Country-specific guidance Current

Storing client identity evidence securely

What "all practicable steps" actually looks like in practice.

The Personal Data (Privacy) Ordinance doesn't list one fixed checklist for securing personal data, it sets a standard: all practicable steps. This guide sets out what that looks like in practice. It is general information, not legal or compliance advice.

Action plan

1 Apply all practicable steps, not just a default IT setting "Practicable" means reasonably practicable given your firm's actual circumstances.

Data Protection Principle 4 of the Personal Data (Privacy) Ordinance requires taking all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use. PCPD's own guidance points to measures such as encryption for data transmission, access controls and authentication, data minimisation and retention policies, and staff training, rather than treating a single default setting as sufficient.

  • Use encryption for transmitting identity evidence, not just for storage at rest
  • Apply access controls so only staff who need the evidence can reach it
  • Train staff on handling identity evidence, not just on general IT policy

Done when: The security measures applied to identity evidence reflect PCPD's practicable-steps guidance, not a single default setting

PCPD: data security guidance
2 Match protection to how sensitive the evidence is An identity document deserves tighter handling than a general enquiry note.

PCPD's guidance directs data users to have particular regard to the nature of the data and the potential harm if it's accessed, processed, or lost without authorisation. Identity documents sit at the more sensitive end of what a firm holds, so apply tighter access limits and closer monitoring to this evidence than to routine correspondence.

  • Treat identity documents as higher-sensitivity than routine client correspondence
  • Limit access to identity evidence to staff who genuinely need it for the engagement
  • Review access permissions periodically, not just when a new matter starts

Done when: Access to stored identity evidence is limited and monitored in proportion to its sensitivity

3 Manage any third party that processes the evidence on your behalf Outsourcing storage doesn't outsource the obligation.

Where your firm engages a data processor, such as a cloud storage or document-management provider, to handle identity evidence, PCPD's guidance requires adopting contractual or other means to ensure that processor also meets the data security requirement. Check this before relying on a third-party platform, not after an incident.

  • Confirm any third-party storage or document-management provider meets equivalent security standards
  • Put the security requirement into the contract with that provider, not just an informal expectation
  • Review third-party arrangements periodically, not only at initial selection

Done when: Any third-party processor handling identity evidence is contractually bound to an equivalent security standard

See setting a record-retention schedule for compliance evidence