Data Protection Notice Template for Hong Kong
Generate a bespoke document
What is a Data Protection Notice?
A Data Protection Notice is a mandatory document for organizations operating in Hong Kong that collect, process, or handle personal data. This notice must comply with the Personal Data (Privacy) Ordinance (PDPO) and guidelines issued by the Privacy Commissioner for Personal Data (PCPD). The document serves as a transparent communication tool between organizations and data subjects, explaining how personal data is collected, used, stored, and protected. Organizations must provide this notice to data subjects at or before the time of data collection, detailing the purposes of collection, potential recipients of the data, and data subjects' rights. The notice should be regularly reviewed and updated to reflect any changes in data handling practices or regulatory requirements.
About the Data Protection Notice
Your Data Protection Notice is a critical legal document that ensures your organization complies with Hong Kong's strict privacy laws while building trust with customers and stakeholders. Under the Personal Data (Privacy) Ordinance, you must provide clear, comprehensive information about how you handle personal data, making this notice an essential component of your legal compliance framework.
When do you need this document?
You need a Data Protection Notice whenever your organization collects personal data from individuals in Hong Kong. This includes setting up new customer accounts, conducting employee recruitment, implementing marketing campaigns, or launching digital services that gather user information. E-commerce businesses require this notice for online transactions, healthcare providers need it for patient records, and educational institutions must have it for student enrollment. Financial services companies use it for account opening procedures, while property management firms need it for tenant applications. Any organization processing personal data through websites, mobile apps, or physical forms must provide this notice at or before data collection begins.
Key legal considerations
Your notice must clearly identify the types of personal data you collect, from basic contact information to sensitive categories like health records or financial data. You must specify exactly why you're collecting this information and how you'll use it, ensuring these purposes align with your actual business practices. The document should detail your data security measures, retention periods for different data types, and any third-party sharing arrangements. You must include information about data subjects' rights, including access, correction, and deletion requests. Cross-border data transfer policies require special attention, particularly when sharing data with overseas subsidiaries or service providers. Your notice should also address direct marketing activities, including clear opt-out mechanisms and consent requirements.
Legal requirements in Hong Kong
Under the Personal Data (Privacy) Ordinance, your notice must comply with six Data Protection Principles covering collection limitations, data accuracy, purpose limitation, data security, openness, and data access rights. The Privacy Commissioner for Personal Data has issued specific guidelines requiring notices to be written in plain language that ordinary individuals can understand. You must provide the notice in both English and Chinese if your organization serves local customers. The document must be easily accessible, whether displayed prominently on your website, included in application forms, or provided as standalone documentation. Any changes to your data handling practices require you to update the notice and notify affected individuals. Failure to provide adequate notices or maintain compliance can result in enforcement action by the PCPD, including investigation orders and penalty notices.
GOVERNING LAW
Applicable law
This Data Protection Notice is drafted to comply with Hong Kong law. Key legislation includes:
PCPD Guidelines on Privacy Notices: Official guidelines from the Privacy Commissioner providing specific requirements and best practices for privacy notices and personal information collection statements
PCPD Guidance on Direct Marketing: Specific guidelines relating to the use of personal data in direct marketing activities, including consent requirements and opt-out mechanisms
PCPD Data Breach Guidance: Guidelines on handling and notification requirements for data breaches, which should be referenced in privacy notices
Cross-border Transfer Guidelines: Guidelines regarding the transfer of personal data outside of Hong Kong, which must be addressed in privacy notices if applicable
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it