Breach reporting in Hong Kong is not yet a statutory obligation — it is encouraged good practice under the PDPO. The rising figure therefore reflects organisations choosing to report, and a genuine increase in incidents.
What the commissioner drew attention to
- Oversight of systems operated by outsourced or third-party providers.
- Data retention: keeping personal data longer than the purpose requires.
- Patching and secure remote access, the two findings in the April enforcement case.
- Whether staff know the internal reporting route, and can reach it out of hours.
What this means for you
Most breach exposure sits with the vendor you did not audit. If you cannot describe what a supplier can access, how it is configured, and when it was last reviewed, you cannot answer the first question a regulator asks.
What the board should ask
Not whether we are secure, but what we would have to do in the first 24 hours, who would decide, and whether we could reconstruct what happened from records.