AI Tools and Personal Data: What PDPC's Guidelines Expect From Your Business
Feeding customer or employee data into an AI chatbot or analytics tool doesn't move that data outside the Personal Data Protection Act (PDPA). It just adds a new vendor relationship the PDPA still applies to.
SMEs are adopting AI tools faster than most of them are updating their data protection practices to match: chatbots handling customer enquiries, AI-assisted analytics, recommendation engines for marketing or hiring. Each of these typically runs on personal data, and Singapore's regulator has already published specific expectations for how that should be handled.
PDPC Has Already Weighed In
On 1 March 2024, the Personal Data Protection Commission (PDPC) published Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems. The Guidelines aren't legally binding in themselves, but PDPC has indicated its enforcement of the PDPA is likely to follow the positions set out in them, which makes treating them as advisory-only a riskier read than it sounds.
What the Guidelines Actually Cover
Broadly, they explain when it may be appropriate to rely on certain PDPA exceptions when using personal data to develop an AI system, and set out recommended data handling and accountability measures for deploying one. A separate set of recommendations targets third-party providers that build or run AI systems for other businesses, since those providers are typically data intermediaries in their own right.
If You Use a Third-Party AI Vendor, You're Still on the Hook
The same principle covered in our guide to managing third-party data processors applies here: engaging a vendor's AI chatbot or analytics product doesn't transfer your PDPA accountability to them. Worth checking specifically before adopting an AI tool: what happens to the customer or employee data you feed into it, whether the vendor uses that data to train models beyond your own account, and whether that's disclosed anywhere in their terms.
What This Looks Like in Practice
- Customer service chatbots. Check whether queries containing personal data are retained by the vendor, and for what purpose, before rolling one out.
- AI-assisted recommendation or decision systems — for marketing targeting, credit or hiring-adjacent decisions — are exactly the scope the 2024 Guidelines address directly, so these deserve the documented accountability measures the Guidelines recommend, not just a vendor's assurance that "it's compliant."
- Generative AI is a fast-moving area even by PDPC's own account: it has separately consulted on guidelines specific to generative AI's use of personal data, so a business adopting these tools should expect the specifics here to keep developing rather than treat the current guidance as final.
Rolling out an AI tool that touches customer or employee data?
Compliz reviews the data flows before you adopt an AI vendor, and builds the accountability documentation PDPC's guidelines expect.
Request a QuoteFrequently Asked Questions
Are AI tools exempt from PDPA obligations?
No. Personal data fed into or processed by an AI tool is still subject to the PDPA in the same way as any other use of that data.
Are PDPC's AI guidelines legally binding?
Not in themselves, but PDPC has indicated its own enforcement approach is likely to follow the positions in them, which in practice makes them worth treating as a compliance baseline.
What do the guidelines actually require?
They set out when certain PDPA exceptions may apply to using personal data to develop an AI system, and recommend specific data handling and accountability measures for deploying one.
If I use a third-party AI vendor's chatbot, am I still responsible for PDPA compliance?
Yes. The vendor is typically a data intermediary carrying some direct obligations of its own, but you remain accountable as the organisation, the same principle that applies to any outsourced data processing.
Are generative AI tools covered by the same guidelines?
PDPC has separately consulted on guidelines specific to generative AI's use of personal data, so this area is still developing and worth checking for updates before treating current guidance as settled.
