• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
location icon香港中環雪厰街二號聖佐治大廈五樓503室phone-icon +852 2868 0696 linkedintwitterfacebook
OLN IP Services
close-btn
OLN IP Services
Get bespoke and commercially-driven advice to your Intellectual Property
Learn More
OLN IP Services
OLN Online
close-btn
OLN Online
Powered by Oldham, Li & Nie, the law firm of choice for Hong Kong’s vibrant startup and SME community, OLN Online is a forward-looking and seamless addition to traditional legal services – a true disruptor.
Learn More
OLN IP Services
  • 繁
    • ENG
    • 简
    • FR
    • 日本語
Oldham, Li & Nie
OLN IP Services
close-btn
OLN IP Services
Get bespoke and commercially-driven advice to your Intellectual Property
Learn More
OLN IP Services
OLN Online
close-btn
OLN Online
Powered by Oldham, Li & Nie, the law firm of choice for Hong Kong’s vibrant startup and SME community, OLN Online is a forward-looking and seamless addition to traditional legal services – a true disruptor.
Learn More
OLN IP Services
  • 關於
        • 獎項與排名
        • 企業社會責任
  • 專業服務
        • 加拿大公證服務
        • 中國事務
        • 香港僱傭法和商業移民法律服務
        • 破產法
        • 爭議解決
        • 投資基金
        • 公證服務
        • 長者法律服務
        • 家事法
        • 保險
        • 私人客戶 – 遺產規劃和遺囑認證
        • 商業詐騙和資產追踪
        • 人身傷害法
        • 稅務諮詢部
        • 中國委托公証服務
        • 知識產權法
        • 金融服務監管部
        • 日本事務
        • 公司和商業法
        • Startups & Venture Capital
        • 法國事務
        • 合規、調查和執法
        • 加拿大公證服務
        • 中國事務
        • 家事法
        • 知識產權法
        • 香港僱傭法和商業移民法律服務
        • 保險
        • 金融服務監管部
        • 破產法
        • 私人客戶 – 遺產規劃和遺囑認證
        • 爭議解決
        • 人身傷害法
        • 日本事務
        • 投資基金
        • 稅務諮詢部
        • 商業詐騙和資產追踪
        • 公證服務
        • 法國事務
        • 公司和商業法
        • Startups & Venture Capital
        • 長者法律服務
        • 中國委托公証服務
        • 合規、調查和執法
  • 律師團隊
  • 最新消息
  • 辦事處

Suite 503, St. George's Building,
2 Ice House Street, Central, Hong Kong

Tel. +852 2868 0696 | Send Email
linkedin twitter facebook
OLN Blue

OLN

  • Block Content Examples
  • Client Information & Registration
  • Contact Us
  • Cookie Policy (EU)
  • Globalaw
  • OLN Podcasts
  • Privacy Policy
  • Review
  • Test Blog
  • 加入我們
  • 專業服務
  • 律師團隊
  • 我們的歷史
    • 獎項與排名
    • 高李嚴律師行的企業社會責任
  • 所獲獎項
  • 標準服務條款
  • 聯繫我們
  • 評價
  • 評語
  • 辦事處
  • 關於我們
  • 高李嚴律師行
  • 高李嚴律師行和社區
  • 關於
        • 獎項與排名
        • 企業社會責任
  • 專業服務
        • 加拿大公證服務
        • 中國事務
        • 香港僱傭法和商業移民法律服務
        • 破產法
        • 爭議解決
        • 投資基金
        • 公證服務
        • 長者法律服務
        • 家事法
        • 保險
        • 私人客戶 – 遺產規劃和遺囑認證
        • 商業詐騙和資產追踪
        • 人身傷害法
        • 稅務諮詢部
        • 中國委托公証服務
        • 知識產權法
        • 金融服務監管部
        • 日本事務
        • 公司和商業法
        • Startups & Venture Capital
        • 法國事務
        • 合規、調查和執法
        • 加拿大公證服務
        • 中國事務
        • 家事法
        • 知識產權法
        • 香港僱傭法和商業移民法律服務
        • 保險
        • 金融服務監管部
        • 破產法
        • 私人客戶 – 遺產規劃和遺囑認證
        • 爭議解決
        • 人身傷害法
        • 日本事務
        • 投資基金
        • 稅務諮詢部
        • 商業詐騙和資產追踪
        • 公證服務
        • 法國事務
        • 公司和商業法
        • Startups & Venture Capital
        • 長者法律服務
        • 中國委托公証服務
        • 合規、調查和執法
  • 律師團隊
  • 最新消息
  • 辦事處
Data privacy APAC countries

APAC Perspectives on Data Privacy Laws: A Globalaw Roundtable Discussion Recap

Data protection

APAC Perspectives on Data Privacy Laws: A Globalaw Roundtable Discussion Recap

May 19, 2025 by OLN Marketing

On 25 April 2025, at the Globalaw Asia Pacific Regional Meeting in Osaka, Japan, our Partner and Head of Tax and Private Client, Anna Chan, joined Uday Singh Ahlawat of Ahlawat & Associates (India), Han Sung Kang of DLG Law Corporation (South Korea), Ariel Hung of Stellex Law Firm (Taiwan) and Yusaku Akasaki of Chuo Sogo LPC (Japan) for an insightful roundtable discussion on the evolving landscape of data privacy laws across key APAC jurisdictions.

Globalaw Asia Pacific Roundtable on Data Protection
Globalaw Asia Pacific Roundtable on Data Protection

The recent decade has seen an increase of phishing attacks and data breaches. With the introduction of the new cybersecurity law in Hong Kong which will come into effect next year, there is heightened concerns over data security and rights of data subjects. The roundtable discussion therefore offered a timely forum to visit topics such as obtaining consent from data subjects, protecting the rights of data subjects and data breaches reporting practices, as well as on recent legislative developments in in Hong Kong, India, Japan, South Korea, and Taiwan. This article summarises each of the participants’ inputs in the roundtable discussion, each speaking from their respective jurisdictions, on these topics.

Obtaining consent from data subjects
  • In Hong Kong, a data user must expressly inform the data subject the purpose for which the data is to be used on or before collection of the data. Provision of personal data pursuant to such information by the data subject shall be deemed sufficient consent which is implied. However, new consent from the data subject is required if such personal data shall be used for a new purpose. So far as cross-border transfer is concerned, the Personal Data (Privacy) Ordinance (“PDPO”) provides, among others, that data subject should also consent in writing specifically but this requirement has not come into effect yet.
  • In India, when seeking consent from data principals, it is crucial to sufficiently disclose that their personal information will be transferred to another entity. The details of such third-party entity (to which the data will be transferred) as well as the purpose of such transfer also needs to be disclosed. In the case of cross-border transfer of personal information, the manner of seeking consent from data principals remains the same.
  • In Japan, business operators must clearly outline the purpose of data collection and obtain specific consent for the cross-border transfer of personal information with certain exceptions.
  • In South Korea, informed and voluntary consent is essential for collecting and using personal data, unless a legal exception applies. Also, consent for collection, third-party provision, and cross-border transfers must be clearly distinguished and obtained separately.
  • In Taiwan, organizations must expressly inform data subjects when collecting personal data, detailing the collection purposes, data types, usage scope (duration, geography, territory, and methods), data subject rights, and consequences of non-disclosure, unless exempt by law. When collection involves planning for cross-border transfers, intended overseas jurisdictions should also be specified.

Is there a “right to be forgotten”?
  • In Hong Kong, while there is no express “right to be forgotten”, under the PDPO, data users must ensure personal data is retained only as long as necessary, and generally must take practicable steps to erase the personal data held by them where it is no longer required unless the statutory exemptions apply.
  • In India, there is no clear statutory provision for the “right to be forgotten” but the Indian courts have recognized the “right to be forgotten” in some judicial pronouncements. The Indian judiciary has also attempted to clarify the distinction between “right to be forgotten” and the “right to erasure” in their judicial pronouncements. Further, the forthcoming Digital Personal Data Protection Act (“DPDPA”) will provide for a statutory “right to erasure” (unless the statutory exemptions apply).
  • In Japan, while there is no express “right to be forgotten”, the Act on the Protection of Personal Information (“APPI”) recognises the right of data subjects to correct, add, or delete their personal data only on the ground that the retained personal data is contrary to the fact.
  • In South Korea, data subjects have the rights to access, correct, delete, and suspend the processing of their data, as well as to withdraw consent. While there is no express “right to be forgotten”, it is being increasingly recognised in practice as a separate right from the general deletion right. In common practice, business operators in South Korea often establish a defined retention period and periodically re-request consent.
  • In Taiwan, while there is no explicit “right to be forgotten”, similar protections exist under the Personal Data Protection Act (“PDPA”) through various data subject rights, including rights to access, correct, delete data and demand cessation of data processing and use. In practice, certain Taiwan courts have interpreted constitutional principles of informational self-determination and privacy to support this right, balancing individual rights against public interest when assessing removal requests, thus adapting to emerging digital privacy challenges.

Data breaches reporting practices
  • In Hong Kong, business operators are encouraged to voluntarily report data breaches in accordance with the best practices published by the Office of the Privacy Commissioner for Personal Data. For now, there are no specific criminal penalties for data breaches while civil liabilities may arise from breaches of contract, confidentiality, and negligence. That said, the newly enacted Protection of Critical Infrastructures (Computer Systems) Ordinance, expecting to take effect on 1 January 2026, will require the operators of crucial infrastructures in Hong Kong in the eight industries including energy, information technology, banking and financial services, transportation, telecommunications and broadcasting services and healthcare services to, among others, implement security plans and protocols, and report on security incidents. Failure to comply will result in fines ranging from HK$500,000 to HK$5 million.
  • In India, the forthcoming DPDPA prescribes that data breaches shall be reported to both the Data Protection Board of India and the data principal without delay. Failure on the part of data fiduciaries in providing such a notice could result in severe criminal penalties (as prescribed under the DPDPA).
  • In Japan, in the event of serious data security breaches, business operators are required to notify both the Personal Information Protection Commission (“JPIPC”) and data subjects. The APPI imposes criminal penalties for various improper handling of personal data as well as failure to comply with the JPIPC rectification requests and orders.
  • In South Korea, in the event of any leak involving sensitive personal data, business operators should notify the Korean Personal Information Protection Commission and data subjects within 24 hours of identifying such leak. Criminal penalties are imposed for intentional or severe negligence (e.g. illegal data sales or leaks), alongside with administrative fines, corrective orders, potential suspension of processing and public disclosure.
  • In Taiwan, the PDPA currently mandates that organisations are required to notify affected individuals of data breaches only after the relevant facts have been clarified. Criminal penalties apply for intentional misconduct, with a tiered system of administrative fines for other non-compliance. Notably, proposed amendments to the PDPA announced in March 2025 include heightened reporting requirements, and business operators should monitor these upcoming developments closely.

Disclaimer: This article is for reference only. Nothing herein shall be construed as Hong Kong legal advice or any legal advice for that matter to any person. Oldham, Li & Nie shall not be held liable for any loss and/or damage incurred by any person acting as a result of the materials contained in this article.

Filed Under: 金融服務監管部, 最新消息, Regulatory Compliance, Investigations and Enforcement Tagged With: data privacy, Data protection

Primary Sidebar

This website uses cookies to optimise your experience and to collect information to customise content. By closing this banner, clicking a link or continuing to browse otherwise, you agree to the use of cookies. Please read the cookies section of our Privacy Policy to learn more. Learn more

Footer

OLN logo

香港中環雪厰街二號聖佐治大廈
五樓503室

電話 +852 2868 0696 | 電郵我們
關於 律師團隊 辦事處 OLN IP Services 私隱政策
專業服務 最新消息 加入我們 OLN Online
關於 專業服務 律師團隊 最新消息 辦事處
加入我們 OLN IP Services OLN Online 私隱政策
linkedin twitter facebook
OLN logo

© 2025 Oldham, Li & Nie. All Rights Reserved.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
聯絡我們

請在此處分享您的訊息的詳細資訊。我們將盡快與您聯繫。

    x