Two instruments apply in Hong Kong: the PDPO (Cap. 486), whose Data Protection Principle 4 requires ‘all practicable steps’ to secure personal data, and the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653), in operation since 1 January 2026. Neither names a certificate. An ISO 27001 ISMS is the recognised way to evidence which practicable steps were taken.
Hong Kong applies two instruments. The Personal Data (Privacy) Ordinance (Cap. 486) has been in force since 20 December 1996, making it one of the oldest data-protection laws in Asia, and is overseen by the Office of the Privacy Commissioner for Personal Data (PCPD). The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) was passed on 19 March 2025, has been in operation since 1 January 2026, and applies to designated critical-infrastructure operators.
| Instrument | Who it binds | What it requires |
|---|---|---|
| PDPO (Cap. 486) | Organisations handling personal data | Data Protection Principle 4: take “all practicable steps” to secure personal data |
| Cap. 653 | Designated critical-infrastructure operators | Computer-system security obligations, overseen by the Office of the Commissioner of Critical Infrastructure (Computer-system Security) |
DPP4 is the provision that applies day to day. “All practicable steps” is technology-neutral: the ordinance names no standard, no control set and no certificate. Nothing compels certification, and nothing defines a threshold of sufficiency. Where the PCPD investigates an incident, a claim that all practicable steps were taken has to be substantiated with records.
Breach notification is not mandatory under the PDPO. PCPD guidance recommends notifying the Commissioner and affected data subjects as soon as practicable where there is a real risk of harm. A reform package that would make notification mandatory and add fines has been under consultation and has not been enacted, so the guidance is the current planning basis.
Cap. 653 changes the position for a narrower group. An organisation designated under it has a dedicated commissioner for its computer-system security, and demonstrating compliance requires monitoring and incident response in operation.
“All practicable steps” has no checklist behind it, which is where a certified ISMS carries the weight: it converts an open-ended legal phrase into a documented, audited record. Risk is assessed across the 93 Annex A controls, applicability and exclusions are recorded in the Statement of Applicability, and evidence is held that the applicable controls run. That record is what practicable steps taken consists of when a regulator examines it.
| Hong Kong obligation | Where the ISMS answers it |
|---|---|
| DPP4 “all practicable steps” (PDPO) | Risk assessment plus the Statement of Applicability — a defensible record of which steps were practicable, and audit evidence that they operate |
| PCPD guidance: notify as soon as practicable where real risk of harm | Incident management with detection in front of it — logging and monitoring running continuously, so the clock starts at detection |
| Cap. 653 designation | Monitoring, incident response and evidence discipline: the operating substance a dedicated security regulator examines |
Certification is not a legal safe harbour in Hong Kong. The PDPO does not name ISO 27001, so the ISMS records the ordinance as a legal requirement and builds its risk assessment against it. The certificate evidences the steps and does not replace the legal analysis.
The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Hong Kong Accreditation Service (HKAS), and not by Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified, which makes scope the first decision. Annual surveillance audits and full recertification every three years follow.
Scope decisions matter in Hong Kong because many Hong Kong entities are the regional headquarters of a wider group. One ISMS can carry Hong Kong plus the rest of the region in a single multi-country scope, which is generally simpler to operate than a certificate per entity. Secure60 has delivery infrastructure in Hong Kong via Rackcorp, with 2 datacentres, so log collection and monitoring can run locally on our security platform where that is required. Secure60 provides infrastructure rather than a local office, and the audit remains with the accredited body.
Deprioritising monitoring on the basis that the PDPO does not compel notification fails on two grounds. The PCPD already expects notification as soon as practicable where there is a real risk of harm, and “as soon as practicable” is judged after the fact against what the logs establish you knew and when. The reform under consultation would make notification mandatory, and organisations that build detection now have nothing to retrofit if it is enacted.
Building to the current guidance therefore also covers the position the law may move to.
We build the ISMS, implement the controls and run the security operations behind them — logging, monitoring, incident response, vulnerability management — with the evidence trail a Stage 2 auditor and a PCPD inquiry both examine. Delivery runs on Hong Kong infrastructure via Rackcorp where local residency is required. The certification audit belongs to an HKAS-accredited certification body, and our work is making sure everything they sample is operating on arrival. Secure60 holds ISO 27001:2022 certification, so the system we build for you is the one we operate.
Is ISO 27001 legally mandatory in Hong Kong?
No. The PDPO’s Data Protection Principle 4 requires ‘all practicable steps’ to secure personal data without naming any standard. A certified ISMS is the practical way to establish that those steps were identified, taken and still operating when the PCPD asks.
Does Hong Kong have mandatory breach notification?
Not under the PDPO as of 2026. PCPD guidance recommends notifying the Commissioner and affected data subjects as soon as practicable where there is a real risk of harm. A reform that would make notification mandatory has been under consultation and has not been enacted.
Does Cap. 653 apply to us?
Only where you are a designated critical-infrastructure operator. The ordinance was passed on 19 March 2025, has been in operation since 1 January 2026, and is overseen by the Office of the Commissioner of Critical Infrastructure (Computer-system Security).
Who performs the ISO 27001 certification audit in Hong Kong?
A certification body accredited by the Hong Kong Accreditation Service (HKAS), and not Secure60. Audit fees are set by the certification body and vary with the size and scope of the system being certified.
Can Secure60 deliver in Hong Kong?
Yes. We have delivery infrastructure in Hong Kong via Rackcorp, with 2 datacentres, so log collection and monitoring can run locally. We have no local offices, and we do not perform the certification audit.