All Insights Personal Data Solution

AI Tools and Personal Data: What PDPC's Guidelines Expect From Your Business

Feeding customer or employee data into an AI chatbot or analytics tool doesn't move that data outside the Personal Data Protection Act (PDPA). It just adds a new vendor relationship the PDPA still applies to.

Compliz Insights · Personal Data Solution · ·

SMEs are adopting AI tools faster than most of them are updating their data protection practices to match: chatbots handling customer enquiries, AI-assisted analytics, recommendation engines for marketing or hiring. Each of these typically runs on personal data, and Singapore's regulator has already published specific expectations for how that should be handled.

PDPC Has Already Weighed In

On 1 March 2024, the Personal Data Protection Commission (PDPC) published Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems. The Guidelines aren't legally binding in themselves, but PDPC has indicated its enforcement of the PDPA is likely to follow the positions set out in them, which makes treating them as advisory-only a riskier read than it sounds.

What the Guidelines Actually Cover

Broadly, they explain when it may be appropriate to rely on certain PDPA exceptions when using personal data to develop an AI system, and set out recommended data handling and accountability measures for deploying one. A separate set of recommendations targets third-party providers that build or run AI systems for other businesses, since those providers are typically data intermediaries in their own right.

If You Use a Third-Party AI Vendor, You're Still on the Hook

The same principle covered in our guide to managing third-party data processors applies here: engaging a vendor's AI chatbot or analytics product doesn't transfer your PDPA accountability to them. Worth checking specifically before adopting an AI tool: what happens to the customer or employee data you feed into it, whether the vendor uses that data to train models beyond your own account, and whether that's disclosed anywhere in their terms.

What This Looks Like in Practice

Rolling out an AI tool that touches customer or employee data?

Compliz reviews the data flows before you adopt an AI vendor, and builds the accountability documentation PDPC's guidelines expect.

Request a Quote

Frequently Asked Questions

Are AI tools exempt from PDPA obligations?

No. Personal data fed into or processed by an AI tool is still subject to the PDPA in the same way as any other use of that data.

Are PDPC's AI guidelines legally binding?

Not in themselves, but PDPC has indicated its own enforcement approach is likely to follow the positions in them, which in practice makes them worth treating as a compliance baseline.

What do the guidelines actually require?

They set out when certain PDPA exceptions may apply to using personal data to develop an AI system, and recommend specific data handling and accountability measures for deploying one.

If I use a third-party AI vendor's chatbot, am I still responsible for PDPA compliance?

Yes. The vendor is typically a data intermediary carrying some direct obligations of its own, but you remain accountable as the organisation, the same principle that applies to any outsourced data processing.

Are generative AI tools covered by the same guidelines?

PDPC has separately consulted on guidelines specific to generative AI's use of personal data, so this area is still developing and worth checking for updates before treating current guidance as settled.