PDPO Compliance for Award Programmes: A Six-Principle Checklist

PDPO compliance is where award programmes are most often quietly exposed. Entry forms collect names, employment details, referee contacts and supporting documents. Judging adds assessments of named individuals. Then the cycle closes, the winner is announced, and the data sits there — indefinitely, on someone’s shared drive, and increasingly on a mailing list it was never collected for.

None of that is unusual and almost none of it is malicious. It is simply what happens when a programme is designed around the ceremony rather than the data. This is a mapping of Hong Kong’s six Data Protection Principles onto what an award programme actually does, in the order the data moves.

On this page

Why PDPO compliance is different for award programmes

Three features make award data awkward in ways ordinary customer data is not.

First, much of it concerns people who never dealt with you directly — referees, nominated colleagues, individuals named inside a case study. They are data subjects too, and they did not fill in your form. Second, judging generates new personal data: an evaluative opinion about a named person, held by you. Third, the programme has a natural end, but almost nothing in a typical award operation triggers deletion when it arrives.

The six principles, mapped to a programme cycle

The six Data Protection Principles for PDPO compliance in award programmes — purpose, retention, use, security, openness, access
DPP1

Purpose and manner of collection

Collect lawfully, fairly and no more than you need, and tell people why at the point of collection. In practice this means a Personal Information Collection Statement on the entry form itself, naming what you collect, the purpose, and who it may be passed to — including judges, who are usually third parties.

Do thisDelete the fields you never actually use. Most entry forms ask for a date of birth nobody reads.
DPP2

Accuracy and retention

Keep data accurate, and no longer than necessary for the purpose. “Necessary” is judged against your stated purpose, so a programme that never states one has no defensible retention period at all.

Do thisWrite a retention schedule per data category before the cycle opens, not after it closes.
DPP3

Use of personal data

Use it only for the purpose stated at collection, or one directly related. A new purpose needs fresh, explicit, voluntary consent. Silence does not count, and neither does a pre-ticked box.

Do thisAudit every downstream use of entrant data. The newsletter is the usual offender.
DPP4

Data security

Take all practicable steps against unauthorised or accidental access, loss or use, proportionate to sensitivity and volume. Where a processor holds data for you, the obligation is discharged contractually — you must bind them.

Do thisCheck what your judges do with entries. Spreadsheets emailed to personal addresses are the common failure.
DPP5

Openness

Make your policies and practices publicly known — what categories of personal data you hold and your main purposes for using it. A privacy policy that exists but describes a different organisation does not satisfy this.

Do thisRead your own privacy policy against your actual entry form. They frequently disagree.
DPP6

Access and correction

Data subjects may request access to their data and correction of inaccuracies. For award programmes this is the uncomfortable one: an unsuccessful entrant may request the personal data you hold about them.

Do thisDecide now, with advice, what a data access request covers in your programme — before one arrives.

The full statutory wording sits with the Privacy Commissioner for Personal Data, and there is a readable summary of the six principles in plain language.

The direct marketing trap

This is the single most common exposure, and it rarely feels like a decision. A programme collects entries, the cycle ends, and the following year those addresses receive a launch announcement. A sponsor is offered the entrant list. A newsletter begins.

Direct marketing is treated seriously under the PDPO. Using personal data for direct marketing requires informed, explicit consent obtained beforehand, and transferring it to a third party for their marketing use is a further step again. This is a criminal-penalty area, not a compliance-team-memo area.

The fix is unglamorous: a separate, unticked opt-in on the entry form, worded for marketing specifically rather than bundled into the terms of entry, with the opt-out honoured promptly. Entering an award is not consent to be marketed to.

How long to keep an entry

There is no statutory number. The test is necessity against your stated purpose, which means you have to reason it out and write it down. A defensible shape for a typical annual programme:

Cycle open
Entries, supporting documents and referee details collected under a PICS that names judges as recipients.
Announcement
Judge access revoked. Working copies held outside the system located and destroyed.
+12 months
Unsuccessful entries and their supporting documents deleted. Scores and audit records retained — they serve a different purpose.
+24 months
Judging records deleted once the challenge window you have defined has closed.
Indefinite
Published winner information only — already public by design, and only what was actually published.

Note the tension with the audit trail argued for in our guide to the award judging process. Governance wants records kept; PDPO compliance wants them deleted when no longer necessary. These are reconciled by defining a challenge window and treating it as the purpose that justifies retention — not by keeping everything forever and hoping the question never comes.

Cross-border transfer and section 33

Programmes evaluating overseas platforms are often told that Hong Kong restricts cross-border transfers. The position is more particular than that: section 33, the provision governing transfers outside Hong Kong, has never been brought into force, and reform of it has been under discussion for years.

That is not permission to be careless. DPP4 still applies wherever the data sits, you remain responsible for a processor’s handling, and DPP1 means you should have told entrants where their data goes. Organisations bridging Hong Kong and the mainland face a second regime entirely. But the honest answer to “can we use an overseas platform” is usually yes, with conditions — not no.

This matters commercially, because in our audit of Hong Kong award portals, data-sovereignty caution was one of the five reasons programmes default to building their own systems. Some of that caution rests on a rule that is not currently in force.

A PDPO compliance self-check

  • Your entry form carries a PICS naming judges and any sponsors as recipients
  • Every field on the form is used by someone for something
  • Marketing consent is a separate, unticked opt-in, not bundled into entry terms
  • A written retention schedule exists per data category, with a deletion trigger
  • Judge access is revoked at announcement, and offline copies are accounted for
  • Your processors are contractually bound to equivalent security obligations
  • Your published privacy policy matches what your entry form actually does
  • You have decided how to handle a data access request from an unsuccessful entrant

Most programmes we have worked with clear four or five of these. The two that fail most often are the retention schedule and the marketing opt-in.


This is general information about how the PDPO applies to award operations, not legal advice, and it is not a substitute for advice on your specific programme. AwardScience is built with these obligations in mind — configurable retention, scoped judge access, and separated marketing consent. Book a live demo or see pricing.

Leave a Reply

Scroll to Top

Discover more from AwardScience | Data-Driven Award & Grant Management Software

Subscribe now to keep reading and get access to the full archive.

Continue reading