PCPD Best Practice Guide on Privacy Management Programme (PMP) 2014 + 2018 + 2024 updates establishes accountability-based governance expectations for data users: top management commitment + dedicated personal data privacy officer or function + reporting line to top management + personal data inventory + privacy policies + risk assessment processes + training + breach handling + communication + complaint handling + monitoring + review + continuous improvement. While DPO is not statutorily required by PDPO, PCPD strongly recommends a Data Protection Officer or Privacy Lead and PCPD PMP Manual provides DPO function description. Privacy Impact Assessment (PIA) recommended for new programmes + systems + technologies including AI + biometric + cloud + cross-border + IoT + analytics. PCPD PIA Information Leaflet + Template + Annexes. Records of processing activities (RoPA-style) + personal data inventory + privacy policy + procedure + DAR + DCR log + complaint log + breach log + cessation notice log + training log + audit + management review. Training: annual mandatory privacy training for all staff + role-based for HR + IT + customer service + marketing + legal + Anti-Doxxing Division liaison + 2024 Generative AI literacy. PCPD Data Protection Officers Club + Privacy Awareness Week + sectoral campaigns. HK PDPO governance + PMP + DPO + PIA + RoPA + training + accountability applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.