This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 3 minute read

Agentic AI and Data Privacy: Hong Kong SAR’s Regulator Sets Out What Businesses Should Do

AI tools have moved beyond the chatbot. The Office of the Privacy Commissioner for Personal Data (PCPD) has published formal guidance on “Protecting Personal Data Privacy in the Use of Agentic AI” (“Agentic AI Guidelines”) on 25 August 2026 to supplement the Model Framework issued in June 2024, making clear that the shift to Agentic AI brings elevated privacy obligations. While the Agentic AI Guidelines are not law, the guidance signals what the PCPD regards as compliant behaviour. If your organisation is using, or is considering using, agentic AI, this new guidance demands your attention.

Automation by Agentic AI Does Not Dilute Accountability

The Agentic AI Guidelines define Agentic AI as “an intelligent system with the capabilities of autonomous perception, memory, decision-making, interaction and execution”, drawing upon the definition introduced by the Security Guidelines for the Deployment and Use of AI Agents issued by the Chinese Mainland’s National Cybersecurity Standardization Technical Committee 260 in July 2026. The guidelines further emphasise that AI agents are not legal persons, and that data users remain accountable for complying with the requirements of the Personal Data (Privacy) Ordinance (PDPO), including the six Data Protection Principles (DPPs), insofar as personal data is collected, held, processed or used by an AI agent. 

Nine Things the PCPD Expects Agentic AI Users to Do

Unlike conventional chatbots, agentic AI typically operates with elevated system access, enabling it to read files, send communications, execute transactions and interact with third-party services autonomously. Multiple AI agents can also operate in parallel within a single system, compounding the potential for data to be aggregated, repurposed or cascaded across workflows in ways that are difficult to monitor or reverse. These characteristics sit uncomfortably with several of the core DPPs, particularly those governing purpose limitation, data accuracy and security. The Agentic AI Guidelines set out nine practical recommendations for organisations and individual users of agentic AI. At a high level, these are:

  1. Data minimisation. Personal data should only be collected for a lawful purpose directly related to a function or activity of the organisation or the individual user. Access control should ringfence the information and systems that an agentic AI may access for a specific purpose. 

  2. Transparency. Organisations should be transparent about their use of agentic AI when processing personal data. For instance, by including such information in their Personal Information Collection Statements (PICS) and Privacy Policy Statements, and may also consider stating the region(s) where personal data is stored or processed. 

  3. Accuracy. Organisations and individual users who process personal data when using agentic AI shall take all practicable steps to ensure the accuracy of personal data processed by agentic AI, including adopting approaches such as chain of thought, retrieval-augmented generation, context-specific fine-tuning and human review. 

  4. Retention limits. Agentic AI systems that maintain conversation histories, cache data or long-term memory containing personal data must not keep such data longer than is necessary, and organisations and individual users are recommended to implement measures to erase personal data that is no longer required. 

  5. Purpose limitation. Organisations and individual users who process personal data should clearly delineate the purposes for which data will be collected and processed by agentic AI, and the circumstances under which human oversight is required. 

  6. Security measures. To protect personal data against unauthorised or accidental access, processing, erasure, loss or use, organisations and individual users should adopt a “human-in-the-loop” approach where the decisions made by agentic AI may have a significant impact on individuals. This includes the implementation of robust technical safeguards, such as including using only verified, up-to-date versions of agentic AI, isolating runtime environments, vetting plugins, and applying LLM guardrails to protect personal data against unauthorised access or leakage. Access rights should be restricted to the minimum necessary, sensitive data should not be shared with AI agents arbitrarily, and systems should have logging and audit capabilities to ensure traceability of all agent operations.

  7. Data access and correction rights. Organisations should select agentic AI systems that adopt the principles of “privacy-by-design” and “privacy-by-default” to ensure that the systems support the exercise of data access and correction rights under the PDPO. 

  8. Continuous risk assessment. Organisations should continuously assess personal data privacy risks and remain vigilant to any requests by agentic AI to execute high-risk operations, including high-stakes, irreversible or atypical actions such as approving transmission of personal data to third parties or permanently deleting personal data. 

  9. Governance and training. Organisations should establish an internal governance structure with sufficient resources, expertise and decision-making authority, and provide adequate training to all relevant personnel. When engaging an external vendor, organisations should use contractual or other means to ensure that the data processor complies with relevant PDPO requirements. 

What Should You Do Now?

Agentic AI systems, by virtue of their broad access rights, autonomous decision-making and capacity to aggregate personal data across multiple sources, present compliance challenges that existing privacy frameworks may not adequately address.

Organisations should begin by assessing whether agentic AI tools are already in use across their operations and evaluating the adequacy of current AI and data governance arrangements, including privacy policies, access controls, retention practices and data processing agreements. Where deployment is planned, a data protection impact assessment should be conducted at the outset.

If you would like to discuss how this guidance applies to your organisation's use of AI, please contact the Linklaters Asia TMT/IP Team. 

To stay up to date with the latest tech developments - subscribe now!

Tags

agentic, ai, data and cyber