Hong Kong Privacy Commissioner Issues Agentic AI Data-Protection Guidance
Key Takeaways
- 01The PCPD issued agentic-AI privacy guidance on 25 August 2026.
- 02The guidance addresses risks including excessive data access, function creep and inaccurate personal data.
- 03The PCPD recommends nine safeguards, including transparency, data minimisation, security, auditability and human oversight.
- 04Organisations using agentic AI should review the data and system permissions available to AI agents and maintain controls over their actions.
Hong Kong’s Office of the Privacy Commissioner for Personal Data (PCPD) published guidance on 25 August 2026 on protecting personal-data privacy when using agentic AI. Agentic AI refers to systems that can independently plan, make decisions and take actions to pursue assigned goals.
The guidance aims to help organisations manage privacy risks arising when these systems access, combine and act on personal data. The PCPD highlights excessive data access, function creep—using data for purposes beyond the original purpose—and inaccurate data as key risks.
The PCPD recommends nine safeguards. They include being transparent about agentic-AI use, collecting and using only data that are necessary, implementing appropriate security controls, maintaining auditability of AI actions and decisions, and ensuring meaningful human oversight.
Organisations deploying agentic AI should assess what data an AI agent can access, what actions it can take, and whether its permissions remain necessary as its functions change. They should also be able to monitor and investigate the system’s use of personal data and retain human control over consequential activities. The guidance is relevant to organisations subject to Hong Kong’s Personal Data (Privacy) Ordinance.