Office of the Privacy Commissioner for Personal Data

08/25/2026 | Press release | Distributed by Public on 08/25/2026 01:22

Privacy Commissioner’s Office (1) Follows up on Three Cases Involving Misuse of Employers’ Personal Data by Foreign Domestic Helpers for Loan Applications and (2) Publishes[...]

Date: 25 August 2026

Privacy Commissioner's Office (1) Follows up on
Three Cases Involving Misuse of Employers' Personal Data by Foreign Domestic Helpers for Loan Applications and
(2) Publishes Guidance on "Protecting Personal Data Privacy in the Use of Agentic AI"

The Office of the Privacy Commissioner for Personal Data (PCPD) today announced its follow-up actions on three complaint cases involving foreign domestic helpers (FDHs) who provided their employers' personal data to financial institutions for loan applications without the employers' knowledge or consent. In all three cases, the FDHs concerned contravened the relevant requirements of the Personal Data (Privacy) Ordinance (PDPO) by improperly using their employers' personal data. Furthermore, the PCPD today published the guidance on "Protecting Personal Data Privacy in the Use of Agentic AI".

1. Summary of the three cases (see Annex 1 for details)

All three complainants were employers of the FDHs concerned. The FDHs concerned applied for loans from financial institutions in the course of their employment. Subsequently, they defaulted on the repayments of their loans and were eventually dismissed by the complainants. In two of the cases, the complainants received WhatsApp messages and telephone calls from financial institutions regarding the FDHs' outstanding debts. In addition to requesting the complainants to remind the FDHs to repay the loans, one financial institution further stated that debt collector would be sent to the complainant's residence if repayments were not made by the specified deadline. In the third case, the complainant received, through the mailbox, overdue notices issued by two financial institutions to the FDH.

The three FDHs concerned admitted that they had provided the complainants' personal data to local or overseas financial institutions when applying for loans, with one FDH submitting loan applications to as many as four financial institutions. The employers' personal data involved included the employers' names, residential addresses and telephone numbers.

Data Protection Principle (DPP) 3(1) of Schedule 1 to the PDPO stipulates that personal data shall not, without the prescribed consent of the data subject (namely, express consent voluntarily given by the data subject), be used (including disclosed or transferred) for a new purpose that is not related to the original purpose for which the data was collected.

In the above cases, having considered the circumstances of each case and the information obtained, the Privacy Commissioner for Personal Data (Privacy Commissioner), Ms Ada CHUNG Lai-ling, found that the FDHs concerned had contravened DPP 3(1) of the PDPO concerning the use (including disclosure) of personal data. The Privacy Commissioner had issued warning letters to the FDHs concerned and requested them to strictly comply with the requirements of the PDPO relating to the use of personal data in the future.

The Privacy Commissioner, Ms Ada CHUNG Lai-ling, reminds FDHs and financial institutions of their responsibilities to safeguard employers' personal data privacy. She said, "FDHs play an important role in sharing household duties and alleviating the caregiving burden of employers. Many employers also fully recognise FDHs' contributions to their households. However, if FDHs use their employers' personal data to apply for loans without the employers' knowledge or consent, unnecessary distress may be caused to the employers. FDHs must comply with the relevant requirements of the PDPO when using their employers' personal data. Meanwhile, financial institutions should remain vigilant and avoid the improper use of employers' personal data for the purpose of loan applications."

The PCPD points out that if FDHs are requested to provide the personal data of their employers or any other third parties during a loan application, FDHs should first ascertain whether the relevant information is necessary and not excessive. FDHs must obtain the employers' voluntary and express prior consent if they intend to use the employers' personal data for loan applications or for any purposes unrelated to employment affairs. FDHs should not provide employers' personal data to financial institutions indiscriminately for the purpose of obtaining loans.

The PCPD also takes the opportunity to remind employers of FDHs to:
  • Clearly inform their FDHs that the employers' personal data may only be used for purposes related to employment affairs and that FDHs should obtain the employers' prior consent before using their personal data for any other purpose; and
  • Exercise caution when handling documents submitted by FDHs for the employers' signatures. Before signing any document, employers should not only ascertain from the FDHs the purpose of signing the document, but also carefully review its contents in order to safeguard personal data privacy and their own interests.

In addition, the PCPD has prepared a pamphlet specifically for FDHs in Chinese, English, Tagalog and Bahasa Indonesia, with a view to reminding FDHs to exercise caution before using their employers' personal data, and to safeguard the personal data privacy of themselves and their employers.

Download the pamphlet titled "Protect Personal Data Privacy: Obtain Employers' Consent Before You Use their Personal Data":
https://www.pcpd.org.hk/english/resources_centre/publications/files/pcpd_obtain_empolyers_consent.pdf

2. Guidance on "Protecting Personal Data Privacy in the Use of Agentic AI"

With the increasing prevalence of the deployment of artificial intelligence (AI), the emergence of agentic AI has brought transformative changes while posing unprecedented challenges to the protection of personal data privacy. The PCPD today published a guidance titled "Protecting Personal Data Privacy in the Use of Agentic AI" (Guidance), which aims to provide practical recommendations to organisations to assist them in harnessing the benefits of agentic AI while safeguarding personal data privacy and complying with the relevant requirements of the PDPO. The Guidance is supported by the Digital Policy Office and the Hong Kong Applied Science and Technology Research Institute as supporting organisations.

The Privacy Commissioner, Ms Ada CHUNG Lai-ling, said, "Unlike conventional AI chatbots, agentic AI can operate with a high degree of autonomy and execute multi-step tasks on behalf of users, from managing emails and making reservations to processing payments. The National 15th Five-Year Plan stresses the important principle of following a holistic approach to development and security. It is essential that innovation be accompanied by robust personal data privacy safeguards. The PCPD has published the Guidance with a view to implementing the Government's 'AI+' policy direction, promoting the safe, lawful and responsible adoption of agentic AI and empowering the community to embrace this transformative technology with confidence and trust."

To align with international standards, in preparing the guidance the PCPD made reference to the "Practical Guidance of Cybersecurity Standards - Security Guidelines for the Deployment and Use of AI Agents" published in July 2026 by the National Technical Committee 260 on Cybersecurity of Standardization Administration of China, along with guidances on the use of agentic AI published in other jurisdictions. The Guidance serves as a supplementary guidance to the "Artificial Intelligence: Model Personal Data Protection Framework" published by the PCPD, which remains generally applicable to the use of agentic AI.

The Guidance explains the risks that agentic AI poses to personal data privacy, including extensive access, function creep and inaccuracy of data (please see Annex 2 for details), and sets out nine recommendations for the safe and responsible use of agentic AI and ensuring compliance with the relevant requirements under the PDPO:

How to Address the Risks that Agentic AI Poses to Personal Data Privacy
  1. Avoid excessive or arbitrary collection of personal data for use by agentic AI: Adhere to the data minimisation principle, establish and implement clear rules on ringfencing the information and systems an agentic AI may access for a specific purpose;
  2. Be transparent about the use of agentic AI in processing personal data: Provide relevant information on the use of agentic AI to process personal data in the Personal Information Collection Statements and Privacy Policy Statements to enhance transparency;
  3. Ensure accuracy of personal data processed by agentic AI: Adopt approaches such as chain of thought, context specific fine-tuning and human review to reduce the risk of generating outputs which contain hallucinated or inaccurate personal data;
  4. Set appropriate retention periods: Prescribe maximum retention periods and implement measures to erase personal data contained in conversation histories, cache data or long-term memory timely;
  5. Ensure personal data is not used for a new purpose without consent: Delineate the purposes for which personal data will be collected and processed by agentic AI, and specify the circumstances under which human oversight is required;
  6. Safeguard the security of personal data in agentic AI systems: Use the latest official versions of agentic AI, adopt adequate measures to ensure system security and data security, install and use plugins or skills with caution, grant the minimum access rights necessary to complete the tasks at hand, adopt large language model guardrails, and establish mechanisms to enable traceability and auditability;
  7. Uphold data access and correction rights: Select agentic AI systems that adopt the principles of "privacy-by-design" and "privacy-by-default" to ensure that the relevant system supports the exercise of data access and data correction rights;
  8. Conduct continuous risk assessments: Test agentic AI for safety and reliability before using agentic AI, continuously assess the personal data privacy risks during its use and adopt measures that commensurate with the risks, adopt a "human-in-the-loop" approach for decisions likely to have a significant impact on individuals; and
  9. Assign clear responsibilities and provide training: Establish an internal governance structure with sufficient resources, expertise and decision-making authority, adopt contractual or other means to ensure compliance of data retention and security requirements when engaging external service providers, and provide adequate training to all relevant personnel.

To facilitate the implementation of the recommendations, the Guidance also includes a Security Checklist in the Annex, which sets out the practical steps that users may take to safeguard personal data privacy throughout the stages of evaluation, preparation, deployment, use and cessation of use.

Download the guidance titled "Protecting Personal Data Privacy in the Use of Agentic AI":
https://www.pcpd.org.hk/english/resources_centre/publications/files/pcpd_use_of_agentic_ai.pdf

The Privacy Commissioner, Ms Ada CHUNG Lai-ling (right) and the Assistant Privacy Commissioner (Legal), Ms Fiona LAI Ho-yan (left), elaborated on three cases involving misuse of employers' personal data by FDHs for loan applications and the Guidance on "Protecting Personal Data Privacy in the Use of Agentic AI".

The Privacy Commissioner, Ms Ada CHUNG Lai-ling, explained the details of the three cases.

The Privacy Commissioner, Ms Ada CHUNG Lai-ling, reminded organisations to use agentic AI carefully and responsibly, while safeguarding personal data privacy.

The Assistant Privacy Commissioner (Legal), Ms Fiona LAI Ho-yan, explained the recommendations set out in the Guidance on "Protecting Personal Data Privacy in the Use of Agentic AI".
End

Annex 1
Summary of Three Cases Involving Improper Use of Employers' Personal Data by Foreign Domestic Helpers

Case (1)

The complainant received a WhatsApp message from an unknown source, and noted that the message related to the FDH employed by her. The complainant subsequently made enquiries with the FDH, who admitted that she had applied for a loan from a financial institution in the Philippines but was unable to repay the loan because of the high interest charged. The FDH also admitted that she had provided the complainant's telephone number to the financial institution as proof of her employment as a FDH in Hong Kong.

Subsequently, the complainant received another WhatsApp message from the financial institution, indicating that the FDH had used the complainant's residential address for the loan application. The financial institution not only requested the complainant to remind the FDH to settle the outstanding debt, but also stated that debt collectors would be sent to the complainant's residence if repayment was not made by the specified deadline. The FDH concerned was eventually dismissed by the complainant.

Case (2)

The complainant received several overdue payment notices addressed to his FDH from two financial institutions through the mailbox of his residence. The complainant subsequently discovered that the FDH had applied for loans from those financial institutions during her employment.

Upon enquiries by the complainant, the FDH concerned admitted that she had provided the employment contract containing the complainant's name and residential address to the financial institutions for the purpose of her loan applications without obtaining the complainant's consent. The complainant subsequently dismissed the FDH concerned.

Case (3)

During her employment, the complainant's FDH applied for loans from four financial institutions. Following her default on loan repayments, one of the financial institutions telephoned the complainant four times and sent her WhatsApp messages within the same day, requesting the complainant to remind the FDH to settle the outstanding debt.

The complainant subsequently questioned the FDH and discovered that the FDH had applied for loans from four financial institutions. The FDH also admitted that, in the course of applying for loans, she had provided complainant's personal data, including the complainant's telephone number and residential address, to a number of financial institutions. The complainant believed that her name was also included in the information disclosed. The complainant dismissed the FDH after learning the incident.

Outcome of Cases (1), (2) and (3)

The Privacy Commissioner, Ms Ada CHUNG Lai-ling, considered that the names, residential addresses and telephone numbers of the employers were originally obtained by the concerned FDHs solely for the purpose of establishing employment relationship and handling employment-related affairs with the employers. However, the concerned FDHs subsequently provided the employers' personal data to financial institutions for applying for loans, which went beyond the original purpose for which the data was collected (namely, the handling of employment-related matters). As such use was neither the original purpose nor a directly related purpose of data collection, the relevant disclosure constituted the use of the data for a new purpose. Given that the FDHs concerned did not obtain the complainants' express consent voluntarily given for such use, they had contravened the requirements of DPP 3(1) as regards the use (including disclosure) of personal data. As a result, the Privacy Commissioner issued warning letters to the FDHs concerned, requiring them to strictly comply with the requirements of the PDPO as regards the use of personal data in the future.

Annex 2
Risks that Agentic AI Poses to Personal Data Privacy
  1. Extensive access: Agentic AI typically operates with higher default access rights. Without stringent access restrictions, agentic AI may access a vast amount of personal data, thereby increasing the risks of unauthorised access, reproduction of personal data by third parties, or accidental erasure where the agentic AI misinterprets user command;
  2. System vulnerabilities: Agentic AI may be granted a high level of access to multiple systems and data sources. Vulnerabilities in its system design or safety controls could pose significant risks to the security of personal data;
  3. Vulnerable plugins or skills: Plugins or skills that have not undergone a rigorous security review may contain malicious code and hackers may exploit such vulnerabilities to gain unauthorised access and seize control of user's accounts or the entire computer systems, leading to the leakage of personal data;
  4. Function creep: Data may be used for purposes beyond the original purpose for which the data was collected or a directly related purpose, as agentic AI often aggregates and recombines personal data from multiple sources and some agentic AI systems may use the data to train large language model; and
  5. Multi-agent risks: The use of multi-agent systems may amplify security risks and cause inaccurate personal data to be cascaded across AI agents through their interactions, which may lead to unfair or harmful outcomes for the data subjects.
Office of the Privacy Commissioner for Personal Data published this content on August 25, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 25, 2026 at 07:22 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]