Hong Kong Launches Personal Data AI Sandbox: What Organisations Can Learn About AI Privacy Governance
Hong Kong’s new school-focused Personal Data AI Sandbox highlights practical AI privacy controls that businesses can apply, although companies cannot join its first phase.
A six-month, school-focused AI sandbox
On 6 July 2026, the Office of the Privacy Commissioner for Personal Data (PCPD) and the Digital Policy Office (DPO) jointly launched the Safeguarding Personal Data AI Sandbox. The first phase will run for six months and is designed to help schools explore and adopt artificial intelligence solutions while complying with the Personal Data (Privacy) Ordinance (PDPO).
The application scope is specific: only publicly funded primary and secondary schools may apply, and 15 school applicants will be selected. Applications close on 30 October 2026, with a briefing session scheduled for 28 August 2026. Ordinary businesses and other organisations are not applicants under this phase.
Selected schools will receive complimentary access to PCPD regulatory guidance on personal data privacy, DPO guidance relating to the Hong Kong Generative Artificial Intelligence Technical and Application Guideline, and technical advice from Cyberport and the Hong Kong Productivity Council.
Why the programme still matters to businesses
Although companies cannot apply for the first phase, the programme reflects a wider operational principle: AI adoption should be supported by privacy governance, technical controls and accountable implementation rather than treated solely as a software purchase.
PCPD’s AI Privacy Protection resources already include a Checklist on Guidelines for the Use of Generative AI by Employees and the Artificial Intelligence: Model Personal Data Protection Framework. According to PCPD, these materials are intended to help organisations develop internal employee policies and procure, implement and use AI in compliance with the PDPO.
A practical AI privacy checklist for organisations
Before staff use generative AI or an organisation deploys an AI system, management should consider:
- Define the purpose and data boundary. Record the business purpose, the categories of personal data involved and whether personal data is genuinely necessary.
- Minimise inputs. Avoid entering client, employee or identification data into public AI tools unless the use is authorised, necessary and supported by appropriate safeguards.
- Control access and retention. Set user permissions, retention periods, deletion arrangements and rules for downloading or reusing AI outputs.
- Review vendors and data flows. Understand where prompts, uploaded files and generated outputs are processed, stored or transferred, and assess contractual and security controls.
- Maintain human oversight. Assign responsibility for checking accuracy, bias, privacy impact and consequential decisions; do not treat AI output as automatically reliable.
- Prepare for incidents. Establish escalation, containment, evidence preservation and notification procedures for accidental disclosure or other personal-data incidents.
- Train employees and keep records. Provide clear permitted-use rules, prohibited data examples and an approval route for higher-risk use cases.
These steps do not replace a case-specific privacy, legal or security assessment. They provide a starting point for aligning AI experimentation with the PDPO and internal governance.
Sources
HKSAR Government, 6 July 2026: https://www.info.gov.hk/gia/general/202607/06/P2026070300679.htm
PCPD AI Privacy Protection resources: https://www.pcpd.org.hk/english/artificial_intelligence/index.html
Disclaimer
This article provides general information only and does not constitute legal, privacy, cybersecurity, accounting or regulatory advice. Organisations should review current official guidance and obtain advice appropriate to their systems, data and circumstances.
