The 60-second summary
On 25 August 2026, Hong Kong’s PCPD published guidance for organisations using agentic AI to handle personal data. It supplements the existing Model Personal Data Protection Framework, which remains applicable. The guidance addresses agents that can act across systems, rather than merely generate text. It covers restricted access, bounded purposes, transparency, accuracy, memory retention, security, individual rights, ongoing risk assessment and governance. Organisations remain responsible for their data handling: delegating a task to an agent does not transfer that responsibility. This is practical guidance under the PDPO, not a new AI law. PrivacyBuilt’s suggested next step is to review each production agent’s permissions, stored personal data and approval gates.
Timeline that matters
2024
Existing Model Framework
The PCPD’s AI Model Personal Data Protection Framework provides the baseline referenced by the supplement.
25 August 2026
Agentic AI guidance published
The PCPD announcement confirms publication of the supplement and accompanying checklist.
31 August 2026
PrivacyBuilt source review
Reviewed the official announcement, eight-page guidance and AI resource collection; no new statutory deadline identified.
7 September 2026
Next editorial review
Check for source revisions and feedback from human review. This is a PrivacyBuilt review date, not a regulator deadline.
What changed
The new supplement translates existing privacy principles into agent-specific recommendations and a lifecycle security checklist. The eight-page publication covers evaluation through retirement, including plugins, connected systems and multi-agent interactions. It makes agent deployment an operational privacy issue spanning procurement, access administration and data lifecycle management. This item was identified during the 31 August review; its publication date is 25 August, not 31 August.
Who should pay attention?
Privacy and legal teams
Confirm scope, purposes, notices and individual-rights handling before approving a use case.
Security and platform teams
Review runtime isolation, identities, permissions, plugin provenance and operational logs.
Product and operations teams
Define which actions can run unattended and which need a named decision-maker.
Procurement teams
Obtain evidence about vendor retention, security and support for correction or access requests.
What the guidance clarifies
- Guidance is not a new enactment
- The publication supports compliance with existing PDPO requirements and supplements the Model Framework. It does not announce a new fine, universal certification requirement or separate compliance deadline.
- Responsibility stays with the data user
- The guidance states that AI agents are not legal persons; organisations controlling the relevant personal-data processing remain accountable.
- An agent’s memory is part of the data lifecycle
- Conversation histories, caches and long-term memory containing personal data need appropriate retention and erasure measures; deleting the original file alone may not address these copies.
- Access and actions require separate controls
- The guidance recommends minimum permissions, caution with plugins and human control over significant-impact decisions. A connector’s ability to read a record should not automatically authorise sending or deleting it.
- Multi-agent workflows need end-to-end testing
- Errors can spread between agents, while complex data flows can obstruct access and correction. Review the complete workflow, not only the accuracy of one model response.
Treat agent access as delegated authority
Why this matters for global organisations
An agent connected to email, documents or business systems can turn a small configuration mistake into an action affecting many people. A reusable governance approach pairs each permitted task with a data boundary, an approval rule and evidence that the control works. These are operational recommendations, not a claim that one legal framework applies everywhere.
- Review read access and action authority separately.
- Include agent memory and logs in data inventories.
- Test the entire workflow using synthetic records before introducing real personal data.
- Give a named owner authority to pause an unsafe workflow.
12 actions to start now
- Create an agent register: record the business purpose, owner, model, connectors, plugins, data categories and permitted actions.
- Map a representative record through input, retrieval, agent memory, logs, downstream tools and vendors; identify copies and retention owners.
- For each task, document the minimum read and write permissions. Use dedicated identities and remove unneeded administrator access.
- Create an action matrix: distinguish drafting from sending, recommending from approving, and identifying records from deleting them.
- Require approval before high-impact disclosures, irreversible deletion or sensitive configuration changes. Test that bypass attempts fail.
- Review plugin provenance and update controls. Keep an approved version list and a process to remove unsupported integrations.
- Test with synthetic data: include inaccurate retrieved records, conflicting instructions, unauthorised recipients and unexpectedly broad requests.
- Check that people can understand the agent’s role in data handling. Route proposed new purposes and required consent questions to counsel.
- Set and test retention rules for conversations, memory, caches and audit records. Document any justified exceptions.
- Exercise an access-and-correction request across the complete workflow, including vendors and derived records.
- Run an incident drill: pause the agent, revoke credentials, preserve proportionate evidence and assess affected data and actions.
- Before retiring an agent, transfer records that must be retained, remove credentials and integrations, and verify residual-data cleanup.
Suggested next steps
- Validate applicability with qualified specialists before implementing legal or compliance changes. The implementation checklist is PrivacyBuilt’s operational analysis, not a verbatim regulator checklist.
Evidence worth retaining
- Approved use-case inventory and accountable owner.
- Data-flow diagram and permissions export, with dated access-review decisions.
- Action matrix, approval-gate configuration and failed-bypass test results.
- Vendor due-diligence record, contractual commitments and plugin/version inventory.
- Synthetic test cases, observed failures, remediation tickets and release sign-off.
- Published notices and documented purpose or consent assessment.
- Retention configuration and deletion-test results for memory, cache and logs.
- Access/correction test record and vendor response evidence.
- Incident-drill results, credential-revocation test and retirement checklist.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Does the PDPO apply to this processing, and who controls collection, holding, processing or use?
- Would any proposed agent action use personal data for a new purpose requiring prescribed consent, or does an applicable exception need assessment?
- Which decisions require human control, and what information must reviewers see to exercise it meaningfully?
- Can the vendor demonstrate deletion and correction across memory, caches and downstream systems?
- Do current notices accurately describe this workflow, recipients and data handling?
- How much logging is necessary for accountability without creating an excessive new store of sensitive data?
- What events require suspension, incident assessment, notification analysis or renewed approval?
Official sources
- PCPD — publication announcement, 25 August 2026 (agentic AI section)
- PCPD — Protecting Personal Data Privacy in the Use of Agentic AI, August 2026; CC BY 4.0
- PCPD — official AI guidance collection and Model Framework
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.