Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

Data Access Requests Under Hong Kong's Privacy Ordinance

Updated 6 min read
Key takeaway

A data access request asks a data user to confirm whether it holds the requester's personal data and supply a copy, subject to the Personal Data (Privacy) Ordinance.

More key points
  • The ordinary response period is 40 calendar days.
  • The organisation must verify identity appropriately, assess the data held, handle third-party information and exemptions correctly, and avoid excessive fees.
On this page8 sections
  1. The right concerns personal data
  2. Verify the requester without creating unnecessary barriers
  3. Record receipt and manage the deadline
  4. Search reasonably identifiable records
  5. Protect other people's personal data
  6. Fees must relate to compliance costs
  7. If full compliance is not possible in time
  8. Deliver and record the response securely

A financial intermediary can hold personal data across account-opening records, correspondence, call recordings, and complaint files. When a customer requests access, the task is to identify the relevant personal data and respond under the Ordinance. It is not enough to send a generic acknowledgement or assume that all internal records are outside the request.

The right concerns personal data

The access right concerns the individual's personal data held by the data user. It does not automatically provide unrestricted discovery of every business document the individual names. A document may contain the requester's personal data, another person's data, commercial information, or a mixture. The organisation should assess the actual content rather than decide solely from the document's title.

For example, a complaint note can include information about the complainant and comments about how the firm handled the complaint. Calling it an internal note does not automatically remove all of its content from the access analysis. Conversely, a request for a general business manual may not identify personal data about the requester. Distinguish the information sought from the container holding it.

Verify the requester without creating unnecessary barriers

The organisation should establish the requester's identity and, where someone acts for another person, the relevant authority. Sending account records to the wrong person would itself create a privacy problem. The verification should be appropriate to the circumstances and the information reasonably required under the Ordinance.

A request sent from an unfamiliar address may need additional checks. A representative may need to demonstrate their status or authority. Explain what information is needed and why. Requiring irrelevant material or repeatedly asking for information already adequately established can delay the response without improving security.

Record receipt and manage the deadline

The PCPD's guidance states that the data user should provide the requested personal data in an intelligible form within 40 calendar days after receiving the request, subject to the applicable provisions. Calendar days should not be replaced with a business-day count. Route the request promptly to the responsible team and retain the receipt date.

An acknowledgement confirms that the request arrived; it does not, by itself, satisfy the obligation to supply the data. Likewise, sending a demand for a fee is not the same as completing the response. The firm needs a process that manages searching, reviewing, any fee issue, and delivery within the legal framework.

If the firm does not hold the requested data, it should still inform the requester within the required period. Silence is not an adequate way to communicate that result. Record the searches or checks supporting the conclusion so the firm can explain why it says the information is not held.

Search reasonably identifiable records

A request can be broad without being impossible to process. PCPD guidance cautions against refusing merely because wording is generic when the firm knows and can reasonably locate the data. A request covering a customer's accounts may be searchable by name or account identifiers. Assess the systems and available indices rather than assume every broad request is invalid.

Ask for clarification when needed to identify the data, but explain the uncertainty. For example, a customer may refer to a conversation without identifying the account or approximate period. A focused clarification can make the search effective. It should not become an excuse to ignore data that is already clearly identifiable and readily retrievable.

Protect other people's personal data

Records can contain personal data about joint account holders, employees, counterparties, or other customers. The Ordinance addresses disclosure of another individual's data and the circumstances for refusal or redaction. Where the request can be satisfied by removing the other person's identifying information, the organisation should assess that route instead of rejecting the whole request automatically.

A call record, for instance, may contain the requester's information alongside another person's account details. The review should identify what can be supplied, what requires redaction, and any lawful basis for withholding. A blanket statement that the file mentions someone else does not explain why all access must be refused. Apply the rule to the actual content.

Fees must relate to compliance costs

A data user may charge for complying with a request, but the fee must not be excessive. PCPD guidance explains that charging should be based on costs directly related to and necessary for compliance, rather than a commercial profit or a deterrent to exercising the right. Inform the requester promptly of the fee and its basis.

Do not assume that a document's original acquisition price can simply be passed on as the access fee. The PCPD's case guidance has addressed this distinction. The cost of obtaining a report for the organisation's earlier business purpose differs from the cost of providing the requester's personal data now. An itemised calculation makes the rationale easier to assess.

Fee payment can affect the obligation under the applicable provisions, but it is not a reason to leave the request unmanaged. Keep records of the amount, notification, payment, and any resulting timing issue. If payment arrives near the deadline and full compliance is not possible within it, follow the statutory process rather than silently restart an arbitrary clock.

If full compliance is not possible in time

The PCPD explains that inability to comply fully within the period requires written notification of the situation and reasons within that period. The data user should comply to the extent possible and complete the response as soon as practicable afterward. A partial response should be clear about what has been supplied and what remains outstanding.

This is different from a lawful refusal under the Ordinance. A refusal needs the applicable basis and required notification. Technical inconvenience, workload, or the sensitivity of an embarrassing internal comment should not be treated as an automatic exemption. Escalate genuine exemption questions to the staff responsible for legal and privacy review.

Deliver and record the response securely

Use an appropriate delivery method for the sensitivity of the data and confirm the destination. Retain the response, the material supplied, redaction decisions, and relevant correspondence. This record supports both privacy compliance and later questions about whether the request was properly handled. An access response should not become a new unauthorised disclosure.

For HKSI questions, focus on the sequence: identify the requester, identify the personal data held, search and review it, apply any lawful restrictions, and respond within the required framework. Acknowledgement, fee notice, and final compliance are different steps. Treat each as part of a managed process rather than assuming that sending any letter closes the request.

Common questions

Is the ordinary data access deadline 40 business days?

No. The PCPD describes the ordinary period as 40 calendar days after receipt, subject to the Ordinance's applicable provisions.

Can a firm refuse every request that includes another person's data?

No. It should assess whether the request can be satisfied with appropriate redaction and apply the Ordinance's specific rules on third-party data and refusal.

Can the firm charge a commercial price for access?

The fee must not be excessive. PCPD guidance ties permitted charges to costs directly related to and necessary for complying with the request.