Our Expert in Hong Kong
No results available
Hong Kong’s cybercrime law landscape shifted decisively in early 2026 when the Law Reform Commission of Hong Kong published its report on cyber‑dependent crimes on 9 January 2026, recommending the creation of five new offence categories targeting conduct that directly attacks computer systems and data. In parallel, the Evidence (Amendment) Bill and its Implementation Rules (LN27) have expanded the framework for how digital evidence is obtained, preserved, and admitted in criminal proceedings. These reforms carry extra‑territorial implications, meaning businesses operating servers outside Hong Kong, and individuals acting from abroad, face materially greater exposure to investigation and prosecution.
For compliance officers, in‑house counsel, and anyone who stores or processes data connected to Hong Kong, understanding these changes is no longer optional; it is an immediate operational priority.
Three things to do right now:
The Law Reform Commission of Hong Kong defines “cyber‑dependent crimes” as offences that can only be committed using a computer, computer network, or other information and communications technology device. These are distinct from “cyber‑enabled crimes”, traditional offences such as fraud that merely use technology as a tool. The LRC’s January 2026 report recommended legislating five specific categories of cyber‑dependent crime to close gaps in Hong Kong’s existing statutory framework, which currently relies on provisions scattered across the Crimes Ordinance (Cap 200) and the Telecommunications Ordinance (Cap 106).
The LRC recommendations group offences into five distinct categories, each targeting a specific type of conduct that harms or compromises computer systems and data:
| Offence category | Typical activity | Maximum penalty (LRC recommendation) |
|---|---|---|
| Illegal access to a computer system | Unauthorised login, brute‑force credential attack | Up to 14 years’ imprisonment for aggravated forms |
| Illegal interference with a computer system | DDoS attacks, sabotaging critical infrastructure | Up to 14 years’ imprisonment where serious harm results |
| Making available or possessing devices/data for crime | Selling exploit kits, distributing ransomware payloads | Up to 10 years’ imprisonment |
Note: Penalties are as recommended by the LRC in its 9 January 2026 report. Legislative enactment may adjust these thresholds. Monitor the Department of Justice Gazette for final statutory text.
Running alongside the LRC’s substantive crime recommendations, the Evidence (Amendment) Bill and its subsidiary Implementation Rules (gazetted as LN27) reshape how investigators collect, handle, and present digital evidence in Hong Kong proceedings. Together, these instruments address long‑standing concerns about the admissibility of electronic records, chain‑of‑custody standards for device data, and the power of law enforcement to compel the production of encrypted material.
The Implementation Rules introduced under LN27 provide operational detail on the procedures courts and investigators must follow when dealing with digital evidence in Hong Kong. Key changes include updated rules on the authentication of electronic records for admissibility purposes, standardised chain‑of‑custody requirements for seized digital devices, and clearer protocols for cross‑referencing metadata with substantive data content. The practical effect is that evidence previously challenged on procedural grounds may now survive scrutiny more consistently, and investigators have a more predictable roadmap for obtaining court orders.
Industry observers expect the combined effect of the evidence‑law amendments and LRC recommendations to significantly expand the circumstances under which police can seek court orders compelling the production of passwords, encryption keys, or decrypted data. While existing powers under the Crimes Ordinance already allow courts to order access to stored computer data, the new framework is likely to create more explicit statutory footholds for compelled decryption in cybercrime investigations. Individuals and companies should assume that encrypted devices and cloud‑stored data are within reach of a properly obtained warrant.
The reforms reinforce duties on data custodians, whether corporate IT departments, cloud service providers, or individual device owners, to preserve data once they become aware of a potential investigation. Failure to preserve relevant digital evidence after receiving a lawful preservation request could itself attract liability. In practice, this means:
One of the most significant elements of the LRC’s 2026 report is its recommendation that core cyber‑dependent offences carry extra‑territorial jurisdiction. The Commission proposed that Hong Kong courts should be able to prosecute an offence where any constituent element, the act, its effect, or the targeted system, has a sufficient connection to Hong Kong, even if the accused person and the computer are both located overseas.
For multinational companies and remote workers, this cross‑border cyber jurisdiction proposal creates new risk vectors. The table below maps three common scenarios to likely Hong Kong exposure.
| Scenario | Likely Hong Kong exposure | Immediate business action |
|---|---|---|
| Company servers are in Singapore, but data of Hong Kong customers is compromised | High, system interference or data interference affecting HK data may trigger jurisdiction | Map all data flows touching Hong Kong; ensure incident response covers HK reporting |
| An employee working remotely from mainland China accesses HK systems without authorisation | High, illegal access to a HK‑based system creates a direct jurisdictional link | Tighten access controls; include cybercrime clauses in remote‑work policies |
| A foreign SaaS vendor’s platform is used to launch a DDoS attack on a Hong Kong target | Moderate to high, the vendor may face production orders and investigation cooperation requests | Review vendor contracts for cooperation clauses; appoint HK counsel for data requests |
Early indications suggest that Hong Kong will pursue cross‑border cases selectively, focusing on conduct causing significant harm to critical infrastructure, financial systems, or large‑scale personal data sets connected to the territory.
Understanding the mechanics of cybercrime investigations in Hong Kong is essential for any compliance programme. The Hong Kong Police Force’s Cyber Security and Technology Crime Bureau (CSTCB) is the lead investigative unit for technology‑related offences. Investigations typically follow a structured sequence.
Under existing Hong Kong law, individuals have the right to request sight of the search warrant before permitting entry, to note the names and identification numbers of attending officers, and to contact a solicitor. Consenting to voluntary device unlocking is not mandatory absent a court order specifically compelling decryption. These procedural safeguards remain in place under the 2026 reforms.
The reforms demand a structured compliance response. The following checklist, sequenced by priority, provides a roadmap for boards, compliance officers, and IT leaders aiming to achieve business cyber compliance ahead of legislative enactment.
| Entity type | What to report / when | Immediate action (first 24–72 hrs) |
|---|---|---|
| SME / private company | Significant system interference, data breach affecting personal data, or evidence of criminal intrusion, report to HKPF if criminal element suspected; PCPD for personal data breach as required | Preserve images of affected systems; notify internal IT and legal; engage external forensic counsel; document timeline |
| Listed company / regulated entity | Same as SME plus regulator notification obligations (sector specific: SFC, HKMA, CA). Follow securities disclosure rules | Activate board reporting; notify regulator, legal, and communications teams; secure evidence and preserve chain of custody |
| Individual / consumer | Report scam or attack to Hong Kong Police (nearest station or online) and Anti‑Scam Helpline (18222) if victim | Preserve screenshots and logs; avoid further interactions with attackers; seek legal advice if police make contact |
Individuals in Hong Kong face heightened exposure under the 2026 cybercrime reforms, whether as suspects, witnesses, or data custodians. The steps below provide a structured response framework.
Preparation is the difference between an orderly response and a crisis. The templates below can be adapted to your organisation’s size and sector. For businesses reviewing their digital evidence obligations in other jurisdictions, similar incident reporting procedures offer a useful reference point.
“Effective immediately, all employees must preserve and refrain from deleting, altering, or overwriting any data, documents, communications, or system logs that may be relevant to [describe incident or investigation scope]. This includes emails, instant messages, database records, access logs, and backup media. Automated deletion schedules must be suspended for all affected systems. Direct any questions to [Legal Department contact].”
“We acknowledge receipt of your request dated [date] and are reviewing it with our legal advisers. We will respond within the timeframe specified. In the meantime, we have taken steps to preserve all data that may fall within the scope of the request. Please direct further correspondence to [external counsel name and contact details].”
Call a criminal solicitor immediately if any of the following apply:
For broader context on regulatory changes affecting businesses and individuals in Hong Kong, see our guide to Hong Kong immigration changes in 2026. For estate and succession planning alongside criminal risk management, our directory of wills and estates lawyers in Hong Kong provides a starting point.
The 2026 cybercrime reforms represent the most significant overhaul of Hong Kong’s computer crime framework in over two decades. The LRC’s five recommended offence categories close long‑standing gaps, while the Evidence Amendment Bill and LN27 Implementation Rules equip investigators with modernised tools for digital evidence collection. For businesses, the message is clear: compliance infrastructure must be built now, before legislation is enacted, to avoid being caught unprepared. For individuals, understanding your rights during a search, and exercising them calmly, is the single most important protective step available. As the legislative process advances, this article will be updated to reflect enacted provisions and commencement dates.
Practitioners and compliance teams should monitor the Department of Justice and Gazette publications for final statutory text and keep cybercrime law Hong Kong firmly on the board agenda.
Last reviewed: 1 August 2026. This article will be updated when the government introduces the relevant bill to the Legislative Council.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Emily Au at Emily Au Solicitor, a member of the Global Law Experts network.
posted 8 minutes ago
posted 33 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
No results available
Find the right Legal Expert for your business
Sign up for the latest legal briefings and news within Global Law Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message