Data, cybersecurity & privacy

Hong Kong IPO disclosure precedents · 52 companies, 55 items

personal information and data protection, cross-border data transfer, cybersecurity review, CIIO, data incidents, MLPS

Compliance matters are read from filings since 24 August 2026.

2026-08-28Application ProofCompliance confirmed

As advised by our PRC Legal Adviser and U.S. Legal Adviser and based on the due diligence conducted by our U.S. Legal Adviser in connection with the [REDACTED], such collection and use of personal data comply with material applicable laws and regulations concerning data privacy and security in China and the United States during the Track Record Period and up to the Latest Practicable Date.

Business · p. 189
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28Application ProofCompliance confirmed
VivaVision Biotech (Zhejiang) Co., Ltd.维眸生物科技(浙江)股份有限公司

As to cross-border data transfer, we mainly transfer summary clinical trial data which does not contain personal information of enrolled patients for regulatory communications and filings and we have not conducted any cross-border transfer of personal data.

Business · p. 220

During the Track Record Period and up to the Latest Practicable Date, we had complied with all relevant laws and regulations concerning data privacy and security in the PRC and the United States in all material aspects and had not been subject to any material administrative penalty concerning data privacy and security.

Business · p. 220
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28Application ProofCompliance confirmed
Nanjing Novlead Biotechnology Co., Ltd.南京诺令生物科技股份有限公司

In respect of our cross-border data transfer activities, as confirmed by our data compliance legal counsel, we are exempt from applying for the outbound data transfer security assessment, concluding a standard contract for the outbound transfer of personal information or obtaining personal information protection certification, for the reason set out as below.

Business · p. 203

Based on the foregoing, as of the Latest Practicable Date, our Directors and our data compliance legal counsel are of the view that we are not subject to a mandatory cybersecurity review pursuant to the Cybersecurity Review Measures.

Business · p. 203

As such, as of the Latest Practicable Date, our cross-border data transfers are in compliance with the requirements of the Personal Information Protection Law, the Regulation on Network Data Security Management, the Provisions on Promoting and Regulating Cross-Border Data Flows, and other relevant laws and regulations.

Business · p. 205
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-28ProspectusCompliance confirmed
Medcaptain Medical Technology Co., Ltd.深圳麦科田生物医疗技术股份有限公司02041.HK

During the Track Record Period and up to the Latest Practicable Date, we had not transmitted any personal information collected or generated in the course of our operations in Chinese Mainland to any overseas entity, organization or individual.

Business · p. 208

As confirmed by our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, we had not incurred any related administrative penalties.

Business · p. 208
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-27Application ProofCompliance confirmed
Shanghai Vision Star Media Co.,Ltd.上海剧星传媒股份有限公司

None of such information constitutes sensitive personal information or involves any data identified, publicly announced or informed as important data by competent authorities.

Business · p. 136

Based on the foregoing, our PRC Legal Advisor is of the view that we have complied with applicable PRC laws and regulations relating to data privacy, cybersecurity and data security in all material respects.

Business · p. 136
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-26Application ProofCompliance confirmed
Zenshine Pharmaceuticals (Nanjing) Group Co., Ltd.征祥医药(南京)集团股份有限公司

As advised by our PRC Data Compliance Counsel, during the Track Record Period and up to the Latest Practicable Date, we had been in compliance with applicable PRC laws and regulations relating to data privacy, cybersecurity, cross-border data transfer and data security in all material respects, and had not been subject to any administrative penalties or legal proceedings in relation thereto.

Business · p. 197

We were not required to undergo a security assessment, enter into the standard contract for the cross-border transfer of personal information, or obtain personal information protection certification.

Business · p. 197
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-25Application ProofCompliance confirmed
Sublime China Information Co., Ltd.山东卓创资讯股份有限公司

Given the above, our PRC Data Compliance Legal Advisers are of the view that we have completed the self-assessment for outbound data transfer in the course of our business as required under the applicable PRC laws and regulations relating to outbound data transfer and that such outbound data transfer activities are compliant with the applicable PRC laws and regulations relating to outbound data transfer.

Business · p. 174

In addition, during the Track Record Period and up to the Latest Practicable Date, as advised by our PRC Data Compliance Legal Advisers and the Directors confirm that we have complied with the applicable PRC laws and regulations relating to data security, personal information protection and cyber security in all material respects.

Business · p. 175
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-25Application ProofCompliance confirmed
Ugreen Group Limited深圳市绿联科技股份有限公司

Given that (i) CCRC has confirmed that listing in Hong Kong does not constitute a listing abroad; (ii) as of the Latest Practicable Date, we have not received any official notification from relevant regulatory authorities designating our network facilities and information systems as Critical Information Infrastructure (“CII”), and therefore we are not deemed as a CII operator; and (iii) as of the Latest Practicable Date, we had not received any notice that we are required to conduct a cybersecurity review or our data processing activity affects or may affect national security, therefore, our PRC Legal Advisor is of the view that as of the Latest Practicable Date, we were not required to file cybersecurity review under the Measures for Cybersecurity Review for our proposed listing.

Business · p. 190

As advised by our PRC Legal Advisor, we are not required to undergo a data export security assessment, on the basis that: (i) our business does not involve critical information infrastructure, we do not provide services to any critical information infrastructure operators, and we have not been designated as a critical information infrastructure operator by any relevant PRC authority; and (ii) the data involved in our sole cross-border data transmission scenario consists of hash values and device location information, which are not highly sensitive in nature, constitute general personal information only and do not fall within the definition of “important data” under the applicable PRC laws and regulations.

Business · p. 190

In line with our actual business operations, we have filed the Standard Contract for the Cross-Border Transfer of Personal Data (“個人信息出境標準合同”) and obtained the relevant certification.

Business · p. 190
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-24ProspectusNon-compliance
SHEIN Global Holdings Limited希音国际控股有限公司00625.HK

In 2018, we became aware that certain personally identifiable information of our customers, including names, login credentials and credit card information, was stolen during a concerted criminal cyberattack on our computer network.

Risk Factors · p. 61

In October 2022, we reached a settlement agreement with the Office of the Attorney General, pursuant to which we paid US$1.9 million in settlement payment in the same month and have maintained a comprehensive information security programme that includes a series of cybersecurity measures to protect consumer information.

Business · p. 206
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-24Application ProofCompliance confirmed
Zhejiang Rongtai Electric Material Co., Ltd.浙江荣泰电工器材股份有限公司

During the Track Record Period, we did not engage in cross-border data transactions and are not classified as a network platform operator processing personal information of over one million users or an operator of critical information infrastructure under the Cybersecurity Review Measures.

Risk Factors · p. 43

Based on the due diligence conducted and documents reviewed by our PRC data compliance legal advisers on information security and privacy, during the Track Record Period and up to the Latest Practicable Date, we were in material compliance with the PRC laws and regulations relating to cybersecurity, data security and privacy protection, and had not been involved in any material violations, including the unlawful collection, use or provision of data.

Business · p. 178
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-24ProspectusCompliance confirmed
Mech-Mind Robotics Technologies Co., Ltd.梅卡曼德(雄安)机器人科技股份有限公司09615.HK

Our PRC Legal Advisor and legal advisors in other relevant jurisdictions are of the view that, during the Track Record Period and up to the Latest Practicable Date, we have been in compliance in all material respects with applicable laws and regulations relating to cybersecurity, data security and personal information protection in the PRC and other relevant jurisdictions.

Business · p. 201

Furthermore, our domestic official website has successfully obtained the Level II Multi-Level Protection Scheme filing (網絡 安全等級保護二級備案) with the local public security authority.

Business · p. 201
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-24Application ProofCompliance confirmed
Shanghai Eigencomm Technologies Co., Ltd.上海移芯通信科技股份有限公司

Within the business scope of cellular IoT chips research, development and commercialization, our PRC Legal Advisor as to data compliance, is of the view that, we had complied, in all material respects, with the applicable laws and regulations with respect to data privacy, cybersecurity, and personal data protection during the Track Record Period and up to the Latest Practicable Date.

Business · p. 190

All data collected by us within Chinese Mainland is stored domestically.

Business · p. 189
The company's explanation, the adviser's view and the page in the filing: see Matters
2026-08-24ProspectusNon-compliance
SHEIN Global Holdings Limited希音国际控股有限公司00625.HK

In April 2026, the Irish Data Protection Commission (the “DPC”) commenced a statutory inquiry into our transfers of certain EU personal data to China, following a complaint filed by a privacy advocacy group.

Business · p. 207

We are currently cooperating with this investigation and intend to vigorously defend our position that our transfers of EU personal data are compliant with the GDPR.

Business · p. 207
The company's explanation, the adviser's view and the page in the filing: see Matters

Tell us