Data, cybersecurity & privacy

Hong Kong IPO disclosure precedents · 52 companies, 55 items

personal information and data protection, cross-border data transfer, cybersecurity review, CIIO, data incidents, MLPS

Compliance matters are read from filings since 24 August 2026.

2026-09-30Application ProofCompliance confirmed
ACROBIOSYSTEMS CO., LTD北京百普赛斯生物科技股份有限公司

As advised by our PRC Legal Advisor, we are not required to file a data export security assessment, enter into a standard personal information export contract, or obtain personal information protection certification for our existing data export scenarios.

Business · p. 174

As advised by our PRC Legal Advisor, we are not obligated to proactively file for a cybersecurity review.

Business · p. 175
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-30PHIPCompliance confirmed
Amicro Technology Co., Ltd.珠海一微科技股份有限公司

As our business primarily serves enterprise customers, we also do not collect any personal data.

Business · p. 170

In our business operations, we may collect and retain limited contact information for business purposes after obtaining the prior consent of customers, suppliers and other business partners, and such collection and retention are in compliance with applicable data privacy and cybersecurity laws and regulations.

Business · p. 170
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-28ProspectusCompliance confirmed
Beijing ESWIN Computing Technology Co., Ltd.北京奕斯伟计算技术股份有限公司01256.HK

Our PRC Legal Advisor is of the view that, the cybersecurity-related laws and regulations have no material impact on our business operation, and we had been in compliance with the relevant laws and regulations in the PRC in respect of cybersecurity, data privacy and protection in all material respects.

Business · p. 188
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-28Application ProofCompliance confirmed
Shandong Linuo Pharmaceutical Packaging Co.,Ltd.山东力诺医药包装股份有限公司

We do not believe these requirements apply to us, as we are not a critical information infrastructure operator and our proposed [REDACTED] in Hong Kong does not constitute a ‘‘listing abroad’’ within the meaning of the Measures.

Risk Factors · p. 48

Such personal information is necessary for the normal conduct of our business operations, and the total volume of personal information transferred out of the PRC is relatively small (not exceeding 10,000 individuals) and does not involve any sensitive personal information.

Risk Factors · p. 49
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-28PHIPCompliance confirmed
Anhui Sinomags Technology Co., Ltd安徽希磁科技股份有限公司

Our PRC Legal Advisor is of the view that, during the Track Record Period and up to the Latest Practicable Date, we had complied with the data privacy and security-related and cyber security-related laws and regulations in the PRC, based on (i) to the best of our knowledge, we have not been subject to any complaint, legal proceeding or administrative penalty or investigation relating to relevant laws and regulations, (ii) we have implemented internal measures with the purpose of ensuring data and cyber security and ensuring compliance with relevant laws and regulations, and (iii) during the Track Record Period and up to the Latest Practicable Date, we did not experience any material data leakage or data loss.

Business · p. 172

We do not transfer any personal information or important data (if any) collected or generated during the ordinary course of our business in China to locations outside mainland China, and therefore do not trigger any prior approval requirements for cross-border data transfer under relevant PRC laws and regulations.

Business · p. 171
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-27Application ProofCompliance confirmed
Voyager Intelligent Systems Limited上海寅家电子科技股份有限公司

Our PRC Legal Advisor is of the view that, during the Track Record Period, we had complied with the applicable laws and regulations in effect in material respects, based on: (i) we have not received any complaint relating to data privacy or security measures; (ii) we have implemented internal policies, with the purpose of ensuring data and information security and ensuring compliance with applicable laws and regulations; (iii) during the Track Record Period, there had been no material incident of data or personal information leakage; (iv) during the Track Record Period, there had been no litigation, claims or administrative penalty relating to the violation of relevant network security, data security and personal information protection laws or regulations, to our best knowledge, pending or threatened against us initiated by competent government authorities or third parties; and (v) we will continue to pay close attention to the regulatory developments in data security and comply with the latest regulatory requirements.

Business · p. 171

Our Directors are of the view that we are able to comply with the relevant cybersecurity laws and regulations in all material aspects.

Business · p. 170
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-25PHIPCompliance confirmed
Shenzhen Transsion Holdings Co., Ltd.深圳传音控股股份有限公司

According to our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, in the course of our business development and operations, we do not involve in engaging in business activities or data processing activities that affect or may affect national security, nor do we involve in providing personal information to overseas; therefore, we are not involved in the circumstances where cybersecurity and data security reviews and assessments are required under the cybersecurity and data security related laws and regulations such as the Cybersecurity Law of the People’s Republic of China, the Data Security Law of the People’s Republic of China, the Measures for Cybersecurity Review, the Measures for Data Export Security Assessment, and the Provisions on Promoting and Regulating the Cross-border Flow of Data.

Business · p. 150

During the Track Record Period and up to the Latest Practicable Date, according to our PRC Legal Advisor, Singapore Legal Advisor, Bangladesh Legal Advisor, UAE Legal Advisor, Ethiopia Legal Advisor, India Legal Advisor, and our Local Legal Advisor as to Hong Kong Law, we had complied with relevant data security and privacy, cybersecurity, cross-border data transfer and personal information protection laws and regulations in all material aspects.

Business · p. 150
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-23Application ProofCompliance confirmed
Onyx International Inc.广州文石信息科技股份有限公司

Up to the Latest Practicable Date, our PRC Data Compliance Counsel is of the view that we are in compliance with all material respects with applicable laws and regulations relating to data, privacy protection, cross-border data transfer and cybersecurity.

Business · p. 160

Our PRC Data Compliance Counsel is of the view that, during the Track Record Period and up to the Latest Practicable Date, we have not been subject to cybersecurity reviews by relevant regulatory authorities, nor have we received any inquiries, notices, warnings or sanctions related to cybersecurity reviews.

Business · p. 160
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-22ProspectusCompliance confirmed
Shenzhen Camsense Technologies Co., Ltd.深圳市欢创科技股份有限公司06802.HK

our PRC Legal Advisors as to data compliance is of the view, and our Directors concur, that we have complied with the relevant laws and regulations on cybersecurity and data security and privacy in all jurisdictions where we operated during the Track Record Period and up to the Latest Practicable Date.

Business · p. 184
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-21Application ProofCompliance confirmed
Dynamic Electronics Co., Ltd.超颖电子电路股份有限公司

With respect to outbound transfers of personal information from Chinese Mainland, pursuant to the Provisions on Promoting and Regulating Cross-Border Data Flows, such transfers satisfied the applicable exemption conditions and were therefore not required to undergo (1) a security assessment for outbound data transfers, (2) the filing of standard contracts for the outbound transfer of personal information, or (3) certification for the outbound transfer of personal information.

Business · p. 148

We are subject to, and have implemented measures to comply with, evolving laws and regulations relating to data security and privacy, including the Cybersecurity Law of China, the Data Security Law of China and the Personal Information Protection Law of China.

Business · p. 148
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-21ProspectusCompliance confirmed
Direct Drive Tech Limited本末动力(北京)科技股份有限公司06731.HK

All data generated and collected in PRC is retained locally at the originating entity in PRC, which maintains ownership and control over the data, and there was no cross-border transfer or transmission of such data.

Business · p. 178

Accordingly, our PRC Data Compliance Advisor, Hankun Data, is of the view that our Group is in compliance with the applicable laws and regulations in respect of data security and privacy in China in all material aspects.

Business · p. 178
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-21ProspectusCompliance confirmed
RoboTechnik Intelligent Technology Co., Ltd.罗博特科智能科技股份有限公司03757.HK

In addition, our PRC Legal Adviser is of the view that (i) our Company was not subject to any material risk in relation to cybersecurity and data compliance, including any material non-compliance with applicable laws and regulatory requirements relating to cybersecurity, data security or personal information protection that would render its business operations unsustainable and incapable of rectification; (ii) our business operations did not rely on any serious violation of applicable laws involving the unlawful collection, use, provision to third parties or cross-border transfer of data; and (iii) we were, in all material respects, in compliance with applicable PRC laws and regulations relating to cybersecurity, data security and personal information protection.

Business · p. 182
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-21ProspectusCompliance confirmed
Red Avenue New Materials Group Co., Ltd.彤程新材料集团股份有限公司09607.HK

We do not otherwise process, disclose or transfer such personal information to any third parties or involve in any cross-border transfer of personal or material business data.

Business · p. 155

Based on the above, as advised by our PRC Legal Adviser, we had been in compliance with relevant PRC laws and regulations concerning cybersecurity, data privacy and data protection during the Track Record Period and Latest Practicable Date.

Business · p. 156
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-18Application ProofCompliance confirmed
Zhejiang Jingxin Pharmaceutical Co., Ltd.浙江京新药业股份有限公司

As advised by our Data Privacy Legal Advisor, after conducting verification under applicable PRC laws and regulations relating to cybersecurity, data security and personal information protection, including the PRC Cybersecurity Law, the PRC Data Security Law and the PRC Personal Information Protection Law, we had, in all material respects, complied with the relevant data privacy and security laws and regulations during the Track Record Period and up to the Latest Practicable Date.

Business · p. 164
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-14ProspectusCompliance confirmed
Shenzhen Forms Syntron Information Co., Ltd.深圳四方精创资讯股份有限公司06700.HK

Moreover, we have not been designated as a Critical Information Infrastructure Operator, and we have not received notice from relevant regulatory authorities indicating that: (i) the services we provide, as well as our data processing activities, affect or may affect national security; (ii) we are required to undergo a cybersecurity review; or (iii) we process core data or important data.

Business · p. 152

Based on the above, our PRC Legal Advisors are of the view that, during the Track Record Period and up to the Latest Practicable Date, we have established internal control management systems for network security, data security and personal information protection, and have taken corresponding compliance measures, and we have satisfied the requirements of the PRC Cybersecurity Law, Data Security Law, and Personal Information Protection Law in all material respects.

Business · p. 152
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-13Application ProofCompliance confirmed
Hai Robotics Innovation Group Co., Ltd.深圳市海柔创新智能科技集团股份有限公司

As advised by our PRC Legal Advisor, based on the foregoing and the relevant regulatory framework, during the Track Record Period and up to the Latest Practicable Date, we have complied with applicable PRC laws and regulations in all material respects in relation to cybersecurity, data security and personal information protection, and no material non-compliance has been identified.

Business · p. 179

We are not involved in cross-border transmission of important data or sensitive personal information, and the volume of general personal information transmitted overseas does not exceed the regulatory thresholds under PRC laws and regulations for completing outbound administrative regulatory procedures.

Business · p. 178
The company's explanation, the adviser's view and the page in the filing: see Matters
1 / 3

Tell us