[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$faOFIBoTYmDK_HfClinX39uJNY1someCCZ2cV0_gEaWw":3,"$fm6Ky0r9HHO8PTXKBgXJeU4fCLm4z6RKRMXFRXG3f560":30},{"success":4,"data":5},true,{"id":6,"slug":7,"title":8,"excerpt":9,"content":10,"category":11,"tags":12,"author":20,"cover_image_url":21,"reading_time_minutes":22,"is_published":4,"published_at":23,"created_at":24,"updated_at":25,"author_avatar":21,"is_featured":26,"meta_title":27,"meta_description":28,"meta_keywords":29},"380f0e8c-c2c8-42c2-af32-bcee561e897a","hk-pcpd-model-ai-framework-hiring","Voluntary on Paper, Benchmark in Practice: What the PCPD's Model AI Framework Means for Hiring in Hong Kong","Hong Kong has no AI statute, but the PDPO binds every employer touching candidate data — and the PCPD's Model AI Framework names the assessment of job applicants as a higher-risk AI use. What the Framework says, how it maps onto a recruitment workflow, and what three annual rounds of published compliance checks signal.","\u003Cp>The EU AI Act gets the headlines. But if you run talent acquisition for a Hong Kong employer, the instrument that already applies to your AI hiring stack is closer to home: the Personal Data (Privacy) Ordinance (PDPO), read through the lens of the Privacy Commissioner's \u003Cem>Artificial Intelligence: Model Personal Data Protection Framework\u003C\u002Fem>. The Framework is voluntary. The PDPO is not. And as of this year, the regulator is no longer just publishing guidance — it is checking. In May 2026, the Office of the Privacy Commissioner for Personal Data (PCPD) announced it had completed its third round of AI compliance checks, this time across 60 organisations.\u003C\u002Fp>\n\n\u003Cp>This piece walks through what the Framework says, why hiring is singled out as a higher-risk use of AI, how it maps onto a recruitment workflow, and what the compliance-check programme signals — keeping three things clearly separated throughout: \u003Cstrong>what the PDPO legally requires\u003C\u002Fstrong>, \u003Cstrong>what the Framework recommends\u003C\u002Fstrong>, and \u003Cstrong>our own reading\u003C\u002Fstrong>.\u003C\u002Fp>\n\n\u003Ch2>The legal baseline: the PDPO and its six Data Protection Principles\u003C\u002Fh2>\n\n\u003Cp>Start with what is binding. The PDPO's Schedule 1 sets out \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fdata_privacy_law\u002F6_data_protection_principles\u002Fprinciples.html\" rel=\"noopener\">six Data Protection Principles (DPPs)\u003C\u002Fa> that apply to any \"data user\" — including any employer collecting candidate data:\u003C\u002Fp>\n\n\u003Cul>\n\u003Cli>\u003Cstrong>DPP1 (Collection):\u003C\u002Fstrong> personal data must be collected lawfully and fairly, for a purpose related to the data user's functions, and the amount collected must be adequate but not excessive.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DPP2 (Accuracy and retention):\u003C\u002Fstrong> data must be accurate and not kept longer than necessary.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DPP3 (Use):\u003C\u002Fstrong> personal data must not be used for a new purpose without the data subject's prescribed consent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DPP4 (Security):\u003C\u002Fstrong> all practicable steps must be taken to protect personal data against unauthorised or accidental access, processing, erasure, loss or use.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DPP5 (Openness):\u003C\u002Fstrong> data users must be transparent about their personal-data policies and practices.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>DPP6 (Access and correction):\u003C\u002Fstrong> individuals have the right to access and correct their personal data.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Cp>None of this is AI-specific, and that is the point. A CV, an interview recording, a psychometric score and an AI-generated candidate ranking are all personal data. Feeding candidate data into an AI screening tool does not create a new legal regime — it creates new ways to breach the existing one. \u003Cem>The PDPO is the binding floor; everything below is elaboration on it.\u003C\u002Fem>\u003C\u002Fp>\n\n\u003Ch2>The Model Framework: what it actually says\u003C\u002Fh2>\n\n\u003Cp>On \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fnews_events\u002Fmedia_statements\u002Fpress_20240611.html\" rel=\"noopener\">11 June 2024, the PCPD published the \u003Cem>Artificial Intelligence: Model Personal Data Protection Framework\u003C\u002Fem>\u003C\u002Fa>, a set of recommendations and best practices for organisations that \u003Cstrong>procure, implement and use\u003C\u002Fstrong> AI systems — deliberately aimed at AI \u003Cem>buyers\u003C\u002Fem>, not just developers, which describes most HR teams. The PCPD positioned it as the first framework of its kind in the Asia-Pacific region.\u003C\u002Fp>\n\n\u003Cp>To be clear about status: the Framework is \u003Cstrong>voluntary guidance\u003C\u002Fstrong>, and nothing in it is directly enforceable. But it is explicitly built to help organisations comply with the PDPO — and, in our reading, if the PCPD ever examines your AI-assisted hiring under the DPPs, the Framework is the most detailed public statement of what \"all practicable steps\" and \"adequate but not excessive\" look like in an AI context. Voluntary on paper; benchmark in practice.\u003C\u002Fp>\n\n\u003Cp>The \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fresources_centre\u002Fpublications\u002Ffiles\u002Fai_protection_framework.pdf\" rel=\"noopener\">Framework itself\u003C\u002Fa> is organised around four parts:\u003C\u002Fp>\n\n\u003Col>\n\u003Cli>\u003Cstrong>AI strategy and governance\u003C\u002Fstrong> — an internal AI strategy, an AI governance committee, procurement diligence on AI suppliers, and employee training.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Risk assessment and human oversight\u003C\u002Fstrong> — a documented, cross-functional risk assessment for each AI system, with the level of human oversight calibrated to the level of risk.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customisation of AI models and implementation and management of AI systems\u003C\u002Fstrong> — data preparation and minimisation, validation and testing before deployment, security measures, continuous monitoring, periodic internal audits, and an AI incident response plan.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Communication and engagement with stakeholders\u003C\u002Fstrong> — transparency towards candidates, staff, suppliers and regulators; handling data access and correction requests; feedback and explanation channels.\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Ch2>Hiring is named as a higher-risk use case — in the document itself\u003C\u002Fh2>\n\n\u003Cp>Here is the part every talent-acquisition lead should read personally. In its section on risk-based human oversight, the Framework lists example use cases that \"may incur higher risk\". One of them, verbatim from Figure 12: \u003Cstrong>\"Assessment of job applicants, evaluation of job performance or termination of employment contracts.\"\u003C\u002Fstrong> The accompanying text is even more direct: an AI system producing an output \"such as the assessment of job applicants\" that has a high likelihood of causing severe and long-lasting harm to individuals, where the risks cannot be adequately mitigated, \"should be considered high risk\".\u003C\u002Fp>\n\n\u003Cp>Why does that classification matter? Because the Framework ties the risk level to the required level of human oversight, in three tiers:\u003C\u002Fp>\n\n\u003Cul>\n\u003Cli>\u003Cstrong>Human-in-the-loop\u003C\u002Fstrong> — humans retain control of the decision-making process. Recommended for \u003Cstrong>high-risk\u003C\u002Fstrong> systems.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Human-in-command\u003C\u002Fstrong> — humans oversee the AI's operation and intervene when necessary; a middle option where full human-in-the-loop is not practicable but risks are non-negligible.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Human-out-of-the-loop\u003C\u002Fstrong> — full automation, reserved for systems with \u003Cstrong>minimal or low\u003C\u002Fstrong> risk.\u003C\u002Fli>\n\u003C\u002Ful>\n\n\u003Cp>Put those together and the message to employers is hard to miss: \u003Cem>AI can rank, score and summarise candidates, but a fully automated rejection — no human ever looking at the decision — sits well outside what the regulator considers appropriate for this risk class.\u003C\u002Fem> That sentence is our reading, not a quoted rule, but it is a short inferential step from text the PCPD itself wrote. Notably, the PCPD's \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fnews_events\u002Fmedia_statements\u002Fpress_20260519.html\" rel=\"noopener\">May 2026 compliance-check announcement\u003C\u002Fa> reported that 79% of organisations checked had adopted human-in-the-loop oversight and 21% human-in-command — none reported fully automated decision-making. The market has understood the signal.\u003C\u002Fp>\n\n\u003Ch2>Mapping the Framework onto a recruitment workflow\u003C\u002Fh2>\n\n\u003Cp>\u003Cstrong>CV screening and candidate ranking.\u003C\u002Fstrong> The Framework's risk-assessment factors track the DPPs directly: the \u003Cem>allowable uses\u003C\u002Fem> of the data (DPP3 — candidate data collected \"to assess your application\" cannot be quietly repurposed to train or customise a model without prescribed consent), the \u003Cem>volume\u003C\u002Fem> collected (DPP1 — adequate but not excessive; scraping a candidate's social footprint to \"enrich\" a profile invites exactly this question), the \u003Cem>sensitivity\u003C\u002Fem> of the data, and its \u003Cem>quality and accuracy\u003C\u002Fem> (DPP2 — a parsing error that garbles a CV is an accuracy problem with legal texture, not just a product bug). The Framework flags biometric data, health data, and data revealing protected characteristics as more sensitive; recruitment files routinely contain all three.\u003C\u002Fp>\n\n\u003Cp>\u003Cstrong>AI-conducted or AI-scored interviews.\u003C\u002Fstrong> Video and voice interviews collect biometric-adjacent data at scale, pushing both the sensitivity and volume factors upward in the Framework's risk calculus. Its transparency recommendations bite here too: organisations should \"clearly and prominently\" disclose the use of AI unless obvious in context, and explain the purposes, benefits, limitations and effects of the system. For decisions with significant impact, the Framework says organisations should provide channels to seek explanation and request human intervention, and should \"carefully consider\" offering an opt-out.\u003C\u002Fp>\n\n\u003Cp>\u003Cstrong>Candidate data lifecycle.\u003C\u002Fstrong> DPP1(3) and DPP5 obligations — telling data subjects the purpose of use and the classes of persons the data may be transferred to — mean a Personal Information Collection Statement written before AI entered the workflow probably no longer describes reality: if candidate data flows to an AI supplier, that is a class of transferee candidates should be told about. And DPP6 plus sections 18 and 22 of the PDPO give candidates statutory access and correction rights that do not evaporate because the data sits inside a vendor's pipeline; the Framework expects organisations to engage the supplier to fulfil such requests where necessary.\u003C\u002Fp>\n\n\u003Cp>\u003Cstrong>Recruiters using generative AI day to day.\u003C\u002Fstrong> In \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fnews_events\u002Fmedia_statements\u002Fpress_20250331.html\" rel=\"noopener\">March 2025 the PCPD added a \u003Cem>Checklist on Guidelines for the Use of Generative AI by Employees\u003C\u002Fem>\u003C\u002Fa>, guidance for internal policy on staff Gen AI use. For a TA team the live risk is mundane: a recruiter pasting a candidate's CV into a public chatbot to \"summarise this\". The Checklist recommends specifying permitted tools, what information may be entered, how outputs may be used, and how incidents get reported. An organisation without such a policy is now measured against published guidance rather than against nothing.\u003C\u002Fp>\n\n\u003Ch2>What the compliance-check round signals\u003C\u002Fh2>\n\n\u003Cp>On \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fnews_events\u002Fmedia_statements\u002Fpress_20260519.html\" rel=\"noopener\">19 May 2026, the PCPD announced\u003C\u002Fa> it had completed compliance checks — launched in January 2026 — on 60 organisations across sectors including banking, finance, education, government, insurance, medical services, retail, telecommunications and technology. Headline findings: 57 of the 60 (95%) used AI in day-to-day operations, up 15 percentage points from the previous round; 24 organisations (42% of the AI users) collected or processed personal data through AI; 92% had data-breach response plans but only 41% specifically addressed AI incidents; 63% conducted regular internal audits or independent assessments. The PCPD found \u003Cstrong>no contraventions of the PDPO\u003C\u002Fstrong> in this exercise, and issued fresh recommendations — including, for the first time in this series, cautions on agentic AI (minimum necessary access rights, care with plugins, continuous risk assessment).\u003C\u002Fp>\n\n\u003Cp>This is the third such round: the PCPD's \u003Ca href=\"https:\u002F\u002Fwww.pcpd.org.hk\u002Fenglish\u002Fartificial_intelligence\u002Findex.html\" rel=\"noopener\">AI Privacy Protection hub\u003C\u002Fa> records checks on 28 organisations in 2024 and 60 in 2025 before this year's 60. Our reading of the trajectory: publish the benchmark (2024), extend it to employee Gen AI use (2025), then check adoption annually in growing, broadening samples and publish the findings. \"No contraventions found\" is a snapshot of a cooperative exercise, not a ceiling on enforcement — and the things a compliance check asks about (governance structure, risk assessment, oversight level, incident plan) are drawn straight from the Framework's four parts. The voluntary document has become the checklist the regulator arrives with.\u003C\u002Fp>\n\n\u003Ch2>A short checklist for Hong Kong TA teams\u003C\u002Fh2>\n\n\u003Cp>A self-audit against the Framework's four parts — recommendations, not statutory obligations, except where a DPP is noted:\u003C\u002Fp>\n\n\u003Col>\n\u003Cli>\u003Cstrong>Inventory\u003C\u002Fstrong> every AI touchpoint in your funnel — sourcing, CV parsing, screening, ranking, interview scoring, chatbots — including ATS features switched on by default.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assign ownership\u003C\u002Fstrong>: a named person or committee accountable for AI in hiring (Part I).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Run and document a risk assessment\u003C\u002Fstrong> per tool: data volume, sensitivity, quality, security, candidate impact (Part II; DPP1\u002FDPP2\u002FDPP4 underneath).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Set the oversight level explicitly\u003C\u002Fstrong> — for candidate assessment, realistically a human decision-maker in the loop, demonstrably so (Part II).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update your Personal Information Collection Statement\u003C\u002Fstrong> so candidates are told data may be processed by AI and transferred to AI suppliers (DPP1(3)\u002FDPP5 — law, not guidance).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Test before and monitor after deployment\u003C\u002Fstrong>, with an AI incident-response plan connected to your data-breach plan (Part III).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Give candidates a channel\u003C\u002Fstrong> for explanation or human review, and be ready for access and correction requests reaching into AI-processed data (Part IV; DPP6\u002Fss. 18, 22 are law).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Adopt a staff Gen AI policy\u003C\u002Fstrong> covering permitted tools and what candidate data may never be pasted into them (March 2025 Checklist).\u003C\u002Fli>\n\u003C\u002Fol>\n\n\u003Ch2>The bottom line\u003C\u002Fh2>\n\n\u003Cp>Hong Kong has not enacted an AI statute, and the Model Framework binds no one. But the PDPO already binds everyone who touches candidate data, the Framework names the assessment of job applicants as a higher-risk AI use, and the regulator now checks organisations against it on an annual, published cycle. An employer waiting for hard AI law before establishing governance is measuring against the wrong clock.\u003C\u002Fp>\n\n\u003Cp>\u003Cem>This article is a general explainer published by a software vendor, not legal advice. The Framework's application to your organisation depends on facts we cannot know from here — instruct qualified Hong Kong counsel before relying on any reading above for your own compliance decisions.\u003C\u002Fem>\u003C\u002Fp>\n\n\u003Chr>\n\n\u003Cp>\u003Cstrong>How this was produced:\u003C\u002Fstrong> Drafted with AI writing tools by the NiceHire team. Every legal claim was verified against the linked primary sources — the PCPD's Model Framework document, its press releases of 11 June 2024, 31 March 2025 and 19 May 2026, the PCPD AI Privacy Protection page, and the PCPD's summary of the Data Protection Principles — all fetched and read on 24 July 2026; quotations are verbatim from the Framework. NiceHire publishes explainers like this because we build hiring software in Hong Kong and these are our rules too.\u003C\u002Fp>","Compliance",[13,14,15,16,17,18,19],"PCPD","PDPO","Hong Kong","AI hiring","compliance","Model AI Framework","data protection","NiceHire Team",null,10,"2026-07-24T01:37:25.988+00:00","2026-07-24T01:37:27.847527+00:00","2026-07-24T01:37:27.996127+00:00",false,"PCPD Model AI Framework: What It Means for Hiring in Hong Kong","The PCPD's Model AI Framework is voluntary — but it names job-applicant assessment as higher-risk AI use, and the regulator now runs annual published compliance checks. A primary-source explainer for Hong Kong TA teams, mapped to the PDPO's six DPPs.","PCPD Model AI Framework, PDPO AI hiring, Hong Kong AI compliance, AI recruitment Hong Kong, data protection principles hiring, PCPD compliance checks 2026",{"success":4,"data":31},{"posts":32,"count":49,"hasMore":26},[33,35],{"id":6,"slug":7,"title":8,"excerpt":9,"category":11,"tags":34,"author":20,"cover_image_url":21,"reading_time_minutes":22,"published_at":23},[13,14,15,16,17,18,19],{"id":36,"slug":37,"title":38,"excerpt":39,"category":11,"tags":40,"author":20,"cover_image_url":21,"reading_time_minutes":47,"published_at":48},"8be0cb6b-6afa-43fa-9798-52127f706332","eu-ai-act-article-50-explainer","The EU AI Act Delay Did Not Cover AI Interviews. Article 50 Applies on 2 August 2026.","The Digital Omnibus pushed the AI Act's high-risk hiring obligations to December 2027 — but the Article 50 duty to tell a candidate they are talking to a machine still applies from 2 August 2026. What moved, what didn't, who carries the obligation, and where NiceHire's own code stood when we checked.",[41,42,43,17,44,45,46],"EU AI Act","Article 50","AI interviews","transparency","Digital Omnibus","hiring",11,"2026-07-24T01:15:53.793+00:00",2]