ISO 27001 · Hong Kong

ISO 27001 in Hong Kong: what it takes

The short answer

Two instruments matter in Hong Kong: the PDPO (Cap. 486), whose Data Protection Principle 4 requires ‘all practicable steps’ to secure personal data, and the new Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653), in operation since 1 January 2026. Neither names a certificate. An ISO 27001 ISMS is the recognised way to evidence practicable steps actually taken.

The two laws that set security expectations in Hong Kong

Hong Kong runs on two instruments. The Personal Data (Privacy) Ordinance (Cap. 486) has been in force since 20 December 1996 — one of the oldest data-protection laws in Asia — and is overseen by the Office of the Privacy Commissioner for Personal Data (PCPD). The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) is the new one: passed 19 March 2025, in operation since 1 January 2026, and aimed at designated critical-infrastructure operators.

Instrument Who it binds What it asks of you
PDPO (Cap. 486) Organisations handling personal data Data Protection Principle 4: take “all practicable steps” to secure personal data
Cap. 653 Designated critical-infrastructure operators Computer-system security obligations, overseen by the Office of the Commissioner of Critical Infrastructure (Computer-system Security)

DPP4 is the clause that matters day to day. “All practicable steps” is technology-neutral: the ordinance names no standard, no control set, no certificate. That cuts both ways — nothing forces you to certify, and nothing tells you when you’ve done enough. When the PCPD investigates an incident, “we took all practicable steps” is a claim you have to prove with records, not assert in a letter.

Breach notification is the part to get exactly right. Under the PDPO it is not mandatory. PCPD guidance recommends notifying the Commissioner and affected data subjects as soon as practicable where there’s a real risk of harm — recommends, not requires. A reform package that would make notification mandatory and add fines has been under consultation, but it has not been enacted. Plan for the guidance; don’t let anyone tell you the reform is already law.

Cap. 653 changes the ground for a narrower group. If your organisation is designated under it, your computer-system security now has its own commissioner. An operator that can’t show monitoring and incident response actually operating has very little to bring to that conversation.

How an ISO 27001 ISMS evidences “all practicable steps”

The phrase “all practicable steps” has no checklist behind it, which is exactly why a certified ISMS earns its keep: it converts an open-ended legal phrase into a documented, audited record. You assess risk across the 93 Annex A controls, record what applies and what doesn’t in the Statement of Applicability, and hold evidence that the applicable controls run. That is what “practicable steps, taken” looks like when a regulator reads it.

Hong Kong obligation Where the ISMS answers it
DPP4 “all practicable steps” (PDPO) Risk assessment plus the Statement of Applicability — a defensible record of which steps were practicable, and audit evidence that they operate
PCPD guidance: notify as soon as practicable where real risk of harm Incident management with detection in front of it — logging and monitoring running continuously, so the clock starts at detection rather than at a customer complaint
Cap. 653 designation Monitoring, incident response and evidence discipline: the operating substance a dedicated security regulator expects to find behind the paperwork

One honest caveat: certification is not a legal safe harbour in Hong Kong. The PDPO doesn’t name ISO 27001, so the ISMS has to record the ordinance as a legal requirement and build its risk assessment against it. The certificate evidences the steps; it doesn’t replace the legal analysis.

Certification and scope in Hong Kong

The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Hong Kong Accreditation Service (HKAS), never by Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s being certified, so settle scope before you collect quotes. After certification come annual surveillance audits and full recertification every three years.

Scope is where Hong Kong gets interesting. Many Hong Kong entities are the regional headquarters of a wider group, and one ISMS can carry Hong Kong plus the rest of the region in a single multi-country scope — usually easier to run than a certificate per entity. Secure60 has delivery infrastructure in Hong Kong via Rackcorp, with 2 datacentres, so log collection and monitoring can run locally on our security platform where that’s the expectation. Infrastructure, not offices — and never the audit.

What most people get wrong

“No mandatory breach notification” gets read as “no detection requirement.” Teams see that the PDPO doesn’t force notification and quietly deprioritise monitoring; the budget goes to policy documents instead.

That reading fails twice. The PCPD already expects notification as soon as practicable where there’s a real risk of harm, and “as soon as practicable” is judged after the fact, against what your logs show you knew and when. And the reform on the table would make notification mandatory — organisations that build detection now have nothing to retrofit if it passes. Build for the guidance, and the law-as-it-may-become costs you nothing extra.

How Secure60 handles this

We build the ISMS, implement the controls and run the security operations behind them — logging, monitoring, incident response, vulnerability management — with the evidence trail that a Stage 2 auditor and a PCPD inquiry both want to see. Delivery runs on Hong Kong infrastructure via Rackcorp where local residency is expected. The certification audit belongs to an HKAS-accredited certification body; our job is making sure everything they sample is actually running when they arrive. We hold ISO 27001:2022 certification ourselves, so the system we build for you is the one we already operate.

Frequently asked questions

Is ISO 27001 legally mandatory in Hong Kong?

No. The PDPO’s Data Protection Principle 4 requires ‘all practicable steps’ to secure personal data without naming any standard. A certified ISMS is the practical way to prove those steps were identified, taken and are still running when the PCPD asks.

Does Hong Kong have mandatory breach notification?

Not under the PDPO as of 2026. PCPD guidance recommends notifying the Commissioner and affected data subjects as soon as practicable where there’s a real risk of harm. A reform that would make notification mandatory has been under consultation — it has not been enacted.

Does Cap. 653 apply to us?

Only if you’re a designated critical-infrastructure operator. The ordinance was passed on 19 March 2025, has been in operation since 1 January 2026, and is overseen by the Office of the Commissioner of Critical Infrastructure (Computer-system Security).

Who performs the ISO 27001 certification audit in Hong Kong?

A certification body accredited by the Hong Kong Accreditation Service (HKAS) — not Secure60. Audit fees are set by the certification body and vary with the size and scope of the system being certified.

Can Secure60 deliver in Hong Kong?

Yes — we have delivery infrastructure in Hong Kong via Rackcorp, with 2 datacentres, so log collection and monitoring can run locally. We don’t have local offices, and we never perform the certification audit.

Operating systems in Hong Kong?

Book a readiness call. We'll map the PDPO and Cap. 653 against your systems and tell you exactly what an ISMS engagement covers.

Book a readiness call Run a pilot