Non-Profit & Associations

PDPO Policy for Hong Kong Non-Profit Compliance

A Hong Kong PDPO policy covering all six DPPs, PCPD codes, data processors, overseas access and form-ready PICS.
4.7/515 reviews50 000+ downloadsInstant download
Share

A Hong Kong data protection policy gives a non-profit one workable set of rules for the personal data it receives from donors, members, volunteers, beneficiaries, employees and website visitors. That matters because the same organisation may collect a payment reference in the morning, a volunteer's health adjustment at lunchtime and a beneficiary's photograph in the afternoon. Each record carries a different purpose, audience and risk. This template turns those differences into an organisation-wide policy, a retention schedule and notices for the forms people actually complete. It is designed for societies, charitable trusts, companies limited by guarantee and other bodies using the wider collection of Hong Kong non-profit and association documents.

The result is an internal governance document with public-facing collection wording. It does not assume that a charity is exempt from privacy law or that a website statement can replace the notice required at the point of collection.

Compliant

2026 Legislation

50,000+ clients

trust us

Affordable

From $4.90 / doc

Secure payment

Instant download

PDPO Policy for Hong Kong Non-Profit Compliance

Secure payment

Fill in the template

What is a Hong Kong data protection policy?

A Hong Kong data protection policy records how an organisation collects, holds, uses, discloses, protects and disposes of personal data. Under the Personal Data (Privacy) Ordinance (Cap. 486), or PDPO, the organisation will generally be a data user when it controls those activities. The policy therefore speaks to the board, employees, volunteers, contractors and service providers who handle data on its behalf.

This template is not a website notice alone. It allocates responsibility to the board, a privacy contact and programme owners. It also sets operational rules for data inventories, access controls, retention reviews, processor appointments, overseas access, incident handling, training and audits. Separate clauses address photographs, testimonials, member directories and other publication decisions, including the risk created by disclosing personal data without the relevant consent where the doxxing provisions may apply.

The document covers paper files, email, messaging services, cloud platforms, recordings and archived material. The organisation must still match the text to practice. A policy cannot repair a donation form that collects unnecessary identity data or a shared drive open to people who have no reason to see beneficiary files.

2

When a non-profit needs this policy

The practical trigger is control of information about identifiable living people, not the organisation's tax status or size. A small society with a spreadsheet of member names and telephone numbers is already handling personal data. A charity running casework, safeguarding or health-related programmes holds records whose unauthorised disclosure could cause much greater harm. A company limited by guarantee may also have employees, directors, contractors, donors and event participants in different systems.

The policy is useful when an organisation replaces informal practices, opens online forms, appoints a cloud provider, starts named fundraising or recruits volunteers. It also creates a common standard where teams have developed their own forms and storage habits. Employers should align it with their Hong Kong employment and HR documents, because the PCPD's Human Resource Management Code sets more specific expectations for employment records.

Adoption should follow a factual review. The organisation needs to identify the data it holds, why it holds it, where it is stored, who can access it, which processors receive it and when it should be deleted. That exercise often exposes the real issues: optional fields presented as mandatory, old volunteer applications kept indefinitely, copies of identity cards retained without a sound reason, or photos reused for publicity without checking the original notice.

3

Clauses and notices included in the template

The generated document contains 22 policy sections and five appendices. Its main components are:

  • document control, scope, definitions and board-level accountability;
  • rules for collection, data minimisation, accuracy, retention, use and security under all six DPPs;
  • treatment of donor, member, volunteer, beneficiary, employee, governance, supplier, event and website data;
  • direct marketing controls for named fundraising and promotional communications;
  • processor due diligence, contract terms, overseas access and cross-border safeguards;
  • procedures for disclosures, publications, incidents, access requests, correction requests and complaints;
  • specific treatment of children, vulnerable persons, cookies, photographs, recordings and identity documents;
  • a retention schedule, three separate PICS and a form deployment checklist.

The identity document clause expressly refers to the PCPD's Code of Practice on the Identity Card Number and Other Personal Identifiers. It tells the organisation to collect an identity number or copy only where collection is permitted and necessary, and to prefer a less intrusive verification method where one will do. Employment records are tied to the Code of Practice on Human Resource Management. These references make the policy more precise than a generic promise to handle sensitive information carefully.

The retention schedule lets the user set periods for donation records, former member records, unsuccessful volunteer applications and former volunteer files. It also explains that applicable income and expenditure records must be retained for at least seven years under section 51C of the Inland Revenue Ordinance. That statutory reference is a floor where the section applies, not a reason to keep every category of personal data for seven years. Governance, safeguarding, disputes and legal holds may justify different periods.

For a non-profit incorporated as a company, the privacy policy should sit beside the entity's constitutional and governance records in its Hong Kong business and incorporation document set. The documents have different jobs: constitutional records regulate the organisation, while this policy regulates the personal data moving through its activities.

4

PICS for donation, membership and volunteer forms

A Personal Information Collection Statement is not the same thing as the full policy. DPP1(3) requires specified information to reach an individual on or before collection when the organisation collects personal data directly. A PICS should explain whether supply is obligatory or voluntary, the consequence of withholding obligatory information, the purposes of use, the classes of possible transferees, access and correction rights, and the person or job title and address handling those requests.

The template supplies distinct notices for donation, membership and volunteer forms because those transactions do not have the same purpose or recipients. The donation notice covers processing and acknowledging the gift, receipts, financial controls and fraud prevention. The membership notice addresses eligibility, registers, meetings, voting and governance. The volunteer notice deals with suitability, references, training, placement, safety, adjustments, safeguarding and expenses. Each version marks the boundary between required information and genuinely optional fields.

If direct marketing is selected, each PICS gains a separate consent statement and response channel. If it is not selected, the notice says the collected data will not be used for direct marketing while preserving necessary service or relationship messages. That distinction prevents an operational email about a donation receipt or volunteer shift from being confused with a named fundraising appeal.

Before deployment, compare each notice with the finished form. Broad transferee language, hidden optionality and stale contact details are common faults. The PICS should be conspicuous, readable and specific, with the privacy contact and postal address filled in correctly.

5

How the document adapts to the organisation

The guided questionnaire asks for the organisation's legal name, form, registration reference, address, public contact details, policy version, approval information and privacy contact. It then records documented operational choices about retention, direct marketing, overseas hosting or access, and volunteers under 18.

Those answers change the legal text. Choosing direct marketing inserts the consent, subject-matter and opt-out controls; choosing no direct marketing inserts a prohibition and an approval process for any later change. Where overseas hosting, support or remote access is used, the questionnaire asks for locations, service arrangements and safeguards. The resulting clauses acknowledge that section 33 of the PDPO has not been brought into operation while still requiring due diligence, transparency, contractual protection and transfer assessment. A separate branch gives age-appropriate rules where volunteers under 18 are accepted.

The questions about retention do not impose one period across every record. They populate a schedule that distinguishes financial files, member administration and volunteer records. The privacy contact details then flow into the policy and all three PICS, reducing the chance that a form points data subjects to a person or address different from the one named in the internal procedure.

6

Putting the policy into practice

Completion is the drafting stage, not the end of the compliance work. The board or governing body should approve the final policy, record the approval date and give the privacy contact enough authority to maintain it. Programme owners should then update live forms, publish the appropriate privacy information, remove unnecessary fields and set deletion tasks against the agreed retention schedule.

Processor contracts deserve a separate check. The policy expects written terms covering instructions, confidentiality, access, security, sub-processing, retention, return or deletion, overseas access, incident reporting and audit information. A familiar software provider should not escape review merely because several teams already use it. The same applies to external mailing services, payment processors, event platforms and volunteer management systems.

Training should use examples drawn from the organisation's work. A fundraiser needs to recognise an opt-out. A volunteer coordinator needs to restrict access to health and safeguarding information. A communications officer needs approval before publishing an identifiable beneficiary story. Anyone receiving an access request or discovering a lost device needs to know whom to contact immediately.

Review the policy at least annually and after a material legal, programme, technology or provider change. Keep a record of incidents and decisions, including why an exception or a longer retention period was necessary. The most persuasive evidence of compliance is the connection between the approved wording, the forms people see and the controls operating behind them.

Key takeaways

PDPO SCOPE

One policy for every type of record

This policy treats the organisation as a data user under the Personal Data (Privacy) Ordinance (Cap. 486) whenever it controls how personal data is collected, held, used or disclosed. It is built for mixed datasets: donor payment references, volunteer health adjustments, beneficiary photographs, staff records and website enquiries. Each has a different purpose and risk, but the rules must still join up.

POINT OF COLLECTION

Use a proper PICS, not just a website page

A website privacy statement does not replace the Personal Information Collection Statement required at the point of collection. The template is form-ready, so the notice can sit on donation forms, membership sign-ups, volunteer applications and programme intake sheets. It forces you to match each field to a stated purpose, the likely transferees and retention approach, reducing the chance of collecting unnecessary identity data.

OPERATIONS

Assign owners, control access, and plan for requests

The document is an internal governance tool, not just wording for the public. It allocates responsibility to the board, a privacy contact and programme owners, then sets operational rules for inventories, access controls, retention reviews, processor management, overseas access and incident handling. It also flags statutory handling of data access requests, including readiness to meet the PDPO 40-day response period.

Frequently Asked Questions

The policy becomes an approved internal rule when the organisation adopts it through its governing process. Its legal value still depends on accurate completion, lawful practices and proper implementation. The PDPO and other mandatory rules prevail over inconsistent wording. Staff, volunteers, contractors and processors should be made subject to the relevant duties through governance decisions, training, engagement terms and contracts. The document supports compliance, but adopting it does not by itself prove that every database, form or disclosure complies with the law.

It includes tailored PICS wording for donation, membership and volunteer forms. Each notice covers supply, consequences, purposes, transferee classes, access and correction rights, and privacy contact details. The organisation should insert the relevant PICS into the form or display a clear link before submission. Other collection journeys, such as beneficiary intake, recruitment, event registration or website tracking, may need their own notice based on the same rules and the actual information collected.

Yes. Captain.Legal produces the completed document in Word and PDF, as explained in the Hong Kong platform FAQ. Use the Word version for a controlled legal or operational review, especially where programme names, processor arrangements or internal job titles need adjustment. Use the PDF as the approved reference copy after the governing body has settled the wording. Keep version, effective date and approval information consistent across both files and replace outdated copies when the policy changes.

There is no sound rule that every donor record should remain for the same period. Where section 51C of the Inland Revenue Ordinance applies, relevant income and expenditure records must be kept for at least seven years after the transaction is completed. Contact preferences, relationship notes and campaign data may have a different life. The template asks for a financial retention period, records the statutory floor where applicable and requires deletion or irreversible anonymisation once another purpose or legal need no longer justifies retention.

Yes. The main policy covers recruitment, employment, payment, performance, disciplinary and governance records, and it refers expressly to the PCPD's Human Resource Management Code. The organisation should connect those rules to its recruitment notices, access permissions, retention decisions and processor arrangements. Its Hong Kong employment contract template serves a different purpose and does not replace an employment PICS or internal privacy procedure. Health, identity and disciplinary information should receive access controls proportionate to the possible harm.

The policy requires immediate internal escalation, containment, preservation of evidence and a documented assessment of the data, people, cause and likely consequences involved. The organisation should decide whether to notify affected individuals, the PCPD, law enforcement, insurers or contractual partners according to the circumstances and applicable duties. It should also recover or erase exposed data where possible, correct the weakness and record the response. Hong Kong does not impose one universal breach notification rule for every incident, so a reasoned assessment matters.

4.7/5

15 verified reviews · 50 000+ downloads

PDPO Policy for Hong Kong Non-Profit Compliance
  • Immediate access to the document
  • PDF + Word download
  • Compliant with 2026 legislation
  • Reviewed by lawyers
Fill in the template
Secure payment
Updated on August 24, 2026

You might also like

Charity Governance Pack Hong Kong
Hong Kong Volunteer Agreement