On 25 August 2026, the Office of the Privacy Commissioner for Personal Data published guidance titled 'Protecting Personal Data Privacy in the Use of Agentic AI.' The guidance sets out practical recommendations for organisations deploying autonomous AI systems that operate across multiple steps and external systems without continuous human oversight. The PCPD issued the guidance under its mandate under the Personal Data (Privacy) Ordinance (Cap. 486) as an administrative publication. It does not create new legal obligations beyond those already imposed by the PDPO.
The guidance applies the six Data Protection Principles of the PDPO to agentic AI deployment. Under DPP1 (Purpose and Collection Limitation), organisations must identify in advance what personal data an AI agent will access, generate, or transmit and limit collection to what is necessary for the specified purpose. DPP4 (Security of Personal Data) requires technical and organisational controls scaled to the autonomous nature of the agent, including agent-level access controls, activity logging, and anomaly detection. DPP6 (Access and Correction) rights remain fully applicable to data processed by an agent acting on an organisation's behalf; organisations cannot rely on AI intermediation to delay or refuse a data subject's access request.
Organisations deploying agentic AI in Hong Kong, whether as autonomous customer service agents, AI-driven workflow automation, or multi-agent pipeline systems, must map the personal data flows created by agent actions and verify compliance with each applicable DPP. Financial services firms, professional services providers, and technology companies processing Hong Kong personal data through agentic AI are the principal addressees. The guidance applies equally to organisations using third-party agentic AI products and to those building proprietary agents.
The guidance does not amend the PDPO and does not introduce new enforcement mechanisms. The PCPD has indicated it may publish sector-specific supplements. Organisations that have already mapped their PDPO obligations for conventional AI should treat the agentic AI guidance as a gap-analysis tool to identify where autonomous agent behaviour creates data flows or access patterns not addressed in existing compliance documentation.
Licentium advises technology companies and regulated entities on AI data privacy compliance in Hong Kong, Singapore, and the broader Asia-Pacific region. Work we undertake includes PDPO compliance assessments, agentic AI data governance reviews, cross-border data transfer analysis, and regulatory strategy for AI product deployments.