Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)
The Hong Kong Personal Data (Privacy) Ordinance (Cap 486, enacted 1996, significantly amended 2012 and 2021) regulates the collection, use, storage, and transfer of personal data. The Privacy Commissioner for Personal Data (PCPD) oversees compliance. The 2021 amendment criminalised doxxing. Establishes six Data Protection Principles (DPPs) governing the lifecycle of personal data. The PCPD has enhanced enforcement powers including criminal prosecution for doxxing.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (1)
Enforcement and Doxxing
PCPD enforcement and anti-doxxing provisions
| Code | Title |
|---|---|
| HK-PDPO-ENF-01 | PCPD Enforcement |
| HK-PDPO-ENF-02 | Direct Marketing |
| HK-PDPO-ENF-03 | Anti-Doxxing (2021 Amendment) |
Maps to 299 other frameworks
Frequently Asked Questions
What is Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486)?
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) is a compliance framework from Hong Kong with 1 domains and 3 controls. The Hong Kong Personal Data (Privacy) Ordinance (Cap 486, enacted 1996, significantly amended 2012 and 2021) regulates the collection, use, storage, and transfer of personal data. The Privacy Commissioner for Personal Data (PCPD) oversees compliance. The 2021 amendment criminalised doxxing. Establishes six Data Protection Principles (DPPs) governing the lifecycle of personal data. The PCPD has enhanced enforcement powers including criminal prosecution for doxxing. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) have?
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) has 3 controls organised across 1 domains. The largest domains are Enforcement and Doxxing (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) map to?
Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) maps to 299 other compliance frameworks. The top mapping partners are GDPR (67% coverage), Colorado Privacy Act (CPA) (67% coverage), Lebanon Electronic Transactions and Personal Data Protection Law (Law No. 81/2018) (67% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) compliance?
Start your Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Hong Kong Personal Data (Privacy) Ordinance (PDPO, Cap 486) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 3 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required