Privacy is another major part of the framework. The Office of the Privacy Commissioner for Personal Data, or PCPD, said it published a Checklist on Guidelines for the Use of Generative AI by Employees in March 2025 to help organisations develop internal policies or guidelines for employees using GenAI at work while complying with the PDPO.
| Document or framework | Main audience | Practical relevance |
|---|---|---|
| Hong Kong Generative Artificial Intelligence Technical and Application Guideline | Technology developers, service providers and users. | Covers the scope and limits of GenAI applications, potential risks and governance principles. |
| DPO guidance on organisation policies | Organisations adopting GenAI services. | Internal policies may cover approved tools, permitted uses, input information, output use and output storage. |
| PCPD Checklist on Guidelines for the Use of Generative AI by Employees | Organisations whose staff use GenAI at work. | Supports internal staff policies while addressing PDPO compliance. |
| PCPD broader AI privacy guidance | Organisations procuring, using or developing AI systems involving personal data. | Includes practical guidance, ethical principles and a self-assessment checklist to assist PDPO compliance in AI development and use. |
The absence of a standalone AI statute does not remove legal and operational risk. The DPO guideline expressly identifies issues such as data leakage, model bias and errors as technical risks that need to be addressed. The PCPD’s employee GenAI checklist connects workplace use of GenAI with internal policies and PDPO compliance.
In practice, the risk often starts with everyday behaviour: an employee pastes customer information into a public GenAI tool, uses AI output in a client document without review, or stores generated material in a way the organisation cannot audit. Those are not futuristic AI-governance problems. They are current data handling, accuracy, accountability and privacy problems.
The DPO guideline says organisations adopting GenAI services should develop internal policies or guidelines. These may cover permitted tools, including publicly available and internally developed GenAI tools or applications; permitted uses such as drafting, summarising information or creating text, audio or visual content; policy applicability; permitted types and amounts of input information; permitted use of output information; and permitted storage of output information.
The PCPD has also said an AI policy should specify the types of devices on which employees may access GenAI tools and the categories of employees who are permitted to use them.
A workable first version of an AI use policy should therefore answer at least these questions:
For many organisations, the biggest AI compliance question is not whether a tool is labelled as AI. It is whether personal data is being collected, entered, processed, exposed, retained or reused.
The PCPD said its employee GenAI checklist was designed to help organisations create internal workplace policies while complying with the PDPO. Broader PCPD guidance also includes practical guidance, ethical principles and a self-assessment checklist to assist organisations in complying with the Personal Data (Privacy) Ordinance, Cap. 486, when developing and using AI.
That means an AI policy should not be limited to a yes-or-no list of tools. It should also address data sources, lawful and appropriate input, access permissions, output review, storage arrangements and deletion or retention practices. Where a system involves personal data, privacy governance is not an optional add-on; it is central to the deployment.
The DPO guideline is not aimed only at engineers or platform vendors. Government material says it provides practical operational guidance for technology developers, service providers and users.
For employees, the safest starting point is simple: follow the organisation’s internal AI policy before entering company documents, customer information, internal emails or other non-public material into a GenAI tool. If there is no policy, that gap should be escalated rather than treated as permission to proceed.
Users should also avoid treating AI output as automatically correct. The official guidance highlights model bias and errors as risks that need to be handled. Important customer-facing content, legal or financial material, HR decisions, medical or sensitive information, and anything involving personal data should be checked by a responsible human reviewer.
Hong Kong does not currently have a standalone legal framework specifically addressing AI, big data or machine learning, according to a 2025 legal overview. However, organisations still need to consider the DPO’s 2025 GenAI guideline, PCPD privacy guidance and existing PDPO requirements where personal data is involved.
The Digital Policy Office released the Hong Kong Generative Artificial Intelligence Technical and Application Guideline on 15 April 2025. Government news said it covers the scope and limitations of GenAI applications, potential risks and governance principles, and provides practical operational guidance for technology developers, service providers and users.
The DPO guideline says organisations adopting GenAI services should develop internal policies or guidelines covering matters such as approved tools, permitted uses, input information, output use and output storage. The PCPD’s employee checklist was also published to help organisations develop workplace GenAI policies or guidelines while complying with the PDPO.
That depends on the organisation’s policy. The DPO guidance says internal policies may define permitted tools, permitted uses and the types and amounts of information that may be entered into GenAI systems. The PCPD has also said AI policies should identify permitted devices and categories of employees allowed to access GenAI tools.
The best summary of Hong Kong’s 2025 AI position is: no single AI Act, but not a free-for-all. Official GenAI guidance, PCPD privacy materials and the PDPO already create a practical compliance framework for organisations using or deploying AI.
For businesses, the first move should be concrete rather than theoretical: define approved tools, permitted uses, input limits, output handling, storage rules, employee and device access, and privacy review. That is the foundation for safer GenAI use in Hong Kong today.
This article is a source-based information summary and does not constitute legal advice. Organisations planning high-risk AI deployments, handling personal data at scale or operating in regulated sectors should review the official materials and seek professional advice.