09 / 15·PDPO, cross-border data, and private AI
PCPD AI personal-data model framework: an SME checklist
The one-page list
1 Who owns AI and personal data. 2 Which workflows use AI and whether they touch personal data. 3 Whether vendors or data leave Hong Kong. 4 Who reviews output. 5 How customers and staff are told. 6 How errors and breaches are escalated.
How to use it
Tick it for fifteen minutes once a quarter. For each gap, name an owner and a date. The framework is a self-check, not a certificate.
How it meets a diagnosis
A business diagnosis listens to one real workflow, then marks which line on this list is still open. Tools follow the gap.
Questions
- Does finishing the checklist mean we comply?
- No. It is a start. Transfers, marketing, and retention still depend on your facts and the latest guidance.
- Is the framework mandatory?
- A model framework is guidance. Do not describe a particular text as legally compulsory. Check the PCPD’s latest version before you adopt it.
This article is general information, not legal advice. PCPD guidance changes — check the latest version before you rely on it.
Want a first look at whether one real workflow touches personal data? Book a 1-hour business diagnosis.
Book a 1-hour diagnosis