Hong Kong’s privacy watchdog received 2,990 complaints in the first half of 2026, a 62% increase from a year earlier, as artificial intelligence accelerated the collection and use of personal information. The rise does not prove that AI caused every dispute. It does show why data governance has become a more immediate consumer issue as online platforms, payment systems, membership programs, and AI-enabled services collect more information at greater speed.
According to the South China Morning Post, the Office of the Privacy Commissioner for Personal Data recorded the increase between January and June. Information and communications technology accounted for 867 cases, the largest category. Privacy Commissioner Ada Chung Lai-ling said data could now be collected, processed, and used rapidly and at scale in the AI era, while public awareness of privacy protection had also improved.
The figures give a concrete local measure to a problem often discussed only in general terms. AI systems rely on data, but the risks for consumers usually begin before a model is trained or an automated decision is made. They begin when an app asks for a phone number, a shopping site requests identity details, or a membership program collects information that is not obviously needed for the service. Hong Kong’s complaint increase suggests that residents are scrutinizing those requests more closely.
Information Technology Generates Hong Kong’s Largest Complaint Category
The 867 information and communications technology cases made that sector the largest source of privacy complaints in the first half, according to the South China Morning Post. The category includes the digital systems through which companies collect, store, and exchange personal information. It does not identify AI as the cause of every individual complaint, but it places technology at the center of the regulator’s concern.
A separate Dimsum Daily report corroborated the 2,990 total and 867 technology-related cases. It also reported that organizations notified the privacy office of 246 data-leak and ransomware incidents during the same six-month period. The difference between a complaint and an incident notification matters. A complaint reflects a concern brought to the regulator by an individual, while a notification can arise when an organization reports a breach or ransomware event. Both figures point to the same operational pressure: more personal information is moving through digital systems that consumers may not fully understand.
Chung’s warning focused on familiar transactions. The reports said consumers often raised concerns after online shopping, card payments, or membership registration when organizations requested excessive information or failed to respond. Those activities existed long before generative AI. What changes in an AI-era environment is the speed with which data can be combined, classified, and reused across products and services.
For companies, that makes data minimization more than a legal formality. Collecting only the information needed for a defined service reduces the volume exposed if a system is misconfigured, breached, or later connected to an AI workflow. For customers, it creates a simpler test: is the requested data necessary to complete the transaction, or is it being gathered for a broader purpose that has not been clearly explained?
AI Makes Data Governance a Consumer Protection Issue
The privacy commissioner described personal data as a valuable and marketable resource, according to the South China Morning Post. That language captures the practical reason the issue is growing. Identity details, transaction records, contact information, and behavioral data can support fraud, targeted marketing, credit assessment, or model development. The more systems that handle them, the more difficult it becomes for an individual to know where the data has traveled.
Artificial intelligence intensifies that challenge because large systems can process information at scale and produce outputs that influence real decisions. An AI model does not need to expose raw data publicly to create a privacy concern. A company may still need to explain what information it collected, why it was used, how long it will be retained, and whether it was shared with service providers or used to train a system.
Hong Kong’s figures also fit a wider Chinese debate over safeguards around AI products. Earlier EastFrontier reporting on China’s AI companion rules showed how regulators have had to address the social consequences of AI services that interact closely with users. Privacy complaints are different from companion-service rules, but both developments show that the public-facing layer of AI is increasingly creating regulatory questions that cannot be left to technical teams alone.
The growing awareness noted by Chung is important because complaint totals can rise for two reasons at once. A higher count can indicate that more problems are occurring. It can also indicate that consumers better recognize when their information is being requested or used inappropriately and know how to report it. The reported 62% increase cannot, by itself, separate those explanations. It does indicate that the regulator is receiving substantially more cases to assess.
The Next Test Is Whether Organizations Change Their Data Practices
The immediate question for Hong Kong businesses is not whether they use a large language model. It is whether their data practices remain defensible when an AI tool, a cloud provider, or a new automated workflow is added to an existing service. A retailer that introduces an AI assistant, for example, must consider the information a customer enters into that assistant, the vendor that processes it, and the internal staff who can access the resulting records.
This is particularly important for organizations that treat AI adoption as a standalone technology project. The complaints reported in the first half of 2026 arose in a market where online shopping, payment, and membership services are already common. New AI functions are being added to those established data flows, not built on a clean slate. That means companies need to examine old consent language, data inventories, vendor contracts, and deletion practices before expanding automated features.
The issue also has a trust dimension. Hong Kong consumers who believe a company asks for more information than necessary may abandon a registration process, refuse to use an AI feature, or file a complaint. A clear explanation of purpose and retention cannot prevent every dispute, but it can reduce the gap between what a service collects and what a customer expects.
China’s ongoing effort to regulate intimate AI features, including the restrictions that reshaped chatbot companion functions, demonstrates how quickly consumer-facing AI can move from product experimentation to policy scrutiny. Hong Kong’s 2,990 complaints add another signal. The data issue is not only about the model itself. It is about the everyday systems that collect the information an AI economy depends on.
The Privacy Commissioner’s figures are therefore a warning against treating data governance as back-office compliance. In the first half of 2026, 867 technology-related complaints and 2,990 complaints overall put the issue directly in front of consumers and regulators. As companies add AI tools to shopping, finance, customer service, and membership systems, the quality of their privacy practices will increasingly determine whether those tools are seen as useful services or new sources of risk.
