数据合规、网络安全及个人信息

港股IPO招股书披露先例 · 52 家公司,55 项

该类事项涉及个人信息及数据保护、跨境数据传输、网络安全审查、关键信息基础设施运营者、数据安全事件及等级保护等议题。招股书通常在风险因素、业务、财务资料及概要等章节作出披露,内容一般包括事件经过、监管机构的调查或处罚、涉及金额及当前进展,并就合规立场与整改作出说明,例如正配合调查或提出上诉、相关传输在规则明确前已完成且其后停止、已支付和解款项并维持信息安全计划、不合规事项已于处罚前整改,以及据其所知不存在未了结的潜在责任或待决程序等。

合规类事项自 2026 年 8 月 24 日起递交的文件开始收录。

2026-08-28Application Proof合规确认

个人数据收集使用符合数据隐私法律

As advised by our PRC Legal Adviser and U.S. Legal Adviser and based on the due diligence conducted by our U.S. Legal Adviser in connection with the [REDACTED], such collection and use of personal data comply with material applicable laws and regulations concerning data privacy and security in China and the United States during the Track Record Period and up to the Latest Practicable Date.

Business · 第 189 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-28Application Proof合规确认
维眸生物科技(浙江)股份有限公司VivaVision Biotech (Zhejiang) Co., Ltd.

数据隐私及安全合规确认

As to cross-border data transfer, we mainly transfer summary clinical trial data which does not contain personal information of enrolled patients for regulatory communications and filings and we have not conducted any cross-border transfer of personal data.

Business · 第 220 页

During the Track Record Period and up to the Latest Practicable Date, we had complied with all relevant laws and regulations concerning data privacy and security in the PRC and the United States in all material aspects and had not been subject to any material administrative penalty concerning data privacy and security.

Business · 第 220 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-28Application Proof合规确认
南京诺令生物科技股份有限公司Nanjing Novlead Biotechnology Co., Ltd.

数据出境豁免及不适用网络安全审查确认

In respect of our cross-border data transfer activities, as confirmed by our data compliance legal counsel, we are exempt from applying for the outbound data transfer security assessment, concluding a standard contract for the outbound transfer of personal information or obtaining personal information protection certification, for the reason set out as below.

Business · 第 203 页

Based on the foregoing, as of the Latest Practicable Date, our Directors and our data compliance legal counsel are of the view that we are not subject to a mandatory cybersecurity review pursuant to the Cybersecurity Review Measures.

Business · 第 203 页

As such, as of the Latest Practicable Date, our cross-border data transfers are in compliance with the requirements of the Personal Information Protection Law, the Regulation on Network Data Security Management, the Provisions on Promoting and Regulating Cross-Border Data Flows, and other relevant laws and regulations.

Business · 第 205 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-28Prospectus合规确认
深圳麦科田生物医疗技术股份有限公司Medcaptain Medical Technology Co., Ltd.02041.HK

数据合规及个人信息保护合规

During the Track Record Period and up to the Latest Practicable Date, we had not transmitted any personal information collected or generated in the course of our operations in Chinese Mainland to any overseas entity, organization or individual.

Business · 第 208 页

As confirmed by our PRC Legal Advisor, during the Track Record Period and up to the Latest Practicable Date, we had not incurred any related administrative penalties.

Business · 第 208 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-27Application Proof合规确认
上海剧星传媒股份有限公司Shanghai Vision Star Media Co.,Ltd.

数据隐私、网络安全及数据安全合规

None of such information constitutes sensitive personal information or involves any data identified, publicly announced or informed as important data by competent authorities.

Business · 第 136 页

Based on the foregoing, our PRC Legal Advisor is of the view that we have complied with applicable PRC laws and regulations relating to data privacy, cybersecurity and data security in all material respects.

Business · 第 136 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-26Application Proof合规确认
征祥医药(南京)集团股份有限公司Zenshine Pharmaceuticals (Nanjing) Group Co., Ltd.

数据合规及数据出境确认

As advised by our PRC Data Compliance Counsel, during the Track Record Period and up to the Latest Practicable Date, we had been in compliance with applicable PRC laws and regulations relating to data privacy, cybersecurity, cross-border data transfer and data security in all material respects, and had not been subject to any administrative penalties or legal proceedings in relation thereto.

Business · 第 197 页

We were not required to undergo a security assessment, enter into the standard contract for the cross-border transfer of personal information, or obtain personal information protection certification.

Business · 第 197 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-25Application Proof合规确认
山东卓创资讯股份有限公司Sublime China Information Co., Ltd.

数据出境自评估完成且数据合规

Given the above, our PRC Data Compliance Legal Advisers are of the view that we have completed the self-assessment for outbound data transfer in the course of our business as required under the applicable PRC laws and regulations relating to outbound data transfer and that such outbound data transfer activities are compliant with the applicable PRC laws and regulations relating to outbound data transfer.

Business · 第 174 页

In addition, during the Track Record Period and up to the Latest Practicable Date, as advised by our PRC Data Compliance Legal Advisers and the Directors confirm that we have complied with the applicable PRC laws and regulations relating to data security, personal information protection and cyber security in all material respects.

Business · 第 175 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-25Application Proof合规确认

无需网络安全审查及数据出境评估

Given that (i) CCRC has confirmed that listing in Hong Kong does not constitute a listing abroad; (ii) as of the Latest Practicable Date, we have not received any official notification from relevant regulatory authorities designating our network facilities and information systems as Critical Information Infrastructure (“CII”), and therefore we are not deemed as a CII operator; and (iii) as of the Latest Practicable Date, we had not received any notice that we are required to conduct a cybersecurity review or our data processing activity affects or may affect national security, therefore, our PRC Legal Advisor is of the view that as of the Latest Practicable Date, we were not required to file cybersecurity review under the Measures for Cybersecurity Review for our proposed listing.

Business · 第 190 页

As advised by our PRC Legal Advisor, we are not required to undergo a data export security assessment, on the basis that: (i) our business does not involve critical information infrastructure, we do not provide services to any critical information infrastructure operators, and we have not been designated as a critical information infrastructure operator by any relevant PRC authority; and (ii) the data involved in our sole cross-border data transmission scenario consists of hash values and device location information, which are not highly sensitive in nature, constitute general personal information only and do not fall within the definition of “important data” under the applicable PRC laws and regulations.

Business · 第 190 页

In line with our actual business operations, we have filed the Standard Contract for the Cross-Border Transfer of Personal Data (“個人信息出境標準合同”) and obtained the relevant certification.

Business · 第 190 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-24Prospectus不合规事项
希音国际控股有限公司SHEIN Global Holdings Limited00625.HK

2018年数据泄露事件及纽约州总检察长和解

In 2018, we became aware that certain personally identifiable information of our customers, including names, login credentials and credit card information, was stolen during a concerted criminal cyberattack on our computer network.

Risk Factors · 第 61 页

In October 2022, we reached a settlement agreement with the Office of the Attorney General, pursuant to which we paid US$1.9 million in settlement payment in the same month and have maintained a comprehensive information security programme that includes a series of cybersecurity measures to protect consumer information.

Business · 第 206 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-24Application Proof合规确认
浙江荣泰电工器材股份有限公司Zhejiang Rongtai Electric Material Co., Ltd.

数据合规:非关键信息基础设施运营者

During the Track Record Period, we did not engage in cross-border data transactions and are not classified as a network platform operator processing personal information of over one million users or an operator of critical information infrastructure under the Cybersecurity Review Measures.

Risk Factors · 第 43 页

Based on the due diligence conducted and documents reviewed by our PRC data compliance legal advisers on information security and privacy, during the Track Record Period and up to the Latest Practicable Date, we were in material compliance with the PRC laws and regulations relating to cybersecurity, data security and privacy protection, and had not been involved in any material violations, including the unlawful collection, use or provision of data.

Business · 第 178 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-24Prospectus合规确认
梅卡曼德(雄安)机器人科技股份有限公司Mech-Mind Robotics Technologies Co., Ltd.09615.HK

数据合规、网络安全及个人信息保护合规确认

Our PRC Legal Advisor and legal advisors in other relevant jurisdictions are of the view that, during the Track Record Period and up to the Latest Practicable Date, we have been in compliance in all material respects with applicable laws and regulations relating to cybersecurity, data security and personal information protection in the PRC and other relevant jurisdictions.

Business · 第 201 页

Furthermore, our domestic official website has successfully obtained the Level II Multi-Level Protection Scheme filing (網絡 安全等級保護二級備案) with the local public security authority.

Business · 第 201 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-24Application Proof合规确认
上海移芯通信科技股份有限公司Shanghai Eigencomm Technologies Co., Ltd.

数据隐私及个人信息保护合规确认

Within the business scope of cellular IoT chips research, development and commercialization, our PRC Legal Advisor as to data compliance, is of the view that, we had complied, in all material respects, with the applicable laws and regulations with respect to data privacy, cybersecurity, and personal data protection during the Track Record Period and up to the Latest Practicable Date.

Business · 第 190 页

All data collected by us within Chinese Mainland is stored domestically.

Business · 第 189 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-24Prospectus不合规事项
希音国际控股有限公司SHEIN Global Holdings Limited00625.HK

法国CNIL就Cookie同意事宜罚款1.5亿欧元

Subsequently, in September 2025, CNIL issued a fine of EUR 150 million against us in connection with our practices for obtaining user consent and cookie practices, though CNIL conceded that all alleged non-compliance had been remediated prior to the fine.

Business · 第 207 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看
2026-08-24Prospectus不合规事项
希音国际控股有限公司SHEIN Global Holdings Limited00625.HK

爱尔兰DPC就欧盟个人数据传输至中国启动法定调查

In April 2026, the Irish Data Protection Commission (the “DPC”) commenced a statutory inquiry into our transfers of certain EU personal data to China, following a complaint filed by a privacy advocacy group.

Business · 第 207 页

We are currently cooperating with this investigation and intend to vigorously defend our position that our transfers of EU personal data are compliant with the GDPR.

Business · 第 207 页
公司的解释、律师意见及原文页码定位:在 Matters 中查看

Tell us