[codicts-css-switcher id=”346″]

Global Law Experts Logo
cybercrime law hong kong

Our Expert in Hong Kong

Hong Kong Cybercrime Reform 2026: What Individuals and Businesses Must Do Now

By Global Law Experts
– posted 55 minutes ago

Hong Kong’s cybercrime law landscape shifted decisively in early 2026 when the Law Reform Commission of Hong Kong published its report on cyber‑dependent crimes on 9 January 2026, recommending the creation of five new offence categories targeting conduct that directly attacks computer systems and data. In parallel, the Evidence (Amendment) Bill and its Implementation Rules (LN27) have expanded the framework for how digital evidence is obtained, preserved, and admitted in criminal proceedings. These reforms carry extra‑territorial implications, meaning businesses operating servers outside Hong Kong, and individuals acting from abroad, face materially greater exposure to investigation and prosecution.

For compliance officers, in‑house counsel, and anyone who stores or processes data connected to Hong Kong, understanding these changes is no longer optional; it is an immediate operational priority.

Three things to do right now:

  • Review and update your incident response plan to address the new cyber‑dependent crime categories and digital evidence preservation duties.
  • Brief your IT team and board on the expanded police powers over device access and compelled production of data.
  • Engage external criminal counsel before an investigation begins, not after.

What the LRC Recommended, Cyber‑Dependent Crimes Explained

The Law Reform Commission of Hong Kong defines “cyber‑dependent crimes” as offences that can only be committed using a computer, computer network, or other information and communications technology device. These are distinct from “cyber‑enabled crimes”, traditional offences such as fraud that merely use technology as a tool. The LRC’s January 2026 report recommended legislating five specific categories of cyber‑dependent crime to close gaps in Hong Kong’s existing statutory framework, which currently relies on provisions scattered across the Crimes Ordinance (Cap 200) and the Telecommunications Ordinance (Cap 106).

The Five Categories of Cyber‑Dependent Crime

The LRC recommendations group offences into five distinct categories, each targeting a specific type of conduct that harms or compromises computer systems and data:

  • Illegal access to a computer system. Gaining unauthorised entry to a program or data held on a computer, regardless of whether damage results.
  • Illegal interference with a computer system. Disrupting or degrading the functioning of a system, what is commonly described as a distributed denial‑of‑service (DDoS) attack or similar sabotage.
  • Illegal interception of computer data. Capturing data transmissions without authorisation, including packet‑sniffing and man‑in‑the‑middle attacks.
  • Illegal interference with computer data. Altering, deleting, or corrupting data stored on a system without authorisation, including ransomware deployment.
  • Making available or possessing a device or data for committing a crime. Creating, distributing, or holding malware, hacking tools, or stolen credentials with intent to use them in any of the above offences.

Recommended Penalties at a Glance

Offence category Typical activity Maximum penalty (LRC recommendation)
Illegal access to a computer system Unauthorised login, brute‑force credential attack Up to 14 years’ imprisonment for aggravated forms
Illegal interference with a computer system DDoS attacks, sabotaging critical infrastructure Up to 14 years’ imprisonment where serious harm results
Making available or possessing devices/data for crime Selling exploit kits, distributing ransomware payloads Up to 10 years’ imprisonment

Note: Penalties are as recommended by the LRC in its 9 January 2026 report. Legislative enactment may adjust these thresholds. Monitor the Department of Justice Gazette for final statutory text.

Evidence Amendment Bill, LN27 and New Investigative Powers

Running alongside the LRC’s substantive crime recommendations, the Evidence (Amendment) Bill and its subsidiary Implementation Rules (gazetted as LN27) reshape how investigators collect, handle, and present digital evidence in Hong Kong proceedings. Together, these instruments address long‑standing concerns about the admissibility of electronic records, chain‑of‑custody standards for device data, and the power of law enforcement to compel the production of encrypted material.

What LN27 Changes

The Implementation Rules introduced under LN27 provide operational detail on the procedures courts and investigators must follow when dealing with digital evidence in Hong Kong. Key changes include updated rules on the authentication of electronic records for admissibility purposes, standardised chain‑of‑custody requirements for seized digital devices, and clearer protocols for cross‑referencing metadata with substantive data content. The practical effect is that evidence previously challenged on procedural grounds may now survive scrutiny more consistently, and investigators have a more predictable roadmap for obtaining court orders.

Device Access and Compelled Decryption

Industry observers expect the combined effect of the evidence‑law amendments and LRC recommendations to significantly expand the circumstances under which police can seek court orders compelling the production of passwords, encryption keys, or decrypted data. While existing powers under the Crimes Ordinance already allow courts to order access to stored computer data, the new framework is likely to create more explicit statutory footholds for compelled decryption in cybercrime investigations. Individuals and companies should assume that encrypted devices and cloud‑stored data are within reach of a properly obtained warrant.

Preservation and Production Duties

The reforms reinforce duties on data custodians, whether corporate IT departments, cloud service providers, or individual device owners, to preserve data once they become aware of a potential investigation. Failure to preserve relevant digital evidence after receiving a lawful preservation request could itself attract liability. In practice, this means:

  • Automated deletion policies (such as 30‑day log rotation) must be paused the moment a legal hold is triggered.
  • Third‑party hosting agreements should include contractual provisions enabling rapid data freezes on instructions from Hong Kong counsel.
  • Any destruction of data after awareness of an investigation creates a serious risk of an obstruction or contempt finding.

Jurisdictional Exposure, Cross‑Border Reach and What It Means for You

One of the most significant elements of the LRC’s 2026 report is its recommendation that core cyber‑dependent offences carry extra‑territorial jurisdiction. The Commission proposed that Hong Kong courts should be able to prosecute an offence where any constituent element, the act, its effect, or the targeted system, has a sufficient connection to Hong Kong, even if the accused person and the computer are both located overseas.

Extra‑Territorial Jurisdiction, Practical Scenarios

For multinational companies and remote workers, this cross‑border cyber jurisdiction proposal creates new risk vectors. The table below maps three common scenarios to likely Hong Kong exposure.

Scenario Likely Hong Kong exposure Immediate business action
Company servers are in Singapore, but data of Hong Kong customers is compromised High, system interference or data interference affecting HK data may trigger jurisdiction Map all data flows touching Hong Kong; ensure incident response covers HK reporting
An employee working remotely from mainland China accesses HK systems without authorisation High, illegal access to a HK‑based system creates a direct jurisdictional link Tighten access controls; include cybercrime clauses in remote‑work policies
A foreign SaaS vendor’s platform is used to launch a DDoS attack on a Hong Kong target Moderate to high, the vendor may face production orders and investigation cooperation requests Review vendor contracts for cooperation clauses; appoint HK counsel for data requests

Early indications suggest that Hong Kong will pursue cross‑border cases selectively, focusing on conduct causing significant harm to critical infrastructure, financial systems, or large‑scale personal data sets connected to the territory.

How Cybercrime Investigations Work in Hong Kong, Step by Step

Understanding the mechanics of cybercrime investigations in Hong Kong is essential for any compliance programme. The Hong Kong Police Force’s Cyber Security and Technology Crime Bureau (CSTCB) is the lead investigative unit for technology‑related offences. Investigations typically follow a structured sequence.

Typical Investigation Timeline

  • Report or intelligence trigger. A complaint is filed at a police station, through the online e‑Report Centre, or via the Anti‑Scam Helpline (18222). Alternatively, CSTCB may initiate a probe based on its own intelligence or referrals from regulators.
  • Preliminary assessment and preservation. Officers assess the complaint, identify systems and data at risk, and may issue informal or formal preservation requests to ISPs, hosting providers, or corporate data custodians.
  • Warrant application and search. If evidence supports reasonable suspicion, police apply to a magistrate for a search warrant. Search warrants may authorise seizure of devices, imaging of hard drives, and extraction of cloud‑stored data.
  • Arrest and interview. Suspects are arrested and cautioned. The right to legal representation applies, any person arrested should exercise it immediately.
  • Charge or release. Police decide whether to charge (referral to the Department of Justice for prosecution) or release with or without conditions. Complex cyber cases may involve extended investigation periods before charge.

Your Rights During Search and Seizure

Under existing Hong Kong law, individuals have the right to request sight of the search warrant before permitting entry, to note the names and identification numbers of attending officers, and to contact a solicitor. Consenting to voluntary device unlocking is not mandatory absent a court order specifically compelling decryption. These procedural safeguards remain in place under the 2026 reforms.

Business Cyber Compliance Checklist, 12 Immediate and Medium‑Term Tasks

The reforms demand a structured compliance response. The following checklist, sequenced by priority, provides a roadmap for boards, compliance officers, and IT leaders aiming to achieve business cyber compliance ahead of legislative enactment.

  1. Adopt or update a cyber incident response plan. Ensure it references the new offence categories and defines escalation triggers specific to Hong Kong cybercrime law.
  2. Implement evidence preservation policies. Suspend automated log deletion when a legal hold is triggered; document procedures in writing.
  3. Create a legal hold playbook. Define who can issue a hold, how IT is notified, and what records must be frozen.
  4. Review device and password management policies. Ensure access logs are retained and that multi‑factor authentication is enforced across critical systems.
  5. Audit vendor and cloud contracts. Insert clauses requiring cooperation with Hong Kong e‑discovery and preservation orders.
  6. Map cross‑border data flows. Identify every data set that touches Hong Kong, customer data, employee data, system logs hosted overseas.
  7. Define reporting and notification triggers. Know when to report to the HKPF, the PCPD, and sector regulators (SFC, HKMA, CA) within required timeframes.
  8. Prepare a communications plan. Draft template statements for internal and external stakeholders in the event of a cyber incident or police investigation.
  9. Train staff. Conduct scenario‑based training covering the new offence categories, evidence handling, and what to do when police make contact.
  10. Appoint external counsel now. Pre‑agree engagement terms with a Hong Kong criminal solicitor experienced in cybercrime, do not wait until an investigation begins.
  11. Review cyber insurance coverage. Confirm that your policy responds to criminal investigation defence costs and digital forensics.
  12. Establish a board reporting template. Ensure the board receives quarterly updates on cyber risk posture and investigation readiness.

Reporting Obligations and Timelines by Entity Type

Entity type What to report / when Immediate action (first 24–72 hrs)
SME / private company Significant system interference, data breach affecting personal data, or evidence of criminal intrusion, report to HKPF if criminal element suspected; PCPD for personal data breach as required Preserve images of affected systems; notify internal IT and legal; engage external forensic counsel; document timeline
Listed company / regulated entity Same as SME plus regulator notification obligations (sector specific: SFC, HKMA, CA). Follow securities disclosure rules Activate board reporting; notify regulator, legal, and communications teams; secure evidence and preserve chain of custody
Individual / consumer Report scam or attack to Hong Kong Police (nearest station or online) and Anti‑Scam Helpline (18222) if victim Preserve screenshots and logs; avoid further interactions with attackers; seek legal advice if police make contact

Practical Steps for Individuals, If Police Contact You or Want Device Access

Individuals in Hong Kong face heightened exposure under the 2026 cybercrime reforms, whether as suspects, witnesses, or data custodians. The steps below provide a structured response framework.

Before Police Arrive

  • Do not delete, modify, or factory‑reset any device. Destruction of evidence after becoming aware of an investigation carries serious legal consequences.
  • Lock your device screen and note the current date and time, this establishes a baseline for any subsequent forensic imaging.
  • Have the name and contact number of a criminal solicitor readily accessible. If you do not have counsel, identify one in advance.

During a Search

  • Ask to see the search warrant. Note the warrant number, the issuing magistrate’s name, and the scope of items authorised for seizure.
  • Record the names and identification numbers of all attending officers.
  • State clearly: “I want to speak to a lawyer before responding to any questions or requests regarding my devices.”
  • Do not voluntarily unlock or provide passwords to any device unless a specific court order compels you to do so. Voluntary consent is not the same as a legal obligation.
  • Observe what items are seized and request a copy of the seizure record before officers depart.

After Police Contact

  • Write down everything you remember about the encounter immediately, times, names, what was said, what was taken.
  • Contact your solicitor and provide the seizure record and warrant details.
  • Preserve any remaining logs, emails, or backup data that relate to the matter. Do not communicate about the investigation over unencrypted channels until advised by counsel.

Incident Handling Templates and Evidence Checklist

Preparation is the difference between an orderly response and a crisis. The templates below can be adapted to your organisation’s size and sector. For businesses reviewing their digital evidence obligations in other jurisdictions, similar incident reporting procedures offer a useful reference point.

Incident Timeline Template

  • Date / time of detection: Record when the incident was first identified and by whom.
  • Nature of incident: Classify against the five LRC categories (access, system interference, interception, data interference, device misuse).
  • Systems affected: List all hardware, software, cloud services, and data sets involved.
  • Preservation actions taken: Document every step, system images, log freezes, backup snapshots, with timestamps.
  • Notifications issued: Record when internal legal, IT, management, police, and regulators were notified.

Sample Legal Hold Notice (Internal)

“Effective immediately, all employees must preserve and refrain from deleting, altering, or overwriting any data, documents, communications, or system logs that may be relevant to [describe incident or investigation scope]. This includes emails, instant messages, database records, access logs, and backup media. Automated deletion schedules must be suspended for all affected systems. Direct any questions to [Legal Department contact].”

Sample Wording, Responding to a Police Data Request

“We acknowledge receipt of your request dated [date] and are reviewing it with our legal advisers. We will respond within the timeframe specified. In the meantime, we have taken steps to preserve all data that may fall within the scope of the request. Please direct further correspondence to [external counsel name and contact details].”

What to Do Next, When to Call Counsel

Call a criminal solicitor immediately if any of the following apply:

  • You have received a police visit, phone call, or written request for information related to a cyber incident.
  • Your organisation has detected a system intrusion that may involve conduct falling within the five LRC offence categories.
  • You are uncertain whether your existing data handling practices comply with the preservation duties under the Evidence Amendment framework.
  • You need to map your cross‑border data exposure to assess jurisdictional risk under the proposed extra‑territorial provisions.

For broader context on regulatory changes affecting businesses and individuals in Hong Kong, see our guide to Hong Kong immigration changes in 2026. For estate and succession planning alongside criminal risk management, our directory of wills and estates lawyers in Hong Kong provides a starting point.

Conclusion, Cybercrime Law Hong Kong in 2026 and Beyond

The 2026 cybercrime reforms represent the most significant overhaul of Hong Kong’s computer crime framework in over two decades. The LRC’s five recommended offence categories close long‑standing gaps, while the Evidence Amendment Bill and LN27 Implementation Rules equip investigators with modernised tools for digital evidence collection. For businesses, the message is clear: compliance infrastructure must be built now, before legislation is enacted, to avoid being caught unprepared. For individuals, understanding your rights during a search, and exercising them calmly, is the single most important protective step available. As the legislative process advances, this article will be updated to reflect enacted provisions and commencement dates.

Practitioners and compliance teams should monitor the Department of Justice and Gazette publications for final statutory text and keep cybercrime law Hong Kong firmly on the board agenda.

Last reviewed: 1 August 2026. This article will be updated when the government introduces the relevant bill to the Legislative Council.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Emily Au at Emily Au Solicitor, a member of the Global Law Experts network.

Sources

  1. Law Reform Commission of Hong Kong, Cyber‑Dependent Crimes Report
  2. Hong Kong Government Press Release, LRC Report on Cyber‑Dependent Crimes (9 January 2026)
  3. Hong Kong Police Force, Cyber Security and Technology Crime Bureau
  4. Hong Kong e‑Legislation
  5. Office of the Privacy Commissioner for Personal Data, Hong Kong
  6. Department of Justice, Hong Kong SAR

FAQs

What are "cyber‑dependent crimes" under the 2026 recommendations?
The Law Reform Commission of Hong Kong defines cyber‑dependent crimes as offences that primarily target computer systems and data. The five recommended categories are illegal access, system interference, data interference, interception, and misuse of devices such as malware or hacking tools.
The LRC recommended extra‑territorial jurisdiction for core cyber‑dependent offences where any constituent element, the act, its effect, or the targeted system, has a sufficient connection to Hong Kong. This increases exposure for companies and individuals operating outside the territory.
The Evidence (Amendment) Bill and Implementation Rules (LN27) update admissibility standards for electronic records and reinforce preservation duties. The likely practical effect will be more explicit statutory authority for courts to order compelled production of encrypted data, subject to warrant and procedural safeguards.
Start with an incident response plan, legal hold procedures, evidence preservation templates, staff training on the new offence categories, cloud vendor contract reviews, and a pre‑agreed engagement with external criminal counsel experienced in Hong Kong cybercrime law.
Politely request to see a warrant. Ask for time to contact a solicitor. Do not provide passwords or unlock devices voluntarily unless a specific court order compels you to do so. Record officer details and preserve the device in its current state.
If personal data is compromised, the guidance of the Office of the Privacy Commissioner for Personal Data applies. Data users should assess whether a breach notification is required under the Personal Data (Privacy) Ordinance and follow the PCPD’s recommended best‑practice notification process.
The LRC recommendations require legislative action by the government and passage through the Legislative Council. Some evidence‑law elements via LN27 may become operational sooner. Track the Department of Justice Gazette for commencement notices.
how to change child's name on birth certificate in kenya
By Global Law Experts

posted 33 minutes ago

what are the requirements for a pledge to be valid?
By Global Law Experts

posted 4 hours ago

Company vs Sole Trader Cyprus

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Join
who are already getting the benefits
0

Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.

Naturally you can unsubscribe at any time.

About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Global Law Experts App

Now Available on the App & Google Play Stores.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Contact Us

Stay Informed

Join Mailing List
About Us

Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.

Social Posts
[wp_social_ninja id="50714" platform="instagram"]
[codicts-social-feeds platform="instagram" url="https://www.instagram.com/globallawexperts/" template="carousel" results_limit="10" header="false" column_count="1"]

See More:

Global Law Experts App

Now Available on the App & Google Play Stores.

Contact Us

Stay Informed

GLE

Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Hong Kong Cybercrime Reform 2026: What Individuals and Businesses Must Do Now

Send welcome message

Custom Message