HomeKnowledge HubOrganisations & Guidance › PCPD Hong Kong

Regulator as guidance publisher · Organisations & Guidance

PCPD Hong Kong — three decades of bilingual privacy guidance

Ordinance in force 20 December 1996Cap. 486English and Traditional Chinese

The PCPD oversees one of Asia’s longest-standing comprehensive data protection laws and publishes its guidance catalogue in English and Chinese in parallel — guidance notes, codes of practice with statutory status, and topic frameworks, several of them recently revised.

Published by
Office of the Privacy Commissioner for Personal Data, Hong Kong — an independent statutory body.
Type
Statutory regulator; guidance publisher; issues codes of practice under the Personal Data (Privacy) Ordinance.
Versions and language
English and Traditional Chinese, in parallel.
Jurisdiction
Hong Kong SAR.
Primary audience
DPOs with Hong Kong operations, processors, group privacy functions.
Topic tags
PDPO · data protection principles · data security · cloud · CCTV and drones · cross-border transfer clauses · generative AI
Availability
Free.

Why it matters

The Commissioner’s statutory duties include approving and issuing codes of practice — which carry evidential weight under the Ordinance — inspecting personal data systems, including those of government departments, and examining proposed legislation for its privacy effects. The guidance output that travels best is practical and specific: a data security guidance note, cloud computing guidance, CCTV and drone-camera guidance (both revised in October 2025), recommended model contractual clauses for cross-border transfer, a generative-AI checklist for employees, and the AI personal-data protection framework already listed in Standards & Frameworks.

The UK position, and the divergences worth stating plainly. Hong Kong has no UK adequacy decision. The Ordinance’s cross-border transfer provision, section 33, has never been brought into force — the PCPD’s own guidance says so — so its model clauses are recommended practice rather than a legal requirement. Hong Kong has no mandatory breach notification duty, which makes its breach-handling guidance a useful comparator to Articles 33 and 34 rather than an equivalent. Data access requests carry a 40-day deadline and a permitted fee regime unlike the UK’s.

The PCPD’s regulator profile sits in Regulators & Authorities.

A curated reference entry maintained by VulaPri. We summarise and link to the original; we do not reproduce or host it. Listed since 15 September 2026 · last verified 15 September 2026 — facts verified against pcpd.org.hk (About PCPD page read 11 September 2026; section 33 status confirmed on the PCPD’s own cross-border guidance, 15 September 2026); guidance titles and dates carried from our 7 August 2026 candidate register. Suggest a correction.