← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Hong Kong Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Hong Kong resident covered by this Annex; the Data Protection Officer ("DPO") for the purposes of Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") Schedule 1 Data Protection Principle 4 (security of personal data) read with the Privacy Commissioner for Personal Data, Hong Kong (the "PCPD") Guidance Note on the Proper Handling of Customers' Personal Data for the Banking Industry + Guidance for Data Users on the Collection and Use of Personal Data through the Internet + Guidance on the Use of Personal Data Obtained from the Public Domain + Privacy Management Programme: A Best Practice Guide (collectively, the principal PCPD interpretive instruments on data-protection-officer designation under PDPO Schedule 1 DPP 4 — the PDPO does not contain a statutory DPO mandate at the Effective date but PCPD interpretive practice strongly recommends DPO designation as part of the Privacy Management Programme expected of every data user under the PCPD's best-practice framework), with business contact published as the publicly-accessible privacy contact in alignment with PDPO Schedule 1 DPP 5 (information to be generally available); the designated contact point for the Privacy Commissioner for Personal Data, Hong Kong ("PCPD"), the Hong Kong Police Force – Cyber Security and Technology Crime Bureau ("CSTCB"), the Office of the Communications Authority ("OFCA"), the Customs and Excise Department – Anti-Internet Piracy Team (insofar as engaged on CSAM cross-border seizure routes), the Social Welfare Department ("SWD"), and the Office of the Government Chief Information Officer ("OGCIO") CyberDefender programme under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") — including the bringing into force of any provision of the Personal Data (Privacy) (Amendment) Ordinance 2021 (in force from 8 October 2021 — Part VIIIA criminalising doxxing) that is not yet operationally in force at the Effective date, or the commencement of PDPO section 33 (the cross-border-transfer provision drafted but not yet commenced at the Effective date; the PCPD has published the Guidance on Personal Data Protection in Cross-border Data Transfer and the Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data in 2014 + updated in May 2022 as the operational guidance for the s 33 gap — § 18 versioning protocol provides for an immediate off-cycle update on s 33 commencement); (b) any amendment to PDPO Schedule 1 (the six Data Protection Principles — DPP 1 collection / DPP 2 accuracy + retention / DPP 3 use / DPP 4 security / DPP 5 openness / DPP 6 access and correction); (c) any Guidance Note, Code of Practice, or Information Leaflet issued by the PCPD under PDPO s 8 + s 12 — including the Guidance for Data Users on the Collection and Use of Personal Data through the Internet, the Privacy Management Programme: A Best Practice Guide (most recent revision), the Guidance on Data Breach Handling and Data Breach Notifications (most recent revision), the Guidance on Doxxing Offences and the Personal Data (Privacy) (Amendment) Ordinance 2021, the Guidance on Personal Data Protection in Cross-border Data Transfer, the Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data (May 2022 update), the Guidance for the Care of Personal Data Agents, the Children Privacy leaflet, and the body of PCPD published Administrative Appeals Board decisions; (d) any decision of the Administrative Appeals Board under PDPO s 39 or any decision of the Court of First Instance / Court of Appeal / Court of Final Appeal bearing on the PDPO, on the Basic Law Art 30 + Art 39 right to privacy of communications, or on the Bill of Rights Ordinance (Cap. 383) Art 14 privacy right; (e) any amendment to the Unsolicited Electronic Messages Ordinance (Cap. 593) ("UEMO") in force from 22 December 2007 or to any Code of Practice issued by the Communications Authority thereunder; (f) any amendment to the Crimes Ordinance (Cap. 200), in particular Part XII (sexual offences) including ss 117 (definitions), 118 (rape), 119 (procurement by threats), 120 (procurement by false pretences), 122 (indecent assault), 123 (sexual intercourse with girl under 13 — absolute), 124 (sexual intercourse with girl under 16), 126 (abduction of unmarried girl under 16), 127 (abduction of unmarried girl under 18 for sexual intercourse), 134 (detention for unlawful sexual intercourse), 138B (administering drugs to obtain or facilitate unlawful sexual act), s 159AAB / s 159AAC / s 159AAD / s 159AAE (intimate-image abuse offences — voyeurism / non-consensual recording / non-consensual publication / threats to publish — introduced by the Crimes (Amendment) Ordinance 2021 in force from 8 October 2021), and s 161 (access to computer with criminal or dishonest intent — modulated by HKSAR v Cheng Ka-Yee [2019] HKCFA 9 to exclude access by a user to his/her own computer); (g) any amendment to the Prevention of Child Pornography Ordinance (Cap. 579) (the principal Hong Kong CSAM statute, in force from 19 December 2003), in particular ss 3 (printing/making/producing/reproduction/copying), 4 (publication), 5 (advertisement), 7 (possession), 8 (defences); (h) any amendment to the Protection of Children and Juveniles Ordinance (Cap. 213) (the principal child-welfare statute, in force from 31 May 1951 with subsequent amendments — definitions s 2; child under 14 / juvenile 14 to under 18; SWD Director powers ss 34–34I; care or protection orders ss 34A–34I; juvenile court jurisdiction); (i) any amendment to the Mental Health Ordinance (Cap. 136) insofar as it engages the cooperation routes for minors with mental health needs; (j) any amendment to the Computer Crimes Ordinance / Crimes Ordinance ss 161 + the Interception of Communications and Surveillance Ordinance (Cap. 589) ("ICSO"), or the Telecommunications Ordinance (Cap. 106) s 24 (unlawful interception); (k) any amendment to the Trade Descriptions Ordinance (Cap. 362), the Sale of Goods Ordinance (Cap. 26), the Supply of Services (Implied Terms) Ordinance (Cap. 457), the Control of Exemption Clauses Ordinance (Cap. 71), or the Unconscionable Contracts Ordinance (Cap. 458) (collectively, the principal Hong Kong consumer-protection bundle); (l) any amendment to a sub-processor's Hong Kong data-handling posture under our sub-processor register; (m) the bringing into force of any post-Effective-date Hong Kong regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex); (n) the entry into force in Hong Kong (via separate domestic implementation or by extension of any treaty action of the People's Republic of China to the HKSAR by virtue of Basic Law Art 153) of the Convention on Cybercrime (Budapest Convention) and/or its Second Additional Protocol (the PRC is not currently a party; Hong Kong is therefore not currently bound; § 18 versioning protocol covers any change in that status); (o) any decision by the Hong Kong Special Administrative Region Government or the National People's Congress Standing Committee under Basic Law Art 158 bearing on the PDPO, on Art 30 + Art 39, or on the cross-border-transfer regime. Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Hong Kong-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants a Hong Kong resident a right that the global Policy does not, this Annex governs. Where the global Policy grants a Hong Kong resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English. The official languages of the Hong Kong Special Administrative Region under Basic Law Article 9 read with the Official Languages Ordinance (Cap. 5) are Chinese (in practice Traditional Chinese in the Hong Kong Cantonese register, with Modern Standard Written Chinese for legal text) and English; both languages have equal status in courts and in legislation, with both Chinese and English versions of any Ordinance being authentic. Traditional Chinese translation of this Annex is queued for the Phase-2 locale rollout per our internal compliance tracker. No translation is statutorily required at the Effective date for the English-language privacy notice to a Hong Kong resident (the PDPO does not mandate multilingual notification; the PCPD's interpretive practice accepts English-language notices provided they are intelligible to the data subject in light of the context, and routinely engages with English-language privacy notices from international data users).


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose country of residence is the Hong Kong Special Administrative Region of the People's Republic of China — the city-state with administrative subdivision into 18 District Councils (Central and Western / Wan Chai / Eastern / Southern / Yau Tsim Mong / Sham Shui Po / Kowloon City / Wong Tai Sin / Kwun Tong / Tsuen Wan / Tuen Mun / Yuen Long / North / Tai Po / Sha Tin / Sai Kung / Kwai Tsing / Islands). There is no district data-protection sub-layer; the PDPO is uniform throughout the HKSAR.

We determine country of residence at install/sign-up time by (a) the country/territory the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Hong Kong as the country/territory of residence, this Annex applies, even if the other signals are non-Hong-Kong. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The PDPO has explicit extraterritorial reach under PDPO s 39 + the PCPD's interpretive practice (New Guidance on the Application of the Personal Data (Privacy) Ordinance to Multi-Jurisdictional Operations + the body of PCPD enforcement actions). The PDPO applies to a data user — including a person located outside Hong Kong — who "controls the collection, holding, processing or use of personal data" of any individual where the data user has a meaningful operational nexus to Hong Kong, including (i) carrying on business in Hong Kong, (ii) offering services to Hong Kong residents, or (iii) monitoring the activities of Hong Kong residents. Balance squarely targets Hong Kong residents through Google Play Hong Kong, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Hong-Kong-resident parents and kids; the PDPO applies in full.

This Annex is drafted as a Hong-Kong-specific instrument. The legal framework documented in this Annex relates exclusively to the Hong Kong Special Administrative Region. It does not address or extend to the Macao Special Administrative Region (which is a separate legal jurisdiction with its own data-protection statute Lei n.º 8/2005 + separate supervisory authority Gabinete para a Protecção de Dados PessoaisGPDP) or to the mainland of the People's Republic of China (which is governed by the Personal Information Protection Law of the PRC, 2021 + adjacent statutes — outside the scope of this Annex).


2. Statutory framework — what applies

The Hong Kong personal-data-protection regime is dominated by the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), in force from 20 December 1996 and substantively amended in 2012 (the Personal Data (Privacy) (Amendment) Ordinance 2012 introducing direct-marketing rules at Part VIA and the data-user-return regime) and in 2021 (the Personal Data (Privacy) (Amendment) Ordinance 2021 introducing Part VIIIA criminalisation of doxxing). The PDPO is supplemented by the PCPD's binding Guidance Notes and the body of PCPD Codes of Practice. Adjacent layers: the Basic Law of the Hong Kong Special Administrative Region (the "Basic Law") Articles 30 and 39 (privacy + ICCPR application); the Bill of Rights Ordinance (Cap. 383) Article 14 (privacy); the Crimes Ordinance (Cap. 200); the Prevention of Child Pornography Ordinance (Cap. 579); the Protection of Children and Juveniles Ordinance (Cap. 213); the Interception of Communications and Surveillance Ordinance (Cap. 589); the Telecommunications Ordinance (Cap. 106); the Unsolicited Electronic Messages Ordinance (Cap. 593); the Trade Descriptions Ordinance (Cap. 362); the Sale of Goods Ordinance (Cap. 26); the Supply of Services (Implied Terms) Ordinance (Cap. 457); the Control of Exemption Clauses Ordinance (Cap. 71); the Unconscionable Contracts Ordinance (Cap. 458).

Instrument Short cite What it does Balance's posture
Basic Law of the HKSAR Basic Law — promulgated by the National People's Congress of the PRC on 4 April 1990; in force in Hong Kong since 1 July 1997. Constitutional-rank instrument under the HKSAR's "one country, two systems" framework. Article 30 — "The freedom and privacy of communication of Hong Kong residents shall be protected by law. No department or individual may, on any grounds, infringe upon the freedom and privacy of communication of residents except that the relevant authorities may inspect communication in accordance with legal procedures to meet the needs of public security or of investigation into criminal offences." — the constitutional anchor for the right to privacy of communications in Hong Kong. Article 39 — incorporates the International Covenant on Civil and Political Rights ("ICCPR") into Hong Kong law as it applied to Hong Kong before 1 July 1997 (including ICCPR Art 17 right to privacy). Article 9 — Chinese and English as official languages. Article 153 — international agreements binding on Hong Kong via PRC accession with HKSAR Government concurrence + decisions of the Central People's Government. The constitutional anchor. The right to privacy in Hong Kong is constitutional (Basic Law Art 30 + Art 39) + statutory (Bill of Rights Ordinance Art 14 + PDPO + common-law doctrine). Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Bill of Rights Ordinance (Cap. 383) BORO — enacted 8 June 1991 to incorporate the ICCPR into Hong Kong domestic law. Article 14 — "(1) No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation. (2) Everyone has the right to the protection of the law against such interference or attacks." — the principal statutory enactment of the ICCPR Art 17 privacy right in Hong Kong, applicable to the HKSAR Government, public bodies, and (per Court of Final Appeal jurisprudence) certain quasi-public bodies. The statutory enactment of the constitutional privacy right. Applies as a context-setting fact. Treatment in §§ 3, 6, 13 below.
Personal Data (Privacy) Ordinance (Cap. 486) PDPO — enacted 3 August 1995; in force 20 December 1996. Substantively amended by the Personal Data (Privacy) (Amendment) Ordinance 2012 (in force 1 October 2012 in respect of Part VIA + 1 April 2013 in respect of the data-user-return regime) and by the Personal Data (Privacy) (Amendment) Ordinance 2021 (in force 8 October 2021 in respect of Part VIIIA doxxing offences). Part I Preliminary; Part II PCPD (Sections 5–14 establishing the Office of the Privacy Commissioner for Personal Data, with full-time independent Commissioner appointed by the Chief Executive); Part III Protection Principles (Schedule 1 — six Data Protection PrinciplesDPP 1 Purpose and Manner of Collection / DPP 2 Accuracy and Duration of Retention / DPP 3 Use of Personal Data / DPP 4 Security of Personal Data / DPP 5 Information to be Generally Available / DPP 6 Access to Personal Data); Part IV Access to + Correction of Personal Data (ss 18–28 — data-access request + data-correction request + 40-day response window + fee constraints); Part V Matching Procedure (s 30); Part VI Codes of Practice issued by PCPD; Part VIA Direct Marketing (ss 35A–35M — opt-in consent + data-subject opt-out + criminal offence under s 35C for failure to comply); Part VII Enforcement (ss 36–48 — investigation + enforcement notice + appeal to Administrative Appeals Board s 39); Part VIIA Specific Offences relating to Personal Data; Part VIIIA Doxxing Offences (introduced by the 2021 Amendment Ordinance, in force 8 October 2021) — s 64(1) disclosure of personal data without consent with intent to threaten, intimidate or harass + ss 66(D)–66(Q) + s 66E PCPD investigation and enforcement powers including cessation notices + extraterritorial reach + offences punishable by fine up to HK$1,000,000 + imprisonment up to 5 years; Part VIII Miscellaneous; Part IX Section 33 — Cross-border Transfer of Personal Data — drafted but NOT YET COMMENCED at the Effective date (a long-standing operational anomaly of Hong Kong privacy law; the PCPD has published the Guidance on Personal Data Protection in Cross-border Data Transfer + the Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data (May 2022 update) as the operative interim mechanism); Schedules 1–13 including Schedule 1 the six Data Protection Principles (the operative substantive layer of the PDPO). The principal statute. Applies in full to Balance as a data user located outside Hong Kong offering services to Hong Kong residents. Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Schedule 1 — Six Data Protection Principles (DPPs) DPPs — the substantive heart of the PDPO. DPP 1 Purpose and Manner of Collection — personal data shall not be collected unless (a) it is collected for a lawful purpose directly related to a function or activity of the data user; (b) the collection is necessary for or directly related to that purpose; and (c) the data is adequate but not excessive in relation to that purpose; and the collection by means is lawful and fair. DPP 2 Accuracy and Duration of Retention — all practicable steps to ensure data is accurate + not kept longer than necessary. DPP 3 Use of Personal Data — personal data shall not be used (which includes disclosure or transfer) for a purpose other than the purpose for which it was collected (or a directly-related purpose) without the prescribed consent of the data subject. DPP 4 Security of Personal Data — appropriate technical + organisational measures to safeguard against unauthorised or accidental access, processing, erasure, loss, or use. DPP 5 Information to be Generally Available — kinds of personal data held + main purposes for which the personal data is or is to be used + identity of the person responsible for the application of the kind of personal data must be made generally available. DPP 6 Access to Personal Data — every data subject is entitled to (a) ascertain whether a data user holds personal data of which he is the data subject; (b) request access to personal data; (c) request correction of inaccurate personal data; with the data user obliged to comply within 40 calendar days under s 19. Applies in full to Balance. Treatment in §§ 4, 6, and 7 below.
PCPD Guidance Notes and Codes of Practice The body of PCPD guidance documents published at https://www.pcpd.org.hk/english/resources_centre/publications/index.html — including the Guidance for Data Users on the Collection and Use of Personal Data through the Internet (most recent revision 2024), the Privacy Management Programme: A Best Practice Guide, the Guidance on Data Breach Handling and Data Breach Notifications (most recent revision), the Guidance on Doxxing Offences and the Personal Data (Privacy) (Amendment) Ordinance 2021, the Guidance on Personal Data Protection in Cross-border Data Transfer (December 2014), the Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data (May 2022 update), the Code of Practice on Consumer Credit Data, the Code of Practice on the Identity Card Number and Other Personal Identifiers, the Guidance for the Care of Personal Data Agents, the Children Privacy leaflet, and the body of PCPD enforcement decisions. Sets the PCPD's binding interpretive layer on the PDPO. Applies in full. The Children Privacy leaflet and the Guidance for Data Users on the Collection and Use of Personal Data through the Internet are particularly relevant.
Personal Data (Privacy) (Amendment) Ordinance 2021 — Part VIIIA Doxxing 2021 Amendment Ordinance — enacted 29 September 2021; in force 8 October 2021. Introduced Part VIIIA Doxxing Offences at PDPO ss 64 + 66D–66Q. s 64(1) offence to disclose personal data of a data subject without the data subject's consent with intent to threaten, intimidate, harass, or cause harm or psychological harm to the data subject or any family member — fine up to HK$1,000,000 + imprisonment up to 5 years on conviction on indictment; lesser tier on summary conviction. s 66E PCPD investigation and enforcement powers including cessation notices to platform operators. Extraterritorial reach under s 66P. The principal Hong Kong anti-doxxing regime. Applies. Balance does not host any user-generated content surface accessible to other Balance users beyond the parent-kid pairing of a single household; doxxing-by-Balance scenarios do not engage the typical Part VIIIA enforcement workflow but Balance cooperates with any properly-issued PCPD cessation notice.
Personal Data (Privacy) (Amendment) Ordinance 2012 — Part VIA Direct Marketing 2012 Amendment Ordinance — in force 1 October 2012. Introduced Part VIA Direct Marketing at PDPO ss 35A–35M. s 35C offence to use personal data in direct marketing without taking the prescribed action (notification of intended use + collection of prescribed consent + provision of response channel). Penalty: fine up to HK$500,000 + imprisonment up to 3 years. Applies. Balance does not use any Hong Kong data subject's personal data in direct marketing. Treatment in § 12 below.
Unsolicited Electronic Messages Ordinance (Cap. 593) UEMO — in force 22 December 2007 (Part I) + 22 December 2007 + 22 December 2008 (Part 2 — commercial electronic messages). Prohibits the sending of an unsolicited commercial electronic message with a Hong Kong link without the recipient's prior consent or after the recipient has unsubscribed. Schedule 2 specifies the required identification + unsubscribe + valid sender details. Enforced by the Office of the Communications Authority (OFCA). Civil cause of action + criminal offences for repeat or aggravated violations. Applies. Balance does not send commercial electronic messages to Hong Kong residents within the meaning of UEMO; the only email Balance sends is transactional. Treatment in § 12 below.
Crimes Ordinance (Cap. 200) Crimes Ordinance — enacted 1 July 1971. Substantive sections relevant to Balance's child-safety + lawful-access posture: Part XII Sexual Offencess 117 definitions including sexual intercourse; s 118 rape; s 119 procurement of woman or girl by threats; s 120 procurement of woman or girl by false pretences; s 122 indecent assault; s 123 sexual intercourse with girl under 13 — absolute liability; s 124 sexual intercourse with girl under 16 (the principal under-16 statutory offence); s 126 abduction of unmarried girl under 16; s 127 abduction of unmarried girl under 18 for sexual intercourse; s 134 detention for unlawful sexual intercourse; s 138B administering drugs to obtain or facilitate unlawful sexual act. Crimes (Amendment) Ordinance 2021 introduced intimate-image abuse offences at ss 159AAB (voyeurism) / 159AAC (unlawful recording of intimate parts) / 159AAD (publication of intimate image without consent) / 159AAE (threat to publish intimate image without consent) — fine + imprisonment up to 5 years on conviction on indictment. s 161 access to computer with criminal or dishonest intent — modulated by HKSAR v Cheng Ka-Yee [2019] HKCFA 9 to exclude access by a user to his/her own computer (a Court of Final Appeal decision narrowing the historically broad s 161 reach). The principal Hong Kong criminal statute relevant to child-safety + intimate-image abuse + access-to-computer offences. Applies. Cross-reference in § 14 below.
Prevention of Child Pornography Ordinance (Cap. 579) POCPO — in force 19 December 2003. The principal Hong Kong CSAM statute. s 3 offences of printing/making/producing/reproduction/copying of child pornography; s 4 publication of child pornography; s 5 advertisement of child pornography; s 7 possession of child pornography; s 8 defences (legitimate purpose / artistic merit / scientific purpose narrowly construed). Schedule definition of child — under 16 years of age + child pornography — visual depiction. The principal CSAM-criminalisation statute. Applies. Treatment in § 14 below.
Protection of Children and Juveniles Ordinance (Cap. 213) PCJO — in force 31 May 1951 with subsequent amendments. s 2 definitions — child under 14 + juvenile 14 to under 18; parent or guardian; care or protection. s 34 SWD Director powers to refer a child or juvenile in need of care or protection; ss 34A–34I care or protection orders (juvenile court jurisdiction); supervision orders; protection orders; removal-to-place-of-safety powers. Juvenile Court jurisdiction under the Juvenile Offenders Ordinance (Cap. 226). The principal child-welfare statute. Applies. Treatment in § 5 + § 14 below.
Interception of Communications and Surveillance Ordinance (Cap. 589) ICSO — in force 9 August 2006. Governs the interception of communications + covert surveillance by law-enforcement authorities. Establishes a regime of prescribed authorisations (judge-issued or executive-issued under defined classes) + the Commissioner on Interception of Communications and Surveillance (a sitting High Court judge with statutory oversight + sealed reporting to the Chief Executive). The principal lawful-interception statute. Applies. Treatment in § 13 below — relevant to E2EE posture and the lawful-access framework.
Telecommunications Ordinance (Cap. 106) — s 24 Telecoms Ordinance s 24 — prohibits unlawful interception of messages transmitted via a telecommunications service (the long-standing principal anti-wiretapping statute, supplemented by ICSO). Applies. Reinforces the E2EE design choice. Treatment in § 13 below.
Computer Crimes — Crimes Ordinance ss 161 + 27A + 60 + 161B Computer crimes — distributed across multiple Crimes Ordinance provisions (no consolidated cybercrime statute at the Effective date; the Hong Kong Law Reform Commission published the Report on Cybercrime in July 2022 recommending a consolidated cybercrime statute, but no implementing legislation has been enacted at the Effective date — § 18 versioning protocol covers its enactment). s 161 access to computer with criminal or dishonest intent (per HKSAR v Cheng Ka-Yee [2019] HKCFA 9 narrowing); s 27A false accounting via computer; s 60 criminal damage to computer; s 161B unauthorised access to a computer system. Applies as the operative cybercrime layer. Treatment in § 13 below.
Trade Descriptions Ordinance (Cap. 362) TDO — in force from 19 July 1980, substantively amended by the Trade Descriptions (Unfair Trade Practices) (Amendment) Ordinance 2012 in force 19 July 2013. Part II false trade descriptions of goods (s 7); Part II unfair trade practices including misleading omissions (s 13C), aggressive commercial practices (s 13F), bait advertising (s 13G), bait-and-switch (s 13H), wrongly accepting payment (s 13I); Part IIA the Compliance Notice + Undertaking regime; enforced by the Customs and Excise Department + the Communications Authority (for services in regulated sectors). Civil + criminal penalties (fine up to HK$500,000 + imprisonment up to 5 years for the most serious offences). The principal Hong Kong consumer-protection statute. Applies. Treatment in § 16 below.
Sale of Goods Ordinance (Cap. 26) SGO — in force from 1 January 1897 (in its original form) + substantively amended. Implied conditions of goods (s 14 fitness for purpose; s 16 merchantable quality; s 17 sale by sample). Applied to digital-content + subscription-service contracts by judicial extension where the contract is in substance a sale of goods + by parallel application of the Supply of Services (Implied Terms) Ordinance. Applies. Treatment in § 16 below.
Supply of Services (Implied Terms) Ordinance (Cap. 457) SSITO — in force 16 January 1995. s 5 implied term of reasonable care and skill; s 6 implied term of reasonable time; s 7 implied term of reasonable charge. Applied to the supply of services to consumers including online subscription services. Applies. Treatment in § 16 below.
Control of Exemption Clauses Ordinance (Cap. 71) CECO — in force 1 December 1990. s 7liability for negligence resulting in death or personal injury cannot be excluded by contract term; s 8 — other liability for negligence can only be excluded subject to the reasonableness test; s 11the reasonableness test (factors include the bargaining position of the parties + alternatives available + inducement). Applies to Balance's Terms of Service and Subscription Terms — exemption clauses are subject to the s 11 reasonableness test in respect of Hong Kong consumers. Treatment in § 16 below.
Unconscionable Contracts Ordinance (Cap. 458) UCO — in force 16 January 1995. s 5 — the court has power to refuse to enforce, or to limit or modify, an unconscionable contract or contract term in a consumer transaction. Unconscionable is assessed against a list of factors at s 6 (bargaining position + understanding + alternatives + pressure + reasonableness). Applies to Balance's Terms of Service and Subscription Terms — unconscionable terms are subject to the UCO s 5 judicial-modification power in respect of Hong Kong consumers. Treatment in § 16 below.
EU adequacy None. Hong Kong does not hold an EU adequacy decision under GDPR Article 45 at the Effective date. EU/EEA → Hong Kong transfers are governed by EU SCCs + Transfer Impact Assessment. Cross-reference in EU / EEA annex § 8. The absence of EU adequacy does not affect Balance's posture because Balance has no Hong Kong data residency (the backend is in the US — see § 9 below).
APEC Cross-Border Privacy Rules (CBPR) Hong Kong has been a participating economy in the APEC Privacy Framework since 2003 but had not yet joined the operational APEC CBPR system at the Effective date; the PCPD has expressed support for the framework but no operational Accountability Agent for Hong Kong was designated at the Effective date. Applies as a context-setting fact. Hong Kong's cross-border-transfer mechanism for Balance is the PCPD Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data (May 2022 update) — see § 8 below.
Convention 108 / Convention 108+ Not applicable. Hong Kong is not a party to the Council of Europe Convention 108 or Convention 108+. The People's Republic of China is not a party. Hong Kong is not within the scope of any China-acceded data-protection treaty. Applies as a context-setting fact. Treatment in § 8 below.
Budapest Convention on Cybercrime Not applicable at the Effective date. Hong Kong is not a party to the Convention on Cybercrime (Budapest Convention). The People's Republic of China is not a party. The HKSAR Government has not signed or acceded. Applies as a context-setting fact. Treatment in § 13 below — the cross-border lawful-access route for Hong Kong is via the HKSAR's Mutual Legal Assistance in Criminal Matters Ordinance (Cap. 525) + bilateral MLATs in force in Hong Kong via PRC accession (per Basic Law Art 153).

(Any prospective Hong Kong regulation governing automated processing, algorithmic decisions, or related techniques — including any post-Effective-date PCPD Guidance Note in that area, the PCPD's voluntary Artificial Intelligence: Model Personal Data Protection Framework (issued June 2024, voluntary best-practice guidance only), the OGCIO's voluntary Ethical Artificial Intelligence Framework (2024 edition, voluntary applies to the HKSAR Government by adoption only), any future Hong Kong primary legislation on AI before the Legislative Council, the National People's Congress Standing Committee's Generative AI Service Management Interim Measures (which apply on the mainland of the PRC but not to the HKSAR), and any successor instrument — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Hong Kong regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 PCPD — Privacy Commissioner for Personal Data, Hong Kong

The principal supervisory authority is the Privacy Commissioner for Personal Data, Hong Kong ("PCPD"), an independent statutory body established under PDPO Part II (ss 5–14). The PCPD is appointed by the Chief Executive of the HKSAR for a fixed term and exercises investigative, enforcement, and recommendatory powers. The PCPD's decisions are reviewable on a points-of-law basis by the Administrative Appeals Board under PDPO s 39 + the Administrative Appeals Board Ordinance (Cap. 442), with onward review to the Court of First Instance on judicial review.

Field Value
Name Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD)
Headquarters 13/F, 248 Queen's Road East, Wan Chai, Hong Kong
Website https://www.pcpd.org.hk/ (English) / https://www.pcpd.org.hk/tc_chi/index.html (Traditional Chinese)
Complaint channel PCPD online complaint form at https://www.pcpd.org.hk/english/complaints/how_complaint/complaint/complaint.html, or via the PCPD's Complaint Form (PCPD-OPS-001); email complaints@pcpd.org.hk; hotline +852 2827 2827
Phone +852 2827 2827 (general); +852 2877 7172 (fax)
Data-breach-notification channel PCPD online Data Breach Notification Form per the PCPD's Guidance on Data Breach Handling and Data Breach Notifications (voluntary at the Effective date — the PDPO does not statutorily mandate breach notification but the PCPD recommends voluntary notification as part of the Privacy Management Programme); accessible at https://www.pcpd.org.hk/english/data_breach_notification/
Commissioner At the Effective date — published at https://www.pcpd.org.hk/english/about_pcpd/commissioner/commissioner.html

The PCPD is the first-line forum for any PDPO-grounded complaint from any Hong Kong resident. A Hong Kong resident may petition the PCPD after first raising the matter with Balance (the PCPD's published Complaint Procedure recommends this sequencing, but the PCPD also accepts direct complaints). We accept all data-access requests / privacy enquiries at (named individual: , in his capacity as the privacy contact under PDPO Schedule 1 DPP 5) and respond within the PDPO timelines (see § 6 below).

A Hong Kong resident may also pursue private remedies via (i) the PDPO s 66 civil cause of action for compensation for damage caused by a contravention of any of the DPPs or other provisions of the PDPO (judicial action available before the Court of First Instance or the District Court depending on the value of the claim); (ii) the common-law tort of breach of confidence developed under Hong Kong common law (Coco v A.N. Clark (Engineers) Ltd [1969] RPC 41 applied in Hong Kong + Campbell v MGN approach influence on Hong Kong common-law privacy doctrine); (iii) the Bill of Rights Ordinance Art 14 cause of action read with the constitutional Art 30 + Art 39; (iv) a complaint to the Police Force under the doxxing provisions PDPO Part VIIIA + the Crimes Ordinance sexual-offences provisions for criminal-law remedies.

3.2 HKSAR Government — Office of the Government Chief Information Officer (OGCIO)

The Office of the Government Chief Information Officer ("OGCIO") is the HKSAR Government's principal ICT-policy body. OGCIO operates the CyberDefender online safety initiative + the Cyber Security Information Portal + the InfoSec portal for general cybersecurity guidance. OGCIO is not a regulator of private data users but plays an interpretive role in HKSAR Government data-protection practice.

Field Value
Name Office of the Government Chief Information Officer (OGCIO)
Headquarters 19/F, West Wing, Central Government Offices, 2 Tim Mei Avenue, Tamar, Hong Kong
Website https://www.ogcio.gov.hk/en/
Phone +852 2867 2611

3.3 Other regulatory bodies

Body Subject matter URL
Hong Kong Police Force — Cyber Security and Technology Crime Bureau (CSTCB) Crimes Ordinance s 161 + s 161B cyber-offences; PDPO Part VIIIA doxxing; intimate-image abuse offences; CSAE https://www.police.gov.hk/ppp_en/04_crime_matters/tcd/index.html
Hong Kong Police Force — Family Conflict and Sexual Violence Policy Unit Sexual offences against children + CSAE https://www.police.gov.hk/
Office of the Communications Authority (OFCA) Unsolicited Electronic Messages Ordinance (Cap. 593) + Telecommunications Ordinance (Cap. 106) https://www.ofca.gov.hk/en/home/index.html
Customs and Excise Department — Anti-Internet Piracy Team Cross-border CSAM seizure routes; Prevention of Child Pornography Ordinance https://www.customs.gov.hk/en/home/index.html
Office for Film, Newspaper and Article Administration (OFNAA) Control of Obscene and Indecent Articles Ordinance (Cap. 390); classification of articles https://www.ofnaa.gov.hk/en/home/index.html
Social Welfare Department (SWD) Protection of Children and Juveniles Ordinance — care or protection orders; Child Protection Registry https://www.swd.gov.hk/en/index/
Department of Justice (DoJ) — International Cooperation Unit Mutual Legal Assistance in Criminal Matters Ordinance (Cap. 525); cross-border lawful-access cooperation https://www.doj.gov.hk/en/index.html
Customs and Excise Department — Trade Descriptions Ordinance enforcement TDO unfair trade practices https://www.customs.gov.hk/en/home/index.html
Consumer Council Consumer protection advocacy; complaints brokerage https://www.consumer.org.hk/en/index
Hong Kong Federation of Youth Groups (HKFYG) Youth services + online safety; Youthline helpline https://www.hkfyg.org.hk/en/
Society for the Protection of Children Children's welfare NGO https://www.spc.org.hk/
Save the Children Hong Kong Children's welfare NGO https://www.savethechildren.org.hk/
Hong Kong Family Welfare Society Family services + child protection https://www.hkfws.org.hk/en/index/
Childline (HKFYG Youth Crime Prevention Centre) Youth helpline +852 2389 1313 via HKFYG
The Boys' & Girls' Clubs Association of Hong Kong Children's services https://www.bgca.org.hk/
Office of the Commissioner on Interception of Communications and Surveillance ICSO oversight https://www.sciocs.gov.hk/en/index.html
Administrative Appeals Board Appeals from PCPD decisions under PDPO s 39 + AAB Ordinance Cap. 442 https://www.aab.gov.hk/en/index.html

3.4 The privacy contact (PDPO Schedule 1 DPP 5)

PDPO Schedule 1 DPP 5 + the PCPD's Privacy Management Programme: A Best Practice Guide require every data user to make generally available (i) the kinds of personal data held; (ii) the main purposes for which the personal data is or is to be used; (iii) the identity of the person responsible for the application of the kind of personal data + how that person can be contacted. The PDPO does not contain a statutory mandate for a Data Protection Officer at the Effective date (in contrast with the GDPR Article 37 mandate, the PIPL DPO mandate, the SG PDPA s 11(3) DPO mandate, or the Israel PPL section 17B1 PPO mandate); the PCPD's Privacy Management Programme best-practice framework strongly recommends DPO designation as part of the Privacy Management Programme expected of every data user.

The Balance privacy contact is:

The privacy contact is published in this Annex, in the global Privacy Policy (Privacy Policy § 1), and at balance.babayagaprogram.com — satisfying PDPO Schedule 1 DPP 5. The privacy contact is the contact point for the PCPD on any regulatory matter and for data subjects on rights-exercise matters.


The PDPO is a consent-and-purpose-limitation regime modulated by the prescribed consent construct at PDPO s 2(3) (consent must be express + voluntary + capable of being withdrawn). Balance processes personal data of Hong Kong residents on the following PDPO mapping:

Processing purpose PDPO basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) PDPO Schedule 1 DPP 1 (lawful and directly-related purpose + necessary and adequate-but-not-excessive collection + lawful and fair means) + PDPO Schedule 1 DPP 3 (use limited to purpose of collection or directly-related purpose; prescribed consent of the data subject under PDPO s 2(3) at sign-up) + performance-of-contract necessity (recognised in PCPD interpretive practice as a discrete legitimate-purpose category) + PDPO Schedule 1 DPP 4 (security obligation) H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal data PDPO Schedule 1 DPP 1 + DPP 3 — the parent's prescribed consent on behalf of the kid (under the Capacity of Minors Ordinance doctrine of parental guardianship + Hong Kong common-law parental-authority doctrine) + the PCPD's Children Privacy leaflet + the Guidance for Data Users on the Collection and Use of Personal Data through the Internet § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts PDPO Schedule 1 DPP 1 + DPP 3 (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access PDPO Schedule 1 DPP 4 security obligation + PDPO s 58 (use of personal data for crime prevention and detection or for the apprehension/prosecution/detention of offenders is exempted from the s 4 DPP 3 use-limitation rule) + the PCPD's interpretive practice on legitimate-security processing H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations PDPO s 60B (use required or authorised by law) + PDPO s 58 (crime prevention/detection/apprehension/prosecution carve-out) § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data PDPO Schedule 1 DPP 1 + DPP 3 prescribed consent — collection of the parent's personal data for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data Performance-of-contract necessity — necessary for the performance of the subscription contract; Trade Descriptions Ordinance + Sale of Goods Ordinance + Supply of Services (Implied Terms) Ordinance + Control of Exemption Clauses Ordinance + Unconscionable Contracts Ordinance consumer-protection overlay in § 16 below H4; § 16 below

Balance does not process sensitive personal data (the PDPO does not have a separate sensitive-data category equivalent to the GDPR Art 9 special-category data, but PCPD interpretive practice + the Code of Practice on the Identity Card Number and Other Personal Identifiers treats Hong Kong Identity Card numbers + other unique identifiers as warranting heightened protection) in respect of any Hong Kong resident.

Balance does not collect any Hong Kong national or HKSAR identification number — Hong Kong Identity Card number (the principal HKSAR identifier issued under the Registration of Persons Ordinance (Cap. 177)), Hong Kong Identity Card number for permanent residents (BD-prefix / RM-prefix / RD-prefix / etc.), Document for Identity Purposes numbers, Re-entry Permit numbers, Hong Kong Special Administrative Region passport numbers, or Home Visit Permit numbers. The PCPD's Code of Practice on the Identity Card Number and Other Personal Identifiers (binding under PDPO s 12) imposes strict limits on the collection of such identifiers; Balance's posture aligns: none collected.


5. Children's rights overlay

Hong Kong does not have a children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The children's regime is built up from (i) the PDPO + the PCPD's binding Children Privacy leaflet + the Guidance for Data Users on the Collection and Use of Personal Data through the Internet; (ii) the Basic Law Art 30 + Art 39 + the Bill of Rights Ordinance Art 14; (iii) the Protection of Children and Juveniles Ordinance (Cap. 213); (iv) the Crimes Ordinance Part XII sexual-offences regime + the Prevention of Child Pornography Ordinance (Cap. 579); (v) Hong Kong common-law parental-authority doctrine + the Family Status Discrimination Ordinance (Cap. 527); (vi) the UN Convention on the Rights of the Child (extended to Hong Kong by the United Kingdom on 7 December 1994 + continuity post-1997 under Basic Law Art 153).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Hong Kong kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Hong Kong residents itemises the categories of personal data being processed, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the PDPO + the Basic Law + the Bill of Rights Ordinance + the common-law breach-of-confidence framework.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of the PDPO + the PCPD Children Privacy leaflet + the PCJO + Hong Kong common-law parental-authority doctrine.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising data file of any user. This is consistent with: (i) the PCPD's interpretive position on advertising to children in the Children Privacy leaflet; (ii) PDPO Part VIA Direct Marketing rules (s 35C prescribed action + prescribed consent — Balance does not engage in direct marketing of any kind); (iii) the TDO Part II unfair-trade-practices regime (which prohibits aggressive commercial practices directed at children); (iv) the Communications Authority's Generic Code of Practice on Television Advertising Standards (insofar as applied by interpretive analogy to online services). Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Hong Kong child-protection bodies are: (i) Social Welfare Department (SWD) — the principal child-welfare lead agency under PCJO Cap. 213; (ii) Hong Kong Police Force — Family Conflict and Sexual Violence Policy Unit + Hong Kong Police Force — Cyber Security and Technology Crime Bureau (CSTCB); (iii) Customs and Excise Department — Anti-Internet Piracy Team for cross-border CSAM seizure routes; (iv) Office for Film, Newspaper and Article Administration (OFNAA) for the classification of articles regime; (v) Society for the Protection of Children; (vi) Save the Children Hong Kong; (vii) Hong Kong Family Welfare Society; (viii) Hong Kong Federation of Youth Groups (HKFYG) + the Childline helpline +852 2389 1313; (ix) The Boys' & Girls' Clubs Association of Hong Kong; (x) the Social Welfare Department — Family and Child Protective Services Unit Hotline 2343 2255; (xi) the Hong Kong Federation of Youth Groups — Youthline +852 2777 8899. Balance cooperates with each on incidents involving Hong Kong kids — see § 14 below.


6. PDPO rights catalogue

6.1 The rights catalogue

A Hong Kong resident has the following rights under the PDPO + PCPD binding guidance as in force at the Effective date.

6.2 Timeline

Where the data-access carve-outs at PDPO Pt VIII (ss 51–62) apply (national security / public order / public safety / prevention/detection of crime / regulatory functions / health emergencies / certain professional confidentialities), Balance may decline to provide access and explain the reasons. PCPD interpretive practice is that any refusal must be supported by reasons in writing.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity. The identity-verification protocol uses the parent's existing authentication credential.

6.4 Fees

Under PDPO s 28 + the PCPD's Guidance on the Imposition of a Fee for Compliance with a Data Access Request, a data user may impose a fee for compliance with a data-access request, provided the fee is not excessive. The fee must reflect direct costs and not be used to deter requests. Balance does not charge for access in practice.

6.5 Language

A request may be submitted in English or Traditional Chinese. The PCPD accepts complaints in English and Traditional Chinese.


7. Children's data — PDPO + PCJO + common-law parental authority

Balance processes personal data of Hong Kong kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Hong Kong resident's personal data leaves Hong Kong at the point of being uploaded to the Balance backend.

8.1 The Hong Kong-to-US transfer mechanism — Schedule 1 DPP 3 + PCPD May 2022 Model Clauses

PDPO s 33 is the statutory cross-border-transfer provision but is NOT YET COMMENCED at the Effective date. The s 33 provision, when commenced, will prohibit the transfer of personal data to a place outside Hong Kong unless one of six conditions is satisfied (whitelist of jurisdictions with adequate protection / written assessment of adequate protection / data-subject consent / etc.). The s 33 provision was enacted in 1995 but has remained un-commenced for nearly three decades — a long-standing operational anomaly of Hong Kong privacy law.

In the s 33 gap, the operative mechanism for cross-border-transfer is the combination of:

Balance relies on the following stack to satisfy DPP 3 + DPP 4 + the PCPD May 2022 Model Clauses framework for the Hong Kong → US transfer:

8.2 The Hong Kong-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country, the Hong-Kong-KZ axis is covered by the PCPD May 2022 Model Clauses Scenario 2 + DPP 3 prescribed-consent overlay — written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.

8.3 PDPO s 33 commencement trigger

Should PDPO s 33 be commenced after the Effective date, Balance will update this Annex via the § 18 versioning protocol to reflect the operative s 33 mechanism (which is expected to require either a whitelisted-jurisdiction transfer, a written assessment of adequate protection at the recipient, or one of the s 33 derogation conditions). Until s 33 is commenced, the PCPD May 2022 Model Clauses framework is the operative mechanism.


9. Data residency for Hong Kong residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Hong Kong resident's personal data held in Hong Kong? No. Every Hong Kong resident's personal data is held in the United States. The PDPO Schedule 1 DPP 3 + DPP 4 + PCPD May 2022 Model Clauses transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there a Hong Kong establishment? No. Balance has no permanent establishment in Hong Kong. The PDPO's extraterritorial reach (s 39 + PCPD interpretive practice) is the basis for Balance's PDPO compliance.
Where is the supervisory authority? Hong Kong — PCPD + OGCIO + the regulatory bodies in § 3.3 above.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Hong Kong does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the Hong Kong Monetary Authority Supervisory Policy Manual on outsourcing by banks — not applicable to Balance) and the Securities and Futures Commission outsourcing guidance (not applicable to Balance).


10. Sub-processors touching Hong Kong-resident data

Sub-processor Role Location of processing Hong Kong transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States PCPD May 2022 Model Clauses Scenario 2 written processor agreement with PDPO-comparable-protection clauses + DPP 3 prescribed consent of the parent on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) PCPD May 2022 Model Clauses Scenario 2 (Google Cloud Data Processing Addendum incorporating the substance of the PCPD clauses) + DPP 3 consent; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) PCPD May 2022 Model Clauses Scenario 2 (Google Cloud Data Processing Addendum incorporating the substance of the PCPD clauses) + DPP 3 consent; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Hong Kong kid + parent devices United States PCPD May 2022 Model Clauses Scenario 2 + DPP 3 as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States PCPD May 2022 Model Clauses Scenario 2 + DPP 3 as above.
Google LLC — Google Play Billing Processes subscription purchases United States PCPD May 2022 Model Clauses Scenario 2 + DPP 3 + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Hong Kong parent users United States PCPD May 2022 Model Clauses Scenario 2 + DPP 3.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + PDPO Schedule 1 DPP 4 security obligation. The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — PCPD Guidance on Data Breach Handling and Data Breach Notifications (voluntary regime)

The PDPO does NOT statutorily mandate breach notification at the Effective date. There is no Hong Kong statutory equivalent of GDPR Art 33 + Art 34, the Singapore PDPA Part VIA (3-calendar-day PDPC notification), the Australian Privacy Act Part IIIC NDB scheme, the Israel PPL section 11D Amendment 13 miyad notification, the Philippines DPA IRR Sec 38 (72 hours). The operative breach-notification regime is the PCPD's voluntary Guidance on Data Breach Handling and Data Breach Notifications (most recent revision):

Audience Trigger Deadline Channel
PCPD A data breach has occurred — defined in the PCPD Guidance as a suspected or confirmed unauthorised or accidental loss, theft, leakage, alteration, destruction, or access to personal data held by the data user. The PCPD recommends voluntary notification as soon as practicable on the data user's reasonable belief that the data breach is likely to result in real risk of harm. Balance internal anchor: as soon as practicable but no later than 72 hours from initial discovery (matched to the GDPR Art 33 benchmark, exceeding the PCPD voluntary expectation). PCPD online Data Breach Notification Form at https://www.pcpd.org.hk/english/data_breach_notification/
Affected individuals A data breach as above where, on the data user's harm-likelihood analysis under the PCPD Guidance, affected-individual notification is warranted to allow the affected individuals to take protective measures. As soon as practicable after PCPD notification, subject to the PCPD Guidance carve-outs (where the data has been rendered unintelligible — e.g., the E2EE ciphertext case — affected-individual notification may not be warranted under the PCPD Guidance harm-analysis framework). Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). Hong Kong Police Force CSTCB + SWD + OFNAA.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, formal assessment under the PCPD Guidance completed within 72 hours of discovery, PCPD voluntary notification within the internal 72-hour anchor, affected-individual notification on harm-likelihood analysis.

11.1 Minimum content of the PCPD notification (per PCPD Guidance on Data Breach Handling and Data Breach Notifications)

The PCPD notification states: - the nature of the data breach, the description of how the breach occurred, the personal data possibly involved, the chronology of the events leading up to the loss of control of the personal data; - the number of data subjects involved (or the best estimate); - the description of the likely consequences of the breach; - the measures taken or proposed to be taken to address the breach (including measures to mitigate possible harm or negative consequences); - the contact information of the privacy contact (, named individual: ).

The English-language template lives in our breach-notification runbook § 8.1. A Traditional Chinese version is queued for Phase 2 locale rollout.

11.2 Non-compliance — PDPO Part VII + Part VIIA

Failure to take all practicable steps to safeguard personal data under PDPO Schedule 1 DPP 4 may be subject to the PCPD's enforcement-notice regime under PDPO ss 50A–50B. Non-compliance with an enforcement notice is an offence under PDPO s 50A(3) — fine up to HK$50,000 + imprisonment up to 2 years on first conviction + HK$100,000 + imprisonment up to 2 years on subsequent conviction. A Personal Data (Privacy) (Amendment) Bill introducing mandatory breach notification and substantially-enhanced administrative-fine quanta has been the subject of public consultation by the PCPD + the Constitutional and Mainland Affairs Bureau but has not been introduced into the Legislative Council at the Effective date — § 18 versioning protocol covers its enactment.

11.3 PDPO Part VIIIA doxxing offences (separate criminal stack)

PDPO Part VIIIA (introduced by the 2021 Amendment Ordinance) criminalises doxxing — s 64 disclosure of personal data without consent with intent to threaten, intimidate, harass, or cause harm. Penalty up to HK$1,000,000 fine + imprisonment up to 5 years on conviction on indictment. The PCPD may issue cessation notices under s 66E to require removal of doxxing material from platforms.


12. Cookies, spam, and electronic direct marketing

Hong Kong does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) PDPO Schedule 1 DPP 1 + DPP 3 for any cookie that processes personal data; (ii) the PCPD's interpretive position on cookies in the Guidance for Data Users on the Collection and Use of Personal Data through the Internet; (iii) the Unsolicited Electronic Messages Ordinance (Cap. 593) for commercial electronic messages; (iv) PDPO Part VIA Direct Marketing for the use of personal data in direct marketing.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send commercial electronic messages within the meaning of UEMO to Hong Kong residents. The only email Balance sends to Hong Kong parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The UEMO commercial electronic message definition requires the message to promote or solicit the supply of goods or services; transactional messages are outside the definition. If Balance ever introduces a marketing channel, we will comply with UEMO Schedule 2 (sender identification + valid unsubscribe + accurate message subject) and the OFCA Code of Practice on the Sending of Commercial Electronic Messages, and we will also comply with PDPO Part VIA Direct Marketing ss 35A–35M: (i) the prescribed action (notification of intended use); (ii) the prescribed consent of the data subject; (iii) the response channel.

12.4 No telemarketing

Balance does not place telemarketing voice calls, SMS, or messaging-app outreach to Hong Kong residents. The UEMO + PDPO Part VIA obligations are not engaged.


13. Lawful-access requests and the encryption posture

Hong Kong authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Hong Kong

A Hong Kong resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

A Hong Kong resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Privacy Commissioner for Personal Data (PCPD) PDPO 13/F, 248 Queen's Road East, Wan Chai, Hong Kong; https://www.pcpd.org.hk/; +852 2827 2827; complaints@pcpd.org.hk
Administrative Appeals Board Appeals from PCPD decisions under PDPO s 39 + AAB Ordinance Cap. 442 https://www.aab.gov.hk/en/index.html
Office of the Government Chief Information Officer (OGCIO) ICT policy + CyberDefender programme 19/F, West Wing, Central Government Offices, Hong Kong; https://www.ogcio.gov.hk/en/; +852 2867 2611
Hong Kong Police Force — Cyber Security and Technology Crime Bureau (CSTCB) Cyber-CSAE + PDPO Part VIIIA doxxing https://www.police.gov.hk/; emergency 999; e-Report Centre https://www.erc.police.gov.hk/
Office of the Communications Authority (OFCA) UEMO + Telecommunications Ordinance https://www.ofca.gov.hk/; +852 2961 6333
Customs and Excise Department TDO + CSAM cross-border seizure https://www.customs.gov.hk/; +852 2543 6429
Social Welfare Department (SWD) PCJO Cap. 213 child-protection https://www.swd.gov.hk/; 2343 2255
Office for Film, Newspaper and Article Administration (OFNAA) Control of Obscene and Indecent Articles Ordinance https://www.ofnaa.gov.hk/; +852 2594 5754
Consumer Council Consumer advocacy + complaints brokerage https://www.consumer.org.hk/; +852 2929 2222
District Court of Hong Kong PDPO s 66 civil action up to HK$3 million; small-claims jurisdiction via Small Claims Tribunal up to HK$75,000 https://www.judiciary.hk/en/
Court of First Instance PDPO s 66 civil action above District Court limits; judicial review of PCPD + AAB decisions https://www.judiciary.hk/en/
Court of Appeal Appellate review of Court of First Instance decisions https://www.judiciary.hk/en/
Court of Final Appeal Final appellate review on points of law https://www.hkcfa.hk/
Office of the Commissioner on Interception of Communications and Surveillance ICSO oversight https://www.sciocs.gov.hk/en/index.html

A Hong Kong resident may always first raise the matter with us at (data-access request; named individual: , in his capacity as the privacy contact under PDPO Schedule 1 DPP 5). We will respond within the PDPO timelines. The PCPD's published policy recommends raising the matter with the data user first but the PCPD also accepts direct complaints, particularly where the complaint involves a serious matter warranting immediate PCPD action.


16. Consumer rights — the TDO + SGO + SSITO + CECO + UCO overlay

The Trade Descriptions Ordinance (Cap. 362) ("TDO"), the Sale of Goods Ordinance (Cap. 26) ("SGO"), the Supply of Services (Implied Terms) Ordinance (Cap. 457) ("SSITO"), the Control of Exemption Clauses Ordinance (Cap. 71) ("CECO"), and the Unconscionable Contracts Ordinance (Cap. 458) ("UCO") apply to Balance's subscription flow as a consumer transaction. The parent is a consumer within the meaning of each statute (not engaged in trade or business in the transaction). Treatment is implemented in Subscription Terms § 20.

16.1 Trade Descriptions Ordinance — unfair trade practices (TDO Part II + Part IIA)

TDO Part II (as amended by the Trade Descriptions (Unfair Trade Practices) (Amendment) Ordinance 2012 in force 19 July 2013) prohibits unfair trade practices in a consumer transaction, including: - s 7 false trade descriptions of goods; - s 7A false trade descriptions of services; - s 13C misleading omissions; - s 13D aggressive commercial practices; - s 13E bait advertising; - s 13F bait-and-switch; - s 13G wrongly accepting payment.

Enforced by the Customs and Excise Department + the Communications Authority for regulated-sector services. Civil + criminal penalties (fine up to HK$500,000 + imprisonment up to 5 years for the most serious offences). The Balance Terms of Service (Terms of Service) and the in-app subscription flow are drafted to avoid each TDO Part II risk.

16.2 Sale of Goods Ordinance + Supply of Services (Implied Terms) Ordinance — implied terms

Applied to Balance's subscription supply as the supply of services to consumers; reasonable care + skill + reasonable time + reasonable charge are implied terms of the subscription contract.

16.3 Control of Exemption Clauses Ordinance — exemption-clause control

Balance's Terms of Service exemption clauses are subject to the s 11 reasonableness test in respect of Hong Kong consumers.

16.4 Unconscionable Contracts Ordinance — judicial-modification power

Balance's Terms of Service and Subscription Terms are subject to the UCO s 5 judicial-modification power in respect of Hong Kong consumers.

16.5 No statutory cooling-off period under Hong Kong general law

Hong Kong general consumer-protection law does not include a statutory cooling-off period for distance-selling contracts (in contrast with the SG CPFTA, the IL Consumer Protection Law s 14C 14-day cooling-off, the AR CDC 10-business-day botón de arrepentimiento, the EU Consumer Rights Directive 14-day right of withdrawal, and similar regimes). Specific sector-specific cooling-off rules apply to certain product categories (e.g., timeshare contracts under the Residential Properties (First-Hand Sales) Ordinance — n/a to Balance; certain financial products under SFC rules — n/a to Balance).

16.6 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the TDO, SGO, SSITO, CECO, or UCO to the prejudice of the Hong Kong consumer are subject to the public policy doctrine + the CECO s 11 reasonableness test + the UCO s 5 judicial-modification power.

16.7 Refunds and the Hong Kong subscription posture

Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the Hong Kong general-consumer-protection minimum (which does not impose a statutory cooling-off period). The 14-day refund window is documented at Subscription Terms § 20.


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Hong Kong Country Annex.

← Back to Privacy Policy · Children's Privacy Notice