What Hong Kong's Personal Data Privacy Ordinance Means for Vehicle Telematics Data Collected From Converted Electric Classics
- ryanwan4
- Aug 11
- 7 min read
Under Hong Kong's Personal Data (Privacy) Ordinance (PDPO), telematics data collected from a converted electric classic (GPS location, driving behaviour, battery diagnostics) is treated as personal data only when it can be practicably linked to an identifiable living person. If the data is properly anonymised or aggregated, it falls outside the ordinance entirely. If it is not, the vehicle owner or the company managing that data must follow the PDPO's Data Protection Principles: collect only what is necessary, get consent before repurposing it, and don't keep it longer than needed [clic.org.hk][elegislation.gov.hk].
TL;DR
Telematics data (location, driving patterns, charging logs) is personal data under the PDPO only if it can identify a living individual, directly or indirectly.
Anonymised or fully aggregated telematics data sits outside PDPO regulation.
There is no telematics-specific or EV-specific law in Hong Kong; general Data Protection Principles apply to every sector, including automotive [dlapiperdataprotection.com].
Consent, data minimisation, and retention limits are the three practical obligations that matter most for anyone collecting this data.
Enforcement is real: unauthorised use for direct marketing or malicious disclosure can carry fines up to HKD 1,000,000 and up to five years in prison.
About the Author: This article is written from the position of a Hong Kong-based EV conversion specialist that builds and maintains telematics-equipped drivetrains for classic cars, giving direct, practical exposure to how data protection rules apply to vehicles it converts and services under warranty.
What Counts as Personal Data When a Classic Car Goes Electric?
An electric conversion doesn't just replace the engine, it usually adds a layer of digital monitoring that a 1960s or 1970s combustion classic never had. Modern EV drivetrains, including the ones used in classic car conversions, typically include a battery management system that logs charge cycles, temperature, and sometimes GPS position for theft recovery or servicing alerts. Under the PDPO, this becomes personal data the moment it can be tied back to a specific driver or owner, whether by name, vehicle registration, account login, or a combination of data points that narrows identification down to one person [clic.org.hk][linklaters.com].
The ordinance itself does not single out cars, batteries, or location trackers as a special category. It defines personal data broadly: any data relating to a living individual from which their identity can be practicably ascertained. That means a raw GPS trail tied to a customer's service account is personal data. A stripped, aggregated dataset showing "average daily distance across 40 converted vehicles" with no identifiers attached generally is not, because no single individual can be picked out of it.
Does the PDPO Treat GPS and Driving Behaviour Data Differently From Other Personal Data?
No, and this is a common misconception. The PDPO does not create a separate legal category for location or driving data. It applies the same test it applies to a name, an email address, or a photo: can this data, alone or combined with other data, identify a living person [linklaters.com]?
This matters practically for anyone running or maintaining a fleet of converted vehicles, because it means there's no shortcut regulation to follow specifically for telematics. There is currently no Hong Kong-specific statute or guideline dedicated to vehicle telematics or EV data collection beyond the PDPO's general principles. Companies operating in this space, including workshops, fleet operators, and conversion specialists, have to interpret and apply the same Data Protection Principles that govern HR records or customer databases [dlapiperdataprotection.com].
What Are the Practical Consent and Retention Rules for Telematics Data?
Consent and retention aren't abstract legal concepts here. They translate into concrete workshop and aftersales practices. The PDPO's Data Protection Principles require that data collection be necessary and not excessive for a lawful purpose, that new uses of the data require explicit consent, and that data isn't kept longer than needed to serve its original purpose [clic.org.hk][jdsupra.com].
In practice, this breaks down into three obligations:
Purpose limitation: if telematics data is collected to monitor battery health for warranty servicing, using that same data later for a different purpose, such as marketing analysis, requires fresh, explicit consent.
Minimisation: collect only what the stated purpose requires. A battery diagnostic log doesn't need to include continuous GPS tracking unless there's a specific, disclosed reason (theft recovery, roadside assistance).
Retention limits: data should be deleted or anonymised once it's no longer needed for the purpose it was collected for, not stored indefinitely "just in case" [mayerbrown.com][jdsupra.com].
Think of it like a workshop invoice trail. A garage keeps service records long enough to honour a warranty claim, not forever, and doesn't hand that invoice history to a third party for an unrelated purpose without asking first. Telematics data follows the same logic, just in digital form.
What Happens If a Company Gets This Wrong?
Building on the retention and consent obligations above, the harder question is what enforcement actually looks like. The Privacy Commissioner for Personal Data can issue an enforcement notice when personal data is misused, and ignoring that notice is itself a criminal offense. Specific violations, such as using telematics data for unauthorised direct marketing or malicious disclosure of a customer's location history, can carry fines of up to HKD 1,000,000 and up to five years in prison.
This is a meaningfully different enforcement structure from a simple monetary penalty regime. The criminal exposure sits with non-compliance after a notice is issued, not automatically at the point of a first data slip. That gives companies a genuine window to correct course, but it also means ignoring a warning from the office of the hong kong privacy commissioner is the point where risk escalates sharply.
Do Cross-Border Data Transfers Change Anything for Fleet Operators or B2B Partners?
A related but distinct question comes up for any business managing multiple converted vehicles across regional partners: what happens when telematics data crosses a border? Section 33 of the PDPO was written to restrict transferring personal data outside Hong Kong unless there's written consent or the destination has comparable privacy protection. However, Section 33 has never actually been brought into force. That means there is currently no mandatory legal restriction on cross-border data transfers under the PDPO, even though the provision exists on paper.
This is worth flagging precisely because it's easy to misstate. A company should not assume Section 33 imposes hard transfer restrictions today, but should also not treat the absence of enforcement as a reason to be careless. Good practice, and often contractual obligation with partners, still points toward minimising unnecessary data movement and being transparent with customers about where their data is processed.
How Does This Apply Differently to a Private Owner Versus a Fleet or Dealer Partner?
Stepping back from the technical detail, a separate concern is who actually holds the compliance obligation. This is where B2C and B2B relationships diverge in practice.
Individual owners (B2C): a private customer who has a classic car converted for personal use typically controls their own vehicle's data. Bespoke conversion clients own their telematics data outright; the conversion specialist's role is limited to what's needed for servicing and the 5-year unlimited mileage warranty it provides on conversions.
Dealer and OEM partners (B2B): under dealer or retailer conversion and OEM conversion arrangements, a dealer or retailer offering EV conversions through a turnkey process is a separate data controller for its own end customers. That dealer, not the conversion specialist, generally holds the direct consent relationship with the driver, though the conversion specialist handling the technical build should still design its systems to minimise unnecessary data capture by default.
This distinction matters because conflating the two creates confusion about who is responsible for consent, storage, and deletion requests. A dealer using a turnkey OEM conversion solution isn't automatically shielded from PDPO obligations just because a technical partner built the drivetrain.
Frequently Asked Questions
Is GPS tracking in a converted classic car always personal data under Hong Kong law? Only if it can be linked to an identifiable individual. Fully anonymised or aggregated location data generally falls outside PDPO regulation [linklaters.com].
Does Hong Kong have an EV-specific data privacy law? No. There is currently no telematics or EV-specific statute; the general PDPO Data Protection Principles apply [dlapiperdataprotection.com].
Can a company use telematics data for marketing without consent? No. Using data for a new purpose, including direct marketing, requires explicit consent beyond what was given for the original purpose [clic.org.hk].
What happens if a business ignores a Privacy Commissioner enforcement notice? Ignoring the notice is a criminal offense, and related violations can carry fines up to HKD 1,000,000 and up to five years in prison.
Can telematics data collected in Hong Kong be sent overseas? Section 33 of the PDPO would restrict this, but it has never been brought into force, so there's currently no mandatory legal barrier, though good data practice still applies.
Who is responsible for data compliance in a dealer partnership conversion? The dealer or retailer holding the direct customer relationship is typically the data controller; the conversion specialist's role is limited to the technical build unless otherwise contracted.
About the Company
A Hong Kong-based EV conversion specialist transforms classic and vintage cars into electric vehicles using in-house, patented powertrain and battery technology. The specialist is moving drivetrain development toward axial flux motors, the newest up-and-coming motor technology currently only found in supercars and ultra-luxury vehicles, as part of its next generation of conversions. Every conversion is road legal in Hong Kong only, backed by a 5-year unlimited mileage warranty, and post-conversion range typically falls between 200 and 300 km WLTP depending on the space and weight available for the battery. The specialist serves private owners through bespoke conversions and supports dealers and retailers through partnered and OEM conversion programmes that handle sourcing, conversion, restoration, quality control, and aftersales end to end.
If you're considering an EV conversion for a classic car, or evaluating a partnership to offer conversions through your own dealership, get in touch to learn more about the process, warranty, and technology behind it.
References
Hong Kong Issues New PCPD Guidance and Leaflets on CCTV, Drones and In-vehicle Cameras | Insights | Mayer Brown (mayerbrown.com)
PERSONAL DATA PRIVACY | Community Legal Information Centre (CLIC) (clic.org.hk)
Hong Kong e-Legislation (elegislation.gov.hk)
Data protection laws in Hong Kong, SAR - Data Protection Laws of the World (dlapiperdataprotection.com)
Data Protected Hong Kong (linklaters.com)
Hong Kong Issues New PCPD Guidance and Leaflets on CCTV, Drones and In-vehicle Cameras | Mayer Brown - JDSupra (jdsupra.com)

Comments