
Government plans to require companies to notify authorities and affected individuals of serious personal data leaks
Hong Kong’s government is preparing to revive long-discussed reforms to its privacy legislation that would require organisations to report data breaches involving personal information, signalling a significant shift in the city’s regulatory approach to data protection.
Officials have indicated that amendments to the Personal Data (Privacy) Ordinance are being prioritised, with the aim of introducing mandatory notification obligations for companies and public bodies when serious data leaks occur.
Under the proposed changes, organisations would be required to inform the Privacy Commissioner for Personal Data and affected individuals within a specified timeframe if a breach poses a real risk of harm.
The move follows a series of high-profile data incidents in recent years that exposed weaknesses in the current framework, which relies largely on voluntary reporting and post-incident enforcement.
Authorities have argued that compulsory notification would improve transparency, strengthen accountability and allow faster mitigation of potential damage to individuals.
The government has stressed that the revival of the bill reflects the growing importance of data governance in a digital economy and the need to align Hong Kong’s standards more closely with international practices.
Officials have also signalled that penalties for non-compliance could be enhanced, alongside clearer powers for the privacy regulator to investigate and enforce breaches of the law.
Business groups are closely watching the proposals, weighing the potential compliance burden against the benefits of greater legal certainty and public trust.
If enacted, the reforms would mark one of the most substantial updates to Hong Kong’s privacy regime in years, reshaping how organisations manage cybersecurity risks and respond to incidents involving personal data.
Officials have indicated that amendments to the Personal Data (Privacy) Ordinance are being prioritised, with the aim of introducing mandatory notification obligations for companies and public bodies when serious data leaks occur.
Under the proposed changes, organisations would be required to inform the Privacy Commissioner for Personal Data and affected individuals within a specified timeframe if a breach poses a real risk of harm.
The move follows a series of high-profile data incidents in recent years that exposed weaknesses in the current framework, which relies largely on voluntary reporting and post-incident enforcement.
Authorities have argued that compulsory notification would improve transparency, strengthen accountability and allow faster mitigation of potential damage to individuals.
The government has stressed that the revival of the bill reflects the growing importance of data governance in a digital economy and the need to align Hong Kong’s standards more closely with international practices.
Officials have also signalled that penalties for non-compliance could be enhanced, alongside clearer powers for the privacy regulator to investigate and enforce breaches of the law.
Business groups are closely watching the proposals, weighing the potential compliance burden against the benefits of greater legal certainty and public trust.
If enacted, the reforms would mark one of the most substantial updates to Hong Kong’s privacy regime in years, reshaping how organisations manage cybersecurity risks and respond to incidents involving personal data.









































