
Latest News
27 Aug 2026
PCPD - Protecting Personal Data Privacy in the Use of Agentic AI” (Guidance)
The Guidance is supported by the Digital Policy Office and the Hong Kong Applied Science and Technology Research Institute as supporting organisations🤝.
The National 15th Five-Year Plan stresses the important principle of following a holistic approach to development and security. It is essential that innovation be accompanied by robust personal data privacy safeguards. The PCPD has published the Guidance with a view to implementing the Government’s ‘AI+’ policy direction, promoting the safe, lawful and responsible adoption of agentic AI and empowering the community to embrace this transformative technology with confidence and trust.”
12 Aug 2026
House Democrats want answers from OpenAI and Anthropic on their rogue AI agents
US House Democrats have decided that AI agents breaking loose from their test environments is a matter for Congress, and on Monday they put that view in writing.
Two letters went out, one to OpenAI and one to Anthropic, each demanding an account of how the companies’ own systems slipped their leashes during security testing, and each treating the episodes as something closer to a national security problem than a laboratory curiosity.
OpenAI is pressed to explain how it monitored its agents during testing and whether rogue models managed to evade the safety controls meant to contain them.
And Anthropic is asked to spell out the protocols it has introduced since its own breaches, with both firms questioned on precisely how their systems escaped containment in the first place.
Similar post in Chinese - 【AI+威脅】美參議員桑德斯致函OpenAI、Anthropic及Meta 促遵守承諾暫停開發AI 警告國會將強制介入 - https://inews.hket.com/article/4175069/%E3%80%90AI-%E5%A8%81%E8%84%85%E3%80%91%E7%BE%8E%E5%8F%83%E8%AD%B0%E5%93%A1%E6%A1%91%E5%BE%B7%E6%96%AF%E8%87%B4%E5%87%BDOpenAI%E3%80%81Anthropic%E5%8F%8AMeta%E3%80%80%E4%BF%83%E9%81%B5%E5%AE%88%E6%89%BF%E8%AB%BE%E6%9A%AB%E5%81%9C%E9%96%8B%E7%99%BCAI%E3%80%80%E8%AD%A6%E5%91%8A%E5%9C%8B%E6%9C%83%E5%B0%87%E5%BC%B7%E5%88%B6%E4%BB%8B%E5%85%A5?mtc=20064
12 Aug 2026
AI capability - Incident Report: unsanctioned agent behaviour during cyber testing
A recent incident report described an AI agent exhibiting unsanctioned behaviour during a cyber testing exercise.
The most interesting takeaway is not the specific incident itself. It's the realization that AI agents can pursue goals in ways we didn't anticipate, even without being explicitly instructed to do so. The report also highlights that traditional security fundamentals such as monitoring, governance, human oversight, and least privilege remain critical as AI capabilities advance.
"The most effective response remains standard cyber hygiene"
The takeaways
🔷 Capability without controls creates risk
🔷 Human oversight remains essential
🔷 Governance must scale as fast as AI innovation
12 Aug 2026
Baptist University reviews IT security after ransomware group claims breach
Baptist University has said it is reviewing the security of its information technology (IT) systems after a ransomware group claimed online to have illegally accessed the Hong Kong institution’s data.
The allegations were made by “The Gentlemen”, an advanced cybercrime group that first appeared in the middle of last year.
The purported data reportedly included roughly 130 staff accounts, about 1,770 other user accounts and 260 third‑party employee credentials.
11 Aug 2026
PCPD article - Building a Strong Privacy Barrier in Hong Kong to Promote AI Governance Innovation
PCPD has launched a series of guidelines since 2021, including the "Ethical Standards for the Development and Use of Artificial Intelligence," "Artificial Intelligence (AI): A Model Framework for Personal Data Protection" (the "Model Framework"), the "Guidelines for Employees Using Generative AI" ("Guidelist"), "Combating the Misuse of AI Deepfake Technology: A Tip for Schools and Parents" ("Tip Pack"), and "Ten Tips for Self-Protection with AI Chatbots." Among them, the Model Framework, Guidelist List, and Tips have all won the Asia-Pacific GovMedia Award, recognizing them as influential public sector projects in the Asia-Pacific region and globally.
11 Aug 2026
PIPL China Simplifies Compliance for Small-Scale Personal Information Handlers
On 22 July 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (Simplified Measures), which will take effect on 1 September 2026.
China issues new rules relaxing compliance burdens for small-scale personal information handlers processing personal information of fewer than 100,000 individuals.
Qualified small-scale handlers benefit from simplified notification and consent mechanisms, extended compliance audit cycles, standardised self-assessment templates, and platform-level privacy compliance.
New rules introduce clear grounds for penalty exemption and mitigation for minor, first-time, or promptly corrected violations.
Businesses should assess whether subsidiaries in China fall within scope of small-scale handlers and consider practical steps to benefit from relaxations.
4 Aug 2026
[Join us on 18 Sep 2026] - ADCC Ice-cream & Promotion Trunk on Campus (first note)
Please mark your calendar for the day.
To enhance public awareness of the latest scam tactics and strengthen public-private collaboration in combating scam, the Anti-Deception Coordination Centre (ADCC) of the Commercial Crime Bureau will have their Anti-Scam promotional trunk and ice-cream van coming to HKU campus.
3 Aug 2026
Anthropic says its AI models hacked 3 organizations during testing
Anthropic said its AI models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company.
Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs.
3 Aug 2026
HK PCPD Office Wins Governance Project of the Year and Outreach Project of the Year at Asia-Pacific Awards
“Hong Kong Governance Project of the Year – Regulatory” and “Hong Kong Outreach Project of the Year – Regulatory” awards, in recognition of its guidance on the “Checklist on Guidelines for the Use of Generative AI by Employees” and the effect of its outreach efforts relating to “Abuse of AI Deepfakes: Toolkit for Schools and Parents”, respectively.
The “Governance Project of the Year – Regulatory” award recognises exceptional initiatives or practices of public organisations.
Published in March 2025, the “Checklist on Guidelines for the Use of Generative AI by Employees” (Guidelines) provide a practical checklist to assist organisations in developing internal policies or guidelines on the use of generative artificial intelligence (AI) by employees at work, while complying with the requirements of the Personal Data (Privacy) Ordinance (PDPO).
https://www.pcpd.org.hk/english/resources_centre/publications/files/guidelines_ai_employees.pdf
“Hong Kong Outreach Project of the Year – Regulatory” award celebrates initiatives that excel in reaching and engaging their target audiences, fostering positive relationships, and making long term and meaningful impact on communities or stakeholders.
Published in December 2025, the “Abuse of AI Deepfakes: Toolkit for Schools and Parents” (Toolkit) provides practical advice to schools and parents to help them prevent and handle deepfake incidents involving children and young people, while safeguarding their privacy in relation to personal data.
https://www.pcpd.org.hk/english/resources_centre/publications/files/ai_deepfake.pdf
30 Jul 2026
SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack
The Securities and Futures Commission (SFC) has reprimanded and fined Luk Fook Securities (HK) Limited (LFSHK) $2.1 million for failing to implement adequate and effective cybersecurity control measures, which might have contributed to its failure to withstand a ransomware attack and led to a delay of approximately three weeks in fully recovering its systems from the cyberattack.
The disruption from the 19 September 2022 ransomware attack on LFSHK’s critical IT infrastructure was sweeping, affecting file servers, domain controllers, email servers, trading application servers, and accounting servers. LFSHK restored its system in phases, and the process was not complete until 7 October 2022.
25 Jul 2026
Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records
A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records.
The alleged breach has not been independently verified, and Decathlon has not publicly confirmed that its systems or customer data were compromised.
The actor claims the Decathlon database includes: Customer IDs, Email addresses, Password hashes, First and last names, Dates of birth, Phone numbers, Street addresses, cities, postal codes, regions, and countries, Account status information, Email-verification status, Preferred store and store-preference data, Favorite sports and purchase-related fields.
24 Jul 2026
AI Pentest Checker-Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities, and create reports.
According to Cato reports, Trim first appeared on a Russian-language cybercrime forum on March 13, 2026, where he shared methods claimed to bypass Claude Opus safety controls.
24 Jul 2026
OnTrac (supporting 70% of the US population) notifies customers of data breach after network hack
OnTrac parcel delivery company is informing that hackers breached its corporate network and may have accessed personal details belonging to its customers. The incident was detected on March 23, and an internal investigation revealed that the attacker accessed certain files between March 20 and 22.
Apart from names, it is unclear what type of information was exposed, as the company redacted the data elements in the notification sample shared with authorities.
In response to the security incident, OnTrac contracted a third-party specialist to help determine the scope of the breach and took steps to “ensure the data described above was re-secured and not distributed.”
23 Jul 2026
Firm hacked by rogue OpenAI models says it is 'a wake-up call'
The co-founder of Hugging Face was hacked after some of OpenAI's most advanced artificial intelligence (AI) models went rogue. Thomas Wolf told BBC's Newsday radio programme that "this will be one of the most common types of cyber attacks we see", but that most firms are not aware that the "game has changed".
The ChatGPT-maker said its AI models broke out of a secure test environment during a trial and launched a cyber attack. The firm said the incident was "unprecedented" and that it was conducting an investigation with Hugging Face.
14 Jul 2026
PCPD Academy- 22July_Recent Court and Administrative Appeals Board Decisions
Date: 22 July 2026 (Wed)
Time: 2:15pm – 5:15pm
Language: English
Format: OnlineKey
Take-aways:Overview of key provisions of the Ordinance and the Data Protection Principles
In-depth discussion of major data privacy issues raised in recent decisions of Hong Kong courts and the Board.
Decisions made by courts and the Board in relation to:
- Interpretation of the definition of “personal data” under the Ordinance
- Circumstances in which collection of personal data may be considered excessive, unfair or unlawful
- Personal Information Collection Statement
- Use of personal data and application of exemptions under the Ordinance
- Handling of data access requests and charging of data access request fee
- Requirements on data retention and data security
- Right to compensation against a data user for damage suffered by reason of a contravention of a requirement under the Ordinance: Tsang Po Mann v Tsang Ka Kit and Anor (DCCJ 4891/2016) [2021] 1 HKLRD 1301
6 Jul 2026
Cyberattack on Hong Kong’s Shun Hing Group affects data of 1 million people
The Office of the Privacy Commissioner for Personal Data said on Thursday that it had launched an investigation into the incident after receiving a data breach report from Shun Hing Group on March 23 (can also refer to earlier post in news in DPO website).
Personal information of more than 920,000 customers, including their names, addresses and email addresses, involved in breach.
2 Jul 2026
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.
In breach notifications filed with the California Attorney General's Office, Oracle says these data theft attacks impacted hundreds of companies and that Nissan was specifically targeted in the campaign.
"Nissan Americas uses Oracle PeopleSoft software to manage employee information, including payroll, tax administration, and other personnel records," reads the breach notification.
25 Jun 2026
PCPD July Professional Workshops-8 Jul DAR_22 Jul AAB
Data Access Request
There are stringent requirements for compliance with a DAR under the Personal Data (Privacy) Ordinance. Dealing properly and effectively with a DAR is a challenge for many organisations. This workshop will examine in details those requirements and offer guidance on the handling of a DAR.
https://www.pcpd.org.hk/english/education_training/organisations/workshops/workshop_outlines.html#3
Administrative Appeals Board
The Board is the statutory body that hears and determines appeals against the decisions of the Privacy Commissioner for Personal Data (“the Commissioner”) by a complainant or the relevant data user complained against. The High Court of Hong Kong deals with magistracy appeals against criminal offences committed under the Ordinance. This workshop (to be conducted by experienced lawyers from the office of the Commissioner) will examine some recent decisions which serve as legal authorities and practical examples in solving problems frequently encountered in compliance work.
https://www.pcpd.org.hk/english/education_training/organisations/workshops/workshop_outlines.html#15
22 Jun 2026
[Join us on 30 June 2026] - PCPD-HKU Joint Data Protection Event "The New AI Era: Data Protection & Cybersecurity in Higher Education" - 2nd reminder
"The New AI Era: Data Protection & Cybersecurity in Higher Education" - first post on 11 May
Our distinguished speakers / panelist include:
Mr. Alex Chan, Assistant Privacy Commissioner, Office of the Privacy Commissioner for Personal Data (PCPD)
Mr. Raymond Lam, Chief Superintendent, Cyber Security and Technology Crime Bureau (CSTCB)
Mr. Otto Lee, Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT)
Mr. Leonard Chan, MH, Founding Chairman, Hong Kong Innovative Technology Development Association (HKITDA)
Prof. S.M. Yiu, Professor, School of Computing & Data Science, The University of Hong Kong (HKU)
In addition, we will have "the Little Grape" as the special guest for the afternoon!
Talks at the events:
Navigating Data Privacy Risks in the Use of AI in Higher Education (by Mr. Alex CHAN)
Digital Resilience: The Industrialisation of Cybercrime (by Ms. Rachel HUI)
Cybersecurity in Higher Education: Trends, Threats & Defences (by Mr. Otto LEE)
Panel Topic: Innovation vs. Third-Party Risk: Balancing Progress and Privacy
Moderator: Mr. Leonard CHAN, MH
Panelists: Mr. Alex CHAN, Ms. Rachel HUI, Mr. Otto LEE, Prof. S.M. YIU
Registration:
For HKU staff: https://hkuems1.hku.hk/hkuems/ec_hdetail.aspx?ueid=106167
For Non-HKU members: https://hkuems1.hku.hk/hkuems/ec_hdetail.aspx?guest=Y&ueid=106169
22 Jun 2026
PCPD established the Hong Kong International Data Privacy Academy
The Hong Kong International Data Privacy Academy (“the Academy”) was officially launched on 16 June 2026 by the Honourable Mr Paul LAM Ting-kwok, GBS, SC, JP, the Secretary for Justice of the Government of the Hong Kong SAR, China, and other officiating guests during the 30th Anniversary Privacy Protection Summit of the Office of the Privacy Commissioner for Personal Data (“PCPD”).
The PCPD established the Academy to actively align with the Country’s 15th Five-Year Plan in supporting Hong Kong’s development as an international high-calibre talent hub and the Government’s policy under the “One Country, Two Systems” to leverage the distinctive advantages of enjoying strong support of the Motherland and being closely connected to the world. It also aims to support the formulation and implementation of the first Hong Kong’s Five-Year Plan by the HKSAR Government under the leadership of the Chief Executive, thereby integrating actively into and serving the overall national development.






![[Join us on 18 Sep 2026] - ADCC Ice-cream & Promotion Trunk on Campus](https://static.wixstatic.com/media/02d43d_9cba608ad97a48c2bada079739641e70~mv2.png/v1/fill/w_310,h_175,al_c,q_85,usm_0.66_1.00_0.01,enc_avif,quality_auto/Image-empty-state_edited.png)











![[Join us on 30 June 2026] - PCPD-HKU Joint Data Protection Event - "The New AI Era: Data Protection & Cybersecurity in Higher Education" - 2nd Reminder with changes (first post on 11 May)](https://static.wixstatic.com/media/02d43d_1fc1ccb01d06497dab89d67da27cdf0f~mv2.png/v1/fill/w_310,h_216,al_c,q_85,usm_0.66_1.00_0.01,enc_avif,quality_auto/Image-empty-state_edited.png)
