Next Generation Partners

Leading Associates

Firms To Watch: Data protection and cyber security

Eversheds Sutherland‘s practice lies within its technology group, led by Rhys McWhirter. The group is often engaged in data transfer assistance in addition to a range of cybersecurity work.

Data protection and cyber security in Hong Kong

DLA Piper

In 2024, DLA Piper has seen a growing number of cyber incidents brought on by malware, phishing, and similar incidents, and excels in handling these type of matters. Advising on the regulatory oversight of data flows also falls within the scope of the group’s work. The team’s extensive client list ranges from large conglomerates such as Hilton to logistics companies such as OmniLogistics. Carolyn Bigg heads up the team, and has a strong track record of being involved in and managing data protection compliance programmes and cyber incidents throughout the Greater China region. Senior associate Venus Cheung is well versed in data protection compliance, and is able to assist clients with cybersecurity incidents and risk management.

Responsables de la pratique:

Carolyn Bigg


Autres avocats clés:

Venus Cheung


Principaux clients

Standard Chartered Bank


IHG


Hilton


Merlin


Stripe


Logitech


3M


Four Seasons Hotels


Cathay Pacific


Porsche


BASF


Chanel


Principaux dossiers


  • Advising Standard Chartered Bank on numerous critical global data compliance projects, including review of key policies and standards on data sovereignty, data conduct and data privacy.
  • Assisting AIG with a number of data protection compliance programmes across Asia Pacific and globally.
  • Advising Four Seasons on this new client on Greater China and broader Asia data protection compliance projects, focusing on consumer data management and cross-border data transfers.

Hogan Lovells

The Hogan Lovells data privacy and cybersecurity team offers clients a one-stop shop for all areas of data protection and cybersecurity compliance, with advice spanning from the acquisition of personal data, to protection issues arising from online data capture. The scale of the group’s work continues to increase, evidenced by a highlight for the team in 2024 which was the largest tech transformation project in Hong Kong. Mark Parsons oversees the practice, and counts high profile clients including the Hong Kong Exchange among his varied client base. Additional key team members include Tommy Liu who provides ‘very technical and commercially-minded advice‘ for clients in a variety of sectors, including TMT and financial services, and concentrates on strategic transaction structuring and complex contractual arrangements.

Responsables de la pratique:

Mark Parsons


Autres avocats clés:

Eugene Low; Tommy Liu; Catharine Lau


Les références

‘The team are our go-to lawyers for all data privacy compliance matters in Greater China and across Asia-Pacific. They understand their clients and the markets well and the quality of their advice is truly top-notch.’

‘Tommy Liu is able to provide very technical and commercially-minded advice. He has an in-depth understanding of the latest developments and a strong knowledge of our business. Always delivers prompt and effective advice. ’

‘Mark Parsons is very knowledgeable and experienced in the areas of data privacy, cyber security and technology and outsourcing. He understands complex commercial dynamic and is able to work with large project teams well. He’s been advising on many banking industry initiatives so his market insight is invaluable. Pricing is competitive, partly because of his deep experience which helps to keep the advice/work focused and efficient.’

Principaux clients

Beijing Kuaishou Technology Co., Ltd. (“Kwai”)


The Hong Kong Association of Banks


HSBC


Hong Kong Exchanges and Clearing Limited


FTI Consulting


USANA Health Science Inc.


China International Capital Corporation


Mox Bank


Hong Kong Jockey Club


Principaux dossiers


  • Advised MPFA/eMPF Platform Company Limited on the terms of service that eMPF PC will be engaged by pension trustees and the operating rules for the platform, as well as various ancillary commercial and regulatory issues.
  • Advising a European-headquartered global corporate travel agency business on data protection aspects of the “zero-day” vulnerability exploit of the secure file transfer application (called MOVEit) impacting its vendor, Progress Software.
  • Advising ZEEKR on its regulatory and compliance issues and have assisted them in the drafting and reviewing agreements in EU, U.S and globally.

Bird & Bird

With a great deal of experience in data protection, Bird & Bird stands out for representing key technology companies with day to day issues such as international policies and handling security breaches, as well as assisting high profile clients in the banking industry. Indeed practice head Wilfred Ng, who ‘understands the nuances of regional implementation and risks prioritisation‘, utilises experience working for a large technology conglomerate and is able to advise on complex regulatory matters in the industry. The group operates in a cross practice manner, incorporating TMT, IP, and regulatory focused advice. the former of which is an area of expertise for Michelle Chan.

Responsables de la pratique:

Wilfred Ng


Autres avocats clés:

Michelle Chan.


Les références

‘The team has strong capabilities and expertise in the data protection and cybersecurity areas. They maintain an up-to-date inventory of applicable laws and regulations, and put clients at the forefront of their mind when circulating updates.’

‘Wilfred Ng’s passion for the area must be commended. He also takes great care of client’s needs and goes above and beyond expectation.’

‘Very responsive and proactive in detecting client’s business needs, with professional advice given with a quick turnaround.’

Principaux clients

Oaktree Capital (Hong Kong) Limited


Principaux dossiers


CMS Hong Kong LLP

CMS‘ data protection and cybersecurity practice sits within the firm’s wider TMT practice, and is therefore engaged in a number of entertainment industry. The group stands out for its ability to lean on an extremely large global network of law firms, leveraging this to assist clients with data protection and cyber security matters of a multi jurisdictional nature. Jonathan Chu has a history of advising on cyber security threats and employee theft of data, and privacy policies, and has a varied client roster which features household names such as Disney. Chu is well supported by senior associate and IP practitioner Mengyi Chen, who is adept at handling GDPR audit/compliance checks in the PRC.

Responsables de la pratique:

Jonathan Chu


Autres avocats clés:

Mengyi Chen


Principaux clients

Disney


Principaux dossiers


  • Advised a global leader in storage and information management services on its global data residency strategy.
  • Advised a Hong Kong-based conglomerate on various data privacy and cross border compliance matters.
  • Advised a global company offering media monitoring and analysis services on a transfer impact assessment for Hong Kong.

Kennedys

Despite working on large scale cross-border cyber incidents and data privacy advice, Kennedys is still able to adopt a ‘regional view when comes to data protection and cyber security which is useful for organisations with regional footprint‘. Such organisations include clients hailing from the financial services, healthcare, hospitality sectors, among others. Joanie Ko leads the team, offering clients assistance with cyber incident response services as well as data privacy advice. Nicholas Blackmore, who splits his time between Hong Kong and Melbourne, is extremely knowledgeable when it comes to IT law.

Responsables de la pratique:

Joanie Ko


Autres avocats clés:

Nicholas Blackmore


Les références

‘Kennedys have a regional view when comes to data protection and cyber security. This is useful for organisations with regional footprint. ’

‘Joanie Ko is a subject matter expert and always able to provide details that allow us to make an informed decision.’

King & Wood Mallesons

King & Wood Mallesons has acted in high profile regulatory reform mandates in the fintech space in 2024, most notably assisting with the Hong Kong government’s Digital Transformation Strategy and Fintech 2025 strategy. Additionally, the group has acted on cross-border data transfer and GDPR matters through the APAC region. Practice head Peter Bullock is an experienced data and cyber security lawyer, who is noted for his proficiency in the technology sector, characteristic of the wider group’s expertise in the FinTech sector, particularly Urszula McCormack who has a strong emerging technologies practice.

Responsables de la pratique:

Peter Bullock; Susan Ning


Autres avocats clés:

Urszula McCormack


Les références

‘Peter Bullock has been instrumental and very helpful. He is technically solid and always offers useful advice. Peter’s knowledge and experience in technology area definitely helps this practice a lot.’

‘Peter Bullock is a very experienced data and cyber security lawyer in the field, and his team is helpful and hardworking.’

Principaux clients

The Hong Kong Association of Banks


Hong Kong Science and Technology Parks Corporation


China Ping An Insurance Overseas (Holdings) Limited


The World Bank


L’Oreal (China) Co., Limited


The Icon Group


Principaux dossiers


  • Acted for the Hong Kong Association of Banks (HKAB) as lead counsel in supporting regulatory reforms in line with the Hong Kong Government’s Digital Transformation Strategy and the Fintech 2025 strategy of the Hong Kong Monetary Authority (HKMA).
  • Acted for The Hong Kong Government’s Hong Kong Science and Technology Parks Corporation in a joint initiative to launch a verification platform for cross-border data in order to facilitate cross-border activity between Hong Kong and Shenzhen in the Mainland of China, both key cities in China’s Greater Bay Area (GBA).
  • Acted for The World Bank as lead counsel to support the Ministry of Home Affairs of Indonesia to introduce e-KYC and an official digital ID system and/or trust framework (Digital Identity Project).

Linklaters

Linklaters navigates an ever changing data privacy landscape, working on an increasingly full gamut of data privacy and cybersecurity, including data privacy and cyber security issues in commercial and technology licensing agreements, as well as potential gaps in their data protection practices that clients may face. On the regulatory side, the group stands out for its regulatory work across Asia and beyond, including assisting with investigations by the PCPD. Practice head Albert Yuen, supported by associate and GDPR data privacy specialist Jasmine Yung, is key in this regard, benefitting from experience working at several international law firms across the APAC region.

Responsables de la pratique:

Albert Yuen


Autres avocats clés:

Jasmine Yung


Les références

‘Linklaters has assisted us on a gap analysis. From the initial scoping discussions, it was clear that the Linklaters team possessed deep, up-to-date knowledge of the latest privacy regulations, industry standards, and emerging best practices.’

‘What truly set Linklaters apart was their ability to translate complex legal and technical concepts into clear, actionable insights. Their final privacy gap analysis report not only highlighted the gaps we needed to address but also provided detailed recommendations on how to do so, including suggested policy updates, process improvements, and technology implementations.’

‘Throughout the engagement, the Linklaters team was responsive, collaborative, and deeply committed to understanding our unique business requirements. They worked closely with our internal privacy and compliance teams, fostering a seamless and productive partnership.’

Principaux clients

Citibank


Hong Kong Exchanges and Clearing Limited


CK Hutchison Holdings Limited


Microsoft


Principaux dossiers


  • Advised Harneys on the sale of its fiduciary business, Harneys Fiduciary, in a transaction backed by global private equity firm, Hillhouse.
  • Advised Hong Kong Exchanges and Clearing Limited on its digital transformation journey, including preparing terms and conditions for HKEX Synapse, a new integrated settlement platform, to complement the existing post-trade infrastructure for Northbound Stock Connect.
  • Advising Citibank on its cooperation with China Guangfa Bank and China Merchant Bank under the cross-boundary wealth management connect (WMC) scheme in the Greater Bay Area.

Mayer Brown

Mayer Brown operates internationally, having been been engaged in a high number of cyber breach cases globally in the past year, as well as providing clients with a range of privacy compliance advice and responses to data breaches. Gabriela Kennedy is the group’s leader, and has the ability to deal with national security and data security requirements, and data transfer advice, which are all important elements of the wider group’s workload.

Responsables de la pratique:

Gabriela Kennedy


Principaux clients

Zoom


Airport Authority Hong Kong


A number of insurance companies


Fung Group


Jardine Matheson & Company Ltd.


Warner Media


Scholastic


RPC

With ‘an abundance of experience in handling cyber breaches’ RPC is well versed in a range of matters including data transfer projects and cyber security matters, and boasts a growing regional practice in Asia. The group has also seen an uptick in work in the technology sector, and in data protection within FinTech such as virtual assets, digital banks and Web3. Practice head Jonathan Crompton is a cyber security expert to whom clients turn to reduce the damage caused by cyberattacks and other data breaches, and Ivan Chang counts high profile, global companies as key clients.

Responsables de la pratique:

Jonathan Crompton


Autres avocats clés:

Ivan Chang


Les références

‘A small but efficient team. Easy to work with and with an abundance of experience in handling cyber breaches.’

‘Jonathan Crompton can cover multiple angles in providing advice. There are often multiple stakeholders in dealing with a cyber breach and Jonathan and his team are helpful in pinpointing action items for different departments in the company and explaining key issues in their respective technical language.’

‘The team provides general guidance on cyber risk issues and shares best practices.’

Principaux clients

Chubb Insurance (Chubb Overseas Global)


Chubb Japan


ACE Insurance


Huatai Insurance


Markel


Munich Re


Principaux dossiers


  • Acting for leading insurers as cyber incident response manager for the Asia region.

Tanner De Witt

As well as acting in data privacy and data breach matters, Tanner De Witt has a strong regulatory practice, often focusing on assisting regulators with data breach matters, and working on many compliance matters in relation to data breaches for clients in a range of industries, including hospitality, manufacturing and education. Practice head Pádraig Walsh, who 'is intelligent, well-considered, strategic and thoughtful in his advice and dealings' displays a prowess in responding to data breaches and regulatory enquiries is an integral part of this. Elsewhere in the team, Tara Chan stands out at associate level for her work in the technology industry, from assisting start ups to large corporations.

Responsables de la pratique:

Padraig Walsh


Autres avocats clés:

Tara Chan


Les références

‘During our collaboration, we have seen nothing but excellence in their management of the client. The team is open in their communication and incredibly responsive to the client’s needs. Their grasp of the legal and practical aspects of the matters are what sets apart their team.’

‘Padraig Walsh is the standout out partner that we have worked with in this particular sector. Padraig is very approachable as well as being sound and eloquent in delivering his thoughts of the current matters he are facing. He is also very honest and open on the practicability of the issues, which is very helpful to find practicable solutions. ’

‘The team is well regarded and esteemed. They have strong capabilities and knowledge in privacy, data protection and cybersecurity. They have a strong client base. They are personable and approachable. ’

Principaux dossiers


  • Advised a Hong Kong securities firm on personal data privacy compliance, including reviewing and amending their Personal Information Collection Statement (PICS).
  • Advised a client on data breach notification obligations under local law for a multinational corporation’s Hong Kong subsidiary.
  • Assisted a large multinational retail enterprise with conducting a comprehensive data protection transfer impact and risk assessment for Hong Kong, aligning with EU data protection law requirements, and provided analysis on complex Hong Kong legislations,

Baker McKenzie

Baker McKenzie's data protection and cyber security practice is prominent in the media sphere, advising leading Chinese technology companies. Its varied workload encompasses cross-border data transfers, data protection compliance, data privacy disputes, cyber security and risk management. IP expert Isabella Liu and Lex Kuo head up the team alongside cyber fraud recovery group head Gary Seib, who is particularly reputed for complex arbitration and litigation related to cybersecurity and data recovery. Kuo acts in a range of regulatory and transactions projects relating to cybersecurity and data privacy.

Responsables de la pratique:

Isabella Liu; Lex Kuo; Gary Seib


Principaux dossiers


Deacons

Deacons is especially prominent in the hospitality, gaming, and IT sectors and is active across China, with offices in Beijing, Shanghai and Guangzhou, as well as having a strong presence in Hong Kong. The group is accomplished in drafting data processing agreements, and advising on data regulations across these jurisdictions, as well as privacy issues in advertising and marketing. Machiuanna Chu heads up the team, bringing a great deal of compliance expertise to clients and experience in investment transactions. Andy Yu and Dora Si are lauded for their ‘deep knowledge of data protection and a longstanding practice in this field.’

Responsables de la pratique:

Machiuanna Chu


Autres avocats clés:

Dora Si; Andy Yu; Charmaine Koo


Les références

‘Available and quick. Pragmatic and proactive solutions.’

‘Dora Si and Andy Yu have a deep knowledge of data protection and a longstanding practice in this field.’