September 8, 2026. Hong Kong is one of the few markets where cold email is lawful without prior consent, and where the contact record you used to send it is governed by a criminal statute carrying a HK$500,000 fine and three years in prison. Both things are true at once. Most compliance guides pick one and ignore the other, which is why so many outbound teams either avoid Hong Kong entirely or walk into it assuming an opt-out market means no rules at all.
The rules sit in two ordinances enforced by two different regulators. Get the split right and Hong Kong is one of the more workable Tier-1 Asian markets for B2B outbound. Get it wrong and the exposure is not the email you sent, it is the list you bought.
Opt-out on the channel, opt-in on the data
The Unsolicited Electronic Messages Ordinance (Cap. 593), the UEMO, governs the message. The Office of the Communications Authority states the position plainly in its own published guidance: this is an opt-out regime in which, in OFCA's words, "a sender may send out unsolicited messages to electronic addresses if he/she follows the rules". Nothing in Part 2 of the Ordinance requires consent before sending. Consent appears only as an exception to the do-not-call rules, never as a precondition.
The Personal Data (Privacy) Ordinance (Cap. 486), the PDPO, governs the contact record. Part 6A makes it a criminal offence to use personal data in direct marketing without consent, and the Privacy Commissioner's position is that a work contact detail combined with a name is personal data. A generic info@ mailbox identifies nobody and falls outside it. A named individual at a company does not.
So the correct framing, and the one almost nobody uses, is this. The UEMO says you may send. The PDPO says you may not use their personal data to do it without consent. Reconciling those two is the whole job.
The Hong Kong link test decides whether the law reaches you
Section 3 of the UEMO is an exhaustive five-limb test, and satisfying any one limb pulls the message in. The message originates in Hong Kong. The sender is physically in Hong Kong, or is a Hong Kong company, or is a foreign organisation carrying on business there. The device used to access the message is in Hong Kong. The registered user of the destination address is in Hong Kong when it is accessed. Or the address was allocated by the Authority.
Section 3(2) closes the obvious escape route. For four of those five limbs it is, in the statute's own words, "immaterial whether the commercial electronic message originates in Hong Kong or elsewhere". A cold email sent from a server in Virginia to a prospect who opens it on a laptop in Central satisfies the test. OFCA confirms the same point from the recipient side: messages received in Hong Kong are covered whether or not the recipient is a Hong Kong resident.
There is a statutory defence for a sender who did not know and could not with reasonable diligence have ascertained that a message had a Hong Kong link. It is a real defence. It is not a licence to avoid checking.
The Part 2 rules every message has to satisfy
These are the operational requirements, and they are more specific than most European equivalents.
- Accurate sender information. Clear identification of the person or organisation who authorised the sending, plus contact details that are reasonably likely to stay valid for at least 30 days after the message goes out. For email, OFCA reads the subsidiary regulation as requiring a name, an address, a telephone number and an email address. A P.O. box does not satisfy the address requirement.
- A free unsubscribe facility, clearly presented. It must remain capable of receiving requests for at least 30 days, and it must cost the recipient nothing.
- Ten working days to honour an unsubscribe. Not ten calendar days. Working days here exclude public holidays and Sundays but include Saturdays, and the clock excludes black rainstorm and gale warning days.
- Three-year retention of unsubscribe requests. You have to be able to prove you received and actioned them.
- No misleading subject line. The heading must not mislead about a material fact regarding the content.
- No concealed calling line identification when sending to a telephone or fax number.
One point saves a lot of wasted effort. Hong Kong has three do-not-call registers, covering fax, short messages and pre-recorded telephone messages, and none for email, because OFCA has published the Authority's decision not to establish one. Email senders have no register to scrub against. SMS and pre-recorded voice senders do, access is paid, and a number becomes off-limits once it has been listed for ten working days.
Breaching Part 2 is not, by itself, an offence
This is the most commonly misreported fact about Hong Kong, and it changes how you should think about risk. A Part 2 contravention does not produce a prosecution. The Authority forms the view that a contravention is likely to continue or repeat, serves an enforcement notice, and only breaching that notice is the offence. The penalty then is a fine at level 6, which OFCA states is currently HK$100,000, rising to HK$500,000 on a second or subsequent conviction, plus HK$1,000 for each day the breach continues.
Part 3 works completely differently, and this is where the real exposure sits. Acquiring or using address-harvesting software, or a harvested-address list, is a standalone offence from day one with no warning shot. Do it knowingly and the maximum on indictment is HK$1,000,000 and five years. The definition is what makes this dangerous: a harvested-address list is one whose production is, in the statute's words, "to any extent, directly or indirectly" attributable to harvesting software. A purchased list is tainted if any part of its provenance traces back to scraping, even at one remove. Buyer and seller are both liable, and a responsible director can be personally liable after the company has closed.
Put bluntly: in Hong Kong, the list you bought is a bigger legal problem than the email you sent. Sound list hygiene and clean sending infrastructure are the actual compliance controls here, which is why we treat email infrastructure and list provenance as one decision rather than two.
What the PDPO adds, and the B2B carve-out that is not law
Before using personal data in direct marketing, Part 6A requires you to tell the person you intend to use it, tell them you may not do so without consent, specify the kinds of data and the classes of marketing subjects, and give them a free response channel. Then you need consent. Consent includes an indication of no objection, but the Privacy Commissioner is explicit that silence is not consent. Breach carries HK$500,000 and three years.
Passing data to someone else for their marketing is heavier again. It has to be in writing, and if the data is provided for gain the maximum rises to HK$1,000,000 and five years. That is the provision list brokers should be reading.
Now the part that makes B2B workable. The Privacy Commissioner's April 2023 direct marketing guidance sets out a three-factor test: was the data collected in the person's official capacity, is the product for the corporation or for personal use, and where it could be either, does the marketing target the company or the individual. Where data was collected in an official capacity and the product is clearly for the company's exclusive use, the Commissioner's stated position is that it "would not be appropriate to enforce" Part 6A. The published example is concrete: business cards collected from procurement staff at an office furniture exhibition, used to send office furniture brochures, fall outside enforcement. The same cards used to market beauty products to those same staff do not.
Two cautions. This is a statement of enforcement policy by a regulator, not a statutory exemption, and there is no B2B exemption anywhere in Part 6A. Never write it into a policy as though B2B is exempt. And it has no effect on the UEMO at all, which applies to messages regardless of whether personal data is involved.
Enforcement: two prosecutions in eighteen years
OFCA publishes its own enforcement statistics, and they are worth reading before anyone budgets for Hong Kong risk. From the UEMO's full commencement in December 2007 through July 2026: 36,064 reports received, 902 warning letters issued, 29 enforcement notices, and two prosecutions. In the whole of 2025, against 831 reports, the Authority issued eight warning letters and zero enforcement notices.
The channel mix in 2025 is also instructive. Of those 831 reports, pre-recorded telephone messages accounted for 509 and email for 82. Complaints about voice are rising sharply. Complaints about email are not.
On the PDPO side there is a real recent conviction. In June 2025 a Hong Kong company was convicted on two direct marketing charges and fined HK$2,500 per charge, HK$5,000 in total, against a HK$500,000 maximum. Note also the pathway: the Privacy Commissioner does not prosecute these directly, it refers cases to the police.
None of that is an argument for ignoring the rules. It is an argument for calibrating: the realistic near-term consequence of a Part 2 slip is a warning letter, while the Part 3 list offences and the PDPO provision offences are the ones that carry real numbers.
One live issue: AI voice calls
Live person-to-person calls are exempt from the UEMO entirely. Pre-recorded ones are not. In a written reply to the Legislative Council on 24 June 2026, the Government confirmed that a fully AI-powered marketing voice call, with no genuine human interaction, is subject to the UEMO. That closes an assumption a lot of voice AI vendors have been making. Note the other half of it: a live human call that is exempt from the UEMO is still squarely inside PDPO Part 6A if it is made to a named individual using their personal data.
What it means for operators
If you are running outbound into Hong Kong, five things follow.
- You can send cold B2B email without prior consent, provided the message carries real sender details, a free unsubscribe, an honest subject line, and you action opt-outs within ten working days. Set the internal SLA at five to be safe.
- Audit where your list came from before you audit your copy. Part 3 is the offence with teeth, and the "to any extent, directly or indirectly" wording means a vendor's assurance is not enough on its own. Ask for provenance in writing.
- Keep B2B genuinely B2B. The Commissioner's carve-out depends on the product being for the company. The moment you market something personal to a work address, you are relying on consent you probably do not have.
- Never sell or pass on a Hong Kong contact list for gain without written consent. That is the HK$1,000,000 provision.
- Treat AI voice as a regulated channel. Pre-recorded and fully automated calls hit the do-not-call registers and the UEMO. Live human calls do not, but the PDPO still applies.
Hong Kong rewards operators who can prove where their data came from. If you want the sending side built so that provenance, authentication and opt-out handling are auditable rather than assumed, that is what our cold email marketing and lead generation work is set up to do. For how this compares with other English-language markets, see our guides to cold email laws in New Zealand and Singapore.
Primary sources: the Unsolicited Electronic Messages Ordinance (Cap. 593) and the Personal Data (Privacy) Ordinance (Cap. 486); OFCA guidance for senders and its published enforcement statistics; the PCPD's Guidance on Direct Marketing; and the Government's 24 June 2026 reply to the Legislative Council. This article is general information about Hong Kong law and is not legal advice. Take advice from a Hong Kong qualified lawyer before relying on it.
Frequently Asked Questions
Yes. The Unsolicited Electronic Messages Ordinance operates an opt-out regime, so you may send commercial email without prior consent as long as you follow the Part 2 rules: accurate sender information, a free and clearly presented unsubscribe facility, an honest subject line, and action on opt-out requests within ten working days. The separate question is whether you may lawfully use the recipient's personal data to do it, which is governed by the Personal Data (Privacy) Ordinance and does require consent.
Usually yes. Section 3 of the UEMO applies where the message has a Hong Kong link, and the test includes the device used to access the message being in Hong Kong, or the registered user of the address being in Hong Kong when it is accessed. Section 3(2) states it is immaterial whether the message originated in Hong Kong or elsewhere. There is a defence for a sender who did not know and could not with reasonable diligence have ascertained the link, but it requires you to have actually checked.
Ten working days from the day the request is sent. Working days exclude public holidays and Sundays but include Saturdays, and days under a black rainstorm or gale warning are excluded. Because the count is working days rather than calendar days, most senders set an internal service level of five days so the legal deadline is never the binding constraint.
No. Hong Kong operates three do-not-call registers, covering fax, short messages, and pre-recorded telephone messages. OFCA has published the decision that the Communications Authority will not establish one for email. If you send only email there is no register to scrub against. If you send SMS or pre-recorded voice, access to the registers is paid, and an address becomes off-limits once it has been listed for ten working days.
It applies where the data identifies a living individual. The Privacy Commissioner's position is that an office telephone number or address combined with a person's name amounts to that person's personal data, so a named individual's work email is in scope while a generic info@ or sales@ mailbox is not. The Commissioner has separately said he would not consider it appropriate to enforce Part 6A where data was collected in an official capacity and the product is clearly for the company's exclusive use, but that is enforcement policy rather than a statutory exemption.
Breaching the Part 2 sending rules is not itself an offence. The Authority serves an enforcement notice first, and breaching that notice carries a fine at level 6, which OFCA states is currently HK$100,000, rising to HK$500,000 on a second conviction plus HK$1,000 per continuing day. Acquiring or using a harvested-address list is a standalone offence carrying up to HK$1,000,000 and five years if done knowingly. Under the PDPO, using personal data in direct marketing without consent carries up to HK$500,000 and three years, and providing it to someone else for gain without consent carries up to HK$1,000,000 and five years.