Jurisdiction
Hong Kong
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Hong Kong regulates personal data through the Personal Data (Privacy) Ordinance (Cap. 486), enforced by the Privacy Commissioner for Personal Data. There is no AI statute. AI expectations are set by PCPD guidance — the 2024 Model Personal Data Protection Framework and the 2025 Checklist on Guidelines for the Use of Generative AI by Employees — and by Digital Policy Office frameworks for government and industry. The Ordinance is principle-based and technology-neutral, so the same six Data Protection Principles apply to a RAG index as to a filing cabinet. Section 33, which would restrict transfers out of Hong Kong, is not in operation.
- Region
- North Asia
- ISO code
- HK
- Privacy framework
- Personal Data (Privacy) Ordinance (Cap. 486). The Ordinance applies to any person who controls the collection, holding, processing or use of personal data, and works through six Data Protection Principles in Schedule 1 covering collection, accuracy and retention, use, security, openness and access. Data processors are not directly regulated: the data user stays responsible and must impose the requirements on its processors by contract or other means. Contravening a Data Protection Principle is not itself an offence, but the Commissioner may issue an enforcement notice and contravening that notice is.
- AI-specific rules
- No AI-specific legislation. The PCPD published the Artificial Intelligence: Model Personal Data Protection Framework in June 2024, setting recommendations across AI strategy and governance, risk assessment and human oversight, customisation and management of AI systems, and communication with stakeholders. It published a Checklist on Guidelines for the Use of Generative AI by Employees in March 2025 for organisations writing an internal Gen AI policy, and Guidance on the Ethical Development and Use of Artificial Intelligence in August 2021. The Digital Policy Office maintains an Ethical AI Framework and a Hong Kong Generative AI Technical and Application Guideline. In banking, the HKMA has issued guiding principles on consumer protection where authorized institutions use generative AI. None of these carries a direct penalty; they are the standard a regulator would measure you against when applying the Ordinance.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
Section 33 of the PDPO would restrict transfers of personal data outside Hong Kong, but it has never been brought into operation — the PCPD states this plainly in its own guidance. There is therefore no statutory transfer mechanism to satisfy and no adequacy list to check. What remains is DPP4, which requires all practicable steps to protect data wherever it is held, and DPP2, which requires a data user to prevent a processor from keeping data longer than necessary. The PCPD recommends model contractual clauses for cross-border transfers as good practice, and publishes separate guidance for the Guangdong-Hong Kong-Macao Greater Bay Area standard contract. Practically, sending prompts and documents to a model provider outside Hong Kong is a due-diligence and contract question, not a permission question.
Regulators
Primary sources
- LegislationPersonal Data (Privacy) Ordinance (Cap. 486) — Hong Kong e-Legislation
- Regulator pagePCPD — The Personal Data (Privacy) Ordinance at a Glance
- Regulator pagePCPD — Six Data Protection Principles
- Regulator guidancePCPD — Artificial Intelligence: Model Personal Data Protection Framework
- Regulator guidancePCPD — Guidance on the Ethical Development and Use of Artificial Intelligence
- Regulator guidancePCPD — Guidance on Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data
- Regulator guidancePCPD — Guidance on Personal Data Protection in Cross-border Data Transfer
- StandardDigital Policy Office — Ethical Artificial Intelligence Framework
- StandardDigital Policy Office — Hong Kong Generative Artificial Intelligence Technical and Application Guideline
- Regulator guidanceHKMA — Consumer Protection in respect of Use of Generative Artificial Intelligence (circular)
- Official faqHong Kong Judiciary — Guidelines on the Use of Generative Artificial Intelligence for Judges and Judicial Officers and Support Staff
02Regulations and guidance
| Instrument | Status |
|---|---|
| PCPD AI Model FrameworkPCPD guidance for organisations that procure, implement and use AI, including generative AI. Recommends measures in four areas: AI strategy and governance, risk assessment and human oversight, customisation and management of AI systems, and communication with stakeholders. Adopts a risk-based approach. It is recommended practice, not a statutory obligation. | In force |
| PCPD Gen AI ChecklistPCPD checklist for organisations writing an internal policy on employee use of generative AI. Covers the scope of permissible use and permitted tools, what may be entered into a prompt, lawful and ethical use and bias, data security and permitted devices, reporting of AI incidents, and consequences of violations. | In force |
| DPO Ethical AI FrameworkThe Hong Kong government’s framework for planning and deploying AI, aimed at bureaux and departments and usable as a reference by others. Version 2.0 is dated December 2025 and cross-references the PCPD ethical AI guidance and the PRC Personal Information Protection Law. The document states only a month, so no exact date is recorded. | In force |
| PCPD Cross-border GuidancePCPD guidance prepared to help data users get ready for the eventual commencement of PDPO section 33 and to raise the standard of protection for transfers out of Hong Kong in the meantime. Explains the section 33 conditions and the due-diligence and contractual route. | In force |
| PCPD Model Contractual ClausesPCPD guidance offering recommended model contractual clauses for transfers of personal data out of Hong Kong. It records that section 33 of the PDPO is not yet in operation and recommends the clauses as good practice, especially for small and medium-sized enterprises. The document states only a month of publication, so no exact date is recorded. | In force |
| PCPD Ethical AI GuidancePCPD guidance from August 2021 on complying with the PDPO when developing or using AI. Sets three data stewardship values and seven ethical principles, including accountability, human oversight, transparency and interpretability, data privacy and fairness, and describes an AI governance and risk-assessment practice. The document states only a month of publication, so no exact date is recorded. | In force |
| HKMA Gen AI CircularHKMA guiding principles for authorized institutions using generative AI in customer-facing applications, building on the 2019 principles for big data analytics and AI: governance and accountability, fairness, transparency and disclosure, and data privacy and protection. It applies to banks and deposit-taking companies, not to other sectors. | In force |
| DPO Generative AI GuidelineGuideline commissioned by the Digital Policy Office and prepared with the Hong Kong Generative AI Research and Development Center. Sets out the technical background and governance principles of generative AI and gives practical guidance to technology developers, service providers and service users. Version 1.1 is dated December 2025. | In force |
| Law Society Gen AI BulletinRisk-management bulletin issued under the Law Society’s Professional Indemnity Scheme on generative AI in legal practice. Identifies hallucination, confidentiality at input, output and retention stages, and legal professional privilege over prompts and AI-generated documents. It is professional guidance, not a rule of law. | In force |
| PDPOHong Kong’s general data protection statute. Six Data Protection Principles govern collection, accuracy and retention, use, security, openness, and access and correction. Data processors are not directly regulated; the data user must impose the requirements by contract. Section 33, restricting transfers outside Hong Kong, has never been brought into operation. | Partly in force |
03Common enterprise issues
Confidentiality
Client confidentiality survives the PDPO analysis
Professional-services firms hold material that is confidential or privileged but not personal data. The PDPO says nothing about it; the duty comes from retainers, common law and professional rules, and it is usually the binding constraint on whether documents may reach a third-party model.
Cross-border transfers
Section 33 is not in operation, so the question is contractual
Teams often ask which transfer mechanism applies before sending data to an overseas model provider. There is no statutory mechanism in force. The work is a due-diligence record, contract terms modelled on the PCPD clauses, and a DPP4 security assessment of the receiving environment.
Prompt leakage
Staff pasting client material into public chatbots
The PCPD 2025 Checklist expects an internal policy naming which Gen AI tools are permitted, which categories of employee may use them, on which devices, and what may be typed into a prompt. Most organisations discover the gap after the fact.
Retention
Retention of prompts, embeddings and logs
DPP2 limits how long personal data is kept. An AI deployment creates new copies — vector indexes, prompt logs, cached outputs, model checkpoints — that are rarely covered by the existing retention schedule.
Sector rules
Banking and insurance supervision sits on top
Authorized institutions must read the HKMA circulars on AI and consumer protection alongside the PDPO. Outsourcing and technology-risk expectations apply to a model provider the same way they apply to any other service provider.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
OpenAIclaim pending review
OpenAI publishes the countries and territories where API access is supported. Hong Kong was not found in that list when it was fetched on 2026-08-20 — confirm against the live page before planning a deployment on the OpenAI API, and ask the vendor in writing rather than relying on a reseller.
Anthropicclaim pending review
Anthropic publishes separate lists for commercial API access and for Claude.ai. Hong Kong was not found in either list when they were fetched on 2026-08-20. Check both, because a team can be entitled to one and not the other.
Googleclaim pending review
Google publishes the countries and territories where the Gemini API and Google AI Studio are available. Hong Kong was not found in that list when it was fetched on 2026-08-20. Vertex AI on Google Cloud is governed separately — do not read one as covering the other.
Microsoftclaim pending review
Azure model availability is published per Azure region, not per country. No Hong Kong region appeared in the Foundry Models availability matrix when it was fetched on 2026-08-20, so a Hong Kong deployment normally means choosing another Asia-Pacific region and treating that as a data-location decision.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.