Skip to Content
OPINION

Notes from the Asia-Pacific region: AI, privacy and cyber enforcement in Greater China, Hong Kong

Recent developments in Greater China signal an active AI governance landscape.

Published
Subscribe to IAPP newsletters

Contributors:

Barbara Li

CIPP/E

Partner

Reed Smith

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains. 

The past several weeks in Greater China have been packed, with significant artificial intelligence and data rules and guidelines released and adopted in both mainland China and Hong Kong.

On 9 Sept., China's highest court — the Supreme People's Court — released the landmark opinions providing guidance to Chinese courts at all levels on handling AI-related cases. The opinions address a wide range of AI issues, including deepfakes, hallucination liability, algorithmic discrimination, autonomous driving, IP protection, training-data disputes, open-source software obligations and AI-fabricated evidence.

On 14 Sept., the National Technical Committee 260 on Cybersecurity of the Standardization Administration of China issued Version 3.0 of its AI Security Governance Framework, providing important updates to Versions 1.0 and 2.0. This round expressly addresses AI agents and physically interactive AI systems for the first time, spells out life cycle governance responsibilities for developers, service providers and deployers, and neatly groups risks into endogenous model risks, such as bias, hallucination and data poisoning, and exogenous misuse risks like deepfakes or cyberattacks, and broader societal risks.

In Hong Kong, the Office of the Privacy Commissioner for Personal Data published Protecting Personal Data Privacy in the use of Agentic AI 25 Aug. This is the first guidance from the PCPD specifically addressing the privacy risks of autonomous AI systems. It sets out nine data protection recommendations and a life cycle security checklist, signaling heightened regulatory expectations for organizations deploying agentic AI. Given the increasingly close AI collaborations between mainland China and Hong Kong, businesses with cross-boundary operations should be mindful of the differing compliance requirements in each jurisdiction and consider adopting a dual-compliance approach.

On the enforcement front, regulators on both sides remain very active.

On 20 Aug., the PCPD released the results of its investigation into the Canvas data breach. The hacking group ShinyHunters exploited cross-site scripting vulnerabilities in the Canvas learning platform and compromised the personal data of over 153,000 students and staff at some universities. The PCPD found no Personal Data (Privacy) Ordinance contravention because the institutions had done their homework: pre-deployment security assessments, contractual security requirements and ongoing monitoring were all in place. 

It nevertheless recommended tightening vendor monitoring, minimizing stored data, enabling multifactor authentication and setting clear retention periods. For business organizations, this is a valuable case study in what "good" third-party governance looks like when a breach hits.

On 15 Sept., the Cyberspace Administration of China published 10 cases in one go, spanning AI, cross-border data, biometrics and cybersecurity. Among the notable cases: a Shanghai tech company was hit for excessive collection and transfer of personal information overseas without the required security assessment; a real-estate company got caught collecting over 5,000 pieces of facial-recognition data without proper notice or separate consent from the data subjects; and an app was found to have pushed users to grant consent to the collection of personal information beyond what was necessary. One AI mini-program was ordered offline for failing to apply both visible and metadata-based AI-generated content labels and for skipping its security assessment and an operator running an API relay to offer access to multiple large language models was sanctioned for the same failures.

This guidance from the regulators is particularly helpful as a reference for businesses seeking to achieve better compliance and manage risks.

This article originally appeared in the Asia-Pacific Dashboard Digest, a free weekly IAPP newsletter. Subscriptions to this and other IAPP newsletters can be found here
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Barbara Li

CIPP/E

Partner

Reed Smith

Tags:

AI and machine learningAI governancePrivacy

Related Stories