This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 4 minute read

Asia TMT Bulletin – July 2026

The July 2026 edition of our Asia TMT Bulletin reflects a month of broad regulatory momentum across the region, with developments spanning data privacy, cybersecurity, intellectual property, artificial intelligence, and digital assets.

China is advancing its data governance framework with finalised classification guidelines for financial information service providers and five new draft national standards. Hong Kong's SFC has put licensed corporations on notice over AI-enabled cyber threats, whilst Thailand introduces a new PDPA certification scheme and consults on amendments to its Cybersecurity Act. Elsewhere, Singapore's CSA has issued new guidance on securing agentic AI systems, Australia's High Court has confirmed that a fixed-yield cryptocurrency product constitutes a financial product under the Corporations Act, and both Singapore and Hong Kong are taking steps to make their patent systems more accessible and commercially attractive.

There seems to be a lot going on…!

Data Privacy

China: Finalised data classification and grading guidelines for financial information service providers 

The Cyberspace Administration of China has finalised guidelines requiring financial information service providers to classify their data across a three-tier framework (with 67 tertiary categories) graded at four levels. Providers holding datasets over certain thresholds will trigger enhanced obligations including directory submission to the competent authority. 

China: Five draft national standards for public consultation

China’s national standardisation committee, TC260, has sought public comments on five draft national standards covering critical information infrastructure security assessments, automated network data collection tools, personal information security specifications, AI application safety for minors, and zero trust capability maturity modelling.

Thailand: PDPC introduces PDPA certification scheme

The Office of the Personal Data Protection Committee (PDPC) has introduced a Personal Data Protection Act (PDPA) certification scheme, awarding certificates and certification marks to public and private organisations meeting 128 criteria across 10 areas. Organisations scoring 80–89.9% receive a Compliance Certificate; those scoring 90% or above receive a PDPA Certificate and certification mark.

Cybersecurity

Hong Kong: SFC issues cybersecurity circular on AI-enabled threats

The Hong Kong Securities and Futures Commission (SFC) has issued a circular urging licensed corporations and virtual asset service providers to review and enhance their cybersecurity frameworks, against the backdrop of a 27% year-on-year increase in cybersecurity incidents and increasingly sophisticated AI-enabled threats. Highlighted risks include AI-assisted zero-day vulnerability exploitation, deepfake impersonation and chained lower-risk vulnerabilities capable of causing high-impact disruption.

Thailand: Proposed revision to the Cybersecurity Act

The National Cybersecurity Agency sought public comments during a one-month consultation on draft amendments to the Cybersecurity Act B.E. 2562 (2019). Key proposals include strengthened powers for cybersecurity regulatory bodies, enhanced incident response obligations, and new compliance inspection authorities.

Intellectual Property

Hong Kong: IP Financing Sandbox records first approval; patent valuation scheme to launch

The Hong Kong Government confirmed the IP Financing Sandbox has seen its first approval, and a two-year Pilot Patent Valuation Support Scheme for eligible SMEs is expected to launch in Q3 2026, advancing Hong Kong's efforts to promote IP-backed financing. 

Singapore: IPOS introduces enhancements to the Patent Prosecution Highway programme

The Intellectual Property Office of Singapore (IPOS) has introduced two enhancements to the Patent Prosecution Highway (PPH), a programme that offers faster and more efficient patent examination through IPOS’ global partnerships. The enhancements are designed to encourage uptake of the PPH. Firstly, from 1 July 2026, IPOS will endeavour to issue first office actions within six months of a PPH request. Secondly, from 3 August 2026 to 31 December 2027, applicants filing a PPH request alongside a new search and/or examination request will pay only 70% of prevailing official fees upfront.

Artificial Intelligence

Singapore: CSA publishes addendum to the Guidelines and Companion Guide on Securing AI Systems

On 17 June 2026, the Cyber Security Agency of Singapore (CSA) published an addendum to its Guidelines and Companion Guide on Securing AI Systems, developed in collaboration with industry, government and international partners. Recognising that agentic AI’s ability to act autonomously introduces new and heightened cybersecurity risks, the addendum provides system owners with practical guidance on identifying and assessing risks specific to agentic AI workflows and implementing controls to mitigate those risks across the development lifecycle.

Digital Assets

AustraliaHigh Court finds that fixed-yield cryptocurrency product constitutes a financial product 

Australia's High Court confirmed that Block Earner’s ‘Earner’ fixed-yield cryptocurrency product constitutes a financial product under the Corporations Act 2001 (Cth) and that Block Earner consequently required an Australian financial services licence. The Court held that the underlying arrangements and contractual substance of Earner ultimately governed its classification as a financial product.

Digital Transformation

Singapore: IMDA launches S$48 million Digital Content and Capability Development programme

The Infocomm Media Development Authority launched the S$48 million Digital Content and Capability Development programme on 18 June 2026 to support Singapore’s media professionals and companies in adapting to a digital-led media landscape. Spanning four years, the programme supports digital content creation and distribution across emerging formats, fosters AI-assisted production workflows, and provides capability development opportunities, including AI training under the National AI Impact Programme.

UAE: UAE establishes Federal Authority for Artificial Intelligence and Data 

The UAE approved the establishment of the Artificial Intelligence and Data Authority, consolidating the country’s AI and data governance functions under a single dedicated federal body. The Authority’s mandate spans national AI strategy, data governance, digital government standards, and international partnerships. It will operate AI-powered data platforms, drive evidence-based decision-making, ensure federal compliance, and build national AI and digital transformation capabilities through research and technical advisory services.

Sanctions 

Australia: Privacy Commissioner finds breaches in third-party tracking pixel investigation

In two separate determinations, the Australian Privacy Commissioner found that health service providers Medmate Australia Pty Ltd and Monash IVF Pty Ltd interfered with individuals' privacy, within the meaning of s 13(1) of the Privacy Act 1988 (Cth), by using third-party tracking pixels on their telehealth and fertility websites. The pixels collected sensitive visitor information and used it to target individuals with advertising on social media platforms without their consent. The Privacy Commissioner has issued declarations ordering the service providers to, among other things, cease collecting sensitive information through tracking pixels and destroy all sensitive information collected. 

To stay up to date with the latest tech developments - subscribe now!

Tags

ai, data and cyber, ip, online safety