top of page
dpo-bg3.jpg

Latest News

PCPD - Protecting Personal Data Privacy in the Use of Agentic AI” (Guidance)

27 Aug 2026

PCPD - Protecting Personal Data Privacy in the Use of Agentic AI” (Guidance)

The Guidance is supported by the Digital Policy Office and the Hong Kong Applied Science and Technology Research Institute as supporting organisations🤝.

The National 15th Five-Year Plan stresses the important principle of following a holistic approach to development and security. It is essential that innovation be accompanied by robust personal data privacy safeguards. The PCPD has published the Guidance with a view to implementing the Government’s ‘AI+’ policy direction, promoting the safe, lawful and responsible adoption of agentic AI and empowering the community to embrace this transformative technology with confidence and trust.”

House Democrats want answers from OpenAI and Anthropic on their rogue AI agents

12 Aug 2026

House Democrats want answers from OpenAI and Anthropic on their rogue AI agents

US House Democrats have decided that AI agents breaking loose from their test environments is a matter for Congress, and on Monday they put that view in writing.


Two letters went out, one to OpenAI and one to Anthropic, each demanding an account of how the companies’ own systems slipped their leashes during security testing, and each treating the episodes as something closer to a national security problem than a laboratory curiosity.


OpenAI is pressed to explain how it monitored its agents during testing and whether rogue models managed to evade the safety controls meant to contain them.

And Anthropic is asked to spell out the protocols it has introduced since its own breaches, with both firms questioned on precisely how their systems escaped containment in the first place.


Similar post in Chinese - 【AI+威脅】美參議員桑德斯致函OpenAI、Anthropic及Meta 促遵守承諾暫停開發AI 警告國會將強制介入 - https://inews.hket.com/article/4175069/%E3%80%90AI-%E5%A8%81%E8%84%85%E3%80%91%E7%BE%8E%E5%8F%83%E8%AD%B0%E5%93%A1%E6%A1%91%E5%BE%B7%E6%96%AF%E8%87%B4%E5%87%BDOpenAI%E3%80%81Anthropic%E5%8F%8AMeta%E3%80%80%E4%BF%83%E9%81%B5%E5%AE%88%E6%89%BF%E8%AB%BE%E6%9A%AB%E5%81%9C%E9%96%8B%E7%99%BCAI%E3%80%80%E8%AD%A6%E5%91%8A%E5%9C%8B%E6%9C%83%E5%B0%87%E5%BC%B7%E5%88%B6%E4%BB%8B%E5%85%A5?mtc=20064

Incident Report: unsanctioned agent behaviour during cyber testing

12 Aug 2026

AI capability - Incident Report: unsanctioned agent behaviour during cyber testing

A recent incident report described an AI agent exhibiting unsanctioned behaviour during a cyber testing exercise.

The most interesting takeaway is not the specific incident itself. It's the realization that AI agents can pursue goals in ways we didn't anticipate, even without being explicitly instructed to do so. The report also highlights that traditional security fundamentals such as monitoring, governance, human oversight, and least privilege remain critical as AI capabilities advance.

"The most effective response remains standard cyber hygiene"

The takeaways
🔷 Capability without controls creates risk
🔷 Human oversight remains essential
🔷 Governance must scale as fast as AI innovation

Baptist University reviews IT security after ransomware group claims breach

12 Aug 2026

Baptist University reviews IT security after ransomware group claims breach

Baptist University has said it is reviewing the security of its information technology (IT) systems after a ransomware group claimed online to have illegally accessed the Hong Kong institution’s data.


The allegations were made by “The Gentlemen”, an advanced cybercrime group that first appeared in the middle of last year.


The purported data reportedly included roughly 130 staff accounts, about 1,770 other user accounts and 260 third‑party employee credentials.

PCPD article - Building a Strong Privacy Barrier in Hong Kong to Promote AI Governance Innovation

11 Aug 2026

PCPD article - Building a Strong Privacy Barrier in Hong Kong to Promote AI Governance Innovation

PCPD has launched a series of guidelines since 2021, including the "Ethical Standards for the Development and Use of Artificial Intelligence," "Artificial Intelligence (AI): A Model Framework for Personal Data Protection" (the "Model Framework"), the "Guidelines for Employees Using Generative AI" ("Guidelist"), "Combating the Misuse of AI Deepfake Technology: A Tip for Schools and Parents" ("Tip Pack"), and "Ten Tips for Self-Protection with AI Chatbots." Among them, the Model Framework, Guidelist List, and Tips have all won the Asia-Pacific GovMedia Award, recognizing them as influential public sector projects in the Asia-Pacific region and globally.

PIPL China Simplifies Compliance for Small-Scale Personal Information Handlers

11 Aug 2026

PIPL China Simplifies Compliance for Small-Scale Personal Information Handlers

On 22 July 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (Simplified Measures), which will take effect on 1 September 2026.

  • China issues new rules relaxing compliance burdens for small-scale personal information handlers processing personal information of fewer than 100,000 individuals.

  • Qualified small-scale handlers benefit from simplified notification and consent mechanisms, extended compliance audit cycles, standardised self-assessment templates, and platform-level privacy compliance.

  • New rules introduce clear grounds for penalty exemption and mitigation for minor, first-time, or promptly corrected violations.

  • Businesses should assess whether subsidiaries in China fall within scope of small-scale handlers and consider practical steps to benefit from relaxations.

[Join us on 18 Sep 2026] - ADCC Ice-cream & Promotion Trunk on Campus

4 Aug 2026

[Join us on 18 Sep 2026] - ADCC Ice-cream & Promotion Trunk on Campus (first note)

Please mark your calendar for the day.


To enhance public awareness of the latest scam tactics and strengthen public-private collaboration in combating scam, the Anti-Deception Coordination Centre (ADCC) of the Commercial Crime Bureau will have their Anti-Scam promotional trunk and ice-cream van coming to HKU campus. 

Anthropic says its AI models hacked 3 organizations during testing

3 Aug 2026

Anthropic says its AI models hacked 3 organizations during testing

Anthropic said its AI models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.


Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs.

Privacy Commissioner’s Office Wins Governance Project of the Year and Outreach Project of the Year at Asia-Pacific Awards

3 Aug 2026

HK PCPD Office Wins Governance Project of the Year and Outreach Project of the Year at Asia-Pacific Awards

“Hong Kong Governance Project of the Year – Regulatory”  and “Hong Kong Outreach Project of the Year – Regulatory” awards, in recognition of its guidance on the “Checklist on Guidelines for the Use of Generative AI by Employees” and the effect of its outreach efforts relating to “Abuse of AI Deepfakes: Toolkit for Schools and Parents”, respectively.

The “Governance Project of the Year – Regulatory” award recognises exceptional initiatives or practices of public organisations.
Published in March 2025, the “Checklist on Guidelines for the Use of Generative AI by Employees” (Guidelines) provide a practical checklist to assist organisations in developing internal policies or guidelines on the use of generative artificial intelligence (AI) by employees at work, while complying with the requirements of the Personal Data (Privacy) Ordinance (PDPO).

https://www.pcpd.org.hk/english/resources_centre/publications/files/guidelines_ai_employees.pdf

“Hong Kong Outreach Project of the Year – Regulatory” award celebrates initiatives that excel in reaching and engaging their target audiences, fostering positive relationships, and making long term and meaningful impact on communities or stakeholders.
Published in December 2025, the “Abuse of AI Deepfakes: Toolkit for Schools and Parents” (Toolkit) provides practical advice to schools and parents to help them prevent and handle deepfake incidents involving children and young people, while safeguarding their privacy in relation to personal data.

https://www.pcpd.org.hk/english/resources_centre/publications/files/ai_deepfake.pdf


SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack

30 Jul 2026

SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack

The Securities and Futures Commission (SFC) has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) $2.1 million for failing to implement adequate and effective cybersecurity control measures, which might have contributed to its failure to withstand a ransomware attack and led to a delay of approximately three weeks in fully recovering its systems from the cyberattack.


The disruption from the 19 September 2022 ransomware attack on LFSHK’s critical IT infrastructure was sweeping, affecting file servers, domain controllers, email servers, trading application servers, and accounting servers. LFSHK restored its system in phases, and the process was not complete until 7 October 2022.

Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records

25 Jul 2026

Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records

A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records. 


The alleged breach has not been independently verified, and Decathlon has not publicly confirmed that its systems or customer data were compromised.


The actor claims the Decathlon database includes: Customer IDs, Email addresses, Password hashes, First and last names, Dates of birth, Phone numbers, Street addresses, cities, postal codes, regions, and countries, Account status information, Email-verification status, Preferred store and store-preference data, Favorite sports and purchase-related fields.

Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform

24 Jul 2026

AI Pentest Checker-Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform

A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities, and create reports.


According to Cato reports, Trim first appeared on a Russian-language cybercrime forum on March 13, 2026, where he shared methods claimed to bypass Claude Opus safety controls.

OnTrac (supporting 70% of the US population) notifies customers of data breach after network hack

24 Jul 2026

OnTrac (supporting 70% of the US population) notifies customers of data breach after network hack

OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.


Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities. 


In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to “ensure the data described above was re-secured and not distributed.”

Firm hacked by rogue OpenAI models says it is 'a wake-up call'

23 Jul 2026

Firm hacked by rogue OpenAI models says it is 'a wake-up call'

The co-founder of Hugging Face was hacked after some of OpenAI's most advanced artificial intelligence (AI) models went rogue. Thomas Wolf told BBC's Newsday radio programme that "this will be one of the most common types of cyber attacks we see", but that most firms are not aware that the "game has changed".


The ChatGPT-maker said its AI models broke out of a secure test environment during a trial and launched a cyber attack. The firm said the incident was "unprecedented" and that it was conducting an investigation with Hugging Face.

PCPD Workshop- 22July_Recent Court and Administrative Appeals Board Decisions (Online workshop) (3 CPD points)

14 Jul 2026

PCPD Academy- 22July_Recent Court and Administrative Appeals Board Decisions

Date: 22 July 2026 (Wed)
Time: 2:15pm – 5:15pm

Language: English

Format: OnlineKey 

Take-aways:Overview of key provisions of the Ordinance and the Data Protection Principles

In-depth discussion of major data privacy issues raised in recent decisions of Hong Kong courts and the Board.

Decisions made by courts and the Board in relation to:
- Interpretation of the definition of “personal data” under the Ordinance
- Circumstances in which collection of personal data may be considered excessive, unfair or unlawful
- Personal Information Collection Statement
- Use of personal data and application of exemptions under the Ordinance
- Handling of data access requests and charging of data access request fee
- Requirements on data retention and data security
- Right to compensation against a data user for damage suffered by reason of a contravention of a requirement under the Ordinance: Tsang Po Mann v Tsang Ka Kit and Anor (DCCJ 4891/2016) [2021] 1 HKLRD 1301

Cyberattack on Hong Kong’s Shun Hing Group affects data of 1 million people

6 Jul 2026

Cyberattack on Hong Kong’s Shun Hing Group affects data of 1 million people

The Office of the Privacy Commissioner for Personal Data said on Thursday that it had launched an investigation into the incident after receiving a data breach report from Shun Hing Group on March 23 (can also refer to earlier post in news in DPO website).


Personal information of more than 920,000 customers, including their names, addresses and email addresses, involved in breach.

Nissan discloses employee data breach linked to Oracle zero-day attacks

2 Jul 2026

Nissan discloses employee data breach linked to Oracle zero-day attacks

Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.


In breach notifications filed with the California Attorney General's Office, Oracle says these data theft attacks impacted hundreds of companies and that Nissan was specifically targeted in the campaign.


"Nissan Americas uses Oracle PeopleSoft software to manage employee information, including payroll, tax administration, and other personnel records," reads the breach notification.

PCPD July Professional Workshops-8 Jul DAR_22 Jul AAB

25 Jun 2026

PCPD July Professional Workshops-8 Jul DAR_22 Jul AAB

Data Access Request

There are stringent requirements for compliance with a DAR under the Personal Data (Privacy) Ordinance. Dealing properly and effectively with a DAR is a challenge for many organisations. This workshop will examine in details those requirements and offer guidance on the handling of a DAR.

https://www.pcpd.org.hk/english/education_training/organisations/workshops/workshop_outlines.html#3


Administrative Appeals Board

The Board is the statutory body that hears and determines appeals against the decisions of the Privacy Commissioner for Personal Data (“the Commissioner”) by a complainant or the relevant data user complained against. The High Court of Hong Kong deals with magistracy appeals against criminal offences committed under the Ordinance. This workshop (to be conducted by experienced lawyers from the office of the Commissioner) will examine some recent decisions which serve as legal authorities and practical examples in solving problems frequently encountered in compliance work.

https://www.pcpd.org.hk/english/education_training/organisations/workshops/workshop_outlines.html#15

[Join us on 30 June 2026] - PCPD-HKU Joint Data Protection Event - "The New AI Era: Data Protection & Cybersecurity in Higher Education" - 2nd Reminder with changes (first post on 11 May)

22 Jun 2026

[Join us on 30 June 2026] - PCPD-HKU Joint Data Protection Event "The New AI Era: Data Protection & Cybersecurity in Higher Education" - 2nd reminder

"The New AI Era: Data Protection & Cybersecurity in Higher Education" - first post on 11 May


Our distinguished speakers / panelist include:

  • Mr. Alex Chan, Assistant Privacy Commissioner, Office of the Privacy Commissioner for Personal Data (PCPD)

  • Mr. Raymond Lam, Chief Superintendent, Cyber Security and Technology Crime Bureau (CSTCB)

  • Mr. Otto Lee, Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT)

  • Mr. Leonard Chan, MH, Founding Chairman, Hong Kong Innovative Technology Development Association (HKITDA)

  • Prof. S.M. Yiu, Professor, School of Computing & Data Science, The University of Hong Kong (HKU)

In addition, we will have "the Little Grape" as the special guest for the afternoon!


Talks at the events:

  • Navigating Data Privacy Risks in the Use of AI in Higher Education (by Mr. Alex CHAN)

  • Digital Resilience: The Industrialisation of Cybercrime (by Ms. Rachel HUI)

  • Cybersecurity in Higher Education: Trends, Threats & Defences (by Mr. Otto LEE)

Panel Topic: Innovation vs. Third-Party Risk: Balancing Progress and Privacy

  • Moderator: Mr. Leonard CHAN, MH

  • Panelists: Mr. Alex CHAN, Ms. Rachel HUI, Mr. Otto LEE, Prof. S.M. YIU

Registration:

For HKU staff: https://hkuems1.hku.hk/hkuems/ec_hdetail.aspx?ueid=106167

For Non-HKU members: https://hkuems1.hku.hk/hkuems/ec_hdetail.aspx?guest=Y&ueid=106169

PCPD established the Hong Kong International Data Privacy Academy

22 Jun 2026

PCPD established the Hong Kong International Data Privacy Academy

The Hong Kong International Data Privacy Academy (“the Academy”) was officially launched on 16 June 2026 by the Honourable Mr Paul LAM Ting-kwok, GBS, SC, JP, the Secretary for Justice of the Government of the Hong Kong SAR, China, and other officiating guests during the 30th Anniversary Privacy Protection Summit of the Office of the Privacy Commissioner for Personal Data (“PCPD”).


The PCPD established the Academy to actively align with the Country’s 15th Five-Year Plan in supporting Hong Kong’s development as an international high-calibre talent hub and the Government’s policy under the “One Country, Two Systems” to leverage the distinctive advantages of enjoying strong support of the Motherland and being closely connected to the world.  It also aims to support the formulation and implementation of the first Hong Kong’s Five-Year Plan by the HKSAR Government under the leadership of the Chief Executive, thereby integrating actively into and serving the overall national development.

Copyright @2026 The University of Hong Kong. All Rights Reserved.
bottom of page