The Personal Data (Privacy) Ordinance for intermediaries
The Personal Data (Privacy) Ordinance binds every data user in Hong Kong, including SFC-licensed firms, through six data protection principles: collection, accuracy and retention, use, security, openness, and access and correction. For intermediaries the sharpest edges are the use principle and the separate direct marketing consent regime.
A brokerage collects more personal data before the first trade than most businesses collect in a year. Identity documents, address proof, income, net worth, employment, family circumstances, sometimes the source of an inheritance. All of it is personal data, and all of it is governed by an ordinance that predates the firm's compliance manual by decades.
The syllabus reduces that to six principles. Learn them in order and Topic 6 gets noticeably easier.
What are the six data protection principles?
| Principle | What it requires | Where a securities firm trips |
|---|---|---|
| Collection | Collect lawfully and fairly, for a purpose directly related to a function of the data user, and no more than necessary | Copying an entire identity document when only the number is needed |
| Accuracy and retention | Keep data accurate; do not keep it longer than necessary for the purpose | Retaining closed-account files indefinitely because nobody owns deletion |
| Use | Do not use data for a new purpose without the data subject's prescribed consent | Account data reused for marketing a new product |
| Security | Take all practicable steps to protect data against unauthorised or accidental access, loss or use | Client lists on an unencrypted laptop or a personal messaging app |
| Openness | Make policies and practices on personal data generally available | No published privacy policy, or one that nobody can find |
| Access and correction | Let data subjects access their data and correct inaccuracies | Ignoring a data access request or charging an excessive fee |
Six. That count is worth holding on to, because questions sometimes offer a seventh invented principle among the options, and it always sounds plausible.
What does the collection principle actually restrict?
Purpose and volume. Data must be collected for a lawful purpose directly related to a function or activity of the data user, and the collection must be necessary and not excessive for that purpose. Collecting a client's marital status to open a securities account is hard to justify. Collecting their income is not, because suitability requires it.
There is also a notification duty at the point of collection. The data subject must be told the purpose, the classes of person to whom the data may be transferred, and their rights of access and correction. That is what the Personal Information Collection Statement in the account-opening pack is doing.
Why is the use principle the one that bites?
Because reuse is so easy and so tempting. Data collected to open and operate an account has been collected for that purpose. Using it to market a structured product, to build a lookalike audience, or to pass to an affiliate is a new purpose, and a new purpose needs the data subject's prescribed consent.
Direct marketing sits on top of this with its own regime. Before using personal data in direct marketing, the firm must notify the data subject of its intention, tell them the kinds of data to be used and the classes of goods or services being marketed, and obtain their consent. The data subject may require the firm to stop at any time, and the firm must comply without charge. Where personal data is to be provided to someone else for their direct marketing, the requirements are stricter still, and written consent is needed.
A pre-ticked box, or a line in the terms saying the client agrees to marketing unless they object, does not meet the consent standard for direct marketing. Questions on this heading usually turn on exactly that point.
How does a data access request work?
A data subject may ask whether the firm holds personal data about them and ask for a copy. The firm has to respond within the statutory period, either supplying the data or refusing on a permitted ground. A fee may be charged, but it must not be excessive.
The interaction that catches intermediaries is the one with the anti-money laundering regime. A client who suspects a suspicious transaction report has been filed may make a data access request to find out. Disclosing the report would be tipping off. The privacy legislation contains exemptions for exactly this kind of conflict, which is why a firm faced with such a request escalates rather than answers.
Who enforces it, and what happens on breach?
The Privacy Commissioner for Personal Data. The Commissioner investigates complaints, can serve an enforcement notice directing a data user to remedy a contravention, and failing to comply with such a notice is an offence. Contravening a data protection principle is not, in itself, a criminal offence, which is a distinction worth carrying into the exam. Some specific conduct, including breaches of the direct marketing rules and certain disclosures of personal data obtained without consent, is criminalised directly.
For an SFC licensee there is a second consequence. A serious data breach is a control failure, and control failures bear on fitness and properness as much as on the privacy regime.
A worked question
A licensed corporation wants to email existing clients about a new fund. The account-opening form contains a clause stating that clients agree to receive marketing unless they write to opt out. Is this sufficient?
- Yes, because the clients accepted the clause when they opened the account
- Yes, provided each email contains an unsubscribe link
- No, because using the data for marketing is a new purpose requiring the data subject's consent, and an opt-out clause does not supply it
- No, because direct marketing to existing clients is prohibited
How to revise this in twenty minutes
Write the six principles from memory, in order, on a blank page. Do it three times across three days. That is the whole technique, and it is more effective than any amount of reading, because the questions are recognition tests and recognition follows recall.
My view is that this is the best-value heading in the entire syllabus. Six items, no ambiguity, no case law to weigh, and they reappear in Topic 6 practice questions with almost no variation. The concession: it is also the heading most likely to feel irrelevant to your day job, and candidates skip it for that reason. The exam does not care whether the material is interesting.
Common questions
What are the six data protection principles in Hong Kong?
Collection, accuracy and retention, use, security, openness, and access and correction. They sit in a schedule to the Personal Data (Privacy) Ordinance and bind every data user in Hong Kong, including SFC-licensed corporations and their representatives.
Can a licensed firm use client account data for marketing?
Not without consent. Marketing is a new purpose, and the use principle prohibits using personal data for a new purpose without the data subject's prescribed consent. The direct marketing regime adds its own notification and consent requirements on top.
Is an opt-out clause enough for direct marketing consent?
No. The firm must notify the data subject of its intention to use the data in direct marketing, identify the kinds of data and the classes of goods or services concerned, and obtain consent. A clause deeming agreement in the absence of an objection does not satisfy that.
Who enforces the Personal Data (Privacy) Ordinance?
The Privacy Commissioner for Personal Data, who investigates complaints and can serve enforcement notices requiring a data user to remedy a contravention. Failing to comply with an enforcement notice is an offence, as is certain specified conduct including breaches of the direct marketing rules.
How long can a firm keep client personal data?
No longer than is necessary for the purpose for which it was collected, under the accuracy and retention principle. Other rules, including record-keeping obligations under the securities regime, may require data to be kept for a defined period, and the two have to be reconciled.