News Updates
Find out all about our firm’s latest news updates below. To learn more about any individual item, please contact us here.
News Updates
Find out all about our firm’s latest news updates below. To learn more about any individual item, please contact us here.
Asian Legal Business (ALB) has just released the ranking of the Top 50 largest firms in Asia 2020. Stevenson, Wong & Co. has once again been listed as one of the largest Hong Kong domestic law firms for 5 consecutive years.

Established in 1978, Stevenson, Wong & Co. has more than 170 experienced lawyers and staff. Our aim is to provide clients with innovative and effective solutions for their personal or commercial problems with our local and international expertise. During these unprecedented times, we strive to ensure that communication with and services to our clients remain unaffected whilst balancing the emotional and physical well-being of our staff. We look ahead to 2021 with both caution and optimism as we continue to provide uninterrupted quality legal services to our clients.

Under these unprecedented times, we strive to ensure that communication and our services to clients remain unaffected whilst the emotional and physical well-being of our staff are just as important. As we look ahead to 2021, we will continue to enhance the quality of our services to our clients and all look forward to a better tomorrow.

We would also like to take this opportunity to congratulate our association firm, AllBright Law Offices, for being ranked as the top 4th largest domestic law firms across Asia.
About ALB and Asia’s Top 50
ALB is a leading law journal published by Thomson Reuters and is considered as one of the most influential legal media in Asia. Organised by ALB, Asia Top 50 aims to identify and rank the largest law firms across Asia by their size and number of lawyers.
For the full ranking, please click here.
Please contact Mr. Willy Cheng, Mr. Hank Lo or Ms. Catherine Por for any enquiries or further information.
Apart from our Personal Data (Privacy) Ordinance (“PDPO”), the European Union’s GDPR which takes effect from 25 May 2018 is an important breakthrough in our data privacy legislation having considered its wide geographical application and the severe monetary penalty to be imposed, as shown in a recent Germany’s case that €35.3 million fine was imposed against an international retailer which adopted inappropriate measures in monitoring and processing the personal data of several hundred employees at one of its branch in Nuremberg.

What are the basic principles for processing data under GDPR?
The GDPR holds the controllers legally accountable for their compliance with various principles in lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.[1] For example, if a Hong Kong company has to discharge its duties on integrity and confidentiality, it has to implement and set up appropriate cyber and data security measures, thus, to add in more stringent data security contractual provisions in their contracts with the data processors.
To what extent is a Hong Kong company affected?
The GDPR has an extra-territorial effect. A Hong Kong company may need to comply with the GDPR if it:
1. has no establishment[2] in the EU but offers goods or services to, or monitor the behaviour of individuals in the EU territory; or
2. has an establishment in the EU, where personal data is processed in the context of the activities of the establishment, regardless of whether the data is actually processed within the EU. [3]
Both data controllers and data processors are regulated when they process the personal data collected from the relevant activities.

Positive Examples:
However, the processing activity related to offer of goods and services will only be caught when it intentionally targets individuals within the EU territory. If the processing relates to a service that is only offered to individuals outside the EU, but the service is not withdrawn when such individuals enter the EU territory, the related processing will not be subject to the GDPR.[4]
Negative Example:

What are the consequences if a company data practice falls below the GDPR standard?
The administrative fines for contravention of the GDPR consist of two tiers, depending on the types of violations. The lower tier fine can be up to €10 million, or 2% of the total worldwide annual turnover of preceding financial year (in the case of an undertaking), whichever is higher.[5] The upper tier fine can be up to €20 million, or 4% of the total worldwide annual turnover of preceding financial year (in the case of an undertaking), whichever is higher.[6]
Under what circumstances will companies be penalised?
Lower tier fines may be imposed if the company fails to comply with any of the following (non-exhaustive list):
1. obtaining parental consent for processing of children’s personal data;
2. processing personal data anonymously if it is not necessary to identify the data subjects;
3. giving data breach notification;
4. appointing data protection officer; or
5. others.[7]
Upper tier fines may be imposed if the company fails to comply with the following (non-exhaustive list):
1. complying with the basic principles for processing, such as obtaining consent before processing;
2. complying with the data subjects’ rights, such as right to erasure, right to object to processing;
3. transferring personal data to a recipient in a third country through lawful mechanism; or
4. others.[8]

What is the difference between ‘data controllers and data processors’ under GDPR and ‘data users’ under PDPO?
To put it simply, ‘controller’ usually refers to the people or companies which decide on how and for what purpose the personal data will be processed, whereas ‘processor’ refers to the people or companies which process the data on behalf of the controller.[9] A company can act in both capacities.
Meanwhile, ‘data users’ is a general concept used in Hong Kong under the PDPO. It is a collective term which covers both ‘data controllers’ and ‘data processors’ as used in GDPR. While GDPR regulates both controllers and processors, processors are not directly regulated by the PDPO.
Consent is a lawful ground for data processing under GDPR. Is it different from the current practice of obtaining consent in Hong Kong?
In Hong Kong, the practice of customers’ ticking in a consent box is usually relevant to the company’s use of the personal data for direct marketing activities. Consent is not a pre-requisite for the collection of personal data in the first place, but it is required when the data collected will be used for a different purpose.[10]
Under the legal principles briefly mentioned above, several lawful grounds are available for companies to collect and process any personal data. The giving of consent is one of them and is probably the most common ground provided that it must be freely given, specific, informed, and unambiguous.[11]

There are other major corporate measures required under GDPR but not under PDPO
The following (non-exhaustive) measures are necessary in demonstrating compliance with GDPR but are not legally required under the PDPO:-
Data protection officer (“DPO”)
Company, regardless of its size, is required to appoint a DPO if its core activities consist of processing which systematically monitor data subjects on a large scale, such as online tracking, profiling (predictions about individual’s preferences), or processing a large scale of sensitive personal data.
DPO is responsible for monitoring the compliance with GDPR and contacting with the supervisory authority.
Data breach notification and remedial actions
The data controllers are required to give notification to the EU regulators of a data breach without undue delay (and where feasible, no later than 72 hours after having become aware of it), unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
Other major corporate measures include (but not limited to):
This article is co-authored by Ms. Milly Hung, Partner of Litigation Department, Mr. Michael Lau, the Associate and Mr. Calvin Lo, the Trainee Solicitor of Stevenson, Wong & Co. Due to the impact of the Covid-19 Pandemic, the potential effects of GDPR to the processing of the staff health data do raise concerns. If you have any problem in relation to this matter, please contact Ms. Milly Hung.
This article is for information purposes only. Its content does not constitute legal advice and should not be treated as such. Stevenson, Wong & Co. will not be liable to you in respect of any special, indirect or consequential loss or damage.
Mr. Terence Lau, Senior Associate of our Corporate Finance Department, hosted a CPD webinar for the topic “IPO101: An Overview of a Listing Offer” on 15 October 2020. In this course, Terence offered a detailed explanation of listing criteria as well as suitability for listing. The syllabus dissected IPO projects and included topics such as reorganisation, due diligence, prospectus drafting and share offer. The webinar also gave an overview of the IPO process pre-IPO investment.

Terence specialises in advising listing applicants, sponsors and underwriters in a broad range of corporate finance transactions, including initial public offering on The Stock Exchange of Hong Kong Limited, subsequent share issues, shares placement, rights issue, open offer and convertible bonds. Terence also advises listed issuers on regulatory and compliance matters.

Please contact Mr. Terence Lau for any enquiries or further information.
Stevenson, Wong & Co. is proud to have been shortlisted as a finalist in 12 categories at the 19th Annual Asian Legal Business (ALB) Hong Kong Law Awards 2020.
Nominations include:
The Hong Kong Law Awards is the biggest and longest-running awards presented by ALB. The awards aim to pay tribute to the outstanding performance of private practitioners and in-house teams from Hong Kong and the region. Results will be announced at the award ceremony on 27 November 2020.
Please click here to view the full list of finalists.
For further information, please contact our Mr. Willy Cheng, Mr. Hank Lo or Ms. Catherine Por.
(中文) 2020年9月17日下午,本所合伙人,诉讼及争议解决部主管徐凯怡律师受Legal Plus邀请,担任「Legal Plus 意见领袖线上论坛:国际仲裁意见领袖线上论坛」 (Legal Plus Leaders Web-forums: International Arbitration Leaders Web-forum) 演说嘉宾。
本次线上论坛由Legal Plus主办,徐律师与来自亚洲、欧洲和中东地区的法律从业者、企业法总等参会人士分享如何运用内地与香港仲裁互助保全安排,最大化地收回债权利益 (Maximizing Recovery Through the Use of PRC-Hong Kong Interim Measures Arrangement in International Arbitration)。


如阁下想了解更多详情,请联络本所合伙人徐凯怡律师 (heidi.chui@sw-hk.com)。
Recent efforts for the testing and tracing of COVID-19 have raised growing concerns over data protection and personal privacy in the wake of the global pandemic. The aim of these measures is to help us navigate the difficult so that we can return to normal life as soon as possible, but at what cost? With reference to several media statements and responses issued by the Privacy Commissioner for Personal Data, Hong Kong (the “Privacy Commissioner”) since the outbreak of the COVID-19 pandemic, this article attempts to summarise what the Personal Data (Privacy) Ordinance (the “PDPO”) expects when it comes to balancing privacy right and public health and safety.

PDPO at a glance
The PDPO is applicable to both the private and the public sectors. The general position is that all data users shall comply with the six Data Protection Principles (“DPP”) when handling personal data:
1. Collection Purpose & Means
2. Accuracy & Retention
3. Use
4. Security
5. Openness
6. Data Access & Correction
Privacy vs. health and life
While data privacy is an important right, the interests protected under the PDPO have to be balanced against other important rights or public interest. The PDPO provides a number of exemptions from some compliance requirements under particular circumstances. When it comes to compelling public health concern, the following are applicable:

Privacy issues considered
1. Mandatory quarantine measures
Location data of persons under quarantine would be collected by the Government so as to monitor whether they are complying with the quarantine conditions. Prior to the collection of such data and in accordance with DPP1, the purpose and manner of collection will be explained to the persons under quarantine and their consents will be obtained for access to their relevant personal data and certain information to be transmitted from their mobile devices (e.g. data involved in the use of video calls).
The Privacy Commissioner also brought to the public’s attention on section 59(1) of the PDPO, which provides an exemption for DPP3, i.e. use of data, and states that in circumstances where the application of the restrictions on the use of data would be likely to cause serious harm to the physical or mental health of the data subject or any other individual, the data user may disclose personal data relating to the physical or mental health of the data subject to a third party without the consent of the data subject.
2. Universal community testing programme
Personal data (including names, Hong Kong Identity Card numbers / birth registration numbers and local mobile phone numbers) will be collected under the programme. The use of such personal data is subject to the consent of the participants and is consistent with the principles of purpose specification and use limitation. Personal data will be handled on a “need-to-know” basis and erased one month after completion of the programme.
3. The use of information on social media for tracking potential carriers of COVID-19
Though the general rule is that personal data obtained from the social media is also regulated by the PDPO, it is subject to competing rights or interests such as the right to life. In accordance with section 59(2) of the PDPO, where the application of the restrictions on the use of data would be likely to cause serious harm to the physical or mental health of the data subject or any other individual, personal data relating to the identity or location of the data subject may be disclosed to a third party without the consent of the data subject. Therefore, if persons are suspected of having close contacts with infected persons, it would be in the public interest to closely monitor their whereabouts, including the venues and the persons that they have visited and contacted, with the aim to control further spread of COVID-19 in the community.
There are sufficient legal and justifiable bases on which the Government may collect and use information obtainable offline or online with the aid of devices, applications, software or super computers with a view to tracking potential COVID-19 carriers or patients in the interests of both the individuals concerned and the public.

4. Temperature collection at work
Employers have legal and corporate responsibility to protect the health of its employees and visitors that it is generally justifiable for employers to collect temperature measurements or limited medical symptoms of COVID-19 information of employees and visitors solely for the purposes of protecting the health of those individuals. Employers should spell out to their employees how the data collected will be handled. A self-reporting system is preferred to an across-the-board mandatory system where health data is collected indiscriminately.
It is reasonable and justifiable for employers to collect temperature measurements or medical condition of employees and visitors. Employers can require employees to complete declaration on personal health data as long as the notification requirement under the PDPO (by providing a Personal Information Collection Statement (PICS) to inform employees of the data collected and the purposes, and the classes of persons to whom their data may be transferred) is complied with. In accordance with section 59 of the PDPO, employers can disclose the identity, health and location data of individuals to the Government or health authorities solely for the purposes of tracking down and treating the infected and tracing their close contacts when pressing needs arise.
5. Work-from-home arrangements
Personal data protection should not hinder the work-from-home arrangements, but employers and employees should exercise extra caution because of the transfer and use of documents and data away from the professionally managed work environment.
Whilst the employers should put into place information systems to ensure secure transmission of data from work to home, the employees should be vigilant about the security of internet connection to prevent data leakage.
6. Temperature/personal data collection at premises
The Privacy Commissioner has pointed out that collection of personal data and/or temperature data by owners of premises is justifiable. They, however, should endeavour to raise the transparency and interpretability of the use of the personal data obtained. Again, the Privacy Commissioner pointed out that privacy right is not an absolute right and the right to life and public interest precede it. Any personal data collected should be necessary, appropriate and proportionate.
To comply with the DPPs, the owners of premises should ensure visitors are informed of the purpose of data collection and let them to decide whether to allow the collection of their biometric data. If visitors refuse to provide information, the owners of premises may refuse entry to protect the health of its staff and others.

Conclusion
Facing the pandemic, it is important to bear in mind that personal data privacy has not been neglected altogether. However, data protection principles should not hinder measures taken to fight COVID-19. The measures undertaken by the Government in balancing privacy right and public health needs have been endorsed by the Privacy Commissioner. Business owners and individuals should continue to observe the DPPs as far as practicable and display best efforts in complying with the requirements under the PDPO.
For more information or advice on privacy issues, please contact our Terence Lau or Elly Woo.
This newsletter is for information purpose only. Its content does not constitute legal advice and shall not be treated as such. Stevenson, Wong & Co. will not be liable to you in respect of any special, indirect or consequential loss or damage.
