Featured Product

    HKMA Sets Out Sound Practices for Data Protection by Banks

    April 04, 2022

    The Hong Kong Monetary Authority (HKMA) has set out sound practices with respect to customer data protection for all authorized institutions.

    HKMA assessed the adequacy and effectiveness of authorized institutions’ customer data protection controls. The findings reveal that the authorized institutions have put in place effective control measures to protect their customer data; however, some areas still need further improvements. For areas that required improvement, the concerned authorized institutions have subsequently taken appropriate remedial actions to strengthen their controls. In the course of the examinations, HKMA has observed some sound practices for customer data protection, which are grouped into four areas and can be summarized as follows:

    • Data Governance—Authorized Institutions should put in place effective data governance framework encompassing risk management process and data security strategy covering customer data protection. The effective data governance framework will ensure that the roles and responsibilities of relevant departments and staff (for example, data owner and three lines of defense) are clearly defined. The framework evaluates the adequacy and effectiveness of the authorized institutions' controls such as identity and access management and encryption controls to safeguard customer data against elevated risk of data breach. Authorized Institutions should also conduct regular assessments to ensure continuous compliance with relevant laws, regulations and their internal policies.
    • Customer data inventory management— Authorized Institutions should identify and document the location of their customer data residing in different parts of its networks, systems, and premises, to facilitate the prevention and detection of loss or leakage of customer data. Institutions should develop clear policies and procedures for maintaining and updating an effective customer data inventory covering all relevant systems and parties, including third parties that process or store customer data. The customer data inventory must be regularly reviewed to ensure completeness and accuracy.
    • Controls over transmission and storage of customer data— Authorized Institutions should adopt effective security measures to minimize the risk of data breach when handling customer data in transit, at rest and at end of life. The institutions should develop data loss prevention policies and measures that are implemented for internal and external communications (for example, e-mail, cloud storage service, and file transfer protocol). Authorized Institutions should take effective measures to address the risk of unauthorized downloading of customer data to portable storage media.
    • Physical and logical security controls of customer data— Authorized Institutions should implement proper physical and logical security controls to prevent customer data from unauthorized access or theft. The institutions should put in place various physical security controls (for example, surveillance cameras and disallowing use of electronic devices) and multi-factor authentication for premises and systems where massive customer data are processed or stored. Authorized Institutions should perform periodic security assessments of customer data protection through on-site inspections covering areas such as network security, physical and logical access controls of operating environments.


    Keywords: Asia Pacific, Hong Kong, Banking, Data Protection, Data Governance, Cyber Risk, Internal Controls, Operational Risk, Basel, Cloud Service Providers, Third-Party Arrangements, Regtech, HKMA

    Featured Experts
    Related Articles

    NGFS Updates Address Short-Term Climate Scenarios and Transition Plans

    The Network for Greening the Financial System (NGFS) is exploring the development of short-term climate scenarios to complement its existing scenario framework of long-term climate scenarios.

    May 31, 2023 WebPage Regulatory News

    ISSB Updates Address ESG Issues while IASB Consults on Impairments

    The International Sustainability Standards Board (ISSB) is seeking feedback, until August 09, 2023, on the exposure draft that sets out the methodology proposed by ISSB to amend the Sustainability Accounting Standards Board (SASB) Standards' metrics

    May 30, 2023 WebPage Regulatory News

    ESRB Publishes Report on Cryptos and DeFi; ECB Updates on Digital Euro

    The European Systemic Risk Board (ESRB) published a report that outlines the systemic implications of crypto markets and proposes policy options to address the risks stemming from crypto-assets and decentralized finance or DeFi.

    May 26, 2023 WebPage Regulatory News

    EU Agencies Issue Updates on DORA, ESAP, and Crowdfunding Regulation

    The European Supervisory Authorities (ESAs) published a discussion paper on their joint advice to the European Commission (EC) on proposals to specify criteria for critical information and communication technology (ICT) third-party service providers

    May 26, 2023 WebPage Regulatory News

    UK Authorities Issue Updates, Finalize Policy on Model Risk Management

    The Prudential Regulation Authority (PRA) finalized the model risk management principles for banks, the policy statement PS5/23 on risks from contingent leverage, and PS4/23 on moving senior managers regime forms from the PRA Rulebook.

    May 25, 2023 WebPage Regulatory News

    APRA Revises Implementation Timeline for Operational Risk Standard

    The Australian Prudential Regulation Authority (APRA) updated the implementation date of the new cross-industry prudential standard CPS 230 on operational risk management

    May 25, 2023 WebPage Regulatory News

    BCBS Consults on Basel FAQs and Amendments, Issues Other Updates

    The Basel Committee on Banking Supervision (BCBS) published a report assessing implementation of the global Basel standards on net stable funding ratio (NSFR) and large exposures (LEX) in South Africa

    May 25, 2023 WebPage Regulatory News

    EBA Announces Multiple Regulatory and Reporting Updates in April 2023

    The European Banking Authority (EBA) published consultations on the amendments to the guidelines on risk-based anti-money laundering and countering the financing of terrorism (AML/CFT) supervision

    May 24, 2023 WebPage Regulatory News

    FSB Issues Statement on USD LIBOR Transition, Issues Other Updates

    The Financial Stability Board (FSB) released a report that offers insights into how financial institutions incorporate climate-related metrics into their compensation frameworks

    May 23, 2023 WebPage Regulatory News

    ACPR Issues Updates on Reporting by Banks and on DLT Pilot Scheme

    The French Prudential Supervisory Authority (ACPR) published reporting updates for the banking sector

    May 22, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8896