Agents Of Change: Hong Kong’s New Data Privacy Guidance For Agentic AI.
Executive summary
On 25 August 2026, the Office of the Privacy Commissioner for Personal Data (“PCPD“) published “Artificial Intelligence: Model Personal Data Protection Framework – Protecting Personal Data Privacy in the Use of Agentic AI “(“Guidance“). The Guidance supplements the PCPD’s 2024 “Artificial Intelligence: Model Personal Data Protection Framework” and provides practical recommendations for organisations deploying or considering deploying agentic AI that are “data users” under the Personal Data (Privacy) Ordinance (Cap. 486) (“PDPO“).
The PCPD joins a growing number of public authorities and regulatory bodies that have published agentic AI-specific materials over the past year, including the European Data Protection Supervisor, the UK Information Commissioner’s Office, Singapore’s Infocomm Media Development Authority (“IMDA“) and three PRC authorities (National Development and Reform Commission (“NDRC“), Cyberspace Administration of China (“CAC“), and Ministry of Industry and Information Technology (“MIIT“). Although the Guidance is non-binding, it indicates how the PCPD considers the existing requirements of the PDPO apply to agentic AI and is likely to serve as an important practical compliance benchmark.
This alert summarises the Guidance, examines the principal data privacy risks and practical compliance steps for data users, and compares Hong Kong’s approach with the PRC and Singapore frameworks.
What is agentic AI?
The Guidance defines agentic AI as a system capable of autonomous perception, memory, decision-making, interaction and execution, built on foundation models integrated with tools, databases, memory and operating systems. The Guidance expressly cites the definition adopted by China’s National Technical Committee 260 on Cybersecurity of Standardisation Administration (“TC260“) in its July 2026 “Security Guidelines for the Deployment and Use of AI Agents,” indicating cross-jurisdictional alignment between Hong Kong and Mainland China in the technical characterisation of agentic AI systems. Unlike conventional generative AI chatbots, which offer primarily question-and-answer interactions, AI agents can execute multi-step tasks such as handling emails, reservations and payments. Multiple agents may collaborate within an agentic system, resulting in increased operational and technical complexity.
Critically, the PCPD emphasises that AI agents are not legal persons. Organisations deploying agentic AI remain accountable as data users under the PDPO and must ensure compliance with the six Data Protection Principles (“DPPs“).
Agentic AI’s autonomy does not diminish organisational accountability. Under the PDPO, an organisation that, either alone or jointly, or in common with others, controls the collection, holding, processing or use of personal data remains a “data user”, regardless of the operational latitude afforded to an AI agent. Before deployment, organisations should assess the actual role and degree of control exercised by each participant in the agentic AI supply chain, including service providers, platform operators and plugin or skill developers. They should determine whether each participant acts as a data user or data processor and allocate responsibilities accordingly. This assessment may be more complex than in traditional vendor procurement arrangements because multiple participants may influence different aspects of the system and its processing activities.
Principal data privacy risks
The Guidance identifies several heightened privacy risks associated with agentic AI. These risks may engage several core DPPs, particularly those governing the collection, accuracy and retention, use and security of personal data, and data access and correction rights:
- Extensive access. AI agents may be granted extensive access to files, emails, credentials and browser-stored content, increasing the risk of unauthorised access, unintended reproduction and accidental erasure of personal data.
- System vulnerabilities. AI agents may be granted high-level access to multiple interconnected systems, meaning that design flaws or inadequate safety controls may expose significant volumes of personal data.
- Vulnerable plugins or skills. Third-party plugins or skills that have not undergone appropriate security review may contain malicious code or other vulnerabilities, creating avenues for unauthorised access to accounts or systems and the leakage of personal data.
- Function creep. Agentic AI may aggregate and recombine personal data from multiple sources, increasing the risk that personal data is used for a new purpose without prescribed consent.
- Multi-agent risks. Inaccurate information, including outputs generated through hallucination, may pass between collaborating agents and lead to unfair or erroneous outcomes. Complex data flows across multiple agents, third-party tools and external data sources may also increase security and data-integrity risks and make it more difficult to identify, retrieve and correct personal data. Depending on the circumstances, these risks may result in non-compliance with multiple DPPs, including those governing the collection, accuracy, use and security of personal data (DPPs 1 to 4).
Key recommendations for data users
The Guidance sets out nine recommendations mapped to the PDPO’s DPPs:
- Data minimisation (DPP 1). Avoid excessive or arbitrary collection of personal data. Ringfence the information and systems accessible to agentic AI for defined, lawful purposes related to a function of the data user and implement appropriate access controls.
- Transparency (DPPs 1 and 5). Organisations should be transparent about their use of agentic AI when processing personal data, including by providing relevant information in Personal Information Collection Statements and Privacy Policy Statements. Data users may also consider identifying the regions in which personal data is stored or processed and the relevant arrangements.
- Data accuracy (DPP 2). Deploy techniques such as chain-of-thought prompting, retrieval-augmented generation, context-specific fine-tuning and human review to mitigate the risk of hallucinated or inaccurate personal data.
- Retention limits (DPP 2). Prescribe maximum retention periods for personal data contained in conversation histories, cached data and long-term memory, and implement measures to erase personal data that is no longer required.
- Purpose limitation (DPP 3). Do not use personal data for a new purpose without the prescribed consent of the data subject. Clearly delineate the purposes for which personal data may be processed and the circumstances in which human intervention is required.
- Data security (DPP 4). Use official software obtained from authorised channels; separate the agentic AI runtime environment from local devices or servers; install plugins or skills only after appropriate security review; grant the minimum access rights necessary; adopt large language model (LLM) guardrails; and maintain logs of relevant operations, timestamps, tools used, data accessed and reasoning of decisions for traceability and auditability.
- Data access and correction rights (DPP 6). Select systems that adopt privacy-by-design and privacy-by-default principles, and verify that agentic AI service providers have embedded data protection, data governance and risk management measures into their system designs.
- Continuous risk assessment. Assess safety, reliability and personal data privacy risks before deployment and regularly reassess those risks during use. Human intervention should be required for high-risk, irreversible or atypical operations.
- Governance and training. Establish a properly resourced governance structure with sufficient expertise and authority. Use contractual or other measures to ensure that external vendors acting as data processors meet the relevant retention and security requirements (DPPs 2 and 4), and provide appropriate training to all relevant personnel.
The PCPD notes that recommendations 1, 3, 4, 5 and 6 above also apply to individual users. The Guidance includes, at Annex A, a Security Checklist setting out practical steps that organisations and individual users may take during the evaluation, preparation, deployment, use and uninstall stages to safeguard personal data privacy when using agentic AI.
Comparing approaches in APAC: Hong Kong, PRC and Singapore frameworks
Regulators in other APAC jurisdictions have a broader policy and governance approach to the issue of agentic AI, rather than focusing specifically on data privacy issues.
PRC Implementation Opinions (May 2026)
In May 2026, China’s CAC, NDRC and MIIT jointly issued the “Implementation Opinions on the Standardised Application and Innovative Development of AI Agents.” The Implementation Opinions adopt a similar technical definition of agentic AI but have a broader policy focus, covering technological and industrial development, infrastructure, standardisation, ecosystem development, safety and governance. They also identify 19 application scenarios across scientific research, industrial development, stimulating consumption, public welfare and social governance.
The PRC framework is underpinned by four principles: safety and controllability; orderliness and standardisation; innovation-driven development; and application-oriented traction. Unlike the Guidance, the Implementation Opinions do not focus on specific personal data obligations. Instead, they address the development and deployment of AI agents at an industry and ecosystem level, prioritising infrastructure, standards and protocols.
Singapore IMDA Model AI Governance Framework for Agentic AI (Version 1.5, May 2026)
In May 2026, Singapore’s IMDA published Version 1.5 of its “Model AI Governance Framework for Agentic AI,” which was subsequently updated in June 2026. The framework is organised around four pillars: (i) assessing and bounding risks upfront; (ii) making humans meaningfully accountable; (iii) implementing technical controls and processes; and (iv) enabling end-user responsibility.
While both the Guidance and the IMDA framework are non-binding, the IMDA framework takes a broader, principles-based approach to AI governance, whereas the Guidance focuses specifically on personal data protection and maps its recommendations to the PDPO’s DPPs. The IMDA framework provides additional detail on risk assessment, agent identity, access management, automation bias and value chain responsibilities. The Singapore Commissioner of the Personal Data Protection Commission noted in an interview published on 26 August in Straits Interactive that, while the framework’s initial focus was agent liability, “there are some answers that need to be figured out including data protection questions”.
Agentic AI frameworks at a glance
| Hong Kong (PCPD) | PRC (CAC/NDRC/MIIT) | Singapore (IMDA) | |
| Primary focus | PDPO personal data protection | Standardised application and innovative development of AI agents, including technological and industrial development, innovation, safety and governance | AI governance, risk management and accountability |
| Legal basis | PDPO (six DPPs) | National policy and implementation instrument designed to operate in conjunction with existing policies, laws and regulations | Non-statutory, principle-based AI framework |
| Risk approach | Nine PDPO-mapped recommendations supported by a Security Checklist | Four overarching principles and sector-specific scenarios | Risk assessment based on factors including the use case, access to sensitive data, scope and reversibility of actions, degree of autonomy, system complexity and usage of third-party solutions |
| Human oversight | Human-in-the-loop mechanisms to retain final control over the decision-making process to prevent and mitigate AI-induced errors and automation bias | Defined boundaries between user-only, user-authorised and autonomous decisions, with users retaining the right to know and final decision-making authority over autonomous decisions | Defined intervention checkpoints and appropriate approval mechanisms, with safeguards against automation bias |
| Agent identity | No detailed agent-identity framework; the Guidance instead emphasises transparency about the use of agentic AI, minimum access rights, logging, traceability and auditability | Proposed agent registration platform providing digital identity management, search and discovery, and capability-declaration services, together with research into agent identity identification and trusted interconnection | Unique agent identities and scoped, least-privilege, time- or session-bound and non-transferable authorisations |
Action points for data users
Organisations deploying or considering deploying agentic AI should:
- conduct a privacy impact assessment (“PIA”) or equivalent AI-specific risk assessment for each agentic AI use case. Although the Guidance does not expressly require a PIA, organisations should evaluate the elevated access rights, multi-agent data flows and plugin or skill risks identified by the PCPD;
- audit existing AI deployments. Identify agentic AI tools already in use across the organisation and assess whether current data governance arrangements, including data processing agreements, access controls, retention practices and security measures, adequately address the associated risks;
- review and update privacy notices and Personal Information Collection Statements to disclose the organisation’s use of agentic AI. Organisations may also consider identifying the regions in which personal data is stored or processed;
- implement robust access controls and data minimisation measures. Ringfence the data and systems accessible to agents for defined purposes and grant agents only the minimum access rights necessary to perform their assigned tasks;
- establish traceability and auditability mechanisms. Log relevant agent operations, timestamps, tools used, data accessed and decision reasoning;
- adopt a human-in-the-loop approach for high-stakes, irreversible or atypical actions, supported by governance structures with sufficient resources and authority;
- train relevant personnel on agentic AI risks and the organisation’s data protection, security, governance and responsible-deployment policies and procedures;
- benchmark against regional standards. Asia-Pacific organisations should consider the Guidance, cross-border definitional convergence between the PCPD and TC260, IMDA’s risk assessment and agent identity frameworks, and the PRC’s broader innovation, safety and governance framework.

For further information, please contact :
Dominic Edmondson, Partner, Dentons
dominic.edmondson@dentons.com




