Data, cybersecurity & privacy

Hong Kong IPO disclosure precedents · 52 companies, 55 items

personal information and data protection, cross-border data transfer, cybersecurity review, CIIO, data incidents, MLPS

Compliance matters are read from filings since 24 August 2026.

2026-09-11Application ProofCompliance confirmed
ASR MICROELECTRONICS CO., LTD.翱捷科技股份有限公司

As advised by our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, we had complied with the applicable PRC laws and regulations relating to data privacy and security in all material respects.

Business · p. 155

During the Track Record Period and up to the Latest Practicable Date, we did not receive any notice or determination from a competent regulatory authority identifying us as a critical information infrastructure operator, and we were not an operator of critical information infrastructure under the Regulation for Safe Protection of Critical Information Infrastructure.

Business · p. 155

In the ordinary course of our business, we generally do not access or collect personal information or data of end users located in any country or region through our products or services.

Business · p. 155
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-11ProspectusCompliance confirmed
Transwarp Technology (Shanghai) Co., Ltd.星环信息科技(上海)股份有限公司06727.HK

During the Track Record Period and as of the Latest Practicable Date, we had not experienced any material data or personal information leakage or loss, infringement of data or personal information, or information security incident, we had not been subject to any investigation, inspection or penalty from the PRC authorities or any other relevant regulatory bodies in relation to violation of cybersecurity, data security and personal data protection laws and regulations.

Business · p. 174

Based on the foregoing, we and our PRC Legal Advisors are of the view that both the Company’s existing products, services and solutions, and their data privacy features as mentioned above comply with data privacy and cybersecurity laws in the PRC effectively in all material respects.

Business · p. 174
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-10Application ProofCompliance confirmed
Guangdong Mic-Power New Energy Co., Ltd.广东微电新能源股份有限公司

As advised by the Company’s PRC Legal Advisor and based on the measures the Company has been taking described above, the Company had complied with applicable laws and regulations relating to cybersecurity, data privacy and protection and cross-border data transmission in all material respects during the Track Record Period and up to the Latest Practicable Date.

Business · p. 201
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-07PHIPCompliance confirmed
Zhejiang Taotao Vehicles Co., Ltd.浙江涛涛车业股份有限公司

We have not been, and are not, subject to any review by the Cyberspace Administration of China, and the [REDACTED] does not fall within the circumstances requiring a mandatory application for cybersecurity review under the Cybersecurity Review Measures

Business · p. 167

During the Track Record Period and as of the Latest Practicable Date, our legal advisors of all relevant jurisdictions and our Directors are of the view, and the Sole Sponsor concurs, that we had complied with applicable laws and regulations relating to data security and data protection in all material aspects and have not received any penalty due to breach of data privacy.

Business · p. 168
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-03Application ProofCompliance confirmed
VATAI HOLDINGS LIMITED深圳欧税通控股股份有限公司

According to our PRC Legal Advisor as to data compliance, while our business processes involve cross-border data transfers, our Company is not a processor of personal information, in such cross-border data transfer scenarios but merely a trustee thereof, and is not the subject obligated to perform the aforesaid obligations under the law.

Risk Factors · p. 38

According to our PRC Legal Advisor as to data compliance and our telephone consultations with the China Cybersecurity Review, Certification And Market Regulation Big Data Center, enterprises seeking listing in Hong Kong are not required to take the initiative to apply for a cybersecurity review solely by reason of its listing in Hong Kong per se, as Hong Kong is a part of the PRC and does not belong to the “foreign country” as stipulated in the Review Measures.

Risk Factors · p. 39
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-09-03Application ProofCompliance confirmed
SHENZHEN SALUBRIS PHARMACEUTICALS CO., LTD.深圳信立泰药业股份有限公司

During the Track Record Period and up to the Latest Practicable Date, the outbound transfer of patient-level data sets from the United States to China only involved personal health data of fewer than 300 U.S. persons—far below the 10,000 U.S. persons threshold for bulk U.S. sensitive personal health data under the NSD Final Rule.

Business · p. 207

Based on the above, our PRC Legal Advisor and the legal advisor to Salubris Bio are of the view that we had complied with the applicable laws and regulations in relation to cross-border data transfer between Chinese Mainland and the United States.

Business · p. 207
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-31Application ProofNon-compliance
ProteLight Pharmaceuticals (Jiangsu) Co., Ltd.普莱医药(江苏)股份有限公司

The data submitted to the FDA mainly consisted of CSRs, with only a very limited amount of de-identified individual safety data, and the relevant transfer was completed in January 2022, when the relevant PRC laws had only recently come into effect and the detailed implementation rules for cross-border data transfer were not yet clear, and there were no clear and specific enforceable provisions in practice regarding the specific compliance pathways and procedures for cross-border data transfer, as the detailed implementation rules and regulatory guidance had not yet been developed or clarified at the relevant time.

Business · p. 169

The Company has ceased such transfer after completion of the FDA submission and will comply with the applicable PRC requirements for any future cross-border data transfer.

Business · p. 169
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-31ProspectusCompliance confirmed
Shenzhen Longsys Electronics Co., Ltd.深圳市江波龙电子股份有限公司09976.HK

Our PRC Legal Advisor is of the view that we have been in compliance with the relevant PRC laws and regulations relating to cybersecurity and data protection in all material aspects during the Track Record Period and up to the Latest Practicable Date.

Business · p. 209

Our PRC Counsel is of the view that we are not required to apply for cybersecurity review for the purpose of the Listing.

Risk Factors · p. 77

As of the Latest Practicable Date, we had not been notified of being classified as a critical information infrastructure operator (CIIO), we had not received any inquiry, notice, warning from any PRC government authorities, and have not been subject to any investigation, sanctions or penalties made by any PRC government authorities regarding national security risks caused by our business operations or the Listing.

Risk Factors · p. 77
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-31Application ProofCompliance confirmed
Zhejiang IPLUSMOBOT Technology Co., Ltd.浙江迦智科技股份有限公司

Our PRC Legal Advisor is of the view that the contact information collected by us does not fall under the scope of personal sensitive information based on the basis that such information is limited to the names, positions, and professional contact details (such as mobile numbers and email addresses) of the contact persons of our business partners, which are voluntarily provided by them through emails or contract execution for the sole purpose of business coordination.

Business · p. 194

As advised by our PRC Legal Advisor, we are not subject to a mandatory cybersecurity review by the Cyberspace Administration of China (the “CAC”), based on the basis that we are not a critical information infrastructure operator and that our [REDACTED] in Hong Kong does not constitute a “[REDACTED] in a foreign country” as defined under the Measures for Cybersecurity Review.

Business · p. 194
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-31Application ProofCompliance confirmed
Ningbo Sunny Smart Autotech Company Limited宁波舜宇智行科技股份有限公司

Our PRC legal advisor is of the view that we have, in all material respects, complied with the applicable PRC laws and regulations with respect to data privacy and cybersecurity during the Track Record Period and up to the Latest Practicable Date, on the basis that: (i) as confirmed by us and verified by our PRC legal advisor, we are not a critical information infrastructure operator, and all of our business data is stored domestically; (ii) we do not process personal information in the ordinary course of our business operations or important data, nor do we engage in any cross-border data transfer; (iii) in respect of cybersecurity and data security management, we have established a organizational structure, institutional framework, technical safeguards and personnel management measures as set forth above, classified all of our information systems as Level 1, and implemented protection measures; (iv) the algorithms and artificial intelligence technologies used internally by us are not subject to the regulations governing algorithmic recommendations, deep synthesis or generative artificial intelligence services; (v) the [REDACTED] does not require a proactive filing for cybersecurity review; and (vi) we have not been involved in any litigation or penalties relating to data compliance during the Track Record Period and up to the Latest Practicable Date.

Business · p. 164

Based on the suite of internal control measures in respect of cyber security and data security as follows, our PRC Legal Advisor is of the view that (i) the users are deemed to have given their consent to the Group to the processing of the submitted personal information for the purpose of product feedback collection, and (ii) our data processing activities during the Track Record Period were in compliance with applicable PRC laws and regulations governing data protection and cybersecurity.

Business · p. 163
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-30Application ProofCompliance confirmed
Hangzhou Bangshun Pharmaceutical Co., Ltd.杭州邦顺制药股份有限公司

Our legal advisor as to data compliance law of the PRC, Allbright Law Offices, is of the view that, during the Track Record Period and up to the Latest Practicable Date, we had complied with all applicable laws and regulations concerning data privacy, cybersecurity and data security in the PRC during the Track Record Period and up to the Latest Practicable Date in view that we had not incurred any administrative penalties related to data security, cybersecurity and data privacy.

Business · p. 191
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-30Application ProofCompliance confirmed
Beijing XSKY Technology Co., Ltd.北京星辰天合科技股份有限公司

our PRC Legal Advisor is of the view that, during the Track Record Period and up to the Latest Practicable Date, (i) we have implemented compliance measures concerning cybersecurity, data protection and personal information protection in accordance with the requirements of relevant cybersecurity, data and personal information protection laws and regulations in all material aspects and (ii) has complied with the relevant data protection and privacy, and cybersecurity regulations in all material aspects.

Business · p. 174

During the Track Record Period and up to the Latest Practicable Date, (i) we had not received any claim from any third party against us on the ground of infringement of any third party’s right to data and privacy protection as provided by any applicable laws and regulations, (ii) there had been no investigation or other legal proceeding pending or threatened against us initiated by competent government authorities or third parties with respect to cybersecurity, data and personal information protection, and (iii) we had not experienced material leakage of personal information in relation to laws and regulations of cybersecurity, data protection and personal information protection.

Business · p. 173
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-30Application ProofCompliance confirmed
ZHE JIANG HAI LIANG CO., LTD.浙江海亮股份有限公司

During the Track Record Period and up to the Latest Practicable Date, according to our PRC Legal Advisors, German Legal Advisors and Thai Legal Advisors, we are in compliance with applicable data privacy and security laws in the relevant jurisdictions in all material respects, and according to our U.S. Legal Advisors, based on our representations of facts, we were not found to be subject to any penalties or legal proceedings for violation or non-compliance with the applicable data privacy and security laws in the relevant states where we operate.

Business · p. 166

We store the data collected and generated in the course of business operations locally and in cloud located in the jurisdictions where the data is generated without transferring data to other jurisdictions from the PRC.

Business · p. 166
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28Application ProofCompliance confirmed
HANGZHOU TANGJI MEDICAL TECHNOLOGY CO., LTD.杭州糖吉医疗科技股份有限公司

Our PRC Legal Advisors have confirmed that, during the Track Record Period and up to the Latest Practicable Date, we had been in compliance with the relevant PRC laws and regulations in all material aspects in this regard.

Business · p. 213

These materials do not contain any personal information or important data, and thus do not trigger cross-border data export regulatory procedures.

Business · p. 213
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28Application ProofCompliance confirmed

During the Track Record Period and up to the Latest Practicable Date, we had complied with all applicable laws and regulations on data privacy and security in all material respects, and our PRC Legal Adviser is of the view that during the Track Record Period and up to the Latest Practicable Date, we had complied with applicable PRC laws and regulations in relation to cross border data transfer in all material respects.

Business · p. 214
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28Application ProofCompliance confirmed
Betta Pharmaceuticals Co., Ltd.贝达药业股份有限公司

Our PRC Legal Adviser is of the view that we have complied in all material respects with applicable PRC data security and personal information protection laws and regulations during the Track Record Period and up to the Latest Practicable Date, and that there has been no unlawful use of personal information.

Business · p. 198

As advised by our PRC Legal Adviser, we had not been subject to any claims, lawsuits, penalties or administrative actions relating to cross-border clinical data transfer activities during the Track Record Period and up to the Latest Practicable Date.

Business · p. 198
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28Application ProofCompliance confirmed
ClubMed Lifestyle Group地中海度假集团

Based on the advice of our legal advisors, we had complied with applicable data privacy and cybersecurity laws and regulations in all material respects during the Track Record Period and up to the Latest Practicable Date.

Business · p. 133

Regarding cybersecurity, the main information systems used by us have completed Class-3 Filing for Cyber-security Classified Protection.

Business · p. 132

During the Track Record Period, we did not experience any material data security incident or material non-compliance in relation to cross-border transfers of personal data.

Business · p. 129
The company's explanation, the adviser's view and the page in the filing: see Matters

Tell us