PCPD e-NEWSLETTER
ISSUE Aug 2026
|
|
|
|
|
PCPD e-NEWSLETTER
ISSUE Aug 2026
|
|
|
|
|
PCPD and HKIRC Sign MoU and Jointly Launch the “Data Privacy and Web Security Scan Programme” to Mitigate Risks of Personal Data Leaks
|
Privacy Commissioner Ms Ada CHUNG Lai-ling, SBS (left), and the Chief Executive Officer of the HKIRC, Ir Wilson WONG Ka-wai, MH (right), encouraged schools, NGOs and SMEs to participate in the “Data Privacy and Web Security Scan Programme”.
|
Privacy Commissioner Ms Ada CHUNG Lai-ling, SBS (left), and the Chief Executive Officer of the HKIRC, Ir Wilson WONG Ka-wai, MH (right), signed a MoU.
|
The PCPD and the Hong Kong International Data Privacy Academy (Academy) recently signed a Memorandum of Understanding (MoU) with the Hong Kong Internet Registration Corporation Limited (HKIRC) to establish a framework for collaboration and strengthen cooperation in areas covering the protection of personal data privacy, data security, cybersecurity and artificial intelligence (AI) governance, etc., with a view to further implementing the “AI+” initiative, and to advancing Hong Kong’s digital economy and information and technology development. As the first collaborative initiative following the signing of the MoU, the PCPD and the HKIRC launched the “Data Privacy and Web Security Scan Programme” (Programme) on 13 August. The Programme is free of charge and open to all schools, non-profit-making organisations (NGOs) and small-and-medium sized enterprises (SMEs) in Hong Kong. The Programme aims to help participating organisations proactively identify potential website security risks and personal data protection vulnerabilities through website security scanning services and professional consultancy support. It seeks to enhance the awareness of management and staff members to cybersecurity and privacy risks, thereby enabling them to strengthen their cybersecurity posture in an increasingly digitalised and AI-driven environment to safeguard digital assets and personal data privacy. The Programme is also one of the commemorative initiatives marking the 30th Anniversary of the establishment of the PCPD. Adopting non-intrusive scanning technology, the Programme can effectively identify website security vulnerabilities and potential personal data protection risks without disrupting normal website operations. The assessment can detect system configuration weaknesses and inappropriate security settings, as well as identify other vulnerabilities that may result in unauthorised leakage or inadvertent exposure of sensitive personal data. Upon completion of the assessment, participating organisations will receive a tailored evaluation report, coupled with consultancy support services that offer concrete recommendations for security enhancements and remediation to further strengthen their overall cyber resilience. Applications for the Programme are now open until 16 November (Monday). Interested schools, NGOs and SMEs may submit their applications through the designated application channel: https://forms.cloud.microsoft/r/UkitjQw6Tg For any questions relating to the Programme, please contact: cybersec@hkirc.hk
|
Privacy Commissioner’s Office (1) Follows up on Three Cases Involving Misuse of Employers’ Personal Data by Foreign Domestic Helpers for Loan Applications and (2) Publishes Guidance on “Protecting Personal Data Privacy in the Use of Agentic AI”
|
Privacy Commissioner Ms Ada CHUNG Lai-ling (right) and the Assistant Privacy Commissioner (Legal) Ms Fiona LAI Ho-yan (left) elaborated on three cases involving misuse of employers’ personal data by foreign domestic helpers (FDHs) for loan applications and the Guidance on “Protecting Personal Data Privacy in the Use of Agentic AI”.
|
On 25 August, the PCPD announced its follow-up actions on three complaint cases involving foreign domestic helpers (FDHs) who provided their employers’ personal data to financial institutions for loan applications without the employers’ knowledge or consent. In all three cases, the FDHs concerned contravened the relevant requirements of the Personal Data (Privacy) Ordinance (PDPO) by improperly using their employers’ personal data. Furthermore, the PCPD published the guidance on “Protecting Personal Data Privacy in the Use of Agentic AI” on 25 August.
1. Summary of the three cases All three complainants were employers of the FDHs concerned. The FDHs concerned applied for loans from financial institutions in the course of their employment. Subsequently, they defaulted on the repayments of their loans and were eventually dismissed by the complainants. In two of the cases, the complainants received WhatsApp messages and telephone calls from financial institutions regarding the FDHs’ outstanding debts. In addition to requesting the complainants to remind the FDHs to repay the loans, one financial institution further stated that debt collector would be sent to the complainant’s residence if repayments were not made by the specified deadline. In the third case, the complainant received, through the mailbox, overdue notices issued by two financial institutions to the FDH. The three FDHs concerned admitted that they had provided the complainants’ personal data to local or overseas financial institutions when applying for loans, with one FDH submitting loan applications to as many as four financial institutions. The employers’ personal data involved included the employers’ names, residential addresses and telephone numbers. Data Protection Principle (DPP) 3(1) of Schedule 1 to the PDPO stipulates that personal data shall not, without the prescribed consent of the data subject (namely, express consent voluntarily given by the data subject), be used (including disclosed or transferred) for a new purpose that is not related to the original purpose for which the data was collected. In the above cases, having considered the circumstances of each case and the information obtained, Privacy Commissioner Ms Ada CHUNG Lai-ling found that the FDHs concerned had contravened DPP 3(1) of the PDPO concerning the use (including disclosure) of personal data. The Privacy Commissioner had issued warning letters to the FDHs concerned and requested them to strictly comply with the requirements of the PDPO relating to the use of personal data in the future. The PCPD is seeking the consent of the complainants concerned to refer the cases to the relevant authorities. The PCPD points out that if FDHs are requested to provide the personal data of their employers or any other third parties during a loan application, FDHs should first ascertain whether the relevant information is necessary and not excessive. FDHs must obtain the employers’ voluntary and express prior consent if they intend to use the employers’ personal data for loan applications or for any purposes unrelated to employment affairs. FDHs should not provide employers’ personal data to financial institutions indiscriminately for the purpose of obtaining loans. The PCPD also takes the opportunity to remind employers of FDHs to:
- Clearly inform their FDHs that the employers’ personal data may only be used for purposes related to employment affairs and that FDHs should obtain the employers’ prior consent before using their personal data for any other purpose; and
- Exercise caution when handling documents submitted by FDHs for the employers’ signatures. Before signing any document, employers should not only ascertain from the FDHs the purpose of signing the document, but also carefully review its contents in order to safeguard personal data privacy and their own interests.
In addition, the PCPD has prepared a pamphlet specifically for FDHs in Chinese, English, Tagalog and Bahasa Indonesia, with a view to reminding FDHs to exercise caution before using their employers’ personal data, and to safeguard the personal data privacy of themselves and their employers.
Download the pamphlet titled “Protect Personal Data Privacy: Obtain Employers’ Consent Before You Use their Personal Data”:
https://www.pcpd.org.hk/english/resources_centre/publications/files/pcpd_obtain_empolyers_consent.pdf
2. Guidance on “Protecting Personal Data Privacy in the Use of Agentic AI”
With the increasing prevalence of the deployment of AI, the emergence of agentic AI has brought transformative changes while posing unprecedented challenges to the protection of personal data privacy. The PCPD published a guidance titled “Protecting Personal Data Privacy in the Use of Agentic AI” (Guidance) on 25 August, which aims to provide practical recommendations to organisations to assist them in harnessing the benefits of agentic AI while safeguarding personal data privacy and complying with the relevant requirements of the PDPO. The Guidance is supported by the Digital Policy Office (DPO) and the Hong Kong Applied Science and Technology Research Institute as supporting organisations.
To align with international standards, in preparing the guidance the PCPD made reference to the “Practical Guidance of Cybersecurity Standards – Security Guidelines for the Deployment and Use of AI Agents” published in July 2026 by the National Technical Committee 260 on Cybersecurity of Standardization Administration of China, along with guidances on the use of agentic AI published in other jurisdictions. The Guidance serves as a supplementary guidance to the “Artificial Intelligence: Model Personal Data Protection Framework” (Model Framework) published by the PCPD, which remains generally applicable to the use of agentic AI.
The Guidance explains the risks that agentic AI poses to personal data privacy, including extensive access, function creep and inaccuracy of data, and sets out nine recommendations for the safe and responsible use of agentic AI and ensuring compliance with the relevant requirements under the PDPO:
How to Address the Risks that Agentic AI Poses to Personal Data Privacy
- Avoid excessive or arbitrary collection of personal data for use by agentic AI: Adhere to the data minimisation principle, establish and implement clear rules on ringfencing the information and systems an agentic AI may access for a specific purpose;
- Be transparent about the use of agentic AI in processing personal data: Provide relevant information on the use of agentic AI to process personal data in the Personal Information Collection Statements and Privacy Policy Statements to enhance transparency;
- Ensure accuracy of personal data processed by agentic AI: Adopt approaches such as chain of thought, context specific fine-tuning and human review to reduce the risk of generating outputs which contain hallucinated or inaccurate personal data;
- Set appropriate retention periods: Prescribe maximum retention periods and implement measures to erase personal data contained in conversation histories, cache data or long-term memory timely;
- Ensure personal data is not used for a new purpose without consent: Delineate the purposes for which personal data will be collected and processed by agentic AI, and specify the circumstances under which human oversight is required;
- Safeguard the security of personal data in agentic AI systems: Use the latest official versions of agentic AI, adopt adequate measures to ensure system security and data security, install and use plugins or skills with caution, grant the minimum access rights necessary to complete the tasks at hand, adopt large language model guardrails, and establish mechanisms to enable traceability and auditability;
- Uphold data access and correction rights: Select agentic AI systems that adopt the principles of “privacy-by-design” and “privacy-by-default” to ensure that the relevant system supports the exercise of data access and data correction rights;
- Conduct continuous risk assessments: Test agentic AI for safety and reliability before using agentic AI, continuously assess the personal data privacy risks during its use and adopt measures that commensurate with the risks, adopt a “human-in-the-loop” approach for decisions likely to have a significant impact on individuals; and
- Assign clear responsibilities and provide training: Establish an internal governance structure with sufficient resources, expertise and decision-making authority, adopt contractual or other means to ensure compliance of data retention and security requirements when engaging external service providers, and provide adequate training to all relevant personnel
To facilitate the implementation of the recommendations, the Guidance also includes a Security Checklist in the Annex, which sets out the practical steps that users may take to safeguard personal data privacy throughout the stages of evaluation, preparation, deployment, use and cessation of use. Download the guidance titled “Protecting Personal Data Privacy in the Use of Agentic AI”: https://www.pcpd.org.hk/english/resources_centre/publications/files/pcpd_use_of_agentic_ai.pdf
|
|
|
|
Personal Data Protection in Practice: Practical Tips for SMEs
|
|
|
PRIVACY COMMISSIONER’S FINDINGS
|
PRIVACY COMMISSIONER’S FINDINGS
|
An Insurance Company Sent Customer’s Personal Data via Unencrypted Email
|
|
|
Digital Identity Protection: Essential Security Tips for Everyday Users
|
|
|
|
A 29-year-old Male Arrested for Suspected Doxxing of a Competitor
|
PCPD Publishes Investigation Findings on the Data Breach Incident of the Online Learning Management Platform Canvas
|
A 37-year-old Male Arrested for Suspected Doxxing of a Former Restaurant Owner and an Agent Arising from Monetary Disputes
|
PCPD Urges Caution against Suspected Fraudulent E-Visa Websites
|
HONG KONG INTERNATIONAL DATA PRIVACY ACADEMY
|
Free Online Seminars: Introduction to the PDPO
|
Arrange an In-house Seminar for Your Organisation
|
APPLICATION / RENEWAL OF DPOC MEMBERSHIP
|
PCPD Supports the Hong Kong Institute of Bankers (HKIB) Annual Banking Conference 2026
|
PCPD Supports the HKIoD’s Directors’ Symposium 2026
|
PCPD Supports the
Hong Kong Volunteer Award 2026
|
|
|
Protecting Children Privacy – Privacy Commissioner Speaks at “Building Digital Safety Together: A Forum to Empower Parents”
|
Reaching Out to Legal Professionals – Privacy Commissioner Attends the CAAO 45th Anniversary Dinner
|
Reaching Out to Property Management Sector – Privacy Commissioner Attends the “Property Management Summit”
|
Nurturing Youngsters Discharging Social Responsibility – PCPD Continues to Fully Support the “Strive and Rise Programme” and Organise Summer Internship Programme
|
Promoting Data Privacy Security – Privacy Commissioner Interviewed by Media on the “Data Privacy and Web Security Scan Programme”
|
Reaching Out to the Community – Privacy Commissioner Interviewed by Commercial Radio’s “Saturday Forum” to Share the PCPD’s Areas of Work
|
Reaching Out to the Community – Privacy Commissioner Interviewed by Media to Urge Caution against Fraudulent E-Visa Websites
|
Promoting Privacy Protection in AI – Privacy Commissioner Publishes an Article in Bauhinia Magazine
|
Promoting Data Privacy Security – Assistant Privacy Commissioner Interviewed by Media on the “Data Privacy and Web Security Scan Programme”
|
Reaching Out to the Community – Assistant Privacy Commissioner Interviewed by Media on Suspected Fraudulent E-Visa Websites
|
Serving the Community – Storytelling Activity of PCPD Volunteer Team
|
Reaching Out to University – Hong Kong International Data Privacy Academy Shares Fraud Prevention Tips with Students of the Hong Kong Polytechnic University
|
|
|
Highlights of the “Draft Regulations on Personal Information Protection of Large-Scale Personal Information Processors” 《大型個人信息處理者個人信息保護規定(徵求意見稿)》 的重點
|
EU: European Telecommunication Standards Institute (ETSI) Initiates Approval for 17 Draft Standards under Cyber Resilience Act
|
EU: European Data Protection Board (EDPB) Sends Letter to Commission regarding US Supreme Court Judgment in Trump v. Slaughter
|
EU: Commission Begins Enforcing EU AI Act Rules and Transparency Requirements
|
EU: European Commission Preliminary Finds TikTok in Breach of Digital Services Act (DSA) for Failing to Ensure Safe Accounts for Minors
|
|
|
|
The “Data Privacy and Web Security Scan Programme” is now open to all schools, NGOs and SMEs in Hong Kong, free of charge.
|
|
|
|
Personal Data Protection in Practice: Practical Tips for SMEs
|
Whether it is an online shop keeping customers’ delivery details, a tutorial centre managing students’ enrolment forms, or a recruitment agency handling job applicants’ resumes, SMEs, like large-scale organisations, process personal data every day.
While SMEs may not have the same level of resources, dedicated compliance teams or sophisticated security systems as large corporations, protecting personal data is no less important for them. By fostering a privacy-conscious mindset and embedding good data handling practices into day-to-day operations, SMEs can also effectively safeguard personal data and reduce risks of data breach incidents, thereby maintaining the trust of customers, employees and business partners.
Here are six practical tips to help SMEs strengthen personal data protection:
-
Collect only necessary personal data: Before collecting personal data, SMEs should consider whether each item is necessary for providing the relevant product or service, and avoid collecting information that is excessive for the stated purpose;
-
Be clear about how personal data will be used: SMEs should provide a clear and easy-to-understand Personal Information Collection Statement to explain why personal data is collected, how it will be used, and whether it may be transferred to third parties;
-
Implement in-house data security policies: Policies should be stipulated to protect personal data stored in all formats, such as locking filing cabinets, restricting access to filing areas in office, strong password control and encryption for electronic files and execute limited access to personal data on a “need-to-know” basis;
-
Conduct regular data inventory checks: SMEs should set out a data retention schedule and conduct regular reviews of personal data to determine whether the collected data is still required;
-
Engage data processors responsibly: SMEs outsourcing personal data processing should disclose only the minimum personal data necessary and adopt appropriate contractual clauses to protect the personal data entrusted to data processors; and
-
Develop data breach handling procedures: SMEs should also develop data breach handling procedures in advance to promptly contain an incident, assess the potential impact, and take appropriate follow-up actions to eliminate the possible loss and damage.
For further guidance, please refer to the “From Principles to Practice – SME Personal Data Protection Toolkit”.
In addition, SMEs seeking to strengthen data security and AI governance may also consider joining the free “Data Privacy and Web Security Scan Programme”, jointly launched by the PCPD and the HKIRC, to identify potential website security risks and personal data protection vulnerabilities.
|
|
|
|
PRIVACY COMMISSIONER’S FINDINGS
|
An Insurance Company Sent Customer’s Personal Data via Unencrypted Email
The Complaint
The complainant took out a pet insurance policy provided by an insurance company (“the Insurance Company”). When submitting a claim through the Insurance Company’s online customer portal, the complainant uploaded an image of his bank card for the purpose of receiving reimbursement. Subsequently, the complainant received an unencrypted email from a representative of the Insurance Company in which his full name and complete bank account number were shown in plain text in the content of the email. The complainant considered that the transmission of sensitive data via email is insecure, particularly as the staff of the Insurance Company did not encrypt his bank account information before sending the email. As a result, the complainant lodged a complaint with the PCPD alleging matters including that the Insurance Company had not taken adequate security measures to protect his personal data.
Outcome
According to the Insurance Company, its established workflow required employees to take sensible precautions to ensure the security of data. The Insurance Company admitted that the case stemmed from the staff’s failure to comply with its relevant internal guidelines resulting in the sensitive personal data in the email not being masked.
After the PCPD’s intervention, the Insurance Company implemented several remedial measures, including providing training to employees on personal data privacy, deploying “the Personal Identifiable Information (PII)” filter in its email system to intercept messages containing sensitive data, and automatically adding a reminder message to outgoing emails sent to external parties to prevent similar incidents from recurring. The PCPD also issued a warning letter to the Insurance Company in response to the incident.
Lessons Learnt
This case sheds light on the potential threat of human errors to personal data security. The Insurance Company acknowledged that while there were established internal procedures in place, oversight in their execution by staff could still lead to customer data leakage. As insurers handle a significant amount of sensitive information during claims processing, constant vigilance is essential. Given the risk of email interception, eavesdropping, or wrong transmission, it is crucial to take prevention measures such as masking or encrypting any sensitive personal information for emails involving bank accounts and identity card numbers. Having guidelines in place alone has proven to be insufficient to completely eliminate the risk of leakage. Therefore, in addition to providing continuous training to frontline staff to ensure that they uphold a prudent attitude in handling customers’ personal data, organisations should also actively introduce technological support measures. Appropriately applying automated features, such as the PII filter in this case, to compensate for human oversight is the way to establish multiple layers of defence mechanisms to reduce the risk of data leakage and build a robust information security network in the digital age.
|
Digital Identity Protection: Essential Security Tips for Everyday Users
|
From accessing online banking and shopping platforms to communicating through instant-messaging applications, individuals rely on a wide range of online accounts every day. The identifiers associated with these services, such as email addresses, mobile phone numbers, and account login credentials, form part of a person’s digital identity, which is used to authenticate the user when accessing online services.
If a digital identity is stolen or an account is hijacked, with the access to vast amount of personal data, fraudsters may impersonate the account holder, blast out phishing messages to the account holder’s family members or friends and subsequently mislead them to conduct money transfer. Victims of these scams would not only suffer from unauthorised disclosure of personal data, but also financial loss and even reputational damage.
To minimise the risk of digital identity theft, please consider the following practical measures:
- Enable two-factor or multi-factor authentication: Use two-factor or multi-factor authentication to strengthen the security of the account;
- Use different and strong passwords: Set different and strong passwords with more complex combination for different online services;
- Stay alert to phishing attacks: Think twice before disclosing personal and sensitive information to guard against phishing attacks;
- Secure accounts on non-personal devices: Do not allow the browser to remember your password if non-personal devices are used. Log out the online service account immediately after use;
- Delete unused accounts: Delete accounts no longer in use to avoid any undetected access due to lack of account management; and
- Regularly monitor account activities: Pay close attention to notifications of suspicious account activities or transactions issued by service providers. If in doubt, promptly seek assistance from the service providers.
In addition, individuals seeking to enhance awareness against online scams are welcome to join the Public Seminar on “Preventing Online Scams and Staying Safe on Messaging App and Social Media” on 15 September organised by the PCPD to learn about latest trends in scams and the corresponding security measures.
|
|
|
|
Protecting Children Privacy – Privacy Commissioner Speaks at “Building Digital Safety Together: A Forum to Empower Parents”
|
Privacy Commissioner Ms Ada CHUNG Lai-ling attended the “Building Digital Safety Together: A Forum to Empower Parents” organised by Meta Hong Kong on 27 August as an officiating guest and delivered the opening address. The forum brought together policymakers, leaders from the education sector, social welfare professionals, and child safety experts to share actionable strategies for protecting the online safety of children and young people. In her address, the Privacy Commissioner pointed out that safeguarding the safety and well-being of children and youngsters in the digital world is a shared responsibility amongst parents, schools, technology platforms and the wider community. She stated that the PCPD has been committed to safeguarding the online privacy of children and youngsters and has undertaken a wide range of initiatives in this regard. The initiatives included the publication of guidance materials such as “Safeguarding Children’s Online Privacy – Practical Tips for Parents and Teachers” and “Abuse of AI Deepfakes: Toolkit for Schools and Parents” (Toolkit), and participation in a global sweep, together with 26 privacy enforcement authorities around the world, to examine almost 900 websites and mobile applications used by children to evaluate their practices for protecting children’s privacy.
|
Reaching Out to Legal Professionals – Privacy Commissioner Attends the CAAO 45th Anniversary Dinner
|
Privacy Commissioner Ms Ada CHUNG Lai-ling attended the gala dinner organised by the Association of China-Appointed Attesting Officers on 27 August to celebrate the 45th anniversary of the establishment of the China-Appointed Attesting Officer (CAAO) system and mingled with members of the legal profession. Established by the National Ministry of Justice in 1981, the CAAO system appoints Hong Kong lawyers to be CAAOs for preparing attested documents for Hong Kong residents to handle legal matters in the Chinese Mainland. The CAAO system is an innovative system designed to address the use of attested documents between Hong Kong and the Chinese Mainland, which operate under different legal systems.
|
Reaching Out to Property Management Sector – Privacy Commissioner Attends the “Property Management Summit”
|
Privacy Commissioner Ms Ada CHUNG Lai-ling attended the “Property Management Summit” (Summit) co-organised by the Home Affairs Department and the Property Management Services Authority (PMSA) on 19 August and engaged with stakeholders of the property management sector.
Centred around the theme “A Decade of Professional Excellence, Advancing Together”, the Summit focused on three core topics: professional invigilation, innovative smart management and emergency response. Through interactive exchanges, policy insights, and practical case sharing, the Summit aimed to deepen mutual understanding and strengthen collaboration among stakeholders, including property management practitioners, government departments and property owners.
|
Nurturing Youngsters Discharging Social Responsibility – PCPD Continues to Fully Support the “Strive and Rise Programme” and Organise Summer Internship Programme
|
Following its efforts in 2024 and 2025 in organising educational talks for participants of the Second and Third Cohort of the “Strive and Rise Programme” (Programme), the Academy organised another educational talk earlier for participants of the Fourth Cohort, and explained to around 50 participants the roles and responsibilities of the PCPD, as well as its work in handling complaints, combatting doxxing offences, and promoting the protection of personal data privacy. Participants were also reminded to say “No” to cyberbullying and doxxing. In addition, a guided tour of the PCPD’s office was arranged for the participants to gain first-hand knowledge of the work of PCPD. The PCPD is one of the supporting organisations of the Programme. Led by the Government and through collaboration among the Government, the business sector and the community, the Programme aims to harness the collective strength of society to support secondary school students from underprivileged families by broadening their horizons, strengthening their self-confidence and fostering a positive outlook on life. Incidentally, the PCPD organises a Summer Internship Programme to provide university students with internship opportunities, enabling them to gain practical work experience and build a strong foundation for their future career development. This year, two interns from The University of Hong Kong and The Chinese University of Hong Kong participated in the Internship Programme.
|
Promoting Data Privacy Security – Privacy Commissioner Interviewed by Media on the “Data Privacy and Web Security Scan Programme”
|
Privacy Commissioner Ms Ada CHUNG Lai-ling was interviewed by Now News’ “News Magazine” on 14 August to introduce the Programme jointly launched by the PCPD and the HKIRC. During the interview, she explained the mode of operation and support services of the Programme, and encouraged schools, non-profit-making organisations and SMEs to make good use of the free website security scanning and professional advisory services provided by the Programme to identify and address potential website security risks at an early stage and strengthen the protection of personal data. The Privacy Commissioner explained that the Programme adopts non-intrusive website security scanning technology. The scanning process simulates the browsing behaviour of ordinary internet users. No attack techniques are deployed to conduct internal inspections. As a result, the scanning process will not cause any damage to or affect the normal operation of the websites. Seminars will be organised by the PCPD at a later stage for the participants of the Programme to share common website security and personal data protection issues, with a view to further strengthening organisations’ cyber resilience. Click here to view the first part of the interview by Now News’ “News Magazine” (Chinese only). Click here to view the second part of the interview by Now News’ “News Magazine” (Chinese only).
|
Reaching Out to the Community – Privacy Commissioner Interviewed by Commercial Radio’s “Saturday Forum” to Share the PCPD’s Areas of Work
|
Privacy Commissioner Ms Ada CHUNG Lai-ling was interviewed by Commercial Radio’s “Saturday Forum” on 15 August, during which she outlined the key areas of work of the PCPD in the first half of this year. During the interview, the Privacy Commissioner noted the PCPD received 2,990 complaints in the first half of this year, representing a 62% increase year-on-year. The increase was mainly attributable to the rapid development of AI and the internet, which has enabled the large-scale collection, processing and use of data, leading to an increase in disputes arising from online activities. Among the complaints received, cases relating to information and communications technology accounted for the largest proportion. She reminded members of the public that personal data has become a valuable and tradeable commodity, urging them to think twice before providing their personal data. In addition, the PCPD received 148 data breach notifications in the first half of the year, representing a 53% increase year-on-year. The Privacy Commissioner pointed out that some organisations mistakenly believed that they might adopt a lax attitude towards monitoring and managing their information systems by outsourcing the management of them to outside contractors. However, under the PDPO, organisations remain primarily responsible for protecting personal data, including continuously monitoring contractors’ performance, conducting security audits and overseeing system updates. She stressed that responsibility for data protection cannot be outsourced. The Privacy Commissioner also noted that 144 doxxing-related complaints were received in the first half of the year, a substantial decrease of nearly 60% from the thousands of cases recorded when the anti-doxxing provisions first came into effect in 2021. The PCPD’s online patrols identified only three such cases during the same period, reflecting a drop of 99% and that malicious doxxing activities are under control.
|
Reaching Out to the Community – Privacy Commissioner Interviewed by Media to Urge Caution against Fraudulent E-Visa Websites
|
Privacy Commissioner Ms Ada CHUNG Lai-ling was interviewed by CRHK Radio 1’s “On a Clear Day” on 5 August, and RTHK Radio 1’s “HK2000” and Now News’ “News Magazine” on 6 August to explain the enquiries and complaints cases received by the PCPD relating to suspected fraudulent electronic visa (e-visa) websites. She also shared fraud prevention tips and highlighted the PCPD’s ongoing efforts to combat fraud.
During the interview, the Privacy Commissioner noted a recent upward trend in the number of enquiries and complaints relating to suspected fraudulent e-visa websites, involving e-visa or entry permission applications for countries including the United States, Thailand and the United Kingdom. In the cases, victims typically realised that they had been deceived after suspected fake e-visa websites became unresponsive upon submission of their personal data and application fees. She also observed that scammers had been leveraging AI technology to create fraudulent websites, making it more difficult to distinguish genuine websites from fraudulent ones.
The Privacy Commissioner pointed out that scammers may exploit advertising functions on search platforms to place fraudulent websites at the top of search results. She advised members of the public who wish to apply for e-visas to carefully check the full website address and not to rely solely on search engine results. Instead, they should access e-visa application platforms through links provided on the websites of Consulates-General or representative offices of the relevant countries or regions in Hong Kong. Information on Consulates-General is available on the website of the Protocol Division of the Government Secretariat.
In addition, the Privacy Commissioner said that to raise the awareness of university students on fraud prevention, the PCPD has, since last year, conducted 20 anti-scam talks for university students, attracting more than 9,500 attendees. The PCPD also produced an anti-fraud video in Cantonese, Putonghua and English, which has been disseminated to tertiary institutions for on-campus screening.
Click here to listen to the interview by RTHK Radio 1’s “HK2000” (Chinese only). Click here to view the first part of the interview by Now News’ “News Magazine” (Chinese only). Click here to view the second part of the interview by Now News’ “News Magazine” (Chinese only).
|
Promoting Privacy Protection in AI – Privacy Commissioner Publishes an Article in Bauhinia Magazine
|
Privacy Commissioner Ms Ada CHUNG Lai-ling published an article titled “Strengthening Hong Kong’s Privacy Safeguards and Promoting Innovation in AI Governance” in Bauhinia Magazine.
In the article, the Privacy Commissioner pointed out that, as AI technologies continue to evolve, advancements in deepfake technology and AI agents have given rise to increasingly complex and diverse privacy risks. She noted that while the Country is actively advancing the “AI Plus” Initiative, it places equal emphasis on AI security governance. The public consultation document on Hong Kong’s Five-Year Plan also echoes the national development direction of upholding a holistic approach to development and security as set out in the Country’s 15th Five-Year Plan.
In the article, the Privacy Commissioner also outlined how the PCPD actively embraces innovation by enhancing the protection of personal data privacy and advancing the secure development and adoption of AI, including publishing several award-winning guidance materials, such as “Model Framework”, “Checklist on Guidelines for the Use of Generative AI by Employees” and the “Toolkit”, conducting compliance checks, and, in collaboration with the DPO, launching the Safeguarding Personal Data AI Sandbox for primary and secondary schools in Hong Kong in July this year.
In addition, the Privacy Commissioner introduced the Academy, which was established in June this year, as well as the PCPD’s work in promoting Chinese rules and Chinese standards to “go global”, with a view to supporting Hong Kong in developing into an international hub for high-calibre talents and enhancing the voice and influence of the Country and Hong Kong in the field of global privacy protection.
Please click here to read the article (Chinese only).
|
Promoting Data Privacy Security – Assistant Privacy Commissioner Interviewed by Media on the “Data Privacy and Web Security Scan Programme”
|
The Assistant Privacy Commissioner for Personal Data (Corporate Communications and Operations) Ms Joyce LAI was interviewed by RTHK Radio 3’s “Backchat” on 19 August to introduce the MoU recently signed between the PCPD, the Academy and the HKIRC. She also highlighted the Programme jointly launched by the PCPD and the HKIRC.
During the interview, the Assistant Privacy Commissioner explained that the MoU establishes a framework for collaboration and enhances cooperation among the three parties in areas including the protection of personal data privacy, data security, cybersecurity and AI governance. The Programme offers free website security scanning services and professional consultancy support to schools, non-profit-making organisations and SMEs in Hong Kong. The Programme aims to assist organisations in proactively identifying website security risks and personal data protection vulnerabilities, thereby strengthening their cybersecurity capabilities and enhancing their overall cyber resilience.
Click here to listen to the interview by RTHK Radio 3’s “Backchat”.
|
Reaching Out to the Community – Assistant Privacy Commissioner Interviewed by Media on Suspected Fraudulent E-Visa Websites
|
The Assistant Privacy Commissioner for Personal Data (Corporate Communications and Operations) Ms Joyce LAI was interviewed by RTHK Radio 3’s “Backchat” on 7 August to explain the enquiries and complaint cases received by the PCPD earlier concerning suspected fraudulent e-visa websites and to share fraud prevention tips with members of the public. During the interview, the Assistant Privacy Commissioner noted that the summer holiday period is a peak season for outbound travel, when suspected fraudulent e-visa websites have appeared increasingly. The PCPD received 16 enquiries or complaint cases over the past three months, all involving the provision of personal data, including names, gender, nationalities, passport numbers and dates of birth, as well as payment of relevant application fees to suspected fraudulent e-visa websites. She highlighted several common features of fraudulent e-visa websites, including website addresses (URLs) with spelling mistakes, extra letters or numbers; prominent placement in “Sponsored” or “Ad” sections at the top of search engine results pages to attract users; the absence of legitimate contact information; and the imposition of hidden surcharges or excessively high fees. She reminded members of the public to stay vigilant when applying for e-visas online, to carefully verify the website and avoid relying solely on search engine results. Click here to listen to the interview by RTHK Radio 3’s “Backchat”.
|
Serving the Community – Storytelling Activity of PCPD Volunteer Team
|
The Volunteer Team of the PCPD organised a storytelling activity for approximately 70 primary school students at the Methodist Centre on 21 August, and shared the contents of a Chinese storybook titled “Adventure in the AI Labyrinth” (《AI迷城歷險記》) (Storybook) published by the PCPD, with a view to helping primary school students use AI and social media responsibly and say no to “doxxing”.
Established in 2022, the PCPD Volunteer Team has made multiple visits to elderly centres to raise awareness of scam prevention among elderly. The Team has also helped prepare meal boxes for people in need. During the COVID-19 pandemic, the Team donated anti-epidemic supplies to various social welfare organisations.
|
Reaching Out to University – Hong Kong International Data Privacy Academy Shares Fraud Prevention Tips with Students of the Hong Kong Polytechnic University
|
The Academy shared anti-scam messages at the Orientation Information Session for postgraduate students of the Hong Kong Polytechnic University (Poly U) earlier (on 18 August), which was attended by about 950 students.
Under the theme of “Beware of Scam – Protect Your Personal Data”, Manager (Corporate Communications) of the PCPD Mr Dicky LI introduced emerging scam trends in the era of AI to students and provided practical tips on fraud prevention and personal data protection.
In addition, the Academy set up an exhibition booth on the campus during the orientation period to disseminate anti-scam and personal data protection information to all students.
|
|
|
|
A 29-year-old Male Arrested for Suspected Doxxing of a Competitor
|
The PCPD arrested a Chinese male aged 29 in Kowloon on 27 August. The arrested person was suspected to have disclosed the personal data of the data subject without his consent, in contravention of section 64(3A) of the PDPO. The PCPD’s investigation revealed that the arrested person has been targeting the victim ever since they competed in the same boxing tournament in early 2025. In March 2025 and August 2026, messages were posted on personal accounts across two social media platforms on two occasions, disclosing the personal data of the victim alongside some negative comments against him. The personal data disclosed included the victim’s English name, Chinese alias, name of his social media platform account, name of his current company’s social media platform account and his photo. The PCPD reminds members of the public that they should not dox others because of personal disputes. Doxxing is a serious offence and the offender is liable on conviction to a fine up to HK$1,000,000 and imprisonment for five years. Relevant Provisions under the PDPO Pursuant to section 64(3A) of the PDPO, a person commits an offence if the person discloses any personal data of a data subject without the relevant consent of the data subject —
- With an intent to cause any specified harm to the data subject or any family member of the data subject; or
- Being reckless as to whether any specified harm would be, or would likely be, caused to the data subject or any family member of the data subject.
A person who commits an offence under section 64(3A) is liable on conviction to a fine of HK$100,000 and imprisonment for two years. Pursuant to section 64(3C) of the PDPO, a person commits an offence if —
a. The person discloses any personal data of a data subject without the relevant consent of the data subject —
- With an intent to cause any specified harm to the data subject or any family member of the data subject; or
- Being reckless as to whether any specified harm would be, or would likely be, caused to the data subject or any family member of the data subject; and
b. The disclosure causes any specified harm to the data subject or any family member of the data subject.
A person who commits an offence under section 64(3C) is liable on conviction on indictment to a fine of HK$1,000,000 and imprisonment for five years. According to section 64(6) of the PDPO, specified harm in relation to a person means —
- Harassment, molestation, pestering, threat or intimidation to the person;
- Bodily harm or psychological harm to the person;
- Harm causing the person reasonably to be concerned for the person’s safety or well-being; or
- Damage to the property of the person.
|
PCPD Publishes Investigation Findings on the Data Breach Incident of the Online Learning Management Platform Canvas
|
Upon completion of its investigations into the data breach incident of Canvas, an online learning management platform, the PCPD published the investigation findings on 20 August. Background The investigations arose from data breach notifications submitted by seven educational institutions to the PCPD between 6 May and 11 May 2026, reporting that they might have been affected by a cyberattack involving the third-party online learning management platform, Canvas (Incident). The seven educational institutions included City University of Hong Kong (CityU), The Hong Kong Academy for Performing Arts (HKAPA), Hong Kong Institute of Construction (HKIC), The Hong Kong University of Science and Technology (HKUST), Hong Kong Art School (HKAS), PolyU and Hong Kong Education City Limited (HKEdCity). Canvas is a web-based learning management platform operated by Instructure, Inc. (Instructure), which assists educational institutions, educators and students to access and manage online course materials, and supports skill development and learning exchange. According to the information published by Instructure[1], Instructure discovered that a hacking group, ShinyHunters, carried out unauthorised activities in Canvas through a “Free-For-Teacher” account (Account) and exfiltrated user data on 29 April 2026. Upon detecting the unauthorised activities, Instructure immediately blocked the unauthorised access and engaged a cybersecurity firm, CrowdStrike (Network Security Company), to initiate an independent investigation. Subsequently on 7 May 2026, the threat actor exploited another security vulnerability to re-access Canvas, and defaced the login pages of some educational institutions to post a ransom note. According to Instructure, the threat actor submitted a support request containing malicious code through the Account and exploited a cross-site scripting (XSS) vulnerability in the platform to obtain an authorisation token and gain elevated access within Canvas to carry out unauthorised activities and exfiltrate personal data. In the wake of the Incident, Instructure had fixed the relevant security vulnerabilities, strengthened security measures, and discontinued the “Free-For-Teacher” service. Following the review carried out by the Network Security Company, Instructure resumed Canvas’s services on 9 May 2026. On 11 May 2026, Instructure announced that it had reached an agreement with the threat actor and retrieved the stolen data. Relevant Requirements of the PDPO According to DPP 4(1) of Schedule 1 to the PDPO, all practicable steps shall be taken by a data user to ensure that any personal data held by the data user is protected against unauthorised or accidental access, processing, erasure, loss or use. In addition, DPP 4(2) provides that if a data user engages a data processor, whether within or outside Hong Kong, to process personal data on the data user’s behalf, the data user must adopt contractual or other means to prevent unauthorised or accidental access, processing, erasure, loss or use of the data transferred to the data processor for processing. Investigation Findings Having considered the circumstances of the Incident and the information obtained during the investigations, the PCPD has the following observations regarding the Incident:
- Among the data breach notifications submitted by the seven educational institutions, only four educational institutions, namely CityU, HKAPA, HKIC and HKUST (Affected Institutions), were affected by the Incident. The Affected Institutions have deployed Canvas for academic purposes, with the earliest adoption in 2014. Up to the present, there is no information suggesting that the remaining educational institutions, namely HKAS, PolyU and HKEdCity, were affected by the Incident.
- According to the updated information provided by the Affected Institutions, the data confirmed to have been affected by the Incident includes:
|
3. The Affected Institutions confirmed that their internal systems (i.e. systems other than Canvas) have not been affected by the Incident. They have also implemented security measures prior to the Incident to ensure that the personal data held by them is protected. These measures included:
- Pre-assessments: Prior to deploying Canvas as their online learning management platform, the Affected Institutions carried out assessments and reviews of the security measures adopted by Canvas to safeguard personal data security, such as evaluating whether the relevant security measures complied with internationally recognised security standards;
- Contractual Means: The Affected Institutions have entered into contractual arrangements requiring the implementation of appropriate organisational and technical measures to ensure that the personal data transferred to Canvas is protected against unauthorised or accidental access, processing, erasure, loss or use. The contractual terms also set out requirements relating to incident response, data confidentiality and compliance obligations, etc.; and
- Continuous Monitoring: The Affected Institutions have already established monitoring mechanisms, including reviews of the third-party security assessment reports to ensure that the security measures implemented on Canvas meet the contractual requirements and internationally recognised security standards.
4. Following the Incident, the Affected Institutions maintained ongoing communication with Instructure to obtain the latest updates of the Incident. They also implemented measures to enhance data security, such as reviewing Canvas accounts’ access rights and log records, enabling multi-factor authentication for Canvas accounts, and resetting login passwords for all Canvas accounts with administrative privileges, etc.
In sum, the data breach incident of the four educational institutions, namely, CityU, HKAPA, HKIC and HKUST, stemmed from vulnerabilities relating to a third-party platform, and the Incident did not affect the internal systems of the Affected Institutions. Investigations revealed that the Affected Institutions had conducted pre-assessments prior to deploying Canvas, adopted contractual means and established monitoring mechanisms to safeguard the personal data transferred to Canvas. In view of the above, Privacy Commissioner Ms Ada CHUNG Lai-ling considered that there is no evidence to suggest that the four educational institutions had failed to take all practicable steps to safeguard the personal data in their possession while using Canvas, and therefore there was no contravention of the PDPO. Notwithstanding the above, the PCPD has recommended the educational institutions involved in the Incident to reassess the risks of data breaches, strengthen monitoring of the security measures implemented by third-party platforms, review and minimise the amount of personal data stored on such platforms, enable multi-factor authentication for accounts and define clear access rights and data retention periods, etc., to ensure data security. The Privacy Commissioner would like to take this opportunity to remind organisations which hold large volumes of personal data to adopt the following organisational and technical measures when engaging data processors (including third-party platforms) to process personal data (including the processing of personal data using AI models) to protect the personal data transferred to data processors:
- Conduct due diligence before engaging data processors: Review the data processors’ backgrounds and evaluate the information security measures implemented by them (e.g. data encryption, access control mechanisms, preventive and detective measures, etc.) to ensure that only competent and reliable data processors are engaged;
- Use of on-premises servers: Where practicable, organisations should prioritise the use of on-premises servers under their direct control and management for processing and storing large amounts of personal data;
- Regulate data processors through contractual means: Enter into data processing contracts that stipulate the security measures to be adopted by the data processors, the consequences for violation of the contracts, and the data user’s rights to review how the data processors process and store personal data;
- Assess the risks of data breaches and establish an ongoing monitoring mechanism: Conduct periodic assessments on the security measures implemented by the data processors and regular reviews of access rights and the system logs of third-party platforms containing personal data so as to ensure that they have fulfilled their contractual obligations and safeguarded data security;
- Develop incident reporting mechanisms: Establish clear incident response plans and require data processors to provide immediate notification following an incident;
- Transfer personal data on a “need-to-know” basis: Conduct assessments to ensure that only the necessary personal data is transferred to data processors. Organisations should also establish data retention policies; and
- Enable security features where appropriate: For example, enable multi-factor authentication provided by third-party platforms to further enhance account security.
The PCPD calls on potentially affected persons to be vigilant of possible theft of their personal data and take the following measures to protect personal data privacy:
- Consider changing the passwords of online accounts and enable multi-factor authentication feature (if available);
- Stay vigilant when they receive any suspicious calls, text messages or emails from unknown sources. Do not arbitrarily open attachments, links or disclose personal data readily;
- Be vigilant against phishing or other possible scams;
- Beware of any unusual logins of personal emails or accounts; and
- Potentially affected persons may make enquiries with the relevant organisation or the PCPD (telephone: 2827 2827 or email: communications@pcpd.org.hk).
Any other organisations notified by Instructure that they have been affected by the Incident may contact Instructure or the PCPD (telephone: 2827 2827 or email: communications@pcpd.org.hk) for enquiries, and the PCPD will provide assistance, as appropriate, to help organisations strengthen their information security.
|
A 37-year-old Male Arrested for Suspected Doxxing of a Former Restaurant Owner and an Agent Arising from Monetary Disputes
|
The PCPD arrested a Chinese male aged 37 in the New Territories on 11 August. The arrested person was suspected to have disclosed the personal data of two data subjects without their consent, in contravention of section 64(3A) of the PDPO. The PCPD’s investigation revealed that in March 2025 the arrested person, who engaged in the wholesale food business, became acquainted with the male victim, who was operating a restaurant (Restaurant) at that time, through the female victim’s consultancy company. The arrested person subsequently supplied frozen meat to the Restaurant between March and May of the same year. A monetary dispute later arose between the arrested person and the male victim following the default in payment by the Restaurant and because the parties were unable to reach an agreement regarding repayment. The Restaurant ultimately closed down in late May 2025. In late May 2026, a message was posted in a personal account on a social media platform, together with photos of the male victim and his family members, a screencap of the registration record of his former company, alongside negative comments accusing the male victim of failing to repay a debt and calling on netizens to locate him. The personal data disclosed included the male victim’s English name, the names of the schools he had attended, his vehicle registration mark, his photos, as well as the name and registered address of his former company. One day later, another message was posted on the same social media platform using the same personal account, together with negative comments accusing the female victim of failing to repay a debt. The female victim’s personal data, including her English alias, phone number and the name of her consultancy company, was also disclosed. The PCPD reminds members of the public that they should not dox others because of monetary disputes. Doxxing is not a means to resolve disputes as it would only escalate conflicts. Moreover, doxxing is a serious offence and the offender is liable on conviction to a fine up to HK$1,000,000 and imprisonment for five years.
|
PCPD Urges Caution against Suspected Fraudulent E-Visa Websites
|
The summer holiday season is a peak period for outbound travel, and suspected fraudulent e-visa websites have emerged from time to time. The PCPD received 16 enquiries or complaints cases over the past three months, involving the provision of personal data and payment of application fees to suspected fraudulent e-visa websites. The PCPD urges members of the public to remain vigilant and verify the authenticity of e-visa websites before applying for e-visas and providing any personal data, so as to safeguard their personal data privacy. The complaints and enquiries received by the PCPD reveal that, victims mistakenly trusted the search results when searching for websites to apply for visas of destinations, electronic travel authorisations or arrival cards. It was only after they had submitted their personal data, including names, gender, nationalities, passport numbers and dates of birth, and paid application fees and related surcharges that they realised the websites concerned might be fraudulent. The monetary losses ranged from over HK$300 to over HK$1,700 in individual cases. The PCPD reminds the public to take note of the following when applying for e-visas online to safeguard their personal data privacy:
- Stay alert and carefully verify the full URL: Fraudulent websites may use URLs that closely resemble those of official websites, but the URLs often contain spelling mistakes, extra letters or numbers, or other irregularities. Members of the public should carefully verify the URL to ensure that they are accessing the correct websites. If in doubt, they may consider making enquiries with the relevant travel agency or Consulate-General in Hong Kong;
- Do not rely solely on search engine results: Search engine results may lead to fraudulent websites. Applicants should access e-visa application platforms through links provided on the websites of Consulates-General or representative offices of the relevant countries or regions in Hong Kong. For enquiries on the visa requirements, they should check with the relevant travel agency, Consulates-General or representative offices. Information on Consulates-General is available on the website of the Protocol Division Government Secretariat: https://www.protocol.gov.hk/en/posts_bodies.html; and
- Pay attention to fraud prevention information: Pay attention to fraud prevention information published by the PCPD, the Police or relevant organisations to bolster the awareness of fraud prevention.
Anyone who suspects that his/her personal data has been leaked may make enquiries or lodge complaints with the PCPD (“Personal Data Fraud Prevention Hotline”: 3423 6611 or email: communications@pcpd.org.hk). If there is any suspicion of fraud on personal data which involves criminal offence(s), they should immediately report the case to the Police. Citizens may also use “Scameter” (https://cyberdefender.hk/en-us/scameter/) to check suspicious phone numbers, email addresses and websites, etc.
|
Highlights of the “Draft Regulations on Personal Information Protection of Large-Scale Personal Information Processors” 《大型個人信息處理者個人信息保護規定(徵求意見稿)》 的重點
To regulate the personal information processing activities of large-scale personal information processors, the Cyberspace Administration of China (CAC) issued the “Draft Regulations on Personal Information Protection of Large-Scale Personal Information Processors” (Draft Regulations) on 7 August 2026 for public consultation. The consultation period will end on 7 September 2026. The Draft Regulations consolidates and refines the regulatory framework under two consultation drafts released by the CAC last year, namely the “Draft Regulations on the Establishment of Personal Information Protection Supervisory Committees by Large Online Platforms” and the “Draft Regulations on Personal Information Protection of Large Online Platforms”. This column previously introduced these two drafts in October 2025 and December 2025 respectively. This article focuses on the key amendments and new requirements in the Draft Regulations.
為規範大型個人信息處理者的個人信息處理活動,國家互聯網信息辦公室(網信辦)在2026年8月7日發布了《大型個人信息處理者個人信息保護規定(徵求意見稿)》1,公開徵求意見至2026年9月7日。《徵求意見稿》是在網信辦去年發布的《大型網絡平台設立個人信息保護監督委員會規定(徵求意見稿)》2(《監督委員會規定 》)及《大型網絡平台個人信息保護規定(徵求意見稿)》3(《個保規定》)的基礎上,整合完善的統一規範框架。本欄曾分別於2025年10月及2025年12月介紹上述兩份文件,本文將重點討論《徵求意見稿》的主要修訂內容及其新增要求。
大型個人信息處理者的定義
與《監督委員會規定》及《個保規定》相比,《徵求意見稿》的監管對象由「大型網絡平台」調整為「大型個人信息處理者」。《徵求意見稿》指出,對大型個人信息處理者的認定,應當綜合考慮下列條件4:
- 處理1000萬人以上自然人個人信息;
- 提供涉及個人信息處理的重要網絡服務,或者經營範圍涵蓋多種業務且涉及個人信息處理;
- 個人信息處理活動對國家安全、經濟運行、社會穩定、公共健康和安全等具有重要影響。
個人信息處理者自行評估後認為符合認定條件,應當向網信部門申報大型個人信息處理者認定,國家網信等部門會研究確定大型個人信息處理者清單,並向社會公告5。
個人信息處理規則
在個人信息處理規則方面,《徵求意見稿》的要求更為全面,除了如《個保規定》般對數據本地化存儲6及個人信息可攜權7作出規定,亦進一步涵蓋了告知與同意8、自動化決策9、以及個人信息的公開和刪除10等層面。
大型個人信息處理者的義務
在大型個人信息處理者的義務方面,《徵求意見稿》在《個保規定》的基礎上作出修訂,並新增了多項要求。
個人信息保護負責人
《徵求意見稿》刪去了《個保規定》中個人信息保護負責人(個保負責人)「對個人信息處理事項具有否決權」的規定11,改為提出若大型個人信息處理者在無正當理由下,不予處理個保負責人提出的合規性意見,或者處理結果違反有關規定,個保負責人可以直接向網信部門報告12。
《徵求意見稿》亦不再要求設立個人信息保護工作機構13,改由個保負責人指導各業務部門中具備個人信息保護合規審計能力的人員,負責所在部門的個人信息處理活動安全管理14。部分原先屬該機構的工作,如制定內部個人信息保護管理制度、開展個人信息安全風險監測等等,則交由個保負責人組織、指導15。
加強未成年人保護
在未成年人保護方面,《徵求意見稿》新增的規定包括:
- 應當通過國家網絡身份認證公共服務等方式識別未成年人16;
- 專責未成年人個人信息保護工作的人員應當經過專門培訓,熟悉未成年人特點和健康成長保護需要17;
- 針對不滿十四周歲未成年人制定專門的個人信息處理規則,對已滿十四周歲不滿十八周歲未成年人採取針對性個人信息保護措施18。
其他新增規定
除上述規定外,《徵求意見稿》亦為大型個人信息處理者增設多項義務,包括:
- 若提供網絡平台服務,並發現平台內產品或者服務提供者嚴重違反法律法規處理個人信息,應當立即採取停止提供服務等處置措施19;
- 個人信息保護社會責任報告應至少包括個人信息保護組織架構和內部管理情况、重大個人信息安全事件處理情况等九項內容20;
- 應當每兩年至少開展一次個人信息保護合規審計、每年對其個人信息處理活動開展風險評估21。
個人信息保護監督委員會
在《監督委員會規定》的基礎上,《徵求意見稿》新增的重點要求包括:
- 大型個人信息處理者應當自被認定之日起6個月內成立監督委員會22;
- 大型個人信息處理者聘用外部成員,應當對外部成員進行安全背景審查。審查時,可以申請公安機關協助23;
- 外部成員應當每年對獨立性情况進行自查,並提交至受聘大型個人信息處理者董事會等機構進行評估24。
至於有關解聘外部成員、召開會議等其他要求,《徵求意見稿》將它們納入在其附件《個人信息保護監督委員會工作規則制定指引》(《指引》)之中,大型個人信息處理者應當按照《指引》制定監督委員會的工作規則25。
總結
《徵求意見稿》整合了《監督委員會規定》及《個保規定》的內容,將監管對象延伸至所有「大型個人信息處理者」,並提出了更全面及具體的個人信息保護要求。有關個人信息處理者宜細閱當中的規定,於《徵求意見稿》定稿後採取相應措施。
1 全文: https://www.cac.gov.cn/2026-08/07/c_1787851071612596.htm
2 全文: https://www.cac.gov.cn/2025-09/12/c_1759395487456327.htm
3 全文:https://www.cac.gov.cn/2025-11/22/c_1765543463511624.htm
4《徵求意見稿》第二條。
5《徵求意見稿》第三條。
6《徵求意見稿》第十三至十六條;《個保規定》第九至十三條。
7《徵求意見稿》第十九條;《個保規定》第十四條。
8《徵求意見稿》第十至十二條。
9《徵求意見稿》第十七條。
10《徵求意見稿》第二十二至二十三條。
11 《個保規定》第五條。
12《徵求意見稿》第二十六條。
13《個保規定》第六條要求大型網絡平台服務提供者明確個人信息保護工作機構,在個人信息保護負責人領導下開展個人信息保護相關工作。
14 《徵求意見稿》第二十七條。
15《徵求意見稿》第二十六條。
16 《徵求意見稿》第三十二條。
17《徵求意見稿》第三十二條。
18 《徵求意見稿》第二十六條。
19《徵求意見稿》第二十九條。
20《徵求意見稿》第三十條。
21《徵求意見稿》第三十三條。
22《徵求意見稿》第三十七條。
23 《徵求意見稿》第三十八條。
24《徵求意見稿》第三十九條。
25 《徵求意見稿》第三十七條。
|
|
|
|
HONG KONG INTERNATIONAL DATA PRIVACY ACADEMY
|
The Academy was officially launched on 16 June 2026 by the Honourable Mr Paul LAM Ting-kwok, GBS, SC, JP, the Secretary for Justice of the Government of the Hong Kong SAR, China, and other officiating guests during the 30th Anniversary Privacy Protection Summit of the PCPD.
The PCPD established the Academy to actively align with the Country’s 15th Five-Year Plan in supporting Hong Kong’s development as an international high-calibre talent hub and the Government’s policy under the “One Country, Two Systems” principle to leverage the distinctive advantages of enjoying strong support of the Motherland and being closely connected to the world. It also aims to support the formulation and implementation of the first Hong Kong’s Five-Year Plan by the HKSAR Government under the leadership of the Chief Executive, thereby actively integrating into and serving the overall national development.
The PCPD 30th Anniversary Privacy Protection Summit was the first signature event launched by the Academy. The Academy provides flagship training programmes on privacy/personal data protection matters for organisations, privacy protection practitioners and other stakeholders in Hong Kong, the Chinese Mainland and other parts of the world. The programmes, which include introductory seminars, professional workshops, topical seminars on emerging issues, dialogues with experts, in-house seminars and online training, are supported by various professional associations and industry groups. For details, please click here to visit the website of the Academy.
|
PCPD 30th Anniversary Presents – Public Seminar on “Preventing Online Scams and Staying Safe on Messaging App and Social Media”
|
In today's digital age, scammers are constantly exploiting instant messaging applications, social media platforms and online channels to deceive users. Recently, fraudulent activities such as WhatsApp hijacking and fake official websites have increased the risks of members of the public falling prey to scams. In light of this, the Academy of PCPD has organised this seminar to enhance public awareness of scam prevention and promote the safe use of messaging applications and social media platforms.
Privacy Commissioner Ms Ada CHUNG Lai-ling will share some real fraudulent cases involving WhatsApp hijacking, as well as other common online scam cases. Ms Maggie TAM, Head of Public Policy, Hong Kong, Meta, is invited to introduce Meta’s anti-scam measures across its platforms, including WhatsApp’s safety and security features.
In addition, to enable parents help teenagers in using messaging applications and social media platforms more safely, Ms Tam will also introduce Meta’s parental supervision tools and safeguards for teen accounts at the seminar.
Members of the public with an interest in the topic are welcome to attend.
Date: 15 September 2026 (Tuesday)
Time: 3:00pm – 4:00pm
Mode: Hybrid
Venue: Hong Kong International Data Privacy Academy, 12/F, Dah Sing Financial Centre, 248 Queen's Road East, Wanchai, Hong Kong
Language: Cantonese
Fee: Free of charge
|
Professional Workshop on Data Protection in Human Resource Management
|
Since job applicants, current and former employees may request access to their personal data kept by organisations from time to time, employers or human resource management professionals have to ensure compliance with the requirements of the PDPO when they collect and handle data of their employees. On the other hand, employers should meet public expectations to constantly protect and respect their employees’ personal data privacy. This workshop enables participants to learn how to handle different scenarios and strengthen their knowledge of data protection in human resource management.
Date: 9 September 2026 (Wednesday)
Time: 2:15pm – 5:15pm
Venue: Lecture Room, the PCPD’s Office, 12/F, Dah Sing Financial Centre, 248 Queen’s Road East, Wanchai, Hong Kong
Language: Cantonese
Fee: $750/$600* (*Members of the DPOC and supporting organisations may enjoy the discounted fee)
Accreditation: 3 CPD points (The Law Society of Hong Kong, Insurance Authority, Estate Agents Authority, PMSA, Hong Kong Institute of Bankers)
Who should attend: Human resource officers, data protection officers, compliance officers, solicitors, administration managers, recruitment agents
|
Practical Workshop on Data Protection Law
|
With the growing public awareness of and expectations for the protection of personal data privacy, it has become a norm for organisations to incorporate personal data privacy protection as part of their corporate governance responsibilities to gain customers’ trust and confidence.
This workshop will examine the practical application of the PDPO at work by the sharing of real-life cases and providing practical advice. This workshop is particularly suitable for barristers, solicitors, in-house legal counsels, data protection officers and compliance officers.
Date: 16 September 2026 (Wednesday)
Time: 2:15pm – 5:15pm
Mode: Online
Language: Cantonese
Fee: $950/$760* (*Members of the DPOC and supporting organisations may enjoy the discounted fee)
Accreditation: 3 CPD points (The Law Society of Hong Kong, Estate Agents Authority, PMSA, Hong Kong Institute of Bankers)
Who should attend: Solicitors, barristers, in-house legal counsels, data protection officers, compliance officers
|
Professional Workshop on Data Protection and Data Access Request
|
Receiving Data Access Requests (DAR) is a frequent occurrence for many organisations. For example, employees may request employers for copies of their previous appraisal reports; patients may request for copies of their medical records, etc. Handling DAR properly, effectively and in a timely manner poses a challenge to many organisations.
This workshop will examine in detail the compliance requirements for handling DAR under the PDPO and offer practical guidance to participants on handling DAR.
Date: 23 September 2026 (Wednesday)
Time: 2:15pm – 5:15pm
Mode: Online
Language: Cantonese
Fee: $750/$600* (*Members of the DPOC and supporting organisations may enjoy the discounted fee)
Accreditation: 3 CPD points (The Law Society of Hong Kong, Insurance Authority, Estate Agents Authority, PMSA, Hong Kong Institute of Bankers)
Who should attend: Solicitors, data protection officers, administration managers, human resource officers, customer services personnel
|
New Series of Professional Workshops on Data Protection from Oct to Dec 2026:
|
Online Free Seminars – Introduction to the PDPO Seminar
|
The PCPD organises free introductory seminars regularly to raise public awareness and their understanding of the PDPO. Details of the upcoming sessions are shown below:
|
Seminar Outline:
- A general introduction to the PDPO;
- The six Data Protection Principles;
- Offences and compensation;
- Direct marketing; and
- Q&A session.
|
Arrange an In-house Seminar for Your Organisation
|
Teaching employees how to protect personal data privacy is increasingly recognised as an important part of employee training. If you wish to arrange an in-house seminar for your organisation to learn more about the PDPO and data privacy protection, you can make a request for an in-house seminar via our online form.
The seminar outline is as follows:
- A general introduction to the PDPO;
- The six Data Protection Principles (industry-related cases will be illustrated);
- Data security management;
- Handling of data breach incidents;
- Direct marketing;
- Offences and compensation; and
- Q&A session.
Duration: 1.5 hours
|
APPLICATION / RENEWAL OF DPOC MEMBERSHIP
|
Apply or renew your DPOC membership today and enjoy privileged access to course enrolments throughout the year!
Special Offer for Organisational Renewals:
Organisations can join the 2-for-1 scheme, which enables you to receive two memberships for the price of one annual fee (HK$450).
Join us now to keep up-to-date with the latest news and legal developments!
|
PCPD Supports the Hong Kong Institute of Bankers (HKIB) Annual Banking Conference 2026
|
The PCPD continues to serve as a supporting organisation for the HKIB Annual Banking Conference this year. The theme of this year’s event is “Bank of Tomorrow: Transform to Excellence”, which will showcase how banks are redesigning their operating models to become smarter, faster and safer, while strengthening their role as trusted platforms that enable connectivity, capital flows and sustainable growth.
Please click here for the details and registration.
|
PCPD Supports the HKIoD’s Directors’ Symposium 2026
|
The “Directors’ Symposium 2026” organised by the Hong Kong Institute of Directors is now open for enrolment. The PCPD is pleased to be one of the supporting organisations of this event.
“Navigating Through Disruptive Forces in Challenging Times” is the theme of the “Directors’ Symposium 2026”.
Please click here for the details.
|
PCPD Supports the Hong Kong Volunteer Award 2026
|
The PCPD is delighted to be one of the supporting organisations of the Hong Kong Volunteer Award (HKV-Award) 2026, co-organised by the Home and Youth Affairs Bureau and the Agency for Volunteer Service, with support from the “JC VOLUNTEER TOGETHER” Project funded by The Hong Kong Jockey Club Charities Trust.
HKV-Award is themed Volunteering Beyond Boundaries this year, to encourage transcending all kinds of volunteering limits, embedding the spirit of helping others into everyday life, and empowering the community.
Please click here for more details.
|
The PCPD values the opinions of all our DPOC members. We love to hear your ideas and suggestions on what privacy topics you would like to learn more about. Email your thoughts to us at dpoc@pcpd.org.hk and we shall include the most popular topics in our future e-newsletters.
|
|
|
|
Contact Us
Address: Unit 1303, 13/F, Dah Sing Financial Centre, 248 Queen’s Road East, Wanchai, Hong Kong
Tel: 2827 2827
If you do not wish to receive the PCPD e-Newsletter, please click here to unsubscribe.
|
Copyright
Disclaimer
The information and suggestions provided in this publication are for general reference only. They do not serve as an exhaustive guide to the application of the law. The Privacy Commissioner makes no express or implied warranties of accuracy or fitness for a particular purpose or use with respect to the information and suggestions set out in this publication. This publication also contains information or suggestions contributed by others, whose views or opinions are solely those of the contributors and do not necessarily reflect or represent those of the Privacy Commissioner. All information and suggestions provided in this publication will not affect the functions and powers conferred upon the Privacy Commissioner under the Personal Data (Privacy) Ordinance.
The PCPD shall not be liable for any damages (including but not limited to damages for loss of business or loss of profits) arising in contract, tort or otherwise from (i) the use of or inability to use this publication or its content, or (ii) from any action taken or decision made on the basis of the content of this publication.
If you click any hyperlink in this publication that brings you to sites operated by other organisations, the PCPD accepts no responsibility for the contents of those sites and shall not be liable for any loss or damage arising out of and/or incidental to the use of the contents.
|
|
|
|
|