← AI Insights
繁體中文 English 简体中文
Levi · LinkedIn · 2026-09-25

HK PDPO and AI Compliance: Minimum Requirements

The PDPO applies to AI through existing principles, and DPP1, DPP3 and DPP4 are the core items to assess before deployment

Further reading: Healthcare Admin AI in Hong Kong: Data Boundaries

PDPOPCPDData ProtectionAI ComplianceCross-Border Data

The Personal Data (Privacy) Ordinance (PDPO, Cap. 486) was not designed specifically for AI, yet at a time of widespread AI adoption its core principles set concrete compliance boundaries for AI data processing. Understanding which data protection principles (DPPs) AI systems affect most directly, and the current framework of data processor obligations, is the compliance assessment groundwork an enterprise needs before deploying AI tools.

The Three Most Directly Affected DPPs

DPP1 (data collection): personal data may only be collected by lawful and fair means, for a lawful purpose directly related to a function of the data user. Using existing customer or employee data for AI model training may breach DPP1 if it goes beyond the original purpose of collection.

DPP3 (data use): personal data may only be used for the purpose for which it was collected or a directly related purpose, unless the data subject's prescribed consent is obtained. Training an AI model on an existing database almost inevitably involves a new use outside the original collection purpose — the first compliance question an enterprise needs to assess before an AI project starts.

DPP4 (data security): data users must take practicable steps to protect personal data from unauthorised or accidental access, processing, erasure or use, including when data is outsourced to an overseas AI service provider. This is the most direct source of compliance obligations for enterprises using external AI APIs.

The PCPD's Current Framework Documents

In June 2024 the PCPD published "AI: Model Personal Data Protection Framework", giving best-practice guidance for implementing LLM and generative AI systems. Enterprises should treat it as the de facto reference standard for meeting the PDPO (DPP4 in particular). In March 2025 the PCPD further published a checklist on guidelines for the use of generative AI by employees, providing an operational-level checking framework.

The PCPD's 2025 compliance checks covered 60 organisations across telecommunications, banking, insurance, healthcare, retail, education and other sectors. 80% of them used AI in daily operations, and no PDPO contraventions were found during the checks.

Data Processor Contract Obligations

When an enterprise uses an external AI API (such as Anthropic Claude, Google Gemini, or OpenAI via the Azure enterprise channel), it is responsible as data user for the security safeguards of the data processor. The Recommended Model Contractual Clauses (RMCs) published by the PCPD in 2022 provide two contract templates covering purpose limitation, data security measures, data retention and deletion requirements, audit rights and sub-processor controls. The PCPD recommends incorporating the RMCs into commercial agreements with AI suppliers.

The Practical Position on Cross-Border Data Transfer

Section 33 of the PDPO (restrictions on cross-border transfer of personal data) has never come into force, so Hong Kong currently has no statutory restriction on cross-border transfer. In practice, the PCPD's RMCs represent best practice without statutory force, but enterprises that disregard PCPD guidance face reputational and regulatory risk. The existing DPPs (DPP4 in particular) still apply in full in cross-border situations, meaning data security obligations do not disappear when data is sent overseas.

The government is advancing PDPO reform, and mandatory data breach notification and administrative fines have entered the consultation process. As of mid-2026, mandatory notification has not yet been legislated, but the Legislative Council held a motion debate in July 2025 on whether the PDPO is adequate in the AI era, giving the reform direction policy support.

The Key Test for Consent

Where personal data used for AI training or analysis is put to a new use outside the original collection purpose, the data subject's prescribed consent is required. Under the PDPO, "prescribed consent" means consent that is express, voluntary and given with knowledge — a pre-ticked checkbox buried deep in the terms of service does not meet this requirement.

Minimum Compliance Checklist for Enterprise AI

Before deploying any AI system that uses personal data, the following assessments are recommended: confirm whether the AI processing purpose falls within the original purpose of data collection; sign a data processing agreement with the AI supplier that contains the key PCPD RMC clauses; confirm the security safeguards for data sent to overseas AI APIs; and establish a data breach response procedure for the AI system (even though mandatory notification is not yet legislated, voluntary notification remains good compliance practice).

Summary

The PDPO applies to AI systems by extending existing principles, without AI-specific legislation. DPP1, DPP3 and DPP4 are the three most critical principles, and the use of external AI APIs triggers the most direct compliance obligations under DPP4. Including an assessment against the PCPD framework documents when an AI project starts costs far less than dealing with compliance problems after go-live.

For practical questions on data flows, see Are Your Documents Uploaded to the US? Data Flows to Know Before Using AI on Confidential Files; for PDPO application in hiring, see AI Recruitment Screening in Hong Kong: Law and Bias; for the overall cross-sector regulatory framework, see Hong Kong AI Regulation 2026: Frameworks, Gaps and Compliance Reality.

Levi is a Hong Kong-based independent AI engineer specialising in production LLM applications, RAG pipelines, and enterprise AI compliance architecture. Contact for a discussion of the topics covered here.

WhatsApp Free Initial Consultation → More enterprise case studies →

Or email: support@hksoka.com