InnovateXP Limited - AI CRM and Event Management Solutions Hong Kong
InnovateXP Limited

02 / 15·PDPO, cross-border data, and private AI

Can staff use of ChatGPT breach the PDPO?

Direct answerStaff using public ChatGPT is not automatically unlawful. The risk is pasting names, phone numbers, ID numbers, contracts, or client records into a public model you do not control. Give the team a one-page policy: what may be pasted, what needs review, and what is banned.

Green, amber, red

Green: public product copy and published market facts. Amber: internal drafts after names and phone numbers are removed. Red: ID numbers, bank details, unpublished contracts, staff discipline records, and raw client chats.

What the one-pager should say

Name the approved tools, banned fields, who may clear amber items, and what happens if someone breaks the rule. New joiners read it on day one. If you cite PCPD generative-AI staff guidance, verify the official title and date on the PCPD site first.

What managers should do

Sample a month of pastes. Move red-zone work to an enterprise account or private AI instead of relying on a verbal reminder.

Questions

Is a company-email ChatGPT account safe?
Not by itself. Who owns the login and what gets pasted are different questions. Consumer plans may still use chats under their terms.
Is removing the name enough?
Not if a phone number, contract ID, or address still identifies the person. Amber becomes green only when the person cannot be identified.

This article is general information, not legal advice. PCPD guidance changes — check the latest version before you rely on it.

Want a first look at whether one real workflow touches personal data? Book a 1-hour business diagnosis.

Book a 1-hour diagnosis