InnovateXP Limited - AI CRM and Event Management Solutions Hong Kong
InnovateXP Limited

09 / 15·PDPO, cross-border data, and private AI

PCPD AI personal-data model framework: an SME checklist

Direct answerThe PCPD has published a model framework to help organisations self-assess AI and personal data. An SME does not need a thick report. A one-page checklist is enough to start: an owner, a data list, risk, human review, openness, and incident handling. Before you cite the framework’s title or date, verify the official text on the PCPD site.

The one-page list

1 Who owns AI and personal data. 2 Which workflows use AI and whether they touch personal data. 3 Whether vendors or data leave Hong Kong. 4 Who reviews output. 5 How customers and staff are told. 6 How errors and breaches are escalated.

How to use it

Tick it for fifteen minutes once a quarter. For each gap, name an owner and a date. The framework is a self-check, not a certificate.

How it meets a diagnosis

A business diagnosis listens to one real workflow, then marks which line on this list is still open. Tools follow the gap.

Questions

Does finishing the checklist mean we comply?
No. It is a start. Transfers, marketing, and retention still depend on your facts and the latest guidance.
Is the framework mandatory?
A model framework is guidance. Do not describe a particular text as legally compulsory. Check the PCPD’s latest version before you adopt it.

This article is general information, not legal advice. PCPD guidance changes — check the latest version before you rely on it.

Want a first look at whether one real workflow touches personal data? Book a 1-hour business diagnosis.

Book a 1-hour diagnosis