News Updates

Find out all about our firm’s latest news updates below. To learn more about any individual item, please contact us here.

20 Nov 2020

Stevenson, Wong & Co. Ranked in Top 5 Largest Hong Kong Domestic Law Firms in ALB Asia 2020

Asian Legal Business (ALB) has just released the ranking of the Top 50 largest firms in Asia 2020. Stevenson, Wong & Co. has once again been listed as one of the largest Hong Kong domestic law firms for 5 consecutive years.

Established in 1978, Stevenson, Wong & Co. has more than 170 experienced lawyers and staff. Our aim is to provide clients with innovative and effective solutions for their personal or commercial problems with our local and international expertise. During these unprecedented times, we strive to ensure that communication with and services to our clients remain unaffected whilst balancing the emotional and physical well-being of our staff. We look ahead to 2021 with both caution and optimism as we continue to provide uninterrupted quality legal services to our clients.

Under these unprecedented times, we strive to ensure that communication and our services to clients remain unaffected whilst the emotional and physical well-being of our staff are just as important. As we look ahead to 2021, we will continue to enhance the quality of our services to our clients and all look forward to a better tomorrow.

We would also like to take this opportunity to congratulate our association firm, AllBright Law Offices, for being ranked as the top 4th largest domestic law firms across Asia.

About ALB and Asia’s Top 50

ALB is a leading law journal published by Thomson Reuters and is considered as one of the most influential legal media in Asia. Organised by ALB, Asia Top 50 aims to identify and rank the largest law firms across Asia by their size and number of lawyers.

For the full ranking, please click here.

Please contact Mr. Willy Cheng, Mr. Hank Lo or Ms. Catherine Por for any enquiries or further information.

13 Nov 2020

Application of the General Data Protection Regulation (“GDPR”) in Hong Kong

Apart from our Personal Data (Privacy) Ordinance (“PDPO”), the European Union’s GDPR which takes effect from 25 May 2018 is an important breakthrough in our data privacy legislation having considered its wide geographical application and the severe monetary penalty to be imposed, as shown in a recent Germany’s case that €35.3 million fine was imposed against an international retailer which adopted inappropriate measures in monitoring and processing the personal data of several hundred employees at one of its branch in Nuremberg.

What are the basic principles for processing data under GDPR?

The GDPR holds the controllers legally accountable for their compliance with various principles in lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.[1] For example, if a Hong Kong company has to discharge its duties on integrity and confidentiality, it has to implement and set up appropriate cyber and data security measures, thus, to add in more stringent data security contractual provisions in their contracts with the data processors.

To what extent is a Hong Kong company affected?

The GDPR has an extra-territorial effect. A Hong Kong company may need to comply with the GDPR if it:

1. has no establishment[2] in the EU but offers goods or services to, or monitor the behaviour of individuals in the EU territory; or

2. has an establishment in the EU, where personal data is processed in the context of the activities of the establishment, regardless of whether the data is actually processed within the EU. [3]

Both data controllers and data processors are regulated when they process the personal data collected from the relevant activities.

Positive Examples:

  • A Hong Kong online sales website, which uses English as language of instruction, has shipping destination to EU member countries
  • A Hong Kong app which provides a location service to tourists from Hong Kong when they are travelling in the EU territory
  • A EU group company which shares and transfers data to its HK subsidiary for storage and analysis

However, the processing activity related to offer of goods and services will only be caught when it intentionally targets individuals within the EU territory. If the processing relates to a service that is only offered to individuals outside the EU, but the service is not withdrawn when such individuals enter the EU territory, the related processing will not be subject to the GDPR.[4]

Negative Example:

  • A Hong Kong mobile news app which provides daily news updates in Chinese language to the Hong Kong users (who provide Hong Kong mobile number in subscribing for the services). The news update services are not subject to GDPR when the Hong Kong users enter the EU territory.

What are the consequences if a company data practice falls below the GDPR standard?

The administrative fines for contravention of the GDPR consist of two tiers, depending on the types of violations. The lower tier fine can be up to €10 million, or 2% of the total worldwide annual turnover of preceding financial year (in the case of an undertaking), whichever is higher.[5] The upper tier fine can be up to €20 million, or 4% of the total worldwide annual turnover of preceding financial year (in the case of an undertaking), whichever is higher.[6]

Under what circumstances will companies be penalised?

Lower tier fines may be imposed if the company fails to comply with any of the following (non-exhaustive list):

1. obtaining parental consent for processing of children’s personal data;

2. processing personal data anonymously if it is not necessary to identify the data subjects;

3. giving data breach notification;

4. appointing data protection officer; or

5. others.[7]

Upper tier fines may be imposed if the company fails to comply with the following (non-exhaustive list):

1. complying with the basic principles for processing, such as obtaining consent before processing;

2. complying with the data subjects’ rights, such as right to erasure, right to object to processing;

3. transferring personal data to a recipient in a third country through lawful mechanism; or

4. others.[8]

What is the difference between ‘data controllers and data processors’ under GDPR and ‘data users’ under PDPO?

To put it simply, ‘controller’ usually refers to the people or companies which decide on how and for what purpose the personal data will be processed, whereas ‘processor’ refers to the people or companies which process the data on behalf of the controller.[9] A company can act in both capacities.

Meanwhile, ‘data users’ is a general concept used in Hong Kong under the PDPO. It is a collective term which covers both ‘data controllers’ and ‘data processors’ as used in GDPR. While GDPR regulates both controllers and processors, processors are not directly regulated by the PDPO.

Consent is a lawful ground for data processing under GDPR. Is it different from the current practice of obtaining consent in Hong Kong?

In Hong Kong, the practice of customers’ ticking in a consent box is usually relevant to the company’s use of the personal data for direct marketing activities. Consent is not a pre-requisite for the collection of personal data in the first place, but it is required when the data collected will be used for a different purpose.[10]

Under the legal principles briefly mentioned above, several lawful grounds are available for companies to collect and process any personal data. The giving of consent is one of them and is probably the most common ground provided that it must be freely given, specific, informed, and unambiguous.[11]

There are other major corporate measures required under GDPR but not under PDPO

The following (non-exhaustive) measures are necessary in demonstrating compliance with GDPR but are not legally required under the PDPO:-

Data protection officer (“DPO”)

Company, regardless of its size, is required to appoint a DPO if its core activities consist of processing which systematically monitor data subjects on a large scale, such as online tracking, profiling (predictions about individual’s preferences), or processing a large scale of sensitive personal data.

DPO is responsible for monitoring the compliance with GDPR and contacting with the supervisory authority.

Data breach notification and remedial actions

The data controllers are required to give notification to the EU regulators of a data breach without undue delay (and where feasible, no later than 72 hours after having become aware of it), unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.

Other major corporate measures include (but not limited to):

  • Internal data protection policy
  • Data protection impact assessment
  • Planned IT system to cover the concept of privacy by design and by default

This article is co-authored by Ms. Milly Hung, Partner of Litigation Department, Mr. Michael Lau, the Associate and Mr. Calvin Lo, the Trainee Solicitor of Stevenson, Wong & Co. Due to the impact of the Covid-19 Pandemic, the potential effects of GDPR to the processing of the staff health data do raise concerns. If you have any problem in relation to this matter, please contact Ms. Milly Hung.

This article is for information purposes only. Its content does not constitute legal advice and should not be treated as such. Stevenson, Wong & Co. will not be liable to you in respect of any special, indirect or consequential loss or damage.



[1] See Article 5 of the GDPR
[2] Examples of an establishment: the presence of sales offices in the EU or an appointment of sales agents or representatives which promote, sell, advertise or market goods or services to individuals in the EU. See also Recital 22 for its definition.
[3] See Article 3 of the GDPR
[4] See p. 15 of European Data Protection Board’s Guidelines 3/2018 on the territorial scope of the GDPR (Version 2.1)
[5] See Article 83(4) of the GDPR
[6] See Article 83(5) of the GDPR
[7] See Articles 8, 11, 25 to 29, 41 42, 43 and 83(4) of the GDPR
[8] See Articles 5, 6, 7, 9, 12 to 22, 44 to 49, 58, 84(5) and Chapter IX of the GDPR
[9] See Recitals (7) and (8) of the GDPR
[10] See Data Protection Principle 3 of the PDPO
[11] See Article 4(11) of the GDPR

4 Nov 2020

Mr. Terence Lau, Senior Associate, Presents Webinar on IPO at Lex Omnibus

Mr. Terence Lau, Senior Associate of our Corporate Finance Department, hosted a CPD webinar for the topic “IPO101: An Overview of a Listing Offer” on 15 October 2020. In this course, Terence offered a detailed explanation of listing criteria as well as suitability for listing. The syllabus dissected IPO projects and included topics such as reorganisation, due diligence, prospectus drafting and share offer. The webinar also gave an overview of the IPO process pre-IPO investment.

Terence specialises in advising listing applicants, sponsors and underwriters in a broad range of corporate finance transactions, including initial public offering on The Stock Exchange of Hong Kong Limited, subsequent share issues, shares placement, rights issue, open offer and convertible bonds. Terence also advises listed issuers on regulatory and compliance matters.

Please contact Mr. Terence Lau for any enquiries or further information.

20 Oct 2020

Stevenson, Wong & Co. Named Finalist in 12 Categories at ALB Hong Kong Law Awards 2020

Stevenson, Wong & Co. is proud to have been shortlisted as a finalist in 12 categories at the 19th Annual Asian Legal Business (ALB) Hong Kong Law Awards 2020.

Nominations include:

  • BDO Award Matrimonial and Family Law Firm of the Year
  • Civil Litigation Law Firm of the Year
  • Criminal Litigation Law Firm of the Year
  • Dispute Resolution Boutique Law Firm of the Year
  • Labour and Employment Law Firm of the Year
  • Private Wealth Law Firm of the Year
  • Real Estate Law Firm of the Year
  • Regulation and Investigations Law Firm of the Year
  • Tax and Trusts Law Firm of the Year
  • Transactional Boutique Law Firm of the Year
  • Dispute Resolution Lawyer of the Year- Ms. Heidi Chui
  • Woman Lawyer of the Year (Law Firm)- Ms. Heidi Chui

The Hong Kong Law Awards is the biggest and longest-running awards presented by ALB. The awards aim to pay tribute to the outstanding performance of private practitioners and in-house teams from Hong Kong and the region. Results will be announced at the award ceremony on 27 November 2020.

Please click here to view the full list of finalists.

For further information, please contact our Mr. Willy Cheng, Mr. Hank Lo or Ms. Catherine Por.

25 Sep 2020

(中文) 合伙人徐凯怡律师受Legal Plus邀请,担任线上论坛演说嘉宾

(中文) 2020年9月17日下午,本所合伙人,诉讼及争议解决部主管徐凯怡律师受Legal Plus邀请,担任「Legal Plus 意见领袖线上论坛:国际仲裁意见领袖线上论坛」 (Legal Plus Leaders Web-forums: International Arbitration Leaders Web-forum) 演说嘉宾。

本次线上论坛由Legal Plus主办,徐律师与来自亚洲、欧洲和中东地区的法律从业者、企业法总等参会人士分享如何运用内地与香港仲裁互助保全安排,最大化地收回债权利益 (Maximizing Recovery Through the Use of PRC-Hong Kong Interim Measures Arrangement in International Arbitration)。

如阁下想了解更多详情,请联络本所合伙人徐凯怡律师 (heidi.chui@sw-hk.com)。

21 Sep 2020

Privacy in the age of COVID-19

Recent efforts for the testing and tracing of COVID-19 have raised growing concerns over data protection and personal privacy in the wake of the global pandemic. The aim of these measures is to help us navigate the difficult so that we can return to normal life as soon as possible, but at what cost? With reference to several media statements and responses issued by the Privacy Commissioner for Personal Data, Hong Kong (the “Privacy Commissioner”) since the outbreak of the COVID-19 pandemic, this article attempts to summarise what the Personal Data (Privacy) Ordinance (the “PDPO”) expects when it comes to balancing privacy right and public health and safety.

PDPO at a glance

The PDPO is applicable to both the private and the public sectors. The general position is that all data users shall comply with the six Data Protection Principles (“DPP”) when handling personal data:

1. Collection Purpose & Means
2. Accuracy & Retention
3. Use
4. Security
5. Openness
6. Data Access & Correction

Privacy vs. health and life

While data privacy is an important right, the interests protected under the PDPO have to be balanced against other important rights or public interest. The PDPO provides a number of exemptions from some compliance requirements under particular circumstances. When it comes to compelling public health concern, the following are applicable:

  • Section 59 of the PDPO provides that situations involving health concern relating to the interests of the public may be exempt from the restrictions on the use of data; and
  • “Right to life” of individuals, as set out in (i) Article 2 of Part II of the Hong Kong Bill of Rights Ordinance and (ii) Article 6 of the International Covenant on Civil and Political Rights (ICCPR), means that every human being has the inherent right to life. This right is absolute and precedes other countervailing interests, including privacy right.

Privacy issues considered

1. Mandatory quarantine measures

Location data of persons under quarantine would be collected by the Government so as to monitor whether they are complying with the quarantine conditions. Prior to the collection of such data and in accordance with DPP1, the purpose and manner of collection will be explained to the persons under quarantine and their consents will be obtained for access to their relevant personal data and certain information to be transmitted from their mobile devices (e.g. data involved in the use of video calls).

The Privacy Commissioner also brought to the public’s attention on section 59(1) of the PDPO, which provides an exemption for DPP3, i.e. use of data, and states that in circumstances where the application of the restrictions on the use of data would be likely to cause serious harm to the physical or mental health of the data subject or any other individual, the data user may disclose personal data relating to the physical or mental health of the data subject to a third party without the consent of the data subject.

2. Universal community testing programme

Personal data (including names, Hong Kong Identity Card numbers / birth registration numbers and local mobile phone numbers) will be collected under the programme. The use of such personal data is subject to the consent of the participants and is consistent with the principles of purpose specification and use limitation. Personal data will be handled on a “need-to-know” basis and erased one month after completion of the programme.

3. The use of information on social media for tracking potential carriers of COVID-19

Though the general rule is that personal data obtained from the social media is also regulated by the PDPO, it is subject to competing rights or interests such as the right to life. In accordance with section 59(2) of the PDPO, where the application of the restrictions on the use of data would be likely to cause serious harm to the physical or mental health of the data subject or any other individual, personal data relating to the identity or location of the data subject may be disclosed to a third party without the consent of the data subject. Therefore, if persons are suspected of having close contacts with infected persons, it would be in the public interest to closely monitor their whereabouts, including the venues and the persons that they have visited and contacted, with the aim to control further spread of COVID-19 in the community.

There are sufficient legal and justifiable bases on which the Government may collect and use information obtainable offline or online with the aid of devices, applications, software or super computers with a view to tracking potential COVID-19 carriers or patients in the interests of both the individuals concerned and the public.

4. Temperature collection at work

Employers have legal and corporate responsibility to protect the health of its employees and visitors that it is generally justifiable for employers to collect temperature measurements or limited medical symptoms of COVID-19 information of employees and visitors solely for the purposes of protecting the health of those individuals. Employers should spell out to their employees how the data collected will be handled. A self-reporting system is preferred to an across-the-board mandatory system where health data is collected indiscriminately.

It is reasonable and justifiable for employers to collect temperature measurements or medical condition of employees and visitors. Employers can require employees to complete declaration on personal health data as long as the notification requirement under the PDPO (by providing a Personal Information Collection Statement (PICS) to inform employees of the data collected and the purposes, and the classes of persons to whom their data may be transferred) is complied with. In accordance with section 59 of the PDPO, employers can disclose the identity, health and location data of individuals to the Government or health authorities solely for the purposes of tracking down and treating the infected and tracing their close contacts when pressing needs arise.

5. Work-from-home arrangements

Personal data protection should not hinder the work-from-home arrangements, but employers and employees should exercise extra caution because of the transfer and use of documents and data away from the professionally managed work environment.

Whilst the employers should put into place information systems to ensure secure transmission of data from work to home, the employees should be vigilant about the security of internet connection to prevent data leakage.

6. Temperature/personal data collection at premises

The Privacy Commissioner has pointed out that collection of personal data and/or temperature data by owners of premises is justifiable. They, however, should endeavour to raise the transparency and interpretability of the use of the personal data obtained. Again, the Privacy Commissioner pointed out that privacy right is not an absolute right and the right to life and public interest precede it. Any personal data collected should be necessary, appropriate and proportionate.

To comply with the DPPs, the owners of premises should ensure visitors are informed of the purpose of data collection and let them to decide whether to allow the collection of their biometric data. If visitors refuse to provide information, the owners of premises may refuse entry to protect the health of its staff and others.

Conclusion

Facing the pandemic, it is important to bear in mind that personal data privacy has not been neglected altogether. However, data protection principles should not hinder measures taken to fight COVID-19. The measures undertaken by the Government in balancing privacy right and public health needs have been endorsed by the Privacy Commissioner. Business owners and individuals should continue to observe the DPPs as far as practicable and display best efforts in complying with the requirements under the PDPO.

For more information or advice on privacy issues, please contact our Terence Lau or Elly Woo.

This newsletter is for information purpose only. Its content does not constitute legal advice and shall not be treated as such. Stevenson, Wong & Co. will not be liable to you in respect of any special, indirect or consequential loss or damage.

NEWER OLDER 1 2 58 59 60 78 79