Publications

𝗣𝗿𝗲𝗽𝗮𝗿𝗶𝗻𝗴 𝗳𝗼𝗿 𝗮𝗻𝗱 𝗿𝗲𝘀𝗽𝗼𝗻𝗱𝗶𝗻𝗴 𝘁𝗼 𝗱𝗮𝘁𝗮 𝗯𝗿𝗲𝗮𝗰𝗵𝗲𝘀: 𝗣𝗿𝗶𝘃𝗮𝗰𝘆 𝗖𝗼𝗺𝗺𝗶𝘀𝘀𝗶𝗼𝗻𝗲𝗿 𝗽𝘂𝗯𝗹𝗶𝘀𝗵𝗲𝘀 𝗿𝗲𝘃𝗶𝘀𝗲𝗱 𝗴𝘂𝗶𝗱𝗮𝗻𝗰𝗲 𝗼𝗻 𝗱𝗮𝘁𝗮 𝗯𝗿𝗲𝗮𝗰𝗵 𝗵𝗮𝗻𝗱𝗹𝗶𝗻𝗴 𝗮𝗻𝗱 𝗻𝗼𝘁𝗶𝗳𝗶𝗰𝗮𝘁𝗶𝗼𝗻𝘀

31/07/2023

The Office of the Privacy Commissioner for Personal Data (“PCPD”) issued an updated “Guidance on Data Breach Handling and Data Breach Notifications” (“the Guidance”) in June 2023 which offers more comprehensive and practical insights to organisations on how to effectively handle data breaches and mitigate the harm that may be caused to affected data subjects.

In the Guidance, the PCPD identified the trends of common causes of data breaches in Hong Kong, which include cyberattacks, system misconfigurations, loss of physical documents/portable devices, improper/wrongful disposal of personal data, inadvertent disclosure by mail/post, and staff negligence/misconduct.

The Guidance recommends organisations to formulate a comprehensive data breach response plan. The plan should specify the procedures to adopt in the event of a data breach, and the strategies for mitigating its impact. The Guidance further recommends five steps that organisations should take in the event of a data breach.

To know more, please read our latest article for this update prepared by our Partner, Charles To, our Associate, Tiffany Li and our Trainee Solicitor Hank Yeung.