New Look. Always Premium. 1000+ Google Reviews & 100+ Authentic Video testimonials you won’t find with our competitors — click and watch!

Key Takeaways: 

  • The Personal Data (Privacy) Ordinance (PDPO, Cap. 486) governs how you collect, use and protect personal data in Hong Kong — whether you are collecting customer data or being asked for your own.
  • Banks, TCSPs and professional firms must collect certain data under the Banking Ordinance (Cap. 155), the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO, Cap. 615) and HKMA guidelines. These requests are usually lawful and non-negotiable.
  • Understand your PDPO rights so you can push back on excessive commercial requests, while recognising Hong Kong’s compliance culture: fighting banks, government or large counterparties rarely ends well.
  • Company documents (Certificate of Incorporation, Business Registration Certificate, NNC1, Annual Return NAR1) requested in ordinary commercial dealings sit largely outside pure PDPO marketing rules.
  • Under the Companies Registry’s Unique Business Identifier (UBI) regime, your 8-digit Business Registration Number (BRN) is now the single primary identifier. The New Inspection Regime further protects directors’ usual residential addresses and full identification numbers from public view.
  • In the AI era the temptation is to collect everything. The law still requires purpose limitation, necessity and explicit consent for secondary uses such as direct marketing.
  • For SMEs without digital watermarking tools, simple physical steps (ink note + company stamp on a black-and-white copy before scanning) remain an effective, low-cost defence against unauthorised re-use.
Displaying the collection of personal data

This article is not filler. After incorporation you will deal with banks, company secretaries, landlords and counterparties. Knowing the boundary between “must-provide for compliance” and “they are overreaching” protects both your rights and your ability to operate.

Overview: Authority & Regulatory Frameworks

Authority / RegimeGoverning Ordinance / RegulatorWhat They Typically Ask ForCan You Push Back?
Written Resolution?AMLO (Cap. 615), Banking Ordinance, HKMA GuidelinesUBO details, passport/ID, source of wealth/fundsNo. Required for legal compliance
Companies Registry FilingPure contractSpouse data, detailed financial/education historyYes. Often over-collection under DPP1

Why founders must understand both rights and compliance culture

Hong Kong runs on a practical compliance culture. Banks and licensed TCSPs face real regulatory pressure under the Banking Ordinance, AMLO and HKMA guidelines. Failure to perform proper customer due diligence can cost them their licence. Providing the required information promptly is almost always the fastest path.

At the same time the PDPO gives you genuine rights. You can and should question requests that go beyond what is necessary for the stated purpose. The smart founder stance is simple: comply quickly with genuine statutory or regulatory demands, document the purpose, and push back politely but firmly on purely commercial over-collection.

The Personal Data (Privacy) Ordinance (PDPO) in plain language for founders

The PDPO (in force since 1996) applies to any data user that collects, holds or processes personal data in Hong Kong. Personal data is any information relating to a living individual from which it is practicable to identify that person directly or indirectly.

Six Data Protection Principles sit at the core:

  1. Purpose and manner of collection (DPP1) — Collect only for a lawful purpose related to your function, and only what is necessary and not excessive.
  2. Accuracy and retention (DPP2) — Keep data accurate and delete it when no longer needed.
  3. Use (DPP3) — Do not use data for a new purpose without the individual’s express, voluntary consent.
  4. Security (DPP4) — Take practicable steps to protect the data.
  5. Openness (DPP5) — Be transparent about the kinds of data you hold and your policies.
  6. Access and correction (DPP6) — Individuals can request access and correction.

Direct marketing is strictly regulated under Part 6A of the PDPO. Before using personal data for direct marketing (or providing it to a third party for that purpose), you must inform the individual and obtain explicit consent. Contravention can attract fines of up to HK$500,000 and 3 years’ imprisonment (or up to HK$1,000,000 and 5 years if the data is provided for gain). The Privacy Commissioner can also issue enforcement notices.

When you yourself collect customer data (especially in an AI-driven business that wants age, gender, nationality, location, purchase frequency, visit timestamps, etc.), the same principles apply. More data may feed models better, but excess collection without a clear lawful purpose, or later use for marketing without consent, creates real PDPO risk.

Why banks and TCSPs ask for so much information

Banking Ordinance + AMLO CDD

Authorised institutions must identify and verify the customer and beneficial owners, understand the purpose of the relationship, and apply enhanced due diligence where risk is higher (PEPs, high-risk jurisdictions, adverse media, etc.). AML systems may surface addresses, employment history or news mentions; banks then ask follow-up questions. These are statutory obligations, not curiosity.

TCSP / company secretary obligations

Licensed TCSPs must perform CDD under AMLO before establishing a business relationship. They identify and verify customers and beneficial owners, obtain information on the purpose of the relationship, and keep records (normally for at least five years after the relationship ends). This is a licensing requirement under both the Companies Ordinance and AMLO.

Spouse or family information

Usually excessive in pure commercial settings. Limited exceptions exist under enhanced due diligence if the spouse is a PEP or creates elevated risk.

Third-party payments

If someone else pays on your behalf, banks and professional firms will normally require identification of the payer. This is a standard CDD.

Company documents and the latest Companies Registry updates

It is normal for counterparties to request:

  • Certificate of Incorporation
  • Business Registration Certificate
  • Occasionally Form NNC1 or NAR1

Under the Unique Business Identifier (UBI) regime (full implementation 27 December 2023), the 8-digit Business Registration Number issued by the Inland Revenue Department is now the single primary identifier across government databases.

Under the New Inspection Regime, directors’ usual residential addresses and full identification numbers are protected information. Public versions of NNC1, NAR1 and the Companies Register generally show only correspondence addresses and partial ID numbers. Full details are withholdable from general public inspection.

These verification steps are driven by commercial risk management and AML expectations rather than PDPO marketing rules.

Practical protection for SMEs

If you do not have enterprise watermarking software, print a black-and-white copy, write the intended recipient and purpose across the document in ink (e.g. “For [Bank Name] account opening only – [Date]”), add a company stamp if available, and re-scan. This low-tech method makes unauthorised re-use significantly harder.

Practical advice for founders

  1. Treat genuine bank, TCSP and regulatory CDD requests as non-negotiable. Provide what is asked, keep copies, and note the stated purpose.
  2. For purely commercial counterparties, ask: “What is the specific purpose and legal basis?” Push back politely on spouse details, detailed education history or other excess requests.
  3. When you collect data yourself, map every data point to a lawful purpose under DPP1. Obtain clear consent for any marketing use. Do not retain data longer than necessary.
  4. Document your data policies so you can demonstrate openness and security if the Privacy Commissioner asks.
  5. In an AI-driven business, resist collecting “everything just in case.” Excess data increases both PDPO risk and breach surface area.

Disclaimer: This is general information only and does not constitute legal advice. For specific situations consult a qualified Hong Kong solicitor or the relevant regulators (PCPD, Companies Registry, HKMA).

Frequently Asked Questions about collection of personal data

1. What counts as personal data under the PDPO?

Any data relating to a living individual from which it is practicable to identify that person directly or indirectly, in any form.

2. Do banks and TCSPs have to follow the PDPO when they collect my data?

Yes. They are data users under the PDPO, but they also have independent statutory duties under AMLO and the Banking Ordinance. Regulatory CDD is generally treated as a lawful purpose.

3. How does the New Inspection Regime affect director privacy on NNC1 or NAR1?

Public versions display correspondence addresses and partial identification numbers. Full residential addresses and full ID numbers are protected and can be withheld from general public inspection.

4. Can I refuse to provide NNC1 or NAR1?

In most ordinary commercial situations, yes. When a powerful counterparty makes it a hard condition of the deal, providing the documents is usually the practical path and is not prohibited by the PDPO.

5. Is asking for spouse information always excessive?

Usually yes in pure commercial contexts. Exceptions can arise under enhanced due diligence if the spouse is a Politically Exposed Person (PEP) or creates elevated AML risk.

6. What should an SME without paid watermarking software do with a BR certificate copy?

Print or photocopy in black-and-white, write the intended recipient and purpose across the document in physical ink, add a company stamp if available, and re-scan. This free method significantly reduces the risk of unauthorised re-use.