Skip to content

Something urgent? Call us now! (852) 3416 1711

Data security: time to review

By Claire Chow

Hong Kong, 3 February 2023: Two personal data leaks by Hong Kong’s electoral office – both caused by human error – have highlighted the importance of cyber security and information protection in the digital age. Businesses and organisations should take note and review their safety mechanisms accordingly.

An investigation by the Office of the Privacy Commissioner for Personal Data found the government’s Registration and Electoral Office (REO) had breached regulations and failed to protect voters’ information. The REO had not taken “all practicable steps” to ensure such details were shielded from unauthorised access, according to the Privacy Commissioner’s report.

In the first incident, during Hong Kong’s fifth wave of Covid-19 infections in March last year, a clerical officer tried to send two spreadsheets with the names and addresses of some 15,000 voters to her personal email so she could work from home the next day. But she typed in the wrong email address and the files went to an unknown recipient.

The following month, during preparations for the Chief Executive election, another REO employee mistakenly attached a reply slip containing details about an Election Committee member when sending a test email to 64 other members or their assistants.

In her investigation, Privacy Commissioner Ada Chung found the first incident stemmed from the officer’s negligence and lack of awareness of the REO’s own guidelines, which stipulated “[staff should] only use the email system of the REO for transmission of classified information through email” and “[staff should not] use personal email accounts for official duties or for transmitting classified information or personal data”. Ms Chung also found the REO had not put in place appropriate information security measures.

The second breach was down to collective negligence and lack of awareness by several staff members and deficiencies in the REO’s workflow, according to the Privacy Commissioner. While working long hours and under pressure to meet deadlines, employees had resorted to last-minute manual checking, thus increasing the risk of human error.

Ms Chung noted: “The two incidents revealed that the Registration and Electoral Office had not taken all practicable steps to ensure that personal data was protected from unauthorised or accidental access, processing, erasure, loss or use.” She concluded the REO had contravened the Personal Data (Privacy) Ordinance. The REO was served with two Enforcement Notices and has since enhanced security measures, including monitoring of its email system, and reviewed workflow procedures.

Concluding her report, Ms Chung provided businesses and organisations with the following recommendations for handling personal data:

  • Thoroughly implement a personal data privacy management programme;
  • Conduct privacy risk assessments and formulate specific guidelines for non-routine work;
  • Devise effective education and training plans on personal data security; and
  • Deploy information security measures to mitigate the risk of human errors.

In conclusion, it should be noted that the digital age is a double-edged sword. While it has brought countless ingenious solutions for processing information, this also means greater threats in terms of cyber security. Personal data loss may include financial, personal and health information.

Such breaches can have devasting consequences for all parties. For an individual, their privacy and security are compromised. For a business or organisation, there are legal, financial and reputational implications. For these reasons, and as highlighted by the REO examples, it is obvious that compliance with relevant data protection laws and robust cyber security measures are in everyone’s best interest.

Claire Chow is an Associate with BC&C, having joined the firm in 2019. She covers a broad range of practice areas including Criminal Matters, Civil and Commercial Litigation, and Intellectual Property. She can be contacted at Claire@boasecohencollins.com.

40+ years of legal experience is just a click away.

Friendly and approachable, we are ready to answer your questions and offer you sound advice.

Contact us now

BC&C-contact-us

News & Knowledge

Learn more about what we do and what we say. Subscribe to our newsletter to ensure you receive our updates.

  • This field is for validation purposes and should be left unchanged.

Shining a light on four decades

Hong Kong, 19 March 2025: Need inspiration? Conceptual artist Sir Michael Craig-Martin – “The Godfather of Brit Art” – has the answer with his sculpture Bright Idea, a four-metre-tall yellow lightbulb constructed from steel. It is one of a series of designs in which he challenges our perceptions of mundane objects by capturing their “formal […]

Read more

Drug sentencing guidelines revised

By Jasmine Kwong Hong Kong, 12 March 2025: In a significant ruling, the Court of Appeal has modified Hong Kong’s sentencing guidelines for defendants convicted after trial of trafficking heroin, cocaine or ice. The move keeps in place lengthy minimum prison terms for small-scale traffickers, but offers courts more room to manoeuvre in handling cases […]

Read more

BC&C celebrates 40 years of legal services

Hong Kong, 10 March 2025: Flashback to 1985 and there was much happening in our city. The Legislative Council held its first-ever election, poignant drama Homecoming was the major winner at the Hong Kong Film Awards and Ecuador’s Andrés Gómez won the Seiko Super Tennis tournament at Victoria Park. As well, legal professionals Melville Boase […]

Read more

Law & More: Episode 50 – José Maurellet SC

Hong Kong, 3 March 2025: This time, we are joined by José-Antonio Maurellet SC, the newly elected chairman of the Hong Kong Bar Association. In a wide-ranging discussion, José looks back on his student days at Oxford, early work as a barrister and the development of his practice in company and commercial law. He also […]

Read more

Bridge-building towards cross-border ties

Hong Kong, 24 February 2025: We were delighted to host our friends from Chance Bridge Law Firm, the new mainland China member of global legal services organisation Ally Law, when they visited our office for an informal meeting. The quartet comprised Managing Partner Ning Zhu and International Consultant Greg Harris from the firm’s Beijing headquarters; […]

Read more