Personal Data (Privacy) Ordinance
Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) is one of Asia’s earliest data protection laws, enacted in 1995, brought into force in 1996 and reinforced in 2021 through amendments introducing anti-doxxing provisions. The PDPO is built around six Data Protection Principles and is overseen by the Privacy Commissioner for Personal Data (PCPD). It is a lighter framework than the GDPR, including in how it treats sensitive data and data sent outside Hong Kong.
Our Experts Are Here To Help You!
Ensure your compliance with Hong Kong’s PDPO for clinical trials and health data.
Key Requirements:
- Comply with the six Data Protection Principles (DPP1 to DPP6), covering fair collection, accuracy and retention, use limitation, data security, openness and data access and correction rights.
- Obtain prescribed consent, express and voluntary, before using personal data for a new purpose unrelated to the purpose for which it was originally collected (DPP3).
- Allow data subjects to access and correct the personal data held by data users (DPP6).
- Apply appropriate security safeguards (DPP4), with heightened protection expected by the PCPD for health, genetic and other sensitive data, even though the PDPO contains no statutory special-category regime.
- Apply sound governance to cross-border data transfers. The provision that would restrict such transfers (Section 33) remains dormant, therefore compliance rests on accountability, documented due diligence, and the PCPD’s voluntary Recommended Model Contractual Clauses.
- Handle personal data breaches in line with the PCPD’s Guidance on Data Breach Handling and Data Breach Notifications, notification being voluntary rather than legally mandatory at present.
- Ensure full compliance with the anti-doxxing provisions introduced in 2021, under which unauthorised disclosure of personal data intended to cause harm is a criminal offence, and the PCPD holds powers of criminal investigation, prosecution and cessation notice.
How MyData-TRUST Can Support You:
- Build a tailored compliance roadmap for your Hong Kong operations
- Support DPO appointment and set up the privacy management and governance framework in line with the PCPD’s recommended practices
- Deliver training and awareness programmes for clinical and research teams
- Review contracts, informed consent forms and clinical trial documentation
Why Compliance Matters for Life Sciences:
- Builds trust in clinical trials and research projects
- Implements safeguards for sensitive health and genetic data
- Mitigates reputational and regulatory risks
Why Choose MyData-TRUST?
- Legal expertise dedicated to data protection compliance
- Proven experience integrating privacy into Life Sciences projects
- Practical support for research and patient data use
- Guidance for cross-border clinical trial data transfers
Frequently asked questions
Does the PDPO require a Data Protection Officer or a local representative in Hong Kong?
No. Unlike some other jurisdictions, the PDPO imposes no statutory obligation to appoint a Data Protection Officer or a local representative. The PCPD does, however, recommend designating a data protection officer and running a Privacy Management Programme as good practice. MyData-TRUST can fulfil this function and support in putting governance in place.
Is data breach notification mandatory under the PDPO?
As of 2026, data breach notification to the PCPD and affected individuals is voluntary, guided by the PCPD’s Guidance on Data Breach Handling and Data Breach Notifications. Reform proposals introducing a mandatory regime have been under discussion but are not yet in force. We recommend establishing a breach-response process in advance.
How are cross-border transfers of clinical trial data handled?
Section 33 of the PDPO, which would restrict cross-border transfers, has not yet been brought into force and has no confirmed implementation timetable. In the meantime, cross-border transfers remain subject to the applicable requirements of the PDPO, including the Data Protection Principles and the use of Recommended Model Contractual Clauses to provide appropriate safeguards for personal data transferred outside Hong Kong. We help review informed consent forms, assess and document cross-border data flows, conduct appropriate due diligence, and implement contractual, organisational and technical safeguards for international transfers of clinical trial data.
Need more information about MyData-TRUST? Get in touch with our experts.
MyData-TRUST offers global coverage

