Data Processing Addendum Template for Hong Kong
Generate a bespoke document
What is a Data Processing Addendum?
The Data Processing Addendum is a critical legal document used when one organization (the data processor) processes personal data on behalf of another organization (the data controller) under Hong Kong law. This document supplements the main service agreement and ensures compliance with the Personal Data (Privacy) Ordinance (PDPO) and guidelines issued by the Privacy Commissioner for Personal Data. It is essential for businesses operating in Hong Kong or processing data of Hong Kong residents, particularly given the territory's strict data protection requirements and its status as an international business hub. The addendum covers crucial aspects such as security measures, data breach procedures, cross-border transfers, and sub-processor arrangements, while addressing specific Hong Kong regulatory requirements.
About the Data Processing Addendum
A Data Processing Addendum (DPA) is an essential legal document that governs how personal data is handled when you engage a third-party processor under Hong Kong law. This addendum supplements your main service agreement and ensures compliance with the Personal Data (Privacy) Ordinance (PDPO) and guidelines from the Privacy Commissioner for Personal Data (PCPD).
When do you need this document?
You need a Data Processing Addendum whenever you engage external service providers to process personal data on your behalf. This includes cloud service providers, payroll companies, IT support services, marketing agencies, or any vendor that accesses personal data of your employees, customers, or business contacts. Hong Kong businesses must use DPAs when outsourcing data processing activities to ensure compliance with the PDPO's data protection principles. The document is particularly crucial for international businesses operating in Hong Kong or processing data of Hong Kong residents, as it establishes clear accountability and legal obligations for all parties involved.
Key legal considerations
Your DPA must clearly define the scope and purpose of data processing activities, specifying what types of personal data will be processed and for what legitimate business purposes. Security measures are paramount – you must require processors to implement appropriate technical and organizational safeguards to protect personal data against unauthorized access, loss, or disclosure. The agreement should address data breach notification procedures, requiring processors to notify you immediately of any security incidents. Sub-processor arrangements need careful consideration, as you remain liable for any third parties your processor engages. Include provisions for data retention, deletion procedures, and the processor's obligation to assist with data subject rights requests. Cross-border data transfer provisions are critical if data will be transferred outside Hong Kong, requiring adequate safeguards and potentially PCPD approval.
Legal requirements in Hong Kong
Under the PDPO, you must ensure your DPA addresses the six Data Protection Principles, particularly principles relating to data security, use limitation, and data quality. The agreement must specify that the processor will only process data according to your documented instructions and for the agreed purposes. Hong Kong law requires explicit provisions for handling data subject access requests, correction requests, and complaints. Your DPA should include audit rights, allowing you to monitor the processor's compliance with data protection obligations. For international data transfers, the agreement must comply with PCPD guidance on cross-border transfers and may require additional safeguards such as standard contractual clauses. The document should also address the processor's obligations to maintain records of processing activities and cooperate with PCPD investigations. Ensure the agreement includes liability allocation and indemnification provisions that protect both parties while maintaining accountability for data protection compliance.
GOVERNING LAW
Applicable law
This Data Processing Addendum is drafted to comply with Hong Kong law. Key legislation includes:
PCPD Guidance on Data Processor Contracts: Guidelines issued by the Privacy Commissioner for Personal Data on recommended provisions for contracts with data processors
Data Protection Principles (DPPs): Six fundamental principles under the PDPO that govern the collection, handling, and use of personal data
Electronic Transactions Ordinance (Cap. 553): Relevant for electronic execution and record-keeping requirements in data processing agreements
Guidance on Cross-border Data Transfer: PCPD guidelines on international data transfers and recommended safeguards
Practice Guide on the Proper Handling of Data Access Requests: PCPD guidance on handling data subject access requests, which should be addressed in the DPA
Information Security and Data Breach Guidance: PCPD guidelines on security measures and breach notification procedures that should be incorporated into the DPA
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it