If you run a business in Hong Kong and you keep a customer's name and mobile number, the Personal Data (Privacy) Ordinance already applies to you. No staff-count threshold, no revenue floor, no small business exemption. Most owners know the PDPO exists. Far fewer know what it asks of them, and almost nobody has looked at their own website through that lens.
A plain English explainer for owners without an IT department. This is not legal advice, and for a live incident you should call a solicitor.
What counts as personal data
The Personal Data (Privacy) Ordinance, 個人資料私隱條例, covers information about a living person where you can work out who that person is, directly or indirectly, and where the information is in a usable form.
That is broader than most owners assume. A table booking with a name, a mobile and a note about a nut allergy counts. So does a delivery address, a scanned HKID copy sitting in email, a CV in a shared folder, recognisable CCTV footage, and a contact form enquiry sitting in your website database since 2021.
You do not need a full name. A membership number you can match to a phone number is enough, because you hold both halves. A rough test: if losing the file would let a stranger contact, impersonate or embarrass a customer or a member of staff, assume the 私隱條例 applies.
The six data protection principles, in owner's language
The ordinance runs on six data protection principles. In plain terms:
Collect only what you need, and say why. A restaurant booking does not need an HKID number. Whatever you collect, say at that moment what it is for.
Keep it accurate, and do not keep it forever. Five years of contact form submissions is not an asset. It is a liability on a server you do not manage.
Use it only for the purpose you gave. A phone number handed over to confirm a delivery is for confirming deliveries. A promotional blast is a different purpose, and it is where most Hong Kong SMEs slip.
Protect it properly. The law asks for all practicable steps against unauthorised access, loss or misuse. Nobody expects a bank's budget from a boutique. They do expect the basics.
Be open about what you do. People should be able to find out what you hold and how you handle it without asking. In practice, a privacy policy someone can actually find.
Let people see and correct their data. Anyone can ask for a copy of what you hold on them, or ask you to fix it. You have 40 days to respond.
Handing the work to a supplier does not hand over the responsibility. Your web developer, host, booking platform and email tool all handle customer data on your behalf, and you remain answerable for it.
Part 6A, the marketing rule that catches people out
Part 6A governs direct marketing, and it is stricter than most people expect.
Before you market to someone for the first time, you have to tell them you intend to, say what data you will use and what you will promote, and give them a free way to say no. Then you wait for their agreement. Silence is not agreement. A pre-ticked box is not agreement.
Pass customer data to another company for its own marketing and the bar is higher again, higher still if you are paid for it. Once someone opts out you must stop, and failing to stop is an offence. Maximum penalties run to a HK$500,000 fine and three years' imprisonment, rising to HK$1,000,000 and five years for providing data to a third party for gain.
The risky habits: buying a contact list, blasting your customer phone list on WhatsApp, marketing to business cards from a trade show, adding every past order to a newsletter.
What actually happens if customer data leaks
Hong Kong does not currently have mandatory breach notification. Telling the Privacy Commissioner is voluntary, though the guidance recommends it and expects you to warn affected individuals where there is real risk of harm. The Government has said for years that it wants to add mandatory notification and direct fines, but nothing is in force yet.
What does happen is a compliance check or an investigation. The Commissioner can issue an enforcement notice telling you to fix specific things, and ignoring it is a criminal offence. Investigation reports are published with the company named, and an individual who suffers damage, including injured feelings, can sue for compensation.
The regulator is often not the expensive part. It is the corporate client who asks for a security questionnaire at renewal, and the customers who stop handing over details.
None of this is rare. HKCERT handled 12,536 security incidents in Hong Kong in 2024, the highest in five years, and phishing made up about 62% of them, up 108% year on year. IBM found AI can draft a convincing phishing email in roughly five minutes, against about 16 hours by hand. Verizon's 2024 Data Breach Investigations Report found 88% of small business breaches involved ransomware or extortion. Small firms are cheap to attack.
The website problems that put owners at risk
Our own scan of 214 Hong Kong business websites used only publicly visible information. The average exposure score was 41 out of 100, where 0 is nothing exposed and 100 is wide open, and 72% had at least one finding we rate high or critical. Four patterns repeat.
The contact form nobody follows. Enquiries usually land in two places, a shared inbox and a copy in the website's own database. Most owners can name the inbox. Few know about the second copy, or how far back it goes.
No encryption where data is collected. HTTPS is the padlock in the address bar. Without it, whatever a customer types travels like a postcard rather than a sealed envelope. Any page with a login, a checkout or a form needs it.
Email anyone can forge. SPF, DKIM and DMARC are three small settings in your domain that let receiving mail systems check that an email claiming to be from you really came from you, like a signature plus a company chop. In our scan, 62% had no DMARC, 68% had no DKIM and 35% had no SPF. That is how a customer ends up paying a fake invoice in your name.
Your details published in WHOIS. WHOIS is the public register of who owns a domain name, a little like a company search. In our scan, 17% published the owner's personal name and contact details. That is your own personal data on display, and it hands an attacker the exact name to impersonate.
Worth doing this week:
- Find out where contact form submissions actually go, then turn on two factor authentication for that inbox
- Search your own domain in a public WHOIS lookup, and switch on domain privacy if your details show
- Check that every page collecting customer information loads with the padlock
- Ask your web developer or host, in writing, where customer data sits and how long backups are kept
- Delete enquiry records you no longer have a reason to hold
- Add a line beside your contact form saying what the details are used for, and a privacy policy that matches reality
Where to start
You do not need to become a privacy expert. Most PDPO exposure at a small business comes from four ordinary things: data collected without a clear purpose, data kept long after that purpose ended, marketing sent without agreement, and a website nobody has checked since it was built.
The easiest first step is knowing what your own site already gives away, so if that would help, we will run a free passive check on your domain and send the findings in plain English.