top of page

15 April 2025

Privacy Commissioner’s Office Publishes Guidelines for the Use of Generative AI by Employees

Privacy Commissioner’s Office Publishes Guidelines for the Use of Generative AI by Employees

https://www.pcpd.org.hk/english/resources_centre/publications/files/

guidelines_ai_employees.pdf (Eng)

https://www.pcpd.org.hk/tc_chi/resources_centre/publications/

files/guidelines_ai_employees.pdf (Chinese)


Privacy Commissioner’s Office Publishes Guidelines for the Use of Generative AI by Employees 

  • Scope of permissible use of Gen AI: Specify the permitted Gen AI tools, the permissible purposes of use and the applicability of the policies or guidelines;

  • Protection of personal data privacy: Provide clear instructions on the types and amounts of information that can be inputted into the Gen AI tools, the permissible purposes for using the output information, the permissible storage of the output information, the applicable data retention policy and other relevant internal policies to comply with;

  • Lawful and ethical use and prevention of bias: Specify that employees shall not use Gen AI tools for unlawful or harmful activities, emphasise that employees are responsible for verifying the accuracy of AI-generated outputs through ways such as proofreading and fact-checking, and for correcting and reporting biased or discriminatory AI-generated outputs, as well as providing instructions on when and how to watermark or label AI-generated outputs;

  • Data security: Specify the types of devices on which employees are permitted to access Gen AI tools and the categories of employees who are permitted to use Gen AI tools, require employees to use robust user credentials, maintain stringent security settings in Gen AI tools, and report AI incidents according to the organisation’s AI Incident Response Plan; and

  • Violations of policies or guidelines: Specify the possible consequences of employees’ violations of the policies or guidelines, and refer to the PCPD’s “Artificial Intelligence: Model Personal Data Protection Framework” (Model Framework) for recommendations on establishing Gen AI governance structure and measures.

Copyright @2024 The University of Hong Kong. All Rights Reserved.
bottom of page