Two instruments matter in Hong Kong: the PDPO (Cap. 486), whose Data Protection Principle 4 requires ‘all practicable steps’ to secure personal data, and the new Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653), in operation since 1 January 2026. Neither names a certificate. An ISO 27001 ISMS is the recognised way to evidence practicable steps actually taken.
Hong Kong runs on two instruments. The Personal Data (Privacy) Ordinance (Cap. 486) has been in force since 20 December 1996 — one of the oldest data-protection laws in Asia — and is overseen by the Office of the Privacy Commissioner for Personal Data (PCPD). The Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) is the new one: passed 19 March 2025, in operation since 1 January 2026, and aimed at designated critical-infrastructure operators.
| Instrument | Who it binds | What it asks of you |
|---|---|---|
| PDPO (Cap. 486) | Organisations handling personal data | Data Protection Principle 4: take “all practicable steps” to secure personal data |
| Cap. 653 | Designated critical-infrastructure operators | Computer-system security obligations, overseen by the Office of the Commissioner of Critical Infrastructure (Computer-system Security) |
DPP4 is the clause that matters day to day. “All practicable steps” is technology-neutral: the ordinance names no standard, no control set, no certificate. That cuts both ways — nothing forces you to certify, and nothing tells you when you’ve done enough. When the PCPD investigates an incident, “we took all practicable steps” is a claim you have to prove with records, not assert in a letter.
Breach notification is the part to get exactly right. Under the PDPO it is not mandatory. PCPD guidance recommends notifying the Commissioner and affected data subjects as soon as practicable where there’s a real risk of harm — recommends, not requires. A reform package that would make notification mandatory and add fines has been under consultation, but it has not been enacted. Plan for the guidance; don’t let anyone tell you the reform is already law.
Cap. 653 changes the ground for a narrower group. If your organisation is designated under it, your computer-system security now has its own commissioner. An operator that can’t show monitoring and incident response actually operating has very little to bring to that conversation.
The phrase “all practicable steps” has no checklist behind it, which is exactly why a certified ISMS earns its keep: it converts an open-ended legal phrase into a documented, audited record. You assess risk across the 93 Annex A controls, record what applies and what doesn’t in the Statement of Applicability, and hold evidence that the applicable controls run. That is what “practicable steps, taken” looks like when a regulator reads it.
| Hong Kong obligation | Where the ISMS answers it |
|---|---|
| DPP4 “all practicable steps” (PDPO) | Risk assessment plus the Statement of Applicability — a defensible record of which steps were practicable, and audit evidence that they operate |
| PCPD guidance: notify as soon as practicable where real risk of harm | Incident management with detection in front of it — logging and monitoring running continuously, so the clock starts at detection rather than at a customer complaint |
| Cap. 653 designation | Monitoring, incident response and evidence discipline: the operating substance a dedicated security regulator expects to find behind the paperwork |
One honest caveat: certification is not a legal safe harbour in Hong Kong. The PDPO doesn’t name ISO 27001, so the ISMS has to record the ordinance as a legal requirement and build its risk assessment against it. The certificate evidences the steps; it doesn’t replace the legal analysis.
The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by a certification body accredited by the Hong Kong Accreditation Service (HKAS), never by Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s being certified, so settle scope before you collect quotes. After certification come annual surveillance audits and full recertification every three years.
Scope is where Hong Kong gets interesting. Many Hong Kong entities are the regional headquarters of a wider group, and one ISMS can carry Hong Kong plus the rest of the region in a single multi-country scope — usually easier to run than a certificate per entity. Secure60 has delivery infrastructure in Hong Kong via Rackcorp, with 2 datacentres, so log collection and monitoring can run locally on our security platform where that’s the expectation. Infrastructure, not offices — and never the audit.
“No mandatory breach notification” gets read as “no detection requirement.” Teams see that the PDPO doesn’t force notification and quietly deprioritise monitoring; the budget goes to policy documents instead.
That reading fails twice. The PCPD already expects notification as soon as practicable where there’s a real risk of harm, and “as soon as practicable” is judged after the fact, against what your logs show you knew and when. And the reform on the table would make notification mandatory — organisations that build detection now have nothing to retrofit if it passes. Build for the guidance, and the law-as-it-may-become costs you nothing extra.
We build the ISMS, implement the controls and run the security operations behind them — logging, monitoring, incident response, vulnerability management — with the evidence trail that a Stage 2 auditor and a PCPD inquiry both want to see. Delivery runs on Hong Kong infrastructure via Rackcorp where local residency is expected. The certification audit belongs to an HKAS-accredited certification body; our job is making sure everything they sample is actually running when they arrive. We hold ISO 27001:2022 certification ourselves, so the system we build for you is the one we already operate.
Is ISO 27001 legally mandatory in Hong Kong?
No. The PDPO’s Data Protection Principle 4 requires ‘all practicable steps’ to secure personal data without naming any standard. A certified ISMS is the practical way to prove those steps were identified, taken and are still running when the PCPD asks.
Does Hong Kong have mandatory breach notification?
Not under the PDPO as of 2026. PCPD guidance recommends notifying the Commissioner and affected data subjects as soon as practicable where there’s a real risk of harm. A reform that would make notification mandatory has been under consultation — it has not been enacted.
Does Cap. 653 apply to us?
Only if you’re a designated critical-infrastructure operator. The ordinance was passed on 19 March 2025, has been in operation since 1 January 2026, and is overseen by the Office of the Commissioner of Critical Infrastructure (Computer-system Security).
Who performs the ISO 27001 certification audit in Hong Kong?
A certification body accredited by the Hong Kong Accreditation Service (HKAS) — not Secure60. Audit fees are set by the certification body and vary with the size and scope of the system being certified.
Can Secure60 deliver in Hong Kong?
Yes — we have delivery infrastructure in Hong Kong via Rackcorp, with 2 datacentres, so log collection and monitoring can run locally. We don’t have local offices, and we never perform the certification audit.