The Honest Part
Is ChatGPT safe for work data: the Hong Kong answer.
The question people want to ask in a meeting and never quite do is this: is ChatGPT safe for work data, or am I one careless paste away from a problem? It is not a paranoid question. It is the single biggest reason I see capable, senior people quietly avoid a tool that would save them hours.
I am not a lawyer and this is not legal advice. It is a practical walk through what Hong Kong's own regulator has published, in plain language. That gap between "nobody explained the rules" and "here are the rules" is where most of the anxiety about AI at work actually lives, not in the technology.
What Hong Kong's regulator has actually published
The PCPD has not stayed quiet on this. On 11 June 2024 it adopted the Artificial Intelligence: Model Personal Data Protection Framework, aimed at organisations procuring or building AI systems. On 31 March 2025 it followed with something more useful for an individual desk: the Checklist on Guidelines for the Use of Generative AI by Employees.
The Checklist is refreshingly concrete. Define which tools and purposes are permitted. Specify exactly what data may be typed in, and how outputs get stored or reused. Require staff to fact-check what generative AI hands back. Restrict use to authorised staff on approved devices. Define what happens when someone breaches the policy. And train people, rather than emailing round a PDF nobody reads.
If your firm has not done this, that gap is not a technicality. It is the policy vacuum you are operating inside every time you paste something in. A generic "be careful with AI" email is not a policy: no permitted tools, no permitted data, no named consequence for getting it wrong.
Is ChatGPT safe for work data? What the six DPPs say
Underneath both documents sit Hong Kong's six Data Protection Principles, and they map onto a prompt box more directly than people expect.
- DPP1 — collect fairly, for a related purpose, and not excessively. Pasting a client's full file when you needed one field is already a problem before you have hit enter.
- DPP2 — accurate, kept no longer than necessary. A chat log sitting in a consumer account indefinitely is the opposite of that.
- DPP3 — no new purpose without consent, which matters once the output gets reused somewhere the data subject never agreed to.
- DPP4 — adequate security safeguards, which a free consumer tier was never built to promise you.
- DPP5 — transparent handling policies. Read the tool's actual terms, not its marketing page.
- DPP6 — rights of access and correction, which get awkward fast once someone's personal data sits inside a third-party vendor's systems.
None of the six is complicated. Together they are a fairly complete checklist for whether a specific paste, right now, is fine. An associate pasting a redacted deal summary into a properly contracted enterprise tier is behaving very differently, in DPP terms, from one pasting the same summary complete with counterparty names into a free account, even though both typed roughly the same three paragraphs.
The cross-border question everyone gets wrong
People sometimes reach for section 33 of the PDPO, the cross-border transfer restriction, as if it settles the question of sending data to an overseas server. It does not. Section 33 was enacted in 1995 and has never been brought into force, with no commencement timetable announced since. The PCPD separately published Recommended Model Contractual Clauses in May 2022, as a voluntary good-practice tool for cross-border transfers generally.
The practical takeaway is narrower than people want it to be. Do not treat the absence of an enforced cross-border rule as a green light, and do not treat its presence on the statute book as a red one either. Read the framework rather than the rumour of it.
"Don't use AI" is not a data policy. It's the absence of one.
A sensible personal rule-set
Stripped of the legal language, a workable personal standard looks like this.
- Never paste identifying client data into a general-purpose prompt: a name, an account number, anything that lets someone reconstruct who this is about.
- Redact first. Most of the time the model does not need the name to do the actual work.
- Know your tier. A free consumer account and a properly contracted Business or Enterprise account are not the same product at a different price. They are different data-handling arrangements, and the difference matters more than which model you picked for the task.
- Read your own firm's policy, in writing, rather than assuming it matches what the person at the next desk is doing.
That last one is the common failure. "The firm must have a policy somewhere" is an assumption, and the assumption is the actual risk, not the tool.
Where this leaves you
None of this is a reason to avoid the tools. It is a reason to be specific about what never goes in, and specific is exactly what a blanket ban never gives you. If you are still deciding what to use in the first place, the guide to AI tools for Hong Kong professionals is the better starting point, and the free prompt library is written to be used with redacted inputs.
Installing the judgement — what to redact, which tier you actually need, what your firm's rules permit — happens case by case, against your real documents. That is closer to an audit of what you touch in a normal week than a policy memo, and it is the part I do with people privately.
You already know what you can't paste. Let's sort out what you can.
METIS is private, one-on-one AI advisory for corporate professionals — built around your real work, in Hong Kong and worldwide. The first conversation is free.
Request a Private Consultation