A calm, practical guide for schools, charities and smaller businesses. What to do first when personal data has been lost, exposed or accessed by the wrong person, and how to think about your obligations under Hong Kong's data-protection law.
Most breaches are not the work of sophisticated criminals. They are a laptop left on a train, a spreadsheet emailed to the wrong list, or a login that should have been switched off months ago. What matters is how the first day or two is handled.
The first task is to stop the situation getting worse. Depending on what has happened, that might mean disabling an account, taking a system offline, recalling an email, changing passwords, or securing a device. If an external attacker may still have access, involve your IT support or a specialist quickly, and be careful not to destroy anything that might later matter.
Work out, as precisely as you can, what has actually happened. Useful questions include:
Write down what you know and when you knew it. A short, factual timeline started early is far more useful than a reconstruction attempted weeks later.
Hong Kong's Personal Data (Privacy) Ordinance requires organisations that hold personal data to take practicable steps to keep it secure. A breach often raises the question of whether those steps were adequate, and what is done in response is part of the picture.
At present there is no general statutory duty under the Ordinance to notify every data breach. The Privacy Commissioner for Personal Data nevertheless recommends notification as good practice where a breach carries a real risk of harm, and has published guidance on handling breaches. The direction of policy in this area has been towards stronger notification expectations, so it is worth taking the question seriously rather than assuming silence is safe.
Whether and when to notify the Privacy Commissioner is a judgement, and it is best made with the facts in front of you. Broadly, the more sensitive the data and the greater the risk to the people affected, the stronger the case for notifying, and for doing so promptly rather than waiting for a complete picture. A notification typically describes what happened, what data was involved, how many people are affected, what you have done to contain it, and what you are doing to reduce the risk of harm.
If you are unsure, this is a good moment to take advice. The choice is not simply whether to notify, but how to frame what you say, and getting that right early tends to make everything that follows easier.
Where a breach may cause real harm, the people affected often need to be told, so that they can protect themselves, for example by changing a password or watching for misuse of their information. Tell them plainly what happened, what it means for them, what you are doing, and what they can do. Say it once, clearly, rather than issuing a stream of partial updates.
For a school or a charity in particular, the tone of that message matters. Honesty handled with care tends to preserve trust; defensiveness rarely does.
Keep the logs, emails, devices and records that show what happened. Resist the urge to tidy up or delete things while you work out what went wrong. If the matter is later reviewed, by the Privacy Commissioner, by an insurer, or by the organisation itself, a preserved record is worth a great deal.
We advise schools, charities, SMEs and institutions on data protection and breach response, including dealings with the Privacy Commissioner. We are used to working quickly and calmly when something has gone wrong, and to helping an organisation get ahead of a risk before it becomes an incident. You can read more on our data protection page and on our business page.
At present there is no general statutory duty under the PDPO to report every breach, but the Privacy Commissioner recommends notification as good practice where there is a real risk of harm. Whether to notify in a given case is a judgement best made with advice.
Where a breach may cause real harm, telling the people affected is usually the right thing to do, so that they can take steps to protect themselves. How and when to tell them is part of the response to plan carefully.
Containment should begin immediately. Assessment, and any decision about notifying the Privacy Commissioner or those affected, should follow promptly rather than being left to drift.
Broadly, any loss of, unauthorised access to, or unauthorised disclosure of personal data your organisation holds. That includes accidents, such as an email sent to the wrong recipient, as well as deliberate attacks.
This page is general information, not legal advice on any specific situation. For advice on your circumstances, contact us.
You will hear back from a person within two working days. If it is urgent, call the office on (852) 2114 1616 during office hours, or call or WhatsApp us on (852) 6483 1803.
Contact us