PDPO Data Protection Principles for AI
Tags: Regulatory
TL;DR
- The framework maps AI Data Privacy to PDPO DPP1–DPP5.
- Covers lawful collection, accuracy/retention, purpose/use limits, security, and openness.
Why it matters for HK marketers: AI that handles personal data must align with PDPO to avoid breaches in targeting, analytics, and automation.
The five principles applied to AI
- DPP1 — Purpose and Manner of Collection: Inform purpose and potential transferees; collect lawfully, fairly, and not excessively for the stated purpose.
- DPP2 — Accuracy and Duration of Retention: Take practicable steps to ensure accuracy and avoid keeping data longer than necessary.
- DPP3 — Use of Personal Data: Use only for original or directly related purposes; otherwise obtain express, voluntary consent.
- DPP4 — Security of Personal Data: Protect against unauthorised or accidental access, processing, erasure, loss, or use.
- DPP5 — Information to Be Generally Available: Provide information on policies/practices, kinds of personal data held, and main purposes of use.
Practical implications for AI
- Limit model features to non-excessive data; document purposes.
- Build data quality checks and retention schedules into pipelines.
- Enforce use limitations in downstream activations; manage consent.
- Implement security controls for training, inference, and storage.
- Publish accessible privacy information covering AI uses.
5 PDPO Data Protection Principles are explicitly referenced for AI privacy.
So what for marketers
Audit current AI use against DPP1–DPP5, especially purpose limitation and consent handling across CDPs, ML models, and activation channels.
← Back to Knowledge Base