Hong Kong PDPO (Cap. 486)
Tags: Regulatory
Role in Generative AI Services
The Personal Data (Privacy) Ordinance (PDPO) (Cap. 486) is cited in the Guideline as a key regulation governing personal data handling by Service Providers of generative AI. Compliance is required when collecting, processing, using, storing, retaining, and deleting user data, including personal data.
Provider Obligations (as outlined in the Guideline)
- Lawful processing: Adhere to PDPO requirements across the full data lifecycle.
- Privacy protection: Avoid excessive collection, misuse, or disclosure of user data; protect Service Users’ privacy rights.
- Security controls: Strengthen encryption and data desensitisation for sensitive data, particularly during transfer.
- Governance and collaboration: Where needed, work closely with Technology Developers and conduct data security surveys among Service Users to identify and remedy vulnerabilities.
Context within Governance Dimensions
PDPO compliance aligns with the Guideline’s governance dimension of Personal Data Privacy, which stresses:
- Clear purposes and methods of personal data collection
- Accuracy and retention duration controls
- Transparent policies and practices, and user access/correction rights
Significance
By anchoring provider practices to the PDPO, the Guideline embeds privacy-by-design norms into the deployment of generative AI services in Hong Kong. This supports public trust, reduces the risk of data exposure and misuse, and ensures AI adoption proceeds in accordance with Hong Kong’s statutory data protection framework.
Sources:- HK_Generative_AI_Technical_and_Application_Guideline_en.pdf
← Back to Knowledge Base