Data Protection Notice Template for Hong Kong

Generate a bespoke document

Trusted by 200k+ teams

4.7 Capterra
4.8 Product Hunt
4.6 Trustpilot

What is a Data Protection Notice?

A Data Protection Notice is a mandatory document for organizations operating in Hong Kong that collect, process, or handle personal data. This notice must comply with the Personal Data (Privacy) Ordinance (PDPO) and guidelines issued by the Privacy Commissioner for Personal Data (PCPD). The document serves as a transparent communication tool between organizations and data subjects, explaining how personal data is collected, used, stored, and protected. Organizations must provide this notice to data subjects at or before the time of data collection, detailing the purposes of collection, potential recipients of the data, and data subjects' rights. The notice should be regularly reviewed and updated to reflect any changes in data handling practices or regulatory requirements.

Reviewed by

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Reviewed by

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdiction

Hong Kong

Publisher

GenieAI

Sector

Business

Cost

Free to use

Last updated

About the Data Protection Notice

Your Data Protection Notice is a critical legal document that ensures your organization complies with Hong Kong's strict privacy laws while building trust with customers and stakeholders. Under the Personal Data (Privacy) Ordinance, you must provide clear, comprehensive information about how you handle personal data, making this notice an essential component of your legal compliance framework.

When do you need this document?

You need a Data Protection Notice whenever your organization collects personal data from individuals in Hong Kong. This includes setting up new customer accounts, conducting employee recruitment, implementing marketing campaigns, or launching digital services that gather user information. E-commerce businesses require this notice for online transactions, healthcare providers need it for patient records, and educational institutions must have it for student enrollment. Financial services companies use it for account opening procedures, while property management firms need it for tenant applications. Any organization processing personal data through websites, mobile apps, or physical forms must provide this notice at or before data collection begins.

Key legal considerations

Your notice must clearly identify the types of personal data you collect, from basic contact information to sensitive categories like health records or financial data. You must specify exactly why you're collecting this information and how you'll use it, ensuring these purposes align with your actual business practices. The document should detail your data security measures, retention periods for different data types, and any third-party sharing arrangements. You must include information about data subjects' rights, including access, correction, and deletion requests. Cross-border data transfer policies require special attention, particularly when sharing data with overseas subsidiaries or service providers. Your notice should also address direct marketing activities, including clear opt-out mechanisms and consent requirements.

Legal requirements in Hong Kong

Under the Personal Data (Privacy) Ordinance, your notice must comply with six Data Protection Principles covering collection limitations, data accuracy, purpose limitation, data security, openness, and data access rights. The Privacy Commissioner for Personal Data has issued specific guidelines requiring notices to be written in plain language that ordinary individuals can understand. You must provide the notice in both English and Chinese if your organization serves local customers. The document must be easily accessible, whether displayed prominently on your website, included in application forms, or provided as standalone documentation. Any changes to your data handling practices require you to update the notice and notify affected individuals. Failure to provide adequate notices or maintain compliance can result in enforcement action by the PCPD, including investigation orders and penalty notices.

Genie's Security Promise

Genie is the safest place to draft. Here's how we prioritise your privacy and security.

Your data is private:

We do not train on your data; Genie's AI improves independently

All data stored on Genie is private to your organisation

Your documents are protected:

Your documents are protected by ultra-secure 256-bit encryption

We are ISO27001 certified, so your data is secure

Organizational security:

You retain IP ownership of your documents and their information

You have full control over your data and who gets to see it