Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote
Hong Kong regulatory

Hong Kong data breach notifications rose 21% in 2025 — and the exposure is usually a supplier

The PCPD received 246 breach notifications in 2025, up 21% from 203 the year before, and published the figure on 3 February 2026. What it called out was oversight of outsourced systems.

Breach reporting in Hong Kong is not yet a statutory obligation — it is encouraged good practice under the PDPO. The rising figure therefore reflects organisations choosing to report, and a genuine increase in incidents.

What the commissioner drew attention to

  • Oversight of systems operated by outsourced or third-party providers.
  • Data retention: keeping personal data longer than the purpose requires.
  • Patching and secure remote access, the two findings in the April enforcement case.
  • Whether staff know the internal reporting route, and can reach it out of hours.

What this means for you

Most breach exposure sits with the vendor you did not audit. If you cannot describe what a supplier can access, how it is configured, and when it was last reviewed, you cannot answer the first question a regulator asks.

What the board should ask

Not whether we are secure, but what we would have to do in the first 24 hours, who would decide, and whether we could reconstruct what happened from records.

Sources
PCPD media statement on its 2025 work report, 3 February 2026 — pcpd.org.hk
PCPD investigation findings, Yau Yat Chuen Garden City Club Limited, 23 April 2026 — pcpd.org.hk