Privacy and security


HSBC's privacy principles

Our business has been built on trust between our customers and ourselves. To preserve the confidentiality of all information you provide to us, we maintain the following privacy principles:

  1. We only collect personal information that we believe to be relevant and required to understand your financial needs and to conduct our business.
  2. We use your personal information to provide you with better customer services and products.
  3. We may pass your personal information to other HSBC Group companies or agents, as permitted by law.
  4. We will not disclose your personal information to any external organisation unless we have your consent or are required by law or have previously informed you.
  5. We may be required from time to time to disclose your personal information to Governmental or judicial bodies or agencies or our regulators, but we will only do so under proper authority.
  6. We aim to keep your personal information on our records accurate and up-to-date.
  7. We maintain strict security systems designed to prevent unauthorised access to your personal information by anyone, including our staff.
  8. All HSBC Group companies, all our staff and all third parties with permitted access to your information are specifically required to observe our confidentiality obligations.

By maintaining our commitment to these principles, we at HSBC will ensure that we respect the inherent trust that you place in us.

Your privacy matters to us

This section provides specific details of how we treat any personal information you might wish to provide us when you visit this site.

Data security

  • Security is our top priority. The Hongkong and Shanghai Banking Corporation Limited ('the Bank') will strive at all times to ensure that your personal data will be protected against unauthorised or accidental access, processing or erasure. We maintain this commitment to data security by implementing appropriate physical, electronic and managerial measures to safeguard and secure your personal data.
  • The secure area of our website supports the use of 128-bit Secure Socket Layer (SSL) encryption technology - an industry standard for encryption over the Internet to protect data. When you provide sensitive information such as credit card details, it will be automatically converted into codes before being securely dispatched over the Internet.
  • Our web servers are protected behind "firewalls" and our systems are monitored to prevent any unauthorised access. We will not send personal information to you by ordinary email. As the security of ordinary email cannot be guaranteed, you should only send email to us using the secure email facility on our website.

    All practical steps will be taken to ensure that personal data will not be kept longer than necessary and that the Bank will comply with all statutory and regulatory requirements in the Hong Kong Special Administrative Region concerning the retention of personally identifiable information.

Security assurance

  • Both you and HSBC play an important role in protecting against online fraud. You should be careful that your bank account details including your Username and/or Password are not compromised by ensuring that you do not knowingly or accidentally share, provide or facilitate unauthorised use of it. Do not share your Username and/or password or allow access or use of it by others. We endeavor to put in place high standards of security to protect your interests. If, in the unlikely event, unauthorised transactions have been conducted through your account through no fraud, fault or negligence on your part, we will see that you are covered for your direct loss up to the full amount of the unauthorised transaction.
  • You should safeguard your unique Username and Password by keeping it secret and confidential. Never write them down or share these details with anyone. HSBC will never ask you for your Internet Banking Password, in order to ensure that you are the only person who knows this information. When choosing your unique Username and Password for the first time, do not create it using easily identifiable information such as your birthday, telephone number or a recognisable part of your name. If you think your Username and/or password has been disclosed to a third party, is lost or stolen and unauthorised transactions may have been conducted, you are responsible to inform us immediately.

Collection of personal information

Use of Cookies, Spotlight Tags and Web Beacons etc

  • We may record your visit to this Site for analysing the number of visitors to this Site, general usage patterns and your personal usage patterns and improving your experience. We may gather some of this information through the use of "cookies". Cookies are small bits of information that are automatically stored on your web browser in your computer that can be retrieved by this Site. Cookies are useful because they allow us to recognise your device and they store information about your use of this Site, thus enabling us to provide more useful features to you, to tailor the content of our website to suit your interests and, where permitted by your marketing preferences, provide you with promotional materials or direct marketing based on your usage patterns. We will be able to access the information stored on the cookies and record how you use this Site. Most browsers are initially set to accept cookies. If you prefer, you can set your browser to disable cookies or to inform you when they are set - please see our cookie policy for more details of how to do this https://www.hsbc.com/cookie-policy . By disabling cookies, you may not be able to take full advantage of this Site, including HSBC Internet Banking. If you accept cookies, you will be acknowledging that your information is being collected, stored, accessed and used as outlined above.
  • We may also work with third parties to research certain usage and activities on this Site for us. These third party research agencies include Doubleclick, Yahoo!, Facebook, Nielsen//NetRatings and Adobe. They use technologies such as cookies, spotlight monitoring and web beacons to collect information for this research. They use the information collected through such technologies (i) to find out more about users of this Site, including user demographics and behaviour and usage patterns, (ii) for more accurate reporting and (iii) to improve the effectiveness of our marketing. They aggregate the information collected and then share it with us. No personally identifiable information about you is collected or shared by Doubleclick, Yahoo!, Facebook, Nielsen//NetRatings and Adobe with us as a result of this research. Should you wish to disable the cookies associated with such technologies, you may change the setting on your browser. However, you may not be able to enter certain parts of this Site, including HSBC Internet Banking.”
  • To find out more about the use of cookies and the information-collecting practices and opt-out procedures of Doubleclick, Yahoo!, Facebook, Nielsen//NetRatings and Adobe, please visit:

Marketing promotions

Occasionally we may collect personal information from visitors to this site and those individuals that participate in a contest or promotion (online or over the telephone,or at one of our branches). Such information is only collected from individuals who voluntarily provide us with their personal information. We may use this information to advise them of products, services and other marketing materials, which we think, may be of interest to them. We may also invite visitors to this site to participate in market research and surveys and other similar activities.

You can choose to receive marketing and other promotional materials by email. If you do receive email or promotional direct mailings, you will always have an opportunity to opt-out.

If at any time you would like us to cease sending you direct mailings, please contact our representatives by calling (852) 2233 3322 for HSBC Premier customers, (852) 2748 8333 for HSBC Advance customers or (852) 2233 3000 for other customers. We will then, at no cost to you, act on your request within 30 days and ensure that you are not included in future direct marketing promotions.

If we do ask you to provide personal information, we will always specify the purpose for which such personal information is collected and ensure that it is only used for the purpose specified at the time of collection.

*Notice relating to the personal data (privacy) ordinance (the 'ordinance')

This Statement is made by The Hongkong and Shanghai Banking Corporation Limited ('the Bank') in accordance with the Personal Data (Privacy) Ordinance of the Hong Kong Special Administrative Region ('the Ordinance'). The Statement is intended to notify you why personal data is collected, how it will be used and to whom data access requests are to be addressed.

  1. From time to time, it is necessary for individuals to supply the Bank with data in connection with the opening or continuation of accounts and the establishment or continuation of banking facilities or provision of banking services or compliance with any laws, guidelines or requests issued by regulatory or other authorities.
  1. Failure to supply such data may result in the Bank being unable to open or continue accounts or establish or continue banking facilities or provide banking services.
  1. It is also the case that data are collected from (i) customers in the ordinary course of the continuation of the banking relationship (for example, when customers write cheques, deposit money or apply for credit), (ii) a person acting on behalf of the individual whose data are provided, and (iii) other sources (for example, information obtained from credit reference agencies). Data may also be generated or combined with other information available to the Bank or any member of the HSBC Group ("HSBC Group" means HSBC Holdings plc, its affiliates, subsidiaries, associated entities and any of their branches and offices (together or individually) and "member of the HSBC Group" has the same meaning).
  1. The purposes for which data may be used are as follows:
    1. considering applications for products and services and the daily operation of products, services and credit facilities provided to customers;
    2. conducting credit checks (including without limitation upon an application for consumer credit (including mortgage loans) and upon periodic or special reviews of the credit which normally will take place one or more times each year);
    3. creating and maintaining the Bank's credit and risk related models;
    4. assisting other financial institutions to conduct credit checks and collect debts;
    5. ensuring ongoing credit worthiness of customers;
    6. designing financial services or related products for customers' use;
    7. marketing services, products and other subjects as described in (f) below;
    8. determining the amount of indebtedness owed to or by customers;
    9. collecting of amounts outstanding from customers and those providing security for customers' obligations;
    10. meeting obligations, requirements or arrangements, whether compulsory or voluntary, of the Bank or any of its branches or any member of the HSBC Group to comply with, or in connection with:
      1. any law, regulation, judgment, court order, voluntary code, sanctions regime, within or outside the Hong Kong Special Administrative Region ("Hong Kong") existing currently and in the future ("Laws");
      2. any guidelines, guidance or requests given or issued by any legal, regulatory, governmental, tax, law enforcement or other authorities, or self-regulatory or industry bodies or associations of financial services providers within or outside Hong Kong existing currently and in the future and any international guidance, internal policies or procedures;
      3. any present or future contractual or other commitment with local or foreign legal, regulatory, judicial, administrative, public or law enforcement body, or governmental, tax, revenue, monetary, securities or futures exchange, court, central bank or other authorities, or self-regulatory or industry bodies or associations of financial service providers or any of their agents with jurisdiction over all or any part of the HSBC Group (together the "Authorities" and each an "Authority") that is assumed by, imposed on or applicable to the Bank or any of its branches or any member of the HSBC Group; or
      4. any agreement or treaty between Authorities;
    11. complying with any obligations, requirements, policies, procedures, measures or arrangements for sharing data and information within the HSBC Group and/or any other use of data and information in accordance with any programmes for compliance with sanctions or prevention or detection of money laundering, terrorist financing or other unlawful activities;
    12. conducting any action to meet obligations of the Bank or any member of the HSBC Group to comply with Laws or international guidance or regulatory requests relating to or in connection with the detection, investigation and prevention of money laundering, terrorist financing, bribery, corruption, tax evasion, fraud, evasion of economic or trade sanctions and/or any acts or attempts to circumvent or violate any Laws relating to these matters;
    13. meeting any obligations of the Bank or any member of the HSBC Group to comply with any demand or request from the Authorities;
    14. enabling an actual or proposed assignee of the Bank, or participant or sub-participant of the Bank's rights in respect of the customer to evaluate the transaction intended to be the subject of the assignment, participation or sub-participation; and
    15. purposes relating thereto.
  1. Data held by the Bank or a member of the HSBC Group relating to an individual will be kept confidential but the Bank or a member of the HSBC Group may provide such information to the following parties (whether within or outside Hong Kong) for the purposes set out in paragraph (d):
    1. any agents, contractors, sub-contractors, service providers or associates of the HSBC Group (including their employees, directors, officers, agents, contractors, service providers, and professional advisers);
    2. any third party service provider who provides administrative, telecommunications, computer, payment or securities clearing or other services to the Bank in connection with the operation of its business (including their employees, directors and officers);
    3. any Authorities;
    4. any person under a duty of confidentiality to the Bank including a member of the HSBC Group which has undertaken to keep such information confidential;
    5. the drawee bank providing a copy of a paid cheque (which may contain information about the payee) to the drawer;
    6. any persons acting on behalf of an individual whose data are provided, payment recipients, beneficiaries, account nominees, intermediary, correspondent and agent banks, clearing houses, clearing or settlement systems, market counterparties, upstream withholding agents, swap or trade repositories, stock exchanges, companies in which the customer has an interest in securities (where such securities are held by the Bank or any member of the HSBC Group) or a person making any payment into the customer's account;
    7. credit reference agencies, and, in the event of default, to debt collection agencies;
    8. any person to whom the Bank or any of its branches or any member of the HSBC Group is under an obligation or required or expected to make disclosure for the purposes set out in, or in connection with, paragraph (d)(x), (d)(xi) or (d)(xii);
    9. any actual or proposed assignee of the Bank or participant or sub-participant or transferee of the Bank's rights in respect of the customer; and
      1. any member of the HSBC Group;
      2. third party financial institutions, insurers, credit card companies, securities and investment services providers;
      3. third party reward, loyalty, co-branding and privileges programme providers;
      4. co-branding partners of the Bank or any member of the HSBC Group (the names of such co-branding partners will be provided during the application process for the relevant services and products, as the case may be);
      5. charitable or non-profit making organisations; and
      6. external service providers (including but not limited to mailing houses, telecommunication companies, telemarketing and direct sales agents, call centres, data processing companies and information technology companies) that the Bank engages for the purposes set out in paragraph (d)(vii).

    Such information may be transferred to a place outside Hong Kong.

    In connection with paragraph (vii) above,

    1. of all the data which may be collected or held by the Bank from time to time in connection with mortgages, the following data relating to the customer (including any updated data of any of the following data) may be provided by the Bank, or on its behalf and/or as agent, to the credit reference agency:
      1. full name;
      2. capacity in respect of each mortgage (as borrower, mortgagor or guarantor);
      3. Hong Kong Identity Card Number or travel document number or certificate of incorporation number;
      4. date of birth or date of incorporation;
      5. correspondence address;
      6. mortgage account number in respect of each mortgage;
      7. type of the facility in respect of each mortgage;
      8. mortgage account status in respect of each mortgage (e.g. active, closed, write-off); and
      9. if any, mortgage account closed date in respect of each mortgage.
      The credit reference agency will use the above data supplied by the Bank for the purposes of compiling a count of the number of mortgages from time to time held by the customer (as borrower, mortgagor or guarantor respectively, whether in sole name or joint names with others) for sharing in the consumer credit database of the credit reference agency by credit providers; and
    1. before the right referred to in (g) (v) below may be exercised, (I) in the event of any default in payment, unless the amount in default is fully repaid or written off (otherwise than due to a bankruptcy order) before the expiry of 60 days as measured by the Bank from the date such default occurred, the customer is liable to have his account repayment data retained by the credit reference agency at least until the expiry of five years from the date of final settlement of the amount in default and (II) in the event of any amount being written off due to a bankruptcy order being made against the customer, the customer is liable to have his account repayment data retained by the credit reference agency, regardless of whether the account repayment data reveal any material default, until the expiry of five years from the date of final settlement of the amount in default or the expiry of five years from the date of discharge from a bankruptcy as notified by the customer with evidence to the credit reference agency, whichever is earlier. Account repayment data include amount last due, amount of payment made during the last reporting period, remaining available credit or outstanding balance and default data (being amount past due and number of days past due, date of settlement of amount past due, and date of final settlement of amount in material default (if any)). Material default is a default in payment for a period in excess of 60 days.
    1. Use of data in direct marketing 

      The Bank intends to use a customer's data in direct marketing and the Bank requires the customer's consent (which includes an indication of no objection) for that purpose. In this connection, please note that:
      1. the name, contact details, products and other service portfolio information, transaction pattern and behavior, financial background and demographic data of a customer held by the Bank from time to time may be used by the Bank in direct marketing;
      2. the following classes of services, products and subjects may be marketed:
        1. financial, insurance, credit card, banking and related services and products;
        2. reward, loyalty, co-branding or privileges programmes and related services and products;
        3. services and products offered by the Bank's co-branding partners (the names of such co-branding partners will be provided during the application for the relevant services and products, as the case may be); and
        4. donations and contributions for charitable and/or non-profit making purposes;
      3. the above services, products and subjects may be provided by or (in the case of donations and contributions) solicited by the Bank and/or:
        1. any member of the HSBC Group;
        2. third party financial institutions, insurers, credit card companies, securities and investment services providers;
        3. third party reward, loyalty, co-branding or privileges programme providers;
        4. co-branding partners of the Bank and the HSBC Group (the names of such co-branding partners will be provided during the application of the relevant services and products, as the case may be); and
        5. charitable or non-profit making organisations;
      4. in addition to marketing the above services, products and subjects itself, the Bank also intends to provide the data described in paragraph (f)(i) above to all or any of the persons described in paragraph (f) (iii) above for use by them in marketing those services, products and subjects, and the Bank requires the customer's written consent (which includes an indication of no objection) for that purpose;
      5. the Bank may receive money or other property in return for providing the data to the other persons in paragraph (f)(iv) above and, when requesting the customer's consent or no objection as described in paragraph (f)(iv) above, the Bank will inform the customer if it will receive any money or other property in return for providing the data to the other persons.

      If a customer does not wish the bank to use or provide to other persons his data for use in direct marketing as described above, the customer may exercise his opt-out right by notifying the bank.

    1. Under and in accordance with the terms of the Ordinance and the Code of Practice on Consumer Credit Data approved and issued under the Ordinance, any individual has the right:
      1. to check whether the Bank holds data about them and of access to such data;
      2. to require the Bank to correct any data relating to them which is inaccurate;
      3. to ascertain the Bank's policies and practices in relation to data and to be informed of the kind of personal data held by the Bank;
      4. in relation to consumer credit, to be informed on request which items of data are routinely disclosed to credit reference agencies or debt collection agencies, and be provided with further information to enable the making of an access and correction request to the relevant credit reference agency or debt collection agency; and
      5. upon satisfactory termination of the credit by full repayment and on condition that there has been, within five years immediately before such termination, no material default under the credit as determined by the Bank, to instruct the Bank to make a request to the relevant credit reference agency to delete from its database any account data relating to the terminated credit.
    1. In accordance with the terms of the Ordinance, the Bank has the right to charge a reasonable fee for the processing of any data access request.
    1. The person to whom requests for access to data or correction of data or for information regarding policies and practices and kinds of data held are to be addressed as follows:

      The Data Protection Officer
      The Hongkong and Shanghai Banking Corporation Limited
      PO Box 72677
      Kowloon Central Post Office
      Hong Kong
      E-mail: dfv.enquiry@hsbc.com.hk
    1. The Bank may have obtained a credit report on the customer from a credit reference agency in considering any application for credit. In the event the customer wishes to access the credit report, the Bank will advise the contact details of the relevant credit reference agency.
    1. Nothing in this Notice shall limit the rights of customers under the Ordinance.

    Note: In case of discrepancies between the English and Chinese versions, the English version shall apply and prevail.

    IMPORTANT: By accessing this web site and any of its pages you are agreeing to the terms set out above. Thank you for choosing HSBC.

    * You may be subject to an earlier version of this Notice (known as Notice to Customers relating to the Personal Data (Privacy) Ordinance ) if you have not consented to subsequent changes to the earlier notice.