Skip to main content

Internet and Email Policy (Hong Kong)

Internet and Email Policy (Hong Kong)

INTERNET AND EMAIL POLICY

Organisation: [Company Name]

Registered Address: [Company Address]

Effective Date: [Effective Date]

Policy Owner: [Policy Owner]

Next Review Date: [Review Date]

1. SCOPE AND PURPOSE

1.1 This Internet and Email Policy ("Policy") applies to [Covered Persons] of [Company Name] ("Company") who use the Company's IT systems, networks, internet access, email, or communication tools ("IT Systems").

1.2 The purpose of this Policy is to: ensure productive and professional use of Company IT Systems; protect the Company's IT infrastructure from security risks; ensure compliance with applicable Hong Kong law including the Personal Data (Privacy) Ordinance (Cap. 486) (PDPO) and the Copyright Ordinance (Cap. 528); and set clear expectations for acceptable use.

1.3 All persons within the scope of this Policy must read and acknowledge receipt of this Policy as a condition of receiving access to Company IT Systems.

2. PERMITTED USE

2.1 Company IT Systems are provided primarily for business purposes. Permitted personal use: [Personal Use Permitted].

2.2 Conditions for personal use: [Personal Use Conditions].

2.3 Users must exercise good judgment and professionalism in all use of Company IT Systems, whether for business or permitted personal purposes.

3. PROHIBITED USES

3.1 The following uses of Company IT Systems are strictly prohibited:

  • Accessing, downloading, transmitting, or storing pornographic, obscene, or offensive material (which may also constitute a criminal offence under the Control of Obscene and Indecent Articles Ordinance Cap. 390);
  • Sending harassing, threatening, discriminatory, or defamatory communications (with potential liability under the Sex Discrimination Ordinance Cap. 480, the Race Discrimination Ordinance Cap. 602, and the Defamation Ordinance Cap. 21);
  • Disclosing the Company's confidential information or any personal data without authorisation, in breach of the PDPO (Cap. 486) or contractual obligations;
  • Downloading, installing, or running unauthorised software, which may infringe copyright under the Copyright Ordinance (Cap. 528);
  • Attempting to gain unauthorised access to any computer system (a criminal offence under the Crimes Ordinance Cap. 200, section 161);
  • Using Company IT Systems for personal financial gain, business activities, or cryptocurrency mining;
  • Forwarding chain messages, spam, or unsolicited commercial emails;
  • Connecting Company devices to unsecured public Wi-Fi networks without VPN protection; and
  • Any other use that violates applicable Hong Kong law or the Company's other policies.

3.2 Social media: [Social Media Policy].

3.3 Additional prohibited uses: [Additional Prohibitions].

4. MONITORING (PDPO NOTICE)

4.1 NOTICE TO ALL USERS: In accordance with the Personal Data (Privacy) Ordinance (Cap. 486) and the guidance of the Privacy Commissioner for Personal Data, you are hereby notified that the Company conducts the following monitoring of Company IT Systems: [Monitoring Scope].

4.2 Purpose of monitoring: [Monitoring Purpose].

4.3 Monitoring data retention: Monitoring logs and records are retained for [Retention Period]. Monitoring data may be disclosed to management, legal advisers, law enforcement agencies, or regulators where required for the stated purposes or by law.

4.4 Employees have no expectation of privacy in respect of their use of Company IT Systems. By using Company IT Systems, you consent to monitoring as described in this Policy.

4.5 Users have the right to access their own personal data held by the Company in connection with monitoring under Data Protection Principle 6 of the PDPO, subject to applicable exemptions.

5. SECURITY OBLIGATIONS

5.1 Password requirements: [Password Requirements].

  • Passwords must not be shared with any other person;
  • Screens must be locked when leaving workstations unattended;
  • Suspected security incidents, malware infections, or phishing attempts must be reported to IT immediately;
  • Company devices must not be left unattended in public places or vehicles;
  • Personal devices may only be used to access Company IT Systems if enrolled in the Company's device management programme.

6. DISCIPLINARY CONSEQUENCES

6.1 Breach of this Policy may result in disciplinary action. [Breach Consequences]. The Company reserves the right to report criminal conduct to law enforcement authorities.

6.2 For breaches involving potential criminal liability under Hong Kong law (e.g. accessing obscene material, unauthorised computer access under the Crimes Ordinance Cap. 200), the Company will report the matter to the Hong Kong Police Force without prior notice.

7. REVIEW AND AMENDMENTS

7.1 This Policy will be reviewed on [Review Date] or whenever significant changes to technology or applicable Hong Kong law require an update.

7.2 The Company reserves the right to amend this Policy at any time and will notify employees of material changes.

EMPLOYEE ACKNOWLEDGEMENT

I confirm that I have read, understood, and agree to comply with the Internet and Email Policy of [Company Name] effective [Effective Date].

Employee name: ______________________________

Job title: ______________________________

Date: ______________________________

Signature: ______________________________

Authorised Signatory (Company)

________________

Signature

Employee Acknowledgement

________________

Signature

Maintained by Vladislav Sergienko, Founder·Template last modified: ·Report an error

What Is a Internet and Email Policy (Hong Kong)?

An Internet and Email Policy in Hong Kong establishes the rules and responsibilities that govern the conduct it addresses.

The Personal Data (Privacy) Ordinance (Cap. 486), administered by the Privacy Commissioner for Personal Data (PCPD), is the primary data protection statute in Hong Kong. The PDPO's six Data Protection Principles (DPPs) impose obligations on employers (as data users) regarding the collection, holding, processing, use, and transfer of employees' personal data. When an employer monitors employees' email and internet use, it collects personal data about those employees — triggering obligations under DPP1 (purpose limitation), DPP3 (use limitation), and DPP4 (data security). The PCPD has published guidance specifically addressing workplace monitoring, recommending that employers: adopt a written IT and email policy; inform employees before monitoring commences; limit monitoring to what is necessary and proportionate; and handle data collected through monitoring in accordance with the PDPO.

The Employment Ordinance (Cap. 57), administered by the Labour Department, governs the employment relationship in Hong Kong. An Internet and Email Policy adopted as part of the employment terms — and acknowledged in writing by employees — becomes a term of employment. Breach of the policy by an employee may constitute misconduct justifying disciplinary action or, in serious cases, summary dismissal for gross misconduct under section 9 of Cap. 57. Any dismissal for IT policy breach must be handled in accordance with fair dismissal principles to avoid a claim before the Labour Tribunal.

Cybersecurity in Hong Kong is addressed through multiple regulatory channels. Regulated entities — banks supervised by the Hong Kong Monetary Authority (HKMA), licensed corporations supervised by the Securities and Futures Commission (SFC), and insurers supervised by the Insurance Authority (IA) — are subject to specific cybersecurity circulars requiring strong IT security management. For general businesses, the PDPO's DPP4 (data security) requires organisations to take all practicable steps to protect personal data against unauthorised or accidental access, processing, erasure, loss, or use.

The Control of Obscene and Indecent Articles Ordinance (Cap. 390), the Sex Discrimination Ordinance (Cap. 480), the Race Discrimination Ordinance (Cap. 602), and the Defamation Ordinance (Cap. 21) create legal risks for employers where employees use company IT systems to access or distribute prohibited content. An Internet and Email Policy that expressly prohibits such uses, and provides for disciplinary consequences, helps establish that the employer has taken reasonable steps to prevent such misuse. The Labour Department and the Privacy Commissioner for Personal Data (PCPD) both provide published guidance to Hong Kong employers on balancing lawful monitoring with employees' privacy rights under Cap. 486.

When Do You Need a Internet and Email Policy (Hong Kong)?

An Internet and Email Policy in Hong Kong is needed by every organisation that provides employees with access to company IT systems, email accounts, or internet connectivity — which in practice means virtually every Hong Kong employer.

New business establishment: a company setting up operations in Hong Kong for the first time should adopt an Internet and Email Policy as part of its employment documentation package, alongside employment contracts and a staff handbook. Adopting the policy before employees commence work confirms monitoring is lawful from the outset under the PDPO and that employees have been informed of acceptable use standards before any potential breaches occur.

Existing businesses without a written policy: many Hong Kong SMEs and even larger organisations operate without a formal written IT policy. The absence of a policy creates legal risks: without express notice to employees about monitoring, the employer may breach the PDPO when monitoring emails and internet use; without clear disciplinary provisions, dismissal for IT misuse may be challenged as unfair before the Labour Tribunal under Cap. 57; and without an acceptable use policy, employees may claim they were unaware that certain conduct was prohibited.

Policy updates for new technology: organisations that have adopted legacy IT policies should update them to address new technologies including cloud computing, remote working platforms such as Microsoft Teams and Slack, bring-your-own-device (BYOD) arrangements, artificial intelligence tools accessed via the internet, and social media use during and outside working hours.

Remote working arrangements: following widespread adoption of remote and hybrid working in Hong Kong, organisations need to update their policies to address security risks of employees accessing company systems from home networks, personal devices, and public Wi-Fi — and to set clear expectations about cybersecurity practices including VPN use, screen locking, and secure document storage.

Regulated financial institutions: banks, licensed corporations, and insurers regulated by the HKMA, SFC, or IA are subject to specific cybersecurity requirements including the HKMA's Cybersecurity Fortification Initiative (CFI) and the SFC's cybersecurity circular, which must be reflected in documented acceptable use policies.

Post-incident review: organisations that have experienced a data breach, cyberattack, or incident involving employee misuse of IT systems should review and update their Internet and Email Policy as part of the incident response and remediation process, and communicate the updated policy to all staff.

What to Include in Your Internet and Email Policy (Hong Kong)

A well-drafted Internet and Email Policy for a Hong Kong employer should include the following key elements to comply with the Personal Data (Privacy) Ordinance (Cap. 486), the Employment Ordinance (Cap. 57), and Hong Kong's broader regulatory framework.

Scope and purpose: the policy should define the IT systems, devices, and services covered — corporate computers and laptops, company-issued mobile devices, corporate email accounts, intranet systems, cloud platforms, and any personal devices used to access company systems under a BYOD arrangement. The policy's purpose — protecting company information, confirming regulatory compliance, and defining acceptable use — should be stated at the outset.

Acceptable use standards: the policy must set out what uses of company IT systems are permitted and prohibited. Prohibited uses should expressly include: accessing or distributing obscene or indecent material (an offence under the Control of Obscene and Indecent Articles Ordinance (Cap. 390)); sending harassing, discriminatory, or defamatory communications creating employer liability under the Sex Discrimination Ordinance (Cap. 480) and Race Discrimination Ordinance (Cap. 602); downloading unlicensed software or infringing intellectual property under the Copyright Ordinance (Cap. 528); and disclosing confidential company information or personal data to unauthorised parties.

Monitoring and privacy notice: the PDPO's Data Protection Principles require employers to inform employees that monitoring is taking place, the purposes for which data collected will be used, and the classes of persons to whom the data may be transferred (DPP1 and DPP3). The policy must include a clear monitoring notice stating that the employer may monitor, log, and review employees' use of company IT systems — including email content, internet browsing history, and system activity — for specified purposes including security, compliance, and investigation of suspected misconduct.

Data security obligations: employees' obligations regarding data security must be specified — password management, mandatory screen locking, prohibition on sharing login credentials, requirements for encrypted storage of sensitive data, and reporting procedures for suspected security incidents. The HKMA's Cybersecurity Fortification Initiative (CFI) and SFC cybersecurity guidelines should be reflected for regulated entities.

Social media policy: the acceptable use section should address employees' use of personal social media accounts during working hours and the prohibition on disclosing confidential company information or making statements that could damage the company's reputation through social media channels.

Disciplinary consequences: the policy must state that breaches will be treated as misconduct and set out the range of disciplinary consequences — from written warning through to summary dismissal for serious breaches under section 9 of the Employment Ordinance (Cap. 57). The policy should identify which breaches constitute gross misconduct warranting summary dismissal — for example, accessing child sexual abuse material, transmitting trade secrets to competitors, or committing fraud using company systems.

Employee acknowledgement: employees must sign an acknowledgement confirming they have read, understood, and agree to comply with the policy. This is essential both as evidence of informed consent for PDPO purposes and as evidence that the employee was aware of the rules in any subsequent disciplinary proceedings before the Labour Tribunal. Section 9 of the Employment Ordinance (Cap. 57) permits summary dismissal for gross misconduct; section 64 of Cap. 57 sets out the employer's general obligations. Section 26 of Cap. 57 requires written consent for wage deductions. Section 4 of the Personal Data (Privacy) Ordinance (Cap. 486) mandates data security measures meeting Data Protection Principle 4 standards. Download a free template at forms-legal.com. Related documents include the HK Data Protection Policy and HK Employment Contract.

Sources & Citations

Statutory citations link to official government sources.

  1. The Personal Data (Privacy) Ordinance (Cap. 486)HK official
  2. The Employment Ordinance (Cap. 57)HK official
  3. The Control of Obscene and Indecent Articles Ordinance (Cap. 390)HK official
  4. Sex Discrimination Ordinance (Cap. 480)HK official
  5. Race Discrimination Ordinance (Cap. 602)HK official
  6. Defamation Ordinance (Cap. 21)HK official
  7. Personal Data (Privacy) Ordinance (Cap. 486)HK official
  8. Employment Ordinance (Cap. 57)HK official
  9. Control of Obscene and Indecent Articles Ordinance (Cap. 390)HK official
  10. Copyright Ordinance (Cap. 528)HK official

Cite this page

Reference this free template in an article, syllabus, or research note:

APA

Forms Legal. (2026). Internet and Email Policy (Hong Kong) (Hong Kong) [Legal document template]. Forms Legal. https://forms-legal.com/hong-kong/business/policies/internet-email-policy-hong-kong

MLA

"Internet and Email Policy (Hong Kong) (Hong Kong)." Forms Legal, 2026, https://forms-legal.com/hong-kong/business/policies/internet-email-policy-hong-kong.

BibTeX
@misc{formslegal-internet-email-policy-hong-kong,
  author       = {{Forms Legal}},
  title        = {Internet and Email Policy (Hong Kong) (Hong Kong)},
  year         = {2026},
  howpublished = {\url{https://forms-legal.com/hong-kong/business/policies/internet-email-policy-hong-kong}},
  note         = {Free legal document template. Based on Personal Data (Privacy) Ordinance (Cap. 486)}
}

Also available for these jurisdictions:

Frequently Asked Questions

Based on Personal Data (Privacy) Ordinance (Cap. 486) — Template last modified June 2026Verify the source →

This template is provided for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction and change over time. Consult a qualified attorney for advice specific to your situation.Full disclaimer

Found an error? Let us know

Related Documents

You may also find these documents useful:

Acceptable Use Policy (Hong Kong)

An Acceptable Use Policy (AUP) for Hong Kong organisations setting out the rules and guidelines for the proper use of company IT systems, networks, and digital resources. Governs employee conduct when accessing company technology, internet, email, and software under Hong Kong common law and practical compliance standards.

AI Acceptable Use Policy (Hong Kong)

An AI Acceptable Use Policy for Hong Kong organisations governing the responsible use of artificial intelligence tools and systems in the workplace. Addresses data protection under the Personal Data (Privacy) Ordinance (Cap. 486), ethical AI principles, and risk management for generative AI and machine learning technologies.

Anti-Bribery Policy (Hong Kong)

An Anti-Bribery Policy for Hong Kong organisations ensuring compliance with the Prevention of Bribery Ordinance (Cap. 201). Establishes clear rules on gifts, hospitality, facilitation payments, and reporting obligations. Covers both public and private sector bribery offences enforced by the ICAC.

Anti-Discrimination Policy (Hong Kong)

A comprehensive workplace Anti-Discrimination Policy for Hong Kong employers, covering obligations under the Sex Discrimination Ordinance (Cap. 480), Disability Discrimination Ordinance (Cap. 487), Family Status Discrimination Ordinance (Cap. 527), and Race Discrimination Ordinance (Cap. 602). Sets out complaint procedures and remedies consistent with Equal Opportunities Commission guidance.

Business Continuity Plan (Hong Kong)

A Business Continuity Plan (BCP) for Hong Kong organisations establishing procedures to maintain critical operations during disruptions. Covers risk assessment, recovery strategies, communication protocols, and testing procedures under Hong Kong common law and industry best practices.