Skip to main content

PCPD AI Compliance Checks: What Hong Kong's Regulator Actually Found in 60 Organisations

In January 2026 Hong Kong's Privacy Commissioner for Personal Data (PCPD) launched compliance checks on 60 organisations.

Last updated August 2026
Quick answer

In early 2026 the PCPD checked 60 organisations. 95% used AI in day-to-day operations; over half used three or more AI systems. The PCPD found no PDPO contraventions and recommended six actions: governance structures, privacy impact assessments (PIAs), AI audits, staff training, incident-response plans, and specific controls for agentic AI.

Results published in May 2026 showed 95% used AI in day-to-day operations and over half used three or more AI systems. The PCPD found no PDPO contraventions — but the specific recommendations they made are the more actionable story.

The most interesting regulatory findings are the ones where nothing broke. In January 2026 the PCPD sampled 60 organisations across sectors and looked at how they were actually using AI. The results — published May 2026 — are one of the cleanest snapshots of AI compliance practice in the region.

What the PCPD did

The PCPD launched the compliance checks in January 2026. The sample was 60 organisations across sectors. The methodology was documentary review and organisational interviews focused on how AI was being used, what governance sat around it, and how personal data flowed through those systems. Results were published in May 2026.

What the PCPD found

  • 95% of organisations used AI in day-to-day operations. A far higher penetration than most surveys report because this counted embedded AI features in commonly used tools, not just standalone AI systems.
  • Over half used three or more AI systems. The single-tool AI story is already out of date for Hong Kong business.
  • No PDPO contraventions were identified in the sample. This is the headline — and it should be read as "the sampled organisations were operating within the current framework", not "AI use in Hong Kong is uniformly compliant".
  • Governance maturity was inconsistent. Organisations that used AI heavily did not always have proportionate governance.

What the PCPD recommended

Six recommendation areas. Each is worth reading as a checklist for a Hong Kong SME:

  1. AI governance structure. Someone accountable — not "IT" as a black box.
  2. Privacy Impact Assessments (PIAs) for material AI use cases involving personal data.
  3. AI audits. Periodic review of what the AI is actually doing in production versus what was documented.
  4. Staff training. Users of AI tools understand what data they can and cannot put in.
  5. Incident-response plans that specifically cover AI-related incidents — not the generic IT incident plan retitled.
  6. Controls for agentic AI. See the detailed post: PCPD's agentic AI alert.

How to read "no contraventions found"

This is the most misread line in the report. It does not mean AI use in Hong Kong is broadly compliant.

It means the sampled 60 organisations were operating within the current PDPO framework — a framework which is materially lighter on AI-specific obligations than, for example, Singapore's post-July-2026 position. The PCPD's recommendations exist because the current absence of contraventions is a floor, not a ceiling.

A Hong Kong business that is comfortable operating at the current statutory floor should still expect the floor to rise. The recommendation list above is the direction.

What to do this quarter — the SME cut

Six PCPD recommendations map to five practical actions for a 5–30 person Hong Kong business:

  1. Name an AI owner. One person. Written down.
  2. List your AI systems. Include embedded features (CRM AI, chatbot integrations, ad-copy assistants). The PCPD's "over half use three or more" figure means the honest count is usually higher than the intuitive one.
  3. Do a lightweight PIA on the two highest-risk systems. Not every system needs a full PIA — the highest-risk ones do.
  4. Ten-minute staff briefing on what not to put into AI tools. Written record.
  5. Add an "AI-related incident" branch to your existing incident-response document. One page.

Hong Kong businesses aligning AI-facing marketing and content programmes with the PCPD's expectations can lean on our Hong Kong GEO / AI search optimization service, where the same governance thread runs through the delivery. Healthcare and clinic operators should also validate ad copy against jurisdiction-specific rules via the HK medical ad checker before publish.

References

  • Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong — compliance checks announcement (January 2026) and results publication (May 2026) — pcpd.org.hk (opens in a new tab)
  • Mayer Brown, "AI in Asia mid-year checkpoint", July 2026

Ready to grow your business with proven digital marketing?

Our team specialises in performance marketing for Malaysian businesses — from clinics and property developers to national institutions and marketplace brands.

Published by shakalakaa team  ·  Editorial standards

FAQ

Frequently asked questions

How many organisations did the PCPD check?

60, across sectors, between January and May 2026.

What percentage were using AI?

95% used AI in day-to-day operations. Over half used three or more AI systems.

Were any PDPO contraventions found?

No — but the PCPD issued six recommendation areas (governance, PIAs, audits, training, incident response, agentic AI controls) which map to how the standard is expected to evolve.

Does the PDPO have AI-specific obligations?

The current PDPO framework is lighter on AI-specific obligations than Singapore's post-July-2026 position. The PCPD's recommendations sit above the statutory floor.

Let's talk

Let's start the convo.