PDPO Compliance for Generative AI
Tags: Regulatory
TL;DR
- The Guideline anchors service providers to the Personal Data (Privacy) Ordinance (Cap. 486) for all user data handling.
- Emphasises minimisation, encryption/desensitisation, lawful consent, and standardised privacy practices across industries.
Why it matters for HK marketers: Mishandling prompts, uploads, or logs in AI tools can breach PDPO and trigger enforcement and reputational damage.
What’s required under the Guideline
- Lifecycle coverage: Comply with PDPO when collecting, processing, using, storing, retaining, and deleting personal data.
- Security: Strengthen encryption and desensitisation in transfer and storage; work with developers to fix vulnerabilities.
- Governance: Conduct data security surveys among users; avoid excessive collection or misuse; enable consented logging only.
- Transparency: Disclose data practices and risks; align cross-industry privacy protections.
PDPO Cap. 486 explicitly cited for AI services.
6 data handling activities covered (collect, process, use, store, retain, delete).
So what for marketers
Map personal data flows in every AI use case, set retention limits, and require vendors to meet PDPO-grade encryption and consent requirements.
← Back to Knowledge Base