PCPD e-NEWSLETTER
ISSUE July 2026
|
|
|
|
|
PCPD e-NEWSLETTER
ISSUE July 2026
|
|
|
|
|
Privacy Commissioner’s Office Wins Governance Project of the Year and Outreach Project of the Year at Asia-Pacific Awards
|
Privacy Commissioner Ms Ada CHUNG Lai-ling received the awards in Singapore.
|
The PCPD has received two accolades at the Asia Pacific GovMedia Conference & Awards 2026, namely the “Hong Kong Governance Project of the Year – Regulatory” and the “Hong Kong Outreach Project of the Year – Regulatory” awards, in recognition of its guidance on the “Checklist on Guidelines for the Use of Generative AI by Employees” and the effect of its outreach efforts relating to “Abuse of AI Deepfakes: Toolkit for Schools and Parents”, respectively. “Hong Kong Governance Project of the Year – Regulatory” The “Governance Project of the Year – Regulatory” award recognises exceptional initiatives or practices of public organisations. Published in March 2025, the “Checklist on Guidelines for the Use of Generative AI by Employees” (Guidelines) provide a practical checklist to assist organisations in developing internal policies or guidelines on the use of generative artificial intelligence (AI) by employees at work, while complying with the requirements of the Personal Data (Privacy) Ordinance (PDPO). Since its publication, the Guidelines have been widely adopted across various sectors. According to the PCPD’s compliance checks conducted in 2026, more than 90% of organisations that collected and/or used personal data through AI systems had either referred, or planned to refer, to the PCPD’s guidance materials on AI, including the Guidelines. In addition, the Chinese YouTube video introducing the Guidelines has attracted more than 160,000 views and over 120,000 views for the video in English, reflecting strong public interest in the Guidelines. “Hong Kong Outreach Project of the Year – Regulatory” The “Outreach Project of the Year – Regulatory” award celebrates initiatives that excel in reaching and engaging their target audiences, fostering positive relationships, and making long term and meaningful impact on communities or stakeholders. Published in December 2025, the “Abuse of AI Deepfakes: Toolkit for Schools and Parents” (Toolkit) provides practical advice to schools and parents to help them prevent and handle deepfake incidents involving children and young people, while safeguarding their privacy in relation to personal data. The award commends the PCPD in promoting the recommendations in the Toolkit to schools and parents through talks, seminars, workshops and media interviews to raise awareness of the risks posed by malicious deepfakes, thereby protecting children and young people. These outreach efforts included presentations on the Toolkit at seminars respectively attended by more than 700 teachers and over 100 primary school principals. The Toolkit helps foster collaboration among schools, parents, children and young people in preventing malicious deepfake incidents. Moreover, the award recognises the deep and meaningful impact of the Toolkit on the community in light of the incidents involving misuse of AI-generated images of children and young people that happened in early 2026. The GovMedia Conference & Awards is organised by Asia-Pacific news platform GovMedia to celebrate the outstanding achievements of government and public sector projects and initiatives in the Asia-Pacific region and recognise public organisations that demonstrate exceptional leadership, creativity and impact in public services.
|
Privacy Commissioner Promotes China’s Initiative
at Asia DPA Exchange
Joining Hands to Build a Global AI Governance System
|
Privacy Commissioner Ms Ada CHUNG Lai-ling (right) promoted China’s Global AI Governance Initiative during a panel discussion at the Asia DPA Exchange of the Singapore Data Festival.
|
Privacy Commissioner Ms Ada CHUNG Lai-ling (right) and the Chief Executive of the Singapore Academy of Law, Mr YEONG Zee-Kin (left), signed a Memorandum of Understanding.
|
Privacy Commissioner Ms Ada CHUNG Lai-ling attended the Singapore Data Festival (Data Festival) and Asia Data Protection Authorities (DPA) Exchange, organised by Singapore’s Infocomm Media Development Authority and Personal Data Protection Commission in Singapore from 20 to 22 July.
On 21 July, the Privacy Commissioner attended the Asia DPA Exchange and joined the Commissioner of Singapore’s Personal Data Protection Commission in a panel discussion titled “Governing Personal Data in the Age of Gen AI”. During the discussion, the Privacy Commissioner pointed out that at the World AI Conference 2026 recently held in Shanghai, China advocated that all countries should adopt a people-centred approach, develop AI for the positive and for good, and join hands to build a just and equitable system for global AI governance. The Privacy Commissioner underscored the significance of the initiative to participants, and highlighted the three-C (facilitating Compliance, Communication and Collaboration) multi-pronged strategy adopted by the PCPD to assist organisations in adopting AI technologies in a safe and responsible manner, thereby supporting Hong Kong’s development as an international innovation and technology centre.
During the Data Festival, the Privacy Commissioner also attended the International Association of Privacy Professionals (IAPP) Asia Forum 2026 organised by the IAPP on 22 July. She joined commissioners from regulators in the Philippines, Singapore and Thailand in a panel discussion titled “How Asian Regulators are Shaping AI and Data Governance”. The Privacy Commissioner shared insights and experience gained from three rounds of compliance checks relating to AI conducted by the PCPD since 2023. She also introduced the award-winning AI guidance materials issued by the PCPD, including the “Artificial Intelligence: Model Personal Data Protection Framework” (Model Framework) and the Guidelines, which assist organisations in adopting AI technologies in a safe, responsible and privacy-friendly manner, and in establishing effective AI governance and risk management framework.
In addition, the PCPD and the Hong Kong International Data Privacy Academy (Academy) signed a Memorandum of Understanding (MoU) with the Singapore Academy of Law and the Asian Business Law Institute in Singapore on 22 July to further deepen their partnership. The MoU seeks to leverage the unique roles of Hong Kong and Singapore as gateways to China and ASEAN countries respectively to strengthen knowledge exchange and collaboration among legal professionals, businesses and other stakeholders in the respective countries, thereby promoting exchanges and cooperation between enterprises in China and those in ASEAN countries.
During the Data Festival, the Privacy Commissioner also met or held bilateral meetings with government officials of Singapore and representatives of privacy or data protection authorities of ASEAN countries, including the Chief Executive of the Authority for Info-communications Technology Industry of Brunei Darussalam and the Chairperson of the Personal Data Protection Committee of Thailand. The meetings covered a range of topics, including personal data protection, AI governance, and served to strengthen ties between the PCPD and data protection authorities in other jurisdictions. Furthermore, the Privacy Commissioner met with industry leaders, including representatives of technology companies such as Meta, to learn about the latest international developments in the privacy landscape and industry practices.
|
Privacy Commissioner’s Office and Digital Policy Office
Collaborate to Launch the Safeguarding Personal Data AI Sandbox
|
The rapid adoption of AI technologies in Hong Kong is transforming organisational practices in content creation, data analysis and service delivery, while also presenting emerging challenges in safeguarding personal data. In active alignment with the guiding principle of ensuring both development and security under the National 15th Five-Year Plan, and to implement the policy direction of the Government of the Hong Kong Special Administrative Region (HKSAR) in promoting the development of “AI+”, the PCPD and the Digital Policy Office (DPO) announced the launch of the Safeguarding Personal Data AI Sandbox (Sandbox) dedicated to primary and secondary schools on 6 July. The Sandbox project is supported by the Hong Kong Cyberport (Cyberport), the Hong Kong Productivity Council (HKPC), the Association of I.T. Leaders in Education and the Hong Kong Association for Computer Education as supporting organisations.
The Sandbox aims to provide a collaborative platform for participating schools, AI solution suppliers, the PCPD, the DPO, the Cyberport and the HKPC, with a view to fostering innovation while facilitating compliance with the PDPO and promoting the responsible adoption of AI technologies. Open to applications from all publicly-funded primary and secondary schools, the first phase of the Sandbox will be six months. The Sandbox will focus on supporting schools in exploring and adopting AI solutions. In the first phase, 15 applicants will be selected to benefit from complimentary access to the PCPD’s regulatory guidance on personal data privacy protection, DPO’s guidance on the Hong Kong Generative Artificial Intelligence Technical and Application Guideline, as well as technical advice from the Cyberport and the HKPC in implementing AI solutions. Applications for the Sandbox are now open until 30 October. A briefing session on details of the Sandbox will be held on 28 August, details will be announced in due course. Interested schools may submit their applications through the dedicated application channel. Further details on the Sandbox and the application process, including the application form and evaluation criteria, are set out in the Framework of the Safeguarding Personal Data AI Sandbox, which is available on the “AI Privacy Protection” thematic webpage of the PCPD’s website. Interested schools may visit https://www.pcpd.org.hk/english/artificial_intelligence/index.html for details of the Sandbox.
|
|
|
|
Protecting Medical Data in the Digital Healthcare Era
|
|
|
PRIVACY COMMISSIONER’S FINDINGS
|
PRIVACY COMMISSIONER’S FINDINGS
|
Accessing a Patient’s Electronic Health Record for Non-medical Purposes
|
|
|
Navigating Digital Healthcare with Personal Data Protection
|
|
|
|
HONG KONG INTERNATIONAL DATA PRIVACY ACADEMY
|
Free Online Seminars: Introduction to the PDPO
|
Arrange an In-house Seminar for Your Organisation
|
APPLICATION / RENEWAL OF DPOC MEMBERSHIP
|
PCPD Supports the Hong Kong Institute of Bankers (HKIB) Annual Banking Conference 2026
|
PCPD Supports the
Hong Kong Volunteer Award 2026
|
PCPD Supports the Cyber Security Staff Awareness Recognition Scheme 2026/27
|
|
|
Reaching Out to Legal Professionals – Privacy Commissioner Attends Reception for the Launch of Sentencing in Hong Kong – Twelfth Edition
|
Promoting Privacy Protection in AI – Privacy Commissioner Interviewed by Media on the Safeguarding Personal Data AI Sandbox
|
Reaching Out to the Community – Privacy Commissioner Attends Celebration Events for 29th Anniversary of the Establishment of the HKSAR and Launch Ceremony for Celebrating the 105th Anniversary of the Founding of the Communist Party of China
|
Bringing Together Data Privacy Talents – Hong Kong International Data Privacy Academy Organises Seminar for Delegation of Mainland Lawyers
|
Reaching Out to the Community – Privacy Commissioner Interviewed by Media on the Establishment of the “Hong Kong International Data Privacy Academy”
|
Enjoying Strong Support of the Motherland and Being Closely Connected with the World – Assistant Privacy Commissioner Attends the 53rd Data Privacy Sub-group Meeting of the APEC Digital Economy Steering Group
|
Reaching Out to the Property Management Sector – Assistant Privacy Commissioner Speaks at the “Application of “iAM Smart” Personal Code in the Property Management Sector” Seminar
|
Promoting Privacy Protection in AI – Assistant Privacy Commissioner Speaks at the AI-Powered Enterprise Forum
|
Reaching Out to the Community – Assistant Privacy Commissioner Interviewed by Media on Dashcam Video Footage and the Protection of Personal Data Privacy
|
Promoting Privacy Protection in AI – Assistant Privacy Commissioner Interviewed by Media on the Safeguarding Personal Data AI Sandbox
|
Promoting Privacy Protection in AI – Assistant Privacy Commissioner Interviewed by Media on the Privacy Risks of AI
|
PCPD 30th Anniversary – Hong Kong International Data Privacy Academy and the University of Hong Kong Jointly Organise a Seminar
|
Promoting Privacy Protection in AI – PCPD’s Representative Speaks at the “Responsible AI Adoption and Governance for NGOs” Seminar
|
Proactive Alignment with 15th Five-Year Plan – PCPD Staff Members Participate in the 2026 Hong Kong Cybersecurity Special Training Course
|
|
|
Highlights of the “Practical Guidance of Cybersecurity Standards – Security Guidelines for the Deployment and Use of AI Agents” 《網絡安全標準實踐指南 — 智能體部署使用安全指引》的重點
|
EU: General Data Protection Regulation (GDPR) EU Representative Enforcement Continues
|
EU: EU Debuts New Digital Sovereignty Assessment Tools
|
EU: European Commission Issues Binding Specification Measures to Google under Digital Markets Act (DMA)
|
EU: European Data Protection Board (EDPB) Calls for Legal Basis for Cross-regulatory Information Sharing
|
|
|
|
Protecting Medical Data in the Digital Healthcare Era
|
As healthcare services become increasingly digitalised, healthcare providers are making greater use of electronic systems to store, access and share patients’ health records. In Hong Kong, the Electronic Health System (“eHealth System”) enables healthcare providers in both the public and private sectors to access and share patients’ health records for healthcare-related purposes with the consent of patients. While electronic health records facilitate more efficient and coordinated care, they also contain sensitive personal data that warrants a high level of protection. Inadequate security measures may increase the risk of unauthorised access, accidental disclosure or personal data leakage, which could undermine the trust and confidence of patients in healthcare services.
To safeguard patients' personal data privacy and maintain public trust in healthcare services, healthcare providers should pay close attention to the following areas when using eHealth System:
- Ensure patients are properly informed: Prior to obtaining joining consent and/or sharing consent, healthcare providers should remind patients to read carefully the relevant “Personal Information Collection Statement”, “Privacy Policy Statement” and “Participant Information Notice”;
- Access and use health records responsibly: Healthcare providers should ensure that healthcare professionals only have access to health records relevant to the healthcare services they provide in accordance with the “patient-under-care” and “need-to-know” principles, and should not use patients’ personal data for new purposes without their explicit and voluntary consent;
- Maintain data accuracy: Healthcare providers should ensure that the electronic health records they provide to the eHealth System are accurate;
- Strengthen data security: Healthcare providers should adopt all practicable steps to protect personal data in the eHealth System and minimise the risk of data breach incidents. If a data breach incident occurs, they should notify both the Commissioner for the Electronic Health Record and the Privacy Commissioner as soon as possible;
- Avoid misuse of health records: Healthcare providers must note that using electronic health records in the eHealth System for direct marketing is a criminal offence under the eHealth Ordinance; and
- Manage data requests properly: Healthcare providers should designate staff to handle data access and data correction requests, and provide proper training and guidelines to staff on the requirements of the PDPO.
For further guidance, please refer to the “Personal Data (Privacy) Ordinance and the Electronic Health System: Points to Note for Healthcare Providers and Healthcare Professionals”.
|
|
|
|
PRIVACY COMMISSIONER’S FINDINGS
|
Accessing a Patient’s Electronic Health Record for Non-medical Purposes
|
The Complaint
The Complainant gave consent to a doctor (Doctor) to upload his health record to the Electronic Health Record Sharing System (prior name of eHealth System) (Sharing System) and access the said data. After the first and only visit, the Complainant made a complaint against the Doctor to the Medical Council of Hong Kong (Medical Council). While the Medical Council was handling the Complainant's case, the Complainant received a text message from the Electronic Health Record Office, informing him that the Doctor had accessed his electronic health record in the Sharing System. The Complainant was dissatisfied that the Doctor had accessed his health record for purposes not related to treatment and thus lodged a complaint against the Doctor with the PCPD.
Outcome
Data Protection Principle (DPP) 3 of the PDPO provides that without the prescribed consent of the data subject, his personal data may only be used (including disclosure or transfer) for the purpose for which the data was originally collected or for purposes directly related to that purpose. The PCPD was of the view that the Doctor was in contravention of DPP 3 by accessing the Complainant's electronic health record in the Sharing System for a purpose other than providing treatment to the Complainant and without obtaining separate consent from the Complainant.
Upon the PCPD's intervention, the Doctor undertook to access electronic health records in the Sharing System only for the purpose of providing treatment to patients and on a “need-to-know” basis.
Regarding the incident, the PCPD issued a warning to the Doctor, requesting him to ensure that the non-compliance in this case would not be repeated. In addition, the PCPD referred the case to the Electronic Health Record Office, which manages the Sharing System, for follow-up actions.
Lessons Learnt
Healthcare providers should exercise prudence and professional judgment before accessing patients’ data in the eHealth System. Inappropriate use of patients’ data in the eHealth System not only contravenes DPP 3 of the PDPO, but may also violate the Code of Practice for using the eHealth System.
|
Navigating Digital Healthcare with Personal Data Protection
|
The growing adoption of healthcare mobile applications, online medical appointment platforms, telemedicine services and electronic health record systems has transformed the way people access healthcare services. While these digital health services offer greater convenience and accessibility, they also involve the collection, storage and transfer of sensitive personal data, such as medical histories, diagnoses and treatment records. If such information falls into the wrong hands, the risk of identity theft, financial loss and other privacy harms may be significantly heightened.
To minimise privacy and security risks when using digital health services, please consider the following practical measures:
- Beware of phishing and social engineering attacks: Exercise caution when handling suspicious emails, messages or phone calls. Do not readily disclose personal or account login information and remain vigilant against phishing and social engineering attacks that may leverage leaked data;
- Monitor personal identity and financial activities: Regularly review bank accounts, credit card statements and medical records for unfamiliar login records, unusual access or unauthorised transactions;
- Enable Multi-Factor Authentication (MFA): Activate MFA for all important online accounts, including healthcare platforms, banking and public services;
- Change passwords regularly: Use strong, unique passwords for important accounts and avoid reusing the same password across multiple services;
- Check device security: Install anti-virus software on computers and mobile devices, perform regular scans and remove potential threats; and
- Seek assistance promptly: If you discover that your personal data has been leaked, report the matter to the PCPD and other law enforcement agencies for assistance.
|
|
|
|
Reaching Out to Legal Professionals – Privacy Commissioner Attends Reception for the Launch of Sentencing in Hong Kong – Twelfth Edition
|
Privacy Commissioner Ms Ada CHUNG Lai-ling attended the reception for the launch of Sentencing in Hong Kong – Twelfth Edition on 8 July. The book was edited by the former Director of Public Prosecutions, Mr Ian Grenville CROSS, GBS, SC and barrister Mr Patrick W S CHEUNG.
Sentencing in Hong Kong has been published for more than 30 years and is the most authoritative publication on sentencing law and practice in Hong Kong. The key updates of the new edition include new sentencing guidelines for dangerous drug trafficking, sentencing principles for national security offences, analysis of aggravating and mitigating factors in sentencing and review on recent judgments in key sentencing areas, etc.
|
Promoting Privacy Protection in AI – Privacy Commissioner Interviewed by Media on the Safeguarding Personal Data AI Sandbox
|
Privacy Commissioner Ms Ada CHUNG Lai-ling was interviewed by RTHK News’ “Hong Kong Today” and RTHK Radio 1’s “HK2000” on 7 July respectively to introduce the Sandbox, a joint initiative launched by the PCPD and the DPO. The Sandbox was introduced in active alignment with the guiding principle of ensuring both development and security under the National 15th Five-Year Plan, and to implement the policy direction of the Government of the HKSAR in promoting the development of “AI+”.
The Privacy Commissioner explained that the Sandbox aims to provide a collaborative platform to assist participating primary and secondary schools to adopt AI solutions in compliance with the requirements of the PDPO, while promoting the responsible use of AI technology. The first phase of the Sandbox will offer 15 places and run for six months. Participating schools will receive guidance from the DPO on the Hong Kong Generative Artificial Intelligence Technical and Application Guideline, while the PCPD will provide professional guidance from the perspective of personal data privacy protection. The Cyberport and the HKPC will also offer technical advice to participating schools as regards the application of AI solutions.
The Privacy Commissioner further explained that schools applying to join the Sandbox will be required to clearly set out their proposed AI applications for assessment and selection by the organisers. Schools may apply for a further six-month extension, if necessary, upon completion of the first phase. She added that the PCPD believes that the Sandbox will help schools adopt AI safely and responsibly, while enabling successful experiences and good practices to be shared with other schools, thereby promoting AI-enabled innovation in the education sector while safeguarding students’ personal data privacy.
Click here to listen to the interview by RTHK News’ “Hong Kong Today” (1:05:54-1:10:34) (Chinese only). Click here to listen to the interview by RTHK Radio 1’s “HK2000” (Chinese only).
|
Reaching Out to the Community – Privacy Commissioner Attends Celebration Events for 29th Anniversary of the Establishment of the HKSAR and Launch Ceremony for Celebrating the 105th Anniversary of the Founding of the Communist Party of China
|
Privacy Commissioner Ms Ada CHUNG Lai-ling attended the flag-raising ceremony cum reception celebrating the 29th anniversary of the establishment of the HKSAR, as well as the launch ceremony for celebrations marking the 105th anniversary of the founding of the Communist Party of China on 1 July.
This year marks both the 29th anniversary of the establishment of the HKSAR and the 105th anniversary of the founding of the Communist Party of China. At the event, the Privacy Commissioner joined members of the community from various sectors in celebrating this significant occasion.
|
Bringing Together Data Privacy Talents – Hong Kong International Data Privacy Academy Organises Seminar for Delegation of Mainland Lawyers
|
The Academy organised a seminar for a delegation of 66 Mainland lawyers on 29 June. The delegates, who came from different provinces in the Chinese Mainland, participated in a training programme in Hong Kong jointly organised by All China Lawyers Association and the Peking University Law School. Privacy Commissioner Ms Ada CHUNG Lai-ling, Assistant Privacy Commissioner (Legal) Ms Fiona LAI Ho-yan and Legal Counsel of the PCPD Ms Stephanie CHAU Yuen-yeng met with the delegation and conducted a seminar on the overview of Hong Kong’s personal data privacy protection regime, the roles and functions of the PCPD, as well as its achievements in handling public enquiries, complaints and combating doxxing acts.
|
Reaching Out to the Community – Privacy Commissioner Interviewed by Media on the Establishment of the “Hong Kong International Data Privacy Academy”
|
Privacy Commissioner Ms Ada CHUNG Lai-ling was interviewed by RTHK Radio 3’s “Backchat” on 26 June to introduce the objectives and the courses offered by the Academy established by the PCPD, as well as the direction of its future development.
The Privacy Commissioner explained that the PCPD established the Academy to proactively align with the National 15th Five-Year Plan, support Hong Kong’s development as an international hub for high-calibre talents, and support the formulation and implementation of Hong Kong’s first Five-Year Plan by the Government of the HKSAR under the leadership of the Chief Executive, thereby actively integrating into and serving the overall national development. She envisaged that the Academy would further strengthen Hong Kong’s influence in data privacy education and contribute to promoting the “AI Training for All” initiative across the wider community.
She pointed out that the Academy offers six core training programmes, namely introductory seminars, professional workshops, topical seminars on emerging issues, dialogues with experts, in-house seminars and online training. The Academy is supported by around 30 organisations drawn from a broad range of professional associations and industry bodies. The long-term vision is to establish the Academy as a leading regional and international platform for data privacy education, and help develop Hong Kong into an international hub for data privacy protection professionals.
Click here to listen to the interview by RTHK Radio 3’s “Backchat”.
|
Enjoying Strong Support of the Motherland and Being Closely Connected with the World – Assistant Privacy Commissioner Attends the 53rd Data Privacy Sub-group Meeting of the APEC Digital Economy Steering Group
|
The Assistant Privacy Commissioner (Legal) Ms Fiona LAI attended the 53rd Data Privacy Sub-group Meeting of the Asia-Pacific Economic Cooperation (APEC) Digital Economy Steering Group held in Chengdu on 26 July.
During the meeting, Ms Lai shared with participants from 11 other member economies the work of the PCPD in promoting privacy protection in AI and cross-boundary flows of personal data. The PCPD has been proactively promoting the safe and responsible development and use of AI through a multifaceted approach encompassing regulatory compliance, education and promotion, and collaboration. Ms LAI also highlighted the significance of the Standard Contract for Cross-boundary Flow of Personal Information Within the Guangdong-Hong Kong-Macao Greater Bay Area (Mainland, Hong Kong) in facilitating the safe and orderly cross-boundary flows of personal information within the Greater Bay Area.
The APEC Digital Economy Steering Group oversees the APEC Internet and Digital Economy Roadmap, pursuant to which members work to improve infrastructure, data flows, trust, inclusion and digital trade.
|
Reaching Out to the Property Management Sector – Assistant Privacy Commissioner Speaks at the “Application of “iAM Smart” Personal Code in the Property Management Sector” Seminar
|
The Assistant Privacy Commissioner (Complaints and Criminal Investigation) Ms Rebecca HO Kan-yeuk attended the “Application of “iAM Smart” Personal Code in the Property Management Sector: New Directions in Digital Transformation and Privacy Compliance” Seminar on 23 July and delivered a speech. The seminar was jointly organised by the Property Management Services Authority and the DPO. At the seminar, Ms Ho explained the Six DPPs under the PDPO and some relevant cases. She also introduced the “Protection of Personal Data Privacy – Guidance for Property Management Sector” issued by the PCPD to the participants, with a view to assisting practitioners of the property management sector in complying with the relevant requirements under the PDPO. Please click here for the presentation deck (Chinese only).
|
Promoting Privacy Protection in AI – Assistant Privacy Commissioner Speaks at the AI-Powered Enterprise Forum
|
The Assistant Privacy Commissioner (Corporate Communications and Operations) Ms Joyce LAI Chi-man attended the AI-Powered Enterprise Forum (Forum) on 20 July. The Forum, which was jointly organised by the DPO and the Hong Kong Internet Registration Corporation Limited (HKIRC), was one of the activities under the “Secure AI@Work Enablement Campaign”.
Ms Lai spoke as a panellist in a panel discussion titled “Opportunities and Challenges of AI Transformation: New Issues in Corporate Governance”. During the panel discussion, she highlighted the importance of establishing a robust AI governance framework and introduced various AI-related guidance published by the PCPD, including the Model Framework and the Guidelines.
|
Reaching Out to the Community – Assistant Privacy Commissioner Interviewed by Media on Dashcam Video Footage and the Protection of Personal Data Privacy
|
The Assistant Privacy Commissioner (Legal) Ms Fiona LAI Ho-yan was interviewed by Commercial Radio’s “On a Clear Day” on 13 July to explain personal data privacy issues relating to dashcam video footage.
While the Assistant Privacy Commissioner did not comment on individual cases, she pointed out that, as the interior of a vehicle is a semi-private space, the installation of dashcam cameras may involve the collection of personal data if the footage captured can be used to identify individuals. In such circumstances, the relevant data users should comply with the requirements of the PDPO. Under DPP 3 of the PDPO, unless the prescribed consent of the data subject has been obtained voluntarily and expressly, personal data may only be used for the purpose for which it was collected or a directly related purpose.
She further explained that uploading video footage containing the personal data of others to social media platforms without the data subjects’ consent may contravene the requirements under DPP 3 of the PDPO. Depending on the specific circumstances of the case, such conduct may also constitute a doxxing offence under the PDPO.
In addition, she referred to the Guidance on the Use of Video Cameras on Drones and Vehicles issued by the PCPD in October 2025, which sets out matters that fleet operators and drivers should take into account when using surveillance cameras, and reminded the relevant parties of the need to comply with the requirements of the PDPO in order to safeguard the personal data privacy of passengers and other individuals.
|
Promoting Privacy Protection in AI – Assistant Privacy Commissioner Interviewed by Media on the Safeguarding Personal Data AI Sandbox
|
The Assistant Privacy Commissioner (Legal) Ms Fiona LAI Ho-yan was interviewed by RTHK Radio 3’s “Backchat” on 10 July to introduce the Sandbox jointly launched by the PCPD and the DPO. The Sandbox was introduced to actively align with the guiding principle of ensuring both development and security under the National 15th Five-Year Plan, and to implement the policy direction of the Government of the HKSAR in promoting the development of “AI+”.
The Assistant Privacy Commissioner explained that the Sandbox is a collaborative platform for participating schools, AI solution suppliers, the PCPD, the DPO and supporting organisations, namely the Cyberport and the HKPC. The Sandbox will focus on the use of AI technologies in primary and secondary schools and will support schools in exploring and adopting AI solutions. It provides an opportunity for schools to identify and address privacy risks at an early stage and to refine their AI use cases with guidance from experts in privacy protection, AI governance and technology.
The Assistant Privacy Commissioner added that participants will benefit from a wide range of support measures, including regulatory insights and guidance from the PCPD and the DPO, technical advice from Cyberport and HKPC, and complimentary quotas for attending seminars on AI and data security organised by the Academy.
Click here to listen to the interview by RTHK Radio 3’s “Backchat”.
|
Promoting Privacy Protection in AI – Assistant Privacy Commissioner Interviewed by Media on the Privacy Risks of AI
|
The Assistant Privacy Commissioner (Legal) Ms Fiona LAI Ho-yan was recently interviewed by RTHK’s “Hong Kong Connection” to explain the privacy risks posed by AI.
In the interview, the Assistant Privacy Commissioner pointed out that while many people consider it harmless to upload photos on social media, the digital footprint accumulated over time in fact poses privacy risks. Such data may reveal not only individuals’ facial images and voices, but also their lifestyle habits, interpersonal networks and behavioural patterns, which could be readily exploited by criminals. She emphasised that the PDPO, as a technology-neutral and principle-based legislation, is applicable to the use of AI to collect, process and use personal data. If the use of generative AI to create content involves personal data, and such use goes beyond the original purpose(s) for which the data was collected, it may constitute a breach of the relevant data protection principle. The creation and/or disclosure of malicious deepfake content may also constitute doxxing under the PDPO, and may even constitute other criminal offences.
The interview by the RTHK’s “Hong Kong Connection”, which was broadcast on 25 June, can be viewed here (Chinese only).
|
PCPD 30th Anniversary – Hong Kong International Data Privacy Academy and the University of Hong Kong Jointly Organise a Seminar
|
To mark the 30th anniversary of the PCPD, the PCPD launches a series of seminars on data security and AI privacy protection. A seminar entitled “The New AI Era: Data Protection and Cybersecurity in Higher Education”, co-organised by the Academy, recently established by the PCPD, and the Information Technology Services – Data Protection Office of the University of Hong Kong, was successfully held on 30 June, attracting over 150 participants from the higher education sector.
At the seminar, a PCPD's representative discussed the privacy risks arising from the use of AI, and highlighted recommendations for developing of organisational AI guidelines and considerations for AI governance.
Please click here for the presentation deck.
|
Promoting Privacy Protection in AI – PCPD’s Representative Speaks at the “Responsible AI Adoption and Governance for NGOs” Seminar
|
A PCPD’s representative delivered a presentation at the “Responsible AI Adoption and Governance for NGOs” seminar organised by the Association of Hong Kong Accountants on 26 June. At the seminar, the PCPD’s representative shared with participants the recommendations on AI governance and best practices provided in the Model Framework published earlier by the PCPD, along with the recommendations for developing internal policies or guidelines on the use of generative AI by employees set out in the Guidelines issued by PCPD. Please click here for the presentation deck (Chinese only).
|
Proactive Alignment with 15th Five-Year Plan – PCPD Staff Members Participate in the 2026 Hong Kong Cybersecurity Special Training Course
|
To proactively align with the National 15th Five-Year Plan, and to better integrate into and contribute to the overall national development, the PCPD arranged for three staff members from different divisions, including Assistant Privacy Commissioner (Complaints and Criminal Investigation) Ms Rebecca HO Kan-yeuk; Acting Chief Personal Data Officer (Compliance and Enquiries) of the PCPD Ms Ayee MAN Oi-yee; and Senior Personal Data Officer (Information Technology) of the PCPD Mr Tamson TAM Ka-wing to participate in the 2026 Hong Kong Cybersecurity Special Training Course organised by the Bauhinia Academy in Shenzhen from 13 to 17 July. The course enhanced the PCPD staff’s understanding of the latest developments in cybersecurity and AI in the Chinese Mainland. The course covered the core concepts and latest developments in the holistic approach to national security, cybersecurity, and AI security. Participants also visited the headquarters of ZTE Corporation and China Electronics Corporation, as well as the Guangdong-Hong Kong-Macao Greater Bay Area Data Application Industrial Park in Shaoguan.
|
|
|
|
Highlights of the “Practical Guidance of Cybersecurity Standards – Security Guidelines for the Deployment and Use of AI Agents” 《網絡安全標準實踐指南 — 智能體部署使用安全指引》的重點
|
The National Technical Committee 260 on Cybersecurity of SAC issued the “Practical Guidance of Cybersecurity Standards – Security Guidelines for the Deployment and Use of AI Agents” (Guidance) on 1 July 2026. The Guidance provides security recommendations covering the entire agent lifecycle, including the stages of assessment, preparation, deployment, use, and decommissioning. It is applicable to the prevention and mitigation of security risks arising from the deployment and use of agents, and may also serve as a reference for organisations when selecting and using commercial agent services. This article provides an overview of the Guidance.
全國網絡安全標準化技術委員會在2026年7月1日發布了《網絡安全標準實踐指南——智能體部署使用安全指引》(《指引》)1。《指引》提供的安全指引涵蓋智能體部署使用的整個生命周期,包括評估、準備、部署、使用、停用等階段,適用於智能體部署使用的安全風險防範,也可為選擇使用商業智能體服務提供參考。
定義2
《指引》指出,智能體一般而言是指具備自主感知、記憶、决策、交互與執行能力的智能系統,而《指引》中所指的智能體是面向個人助手場景、需要用戶授予較高權限、基於大模型的人工智能智能體,一般為軟件系統。
各階段的安全措施
1. 評估階段3
在此階段,應評估使用智能體的必要性、開源智能體與商業智能體的適用性,以及擬選擇智能體是否具備基礎安全特性要求等,例如:
- 應明確使用目的、場景,評估採用智能體的必要性與合理性
- 應了解智能體的技術特性、安全風險等
- 宜優先選擇由提供方同時提供智能體和配套安全防護能力的成套方案,慎重選擇缺乏安全防護措施的開源項目
- 應檢查擬部署使用的智能體是否存在自動開放公網接口等重大安全隱患
- 不應選擇缺少日誌審計、權限管理等基礎性安全機制的智能體
2. 準備階段4
涵蓋安裝物料、部署環境 、大模型的選擇,以及安全防護等,例如:
- 應從官方網站等渠道獲取智能體安裝物料,並於安裝前驗證其真實性和完整性,防範安裝物料被投毒或篡改
- 根據安裝部署方式,採取相應的安全防護措施:
○ 若在本地環境部署而設備中存在敏感數據、私隱文件,應提前進行清理或遷移 ○ 若在虛擬化環境部署,應通過禁止虛擬機訪問其宿主機內文件等配置實施嚴格隔離 ○ 若在雲環境部署,應選擇具備智能體身份管理、訪問控制、日誌審計等能力的雲平台
- 若對數據安全、私隱保護有相關要求,且具備相關算力條件和技術基礎,宜優先採用本地化部署的大模型
- 應根據安全需求,對所選智能體及大模型已有安全機制進行差距分析,如輸入輸出內容安全保護、高風險操作攔截與管理等方面的安全能力不足,宜部署安全工具或接入安全服務等方式增強
3. 部署階段5
部署階段的安全指引涵蓋部署方式、插件安裝、運行賬戶、權限配置、網絡暴露控制、日誌審計、高風險操作管理等方面,例如:
- 應根據官方文檔或經核驗的部署腳本進行部署
- 應在安裝插件前檢查來源的可靠性
- 不應使用操作系統管理員權限運行智能體
- 應限制智能體的可訪問目錄範圍
- 應將智能體及其相關服務配置為僅本機可訪問
- 應開啟智能體的日誌記錄功能
- 應提前建立高風險操作清單,並對清單內操作實行二次確認或直接阻斷
4. 使用階段6
使用階段的安全指引包含安全覆查、技能安全、敏感信息保護、網絡訪問安全、長期記憶管理、應急處置與更新等方面,例如:
- 應對智能體安裝與配置情況進行覆查
- 向連入互聯網絡的智能體提供個人信息時,應堅持最小必要原則,審慎提供生物特徵、家庭私隱等敏感信息;未獲得第三方授權時,不應提供第三方的個人信息及敏感數據
- 宜定期開展智能體運行環境內有價值數據的容災備份
- 宜定期手動查看長期記憶文件記錄的內容,對不宜存儲的個人信息、私隱數據、內部信息及時進行處理
- 宜及時回收敏感權限,定期清理不再使用的技能與敏感對話記錄
5. 停用階段7
停用階段關注安全地終止運行、 清理數據與權限、完成環境回收等,例如:
- 應停止智能體主程序,以及所有關聯服務與後台進程的運行
- 完成必要數據備份後,根據部署環境(本地/雲端/虛擬化環境)執行相應的環境清理操作
安全檢查清單及安全管理指引
《指引》附錄A根據上述各項措施,提供了部署使用智能體的安全檢查清單,如使用者在安全檢查或使用過程中發現存在安全問題,宜及時根據《指引》的相應部分加固。
此外,為應對內部人員部署使用智能體可能帶來的各類安全風險,《指引》建議機構按照其附錄B的安全管理指引,建立相關安全管理制度及配套安全能力,涵蓋範疇包括:
- 建立內部智能體使用管理制度
- 建立智能體資產登記表
- 對已審批智能體活動進行管理
- 有助機構發現內部未經審批智能體的措施
- 為員工開展安全教育
總結
《指引》為智能體的評估、準備、部署、使用、停用五個階段提出了多項安全措施,並且為使用者提供安全檢查清單、為組織提供安全管理指引。有關各方宜按照《指引》要求部署使用智能體,減低其帶來的各種安全風險。
1 全文: https://www.tc260.org.cn/portal/article/2/71c613fd3db34b6a9da62f25b8219733
2《指引》第3.1章。
3 《指引》第6章。
4《指引》第7章。
5《指引》第8章。
6《指引》第9章。
7《指引》第10章。
|
|
|
|
HONG KONG INTERNATIONAL DATA PRIVACY ACADEMY
|
The Academy was officially launched on 16 June 2026 by the Honourable Mr Paul LAM Ting-kwok, GBS, SC, JP, the Secretary for Justice of the Government of the Hong Kong SAR, China, and other officiating guests during the 30th Anniversary Privacy Protection Summit of the PCPD.
The PCPD established the Academy to actively align with the Country’s 15th Five-Year Plan in supporting Hong Kong’s development as an international high-calibre talent hub and the Government’s policy under the “One Country, Two Systems” principle to leverage the distinctive advantages of enjoying strong support of the Motherland and being closely connected to the world. It also aims to support the formulation and implementation of the first Hong Kong’s Five-Year Plan by the HKSAR Government under the leadership of the Chief Executive, thereby actively integrating into and serving the overall national development.
The PCPD 30th Anniversary Privacy Protection Summit was the first signature event launched by the Academy. The Academy provides flagship training programmes on privacy/personal data protection matters for organisations, privacy protection practitioners and other stakeholders in Hong Kong, the Chinese Mainland and other parts of the world. The programmes, which include introductory seminars, professional workshops, topical seminars on emerging issues, dialogues with experts, in-house seminars and online training, are supported by various professional associations and industry groups. For details, please click here to visit the website of the Academy.
|
Professional Workshop on Data Protection in Direct Marketing Activities
|
Organisations often use customers’ personal data to conduct direct marketing activities to promote products or services. These activities are governed by the PDPO. Organisations have the responsibility to ensure that their employees clearly understand and comply with the provisions on direct marketing under the PDPO, which also helps organisations maintain a positive reputation and demonstrate their corporate social responsibility.
This workshop will explain in detail the requirements of the direct marketing provisions under the PDPO and provide participants with practical guidance on compliance and share conviction cases relating to direct marketing, aiming to help participants understand how to properly use customers’ personal data in direct marketing activities.
Date: 5 August 2026 (Wednesday)
Time: 2:15pm – 5:15pm
Venue: Lecture Room, the PCPD’s Office, 12/F, Dah Sing Financial Centre, 248 Queen’s Road East, Wanchai, Hong Kong
Language: Cantonese
Fee: $750/$600* (*Members of the DPOC and supporting organisations may enjoy the discounted fee)
Accreditation: 3 CPD points (The Law Society of Hong Kong, Insurance Authority, Estate Agents Authority, Property Management Services Authority, Hong Kong Institute of Bankers)
Who should attend: Data protection officers, compliance officers, company secretaries, administration managers, IT Managers, solicitors, database managers and marketing professionals
|
Professional Workshop on Personal Data Privacy Management Programme
|
With the ever-rising expectations of customers and stakeholders regarding organisations’ responsible use of personal data in recent years, the protection of personal data privacy should no longer be seen as purely a compliance issue. To build trust with customers and enhance their competitive and reputational advantages, organisations should develop and implement a comprehensive Personal Data Privacy Management Programme (PMP) to proactively embrace personal data privacy protection as part of their corporate governance responsibilities and apply it as a business imperative throughout the organisations.
By attending this workshop, participants will understand the key components of a PMP, and learn how to continuously maintain and improve it for effective implementation in their organisations.
Date: 12 August 2026 (Wednesday)
Time: 2:15pm – 4:15pm
Mode: Online
Language: Cantonese
Fee: $750/$600* (*Members of the DPOC and supporting organisations may enjoy the discounted fee)
Accreditation: 2 CPD points (The Law Society of Hong Kong, Estate Agents Authority, Property Management Services Authority, Hong Kong Institute of Bankers)
Who should attend: Data protection officers, compliance professionals, company secretaries, solicitors, executives from business and public sectors, and those who are interested in keeping abreast of the data protection trend and best practices
|
Professional Workshop on Data Protection in Banking/Financial Services
|
The application of fintech has developed rapidly in recent years, changing the landscape of the financial world. Practitioners of the banking and financial industry may face different personal data privacy issues in their business operations. To deal with these new challenges, a clear understanding of the requirements under the PDPO is necessary.
This workshop examines the risks of handling personal data in the daily operations of banking and financial services institutions, and provides practical advice on how to deal with these issues effectively. It is particularly suitable for data protection officers, compliance officers, banking/financial practitioners, company secretaries and solicitors.
Date: 19 August 2026 (Wednesday)
Time: 2:15pm – 5:15pm
Mode: Online
Language: Cantonese
Fee: $750/$600* (*Members of the DPOC and supporting organisations may enjoy the discounted fee)
Accreditation: 3 CPD points (The Law Society of Hong Kong, Estate Agents Authority, Hong Kong Institute of Bankers)
Who should attend: Data protection officers, compliance officers, company secretaries, solicitors, advisers and other personnel undertaking work relating to the banking/financial industry
|
New Series of Professional Workshops on Data Protection in Sep 2026:
|
Online Free Seminars – Introduction to the PDPO Seminar
|
The PCPD organises free introductory seminars regularly to raise public awareness and their understanding of the PDPO. Details of the upcoming sessions are shown below:
|
Seminar Outline:
- A general introduction to the PDPO;
- The six Data Protection Principles;
- Offences and compensation;
- Direct marketing; and
- Q&A session.
|
Arrange an In-house Seminar for Your Organisation
|
Teaching employees how to protect personal data privacy is increasingly recognised as an important part of employee training. If you wish to arrange an in-house seminar for your organisation to learn more about the PDPO and data privacy protection, you can make a request for an in-house seminar via our online form.
The seminar outline is as follows:
- A general introduction to the PDPO;
- The six Data Protection Principles (industry-related cases will be illustrated);
- Data security management;
- Handling of data breach incidents;
- Direct marketing;
- Offences and compensation; and
- Q&A session.
Duration: 1.5 hours
|
APPLICATION / RENEWAL OF DPOC MEMBERSHIP
|
Apply or renew your DPOC membership today and enjoy privileged access to course enrolments throughout the year!
Special Offer for Organisational Renewals:
Organisations can join the 2-for-1 scheme, which enables you to receive two memberships for the price of one annual fee (HK$450).
Join us now to keep up-to-date with the latest news and legal developments!
|
PCPD Supports the Hong Kong Institute of Bankers (HKIB) Annual Banking Conference 2026
|
The PCPD continues to serve as a supporting organisation for the HKIB Annual Banking Conference this year. The theme of this year’s event is “Bank of Tomorrow: Transform to Excellence”, which will showcase how banks are redesigning their operating models to become smarter, faster and safer, while strengthening their role as trusted platforms that enable connectivity, capital flows and sustainable growth.
Please click here for the details and registration.
|
PCPD Supports the Hong Kong Volunteer Award 2026
|
The PCPD is delighted to be one of the supporting organisations of the Hong Kong Volunteer Award (HKV-Award) 2026, co-organised by the Home and Youth Affairs Bureau and the Agency for Volunteer Service, with support from the “JC VOLUNTEER TOGETHER” Project funded by The Hong Kong Jockey Club Charities Trust.
HKV-Award is themed Volunteering Beyond Boundaries this year, to encourage transcending all kinds of volunteering limits, embedding the spirit of helping others into everyday life, and empowering the community.
Please click here for more details.
|
PCPD Supports the Cyber Security Staff Awareness Recognition Scheme 2026/27
|
The PCPD is delighted to be one of the scheme partners of the Cyber Security Staff Awareness Recognition Scheme 2026/27 (the Scheme). Co-organised by the DPO, HKIRC and ISACA China Hong Kong Chapter, the Scheme aims to promote “Human Firewall” concept among the industry by raising cyber security staff awareness on top of technical protection as a second level defense line, and to enhance organisations’ protection level by encouraging the organisations to raise staff awareness by multiple channels, e.g. training, policy, communication, drill, etc. The Scheme is now open for application until 14 August.
Please click here for the Scheme details and application.
|
The PCPD values the opinions of all our DPOC members. We love to hear your ideas and suggestions on what privacy topics you would like to learn more about. Email your thoughts to us at dpoc@pcpd.org.hk and we shall include the most popular topics in our future e-newsletters.
|
|
|
|
Contact Us
Address: Unit 1303, 13/F, Dah Sing Financial Centre, 248 Queen’s Road East, Wanchai, Hong Kong
Tel: 2827 2827
If you do not wish to receive the PCPD e-Newsletter, please click here to unsubscribe.
|
Copyright
Disclaimer
The information and suggestions provided in this publication are for general reference only. They do not serve as an exhaustive guide to the application of the law. The Privacy Commissioner makes no express or implied warranties of accuracy or fitness for a particular purpose or use with respect to the information and suggestions set out in this publication. This publication also contains information or suggestions contributed by others, whose views or opinions are solely those of the contributors and do not necessarily reflect or represent those of the Privacy Commissioner. All information and suggestions provided in this publication will not affect the functions and powers conferred upon the Privacy Commissioner under the Personal Data (Privacy) Ordinance.
The PCPD shall not be liable for any damages (including but not limited to damages for loss of business or loss of profits) arising in contract, tort or otherwise from (i) the use of or inability to use this publication or its content, or (ii) from any action taken or decision made on the basis of the content of this publication.
If you click any hyperlink in this publication that brings you to sites operated by other organisations, the PCPD accepts no responsibility for the contents of those sites and shall not be liable for any loss or damage arising out of and/or incidental to the use of the contents.
|
|
|
|
|