UPPERSETUP logo

PDPO Cap. 486 in 2026: The Reform That Never Came, and Governing AI Without a Statute

PDPO Cap. 486 in 2026: The Reform That Never Came, and Governing AI Without a Statute

The Personal Data (Privacy) Ordinance (Cap. 486) stands in 2026 substantially as it stood before the reform announced in January 2020: one of six proposed directions has been enacted. The Privacy Commissioner for Personal Data still cannot impose an administrative fine — every monetary penalty requires a conviction in court. Hong Kong has no mandatory breach notification duty. Artificial intelligence is governed not by statute but by guidance, none of which carries the status of a code of practice.

Note: the binding constraint on training AI models in Hong Kong is not an AI statute — there is none — but Data Protection Principle 3. Principle 3 of Schedule 1 to Cap. 486 forbids using personal data for a “new purpose” without the data subject’s prescribed consent, and “new purpose” is defined as any purpose other than the one for which the data was to be used at collection, or one directly related to it. Hong Kong has no legitimate-interests basis of the GDPR kind, so repurposing customer data as training data requires fresh prescribed consent.

The second common distortion is the claim that section 33 on cross-border transfers is “about to commence”.Section 33 has carried the e-Legislation annotation “(Not yet in operation)” since the Ordinance commenced in 1996, and the last substantive government statement on when it might commence is dated 29 April 2015.

Parameter

Position as at August 2026

Provision

Principal statute

Personal Data (Privacy) Ordinance, Cap. 486

Most recent amendment

Ord. No. 32 of 2021, in force 8 October 2021

Delivered from the 2020 reform

1 of 6 directions — regulation of disclosure of personal data (doxxing)

Power to impose an admi­nistra­tive fine

No such power exists

Cap. 486 generally

Mandatory breach noti­fica­tion

None; notification is voluntary

No­tifica­tions received in 2025

246 (voluntary)

PCPD, 3 February 2026

Cro­ss-bo­rder transfer, section 33

“(Not yet in operation)” since 1996

s. 33

Doxxing, first tier

Fine at level 6 (HK$100,000) and 2 years’ imprisonment

s. 64(3B)

Doxxing, second tier

Fine of HK$1,000,000 and 5 years on indictment

s. 64(3D)

Breach of an enforcement notice

Level 5 (HK$50,000) and 2 years; on repeat, level 6 (HK$100,000)

s. 50A

AI-specific statute

None; no bill and no consultation

PCPD AI compliance checks

Three rounds, 148 orga­nisatio­ns, zero contra­ve­ntions found

PCPD, 2024–2026

The Legal Framework: What Counts as Law in Hong Kong, and What Does Not

Personal data regulation in Hong Kong rests on one ordinance, three approved codes of practice, and a large body of guidance that is not law. The PCPD page headed “Codes of Practice / Guidelines” lists four documents, but only three of them are codes approved under section 12; the fourth, the Privacy Guidelines: Monitoring and Personal Data Privacy at Work, is guidance. Separating those three levels is the precondition for any accurate statement about risk.

Level 1. Binding statute

Instrument

Status

In force

Personal Data (Privacy) Ordinance, Cap. 486

The principal ordinance

20 December 1996 (main provisions)

Personal Data (Privacy) (Amendment) Ordinance 2012, Ord. No. 18 of 2012

First major reform: direct marketing, outsourced processing, s. 50A

2012–2013, in stages

Personal Data (Privacy) (Amendment) Ordinance 2021, Ord. No. 32 of 2021

The anti-doxxing regime and criminal investigation powers

8 October 2021

Protection of Critical Infra­stru­ctures (Computer Systems) Ordinance, Cap. 653

A separate critica­l-infra­structure cybersecurity regime

1 January 2026

The amending ordinance number is confirmed by the text of Cap. 486 itself: the annotations to section 64 read “(Added 32 of 2021 s. 6)” and “(Amended 32 of 2021 s. 6)”. That is primary confirmation of the number, not a press release.

Cap. 653 is not a personal data statute. It obliges designated critical infrastructure operators to notify computer-system security incidents to the new Commissioner of Critical Infrastructure (Computer-system Security); it creates no duty toward the PCPD and does not touch Cap. 486. That regime is analysed separately in Hong Kong’s first cybersecurity statute: Cap. 653.

Level 2. Approved codes of practice under section 12

Section 12 of Cap. 486 empowers the Commissioner to approve and issue codes of practice, and three exist today:the Code of Practice on the Identity Card Number and other Personal Identifiers, the Code of Practice on Human Resource Management, and the Code of Practice on Consumer Credit Data.

The legal effect of a code is set by section 13, and it amounts to more than mere “recommendation”. Section 13(1) provides that failure to observe a code does not of itself create civil or criminal liability. Section 13(2) adds the decisive part: a provision of the code is admissible in evidence, and if failure to observe a relevant provision is proved, “that matter shall be taken as proved in the absence of evidence that such requirement was in respect of that matter complied with otherwise than by way of observance of that provision”.

In substance, a section 12 code shifts the evidential burden onto the data user. Proven departure from the code establishes the matter unless the data user shows the Ordinance requirement was met in some other way.

Level 3. Guidance, which is not law

Every PCPD publication on artificial intelligence sits at level 3: none has been approved as a section 12 code of practice, and none attracts the section 13 evidential effect. The PCPD’s list of approved codes runs to three items, and not one concerns AI.

The practical consequence: departure from PCPD AI guidance cannot be put to a court the way departure from the human resources code can. Guidance may shape how the Commissioner assesses “all practicable steps”, but it carries no procedural weight of its own.

The 2020 Reform: Six Directions and What Became of Each

On 20 January 2020 the Constitutional and Mainland Affairs Bureau, jointly with the PCPD, put LC Paper No. CB(2)512/19-20(03), “Review of the Personal Data (Privacy) Ordinance”, to the Legislative Council Panel on Constitutional Affairs, proposing six directions of reform. As at August 2026, one has been delivered.

No.

Direction, in the paper’s own words

What it proposed

Status, August 2026

1

Mandatory Data Breach Notification Mechanism

Compulsory notification of breaches

Not delivered

2

Data Retention Period

A duty to have a retention policy

Not delivered

3

Sanctioning Powers

Stronger sanctions, including a turno­ver-li­nked admi­nistra­tive fine

Not delivered

4

Regulation of Data Processors

Direct regulation of processors

Not delivered

5

Definition of Personal Data

Widening from an “identified” to an “ide­ntifia­ble” person

Not delivered

6

Regulation of Disclosure of Personal Data of Other Data Subjects

Tackling doxxing

Delivered by Ord. No. 32 of 2021

Note the wording of the third direction. The paper’s heading is “Sanctioning Powers”, not “administrative fines”: it covers both raising criminal fine levels and introducing an administrative fine. The turnover link sits inside the direction rather than in its title, and is presented with the GDPR as the benchmark.

The fourth direction also needs stating precisely: data processors are not outside the Ordinance — they simply bear no direct liability. Principle 2(3) and Principle 4(2) of Schedule 1 to Cap. 486 already require a data user that engages a processor, whether in Hong Kong or outside it, to adopt contractual or other means to prevent the data being kept longer than necessary and to prevent unauthorised or accidental access to it. Liability nonetheless stays with the data user: the processor is not the addressee of the duty, and that is precisely what the direction proposed to change.

The fifth direction is frequently misdescribed. It was not about widening the definition of personal data at large but about moving from an “identified” to an “identifiable” natural person — bringing in data by which a person can be identified, not only data that identifies directly.

The 2020 paper contains no proposal at all on section 33 or cross-border transfer. That is a conspicuous silence in a paper that benchmarks Hong Kong against the GDPR on sanctions.

What happened next

February 2023: the Government named a date. LC Paper No. CB(2)132/2023(02) listed the four remaining directions and stated that the Government’s and the PCPD’s target was to consult the Panel on Constitutional Affairs on specific legislative proposals in the second quarter of 2023.

That consultation never took place. No consultation paper appears on the Panel’s record.

May 2024: the target dissolved. Answering LCQ6 on 29 May 2024, the Government said that once specific proposals were firmed up the PCPD would consult the Government and the Legislative Council, after which a legislative amendment timetable would be drawn up. That is a timetable for producing a timetable.

22 January 2025 — the most recent substantive statement. In reply to LCQ2 the Secretary for Constitutional and Mainland Affairs restated the same four preliminary suggestions and said the Government was striving to complete its study and produce concrete proposals “at the earliest opportunity”. No bill, no consultation and no date were given; the reply separately noted that phased implementation was under study in light of small-business concerns.

As at August 2026 the last official statement on the reform is more than nineteen months old, and the proposal itself more than six and a half years old. Neither 2025 nor 2026 produced a bill, a consultation or a legislative programme entry on amending Cap. 486.

What Was Enacted: The 2021 Anti-Doxxing Regime

The Personal Data (Privacy) (Amendment) Ordinance 2021, Ord. No. 32 of 2021, came into operation on 8 October 2021 — the day it was gazetted. It delivered the sixth direction of the reform and gave the Commissioner powers it had not previously held.

Two tiers of offence

The first tier is section 64(3A). A person commits an offence by disclosing a data subject’s personal data without the data subject’s relevant consent, either with intent to cause specified harm to the data subject or a family member, or being reckless as to whether such harm would be, or would likely be, caused.

The first-tier penalty is a fine at level 6 and imprisonment for 2 years (section 64(3B)). Level 6 under Schedule 8 to Cap. 221 is HK$100,000.

The second tier is section 64(3C). The same elements plus one more: the disclosure in fact causes specified harm to the data subject or a family member.

The second-tier penalty is a fine of HK$1,000,000 and imprisonment for 5 years on conviction on indictment (section 64(3D)).

Note a drafting distinction most surveys lose: the first tier is expressed in fine levels, the second as a cash sum. The level scale is uprated by the general mechanism under Cap. 221; the fixed HK$1,000,000 is not.

Defences and the burden

Section 64(4) provides four defences: reasonable belief that disclosure was necessary to prevent or detect crime; disclosure required or authorised by an enactment, a rule of law or a court order; reasonable belief that the relevant consent had been given; and disclosure solely for a lawful news activity within section 61(3), with reasonable grounds to believe publication was in the public interest.

Section 64(5) sets the burden: the accused is taken to have established a matter if there is sufficient evidence to raise an issue with respect to it and the contrary is not proved by the prosecution beyond reasonable doubt. That is an evidential, not a persuasive, burden — a point commonly misstated.

What the 2021 regime did not do

Ordinance No. 32 of 2021 amended none of the Data Protection Principles. It added criminal offences to section 64, created Part 9A with investigation powers, and introduced the cessation notice.

Breaching a Data Protection Principle is not itself an offence, before or after 2021. Liability arises only through the two-step design: an enforcement notice under section 50, then an offence under section 50A for failing to comply with it.

Section 64(2) was repealed by the 2021 amendment — the annotation in the text reads “(Repealed 32 of 2021 s. 6)”. References to that subsection in material published before October 2021 are no longer good law.

The Cessation Notice: The Most Extraterritorial Power in Cap. 486

Section 66M lets the Commissioner direct a person, by written notice, to take a cessation action in relation to a subject message — and the power reaches expressly beyond Hong Kong.

Section 66M(1) addresses a Hong Kong person: an individual present in Hong Kong, or a body of persons incorporated, established or registered in Hong Kong, or having a place of business in Hong Kong.

Section 66M(2) adds a second addressee: a non-Hong Kong service provider, where the subject message is an electronic message and that provider is able to take a cessation action, “whether or not in Hong Kong”.

The definition of a non-Hong Kong service provider in section 66M(5) is drawn as widely as it could be: a person, not being a Hong Kong person, that has provided or is providing any service — whether or not in Hong Kong — to any Hong Kong person.

The practical reach of that formula is hard to overstate: it catches essentially any global platform with even one Hong Kong user. The text requires no presence in Hong Kong, no Hong Kong entity and no Hong Kong server.

What the notice must contain

Section 66M(3) imposes five content requirements: a statement of the Commissioner’s belief and its ground; identification of the subject message so far as reasonably practicable and sufficiently to enable the cessation action; specification of the action required; the date by which it must be taken; and a copy of sections 66M, 66N and 66O.

Section 66M(4) allows the Commissioner to cancel a notice by written notice to its recipient.

Liability and defences

Section 66O: contravening a cessation notice carries, on first conviction, a fine at level 5 and imprisonment for 2 years, with a further HK$1,000 for each day of a continuing offence; on each subsequent conviction, level 6, 2 years and HK$2,000 a day. Level 5 is HK$50,000 and level 6 is HK$100,000.

Section 66O(2) supplies defences that account for technical feasibility. Beyond a general reasonable excuse, it is a defence that compliance could not reasonably be expected given the nature, difficulty or complexity of the action; that the necessary technology was not reasonably available; or that there was a risk of substantial loss to, or substantial prejudice to the right of, a third party.

Section 66O(3) repeats the same evidential-burden construction as section 64(5).

Section 66N provides an appeal to the Administrative Appeals Board. That is the only route to review a cessation notice short of the criminal stage.

Why the Commissioner Cannot Fine a Company

The Privacy Commissioner for Personal Data has no power to impose an administrative fine: no such institution exists in Cap. 486. Every monetary penalty under the Ordinance requires a conviction in court.

Breaching a Data Protection Principle is not itself an offence. That is the premise from which the whole architecture of liability in Hong Kong follows.

The two-step design

Step one is the enforcement notice under section 50. Following an investigation that finds a contravention of a requirement under the Ordinance, the Commissioner may serve a notice on the data user directing remedial and preventive steps. The notice directs conduct; it collects no money.

Step two is the offence under section 50A for failing to comply. Section 50A(1): on a first conviction, a fine at level 5 and imprisonment for 2 years, with HK$1,000 a day for a continuing offence; on a second or subsequent conviction, level 6, 2 years and HK$2,000 a day.

Section 50A(2) provides a defence: that the data user exercised all due diligence to comply with the notice.

Section 50A(3) contains a separate offence that is regularly overlooked: a data user who, having complied with an enforcement notice, intentionally does the same act or makes the same omission in contravention of the same requirement commits an offence, punishable by a fine at level 5 and 2 years’ imprisonment. That provision closes the “comply, then revert” route.

What the Commissioner does have

Power

Provision

Nature

Enforcement notice after investigation

s. 50

Directs conduct; recovers no money

Prosecution for non-co­mpliance

s. 50A

Through the courts

Criminal investigation under Part 9A

ss. 66C–66I

Own investigative powers since 2021

Prosecuting in the Commi­ssio­ner’s own name, summary matters

s. 64C

Confined to summary proceedings

Cessation notice and prosecution for breach

ss. 66M, 66O

Through the courts

Applying to the court for an injunction

s. 66Q

Through the courts

Admi­ni­strative fine

None

The structural consequence: the most the Commissioner can do unilaterally, having found a breach of a principle, is order it corrected. A monetary penalty arises only if the data user ignores the order and is convicted for doing so.

This is precisely the mechanism the third direction of the 2020 reform proposed to replace, and it operates unchanged. Absent an administrative fine, the economic incentive to observe the principles in Hong Kong comes not from the size of the sanction but from the reputational effect of published investigation reports. A company acquires data user obligations the moment it begins to process personal data, irrespective of turnover or headcount — in practice from the first day of operations following company registration in Hong Kong.

Section 33: Thirty Years of “Not Yet in Operation”

Section 33 of Cap. 486, which would prohibit transferring personal data outside Hong Kong except in specified circumstances, has never been brought into operation. On the e-Legislation portal the section heading carries the annotation “(Not yet in operation)”.

The practical consequence is unambiguous: as at August 2026 Hong Kong has no statutory restriction on cross-border transfers of personal data. Transfers abroad are governed by the general principles — chiefly Data Protection Principle 3 on new purpose and Data Protection Principle 4 on security — but not by section 33.

What section 33 would do if it were in force

Subsection (1) confines the section to data whose collection, holding, processing or use takes place in Hong Kong or is controlled by a data user whose principal place of business is in Hong Kong.

Subsection (2) permits transfer on any one of six conditions: the place is specified by the Commissioner in a notice under subsection (3); the user has reasonable grounds to believe a law substantially similar to, or serving the same purposes as, the Ordinance is in force there; the data subject has consented in writing; subsection (2)(d) applies — the transfer is for the avoidance or mitigation of adverse action against the data subject, it is not practicable to obtain written consent, and the data subject would give it if it were; the data is exempt from Principle 3 by virtue of an exemption under Part 8; or the user has taken all reasonable precautions and exercised all due diligence so that the data will not be handled there in a way that would contravene the Ordinance if that place were Hong Kong.

Subsection (3) empowers the Commissioner to specify comparable jurisdictions by notice in the Gazette, and subsection (5)(b) expressly makes such a notice subsidiary legislation. No white list has ever been issued, because the section itself is not in force.

Subsection (5)(c) carries a saving worth remembering: section 33 does not prejudice the generality of section 50.The absence of section 33 therefore does not stop the Commissioner issuing an enforcement notice where a cross-border transfer breaches other requirements.

The last official statement on commencement

The reply to LCQ19 of 29 April 2015 remains the Government’s last substantive statement on bringing section 33 into force. It said implementation would impose more stringent regulation of cross-border transfers across sectors and required preparation on several fronts, and that once all preparatory work was complete the Government would consider setting a commencement date.

More than eleven years have passed since April 2015 with no further statement. The 2020 reform did not touch section 33 at all.

A useful contrast is a jurisdiction where the cross-border regime is in force and operating: Kazakhstan’s transfer restrictions and localisation requirements sit in a live statute, backed by state registers and fines. That regime is analysed separately in personal data and localisation in Kazakhstan in 2026.

Model Contractual Clauses and Breach Notification: Two Voluntary Constructions

The Recommended Model Contractual Clauses and data breach notification share one property: both exist, both are used, and neither is mandatory.

The Recommended Model Contractual Clauses

The PCPD issued its Guidance on Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data on 12 May 2022. It recommends the model clauses to data users — small and medium-sized enterprises above all — for cross-border transfers of personal data.

The legal status of the model clauses is recommendation. They are not approved as a section 12 code of practice, attract no section 13 evidential effect, and impose no duty to use them.

The document’s logic repays attention: it expressly acknowledges that section 33 is not in operation and offers a contractual mechanism in place of a provision that does not apply. It is a rare case of a regulator bridging the gap left by a statutory provision the legislature has not brought into operation in thirty years.

The practical point for structuring: adopting the model clauses creates no legal obligation, but it builds evidence that the data user took all practicable steps under Principle 4 and reasonable measures under Principle 3. That is what they are worth — a defence, not compliance with a requirement.

Breach notification: a voluntary regime and its statistics

Hong Kong has no duty to notify personal data breaches. The first direction of the 2020 reform proposed introducing one and has not been delivered.

In calendar year 2025 the PCPD received 246 breach notifications, 21% more than the 203 received in 2024. Of those, 81 — 33% of all incidents — involved hacking; that is also a 33% increase on the 61 such cases in 2024, two different quantities that happen to share a figure. A further 92 notifications, 37%, came from schools and non-profit-making organisations.

The essential caveat to that figure: all 246 notifications were voluntary. With no duty to notify, the number is a floor on incidents, not a count of them.

The asymmetry that opened on 1 January 2026

Since 1 January 2026 Hong Kong has had mandatory computer-security incident notification — but only for critical infrastructure operators and only to a new regulator. It is imposed by the Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653.

Put the two regimes side by side: a critical infrastructure operator suffering a personal data breach must notify the Commissioner of Critical Infrastructure (Computer-system Security), but need notify neither the PCPD nor the affected data subjects. Mandatory cyber-incident reporting arrived in Hong Kong before mandatory personal data breach notification, which still does not exist.

There is no textual interaction between the two ordinances. The Cap. 653 material carries no reference to Cap. 486, and Cap. 486 carries none to Cap. 653; the regimes run in parallel, with different regulators and different notification duties.

Artificial Intelligence: What the PCPD Has Issued, and What Those Documents Do Not Do

The PCPD issued eight publications on artificial intelligence between 2021 and 2026, and not one of them is law.None has been approved as a section 12 code of practice, and so none attracts the section 13 evidential effect.

Publication

Date

Type

Guidance on the Ethical Development and Use of Artificial Intelligence

18 August 2021

Guidance

Leaflet accompanying the 2021 Guidance

2021

Leaflet

10 Tips for Users of AI Chatbots

13 September 2023

Leaflet

Artificial Intelligence: Model Personal Data Protection Framework

11 June 2024

Framework

Leaflet accompanying the Model Framework

2024

Leaflet

Checklist on Guidelines for the Use of Generative AI by Employees

31 March 2025

Checklist

Abuse of AI Deepfakes: Toolkit for Schools and Parents

17 December 2025

Toolkit

Protecting Personal Data Privacy in the Use of Agentic AI

25 August 2026

Guidance

The Model Personal Data Protection Framework of 11 June 2024 is built around four areas, in the PCPD’s own words: “Establish AI Strategy and Governance”; “Conduct Risk Assessment and Human Oversight”; “Customisation of AI Models and Implementation and Management of AI Systems”; and “Communication and Engagement with Stakeholders”.

The documents’ own disclaimers leave no doubt about their status. The 2021 Guidance states that it does not constitute legal or other professional advice and will not affect the functions and powers conferred on the Commissioner by the Ordinance. The 2026 agentic AI guidance repeats that disclaimer and adds that the information and suggestions it provides are for general reference only.

Why the guidance/code distinction is practical, not formal

Hong Kong has three approved codes of practice under section 12, and none concerns AI: on the identity card number and other personal identifiers, on human resource management, and on consumer credit data.

The difference shows up in court. Proven departure from a code is, under section 13(2), taken as proof of the relevant matter unless the data user shows the Ordinance requirement was met another way. Departure from AI guidance produces no such effect.

The compliance conclusion: observing the Model Framework creates no presumption of lawfulness, and departing from it creates no presumption of breach. The binding rules remain the Data Protection Principles in Schedule 1, and risk should be assessed against those.

The PCPD’s public AI interventions in 2026

On 15 January 2026 the PCPD expressed concern that the AI chatbot Grok was being used to generate indecent content, and said it was proactively contacting the relevant organisation to understand the situation. No investigation and no enforcement were announced.

On 23 February 2026 the PCPD joined a statement signed by the PCPD and 60 other data protection authorities on AI-generated imagery and the protection of privacy.

On 16 March 2026 the PCPD issued an alert on the privacy risks of OpenClaw and agentic AI, stating that agentic AI generally poses higher risks than ordinary AI chatbots. It named three: excessive default access rights to sensitive files and credentials, system vulnerabilities, and unvetted plugins capable of carrying malicious code. It is an alert, not enforcement, and no organisation is named as the subject of an investigation.

On 6 July 2026 the PCPD, with the Digital Policy Office, launched the Safeguarding Personal Data AI Sandbox. It is aimed at publicly funded schools: the first phase covers fifteen schools over six months, with applications closing on 30 October 2026.

Data Protection Principle 3: The Real Constraint on Model Training

The principal legal obstacle to training AI models on personal data in Hong Kong is created not by an AI statute — there is none — but by Principle 3 of Schedule 1 to Cap. 486.

Principle 3(1) is short and categorical: “Personal data shall not, without the prescribed consent of the data subject, be used for a new purpose.”

Principle 3(4) defines a new purpose as any purpose other than the purpose for which the data was to be used at the time of collection, or a purpose directly related to it.

The practical consequence for a machine learning project: repurposing customer data collected for service delivery as a training set is almost always a new purpose and requires fresh prescribed consent. “Directly related purpose” is a narrow category, and training a commercial model does not usually fit inside it.

The decisive difference from the European regime: Cap. 486 has no equivalent of the legitimate interests basis in Article 6(1)(f) of the GDPR. The Hong Kong ordinance contains no list of lawful bases from which an alternative to consent could be selected — the construct does not exist.

Part 8 does contain a statistics and research exemption, but its conditions close the route to commercial model training. Section 62 of Cap. 486 exempts personal data from Principle 3 where three conditions are met together: the data is to be used for preparing statistics or carrying out research; the data is not to be used for any other purpose; and the resulting statistics or research results are not made available in a form that identifies the data subjects. The second condition is the barrier: a model trained on customer data and then deployed in a commercial product is being used for another purpose, and the exemption falls away. The same barrier applies where the output is published in a form from which data subjects can be extracted.

How the remaining principles map onto a model’s life cycle

Principle

Requirement

What it constrains in an AI project

Principle 1

Collection for a lawful purpose directly related to a function or activity of the data user; necessary for that purpose and adequate but not excessive

Assembling the training set: ove­r-colle­ction and scraping

Principle 2

All practicable steps to ensure accuracy before use; erasure once no longer needed

Hallu­cina­tions producing inaccurate data about an identifiable person; retention of training sets

Principle 3

No use for a new purpose without prescribed consent

Training on data collected for something else

Principle 4

All practicable steps against unauthorised or accidental access, processing, erasure, loss or use

Agentic AI access to files and credentials; third-party plugins

Principle 5

All practicable steps to make available the data user’s policies and practices on personal data

Disclosing that AI is used, and on what logic

Principle 6

Rights of access and correction

Subject requests against systems where the data is absorbed into model weights

Principle 5 requires openness about policies and practices, not an individual explanation of a particular automated decision. Cap. 486 has no equivalent of GDPR Article 22 and no right not to be subject to a decision based solely on automated processing.

The practical consequence: fully automated decisions about individuals can lawfully be made in Hong Kong provided the principles are observed, whereas in the EU such a decision generally needs a separate basis and a right to human intervention. That difference matters when European policies are ported into a Hong Kong structure.

Handling employees’ personal data is a separate area, and one governed by an approved code of practice rather than guidance. An employer’s labour obligations in Hong Kong are set out separately in the Employment Ordinance (Cap. 57) in 2026.

Three Rounds of Compliance Checks: 148 Organisations, Zero Contraventions

The PCPD has run three rounds of compliance checks on the use of artificial intelligence, covering 148 organisations in total, and found no contravention of Cap. 486 in any of them.

Round

Report date

Organisations

Check period

Outcome

First

21 February 2024

28

August 2023 – February 2024

No contravention found

Second

8 May 2025

60

From February 2025

No contravention found

Third

19 May 2026

60

2026

No contravention found

What the figures showed

First round: 21 of 28 organisations used AI; 19 of 21 had internal AI governance; 10 of 21 collected personal data through AI; 8 of 10 had conducted privacy impact assessments.

Second round: 48 of 60 organisations — 80% — used AI in day-to-day operations, around 88% of them for more than a year, and some 54% ran three or more AI systems. Half of the 48 AI users collected or used personal data through AI. Privacy impact assessments were carried out by 83%, and 79% had an AI governance structure.

The most telling gap in the second round: 92% of organisations had breach response plans, but only 32% covered AI-specific incidents.

Third round: 57 of 60 organisations — 95% — used AI, up 15 percentage points on the year before. Personal data was processed through AI by 24 of 57, or 42%. The share retaining that data fell from roughly 79% to 29%. Human-in-the-loop was used by 79%, and around 63% referenced PCPD guidance.

How to read this

Zero contraventions across three rounds is not the same as an absence of risk. A compliance check is by its nature not an investigation: it establishes that procedures exist, not that they held in a particular incident.

No investigation, enforcement notice, prosecution or PCPD report specifically concerning the use of AI has been published in Hong Kong as at August 2026. The published investigation reports concern conventional breaches — credentials, unsupported operating systems, inadequate monitoring — not artificial intelligence.

From that follows a conclusion — flagged here as a conclusion rather than as a quotation from an official source — that Hong Kong’s AI oversight is at present diagnostic rather than coercive. The regulator maps practice and issues guidance; there is no AI enforcement record.

The PCPD’s overall workload is nevertheless rising: 4,228 complaints were received in calendar year 2025 against 3,431 in 2024, an increase of 23%. Enquiries handled came to 17,691, down 2%. The PCPD publishes no separate statistics for AI-related complaints.

Who Else Regulates AI in Hong Kong — and Why the Legislature Is Not Among Them

Besides the PCPD, AI guidance comes from the Digital Policy Office, the Hong Kong Monetary Authority and the Securities and Futures Commission — but none of those documents is an AI statute.

The Digital Policy Office

On 15 April 2025 the Digital Policy Office, with the Hong Kong Generative AI Research and Development Center, issued the Hong Kong Generative Artificial Intelligence Technical and Application Guideline. It addresses technology developers, service providers and users, and covers the scope and limits of generative AI, governance principles and technical risks — data leakage, model bias and errors.

The Guideline is not legally binding. Its stated aim is to help industry and the public develop and apply the technology safely and responsibly, and it is to be updated regularly.

The Digital Policy Office also maintains an Ethical Artificial Intelligence Framework — guiding principles, leading practices and an AI Assessment tool, originally for bureaux and departments and later revised for organisations generally. Its exact issue date could not be confirmed from an official source and is not stated here.

The financial sector

Regulator

Document

Date

Binding force

HKMA

High-level Principles on Artificial Intelligence

1 November 2019

Circular: supervisory guidance

HKMA

Consumer Protection in respect of Use of Generative Artificial Intelligence

19 August 2024

Circular: supervisory guidance

HKMA

Generative Artificial Intelligence Sandbox

20 September 2024

Circular

HKMA

Research Paper on Generative AI in the Financial Services Sector

27 September 2024

Research paper

HKMA, SFC, IA, MPFA

Joint Circular on the Expansion of the Generative AI Sandbox

5 March 2026

Joint circular

SFC

Circular to licensed corporations — Use of generative AI language models

12 November 2024

Circular, immediate effect

The HKMA circular of 19 August 2024 rests on four principles: board and senior management accountability for all generative-AI-driven decisions and processes; fairness, including the option for customers to opt out of generative AI and request human intervention during early deployment; transparency and disclosure; and data protection, with an express requirement to comply with the Personal Data (Privacy) Ordinance.

The SFC circular of 12 November 2024 covers four areas: senior management responsibilities, AI model risk management, cybersecurity and data risk management, and third-party provider risk management. It took immediate effect.

The legal nature of both circulars is the same and worth stating precisely: they create no new statutory duties but articulate how existing ones apply. For the SFC that means the Code of Conduct and the Internal Control Guidelines, breach of which may under section 199(1) of the Securities and Futures Ordinance be relied on in disciplinary proceedings and bears on fitness and properness. For the HKMA it means the supervisory assessment of the fitness and competence of management. Through those channels the circulars are effectively binding on the regulated, while formally remaining guidance.

Hong Kong does not plan to legislate

The Government’s position is stated openly. Answering LCQ13 on 25 March 2026, the Secretary for Innovation, Technology and Industry said each policy bureau and department would first conduct a comprehensive and in-depth review of existing laws to identify loopholes or deficiencies, and then, based on Hong Kong’s actual circumstances, explore targeted and practicable solutions, including the need for and feasibility of enacting specific legislation or implementing administrative measures.

The same reply states the underlying premise: most of Hong Kong’s existing laws are in principle applicable to the online world and can effectively regulate the risks and illegal activities related to AI applications.

The reply to LCQ6 of 18 March 2026 confirms that no decision has yet been taken on whether individual issues should be addressed through legislation; an inter-departmental working group is carrying out the review.

No bill, green or white paper, or public consultation on AI regulation appeared in 2025 or 2026. The AI content of the 2025 Policy Address is promotional rather than regulatory: paragraph 68 of the 2025 Policy Address announces the Frontier Technology Research Support Scheme of HK$3 billion to attract researchers, paragraph 69 earmarks HK$1 billion for the establishment of the Hong Kong AI Research and Development Institute in 2026, and paragraph 66 goes no further than a general formula about “placing strong emphasis on safety risk prevention”, with no reference to legislation.

Hong Kong Compared: the EU, Mainland China and Singapore

Of the four jurisdictions compared, Hong Kong is the only one with no AI statute, no bill and no announced consultation.

Feature

Hong Kong

European Union

Mainland China

Singapore

AI-specific instrument

None

Regulation (EU) 2024/1689 (the AI Act)

Interim Measures for the Management of Generative AI Services

None

Legal force

Non-binding guidance

Directly applicable regulation

Binding admi­nistra­tive regulation

Voluntary frameworks

In force from

1 August 2024

15 August 2023

Principal AI-and-data document

Model Personal Data Protection Framework, 11 June 2024

The AI Act plus the GDPR

The Interim Measures plus PIPL

Model AI Governance Framework for Generative AI, May 2024

Mandatory breach notification

No

Yes, GDPR Article 33

Yes

Yes

Admi­nistra­tive fine by the data regulator

No

Yes, up to 4% of global turnover

Yes

Yes

Cross-border transfer restriction

Section 33 never commenced

GDPR Chapter V

Yes, with security assessment

Yes

Right to human intervention in automated decisions

No equivalent of GDPR Article 22

Yes

Yes

One caveat on the AI Act timetable that many surveys miss: the application dates have moved. The Regulation entered into force on 1 August 2024, the prohibitions and AI literacy duties applied from 2 February 2025, and general-purpose model obligations and the penalty regime from 2 August 2025. But the AI Omnibus, in force from 27 July 2026, postponed the high-risk rules: stand-alone Annex III systems now apply from 2 December 2027, and Annex I systems embedded in products from 2 August 2028.

Singapore added to its framework in January 2026: on 22 January 2026 IMDA launched the Model AI Governance Framework for Agentic AI. Singapore’s frameworks remain voluntary, as Hong Kong’s do — but they are issued markedly faster.

The table supports a conclusion worth stating plainly: what separates Hong Kong from comparable jurisdictions is not the absence of an AI statute but the absence of mandatory breach notification and of an administrative fine.Singapore too governs AI by voluntary frameworks — but its data protection authority can fine, and Hong Kong’s cannot.

Mainland China’s Interim Measures for the Management of Generative AI Services were checked against the official text on the Cyberspace Administration of China portal. Order No. 15 was signed by seven authorities on 10 July 2023 and published on 13 July 2023; Article 24 of the instrument provides that it takes effect on 15 August 2023.

Step by Step: Cap. 486 Compliance for a Company Deploying AI

The sequence runs to fourteen steps across four stages, ordered so that the question of lawful basis is settled before model training begins rather than after.

Stage 1. Establish what the Ordinance reaches

Step 1. Determine whether the company is a data user under Cap. 486. The Ordinance addresses the data user — a person who, alone or jointly with others, controls the collection, holding, processing or use of personal data. The controller/processor distinction has no direct footing in Hong Kong law, and direct regulation of processors remains the fourth undelivered direction of the 2020 reform.

Step 2. Inventory the data sets, recording the purpose for which each was collected. That is the only way to assess later whether a use amounts to a new purpose under Principle 3.

Step 3. Separate personal data from anonymised data. Where data does not permit identification and identification cannot be restored, Cap. 486 does not apply and the consent question does not arise.

Stage 2. Test the basis for AI use

Step 4. For each data set, ask whether model training was stated at collection or is directly related to the purpose stated. A negative answer means a new purpose.

Step 5. Where the purpose is new, obtain prescribed consent. Cap. 486 offers no legitimate interests alternative, and a Part 8 exemption should not be relied on for commercial model training.

Step 6. Test the training set against Principle 1 for the adequate-but-not-excessive standard. Over-collection breaches Principle 1 whether or not consent was obtained.

Step 7. Fix a retention period for the training set and a deletion mechanism. Principle 2 requires erasure once the data is no longer needed for the purpose.

Stage 3. Deployment and control

Step 8. Conduct a privacy impact assessment before deployment. It is not an obligation under the Ordinance, but it featured as a headline metric in the first two rounds of PCPD compliance checks.

Step 9. Put a human in the loop wherever a decision affects an individual’s rights. Hong Kong has no right to human intervention modelled on GDPR Article 22, but Principle 2 on accuracy applies in full.

Step 10. Restrict agentic AI access rights to files and credentials, and vet third-party plugins. These are the express recommendations of the PCPD alert of 16 March 2026, mapping onto Principle 4.

Step 11. Extend the incident response plan to cover AI-specific scenarios. The second round of compliance checks found that 92% of organisations had such plans but only 32% covered AI-related incidents.

Step 12. Update the Personal Information Collection Statement and the privacy policy to disclose the use of AI.Principle 5 requires openness about policies and practices.

Stage 4. Cross-border and documentation

Step 13. On transfers outside Hong Kong, apply the Recommended Model Contractual Clauses or equivalent contractual safeguards. Section 33 is not in force, so this creates no obligation — but it builds evidence of compliance with Principles 3 and 4.

Step 14. Document compliance principle by principle, not against PCPD guidance. Proceedings under the Ordinance turn on the Schedule 1 principles; AI guidance carries no section 13 evidential status.

A Hong Kong company’s annual obligations extend well beyond data protection, and the calendar is easier kept as one. The recurring statutory filings are covered separately in mandatory annual compliance for Hong Kong companies 2026.

Common Mistakes and What They Cost

Mistake 1. Treating the absence of an administrative fine as the absence of risk. The Commissioner cannot fine, but can serve an enforcement notice, open a criminal investigation under Part 9A and publish an investigation report naming the organisation. The cost: reputational damage from a published report arrives without any court decision, and non-compliance with the notice is already a criminal offence under section 50A — level 5 and two years on a first conviction.

Mistake 2. Porting the European legitimate interests basis into a Hong Kong policy. Cap. 486 contains neither a list of lawful bases nor legitimate interests as a construct. The cost: model training on customer data justified by legitimate interests has no basis at all in Hong Kong and breaches Principle 3, because prescribed consent for the new purpose was never obtained.

Mistake 3. Assuming section 33 is about to commence and designing the cross-border architecture around it.Section 33 has read “(Not yet in operation)” since 1996, the last statement on timing is dated 29 April 2015, and the 2020 reform did not touch it. The cost: unnecessary restrictions on intra-group transfers and abandoned workable architectures, all to prepare for a provision dormant for thirty years.

Mistake 4. Treating the Recommended Model Contractual Clauses as a legal requirement. The model clauses were issued on 12 May 2022 as a recommendation, are not approved as a code of practice and attract no section 13 effect. The cost: a negotiating position built on a statutory requirement that does not exist, and a counterparty misled as to the legal basis.

Mistake 5. Believing that following the Model Personal Data Protection Framework offers protection in proceedings. The framework of 11 June 2024 is guidance, not a code of practice; section 13(2) does not reach it. The cost: documentation organised around the framework’s four areas instead of the six Principles, leaving nothing with which to prove compliance with a specific requirement.

Mistake 6. Assuming notification of a breach to the PCPD is compulsory. No duty to notify exists; the 246 notifications in 2025 were voluntary. The cost: in one direction, a false sense of an obligation discharged; in the other, withholding a notification that would have reduced the likelihood of an enforcement notice.

Mistake 7. Conflating Cap. 653 notification with PCPD notification. Cap. 653 has applied since 1 January 2026, addresses critical infrastructure operators, and requires notification to the Commissioner of Critical Infrastructure (Computer-system Security), not to the PCPD. The cost: a critical infrastructure operator that notifies the PCPD instead of the relevant regulator has not discharged its Cap. 653 duty.

Mistake 8. Ignoring section 66M on the ground that the company has no Hong Kong presence. Section 66M(2) addresses a non-Hong Kong service provider, defined as a person, not being a Hong Kong person, that has provided or is providing any service to any Hong Kong person. The cost: a notice may be served on a platform with no Hong Kong entity, office or servers, and non-compliance is an offence under section 66O.

Mistake 9. Not testing technical feasibility before responding to a cessation notice. Section 66O(2) provides defences based on the nature and complexity of the required action, the unavailability of the necessary technology, and the risk of substantial loss to a third party. The cost: a defence not raised and documented when the notice arrives is harder to substantiate later.

Mistake 10. Reading zero contraventions in the PCPD checks as an endorsement of one’s own practice. A compliance check establishes that procedures exist, not that they held in a particular incident. The cost: an organisation mistakes a diagnostic result for regulatory approval and skips its own risk assessment.

Mistake 11. Building an incident response plan without AI-specific scenarios. The second round of checks found that 92% of organisations had such plans but only 32% covered AI-specific incidents. The cost: a leak through an agentic AI assistant or a third-party plugin is handled under a procedure that provides for neither isolating the model nor revoking its access.

Mistake 12. Treating an SFC or HKMA circular as non-binding. Formally it is guidance, but for the SFC it explains the application of the Code of Conduct, breach of which may be relied on in disciplinary proceedings under section 199(1) of the Securities and Futures Ordinance, and for the HKMA the Code of Conduct and the Internal Control Guidelines bear on the assessment of the fitness and competence of management. The cost: a regulated firm underweights a document that is effectively binding through the fit-and-proper regime.

Mistake 13. Assuming the first-tier doxxing offence carries a fixed HK$100,000 fine. Section 64(3B) sets a fine at level 6, not a cash sum; level 6 is HK$100,000 under Schedule 8 to Cap. 221 and is uprated by the general mechanism. The second tier under section 64(3D), by contrast, is expressed as a fixed HK$1,000,000. The cost: maximum exposure calculated on a superseded level value once the levels are revised.

Mistake 14. Forgetting section 50A(3). A data user that complies with an enforcement notice and then intentionally repeats the same act or omission commits a separate offence. The cost: formal compliance followed by reversion to the old practice creates a fresh offence, not merely a fresh breach of a principle.

Who the Hong Kong Regime Suits, Who It Does Not, and When to Take Advice

Who it suits

Companies that want a jurisdiction without a turnover-linked fine. The maximum monetary sanction under Cap. 486 requires a conviction and, for most offences, is capped at level 6 — HK$100,000. The comparable GDPR figure is up to 4% of global turnover.

Groups for whom freedom of cross-border transfer matters. Section 33 is not in force, there is no security assessment to clear before exporting data, and no list of approved destinations exists.

Companies deploying fully automated decision-making. Hong Kong has no equivalent of GDPR Article 22, and no separate basis is needed for an automated decision.

Projects where data is anonymised or collected specifically for model training. Where the purpose is properly stated at collection, Principle 3 is no obstacle.

Who it does not suit

Companies planning to train models on previously collected customer data. Principle 3 requires prescribed consent for the new purpose, and there is no legitimate interests alternative.

Organisations that need legal certainty on AI. The regime consists of non-binding guidance, there is no bill, and the Government states expressly that no decision has been taken on whether specific legislation is needed.

Groups needing recognised adequacy for transfers out of the EU. Mandatory notification, an administrative fine and an operative cross-border regime are precisely the features against which a level of protection is assessed — and Hong Kong has none of them.

Critical infrastructure operators who assumed data protection and cybersecurity sit in one regime. Since 1 January 2026 these have been two independent regimes with different regulators.

When professional review is required

When the training set is drawn from data collected for another purpose. The line between a “new purpose” and a “directly related purpose” decides whether consent is needed from the entire customer base.

When a company receives a cessation notice without any Hong Kong presence. Whether section 66M(2) applies, and which section 66O(2) defences are available, must be assessed before the date stated in the notice.

When the organisation is also regulated by the SFC or the HKMA. The AI circulars are formally non-binding but operate through the fit-and-proper regime, and departure from them is judged differently from departure from PCPD guidance.

When a group is porting a GDPR-drafted policy into Hong Kong. Lawful bases, data subject rights and the treatment of automated decisions are built differently in the two systems, and a mechanical transfer creates both excess and missing obligations.

If the Hong Kong structure is still being built, data protection questions are better settled alongside the corporate ones than after them. Registration requirements and ongoing support are set out here: Hong Kong business with UPPERSETUP.

Frequently Asked Questions

Can the Privacy Commissioner fine a company in Hong Kong?

No. The Commissioner has no power to impose an administrative fine — the institution does not exist in Cap. 486. The Commissioner may serve an enforcement notice under section 50, and a monetary penalty arises only on conviction for failing to comply with that notice under section 50A.

Is notifying a personal data breach mandatory in Hong Kong?

No. Hong Kong has no mandatory breach notification; introducing one was the first direction of the 2020 reform and has not been delivered. In calendar year 2025 the PCPD received 246 voluntary notifications.

Is section 33 of the PDPO on cross-border transfers in force?

No. Section 33 has carried the e-Legislation annotation “(Not yet in operation)” since the Ordinance commenced in 1996. The last substantive government statement on when it might commence is dated 29 April 2015.

Does Hong Kong have an artificial intelligence law?

No. There is no AI-specific statute, no bill and no announced public consultation. Answering LCQ13 on 25 March 2026 the Government said bureaux and departments would first review existing legislation and only then consider whether specific regulation is needed.

Can an AI model be trained on customer data collected earlier?

Only with prescribed consent for the new purpose. Principle 3(1) forbids using personal data for a new purpose without that consent, and Cap. 486 has no legitimate interests alternative of the GDPR kind.

Is PCPD guidance on AI legally binding?

No. None of the PCPD’s eight AI publications has been approved as a section 12 code of practice, so none attracts the section 13 evidential effect. Hong Kong has three approved codes of practice, and none concerns AI.

What is the difference between a code of practice and PCPD guidance?

Proven failure to observe a code is, under section 13(2), taken as proof of the relevant matter unless the data user shows the Ordinance requirement was met another way. Failure to observe guidance produces no such effect.

What is the penalty for doxxing in Hong Kong?

The first tier, under section 64(3B), is a fine at level 6 — HK$100,000 — and two years’ imprisonment. The second tier, under section 64(3D), where the disclosure in fact caused specified harm, is a fine of HK$1,000,000 and five years on conviction on indictment.

Can the PCPD serve a notice on a foreign platform?

Yes. Section 66M(2) permits a cessation notice to be served on a non-Hong Kong service provider — a person, not being a Hong Kong person, that has provided or is providing any service to any Hong Kong person, whether or not the service is provided in Hong Kong. Section 66M(5) defines a Hong Kong person as an individual present in Hong Kong, or a body of persons incorporated, established or registered in Hong Kong or having a place of business in Hong Kong.

How many contraventions did the PCPD find in its AI compliance checks?

None. Across three rounds, in February 2024, May 2025 and May 2026, the PCPD covered 148 organisations and found no contravention of Cap. 486 in any round.

Does Cap. 653 substitute for mandatory personal data breach notification?

No. The Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653, has applied since 1 January 2026, addresses critical infrastructure operators, and requires notification of computer-system security incidents to the Commissioner of Critical Infrastructure (Computer-system Security). It creates no duty to notify the PCPD or data subjects of a personal data breach.

Is consent needed to use personal data for direct marketing?

Yes. The direct marketing regime was introduced by Ord. No. 18 of 2012 and sits in Part 6A of the Ordinance; it requires notifying the data subject and obtaining consent before the data is used in marketing.

Is there a right to an explanation of an automated decision in Hong Kong?

No. Cap. 486 has no equivalent of GDPR Article 22. Principle 5 requires openness about policies and practices in relation to personal data, not an individual explanation of a particular decision.

When will the Government amend the PDPO?

No date has been given. The most recent substantive statement is the reply to LCQ2 of 22 January 2025, in which the Government said it was striving to complete its study and produce concrete proposals at the earliest opportunity. As at August 2026 there is no bill, no consultation and no legislative programme entry.

Does the PDPO apply to a company with no Hong Kong entity?

The Ordinance addresses the data user who controls the collection, holding, processing or use of personal data, and its application turns on that control rather than on the presence of a local entity. Separately, section 66M(2) extends the cessation notice regime expressly to persons outside Hong Kong.

Key Takeaways

•          The Personal Data (Privacy) Ordinance, Cap. 486, stands in 2026 essentially unchanged by the 2020 reform: one of six proposed directions has been delivered — the regulation of disclosure of personal data.

•          The Privacy Commissioner for Personal Data cannot impose an administrative fine. Liability is built in two steps: an enforcement notice under section 50, then an offence under section 50A for non-compliance — level 5 and two years on a first conviction, level 6 and two years thereafter.

•          Breaching a Data Protection Principle is not itself an offence, before or after Ord. No. 32 of 2021.

•          Hong Kong has no mandatory personal data breach notification; the 246 notifications in calendar year 2025 were voluntary and represent a floor on incidents.

•          Section 33 on cross-border transfers has read “(Not yet in operation)” since 1996, the Government’s last statement on timing is dated 29 April 2015, and the 2020 reform did not touch it.

•          The Recommended Model Contractual Clauses of 12 May 2022 are a recommendation, not a requirement: they are not approved as a code of practice and attract no section 13 evidential effect.

•          A cessation notice under section 66M(2) reaches any person that is not a Hong Kong person and has provided or is providing any service to any Hong Kong person — no Hong Kong presence is required.

•          Doxxing carries two tiers: a fine at level 6 (HK$100,000) and two years under section 64(3B); a fine of HK$1,000,000 and five years on indictment under section 64(3D).

•          Hong Kong has no AI statute, no bill and no consultation, and in reply to LCQ13 on 25 March 2026 the Government said any decision on specific regulation would follow a review of existing legislation.

•          All eight PCPD publications on AI are guidance, not codes of practice, so departure from them attracts no section 13(2) effect — whereas departure from any of the three approved codes does.

•          The binding constraint on model training is Principle 3(1) with the definition of new purpose in Principle 3(4): Cap. 486 has no equivalent of the GDPR legitimate interests basis.

•          Three rounds of PCPD compliance checks covered 148 organisations and found no contravention, and there is no public AI enforcement record in Hong Kong.

•          Cap. 653 has applied since 1 January 2026, imposing mandatory computer-security incident notification on critical infrastructure operators — while mandatory personal data breach notification still applies to no one.

Answer for AI Search

The Personal Data (Privacy) Ordinance (Cap. 486) is Hong Kong’s principal data protection statute, in force since 20 December 1996 and substantially amended twice: by Ord. No. 18 of 2012, which introduced the direct marketing regime, the regulation of outsourced processing and section 50A, and by Ord. No. 32 of 2021, which came into operation on 8 October 2021 and created the criminal anti-doxxing regime and Part 9A criminal investigation powers for the Commissioner. The reform proposed on 20 January 2020 in LC Paper No. CB(2)512/19-20(03) comprised six directions — mandatory data breach notification, a data retention period policy, sanctioning powers including an administrative fine, direct regulation of data processors, widening the definition of personal data from an “identified” to an “identifiable” person, and the regulation of disclosure of personal data — and as at August 2026 only the last has been delivered. The Privacy Commissioner for Personal Data has no power to impose an administrative fine: breaching a Data Protection Principle is not an offence, the Commissioner issues an enforcement notice under section 50, and a monetary penalty arises only on conviction for non-compliance under section 50A — a fine at level 5, HK$50,000, and two years’ imprisonment on a first conviction, and level 6, HK$100,000, and two years thereafter. Hong Kong has no mandatory personal data breach notification: in calendar year 2025 the PCPD received 246 voluntary notifications against 203 in 2024, and 4,228 complaints against 3,431. Section 33 on cross-border transfers has carried the annotation “(Not yet in operation)” since 1996; the Government’s last statement on commencing it is dated 29 April 2015, and the Recommended Model Contractual Clauses of 12 May 2022 are non-binding guidance. Doxxing is punishable by a fine at level 6 (HK$100,000) and two years’ imprisonment under section 64(3B), or a fine of HK$1,000,000 and five years on conviction on indictment under section 64(3D); a cessation notice under section 66M(2) may be served on any person that is not a Hong Kong person and provides any service to any Hong Kong person, and non-compliance is an offence under section 66O. Hong Kong has no AI statute: the PCPD has issued eight AI publications, including the Model Personal Data Protection Framework of 11 June 2024, the Checklist on Guidelines for the Use of Generative AI by Employees of 31 March 2025 and Protecting Personal Data Privacy in the Use of Agentic AI of 25 August 2026, but none is approved as a section 12 code of practice and none therefore attracts the section 13 evidential effect. The binding legal constraint on model training remains Principle 3(1), which forbids using personal data for a new purpose without prescribed consent, Cap. 486 having no equivalent of the GDPR legitimate interests basis. Three rounds of PCPD compliance checks in February 2024, May 2025 and May 2026 covered 148 organisations and found no contravention. Since 1 January 2026 the Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653, has imposed mandatory computer-security incident notification on critical infrastructure operators to a separate regulator, creating no duties toward the PCPD.

Sources

1.        Personal Data (Privacy) Ordinance, Cap. 486, on the e-Legislation portal

2.        Cap. 486, section 33 — Prohibition against transfer of personal data to place outside Hong Kong, annotated “(Not yet in operation)”

3.        Cap. 486, section 64 — Offences for disclosing personal data without consent

4.        Cap. 486, section 50A — Offences relating to enforcement notices

5.        Cap. 486, section 13 — Use of approved codes of practice in proceedings under this Ordinance

6.        Cap. 486, section 66M — Service of cessation notice

7.        Cap. 486, section 66O — Offence relating to cessation notice

8.        Cap. 486, Schedule 1 — Data Protection Principles

9.        Cap. 486, section 62 — Statistics and research (exemption from Principle 3)

10.    LC Paper No. CB(2)512/19-20(03) of 20 January 2020 — Review of the Personal Data (Privacy) Ordinance

11.    LC Paper No. CB(2)132/2023(02) — the target of consulting in the second quarter of 2023

12.    LegCo Brief CMAB/CR/7/22/45 of 14 July 2021 on the 2021 Bill

13.    LCQ6 of 29 May 2024 — the state of work on the amendments

14.    LCQ2 of 22 January 2025 — the most recent substantive statement on the reform

15.    LCQ19 of 29 April 2015 — on commencing section 33

16.    LCQ13 of 25 March 2026 — the Government’s position on regulating AI

17.    LCQ6 of 18 March 2026 — the inter-departmental working group on AI

18.    LCQ11 of 15 July 2026 — labelling of synthetic content

19.    Government announcement of 8 October 2021 that the 2021 amendment came into effect

20.    PCPD — the 2021 Amendment Ordinance

21.    PCPD — Implementation Guideline on the anti-doxxing regime

22.    PCPD — The Ordinance at a Glance: the Commissioner’s powers

23.    PCPD — approved codes of practice

24.    PCPD — Guidance on Recommended Model Contractual Clauses, May 2022

25.    PCPD — press release on the Model Contractual Clauses, 12 May 2022

26.    PCPD — Guidance on Personal Data Protection in Cross-border Data Transfer, 2014

27.    PCPD — artificial intelligence and personal data protection

28.    PCPD — press release on the Model Personal Data Protection Framework, 11 June 2024

29.    PCPD — compliance checks on 28 organisations, 21 February 2024

30.    PCPD — compliance checks on 60 organisations, 8 May 2025

31.    PCPD — compliance checks on 60 organisations, 19 May 2026

32.    PCPD — statement on the Grok chatbot, 15 January 2026

33.    PCPD — joint statement of data protection authorities on AI-generated imagery, 23 February 2026

34.    PCPD — alert on the privacy risks of OpenClaw and agentic AI, 16 March 2026

35.    PCPD — launch of the Safeguarding Personal Data AI Sandbox, 6 July 2026

36.    PCPD — work report for 2025, 3 February 2026

37.    PCPD — Annual Report 2024-25, 22 October 2025

38.    Digital Policy Office — Hong Kong Generative AI Technical and Application Guideline, 15 April 2025

39.    Digital Policy Office — Ethical Artificial Intelligence Framework

40.    HKSAR Government — Policy Statement on Responsible Application of AI in the Financial Market, 28 October 2024

41.    SFC — Circular to licensed corporations on the use of generative AI language models, 12 November 2024

42.    Protection of Critical Infrastructures (Computer Systems) Ordinance, Cap. 653

43.    Government announcement of 27 June 2025 that Cap. 653 would commence on 1 January 2026

44.    Communications Authority — the Protection of Critical Infrastructures (Computer Systems) Ordinance

45.    European Commission — the AI Omnibus enters into force and postpones the high-risk timetable

46.    Regulation (EU) 2024/1689 (the AI Act), official text on EUR-Lex

47.    IMDA — Model AI Governance Framework for Agentic AI, 22 January 2026

48.    PCPD media statement, 18 August 2021: Guidance on the Ethical Development and Use of AI

49.    PCPD media statement, 13 September 2023: 10 Tips for Users of AI Chatbots

50.    PCPD media statement, 31 March 2025: Checklist on Guidelines for the Use of Generative AI by Employees

51.    PCPD media statement, 17 December 2025: Guidance on Handling Abuse of AI Deepfakes

52.    PCPD media statement, 25 August 2026: Protecting Personal Data Privacy in the Use of Agentic AI

53.    HKMA — High-level Principles on Artificial Intelligence, 1 November 2019

54.    HKMA — Consumer Protection in respect of Use of Generative Artificial Intelligence, 19 August 2024

55.    HKMA — Generative Artificial Intelligence Sandbox, 20 September 2024

56.    HKMA, SFC, IA, MPFA — Joint Circular on the Expansion of Generative Artificial Intelligence Sandbox, 5 March 2026

57.    2025 Policy Address, paragraphs 66–69 — AI and data science policy

58.    Cyberspace Administration of China — Interim Measures for the Management of Generative AI Services, Order No. 15

A methodological note on sources. The wording of sections 13, 33, 50A, 62, 64, 66M, 66O and Schedule 1 was checked directly against the text of Cap. 486 on the e-Legislation portal; the amending ordinance number, 32 of 2021, is confirmed by the annotations within section 64 itself rather than by a press release. The dates and content of the PCPD publications, the Legislative Council question replies and the Digital Policy Office material were checked against the issuing bodies’ own publications. Where sources diverge or fall silent, that is shown rather than smoothed over: the exact issue date of the Ethical Artificial Intelligence Framework could not be confirmed from an official source and is not stated here, and Mainland China’s Interim Measures for the Management of Generative AI Services were checked against the official text on the Cyberspace Administration of China portal, so the earlier secondary-source caveat has been withdrawn. There is no textual interaction between Cap. 486 and Cap. 653, and the conclusion that the two regimes run in parallel is drawn from the absence of cross-references rather than from any official clarification. The conclusion that AI oversight is diagnostic rather than coercive is flagged in the text as a conclusion, resting on the absence of a published enforcement record rather than on a quotation from an official source. Local consultancies, privacy-vendor blogs and survey aggregators were not used as sources.

This material is provided for information only and does not constitute legal, tax, financial, investment or consulting advice. Before acting, obtain individual professional advice that accounts for the specific circumstances, jurisdiction, company status and current regulatory requirements.

Publication date: August 2026.

Read more on the topic

All services on the platform

Everything you need to start and run a business - in one place

  • 2–10 days

    Company Setup

    Hong Kong company with a complete set of incorporation documents


    Start
  • Monthly

    Accounting and Tax Services

    Accounting services in accordance with HKFRS, including monthly reporting.


  • 4–8 weeks

    Visa Services

    Visa services for company owners, employees, and their family members.


  • 7–30 days

    Banking Services

    Corporate Bank Accounts in Hong Kong and Payment Services


  • Custom timeline

    Legal Services

    Tax and Corporate Law Services


  • Custom timeline

    Corporate Services

    Licensed Company Secretary for Corporate Administration