of the Laws of Hong Kong, is Hong Kong’s main data protection law. It regulates how “data users”, meaning anyone who controls the collection, holding, processing or use of personal data, handle information about individuals. It is overseen by the Privacy Commissioner for Personal Data (PCPD).

At its core are six Data Protection Principles:

  • Collection: Personal data must be collected lawfully and fairly, for a purpose related to the data user’s activities, and no more than necessary. On or before collection, individuals must be told the purpose, who the data may be given to, whether supplying it is voluntary, and how to request access and correction.
  • Accuracy and retention: Data must be accurate and not kept longer than needed.
  • Use: Data may not be used for a new purpose without the individual’s express and voluntary consent.
  • Security: Data must be protected against unauthorized or accidental access, processing, erasure, loss or use.
  • Openness: Data users must make their personal data policies and practices available.
  • Access and correction: Individuals can ask for a copy of their data and ask for it to be corrected.

The PDPO also has specific rules on using personal data for direct marketing, which needs the individual’s consent.

Who does the PDPO apply to?

The PDPO applies to both the private and public sectors in Hong Kong, covering any business that collects or uses personal data in or from Hong Kong. Businesses outside Hong Kong that collect personal data from Hong Kong customers should treat the PDPO as relevant to them.

What happens if I don’t comply with the PDPO?

The PCPD can investigate complaints and, if it finds a contravention, issue an enforcement notice directing the data user to take remedial and preventive steps. Consequences can include:

  • Breaching an enforcement notice: A criminal offence punishable on first conviction by a fine of up to HK$50,000 and imprisonment for 2 years, plus a daily fine of up to HK$1,000 if the offence continues.
  • Direct marketing offences: Fines of up to HK$500,000 and imprisonment for 3 years, rising to HK$1,000,000 and 5 years where personal data is provided to a third party for gain.
  • Compensation claims: Individuals can seek compensation through a civil claim for damage caused by a contravention.
  • Published findings: The PCPD can publish a report of its investigation and recommendations when this is in the public interest.

When did the PDPO go into effect?

The PDPO was passed in 1995 and took effect in December 1996, except for certain provisions. Major amendments in 2012 introduced the direct marketing provisions, and amendments in 2021 made doxxing a criminal offence.

Complying with the PDPO

The PDPO does not have a cookie-specific consent rule like the GDPR, but cookies and tracking tools that collect personal data are subject to its principles. For a Shopify store selling to customers in Hong Kong, that means telling visitors clearly, at or before the point of collection, what personal data is collected through cookies and similar tools, why, and who it is shared with, for example in a cookie banner and a Personal Information Collection Statement or privacy policy. If you use personal data for direct marketing, you must get the customer’s consent first, and using data for a new, unrelated purpose needs express and voluntary consent.

The provision of the PDPO that would restrict transfers of personal data outside Hong Kong is not yet in operation, but the PCPD publishes recommended model contract clauses for transfers. You should also be ready to respond to data access and correction requests.

A Consent Management Platform (CMP) like Pandectes GDPR Compliance helps with the parts of this that happen on your storefront. It shows a cookie banner and can block non-essential cookies until the visitor consents, automatically scans and classifies the cookies on your store, and generates a cookie declaration for your policy. It keeps consent logs as proof of consent, helps you handle data subject requests, and lets you configure banner settings by region using geolocation, so visitors from Hong Kong can see a banner suited to the PDPO.

The PDPO is under review and may change, so review your setup with legal counsel where appropriate.

Make your Shopify Store's use of cookies and online tracking compliant today

Try for free