All articles
PlaybookJul 2026 · 6 min read

What does a privacy policy need for a Hong Kong website? (PDPO basics)

A Hong Kong website's privacy policy has to say what personal data you collect, why, who sees it, and how people can access or correct their own data. The rules come from the Personal Data (Privacy) Ordinance (Cap. 486), enforced by the Privacy Commissioner.

The short answer

If your site collects any personal data from Hong Kong visitors, you need a privacy policy that a normal person can actually read. The law behind it is the Personal Data (Privacy) Ordinance (PDPO, Cap. 486), and the body that enforces it is the Office of the Privacy Commissioner for Personal Data (PCPD). Personal data means anything that can identify a living person: a name, email, phone number, photo, IP address in some cases, even a delivery address tied to an order.

You do not need to register your site with anyone, and there is no government template to fill in. What you do need is to be honest and specific about your own data handling, and to make that statement easy to find, usually a link in the footer of every page.

What the policy should actually say

Start with what you collect and why. The PDPO's first Data Protection Principle says data must be collected for a lawful purpose directly related to your work, and you should not gather more than you need. So list the data types (name, email, phone, order details) and pair each with a plain reason, such as "to process and deliver your order".

Then cover the rest: who you share data with (payment processors, couriers, cloud hosting), whether any of it leaves Hong Kong, how long you keep it, and how it is kept secure. Finish with the visitor's rights. Under the PDPO, people can ask what data you hold about them (a data access request) and ask you to correct it, so give a real contact point, an email or address, that a person can use to make that request.

Cookies, analytics, and the collection statement

Most Hong Kong sites run Google Analytics, a Facebook pixel, or similar tools, and these set cookies that track behaviour. Say so plainly. Name the main tools, explain what they do in one line each, and tell people how to opt out or manage cookies in their browser. A short cookie banner that links to this section is common and reasonable.

When you collect data through a form, the PDPO expects a Personal Information Collection Statement (PICS) at the point of collection. In practice that is a short note beside the submit button: what the data is for, whether giving it is optional, who it may be passed to, and a link to the full policy. It does not need to be long, but it should appear where people actually type their details.

Direct marketing needs extra care

If you plan to email or message customers with promotions, Hong Kong has stricter rules here than many owners expect. Part 6A of the PDPO requires you to tell people you intend to use their data for direct marketing, say what kinds of goods or services, and get their consent before you start. Silence is not consent, so a pre-ticked box does not count.

Every marketing message after that must offer an easy way to opt out, and once someone opts out you must stop. Your privacy policy should describe this choice, and your sign-up forms should carry a clear, separate consent for marketing rather than bundling it into the main terms.

Common mistakes to avoid

The biggest one is copying another company's policy word for word. If it describes data practices you do not follow, it is worse than useless, because you are now on record making a promise you break. Write about what your own site really does. If you later add a chatbot or a loyalty programme, update the policy at the same time.

Two more worth noting. Hong Kong has no fixed word count or mandatory clause list, so a clear one-page statement beats a long legalistic one nobody reads. And breach notification is currently not mandatory under the PDPO, but the Commissioner recommends telling affected people and reporting serious incidents, so it is wise to have a plan for that day before you need it.

Common questions

Is a privacy policy legally required for a Hong Kong website?

If your site collects personal data, you are bound by the PDPO, and the openness principle expects you to make your data practices known. A written privacy policy is the standard way to do that. A purely static site that collects nothing has less to say, but the moment you add a contact form or analytics, you are collecting data and should publish a policy.

What is the difference between a privacy policy and a PICS?

A privacy policy is the full, always-available statement of how you handle data across the whole site. A Personal Information Collection Statement (PICS) is a short notice shown at the exact moment you collect data, such as next to a form's submit button. You usually need both: the PICS at the point of collection, linking through to the fuller policy.

Do I need consent before sending marketing emails in Hong Kong?

Yes. Part 6A of the PDPO requires you to notify people and obtain their consent before using their personal data for direct marketing, and to offer an opt-out in every message. A pre-ticked box or burying consent inside general terms does not meet the standard. Keep marketing consent separate and clearly worded.

Can I just copy a privacy policy from another website?

It is a bad idea. A borrowed policy almost always describes data practices that do not match yours, which turns it into a set of promises you are not keeping. It should reflect your real tools, your real sharing partners, and your real contact point for access requests. Use other policies for structure, then write the substance yourself.

Have a project in mind?

Tell us what you need — software, production, or both. We reply within one business day.

Start an enquiry