Hong Kong: PCPD issues further guidance on best practices in the use of agentic AI
September 10, 2026
Hong Kong: PCPD issues further guidance on best practices in the use of agentic AISeptember 10, 2026 In August 2026, the Hong Kong Privacy Commissioner for Personal Data (“PCPD”) published the Model Personal Data Protection Framework on the Use of Agentic AI (the “Guidance”), supplementing its existing Artificial Intelligence Model Personal Data Protection Framework. What is the Guidance about?The Guidance identifies five personal data privacy risks associated with agentic AI, namely extensive access, system vulnerabilities, vulnerable plugins or skills, function creep and multi-agent risks. Against this backdrop, the Guidance sets out nine recommendations aimed at assisting organisations in complying with the six Data Protection Principles (“DPPs”) under the Personal Data (Privacy) Ordinance (“PDPO”). These recommendations address matters including access limitation, transparency, data accuracy and retention, prescribed consent, security and access controls, data access and correction rights, continuous risk assessments, and internal governance. A practical Security Checklist further sets out measures for organisations to consider at the evaluation, preparation, deployment, use and uninstall stages of an agentic AI system. Why is it relevant to my organisation?Agentic AI has already featured in the PCPD's recent regulatory activity. In May 2026, the PCPD published the findings of compliance check launched in January 2026. The check covered 60 organisations. PCPD’s report specifically recommended that organisations use agentic AI prudently, including by limiting access rights and continuously assessing associated risks. This follows a March 2026 public alert concerning the privacy and security risks posed by OpenClaw and other Agentic AI system. Taken together, these developments indicate the PCPD is taking a keen interest in, if not increasing its scrutiny on, the use of agentic AI by a wide range of organisations. Accordingly, understanding how the DPPs and the broader PDPO framework fits into the deployment and operation of agentic AI systems would be key for companies that wish to remain compliant. What are the key takeaways from the Guidance?The key distinction between agentic AI and conventional GenAI tools lies in the degree of autonomy or "agency" afforded to the system. Rather than merely generating an output in response to a prompt, or following a fixed sequence of predefined steps, an AI agent may determine and execute intermediate steps it deems necessary to achieve an overarching goal with limited real-time human involvement. Drawing on this distinction, we set out below three selected key takeaways for companies that are looking to deploy, or have already deployed, agentic AI systems in their operations. 1. Deployer remains responsible for PDPO compliance, but not necessarily the only party responsible The Guidance expressly sets out AI agents are not distinct legal persons. The fact that an AI agent may “autonomously” make decisions or take actions does not displace the deployer’s responsibilities. Taking a technology-neutral lens, the relevant question remains which person controls the collection, holding, processing or use of the personal data and thus qualifies as a "data user". The AI agent is a means, through which the relevant processing is carried out, rather than a separate legal actor to which responsibility can be transferred. This is in line with a broader regulatory approach towards agentic AI. The UK Information Commissioner’s Office (see discussion paper) has similarly stated terminologies such as “agent” or “agency” do not remove an organisation’s responsibilities for data processing. Singapore’s Infocomm Media Development Authority also emphasised that human remains the ultimate accountable party for AI agents’ actions (see our earlier briefing at this link). While the Guidance does not directly address PDPO compliance obligations of third parties, this should not be taken to mean that such obligations rest solely with the deployer. Depending on the technical and contractual arrangements, an agentic AI provider, the underlying model provider, platform operator, or other service provider may also be a data user where it exercises control over the processing activities, alone or jointly with the deployer. This is particularly relevant where a provider controls and uses personal data processed by AI agents for its own purposes, such as model improvement, analytics or other secondary uses. A provider that processes such personal data solely on the deployer’s behalf may instead be a data processor. In that case, the deployer remains subject to specific obligations to address retention and security risks associated with the outsourced processing. 2. Transparency should focus on the substance of processing, not the technology label The Guidance recommends that organisations be transparent about their use of agentic AI when processing personal data, including by providing such information in their Personal Information Collection Statements (“PICS”). However, no further guidance was given with respect to different deployment contexts. This recommendation should be distinguished from the minimum notification requirements expressly prescribed by DPP1(3). DPP1(3) does not expressly require a data user to disclose the particular technology or means used to process data. Its focus is instead on the purposes for data processing, classes of transferees, etc.. Accordingly, where the introduction of an AI agent changes only the technical means by which an existing processing activity is performed, without changing the relevant matters required to be notified under DPP1(3), the use of agentic AI would not of itself appear to create a separate disclosure requirement. However, the position differs where the introduction of agentic AI changes the substance of the processing. For example, an agent may collect additional personal data without obtaining separate consent, transfer data to classes of service providers not covered by an existing PICS, or use personal data in ways beyond the original purposes. Such changes would most likely raise further compliance concerns under the PDPO. The compliance measure is not simply inserting a sentence on agentic AI into every PICS. Companies should (i) map the actual use case and data flows, (ii) identify whether deployment changes anything that affects compliance with the DPPs, and (iii) determine what additional disclosure is appropriate to satisfy the PCPD's broader transparency recommendation. The words “agentic AI” should not be treated as invariably necessary or sufficient disclosure in itself. Separately, it should be considered whether material use of agentic AI should be reflected in their broader privacy policies in light of DPP5's requirement to take practicable steps to make the data user's policies and practices concerning personal data generally ascertainable. 3. Agentic AI requires regular privacy assessment, and more Where there is any material modification to an agent's capabilities, permissions or integrations, which is highly likely as companies assess and adjust the use cases of agentic AI, a pre-deployment privacy assessment may not accurately capture risks associated with the actual operations. The Guidance recommends testing agentic AI for safety and reliability before deployment and continuously assessing personal data privacy risks throughout its use. In practice, this means that privacy assessment should not be treated as a one-off exercise carried out before deployment. Changes to an agent's permitted actions, access rights, connected systems, plugins, underlying models or use cases may alter its personal data processing. It should therefore trigger an assessment of whether the existing privacy analysis remains valid. Deployers should therefore bring agentic AI within existing change-management processes, with appropriate legal, privacy and security review thresholds for material changes. Access rights to modify an agent's configuration should also be restricted. This can help prevent apparently routine technical changes from producing unintended changes to the nature, scope or purposes of personal data processing that result in a breach of the PDPO. ++++++++++ For companies that are already compliant with the PDPO, adopting agentic AI does not require a new data protection rulebook. It does require organisations to revisit how existing rules apply in a more autonomous operating environment. The focus should therefore be on substance, not labels: who controls the processing, what the agent can access and do, how data flows change over time, and whether internal governance can keep pace with these changes. If your company has plans to deploy agentic AI at scale, please feel free to contact one of our team members to discuss how privacy compliance should be built into procurement, contracting, system design and change management. Key contacts
Latest InsightsLatest News
Latest Events
legal updates September 10, 2026 Global Life Sciences & Healthcare Bulletin legal updates September 10, 2026 Hong Kong: PCPD issues further guidance on best practices in the use of age... legal updates September 10, 2026 EU WEEE Directive Reform: Tighter Rules, Rising Costs guides and reports September 10, 2026 EU Cyber Resilience Act: Single Reporting Platform Goes Live firm news August 26, 2026 Eversheds Sutherland strengthens top-ranked pensions practice with appointm... client news August 13, 2026 Eversheds Sutherland advises H.I.G. Capital on investment in Phoenix ME client news August 13, 2026 Eversheds Sutherland reappointed to the UK's Government Commercial Agency l... firm news August 12, 2026 William A. Nelson, Former Investment Adviser Association Policy Leader, Joi... in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States virtual Employment law in the Kingdom of Saudi Arabia September 29, 2026 9.30am - 12.30pm (BST) Virtual in-person Labor relations conference - turning legal change into workplace reality October 08, 2026 10.00am - 4.00pm (BST) London, United Kingdom |