Compliance Radar

Who was sanctioned, and for what?

Fines, court rulings and incidents from Europe, North America, Latin America, Asia-Pacific and Middle East: 1,929 cases from 40 jurisdictions, each with an official source and checked against that source before publication. Filter by country, area of law and sector. Click a chart to drill down one level.

1case from 1 jurisdiction
–Total of monetary amounts (0 cases with an amount)
–Largest single case
–Median per case with an amount

Click a bar to drill down one level.

Where?

by authority
  1. Privacy Commissioner for Personal Data (PCPD), Hongkong – 0 % · 1 case

What for?

by area of law

All areas of law

  1. Data protection – 0 % · 1 case

Who?

by company
  1. Kwong's Art Jewellery Trading Company Limited, My Jewelry Management Limited – 0 % · 1 case

When?

per quarter, by date of decision
Trend
PeriodCasesTotal
Q4 20230–
Q1 20240–
Q2 20240–
Q3 20240–
Q4 20240–
Q1 20250–
Q2 20250–
Q3 20251–
Q4 20250–
Q1 20260–
Q2 20260–
Q3 20260–
Q4 20260–

1 case

21 Aug 2025 Kwong's Art Jewellery Trading Company Limited, My Jewelry Management LimitedJewellery companies: data of around 79,400 people stolen – enforcement notices Hong KongData breaches and data security Order

At Kwong's Art Jewellery Trading Company Limited and its retail subsidiary My Jewelry Management Limited, which run their IT systems jointly, an attacker (reported in November 2024) obtained the credentials of an administrator account by brute force, exfiltrated the database and deleted it; around 79,400 individuals were affected, including customers and current and former employees. In its report published on 21 August 2025 the PCPD (Privacy Commissioner for Personal Data, Hong Kong's data protection authority) found breaches of DPP 4(1), among other things because the account of a departed employee had not been deleted in time, server operating systems were outdated and security policies and security assessments were lacking. Both companies were served enforcement notices to remedy the deficiencies and prevent further contraventions.

What organisations can take from it

Delete the accounts of departing staff immediately, keep servers up to date and protect administrator access against brute-force attacks.

Relevance to training and awareness

Access management for leavers, patch management and protection of administrator accounts

Authority / court
Privacy Commissioner for Personal Data (PCPD), Hongkong
Area of law
Data protection · Data breaches and data security
Legal basis
Personal Data (Privacy) Ordinance, Data Protection Principle 4(1); Enforcement Notices
Action
Order
Status of proceedings
unknown
Sector
Retail and e-commerce
Published
21 Aug 2025

Checked against the official source on 3 Oct 2026 · Direct link

Report an error

Anonymous: we store only your text, no contact details and no IP address.

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial