In December 2017, the Privacy Commissioner for Personal Data ("PCPD") issued guidance titled Data Protection & Business Facilitation—Guiding Principles for Small and Medium Enterprises ("Guiding Principles") to assist small and medium enterprises. The Guiding Principles cover a number of areas, including: (i) collecting customers' personal data; (ii) use of customers' personal data; (iii) safeguarding customers' personal data; (iv) operating online businesses or services; (v) operating businesses outside Hong Kong; (vi) marketing of products or services; (vii) recruitment; (viii) installing CCTV for security purpose; (ix) collecting employees' personal data for monitoring; (x) outsourcing the processing of personal data; and (xi) handling data access and data correction requests.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.