PDPO does not have GDPR-style special categories of sensitive data definition, but PCPD has issued codes of practice and sectoral guidance treating certain data categories with heightened expectations: Code of Practice on Human Resources Management (covering recruitment, current employment, former employment, monitoring), Code of Practice on Consumer Credit Data, Guidance on CCTV + Drones (2015 + 2024 updates), Guidance on Collection + Use of Personal Data + Use of Mobile Apps, Guidance on Personal Data of Customers + Members + Subscribers. CCTV expectations: PIA + necessity + proportionality + signage + retention 30-90 days typical + processor or operator due diligence + access logs + privacy zones + facial recognition + AI analytics impact assessment. Workplace monitoring: PCPD Code of Practice on Human Resources Management + Privacy Guidelines on Monitoring and Personal Data Privacy at Work (3-A test: assessment + alternative + accountability), PICS at hiring + PPS published + grievance procedure + works council where applicable. Children data: PCPD Children Privacy + Cybersecurity Guidance + e-learning + social media + EdTech sectoral expectations. Health data: PCPD Health Data Privacy Guidance + Electronic Health Record Sharing System (eHRSS) framework. Biometric: PCPD Guidance on Collection of Fingerprint Data 2015 + heightened scrutiny. HK PDPO sensitive + CCTV + workplace + children + sectoral codes + PCPD guidance applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.