Skip to main content

Cloud Services Agreement (Hong Kong)

Cloud Services Agreement (Hong Kong)

CLOUD SERVICES AGREEMENT

Personal Data (Privacy) Ordinance (Cap. 486), Hong Kong SAR

This Cloud Services Agreement is entered into on [Agreement Date] between:

(1) [Provider Name] (CRN: [Provider CRN]) of [Provider Address] (“the Provider”); and

(2) [Customer Name] (CRN: [Customer CRN]) of [Customer Address] (“the Customer”).

1. CLOUD SERVICES

1.1 The Provider agrees to provide [Service Type] services to the Customer as described in this Agreement.

1.2 Service description: [Service Description].

1.3 Data centre location(s): [Data Centre Location]. The Provider shall not move Customer data outside the specified location(s) without the Customer’s prior written consent.

1.4 The initial contract term is [Contract Term] from the date of this Agreement, automatically renewing for successive 12-month periods unless either Party gives at least 90 days’ written notice before the end of the then-current term.

1.5 The Provider shall perform all services with reasonable care and skill in accordance with the Supply of Services (Implied Terms) Ordinance (Cap. 457).

2. SERVICE LEVELS

2.1 The Provider guarantees [Uptime Commitment] availability of the services, measured monthly, excluding scheduled maintenance windows notified at least 48 hours in advance.

2.2 Support is available during [Support Hours]. Severity 1 incidents (service unavailable) shall receive initial response within 30 minutes.

2.3 If the Provider fails to meet the uptime commitment in any calendar month, the Customer is entitled to a service credit of [Service Credit Rate] of the monthly fee for each full 0.1% below the committed level, capped at 100% of the monthly fee.

3. FEES AND PAYMENT

3.1 The Customer shall pay [Monthly Fee] per month. No GST or VAT applies in Hong Kong.

3.2 Payment terms: [Payment Terms]. Invoices are due within 30 days of issue.

3.3 Late payments attract interest at [Late Penalty Rate]% per month on overdue amounts.

3.4 The Provider may suspend services if any invoice remains unpaid for more than 30 days after the due date, upon 14 days’ written notice.

4. DATA PROTECTION

4.1 Personal data processing: [Personal Data Processed]. Categories of personal data: [Data Categories].

4.2 The Provider shall comply with the Personal Data (Privacy) Ordinance (Cap. 486) and its Data Protection Principles. The Provider shall process personal data only on the Customer’s documented instructions (DPP 3) and implement appropriate security measures (DPP 4).

4.3 The Provider shall notify the Customer without undue delay upon becoming aware of any actual or suspected data breach and provide reasonable assistance in investigating and remediating the breach.

4.4 The Provider shall assist the Customer in responding to data access and correction requests under DPP 6 of the PDPO.

5. INTELLECTUAL PROPERTY AND DATA OWNERSHIP

5.1 The Customer retains all intellectual property rights in its data, content, and configurations stored on the Provider’s platform.

5.2 The Provider retains all intellectual property rights in its platform, software, infrastructure, and documentation.

5.3 Nothing in this Agreement transfers ownership of either Party’s intellectual property to the other Party.

6. TERMINATION AND DATA EXIT

6.1 Either Party may terminate this Agreement for material breach not remedied within 30 days of written notice, or upon insolvency of the other Party.

6.2 Upon termination, the Provider shall make all Customer data available for export in a standard machine-readable format for a transition period of 60 days.

6.3 After the transition period, the Provider shall permanently delete all Customer data from its systems within 30 days and provide written certification of deletion, consistent with DPP 2 of the PDPO.

7. GOVERNING LAW AND DISPUTES

7.1 This Agreement is governed by the laws of the Hong Kong Special Administrative Region of the People’s Republic of China.

7.2 Disputes: [Dispute Resolution]. If HKIAC arbitration is selected, disputes shall be finally resolved by arbitration under the HKIAC Administered Arbitration Rules, with the seat of arbitration in Hong Kong.

EXECUTION

IN WITNESS WHEREOF, the Parties have executed this Cloud Services Agreement as of the date first written above.

Provider (Authorised Signatory)

________________

Signature

Customer (Authorised Signatory)

________________

Signature

Maintained by Vladislav Sergienko, Founder·Template last modified: ·Report an error

What Is a Cloud Services Agreement (Hong Kong)?

A Cloud Services Agreement in Hong Kong sets out the rights and obligations the parties agree to be bound by.

The Personal Data (Privacy) Ordinance (Cap. 486) — administered by the Office of the Privacy Commissioner for Personal Data (PCPD) — is the primary data protection statute in Hong Kong. Schedule 1 of Cap. 486 contains six Data Protection Principles (DPPs) that govern all personal data processing. DPP 4 imposes an obligation on data users (including customers of cloud services) to take all practicable steps to confirm that personal data held by the data user (or on its behalf by a data processor such as a cloud provider) is protected against unauthorised or accidental access, processing, erasure, loss, or use. This obligation requires customers to conduct due diligence on cloud providers' security measures and to include appropriate contractual protections in the cloud services agreement. The PCPD has published specific guidance on cloud computing recommending written contracts specifying data handling obligations, data centre locations, sub-processing arrangements, and incident response procedures.

For regulated entities in Hong Kong, additional sector-specific requirements apply. The Hong Kong Monetary Authority (HKMA) — the central bank and banking regulator — has issued the Supervisory Policy Manual module on technology risk management (TM-G-1) and the cloud computing guidance requiring authorised institutions (banks) to conduct risk assessments, perform due diligence on cloud providers, maintain an exit strategy, and notify the HKMA before outsourcing critical or important operations to cloud providers. The Securities and Futures Commission (SFC) has issued circular guidance on cloud computing for licensed corporations. The Insurance Authority (IA) similarly requires oversight of cloud arrangements by regulated insurers.

Hong Kong imposes no goods and services tax (GST) or value-added tax (VAT), meaning the agreed service fees are the total amounts payable without any consumption tax. All fees should be expressed in Hong Kong Dollars (HKD), though USD pricing is also common for international cloud providers. Payment is typically made by credit card, bank transfer, or direct debit under a subscription arrangement.

The Electronic Transactions Ordinance (Cap. 553) provides the legal framework for electronic contracts and electronic signatures in Hong Kong — cloud services agreements executed electronically are legally binding provided they comply with the requirements of Cap. 553. The Copyright Ordinance (Cap. 528) is relevant where the cloud service involves software licensing — customers should confirm they hold appropriate licences for any software deployed on cloud infrastructure. The Telecommunications Ordinance (Cap. 106) governs telecommunications services in Hong Kong and may be relevant to cloud connectivity and network services.

When Do You Need a Cloud Services Agreement (Hong Kong)?

Cloud Services Agreement in Hong Kong is needed whenever an organisation engages a cloud provider to host, store, process, or manage data or applications on its behalf. The following specific circumstances each require a properly drafted agreement.

Cloud infrastructure migration: When a Hong Kong business migrates its IT operations to public cloud infrastructure (AWS Asia Pacific Hong Kong, Microsoft Azure Hong Kong, Google Cloud Hong Kong) or to a private or hybrid cloud deployment, the Cloud Services Agreement governs data residency, security standards, service levels, and compliance requirements under the Personal Data (Privacy) Ordinance (Cap. 486) and the Electronic Transactions Ordinance (Cap. 553).

Regulated financial institutions: When a bank, securities broker, or insurer regulated by the Hong Kong Monetary Authority (HKMA), the Securities and Futures Commission (SFC), or the Insurance Authority (IA) engages cloud services, the agreement must comply with the HKMA's Supervisory Policy Manual TM-G-1, the SFC's circular on cloud computing, or the IA's guidance — including requirements for risk assessment, due diligence, contractual protections, notification obligations, and exit strategy documentation.

SaaS business applications: When a Hong Kong organisation subscribes to a Software as a Service (SaaS) application — such as Salesforce CRM, SAP ERP, Workday HR, or Xero accounting — that processes personal data of Hong Kong employees, customers, or counterparties, the SaaS agreement must include PDPO-compliant data processing terms under Cap. 486.

Healthcare cloud services: When a Hong Kong private hospital, medical clinic, or health data platform engages cloud services to store patient medical records or health data, the agreement must address the heightened sensitivity of health data under DPP 3 of Cap. 486 and the requirements of the Private Healthcare Facilities Ordinance (Cap. 633). The PCPD has flagged health data as requiring special care.

Cross-border data processing: When a Hong Kong organisation's cloud services involve data being processed in data centres outside Hong Kong — for example, in Singapore, Japan, or the United States — the agreement must address cross-border data transfer considerations under the PDPO guidance issued by the PCPD, even though Section 33 of Cap. 486 restricting cross-border transfers has not yet been brought into force.

What to Include in Your Cloud Services Agreement (Hong Kong)

Cloud Services Agreement in Hong Kong should contain the following key elements to be legally effective under the Personal Data (Privacy) Ordinance (Cap. 486), compliant with regulatory guidance from the Hong Kong Monetary Authority (HKMA) and the Securities and Futures Commission (SFC), and sufficient to manage data protection obligations and service quality.

Service Description: A precise definition of the cloud services provided — specifying the service model (IaaS, PaaS, or SaaS), the specific compute, storage, or software functionality, service tiers, and any exclusions or limitations. For regulated institutions, the service description must be sufficiently detailed to satisfy the HKMA’s Supervisory Policy Manual TM-G-1 due diligence requirements.

Service Level Agreement: Uptime commitments (typically 99.9% per calendar month), performance metrics, scheduled maintenance windows (excluded from uptime calculations), support response times tiered by severity (Severity 1 through Severity 4), service credit percentages for SLA breaches, and a cap on total credits. The Supply of Services (Implied Terms) Ordinance (Cap. 457) implies a baseline of reasonable care and skill even where the SLA is silent on a particular obligation.

Data Protection Compliance: The provider’s obligations as a data processor under the Personal Data (Privacy) Ordinance (Cap. 486), including compliance with Data Protection Principles 1 through 6 in Schedule 1 of Cap. 486. DPP 4 security obligations — requiring all practicable steps to protect personal data against unauthorised access, processing, erasure, loss, or use — must be specified in contractual terms. Incident notification requirements (breach notification timelines) and restrictions on onward transfer or secondary use of personal data under DPP 3 should be included.

Data Sovereignty and Residency: Identification of data centre locations where customer data will be stored and processed; whether the provider may transfer data between jurisdictions; the customer’s right to restrict data to specific geographic regions (e.g. Hong Kong, Asia-Pacific); and notification obligations if data centre locations change. For regulated financial institutions, additional data residency requirements from the HKMA apply.

Security Standards: The provider’s obligation to maintain and regularly audit technical and organisational security measures — including encryption at rest and in transit, identity and access management, network security, vulnerability management, penetration testing schedules, and audit log retention. Security incident response procedures and the timeline for notifying the customer following a security event must be specified.

Intellectual Property: Confirmation that the customer retains full ownership of all customer data uploaded to, created within, or processed by the cloud platform. The provider retains ownership of the platform, software, and underlying technology. No licence to the customer’s data beyond what is necessary to provide the services should be granted. Under the Copyright Ordinance (Cap. 528), software licensing terms should be addressed where applicable.

Regulatory Audit Rights: The customer’s right to conduct audits or commission third-party assessments of the provider’s data protection and security practices — a requirement under HKMA guidance for authorised institutions. The provider’s obligation to produce audit reports, certifications (ISO 27001, SOC 2), and regulatory examination assistance.

Termination and Data Exit: The transition period (30-90 days post-termination) during which customer data remains accessible for export; data export format (CSV, JSON, XML, or standard API); permanent deletion obligations and written certification of deletion within a specified period (typically 30 days after the transition period); deletion of backup and archival copies within 90 days; and transition assistance rates if migration support is required. These provisions align with DPP 2 of Cap. 486 (data retention) and the HKMA’s exit strategy requirements for authorised institutions.

Governing Law and Dispute Resolution: Hong Kong law as the governing law; dispute resolution by arbitration under the Hong Kong International Arbitration Centre (HKIAC) pursuant to the Arbitration Ordinance (Cap. 609), or by litigation in the Courts of First Instance; and jurisdiction clauses for interim relief. Forms-legal.com provides a free Cloud Services Agreement template for Hong Kong organisations alongside the related hk-data-processing-agreement and hk-saas-agreement.

Sources & Citations

Statutory citations link to official government sources.

  1. The Personal Data (Privacy) Ordinance (Cap. 486)HK official
  2. The Electronic Transactions Ordinance (Cap. 553)HK official
  3. The Copyright Ordinance (Cap. 528)HK official
  4. The Telecommunications Ordinance (Cap. 106)HK official
  5. Personal Data (Privacy) Ordinance (Cap. 486)HK official
  6. Electronic Transactions Ordinance (Cap. 553)HK official
  7. Private Healthcare Facilities Ordinance (Cap. 633)HK official
  8. The Supply of Services (Implied Terms) Ordinance (Cap. 457)HK official
  9. Under the Copyright Ordinance (Cap. 528)HK official
  10. International Arbitration Centre (HKIAC) pursuant to the Arbitration Ordinance (Cap. 609)HK official

Cite this page

Reference this free template in an article, syllabus, or research note:

APA

Forms Legal. (2026). Cloud Services Agreement (Hong Kong) (Hong Kong) [Legal document template]. Forms Legal. https://forms-legal.com/hong-kong/business/intellectual-property/cloud-services-agreement-hong-kong

MLA

"Cloud Services Agreement (Hong Kong) (Hong Kong)." Forms Legal, 2026, https://forms-legal.com/hong-kong/business/intellectual-property/cloud-services-agreement-hong-kong.

BibTeX
@misc{formslegal-cloud-services-agreement-hong-kong,
  author       = {{Forms Legal}},
  title        = {Cloud Services Agreement (Hong Kong) (Hong Kong)},
  year         = {2026},
  howpublished = {\url{https://forms-legal.com/hong-kong/business/intellectual-property/cloud-services-agreement-hong-kong}},
  note         = {Free legal document template. Based on Personal Data (Privacy) Ordinance (Cap. 486)}
}

Also available for these jurisdictions:

Frequently Asked Questions

Based on Personal Data (Privacy) Ordinance (Cap. 486) — Template last modified June 2026Verify the source →

This template is provided for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change over time. Consult a qualified attorney for advice specific to your situation.Full disclaimer

Found an error? Let us know

Related Documents

You may also find these documents useful:

SaaS Agreement (Hong Kong)

A Software as a Service (SaaS) Agreement for Hong Kong governing subscription-based access to cloud-hosted software. Addresses the Supply of Services (Implied Terms) Ordinance (Cap. 457), PDPO (Cap. 486) data protection, service levels, data ownership, and subscription terms. Suitable for B2B SaaS providers and enterprise customers.

IT Services Agreement (Hong Kong)

An IT Services Agreement for Hong Kong covering managed IT services, technical support, system maintenance, and IT consulting. Addresses the Supply of Services (Implied Terms) Ordinance (Cap. 457), PDPO (Cap. 486) data protection obligations, service levels, and IP ownership. Suitable for outsourced IT support, managed services providers, and IT consulting engagements.

Data Processing Agreement (Hong Kong)

A Data Processing Agreement (DPA) governing the processing of personal data by a third-party processor on behalf of an organisation, compliant with the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles. Establishes processor obligations, data handling standards, and security requirements under Hong Kong's PDPO framework.

Service Agreement (Hong Kong)

A general service agreement governing the provision of services between a service provider and client under Hong Kong law, including the Supply of Services (Implied Terms) Ordinance (Cap. 457) and the Personal Data (Privacy) Ordinance (Cap. 486). Suitable for professional, technology, creative, and commercial service engagements. No GST or VAT applies in Hong Kong. HKIAC arbitration clause included.

Non-Disclosure Agreement (Hong Kong)

A confidentiality agreement binding parties to protect proprietary information under Hong Kong common law of confidence and the Personal Data (Privacy) Ordinance (Cap. 486). Suitable for employment, business partnerships, technology licensing, and M&A due diligence contexts in Hong Kong.