/ 5 min read / Reed Smith Client Alerts

Hong Kong’s new Guidance on protecting personal data privacy in agentic AI use

On 25 August 2026, the Office of the Privacy Commissioner for Personal Data of Hong Kong (PCPD) published a dedicated guidance document Protecting Personal Data Privacy in the Use of Agentic AI (Guidance). While the Artificial Intelligence: Model Personal Data Protection Framework issued in June 2024 (2024 Framework) remains generally applicable to the use of agentic AI, the Guidance is the PCPD’s first publication to address agentic AI as a standalone topic and signals a step-change in the Hong Kong regulator’s expectations for organisations deploying autonomous AI systems.

The Guidance builds on the PCPD’s evolving suite of AI-related publications, following the 2021 Guidance on Ethical Development and Use of AI, the 2024 Framework, and the March 2025 Checklist on Guidelines for the Use of Generative AI by Employees. This new Guidance follows a period of rapid adoption of open-source agent tools such as OpenClaw across Hong Kong. 

This alert summarises what the Guidance says, its implications for your business, how it compares with mainland China’s parallel regulatory moves, and the steps organisations should take now.

Scope of applicability

This new Guidance applies to data users, including organisations and individuals that collect, hold, process, or use personal data in agentic AI systems. Agentic AI, as described by the PCPD, refers to an intelligent system capable of autonomous perception, memory, decision-making, interaction, and execution, typically built upon foundation models integrated with additional tools such as databases, memory, and computer operating systems.

Risks of using agentic AI

The Guidance highlights that agentic AI poses materially higher personal data privacy risks than conventional AI chatbots, owing primarily to its greater operational autonomy and broader system access. Agentic AI typically operates with elevated default access rights, enabling it to access files, emails, account credentials, and browser-stored contents. Unless stringent access restrictions are implemented, agentic AI may access a vast amount of personal data, increasing the risks of unauthorised access, reproduction of personal data by third parties, or accidental erasure resulting from any misinterpretation of user commands.

The Guidance also warns of “function creep” risks. Agentic AI, by aggregating and recombining personal data from multiple sources, may use such data for purposes beyond those for which it was originally collected, particularly where the data is used to train large language models. These risks are amplified in multi-agent systems. Inaccurate personal data, whether sourced externally or generated through AI hallucination, may cascade across interacting agents, potentially leading to unfair or harmful outcomes for data subjects.

Nine recommendations and a lifecycle security checklist

Building on the six Data Protection Principles (DPPs) outlined in the Personal Data (Privacy) Ordinance (Cap. 486) (PDPO), the PCPD sets out nine data-protection recommendations:

  1. data minimisation and ring-fencing (DPP 1);
  2. transparency in the use of agentic AI for personal data processing (DPP 1 and 5);
  3. accuracy of processed data (DPP 2);
  4. defined retention periods (DPP 2); 
  5. purpose limitation (DPP 3);
  6. security safeguards, such as environment segregation and network controls (DPP 4);
  7. upholding data subject rights in data access and correction (DPP 6);
  8. continuous risk assessment with a human-in-the-loop approach; and
  9. clear governance with staff training

The Guidance is accompanied by a Security Checklist that provides a structured, stage-by-stage framework of practical steps to safeguard personal data privacy when deploying and using agentic AI. The Checklist covers the entire lifecycle of agentic AI use, and is organised into five key phases: evaluation, preparation, deployment, use, and uninstallation. The Checklist distinguishes between measures applicable to organisations and those applicable to individual users. Notably, the Checklist was prepared with reference to the Practical Guidance of Cybersecurity Standards – Security Guidelines for the Deployment and Use of AI Agents, published by the National Technical Committee 260 of China (TC260) in July 2026, signalling a degree of cross-boundary regulatory alignment in addressing the privacy risks of agentic AI.

Organisations remain accountable

The Guidance makes clear that AI agents are not legal persons and that organisations, as data users under the PDPO, remain accountable for complying with the requirements of the PDPO insofar as they control the collection, holding, processing or use of personal data, regardless of the agent’s autonomous capabilities. Organisations must map controller and processor roles across their agentic AI supply chain, assessing whether each provider acts as an independent controller, joint controller, processor, or subprocessor, and include appropriate language to specify the rights and obligations of each party in the service agreement.

Comparison with mainland China

Organisations with operations spanning Hong Kong and mainland China face parallel but materially different regulatory expectations on agentic AI.

The gap lies in enforceability and specificity. Mainland China’s framework is more prescriptive, backed by multi-agency enforcement, and trending towards mandatory filing and registration, while Hong Kong’s approach is non-binding and principles-based. The Guidance supplements the existing PDPO but carries no standalone enforcement mechanism beyond the PDPO’s existing powers.

The framework centres on controllership, transparency, data minimisation, and human-in-the-loop oversight, with organisations left to calibrate the appropriate level of agent authority internally.

Despite the structural differences, both jurisdictions converge on the same core operational expectations: human oversight, least-privilege access, plugin and skill vetting, environment segregation, and continuous monitoring.

Organisations operating across both jurisdictions face cumulative compliance obligations. The prudent approach is to adopt the higher mainland standard as a baseline and layer Hong Kong-specific PDPO requirements on top.

Practical steps

Organisations deploying agentic AI in Hong Kong, particularly those also operating in mainland China, should take the following steps:

  1. Inventory and assess. Map all agentic AI deployments across the organisation, recording autonomy levels, data access scope, and connected third-party plugins or Model Content Protocol servers. Organisations should conduct privacy impact assessments specific to agentic AI, covering each stage of the processing lifecycle, including evaluation, deployment, operation, and cessation.
  2. Implement technical safeguards. Enforce least-privilege access for all agent deployments. Organisations should deploy agents in segregated environments with strengthened network controls. In addition, organisations should vet all plugins and third-party integrations against a whitelist of approved tools and maintain an agent asset register. Moreover, it is advisable to establish human-in-the-loop approval gates for higher-risk or irreversible decisions involving personal data.
  3. Update policies and disclosures. Amend Personal Information Collection Statements and Privacy Policy Statements to disclose the use of agentic AI in personal data processing. Organisations should revise internal AI policies and employee handbooks to address agentic AI specifically, prohibit shadow agents, and set out consequences for non-compliance. 
  4. Strengthen contracts and incident response. Impose data security, accountability, and audit obligations on AI agent vendors. Organisations should clarify controllership and processor roles contractually by including obligations and rights of each party. Moreover, organisations should incorporate agentic AI breach scenarios into existing incident-response plans and rehearse them.
  5. Monitor regulatory developments. Track the PCPD’s ongoing compliance-check programme. In mainland China, organisations should monitor the implementing rules under the applicable regulations, TC260’s evolving technical standards, and progress on the draft AI Law currently before the National People’s Congress.

Client Alert 2026-181

Related Insights