ANALYSISMEMBER

Hong Kong's Critical Infrastructure Ordinance provides opportunities for privacy professionals

Published
Subscribe to IAPP Newsletters

Contributors:

Peter Carberry

CIPP/E, CIPP/US, CIPM, FIP

Senior information governance officer

MMU

Editor's note: The IAPP is policy neutral. We publish contributed opinion and analysis pieces to enable our members to hear a broad spectrum of views in our domains.

Beginning 1 Jan. 2026, Hong Kong's Protection of Critical Infrastructures (Computer Systems) Ordinance, comparable to the EU NIS2 Directive and the U.K.'s forthcoming Cyber Security and Resilience Bill, will come into force. 

The ordinance will regulate critical infrastructure operators, obliging them to apply prescriptive organizational, preventative and incident reporting and response standards to protect computer systems that support critical infrastructure.

While the CI Ordinance is not in itself a privacy regulation, it was passed in early 2025, shortly after the Office of the Privacy Commissioner for Personal Data reported a roughly 30% increase in data breach notifications, and brings with it implications for privacy practitioners. 

Transitioning from principles to prescriptions

The current prevailing privacy law, the Personal Data (Privacy) Ordinance, developed originally with reference to the Organisation for Economic Co-operation and Development's Privacy Guidelines and the EU Data Protection Directive, is less prescriptive than not only the EU General Data Protection Regulation but also neighboring jurisdictions in the Greater Bay Area. In the regulator's own words, the principles of the PDPO are not "not couched in definitive terms."

The CI Ordinance, by contrast, draws closer parallels with regulations on critical infrastructure in mainland China and Macao, highlighting recent efforts to achieve greater regulatory convergence in the region. As such, a detailed look at the ordinance may already point to future regulatory convergence in the GBA and a more prescriptive environment for data protection in Hong Kong.

The new dynamics of breach reporting

Contributors:

Peter Carberry

CIPP/E, CIPP/US, CIPM, FIP

Senior information governance officer

MMU

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership