← AI Insights
繁體中文 English 简体中文
Levi · LinkedIn · 2026-09-25

Mainland Firms in HK: AI Cross-Border Compliance

Mainland-linked firms in Hong Kong face three overlapping frameworks (PIPL, DSL, PDPO) plus access limits on US AI services

Cross-Border DataPIPLPDPOGreater Bay AreaMainland Enterprises

Hong Kong maintains a separate legal system under the "One Country, Two Systems" framework, but Mainland-linked companies based in Hong Kong face not one body of law on AI data compliance but two overlapping and partly conflicting regulatory systems — the PIPL and DSL of Mainland China, and Hong Kong's PDPO.

How the PIPL Defines Hong Kong

The Personal Information Protection Law (PIPL, in force since November 2021) explicitly treats Hong Kong as "overseas" for cross-border data transfer. Under Article 38, transferring personal information overseas requires one of three mechanisms: passing a security assessment by the Cyberspace Administration of China (CAC), signing standard contracts (SCCs), or obtaining certification. Article 40 requires large volumes of personal information to be stored within the Mainland, with a security assessment completed before any overseas transfer.

New CAC rules in March 2024 introduced exemption provisions lowering the compliance threshold for low-volume transfers or transfers necessary for a contract, but the basic framework is unchanged. Transferring personal information from Hong Kong to Mainland systems, or processing in Hong Kong personal information obtained from the Mainland, is subject to the PIPL cross-border transfer mechanism requirements.

The Jurisdictional Boundary of the DSL

The Data Security Law (DSL, in force since September 2021) raises a more complex question of applicability to Hong Kong. The DSL applies to data processing activities within China and to overseas activities that harm national security or the public interest. Hong Kong's position under "One Country, Two Systems" leaves legal uncertainty about the DSL's specific jurisdictional boundary over Mainland-linked entities in Hong Kong, and no clear case law exists yet to refer to. The DSL's restriction on storing "important data" overseas likewise raises the question of whether Hong Kong counts as "overseas", on which there is no authoritative interpretation yet.

The Greater Bay Area Exception Framework

In June 2023 the CAC and the Innovation, Technology and Industry Bureau (ITIB) signed a memorandum of cooperation establishing a formal framework for cross-border flows of specific categories of data within the Guangdong–Hong Kong–Macao Greater Bay Area. It is currently the only mechanism supported by formal documentation for data flows between Hong Kong and the Mainland, though its scope is limited to the specific data types the memorandum defines.

Access Restrictions on US AI Services: A Commercial Decision, Not a Regulatory Policy

One widely misunderstood fact: the access restrictions OpenAI and Anthropic apply to Hong Kong are commercial decisions, and are not Hong Kong government policy. OpenAI has restricted Hong Kong users from ChatGPT and its API since July 2024; since September 2025 Anthropic has blocked global companies with majority Chinese ownership, regardless of location. This means a considerable number of Mainland-linked companies in Hong Kong can no longer use the Claude and ChatGPT commercial APIs directly.

Practical alternatives: Google Gemini Cloud (available in Hong Kong, with data residency options), the Microsoft Azure OpenAI enterprise channel (available in Hong Kong), and DeepSeek and Qwen (no access restrictions in Hong Kong, but involving a different set of data sovereignty considerations).

Basic Principles for a Compliance Architecture

Architecture principles that satisfy both the PIPL and the PDPO: use the Greater Bay Area MOU framework for approved categories of data flow; use the PDPO Recommended Model Contractual Clauses (RMCs) for data processor relationships within Hong Kong; use PIPL standard contracts for cross-border flows involving Mainland personal information; and keep unpublished price-sensitive information and highly sensitive commercial information off public AI APIs.

Summary

The challenge of AI compliance for Mainland companies in Hong Kong involves the overlap of three frameworks at the legal level and, at the operational level, the commercial reality of access restrictions from US AI suppliers. Both dimensions need to be addressed explicitly at the AI system design stage, without waiting for a compliance problem to appear before remedying it.

For analysis of the Hong Kong-side framework, see Hong Kong PDPO and AI Compliance: Framework and Enterprise Minimums and Hong Kong AI Regulation 2026: Frameworks, Gaps and Compliance Reality; for the data sovereignty assessment of DeepSeek and Qwen, see DeepSeek and Qwen for Hong Kong Enterprises: Cost, Data Sovereignty and Deployment.

Levi is a Hong Kong-based independent AI engineer specialising in production LLM applications, RAG pipelines, and enterprise AI compliance architecture. Contact for a discussion of the topics covered here.

WhatsApp Free Initial Consultation → More enterprise case studies →

Or email: support@hksoka.com