The Privacy Commissioner for Personal Data (PCPD) announced on 25 August 2026 that it had published a guidance document titled ‘Protecting Personal Data Privacy in the Use of Agentic AI’. The guidance is intended to provide practical recommendations for organisations that deploy agentic AI, helping them to safeguard personal data privacy and to comply with the Personal Data (Privacy) Ordinance (PDPO). It is supported by the Digital Policy Office and the Hong Kong Applied Science and Technology Research Institute.
The Office of the Privacy Commissioner for Personal Data (PCPD) published a guidance document entitled ‘Protecting Personal Data Privacy in the Use of Agentic AI’ on 25 August 2026. The guidance is supported by the Digital Policy Office and the Hong Kong Applied Science and Technology Research Institute, and it references the ‘Practical Guidance of Cybersecurity Standards – Security Guidelines for the Deployment and Use of AI Agents’ issued in July 2026 by the National Technical Committee 260 of the Standardisation Administration of China, as well as guidance from other jurisdictions. It is presented as a supplementary resource to the PCPD’s existing ‘Artificial Intelligence: Model Personal Data Protection Framework’.
Agentic AI is a type of artificial intelligence that can work towards a goal, decide what steps to take and carry out tasks on a user’s behalf with limited human supervision. The guidance outlines the privacy risks associated with agentic AI. It sets out nine recommendations for organisations, covering data minimisation and ring‑fencing, transparent privacy notices, accuracy of processed data, purpose limitation, defined retention periods, security safeguards, support for data‑subject rights, continuous risk assessment with a human‑in‑the‑loop approach, and clear governance with training. An annex provides a security checklist to help implement the recommendations throughout the evaluation, deployment, use and cessation stages of agentic AI.
The Privacy Commissioner said that ‘unlike conventional AI chatbots, agentic AI can operate with a high degree of autonomy and execute multi‑step tasks on behalf of users, from managing e‑mail and making reservations to processing payments’. She linked the guidance to the government’s ‘AI+’ policy direction and to the holistic development principle in China’s 15th Five‑Year Plan, stating that innovation must be accompanied by robust personal data privacy safeguards.
Why does this matter?
The guidance responds to the heightened privacy risks created by agentic AI systems that can autonomously access personal data, make decisions and perform consequential actions. It establishes practical governance expectations across the AI lifecycle, including data minimisation, transparency, security, human oversight, accountability and protection of data subject rights. More broadly, it shows that existing data protection frameworks are being adapted to address autonomous AI while enabling innovation under Hong Kong’s ‘AI+’ policy direction.