Lexguard AI logo
Lexguard AI logo

PCPD Agentic AI Guidance: What Hong Kong’s New Privacy Guidance Means for Business Leaders

The PCPD released its agentic AI privacy guidance on August 25, 2026. Learn what the new guidance means for CEOs, legal, risk, technology, procurement, and business leaders.

Lewis Ho

AI Privacy

The Office of the Privacy Commissioner for Personal Data (PCPD) released its new guidance, “Protecting Personal Data Privacy in the Use of Agentic AI,” on August 25, 2026. The guidance is designed to help organizations use agentic AI safely and responsibly while complying with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO).

The document is not long. Its implications are.

Agentic AI can manage email, make reservations, process payments, retrieve information from multiple systems, and complete multistep tasks with limited human intervention. Unlike a conventional chatbot that mainly generates a response, an AI agent may decide what steps to take, which tools to use, what information to retrieve, and whether to delegate part of the task to another system.

That creates a different privacy and governance problem.

Organizations must understand not only whether they use AI, but also:

  • what their AI agents are permitted to do;

  • which personal data they can access;

  • which systems and vendors they can call;

  • whether they can delegate tasks;

  • how long they retain information; and

  • when a human must review or approve an action.

The PCPD’s guidance is therefore best understood as a management document as much as a privacy document. Its practical value lies in translating the rules into decisions for the executives and functions responsible for strategy, legal risk, technology, security, procurement, and business operations.


The PCPD’s New Agentic AI Guidance: The Core Message

The PCPD identifies several privacy risks associated with agentic AI, including excessive access, system vulnerabilities, vulnerable plugins, function creep, and risks created by multiple agents passing information between one another. The guidance sets out nine recommendations covering data minimization, transparency, accuracy, retention, purpose limitation, security, access and correction rights, continuous risk assessment, and accountability.

In practical terms, the PCPD expects organizations to place clear limits around the agent’s authority.

An agent should not receive broad access simply because broader access makes the system easier to deploy. It should receive only the information and permissions necessary for the task.

The organization should also explain the use of agentic AI in relevant Personal Information Collection Statements and Privacy Policy Statements. The guidance does not mean that every technical detail must appear in a privacy notice. It does mean that an organization’s public statements should accurately describe the relevant purposes and processing arrangements.

The key management question is:

Can the organization explain what its AI agents are allowed to do with personal data—and prove that they stay within those limits?


Why Agentic AI Requires a Different Governance Approach

Traditional AI tools often operate within a relatively defined interaction: a user submits a prompt, the system produces an output, and a person reviews the result.

Agentic AI may operate across a chain of actions.


Traditional AI

Agentic AI

Responds to a prompt

Plans and executes multiple steps

Usually operates within one application

May move across systems, databases, and tools

Human reviews the output

Human may review only after an action occurs

Data flows are easier to identify

Data may pass through multiple agents and providers

Function is often fixed at launch

New tools and connectors may expand the workflow

Risk assessment may focus on the model

Risk assessment must cover the full operating environment

A new connector, plugin, memory function, model update, or delegated task can change the nature of the processing. That is why the PCPD calls for continuous risk assessment rather than a single review before deployment. It also recommends human involvement in decisions likely to have a significant impact on individuals.

AI Privacy

What the PCPD Agentic AI Guidance Means for Different Roles

For the CEO: Agentic AI Is an Accountability and Trust Issue

The CEO does not need to understand every model parameter. The CEO does need to know whether the organization has authorized systems that can move personal data beyond its intended control environment.

The CEO should ask:

  • Where does the organization use autonomous or semi-autonomous AI?

  • What customer, employee, or third-party data can those agents access?

  • Can an agent call an external tool or delegate work to another provider?

  • Which decisions or actions can occur without human approval?

  • Are those activities consistent with the organization’s stated purposes?

  • Who is accountable when an agent takes an inappropriate action?

The risk extends beyond a privacy-notice issue. Poorly governed agentic AI can contribute to unauthorized disclosure, inaccurate customer treatment, uncontrolled data transfers, operational disruption, contractual disputes, and reputational damage.

The CEO should require management to identify the organization’s highest-impact agentic AI workflows and report whether each one has:

  • an approved business purpose;

  • defined limits on data access;

  • a named accountable executive;

  • appropriate vendor controls;

  • clear human approval points; and

  • ongoing monitoring.

The CEO’s role is to ensure that agentic AI is treated as an enterprise governance matter, not only as an innovation or IT project.


For the General Counsel: Make Sure the Privacy Position Matches the Workflow

For the General Counsel, the central risk is the gap between legal documentation and operational behavior.

A privacy statement that refers broadly to using AI to improve services may not adequately describe a workflow in which an agent:

  • retrieves customer records;

  • combines information from multiple systems;

  • sends data to an external model;

  • delegates a task to a sub-processor; or

  • communicates a decision to an individual.

The legal review should consider whether the organization’s Personal Information Collection Statements and Privacy Policy Statements address, at an appropriate level:

  • the categories of personal data involved;

  • the purposes of processing;

  • the use of agentic AI;

  • external model, tool, and sub-agent providers;

  • relevant processing locations;

  • retention and memory arrangements;

  • human review of significant actions; and

  • access and correction mechanisms.

The PCPD specifically recommends transparency about the use of agentic AI and requires organizations to avoid using personal data for a new purpose without consent where the PDPO requires consent.


Contract questions for legal teams

Vendor agreements should address more than ordinary cloud hosting and confidentiality. Legal teams should ask:

  1. Can the provider appoint new sub-processors without approval?

  2. Can an agent invoke unlisted tools or sub-agents?

  3. Can prompts, outputs, logs, or memory data be used for model training?

  4. Are downstream providers bound by equivalent privacy and security obligations?

  5. Can the organization audit the processing chain?

  6. Can it suspend a tool, agent, or data flow quickly?

  7. Are records available showing which systems accessed or changed personal data?

  8. Can the provider verify deletion from logs, caches, backups, and long-term memory?

The goal is not to remove every risk. It is to make responsibility, authorization, evidence, cooperation, and remediation clear.


For the Chief Risk Officer: Treat Agentic AI as a Changing Control Environment

The Chief Risk Officer should treat agentic AI as an operational risk issue, not simply a technology risk issue.

The risk profile can change when the organization:

  • adds a new data source;

  • connects a new application;

  • enables a plugin;

  • changes the underlying model;

  • permits delegation;

  • expands the agent’s memory; or

  • reduces human approval requirements.

Each change may affect privacy, cybersecurity, third-party, conduct, operational resilience, legal, and reputational risk.

A practical risk framework could classify agent actions as follows:


Risk level

Example

Possible control

Low

Drafting an internal summary without external transmission

Routine monitoring and access controls

Moderate

Retrieving customer information from approved systems

Purpose limitation, logging, and periodic review

High

Sending personal data to a third party or changing a customer record

Human approval and a detailed audit trail

Critical

Deleting records, transferring sensitive data, approving payments, or changing system permissions

Dual approval, strict technical controls, and immediate escalation

The CRO should expect reporting on:

  • access outside the approved data scope;

  • unexpected tool calls;

  • unexplained delegation;

  • inaccurate personal data;

  • failed approval steps;

  • retention outside policy;

  • unexpected cross-border processing; and

  • changes to permissions, models, or architecture.

If the workflow can change without a corresponding change-control process, the organization’s risk assessment is unlikely to remain current.


For the CIO and CISO: Turn Governance Commitments into Technical Limits

The CIO and CISO are responsible for ensuring that the agent’s technical authority matches its approved purpose.

A privacy notice cannot correct excessive permissions. If an agent needs access to invoice records but receives access to an entire mailbox or customer database, the organization has created a data-minimization and access-control problem before the agent produces an output.

The PCPD recommends granting agentic AI only the minimum access rights necessary for the task. It also recommends security measures such as guardrails, traceability, auditability, careful use of plugins and skills, and current system versions.

Technical controls should include:

  • least-privilege access;

  • separate credentials for different agents and functions;

  • field-level filtering and masking;

  • approved-tool and application allowlists;

  • restrictions on outbound data transfers;

  • isolated memory stores;

  • defined retention and deletion controls;

  • monitoring of prompts, outputs, and tool calls;

  • tamper-resistant audit logs; and

  • emergency shutdown or credential-revocation mechanisms.

The CIO and CISO should distinguish between an agent’s ability to read information and its ability to take action. Read access, write access, and execution authority should be separately designed and monitored.

They should also assess whether a vendor can materially change the workflow without the organization’s knowledge. An automatic model update, newly enabled plugin, or revised routing rule may create a different processing environment even when the organization has not changed its own configuration.


For Business Unit Leaders: Define the Purpose More Precisely Than “Productivity”

Business leaders often adopt agentic AI to improve service, reduce costs, or increase responsiveness. Those may be valid objectives, but “improve productivity” does not sufficiently define the processing activity.

The business owner should be able to explain:

  • what task the agent performs;

  • whose personal data it uses;

  • why the information is necessary;

  • what the agent cannot do;

  • when a human must intervene;

  • which vendors support the workflow; and

  • how the system will be changed, reviewed, or retired.

A new data connector should not be treated as a routine technical enhancement. It may change the purpose, risk profile, data flows, and privacy disclosures associated with the use case.

A sound operating rule is:

No new connector, plugin, sub-agent, or memory function should enter production until the organization confirms that its purpose, disclosures, permissions, and vendor controls remain aligned.


For Procurement and Vendor Management: Map the Entire Processing Chain

Traditional vendor reviews often focus on the primary provider and its listed sub-processors. Agentic AI requires a broader view.

Procurement should identify:

  • the principal agent provider;

  • the underlying model provider;

  • cloud and hosting providers;

  • tool and plugin providers;

  • data-enrichment services;

  • identity and fraud-screening providers;

  • analytics platforms;

  • logging and monitoring providers;

  • memory or vector-database providers; and

  • agents that may receive delegated tasks.

The key question is whether a provider can introduce or invoke new processing participants during runtime.

Contracts should address:

  • unauthorized sub-agent access;

  • secondary use of personal data;

  • model training and tuning;

  • unapproved jurisdictional transfers;

  • retention of prompts and outputs;

  • delegation beyond the agreed purpose;

  • material architecture changes; and

  • cooperation with investigations, access requests, correction requests, deletion, and regulatory inquiries.

A sub-processor list remains useful. It may not be enough if the agent can dynamically call services that are not clearly identified or controlled.

AI Privacy

The PCPD’s Nine Recommendations: An Executive Summary

The new PCPD guidance recommends that organizations:

  1. Avoid excessive collection by applying data minimization and restricting the systems and information an agent can access.

  2. Be transparent about the use of agentic AI in relevant privacy statements.

  3. Protect data accuracy through testing, context-specific controls, and human review where appropriate.

  4. Set retention periods and erase personal data from conversation histories, caches, and long-term memory when no longer needed.

  5. Prevent function creep by defining processing purposes and requiring oversight for expanded or higher-risk uses.

  6. Protect system and data security through access controls, guardrails, cautious plugin use, traceability, and auditability.

  7. Support access and correction rights by selecting systems designed to accommodate privacy rights.

  8. Conduct continuous risk assessments and use human review for decisions likely to significantly affect individuals.

  9. Assign responsibility and provide training through clear governance structures, adequate resources, contractual controls, and workforce education.

The guidance also includes a security checklist covering evaluation, preparation, deployment, use, and cessation of agentic AI. That checklist can help organizations convert broad principles into implementation steps.


What Senior Management Should Do Now

Within 30 Days

  • Identify all production systems with autonomous or semi-autonomous capabilities.

  • Rank them by data sensitivity and ability to take external action.

  • Assign an accountable business owner and executive sponsor.

  • Review current privacy notices and Personal Information Collection Statements.

  • Pause expansion of high-risk workflows where ownership or controls are unclear.

Within 60 Days

  • Map the data flows, tools, models, agents, and sub-processors supporting priority use cases.

  • Review vendor contracts and downstream-provider arrangements.

  • Define approval thresholds for high-risk actions.

  • Confirm retention, memory, logging, and deletion controls.

  • Establish a process for reviewing material changes to agent capabilities.

Within 90 Days

  • Update privacy notices and internal documentation where necessary.

  • Implement continuous monitoring and change management.

  • Test scenarios involving unauthorized disclosure, inaccurate data, failed approvals, vendor compromise, and unexpected delegation.

  • Report material gaps to the board or relevant risk committee.

  • Establish periodic reporting for significant agentic AI deployments.

AI Privacy

Board-Level Takeaway

The PCPD’s new agentic AI guidance does not require directors and senior executives to become AI engineers. It does require them to understand what the organization’s systems can do with personal data and whether the organization has governance proportionate to that capability.

The more autonomous the workflow, the less useful it is to describe the system simply as “AI.” Management should be able to explain the purpose of the processing, the data involved, the systems and providers in the processing chain, the limits on the agent’s authority, and the points at which a human must intervene.

The standard is not maximal disclosure or the elimination of innovation. It is accurate disclosure, limited authority, controlled delegation, meaningful human oversight, and evidence that controls operate in practice.

In our governance audit practice at Lexguard, we recommend pairing a review of privacy statements with an agentic AI data-mapping exercise. That combination shows whether the organization’s public disclosures, vendor contracts, technical permissions, and actual workflows still describe the same system, which is a question senior management should be able to answer before the regulator asks it.

FAQ
  1. What does Hong Kong’s PCPD guidance require for agentic AI?

The Hong Kong Office of the Privacy Commissioner for Personal Data’s August 25, 2026 guidance recommends continuous risk assessments, data minimization, purpose limitation, appropriate retention, security controls, traceability, human oversight, training, and transparency in Personal Information Collection Statements and Privacy Policy Statements under the Personal Data (Privacy) Ordinance (Cap. 486).

  1. Why do multi-agent workflows create vendor liability risk?

A primary AI agent may delegate personal-data processing to sub-agents, plugins, model providers, or external tools that the enterprise did not directly approve. The PCPD identifies multi-agent data-flow and access risks. Contracts should control sub-processors, prohibit unauthorized secondary use, require equivalent safeguards, preserve audit rights, and provide logs and suspension rights.

  1. What is the most defensible governance action for a Hong Kong enterprise?

An enterprise should conduct an agentic data-mapping exercise and review its Personal Information Collection Statements, Privacy Policy Statements, vendor agreements, sub-processor controls, retention rules, access rights, human checkpoints, and audit logs. The review should test whether actual workflows remain within documented purposes under DPPs 1, 2, 3, 4, 5, and 6.