On 25 August 2026, the Office of the Privacy Commissioner for Personal Data (“PCPD”) issued guidance on “Protecting Personal Data Privacy in the Use of Agentic AI” (“Guidance”).
The Guidance should be read in conjunction with the “Artificial Intelligence: Model Personal Data Protection Framework” (“Model Framework”) issued by the PCPD in June 2024, which was the first guidance document targeted at organisations procuring, implementing and using AI systems in the context of their compliance with the Personal Data (Privacy) Ordinance (“PDPO”).
The AI regulatory journey so far

With the Guidance, the PCPD officially joins the latest cohort of global data protection authorities laying down regulatory expectations on the risks and compliance obligations specific to agentic systems. In the past 12 months, the EDPS, UK ICO, Spanish AEPD, Dutch AP and Singapore IMDA have issued dedicated regulatory publications on the use of agentic AI. For more detailed guidance on the agentic privacy implications from a GDPR perspective, see our separate Bird & Bird guidance here.
So what for data users in Hong Kong?
1. Are you in control?
The Guidance begins by emphasising that data users should adopt a cautious and responsible approach, the underlying theme being accountability of data users towards agentic AI usage. This echoes the approach taken by other key data protection regulators around the world.
But what does “accountability” really mean in practice? It starts with identifying who is in control and asking whether they should be in control.
The Guidance and other regulatory publications show that the “autonomous” capacity of an agent to execute decisions and carry out tasks does not displace the need for data users to examine where controllership sits and its applicable data protection obligations. Agentic AI requires a different analysis from traditional vendor procurement. Before deployment, data users should carefully assess whether the provider acts as an independent controller, joint controller, processor or subprocessor.
Fewer instructions ≠ Less control
Under the PDPO, an organisation is a data user if it “controls” the processing of the relevant data. The fact that fewer instructions are needed for an agent to execute a task for a data user does not mean the degree of “control” under the PDPO will diminish. It remains important to assess whether the organisation has “empowered” the agent with the means and purpose of processing personal data. For instance, do you let your agent run on full access mode, or approval request mode? Do you have meaningful and practical measures in place to review and approve an agent’s actions?
The bottom line is that if an organisation is responsible for determining the level of authority for an agent’s decision-making process and levels of information access, it is likely that “control” is still assumed by the data user.
2. Multi-sources of data access = multi-sources of risks
The Guidance highlights the likelihood of amplified risks when inaccurate data is processed by the integrated data processing activities and workflows of a multi-agent setting. For data users, this is an acute reminder of the myriads of data protection risks that can arise when inadequate controls over agentic capabilities lead to the processing of inaccurate datasets. For instance, are you connecting your agents to third party plugins, tools and MCP servers? Is your agent accessing third party databases or collecting third party personal data, e.g. through web-scraping?
It is clear that agentic AI solutions require a more rigorous understanding of the data flows and the different levels of integration between agentic workflows. For example, if an agent has access to a publicly available database and is tasked with a retrieval function, data users should consider what the parameters are for an agent to collect and procure personal data from data subjects and data providers. Are these set in advance by the data user or subject to the agent’s determination during the task-execution process?
If the information made available to the agent was wrongfully acquired at the outset, in addition to the processing of inaccurate personal data (raising DPP2 concerns), this can lead to potential violations of various DPPs such as DPP1 (processing without lawful purpose and excessive collection), DPP3 (use of data for a new purpose other than the original or directly related purpose for which the data was collected at source) and DPP4 (unauthorised access and dissemination).
Where agents access multiple data sources, data users must understand how data is collected, transferred and managed throughout its lifecycle, and the risks at each stage. As noted in the Model Framework, a privacy impact assessment will likely be required under the PDPO to weigh those risks against the need for agentic AI processing and assess whether privacy-enhancing technologies should be used.
3. Are you truly risk-based?
Building on its acknowledgement of a risk-based approach mentioned in the Model Framework, the PCPD reiterates in the Guidance that continuous risk assessments must be conducted prior to any adoption of agentic AI solutions.
The PCPD emphasises that the risk assessment should cover each stage of the agentic AI processing activities, and on a continuing basis. The Annex to the Guidance includes a security checklist to help data users identify proportionate mitigation measures for each stage.
A risk-based approach requires data users to monitor and reassess privacy risks as circumstances change. A static set of industry best practice safeguards is not enough, particularly if based on a one-off pre-launch risk assessment. Data users should consider:
- Are mechanisms in place, including contractual rights against service providers, to safeguard against functional creep in agentic AI processing?
- If sensitive data is involved, what contingency measures will be triggered if human oversight fails? Is this planned for in the AI-incident response mechanism?
4. How transparent are you about your use of agentic AI?
One area businesses often overlook is the requirement to be transparent under DPP1(3) and DPP5, as the PCPD reminds us in the Guidance. In particular, businesses should explain in their Personal Information Collection Statements and Privacy Policy Statements that they are using agentic AI to process personal data and how this is done.
An intelligible and effective notice must account for the specific use case and context in which AI (agentic or non-agentic) solutions will be used, and their impact on individuals. A customer-facing agentic assistant for a financial services institution for account opening will require a different level of explanation from one used by a retailer handling transactional queries. The notice should therefore be tailored to the actual AI use case, rather than relying on generic disclosures.In our experience, this remains a known gap in the market. Many businesses are likely using AI or agentic AI tools involving personal data in some capacity without being sufficiently transparent about that use. Their transparency obligations remain the same: data users are still expected to explain to data subjects why their personal data is being processed and with whom it is shared.

For further information, please contact:
Wilfred Ng, Partner, Bird & Bird
wilfred.ng@twobirds.com




