Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
The Hong Kong Personal Data (Privacy) Ordinance (Cap 486, enacted 1996, significantly amended 2012 and 2021) regulates the collection, use, storage, and transfer of personal data. The Privacy Commissioner for Personal Data (PCPD) oversees compliance. The 2021 amendment criminalised doxxing. Establishes six Data Protection Principles (DPPs) governing the lifecycle of personal data. The PCPD has enhanced enforcement powers including criminal prosecution for doxxing.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
AI
| Code | Title |
|---|---|
| PDPO-AI | AI and Automated Processing |
Accountability
| Code | Title |
|---|---|
| PDPO-Records | Records and Accountability |
Assessment
| Code | Title |
|---|---|
| PDPO-DPIA | Privacy Impact Assessment |
Breach
| Code | Title |
|---|---|
| PDPO-Breach | Data Breach Handling |
Children
| Code | Title |
|---|---|
| PDPO-Children | Children and Minors |
Collection
| Code | Title |
|---|---|
| PDPO-DPP1 | DPP1 Purpose and Collection |
Complaints
| Code | Title |
|---|---|
| PDPO-Complaints | Complaints and PCPD Liaison |
Cross Border
| Code | Title |
|---|---|
| PDPO-Sec33 | Cross Border Transfer Readiness |
Doxxing
| Code | Title |
|---|---|
| PDPO-Doxxing | Anti Doxxing Compliance (2021 Amendment) |
Employment
| Code | Title |
|---|---|
| PDPO-Employment | Workplace Monitoring and HR Data |
Enforcement and Doxxing
PCPD enforcement and anti-doxxing provisions
| Code | Title |
|---|---|
| HK-PDPO-ENF-01 | PCPD Enforcement |
| HK-PDPO-ENF-02 | Direct Marketing |
| HK-PDPO-ENF-03 | Anti-Doxxing (2021 Amendment) |
Governance
| Code | Title |
|---|---|
| PDPO-DPO | Data Protection Officer or Privacy Lead |
Marketing
| Code | Title |
|---|---|
| PDPO-Direct-Marketing | Direct Marketing Consent |
Notice
| Code | Title |
|---|---|
| PDPO-PICS | Personal Information Collection Statement |
Programme
| Code | Title |
|---|---|
| PDPO-PMP | Privacy Management Programme |
Quality
| Code | Title |
|---|---|
| PDPO-DPP2 | DPP2 Accuracy and Retention |
Rights
| Code | Title |
|---|---|
| PDPO-DPP6 | DPP6 Access and Correction |
Security
| Code | Title |
|---|---|
| PDPO-DPP4 | DPP4 Security |
Sensitive
| Code | Title |
|---|---|
| PDPO-Sensitive-Data | Sensitive Categories Handling |
Surveillance
| Code | Title |
|---|---|
| PDPO-CCTV | CCTV and Surveillance |
Third Party
| Code | Title |
|---|---|
| PDPO-Processor | Data Processor Oversight |
Training
| Code | Title |
|---|---|
| PDPO-Training | Awareness and Training |
Transparency
| Code | Title |
|---|---|
| PDPO-DPP5 | DPP5 Openness |
Use
| Code | Title |
|---|---|
| PDPO-DPP3 | DPP3 Use Limitation |
Your Compliance Coverage
If you comply with Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486), you already cover:
GDPR
8%
2 controls mapped
Compare →Colorado Privacy Act (CPA)
8%
2 controls mapped
Compare →Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018)
8%
2 controls mapped
Compare →+ 305 more: Wisconsin Data Privacy Act (SB 670) (8%), Tennessee Information Protection Act (TIPA) (8%)
See all 308 mapped frameworks ↓Maps to 308 other frameworks
Frequently Asked Questions
What is Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)?
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) is a compliance framework from Hong Kong with 24 domains and 26 controls. The Hong Kong Personal Data (Privacy) Ordinance (Cap 486, enacted 1996, significantly amended 2012 and 2021) regulates the collection, use, storage, and transfer of personal data. The Privacy Commissioner for Personal Data (PCPD) oversees compliance. The 2021 amendment criminalised doxxing. Establishes six Data Protection Principles (DPPs) governing the lifecycle of personal data. The PCPD has enhanced enforcement powers including criminal prosecution for doxxing. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) have?
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) has 26 controls organised across 24 domains. The largest domains are Enforcement and Doxxing (3 controls), AI (1 controls), Accountability (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) map to?
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) maps to 308 other compliance frameworks. The top mapping partners are GDPR (8% coverage), Colorado Privacy Act (CPA) (8% coverage), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) (8% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) compliance?
Start your Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required