Hong Kong's Personal Data (Privacy) Ordinance (PDPO) is often treated as a legal or HR matter. In practice, whether a business actually protects personal data day to day depends heavily on its IT environment: where data is stored, who can access it, how devices are secured, and how quickly the organization can respond when something goes wrong.
For most Hong Kong businesses, personal data is scattered across many systems at once. Customer records live in the CRM. Employee files sit in HR platforms, payroll software, and shared drives. Contact details flow through email. Financial data moves through accounting systems. That spread creates real exposure when IT controls are not in place.
This article is for general information only and is not legal advice. Businesses should consult qualified legal counsel for formal interpretation of their PDPO obligations.
Why PDPO Compliance Depends on Good IT Controls
The PDPO is built around six Data Protection Principles covering the full lifecycle of personal data: how it is collected, kept accurate, retained, used, protected, and made accessible for correction. The Office of the Privacy Commissioner for Personal Data (PCPD) oversees enforcement and provides guidance on security controls and data breach handling.
While legal and policy work is essential, day-to-day risk lives in IT systems. Security, retention, access control, and breach response all depend on how well IT environments are configured and managed. The checklist below focuses on practical IT safeguards that help align IT practices with PDPO obligations and reduce personal data handling risk.
1. Know Where Personal Data Is Stored
You cannot protect data you have not identified. A basic data inventory is the starting point for any meaningful PDPO checklist.
From an IT perspective, personal data may sit in:
- Microsoft 365 services: Exchange, SharePoint, OneDrive, and Teams
- CRM systems, marketing platforms, and customer portals
- HR, payroll, and recruitment systems
- Accounting and ERP software
- Local file servers and network shared drives
- Staff laptops, mobile phones, USB drives, and external storage
- Third-party SaaS applications used across departments
- Backup systems and archives, including cloud backup
At minimum, document what categories of personal data you hold (contact details, ID numbers, financial records), where it sits, and which team owns each system. This inventory is the foundation for everything else on this checklist.
2. Control Who Can Access Personal Data
In many businesses, weak access control is a bigger risk than weak technology. Over-permissioned shared folders and Microsoft 365 sites mean that a single compromised account can expose far more data than necessary.
Practical steps to take:
- Apply role-based access control so staff only see the data they need for their job
- Set least-privilege permissions on shared folders, SharePoint sites, and line-of-business applications
- Review access regularly, especially for HR, finance, CRM, and shared mailboxes
- Keep admin accounts separate from everyday user accounts
- Enable multi-factor authentication (MFA) on Microsoft 365, VPNs, and all remote access services
- Disable or remove all access immediately when a staff member or contractor leaves
Offboarding is a particularly common weak spot. Active accounts from former employees are a straightforward entry point for unauthorized access to personal data.
3. Secure Devices and Cloud Platforms
Laptops, phones, and cloud services are where personal data gets accessed every day. Strengthening endpoint and cloud security is one of the highest-impact steps for handling personal data in Hong Kong businesses.
- Enable full-disk encryption on company laptops and desktops that store or cache personal data
- Deploy modern endpoint protection (EDR or next-generation antivirus) with centralized monitoring
- Keep operating systems, browsers, and applications patched and up to date
- Use a mobile device management solution such as Microsoft Intune to enforce encryption, screen locks, and remote wipe
- Review Microsoft 365 security settings including MFA, conditional access policies, and alerts for suspicious sign-ins
For many Hong Kong businesses, tightening Microsoft 365 security and device management delivers significant risk reduction without disrupting day-to-day operations.
4. Review Internal and External Data Sharing
Many personal data incidents are not caused by sophisticated attacks. They come from ordinary sharing habits: a link sent to the wrong person, a spreadsheet emailed to a vendor, or a shared folder left open to everyone in the company.
Areas to review:
- External sharing settings in Microsoft 365 (SharePoint, OneDrive, Teams): ensure links expire and are scoped to specific recipients
- Internal shared folders open to entire departments when they contain HR or customer records
- Email attachments used for bulk data exports, especially to third parties
- Vendor and contractor accounts with access to production systems or cloud storage
- Consumer file-sharing tools or messaging apps used for work data
Technical controls help here. Expiring links, data loss prevention rules, and approval workflows for bulk exports can significantly reduce accidental or unauthorized disclosure.
5. Strengthen Backup, Retention, and Deletion Practices
The PDPO's retention principle expects organizations to keep personal data only as long as necessary. From an IT perspective, keeping everything indefinitely increases both risk and exposure.
- Define retention periods for key systems: HR records, CRM data, email, Teams chats, and file storage
- Implement retention policies where the platform supports it, such as Microsoft 365 retention labels
- Establish secure deletion processes for systems that hold personal data, including end-of-life laptops and decommissioned SaaS platforms
- Ensure backups cover cloud platforms as well as on-premises systems, with backup data encrypted and access-controlled
- Test restore processes regularly so the business can recover from ransomware, accidental deletion, or system failure
Backups support business continuity and help demonstrate data security discipline, but they do not replace retention management. Backup data should follow the same principles: limit retention where feasible and protect it with strong access control.
6. Prepare for Data Breaches Before They Happen
PCPD guidance recommends that organizations maintain a written response plan and take action as soon as practicable when a breach creates a real risk of harm. Having a plan ready before an incident occurs makes the response significantly faster and less disruptive.
A practical data breach response plan for Hong Kong should include:
- Named internal contacts and escalation paths covering IT, senior management, and where applicable, legal
- Procedures for quickly gathering key facts: what happened, what data is involved, how many people are affected, and whether systems are still compromised
- Technical steps to contain the incident: isolating systems, resetting credentials, disabling unsafe sharing links, or blocking malicious access
- Logging and evidence preservation so the incident can be properly investigated and reported
- Criteria for when to seek legal advice on whether to notify the PCPD or affected individuals
- Draft communication templates for internal updates and customer notifications
Businesses should seek legal advice when deciding whether and how to notify regulators or affected individuals. The PCPD's breach guidance provides a useful baseline for understanding expectations.
7. Train Staff on Everyday Data Handling
Strong technology controls are not a complete solution. Phishing emails, messages sent to the wrong recipient, weak passwords, and lost devices are all common causes of personal data incidents.
Short, regular training activities are more effective than annual long-form sessions. Key topics to cover:
- Recognizing phishing and social engineering attempts targeting Microsoft 365 and business systems
- Using strong, unique passwords combined with MFA
- Checking recipient lists and attachments carefully before sending personal data
- Avoiding personal email accounts or consumer cloud storage for work data
- Safe use of public Wi-Fi and VPNs when accessing company systems remotely
- Reporting suspected incidents promptly: lost devices, misdirected emails, or suspicious logins
Common PDPO-Related IT Mistakes
Reviewing IT controls against PDPO expectations tends to surface the same issues across businesses:
- No clear inventory of where personal data is stored
- Former staff accounts still active in Microsoft 365, VPNs, or SaaS platforms
- Too many users with admin rights or global permissions
- Shared folders open to the whole company containing HR or customer data
- No MFA on Microsoft 365 or other key services
- Personal data sent routinely through unsecured email attachments
- Vendor and contractor access not regularly reviewed or removed
- No tested backup and restore process
- No documented breach response plan
Addressing these items does not replace legal compliance work, but it significantly reduces the likelihood and impact of incidents involving personal data.
How FunctionEight Can Help
FunctionEight helps Hong Kong businesses put practical IT controls in place that support privacy and security obligations. This includes IT security audit in Hong Kong engagements, IT consultancy projects focused on access control and Microsoft 365 security, and ongoing managed IT support services for businesses across Hong Kong and APAC.
Typical areas of assistance include reviewing access rights across Microsoft 365 and core business systems, improving endpoint protection and patch management, strengthening Microsoft 365 security configuration, reviewing backup and recovery practices, and coordinating IT management services around monitoring, incident response, and vendor oversight.
The goal is practical and focused: help businesses identify gaps and put sensible IT controls in place that align with their data privacy obligations.
Conclusion
PDPO compliance in Hong Kong is supported as much by good IT discipline as by formal policies and legal documents. Visibility of where personal data is stored, strong access control, secured devices and cloud platforms, careful sharing practices, sensible retention, tested backups, trained staff, and a clear breach response plan all work together to reduce personal data handling risk.
Businesses do not need to turn this into a complex technical project. Working through the checklist above, reviewing the most common gaps, and making steady improvements is a practical and proportionate approach. Combined with appropriate legal advice, solid IT controls make it easier to demonstrate that your organization is taking reasonable steps to protect the personal data it holds.
If your business handles customer, employee, or operational data in Hong Kong, FunctionEight can help review your current IT controls and identify practical improvements. Contact FunctionEight to discuss IT security audits, Microsoft 365 security, managed IT support, or broader IT consultancy for your Hong Kong business.
FAQs
Is PDPO compliance only a legal issue?
No. PDPO is a legal framework, but most of the important controls are implemented through IT: access management, device security, backup, and monitoring. Legal and IT teams should work together to support PDPO compliance effectively.
What personal data should Hong Kong businesses protect?
Any data relating to an identifiable living individual, including customer contact details, employee records, ID numbers, financial information, and records held in CRM, HR, accounting, email, and other business systems.
How can IT support PDPO compliance?
IT supports PDPO compliance by mapping where personal data is stored, controlling who can access it, securing endpoints and cloud platforms, managing retention and backup, monitoring for incidents, and maintaining IT systems in a well-governed and supported state.
Should Hong Kong businesses have a data breach response plan?
Yes. PCPD guidance recommends that organizations have clear procedures for handling data breaches, including containment, investigation, risk assessment, and decisions around notification. A clear plan helps organizations respond quickly and consistently, and it demonstrates that the business takes its Hong Kong data privacy obligations seriously.







