Skip to content Skip to footer

PCPD’s Guidelines for Devising an Internal Gen AI Policy Creates a Win-Win Situation

Home > Media / Publication > HR Journal

PCPD’s Guidelines for Devising an Internal Gen AI Policy Creates a Win-Win Situation

2025-06-13

Key Takeaways:

  • To help organisations and members of the public address the privacy risks brought by the AI tsunami, the PCPD has published a series of guidance materials and leaflets since 2021.
  • In particular, the “Checklist on Guidelines for the Use of Generative AI by Employees” was published in March 2025 to help organisations develop internal policies or guidelines on the use of Gen AI by employees at work while complying with the relevant requirements of the PDPO.

Since artificial intelligence (AI) chatbots took the world by storm in 2022, human resources professionals have faced a conundrum. Although generative AI (Gen AI) can potentially enhance an organisation’s productivity, the excitement over this emerging technology is tempered by the challenges in governing its use and ensuring data security and compliance with laws such as the Personal Data (Privacy) Ordinance (the PDPO).

Compliance checks completed by my Office (the PCPD) in May 2025 found that 80% of the organisations examined used AI in their day-to-day operations. A recent study published by the Hong Kong Federation of Trade Unions (the HKFTU) further revealed that nearly 70% of employees did not regularly or proactively disclose their use of Gen AI to their employers, and more than 40% expressed little concern about the liability of exposing or mishandling personal data or confidential information when using Gen AI. With these trends in mind, the question arises of how an organisation can ensure that their employees use AI safely in the ever-evolving digital landscape, with a view to leveraging the benefits of the new technology while safeguarding the interests of the organisation and its employees to create a win-win situation.

AI Security

As data is the lifeblood of AI, it is abundantly clear that threats to personal data privacy are among the most concerning risks posed by AI. Although some encouragement can be taken from the PCPD’s 2024 survey showing that nearly 70% of enterprises recognised significant privacy risks in AI use, only 28% of these had established an AI security policy. Clearly, awareness does not equate to action, and this leaves some organisations vulnerable to AI security risks and their employees uncertain about what is permissible.

The PCPD’s New Guidelines

To help organisations and members of the public address the privacy risks brought by the AI tsunami, the PCPD has published a series of guidance materials and leaflets since 2021. In particular, the “Checklist on Guidelines for the Use of Generative AI by Employees” (the Guidelines) was published in March 2025 to help organisations develop internal policies or guidelines on the use of Gen AI by employees at work (AI policy) while complying with the relevant requirements of the PDPO. The HKFTU study published in May, calls amongst other things for organisations to make reference to the Guidelines when formulating an internal AI policy.

The Guidelines recommend that organisations consider the following areas when developing an internal AI policy.

a)  Scope of Permissible Use of Gen AI
Organisations should specify the permitted Gen AI tools and clearly define the permissible purposes for using these tools; for example, whether an employee can use these tools for drafting documents and summarising information. To delineate accountability, organisations should also specify whether the AI policy applies to the entire organisation or only to specific divisions.

b)  Protection of Personal Data Privacy
The Guidelines recommend that organisations provide clear instructions on the “inputs” and “outputs” of Gen AI tools. Specifically, the permissible types and amounts of information that can be inputted into Gen AI tools should be stated, and the permissible purposes for using AI-generated outputs, the permissible means of storage of such information, and the applicable data retention policy and other relevant policies with which employees must comply should be set out.

c)  Lawful and Ethical Use and Prevention of Bias
An organisation’s AI policy should specify that employees must not use Gen AI tools for unlawful or harmful activities, and that employees are responsible for verifying the accuracy of AI-generated outputs and for correcting and reporting biased or discriminatory outputs. Organisations should also provide instructions on when and how to watermark or label AI-generated outputs.

d)  Data Security
To safeguard data security, the Guidelines recommend that an organisation’s AI policy should specify which categories of employees are permitted to use Gen AI tools and the types of devices on which their use is permitted. Employees should use robust user credentials and maintain stringent security settings in these tools. They should also be required to report AI incidents in accordance with the organisation’s AI incident response plan.

e)  Violations of AI Policy
Lastly, organisations should specify the possible consequences of violations of the AI policy by employees. For recommendations on establishing a proper Gen AI governance structure and other relevant considerations, organisations can refer to the PCPD’s “Artificial Intelligence: Model Personal Data Protection Framework”.

Practical Tips

In addition, the Guidelines provide practical tips on supporting employees in using Gen AI tools, including (a) enhancing transparency by regularly informing employees of the AI policy and any updates, (b) providing training and resources, (c) assisting employees with a designated support team, and (d) establishing a feedback mechanism for identifying areas for improvement.

Act Now

As digital technology continues to develop at a breakneck speed, imposing a blanket ban on AI tools is obviously not the optimal solution to the challenges that they bring. Organisations are encouraged to devise an internal AI policy or guideline to provide clear guidance to employees on the use of Gen AI at work. Having a clear AI policy or guideline can help to build trust and understanding between an organisation and its employees over the use of AI, thereby creating a win-win situation that is conducive to the success of the organisation.

E-mail*
Set Your Password*
Confirm Your Password*
** Your password must be minimum of 8 characters in length and use at least three of the following: uppercase letters, lowercase letters, numbers, and symbols.** eg. A12345^ /// Ab1234
  • I understand and agree that the personal data provided above will be used by the Institute for direct marketing activities and notification according Privacy Policy until further notice.
  • Your registered email address will serve as your login ID.
?
Join as member
to enjoy exclusive discount

條款和條件

  1. 會籍有效期由4月1日至3月31日(會員可選擇一年或兩年,而「專業途徑為基礎」的資深會員、專業會員、副會員需符合 持續專業發展(CPD)的要求。)
  2. 本會可隨時調整入會費及會員年費,而無需事先通知。
  3. 本會每年3月以郵寄及電郵形式通知會員續會,會員收到發票後,可按照付款方式繳交續會年費。於早鳥優惠期間成功繳交續會年費可享早鳥優惠價,及本年度續會之會員可獲得相應金額的電子代用券。
  4. 升級之會籍有效期由4月1日至3月31日,並按照會員所選之續會年期計算 (一年或兩年)。
  5. 會員持有有效的會籍及符合會籍升級之條件,可申請會籍升級。有關申請安排可與會員服務部聯絡。
  6. 年滿60歲且已退休的會員可電郵本會申報。會員年費可獲半價優惠。
  7. 會員可選擇重新續回自2010年4月1日新會籍制度後終止的會籍,並有機會:
    。 繳付復原費用及於會籍終止其間所欠交的會員年費;及
    。 提供有關會籍終止期間內已符合續專業發展 (CPD) 要求的紀錄(如適用)。
  8. 本會保留酌情處理的權利,並就每項申請擁有最終決定權。有關費用不可取消且不可退還。

 

如果您對會籍有任何疑問,歡迎致電會員服務部 (2837 3814 / 2837 3813) 
發送電子郵件至  membership@hkihrm.org

世界大型企業聯合會(TCB)亞洲理事會會籍

會員專享優惠 –世界大型企業聯合會(TCB)亞洲理事會會籍

作為香港人力資源管理學會(HKIHRM)的資深會員或專業會員,您可享高達20%的折扣,加入世界大型企業聯合會(TCB)的亞洲理事會會籍,獲取前瞻性見解。

世界大型企業聯合會(TCB)亞洲理事會會籍為您提供同行網絡、思想領導力資源以及專家支援,協助您應對工作挑戰,提升團隊及組織績效。透過匯聚全球領先企業的高級管理人員,理事會將引領您參與深度且以解決方案為導向的對話。

亞洲理事會會籍包括:

  • 每年兩至三次的實體會議
  • 專屬理事會網站
  • 理事會基準調查及專屬團隊支援

申請資格:

  • 有效的學會資深會員或專業會員會籍
  • 以個人名義申請
  • 申請需經TCB審核及批准

首年會籍折扣優惠

  • 1年會籍: 美金 9,000 (美金 7,200)

申請及查詢:
Brendan Moran先生
電郵:Brendan.moran@conference-board.org;電話:+65 6645 4696

與海外會籍及資格相互認可之安排

香港人力資源管理學會(HKIHRM)與加拿大卑詩省的The Chartered Professionals in Human Resources of British Columbia and YukonCPHR BC & Yukon)已達成專業會員會籍相互承認的安排

學會的資深會員F.I.H.R.M.(HK) 及專業會員M.I.H.R.M.(HK)均可成為加拿大CPHR BC & Yukon’s Chartered Professional in Human Resources Designation (CPHRTM) 的專業會員。此共識是基於雙方有關會籍之專業性及認受性達致相同水平而作出的互相承認。

  • 如欲成為香港人力資源管理學會之專業會員M.I.H.R.M.(HK),請按此了解更多;申請表格請按此(只有英文版本)。
  • 如欲成為加拿大CPHR BC & Yukon之CPHRTM專業會員,請 按此了解更多;申請表格請按此(只有英文版本)。

查詢:

香港人力資源管理學會:+(852) 2837 3814,membership@hkihrm.org 

CPHR BC & Yukon:請將您的申請直接電郵至  cphr@cphrbc.cahttps://cphrbc.ca/cphr/i-am-a-cphr/cphr-mutual-recognition/

    Pesonal Information

    Training Information

    Need assistance? Interested in joining us? Or just have a question?

    We’re here to help! Reach out via message, and our team will respond as quickly as possible.

        Asia Council Membership

        HKIHRM Members’ Privilege – Asia Council Membership of The Conference Board (TCB)

        As a HKIHRM Fellow and Professional Member, you are entitled to a 20% discount for joining the Asia Council Membership of TCB, an international think tank that delivers trusted insights for what’s ahead.

        TCB of Asia Council package offers a peer network, a portfolio of thought leadership, and access to experts to help address your job challenges and strengthen your team and organisation’s performance. By bringing together select senior executives from the world’s leading companies, the Council engages you in an immersive, solutions-focused conversation.

        The Asia Council Membership includes:

        • Two to three in-person meetings a year
        • Private Council website
        • Council bench-marking surveys and dedicated support from your Council team

        Eligibility:

        • Active HKIHRM Fellow and Professional Members
        • Individual basis
        • The application is subject to TCB’s vetting and approval

        Discounted Offer (1st year of membership only)

        • Year 1: USD 9,000 (USD 7,200)

        Application & Enquiry:
        Mr Brendan Moran
        Email: Brendan.moran@conference-board.org Tel: +65 6645 4696

        Reciprocal Membership

        Mutual Recognition of Professional Membership between HKIHRM and Canada-based CPHR British Colombia & Yukon

        HKIHRM has established mutual recognition of Professional Membership with the Chartered Professionals in Human Resources of British Columbia and Yukon CPHR British Colombia & Yukon since 2015. This understanding is based on a recognition of ‘substantial equivalency’ of the F.I.H.R.M.(HK) or M.I.H.R.M.(HK) designation to those of the CPHRTM designation, a CPHR British Colombia & Yukon’s Chartered Professional in Human Resources designation. HKIHRM Fellow Members and Professional Members are eligible to obtain the CPHRTM designation from CPHR British Colombia & Yukon.

        • To become a Professional Member M.I.H.R.M.(HK) of HKIHRM, please click HERE  for more information. Application form can be downloaded HERE .
        • To become a CPHRTM member of CPHR British Colombia & Yukon, please click HERE for more information. Application form can be downloaded HERE.

        Enquiry:

        HKIHRM: +(852) 2837 3814, membership@hkihrm.org 

        CPHR British Colombia & Yukon: Please send your application directly to cphr@cphrbc.ca, https://cphrbc.ca/cphr/i-am-a-cphr/cphr-mutual-recognition/

        Terms and Conditions

        1. Membership fee is charged for members joining between 1 April and 31 March for one-year or two-year subscription. (and subject to meeting mandatory CPD requirement for Professional-route-based Membership  only for renewed Fellow, Professional and Associate Members)
        2. Entrance and annual subscription fees are subject to review by the Institute without prior notice.
        3. HKIHRM will notify members to renew their membership via mail and email every year in March. Members can settle renewal fee by different payment methods marked in the invoice and enjoy the discount rate if the renewal fee is settled before the early bird period. E-vouchers will be provided if the renewal fee is settled.
        4. The upgraded membership fee is charged for members joining between 1 April and 31 March for one year or two years subscription (Same as selected membership renewal period).
        5. Member must have a valid membership and meet the upgrade requirements in order to apply for a membership upgrade. For assistance with the application process, please contact Member Services Team.
        6. Those aged 60 or above AND on permanent retirement may notify HKIHRM by email to enjoy 50% discount on the individual membership fee.
        7. Members can apply for membership reinstatement after their membership has been suspended since the introduction of new membership scheme on 1 April 2010 by:
          • paying a reinstatement fee (all the outstanding annual membership fee since his / her suspension); and
          • providing CPD records for the year(s) showing you have met the CPD requirement since you have ceased to be a member (if applicable)
        8. HKIHRM shall has absolute discretion in respect of each application to decide conclusively whether he / she has fulfilled the conditions applicable to his / her case or not. The decision of the HKIHRM is final and shall not be subject to any appeal. Membership fee is non-cancellable and non-refundable.


        If you have any enquiry on membership, please contact
        Member Services Team (2837 3814 / 2837 3813) or email at membership@hkihrm.org.