News

Computer Crime Law Reform

2 February 2026

In January 2026, the Law Reform Commission of Hong Kong published its final report on Cyber-Dependent Crimes and Jurisdictional Issues. The report recommends a new piece of bespoke cybercrime legislation and provides a blueprint for five proposed offences. The Government has welcomed the report and is studying its recommendations; these proposals have not yet been enacted as a standalone Cybercrime Ordinance.

  • Illegal Access to a Program or Data: The proposed offence would address unauthorized access, including basic hacking and credential attacks, and modernize the existing law governing computer access.
  • Illegal Interception of Computer Data: The proposed offence would prohibit unauthorized interception of non-public computer data during transmission, including conduct such as packet sniffing.
  • Illegal Interference with Computer Data: The proposed offence would address unauthorized deletion, alteration, suppression or deterioration of computer data, including ransomware encryption.
  • Illegal Interference with a Computer System: The proposed offence would address serious hindering or interruption of a computer system, including network-flooding and distributed denial-of-service attacks.
  • Making Available a Device, Program or Data for Committing a Cyber-related Crime: The proposed offence would address knowingly making such material available for use in cyber-related crime. It would also cover possessing the material for the purpose of making it available; it is not a general offence of simple possession without that purpose.

Separately, the Protection of Critical Infrastructures (Computer Systems) Ordinance (Cap. 653) came into force on 1 January 2026 and establishes a mandatory cybersecurity regime for designated operators of essential infrastructure in sectors including energy, information technology, banking and financial services, transport, healthcare, and telecommunications and broadcasting. Designated operators must maintain appropriate governance, security-management and emergency-response arrangements, conduct regular risk assessments and audits, participate in drills, and report serious computer-system security incidents within 12 hours and other reportable incidents within 48 hours. The accompanying Code of Practice guides compliance and places particular emphasis on senior oversight, supply-chain and cloud-security controls, while non-compliance with statutory obligations or regulatory directions may result in substantial corporate fines and continuing daily penalties; organisations outside the formal regime may also be affected through stricter contractual requirements when supplying designated operators.

WhatsApp Us