Hong Kong’s Privacy Commissioner for Personal Data (PCPD) has proposed significant amendments to the Personal Data (Privacy) Ordinance (PDPO) to address the challenges posed by artificial intelligence and automated decision-making systems.
The proposed amendments include:
– Mandatory impact assessments for organisations deploying AI systems that process personal data
– New rights for data subjects to understand how automated decisions affecting them are made
– Requirements for transparency in AI training data sources
– Establishment of an AI governance framework for the private sector
The consultation period runs until September 2026, with implementation expected in early 2027.
“Hong Kong must strike a balance between fostering AI innovation and protecting personal privacy,” the PCPD stated. “These amendments will provide clear guidelines for organisations while maintaining our competitive edge as an AI hub.”
HKISG welcomes the proposed changes and will be monitoring the consultation process closely to provide guidance to members.
Why this matters for cybersecurity and AI security
PDPO updates aimed at AI and automated decision-making sit at the intersection of privacy and AI security:
- Impact assessments force organisations to inventory where personal data feeds models, RAG stores, and agents.
- Transparency rights create evidence expectations that map to HKISG Methodology Evidence quality and AI security domains.
- Training-data transparency pressures vendors — and buyers — to ask harder questions before enabling GenAI features.
See also: Prompt Injection, AI Security and Governance, and PDPO (glossary).
Hong Kong operator checklist
- Confirm whether the systems, vendors, or practices described apply to your estate.
- Assign an owner and a review date — do not leave findings as unread newsletter content.
- Capture evidence (configs, tickets, screenshots) if you later enter a Trust Review.
- Brief leadership with a dated one-page note when residual risk remains high.
What “good” looks like
- Controls are operated, not only documented
- Privileged access uses phishing-resistant MFA where feasible
- Detection and response paths are exercised at least annually
- Third-party dependencies have an owner and an exit plan
Sources and further reading
- HKISG Security Bulletins
- Prompt Injection (wiki)
- AI Security and Governance
- Assessment Methodology
- Governance & Integrity
- Online Education
- External: HKCERT · PCPD
Editorial note
This page is published by the Hong Kong Information Security Group (HKISG) for educational and early-warning purposes. It is not a substitute for legal advice, formal audit opinions, or national CERT coordination.
Frequently asked questions
Who should read this?
Security, IT, and risk owners in Hong Kong organisations who need practical context rather than marketing claims.
Does this change any public HKISG rating?
No. TrustScores are produced only through the published Trust Review / Awards process. Reading this page does not alter scores.
How often is this content reviewed?
HKISG dates publications and retains corrections under our editorial standards. Check the updated field in the page header when present.