Whether you are in the business of data storage or have a digital presence that collects personal information, you have legal obligations in Hong Kong. The Hong Kong Personal Data Protection Ordinance (PDPO) regulates the collection, processing, holding and use of personal data by establishing data subject rights, specific obligations to data controllers and six data protection principles. While it is not yet certain that the PDPO will be amended to align with the GDPR, any changes could have serious implications for businesses using or processing personal data in Hong Kong.
A centralized approach to data governance is the best way to mitigate these risks. Ensure that your organization has dedicated resources to help you meet your obligations under the PDPO. This includes the identification of a data governance leader and team members. Ideally, these people should be both business and IT savvy, and have experience in building bridges between business and IT. Data and enterprise architects, and senior business systems analysts are all good candidates. They can translate how your data governance framework affects all aspects of business processes, decisions and interactions, and help you identify the right people to be data stewards.
For example, if you store and process sensitive customer data, you must comply with requests for information from law enforcement authorities in accordance with Hong Kong laws. This could include subpoenas, court orders or other legal process. A cloud service provider is not allowed to refuse such requests, unless there are reasonable grounds to do so. In addition, you must comply with any other requests for disclosure of personal information from a government body or regulator in Hong Kong.
If the PDPO is changed to include a definition of “personal data” similar to that of the GDPR, it will mean additional protection for individuals and increased compliance measures for businesses that use data. This is particularly true for businesses that learn about individuals’ behaviours, or process information that will have an impact on them as individuals.
Tech Data Distribution (Hong Kong), a TD SYNNEX company, is an innovative partner helping more than 150,000 customers in 100+ countries maximize the value of their technology investments, demonstrate business outcomes and unlock growth opportunities. Our 23,500+ co-workers are dedicated to uniting compelling IT products, services and solutions from 1,500+ best-in-class technology vendors. Located in Clearwater, Florida and Fremont, California, Tech Data is committed to delivering an unrivalled customer and partner experience.