Advertisement

Editorial | Step up cybersecurity measures to prevent personal Hong Kong data leaks

  • Three serious Hong Kong government breaches in a week are an embarrassment and highlight need for public and private sectors to eliminate latest risks

Reading Time:2 minutes
Why you can trust SCMP
0
Ada Chung Lai-ling, Hong Kong’s privacy commissioner for personal data, at a Wan Chai press conference on a data leak investigation report. Photo: Yik Yeung-man

The prime responsibility of any organisation that collects, stores and uses people’s personal details is to take every step necessary to ensure the information is kept safe and secure. Successive Hong Kong government departments have, however, failed to honour this basic requirement, experiencing a series of embarrassing data leaks. It is an unacceptable state of affairs.

Details of three serious breaches were revealed last week. The Companies Registry leaked the data of 110,000 people, including names, passport and identity card numbers.

Personal information of 17,000 residents collected during the pandemic in 2022 was exposed by the Electrical and Mechanical Services Department following an error in the password login system. And the Consumer Council breached privacy rules when details of more than 170 people were leaked in a cybersecurity attack.

This week, the Fire Services Department joined the list, revealing a potential data leak involving details of more than 5,000 staff and residents.

Ada Chung Lai-ling, Hong Kong’s personal data privacy commissioner, at a press conference on a data leak investigation report in Wan Chai. Details of three serious breaches were revealed last week. Photo: Yik Yeung-man
Ada Chung Lai-ling, Hong Kong’s personal data privacy commissioner, at a press conference on a data leak investigation report in Wan Chai. Details of three serious breaches were revealed last week. Photo: Yik Yeung-man

The blunders are part of a series of disturbing breaches in recent months in the public and private sectors. Some were due to human error and others the result of a vulnerable system.

There is an urgent need for porous defences to be strengthened. Our privacy is at stake.

Advertisement