Hong Kong companies must comply with the Personal Data (Privacy) Ordinance (PDPO) when collecting and using customer data for marketing purposes.

This article is not filler. After incorporation you will deal with banks, company secretaries, landlords and counterparties. Knowing the boundary between “must-provide for compliance” and “they are overreaching” protects both your rights and your ability to operate.
| Authority / Regime | Governing Ordinance / Regulator | What They Typically Ask For | Can You Push Back? |
| Written Resolution? | AMLO (Cap. 615), Banking Ordinance, HKMA Guidelines | UBO details, passport/ID, source of wealth/funds | No. Required for legal compliance |
| Companies Registry Filing | Pure contract | Spouse data, detailed financial/education history | Yes. Often over-collection under DPP1 |
Hong Kong runs on a practical compliance culture. Banks and licensed TCSPs face real regulatory pressure under the Banking Ordinance, AMLO and HKMA guidelines. Failure to perform proper customer due diligence can cost them their licence. Providing the required information promptly is almost always the fastest path.
At the same time the PDPO gives you genuine rights. You can and should question requests that go beyond what is necessary for the stated purpose. The smart founder stance is simple: comply quickly with genuine statutory or regulatory demands, document the purpose, and push back politely but firmly on purely commercial over-collection.
The PDPO (in force since 1996) applies to any data user that collects, holds or processes personal data in Hong Kong. Personal data is any information relating to a living individual from which it is practicable to identify that person directly or indirectly.
Six Data Protection Principles sit at the core:
Direct marketing is strictly regulated under Part 6A of the PDPO. Before using personal data for direct marketing (or providing it to a third party for that purpose), you must inform the individual and obtain explicit consent. Contravention can attract fines of up to HK$500,000 and 3 years’ imprisonment (or up to HK$1,000,000 and 5 years if the data is provided for gain). The Privacy Commissioner can also issue enforcement notices.
When you yourself collect customer data (especially in an AI-driven business that wants age, gender, nationality, location, purchase frequency, visit timestamps, etc.), the same principles apply. More data may feed models better, but excess collection without a clear lawful purpose, or later use for marketing without consent, creates real PDPO risk.
Banking Ordinance + AMLO CDD
Authorised institutions must identify and verify the customer and beneficial owners, understand the purpose of the relationship, and apply enhanced due diligence where risk is higher (PEPs, high-risk jurisdictions, adverse media, etc.). AML systems may surface addresses, employment history or news mentions; banks then ask follow-up questions. These are statutory obligations, not curiosity.
TCSP / company secretary obligations
Licensed TCSPs must perform CDD under AMLO before establishing a business relationship. They identify and verify customers and beneficial owners, obtain information on the purpose of the relationship, and keep records (normally for at least five years after the relationship ends). This is a licensing requirement under both the Companies Ordinance and AMLO.
Spouse or family information
Usually excessive in pure commercial settings. Limited exceptions exist under enhanced due diligence if the spouse is a PEP or creates elevated risk.
Third-party payments
If someone else pays on your behalf, banks and professional firms will normally require identification of the payer. This is a standard CDD.
It is normal for counterparties to request:
Under the Unique Business Identifier (UBI) regime (full implementation 27 December 2023), the 8-digit Business Registration Number issued by the Inland Revenue Department is now the single primary identifier across government databases.
Under the New Inspection Regime, directors’ usual residential addresses and full identification numbers are protected information. Public versions of NNC1, NAR1 and the Companies Register generally show only correspondence addresses and partial ID numbers. Full details are withholdable from general public inspection.
These verification steps are driven by commercial risk management and AML expectations rather than PDPO marketing rules.
Practical protection for SMEs
If you do not have enterprise watermarking software, print a black-and-white copy, write the intended recipient and purpose across the document in ink (e.g. “For [Bank Name] account opening only – [Date]”), add a company stamp if available, and re-scan. This low-tech method makes unauthorised re-use significantly harder.
Disclaimer: This is general information only and does not constitute legal advice. For specific situations consult a qualified Hong Kong solicitor or the relevant regulators (PCPD, Companies Registry, HKMA).
1. What counts as personal data under the PDPO?
Any data relating to a living individual from which it is practicable to identify that person directly or indirectly, in any form.
2. Do banks and TCSPs have to follow the PDPO when they collect my data?
Yes. They are data users under the PDPO, but they also have independent statutory duties under AMLO and the Banking Ordinance. Regulatory CDD is generally treated as a lawful purpose.
3. How does the New Inspection Regime affect director privacy on NNC1 or NAR1?
Public versions display correspondence addresses and partial identification numbers. Full residential addresses and full ID numbers are protected and can be withheld from general public inspection.
4. Can I refuse to provide NNC1 or NAR1?
In most ordinary commercial situations, yes. When a powerful counterparty makes it a hard condition of the deal, providing the documents is usually the practical path and is not prohibited by the PDPO.
5. Is asking for spouse information always excessive?
Usually yes in pure commercial contexts. Exceptions can arise under enhanced due diligence if the spouse is a Politically Exposed Person (PEP) or creates elevated AML risk.
6. What should an SME without paid watermarking software do with a BR certificate copy?
Print or photocopy in black-and-white, write the intended recipient and purpose across the document in physical ink, add a company stamp if available, and re-scan. This free method significantly reduces the risk of unauthorised re-use.

Our comprehensive support which allows your company to operate efficiently without physical presence in Hong Kong.

Our company formation packages include a registered address service prepared for you hassle-free.