Skip to main content
What's New

Disclosure Records of Recognized Certification Authorities

Disclosure Record for the Postmaster General

(This is page 40 of the disclosure record for the Postmaster General maintained by the Commissioner for Digital Policy (“CDP”) under section 31(1) of the Electronic Transactions Ordinance (Cap. 553) (“ETO”). Click this link to go back to page 1 of the disclosure record.)

Assessment Report and Statutory Declaration in respect of Certification Authority Infrastructure Upgrade

Postmaster General (“PMG”) (hereinafter referred to as Hongkong Post CA (“HKPCA”)) planned to upgrade its certification authority infrastructure for e-Cert services. The Commissioner for Digital Policy (the “CDP”) considered that the changes involved in the certification authority infrastructure upgrade are major changes. In this light, the CDP had, by notice given to the HKPCA, required the HKPCA to furnish to the CDP an assessment report and a statutory declaration pursuant to section 43A(1) of the ETO. In this connection, HKPCA arranged the preparation of an assessment report produced by an independent assessor as well as furnished a statutory declaration made by a responsible officer of HKPCA in relation to the certification authority infrastructure upgrade.

In accordance with section 43A(3) of the ETO, the CDP must publish in the disclosure record for HKPCA as a recognized CA the dates of and the material information in the assessment report and statutory declaration on the CA services of the HKPCA. Only those parts of the report and statutory declaration containing material information are herewith published.

Assessment Report

A. Date of the Report

  • The date of the report is 31 August 2025.

B. Material Information

  1. In the assessor's opinion, in all material respects:
    1. the management assertions, in respect of HKPCA's and Certizen as its agent's capability to comply with the sections of the ETO, the COP (See Note 1) and the MRCP (Note 2) set out in Appendix 3 of the assessment report (See Note 3) are reasonable. In particular, HKPCA with Certizen as its agent is capable of:
      1. disclosing its business practices in its CPS (see Note 4) in accordance with the ETO and the COP and the MRCP and providing its services in accordance with its disclosed business practices.
    2. no information came to the assessor’s attention during the course of the assessment that would indicate that the management assertions in respect of HKPCA’s and its agent’s capability to comply with the sections of the COP set out in Appendix 4 of the assessment report are not reasonable; and
    3. based on the conclusions drawn in paragraphs (a) and (b) above, the management assertions, in respect of HKPCA’s and its agent’s capability of complying with the provisions of the ETO applicable to a recognized CA and the COP are reasonable.

Statutory Declaration

A. Date of the Declaration

  • The date of the declaration is 26 September 2025.

B. Material Information

  • Having regard to HKPCA’s certification authority infrastructure upgrade, a responsible officer of HKPCA declares that HKPCA as an RCA (See Note 5) is capable of complying with the provisions of the ETO and the provisions of the COP which have been set out under paragraph 2 of Appendix of Annex I of the memorandum from the CDP dated 27 January 2025 (see Note 6).

Notes

1. Code of Practice for Recognized Certification Authorities (“COP”) (Version 3.2) issued by the CDP under section 33 of the ETO.

2. Certificate Policy for Mutual Recognition in Electronic Signature Certificates Issued by Hong Kong and Guangdong (“MCRP”).

3. The Appendix 3 of the assessment report is extracted as follows:

Applicable ETO provisions

    1. Part X - General Provisions as to Recognized CAs:
      Sections 36, 37, 39, 40, 44 and 45(1).
    2. Part XI - Provisions as to Secrecy, Disclosure and Offences:
      Sections 46, 47 and 48.

Applicable Code of Practice provision

    1. General Responsibilities of a Recognized CA:
      Paragraphs 3.1 to 3.6 inclusive and 3.8.
    2. Certification Practice Statement:
      Paragraphs 4.1 to 4.13 inclusive.
    3. Trustworthy System:
      Paragraphs 5.1 to 5.3 inclusive, 5.6 to 5.17 inclusive and 5.19 to 5.21 inclusive.
    4. Certificates and Recognized Certificates:
      Paragraphs 6.1 to 6.23 inclusive.
    5. Reliance Limit and Liability Cover:
      Paragraphs 8.1 to 8.4 inclusive.
    6. Repositories:
      Paragraphs 9.1 to 9.5 inclusive.
    7. Disclosure of Information:
      Paragraphs 10.1 to 10.6 inclusive.
    8. Adoption of Standards and Technology:
      Paragraph 14.1.
    9. Inter-operability:
      Paragraphs 15.1 and 15.2.
    10. All paragraphs in Appendix 1 of the Code of Practice, which are applicable to the requirements stipulated in the MRCP.

4. Certification Practice Statements (“CPS”).

5. Recognized Certification Authority (“RCA”).

6. Paragraph 2 of Appendix of Annex I of the memorandum from the CDP is reproduced below for reference:

2. For the purpose of section 43A(1)(d)(i) of the ETO

2.1 A responsible officer of PMG shall make a statutory declaration which states that, having regard to PMG’s Certification Authority infrastructure upgrade, PMG is capable of complying with the following provisions of the COP.

    1. General Responsibilities of a Recognized CA:
      Paragraphs 3.7 and 3.9.
    2. Trustworthy System:
      Paragraph 5.18.
    3. Disclosure of Information:
      Paragraphs 10.7 to 10.9 inclusive.
    4. Consumer Protection:
      Paragraph 16.1.

2.2 A responsible officer of PMG shall make a statutory declaration which states that, having regard to PMG’s Certification Authority infrastructure upgrade, PMG is capable of complying with the MRCP.