Description

Closed PCPD Investigation into ZA Bank Limited to Ensure Data Security

On 9 October 2023, the Office of the Privacy Commissioner for Personal Data (PCPD) Hong Kong closed its investigation into ZA Bank Limited, Hong Kong's first virtual bank, concerning compliance with data protection laws. The PDPC's investigation found that ZA Bank complies with data protection principles for most parts, but it recommended several improvements, such as strengthening data processor management, enhancing data loss prevention system monitoring, limiting staff access to customer data, centralizing internal policies on data handling, and regularly reviewing the personal data system for better customer data protection.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Data protection regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies), other service provider
Implementation Level
national
Government Branch
executive
Government Body
data protection authority

Complete timeline of this policy change

Hide details
2023-06-30
under deliberation

On 30 June 2023, the Office of the Privacy Commissioner for Personal Data (PCPD) Hong Kong opened i…

2023-10-09
in force

On 9 October 2023, the Office of the Privacy Commissioner for Personal Data (PCPD) Hong Kong closed…