Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • DHS Board Blames Microsoft’s ‘Cascade’ of Errors for 2023 E-mail Breach
    • Bill to Revise Browser Requirements Under CCPA Advances
    • Children’s Data Privacy Act Advances in California
    • D.C. Circuit Gives Hikvision, Dahua Some Hope in ‘Covered List’ Case
    • Greek Immigration Authority Fined Over GDPR Violations
    • HEALTH CARE COMPLIANCE NEWS—New Jersey SNF hit with $100K CMP for HIPAA violation over timely access to medical records
    • Hong Kong DPA Issues Enforcement Notice After Cyberport Data Breach
    • Italy Suspends Worldcoin’s Orb Collection of Iris Scans
    • NIST Publishes Draft Handbook on IoT Cybersecurity
    • Summit Seeks Clarity Amid ‘Rip-and-Replace' Funding Shortfall
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Hong Kong DPA Issues Enforcement Notice After Cyberport Data Breach, (Apr 3, 2024)

    By Tony Foley

    The Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD) released an investigative report yesterday regarding a data breach of the Hong Kong Cyberport Management Co. Ltd. last fall.

    According to a statement announcing the report, the ...

    By Tony Foley

    The Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD) released an investigative report yesterday regarding a data breach of the Hong Kong Cyberport Management Co. Ltd. last fall.

    According to a statement announcing the report, the investigation arose from a data breach notification submitted by Cyberport stating that its computer systems and file servers had been attacked by ransomware. The incident resulted in the leakage of personal data of more than 13,000 data subjects, many of whom were unsuccessful job applicants and former employees of Cyberport.

    Although the PCPD acknowledged Cyberport’s cooperation in the investigation, the investigative report found that the following deficiencies led to the breach:

    1. A lack of effective detection measures in Cyberport’s information systems, causing its failure to detect the “brute force attacks” by the hacker;

    2. A failure to implement multifactor authentication for remote access to data;

    3. Insufficient security audits of its information systems;

    4. A lack of specificity in its information security policy, which failed to provide a concrete cybersecurity framework for employees to follow; and

    5. Unnecessary retention of personal data after the expiration of its specified retention periods, which related to about 40% of the total number of affected individuals.

    PRPC said that, as a well-established organization continuously holding and processing personal data, stakeholders and the public had a reasonable expectation that Cyberport would allocate sufficient resources to ensure the security of its information systems.

    Based on the deficiencies outlined above, PDPC found that Cyberport did not take all practicable steps to ensure that the personal data involved was protected against unauthorized or accidental access, processing, erasure, loss, or use, in violation of the Personal Data (Privacy) Ordinance (PDPO). The report also concluded that Cyberport failed to ensure that personal data was not kept longer than necessary. Accordingly, the PDPC issued an enforcement notice directing Cyberport to remedy these contraventions and prevent their recurrence in the future.

    Privacy Commissioner Ada Chung Lai-ling also outlined several general recommendations for organizations that use information and communications technologies for processing personal data, including establishing a privacy management framework and appointing a data protection officer, establishing a robust cybersecurity framework, conducting timely risk assessments and security audits, establishing a corporate culture that values information security, and timely deleting personal data when necessary.

    News: InternationalLegislation LitigationEnforcement DataSecurity DataBreach DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use