Intercompany Data Processing Agreement Template for Hong Kong
Generate a bespoke document
What is a Intercompany Data Processing Agreement?
The Intercompany Data Processing Agreement is essential for multinational companies operating in Hong Kong that need to establish formal arrangements for processing personal data within their group structure. This document becomes necessary when one group entity processes personal data on behalf of another, requiring compliance with Hong Kong's Personal Data (Privacy) Ordinance (PDPO) and associated regulations. The agreement is particularly important in the context of Hong Kong's data protection regime, which requires documented arrangements for data processing activities, even between affiliated entities. It addresses key aspects such as data security measures, breach reporting procedures, audit requirements, and cross-border transfer mechanisms, while taking into account the intra-group nature of the relationship. This template is designed to balance regulatory compliance with practical considerations of intra-group operations.
Trusted by high-performance teams
About the Intercompany Data Processing Agreement
An Intercompany Data Processing Agreement is a legally binding contract that governs how personal data is processed between affiliated companies within a corporate group under Hong Kong law. When one group entity acts as a data processor on behalf of another group entity serving as the data controller, this agreement ensures compliance with the Personal Data (Privacy) Ordinance (PDPO) and establishes clear responsibilities for data protection obligations.
When do you need this document?
You need an Intercompany Data Processing Agreement when your Hong Kong group company processes personal data on behalf of another group entity, such as when a subsidiary handles customer data for its parent company or when centralised HR departments process employee information across multiple group entities. This document is essential for shared services arrangements, including IT support, payroll processing, customer service operations, or marketing activities conducted by one group company for another. The agreement becomes particularly important when personal data crosses jurisdictional boundaries within your corporate group, ensuring compliance with Hong Kong's transfer requirements and maintaining adequate protection standards. Even though the entities are related, Hong Kong's PDPO requires formal documentation of processing arrangements to demonstrate accountability and establish clear data protection responsibilities.
Key legal considerations
The agreement must clearly define the roles of data controller and data processor, specifying the scope and purpose of processing activities in detail. Essential clauses include data security measures that meet PDPO requirements, breach notification procedures with specific timeframes, and audit rights allowing the controller to verify compliance. The document should address data retention periods, deletion requirements, and procedures for handling data subject requests including access, correction, and erasure rights. Sub-processing arrangements must be carefully regulated, requiring prior written consent and ensuring adequate protection when other group entities are involved. Liability allocation between group companies requires careful consideration, balancing commercial relationships with regulatory compliance obligations. The agreement should include termination provisions specifying data return or destruction requirements and survival clauses for ongoing obligations.
Legal requirements in Hong Kong
Under Hong Kong's Personal Data (Privacy) Ordinance, the agreement must ensure compliance with all six Data Protection Principles, particularly focusing on security safeguards and data quality requirements. The document must address cross-border data transfer requirements, incorporating appropriate safeguards when personal data moves between Hong Kong and other jurisdictions within the group structure. Specific provisions are needed for handling data subject requests, ensuring responses within the statutory timeframe of 40 days unless exemptions apply. The agreement should incorporate Privacy Commissioner guidelines on data processing and transfer, particularly the Transfer of Personal Data Guidelines for international group structures. Documentation requirements under the Companies Ordinance must also be considered, ensuring proper corporate authorisation and record-keeping for intercompany agreements involving data processing activities.
GOVERNING LAW
Applicable law
This Intercompany Data Processing Agreement is drafted to comply with Hong Kong law. Key legislation includes:
Companies Ordinance (Cap. 622): Governs company operations in Hong Kong, including requirements for transactions between related companies and documentation requirements for intercompany agreements.
Data Protection Principles (DPPs) under PDPO: Six principles that form the foundation of Hong Kong's data protection regime, covering data collection, accuracy, retention, usage, security, and access rights.
Transfer of Personal Data (Outside Hong Kong) Guidelines: Guidelines issued by the Privacy Commissioner providing requirements and best practices for international data transfers, which may be relevant if the intercompany agreement involves cross-border data flows.
Electronic Transactions Ordinance (Cap. 553): Relevant for electronic execution and record-keeping requirements if the agreement is to be executed or maintained electronically.
Guidance on Data Processor Contracts under PDPO: Specific guidance from the Privacy Commissioner on contractual terms and safeguards required in data processing agreements.
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

