PCPD Hong Kong — three decades of bilingual privacy guidance
The PCPD oversees one of Asia’s longest-standing comprehensive data protection laws and publishes its guidance catalogue in English and Chinese in parallel — guidance notes, codes of practice with statutory status, and topic frameworks, several of them recently revised.
- Published by
- Office of the Privacy Commissioner for Personal Data, Hong Kong — an independent statutory body.
- Type
- Statutory regulator; guidance publisher; issues codes of practice under the Personal Data (Privacy) Ordinance.
- Versions and language
- English and Traditional Chinese, in parallel.
- Jurisdiction
- Hong Kong SAR.
- Primary audience
- DPOs with Hong Kong operations, processors, group privacy functions.
- Topic tags
- PDPO · data protection principles · data security · cloud · CCTV and drones · cross-border transfer clauses · generative AI
- Availability
- Free.
Why it matters
The Commissioner’s statutory duties include approving and issuing codes of practice — which carry evidential weight under the Ordinance — inspecting personal data systems, including those of government departments, and examining proposed legislation for its privacy effects. The guidance output that travels best is practical and specific: a data security guidance note, cloud computing guidance, CCTV and drone-camera guidance (both revised in October 2025), recommended model contractual clauses for cross-border transfer, a generative-AI checklist for employees, and the AI personal-data protection framework already listed in Standards & Frameworks.
The UK position, and the divergences worth stating plainly. Hong Kong has no UK adequacy decision. The Ordinance’s cross-border transfer provision, section 33, has never been brought into force — the PCPD’s own guidance says so — so its model clauses are recommended practice rather than a legal requirement. Hong Kong has no mandatory breach notification duty, which makes its breach-handling guidance a useful comparator to Articles 33 and 34 rather than an equivalent. Data access requests carry a 40-day deadline and a permitted fee regime unlike the UK’s.
The PCPD’s regulator profile sits in Regulators & Authorities.
