In a blog post, the Hong Kong Mandatory Provident Fund Schemes Authority’s chair set out how the eMPF Platform has been designed, developed and is operated with user privacy and data security as a priority. The post describes a multi-layer security approach aligned with Government policies on handling confidential data and referencing international information security standards and best practices. All user data migrated to eMPF is stored on servers located in Hong Kong and the arrangements are described as fully compliant with the Personal Data (Privacy) Ordinance. Critical data, including personal information, is protected by multiple layers of encryption, supported by independent third-party risk assessments and audit checks, and a 24-hour network monitoring system intended to detect and intercept cyberattacks in real time. The post also describes contingency infrastructure and backup data to restore operations quickly in an emergency, strict access controls limiting case-related data access to authorised personnel in a secured administration office environment, and a prohibition on data replication. Separately, the project team reports multiple rounds of stress testing and ongoing performance optimisation following Digital Policy Office guidelines, supported by phased onboarding of trustees from smaller to larger assets under management to manage system load and enable monitoring and adjustments.
Hong Kong Mandatory Provident Fund Schemes Authority 2025-09-28
Hong Kong Mandatory Provident Fund Schemes Authority outlines eMPF Platform privacy and cyber security safeguards
The Hong Kong Mandatory Provident Fund Schemes Authority detailed the eMPF Platform's design prioritizing user privacy and data security, with a multi-layer security approach compliant with local and international standards. Data is stored on Hong Kong servers, protected by encryption, third-party audits, and 24-hour monitoring. The platform includes contingency measures, strict access controls, and phased onboarding to manage system load.