{"id":29230,"date":"2025-04-25T09:08:54","date_gmt":"2025-04-25T09:08:54","guid":{"rendered":"https:\/\/prelive-tdw.visibleone.app\/insight-and-news\/legal-update-pcpds-checklist-on-use-of-genai-at-work\/"},"modified":"2025-11-14T11:00:58","modified_gmt":"2025-11-14T11:00:58","slug":"legal-update-pcpds-checklist-on-use-of-genai-at-work","status":"publish","type":"insight-and-news","link":"https:\/\/www.tannerdewitt.com\/zh-hans\/insight-and-news\/legal-update-pcpds-checklist-on-use-of-genai-at-work\/","title":{"rendered":"Legal Update: PCPD\u2019s Checklist on Use of GenAI at Work"},"content":{"rendered":"\n    \n\n<div style=\"background-image:url('https:\/\/www.tannerdewitt.com\/wp-content\/themes\/tanner-de-witt\/images\/insightdetails.jpeg')\"\n    class=\"insight-news-detail-hero\" id=\"insight-news-detail-hero\">\n\n\t\t<div style=\"background-color:\" class=\"insight-news-detail-hero-overlay \"><\/div>\n            <div class=\"z-[0]\">\n                <div class=\"insight-news-breadcrumbs flex items-end practice-areas-featured-breadcrumbs \">\n                    <a class=\"page-link no-underline\" href=\"https:\/\/www.tannerdewitt.com\/zh-hans\/\">Home<\/a>                <\/div>\n\n\n                <div class=\"hero-title\">\n                    <h1>\n                        Legal Update: PCPD\u2019s Checklist on Use of GenAI at Work                    <\/h1>\n                <\/div>\n                \n                    <div style=\"\" class=\"hero-date \">\n\n                        <span class=\"month\">Apr<\/span>\n                        <span class=\"day\">25<\/span>\n                        <span class=\"year\">2025<\/span>\n                    <\/div>\n\n            <\/div>\n    \n\n    \n\n\n\n<\/div>\n\n\n\n<script >\n    (function () {\n        document.addEventListener(\"DOMContentLoaded\", () => {\n\n            const breadCrumbsContainer = Array.from(document.querySelectorAll(\".practice-areas-featured-breadcrumbs\"));\n\n            breadCrumbsContainer.forEach(container => {\n                const breadCrumbLinks = Array.from(container.querySelectorAll('.page-link'));\n                const breadCrumbSeperators = Array.from(container.querySelectorAll('.separator'));\n\n                if (Array.from(breadCrumbLinks).length === 1) {\n                    const homeNode = breadCrumbLinks[0];\n\n                    if (!homeNode) {\n                        return\n                    }\n\n                    const postTypeNode = homeNode.cloneNode(true);\n                    postTypeNode.textContent = \"Insights and News\";\n                    container.insertAdjacentHTML('beforeend', `<span class=\"separator practice-areas-featured-breadcrumb-item-slash\">\/<\/span>`)\n                    container.insertAdjacentElement('beforeend', postTypeNode)\n                    breadCrumbLinks.push(postTypeNode);\n\n                    if (\"Insights\") {\n                        const categoryNode = homeNode.cloneNode(true);\n\n                        categoryNode.textContent = \"Insights\";\n                        container.insertAdjacentHTML('beforeend', `<span class=\"separator practice-areas-featured-breadcrumb-item-slash\">\/<\/span>`)\n                        container.insertAdjacentElement('beforeend', categoryNode)\n                        breadCrumbLinks.push(categoryNode);\n                    }\n\n\n                    const titleNode = homeNode.cloneNode(true);\n\n                    titleNode.textContent = \"Legal Update: PCPD\u2019s Checklist on Use of GenAI at Work\";\n                    container.insertAdjacentHTML('beforeend', `<span class=\"separator practice-areas-featured-breadcrumb-item-slash\">\/<\/span>`)\n                    container.insertAdjacentElement('beforeend', titleNode)\n                    breadCrumbLinks.push(titleNode);\n\n\n\n\n                }\n\n                breadCrumbLinks.forEach((link, index) => {\n\n                    link.classList.add('practice-areas-featured-breadcrumb-item-name');\n                    const origin = window.location.origin;\n                    const href = window.location.href;\n\n                    const originSplitter = window.location.href.includes(\"insight-and-news\") ? \"insight-and-news\" : window.location.href.includes('insights-and-news') ? \"insights-and-news\" : \"\"\n\n                    const paths = href.split(originSplitter);\n                    const links = paths[1].split(\"\/\").filter(Boolean)\n\n\n                    const resolvedOrigin = originSplitter ? (href.split(originSplitter)[0] || \"\") : (origin + \"\/\")\n\n                    if (index === 0) {\n\n                        if (!originSplitter) {\n                            link.href = origin\n                        } else {\n                            link.href = resolvedOrigin;\n                        }\n\n\n                    } else if (index === 1) {\n                        link.href = resolvedOrigin + originSplitter\n\n                    }\n                    else if (index === 2) {\n                        console.log(links)\n                        link.href = resolvedOrigin + originSplitter + \"\/\" + (links[0] || \"\")\n                    }\n                    else if (index === 3) {\n\n                        link.href = resolvedOrigin + originSplitter + \"\/\" + (links[0] || \"\") + \"\/\" + (links[1] || \"\")\n\n                    }\n\n\n\n                    \/\/ const words = link.textContent.split(\" \")\n                    \/\/ if (words.length > 4) {\n                    \/\/     link.textContent = words.slice(0, 4).join(\" \") + \"...\"\n                    \/\/ }\n\n                })\n\n                breadCrumbSeperators.forEach(separator => {\n                    separator.textContent = \"\/\"\n                    separator.classList.add('practice-areas-featured-breadcrumb-item-slash')\n                });\n\n\n            })\n\n\n        })\n        removeDivTag()\n    })();\n\n    function removeDivTag() {\n        console.log(\"remasfljas\");\n        const editorContainer = document.querySelector(\".editor-wysiwyg\");\n        \/\/ editorContainer.innerText = editorContainer.innerText.replace(\"<\/div>\", \"\")\n        Array.from(editorContainer.childNodes).forEach(el => {\n            if (el.textContent.includes(\"<\/div>\")) {\n                el.textContent = \"\"\n            }\n        })\n    }\n<\/script>\n\n<div class=\"editor-wysiwyg my-[40px]\">\n<div class=\"single-section\">\n<p>The rapid adoption of generative artificial intelligence (\u201c<strong>GenAI<\/strong>\u201d) applications and agents is quickly transforming the workplace and how work is done in many enterprises in Hong Kong. The ease of use of GenAI tools can disguise personal data privacy and protection risks. In this update,\u00a0<a href=\"https:\/\/www.tannerdewitt.com\/our-people\/padraig-walsh\/\">P\u00e1draig Walsh<\/a>\u00a0from our\u00a0<a href=\"https:\/\/www.tannerdewitt.com\/practice-areas\/data-privacy\/\">Data Privacy<\/a>\u00a0practice looks at the new guidelines published by the Office of the Privacy Commissioner for Personal Data (\u201c<strong>PCPD<\/strong>\u201d) to help businesses develop internal policies or guidelines for employees\u2019 use of Gen AI at work.<\/p>\n<p>The key points of the PCPD Guidelines for the Use of Generative AI by Employees are:<\/p>\n<p>(a)\u00a0<strong>Specify the scope of permissible use<\/strong><\/p>\n<p>Businesses should specify:<\/p>\n<p>(i) what GenAI tools can be used. Ideally, the permitted list should identify the specific version that is permitted, noting that commercially licensed versions of publicly available GenAI tools may provide more privacy protection.<\/p>\n<p>(ii)\u00a0what the permitted GenAI tools can be used for. This should identify the specific work processes that the permitted GenAI tools can be used for \u2013 such as drafting marketing collateral, and so on.<\/p>\n<p>(iii)\u00a0who is permitted to use the GenAI tools. This could be everybody in the business, or specific departments or ranks.<\/p>\n<p>(b)\u00a0<strong>Protect personal data privacy<\/strong><\/p>\n<p>GenAI tools generally function by the user providing inputs or prompts that are processed to deliver an output. Businesses should:<\/p>\n<p>(i) specify the permissible types and amounts of information that can be inputted into GenAI tools;<\/p>\n<p>(ii)\u00a0expressly prohibit excluded information (which may include personal, confidential, proprietary or copyrighted information);<\/p>\n<p>(iii)\u00a0specify the permissible use of the information and output generated by GenAI tools and identify situations where personal data should be anonymised before further use;<\/p>\n<p>(iv) specify how output information should be stored and deleted; and<\/p>\n<p>(v)\u00a0ensure that the policies or guidelines on the use of GenAI align with other relevant internal policies, including those on personal data handling and information security.<\/p>\n<p>(c)\u00a0<strong>Lawful and ethical use and prevention of bias<\/strong><\/p>\n<p>Businesses should specify that employees must not use GenAI tools for unlawful or harmful activities. They should also define the ethical values and standards which employees should observe when reviewing AI-generated output, including accuracy, prevention of bias and discrimination, and labelling to identify use of GenAI in production of materials.<\/p>\n<p>(d)\u00a0<strong>Data security<\/strong><\/p>\n<p>Businesses should specify:<\/p>\n<p>(i)\u00a0the devices on which employees are permitted to access Gen AI tools (e.g. office computers, work phones, and tablets). In general, employees should only use GenAI tools for work-related purposes on work provided devices;<\/p>\n<p>(ii)\u00a0who is permitted to use Gen AI tools (e.g. employees with operational needs who have received relevant training);<\/p>\n<p>(iii)\u00a0the use of robust user credentials and stringent security settings when using the tools. Security settings should prioritise data security, which may include measures such as disabling saving functions and prohibiting sharing of prompts with GenAI providers; and<\/p>\n<p>(iv) the procedures for reporting data breaches, unauthorised input of personal data, abnormal output results, and potentially illegal output.<\/p>\n<p>(e)\u00a0<strong>Specify consequences of violation of the policies or guidelines<\/strong><\/p>\n<p>Businesses should specify the possible consequences of employees\u2019 violation of the policies or guidelines on the use of GenAI.<\/p>\n<p>(f)\u00a0<strong>Support employees in using GenAI tools<\/strong><\/p>\n<p>Businesses should ensure that the policies or guidelines on the use of AI are clearly communicated to employees. Businesses should also provide training and resources to help employees understand the risks of GenAI, and to use GenAI tools effectively and responsibly. Businesses should establish channels for employees to provide feedback on their experience using GenAI tools.<\/p>\n<p><strong>Concluding remarks<\/strong><\/p>\n<p>In Hong Kong, the PCPD has taken the lead in giving horizontal guidance across all industry sectors in respect of risks associated with adoption of GenAI. Even in these guidelines, the PCPD noted that its reference to information includes personal data and general information also. This is sensible. It is difficult to segregate and deal with personal data risks only when addressing GenAI systems.<\/p>\n<p>The adoption of the recommendations in these guidelines is a very good step forward for businesses looking to adopt and implement a framework to guide employees on the use of GenAI tools in the workplace. Ultimately, the implementation of the guidelines will safeguard personal data and also provide a foundation for the safe and responsible use of AI by businesses.<\/p>\n<p>The path to implementation of the PCPD guidelines involves assessing the guidelines in the context of the business and its business processes, drafting an AI Usage Policy that will apply to employees, and providing training, guidance and support to employees on the requirements of that policy. We at Tanner De Witt can help and assist in each of these steps.<\/p>\n<p>The PCPD Guidelines for the Use of Generative AI by Employees is available on this\u00a0<a href=\"https:\/\/www.pcpd.org.hk\/english\/resources_centre\/publications\/files\/guidelines_ai_employees.pdf\" target=\"_blank\" rel=\"noopener\">link<\/a>.<\/p>\n<p>\u00a0<\/p>\n<p class=\"has-text-align-right\"><em><strong>P\u00e1draig Walsh<\/strong><\/em><\/p>\n<p>\u00a0<\/p>\n<p>If you want to know more about the content of this article, please contact:<\/p>\n<p><a href=\"https:\/\/www.tannerdewitt.com\/our-people\/russell-bennett\/\"><strong>P\u00e1drai<\/strong><\/a><a href=\"https:\/\/www.tannerdewitt.com\/our-people\/padraig-walsh\/\"><strong>g Walsh<\/strong><\/a><\/p>\n<p>Partner |\u00a0<a href=\"mailto:PadraigWalsh@tannerdewitt.com\">Email<\/a><\/p>\n<p><em>Disclaimer: This publication is general in nature and is not intended to constitute legal advice. You should seek professional advice before taking any action in relation to the matters dealt with in this publication. This article was last reviewed on 25 April 2025.<\/em><\/p>\n<\/div>\n<\/div>\n\n\n\n\n<\/div>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The rapid adoption of generative artificial intelligence (\u201cGenAI\u201d) applications and agents is quickly transforming the workplace and how work is done in many enterprises in Hong Kong. The ease of use of GenAI tools can disguise personal data privacy and protection risks. In this update,\u00a0P\u00e1draig Walsh\u00a0from our\u00a0Data Privacy\u00a0practice looks at the new guidelines published by [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"footnotes":""},"tags":[],"insight-category":[1121],"insight-month":[1155],"insight-practice-area":[1142],"insight-year":[1147],"class_list":["post-29230","insight-and-news","type-insight-and-news","status-publish","hentry","insight-category-legal-updates-and-insights","insight-month-april","insight-practice-area-technology-media-and-telecommunications-tmt","insight-year-1147"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-and-news\/29230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-and-news"}],"about":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/types\/insight-and-news"}],"author":[{"embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-and-news\/29230\/revisions"}],"predecessor-version":[{"id":30442,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-and-news\/29230\/revisions\/30442"}],"wp:attachment":[{"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/media?parent=29230"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/tags?post=29230"},{"taxonomy":"insight-category","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-category?post=29230"},{"taxonomy":"insight-month","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-month?post=29230"},{"taxonomy":"insight-practice-area","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-practice-area?post=29230"},{"taxonomy":"insight-year","embeddable":true,"href":"https:\/\/www.tannerdewitt.com\/zh-hans\/wp-json\/wp\/v2\/insight-year?post=29230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}