Schedule 1 DPP4 Data Security Principle requires all practicable steps shall be taken to ensure that personal data held by a data user is protected against unauthorised or accidental access, processing, erasure, loss or use. Practicable steps consider: kind of data + harm if compromised, physical location, security measures incorporated in equipment, measures for ensuring integrity prudence + competence of persons with access, measures for ensuring secure transmission. If a data user engages a data processor (within or outside Hong Kong) to process data on its behalf, the data user must adopt contractual or other means to prevent unauthorised + accidental access + processing + erasure + loss + use of the data transferred to the processor. PCPD Guidance on Data Security 2022 + 2024 supplement updates: encryption + access control + network security + endpoint + vulnerability + patching + backup + incident response + secure disposal + audit logs + privileged access + multi-factor authentication + cloud security. Voluntary Data Breach Notification regime via PCPD Data Breach Notification Form (currently): notify affected data subjects + PCPD as soon as practicable, contain the breach, remediate + preserve evidence, post-incident review. 2024-2025 pending: mandatory breach notification with statutory timeframe + thresholds + administrative fines (PCPD enforcement reform consultation 2024). HK PDPO DPP4 + processor oversight + voluntary breach notification + pending mandatory regime applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.