Back to perspectives

Family Governance

Before an AI agent accesses family data: permissions and an exit plan

Server cabinets viewed through a doorway, illustrating an access boundary
AI-generated conceptual image. The scene is fictional and does not depict actual facilities, documents, assets or events, or imply endorsement of G70 by any institution.

The PCPD’s new guidance brings agentic AI privacy risks into everyday operations. Family offices can examine minimum permissions, human approval and how data exits a service.

G70

Reading points

1

Official recommendations | Limit access and retain control

2

G70 view | Begin with a bounded task

3

An exit process and questions to ask

01

Official guidance | Responsibility stays with the data user

As of 2 October 2026. Hong Kong’s Office of the Privacy Commissioner for Personal Data published guidance on protecting personal data privacy in the use of agentic AI on 25 August, supplementing its AI personal data protection framework. This is guidance, not a new statute.

The PCPD explains that agents can execute multi-step tasks for users. Organisations remain responsible as data users for complying with the Personal Data (Privacy) Ordinance where agents process personal data. Delegating execution does not delegate that responsibility.

02

Official recommendations | Limit access and retain control

The guidance addresses data minimisation, minimum access rights, retention, access and correction, and ongoing risk assessment. It recommends human involvement and final control over decisions that may significantly affect individuals.

Personal data may remain in conversations, caches and long-term memory. A review therefore needs to extend beyond the original folder to understand retention and deletion by external providers, tools and memory features.

03

G70 view | Begin with a bounded task

We suggest testing a lower-risk, reversible task, such as organising publicly available meeting materials after removing personal identifiers. Use a separate workspace and record the permitted data, tools and prohibited actions. This is a general operating suggestion, not a compliance certification.

Assess necessity and sensitivity before including passports, medical records, children’s data or family correspondence. Consider requiring named human approval for transfers to third parties, deletion and permission changes, with a clear record of review responsibility.

04

An exit process and questions to ask

Before retiring an AI tool, identify work records that need retention, active account connections, granted permissions and data held in conversations or memory. Handle these under an agreed retention process. Removing the desktop application alone may leave data or access behind.

Ask the provider and professional advisers whether data is used for training, who can access it, how correction and deletion work, and who revokes permissions when staff leave or suppliers change. G70’s focus is whether operation of the intended data boundaries can be demonstrated.

Sources