Using generative AI without breaching the PDPA: a checklist for Singapore businesses
Twelve practical checks to run before your team puts customer or employee data into an AI tool, based on the PDPA's core obligations and the PDPC's guidance on AI systems.
Most PDPA problems with AI are not caused by sophisticated systems. They are caused by an employee pasting a customer list, a CV or a medical certificate into a free chatbot to save ten minutes. The Personal Data Protection Act 2012 does not prohibit using AI, but it applies to personal data whatever tool processes it.
This checklist is written for business owners and operations managers, not lawyers. It is a starting point, not legal advice. If your use of AI involves sensitive data at scale, have it reviewed by your Data Protection Officer or legal adviser.
Why AI raises new PDPA questions
The PDPA's obligations are familiar: consent, purpose limitation, notification, protection, retention limits and so on. Generative AI puts pressure on several of them at once:
- Data may be sent to a provider overseas, engaging the transfer limitation obligation
- Inputs may be stored or used to improve the provider's models, raising purpose and protection questions
- Outputs can be wrong or invented, touching the accuracy obligation
- Prompts and outputs are new records that need a retention decision
The PDPC's Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, issued in 2024, explain how the Act applies when organisations develop or deploy AI systems. They are worth reading in full if you build AI into customer-facing processes.
The checklist
Before choosing a tool
- Use business accounts, not personal ones. Enterprise and business plans from the main providers typically commit not to train on your data and offer data-processing terms. Free consumer accounts often do not.
- Read the data-processing terms. Check where data is stored, how long prompts are retained, whether staff at the provider can access them, and what sub-processors are used.
- Check overseas transfer. If data leaves Singapore, you remain responsible for ensuring it receives a comparable standard of protection. Contractual clauses in the provider's terms are the usual mechanism.
Before using personal data
- Ask whether you need personal data at all. Many tasks, such as drafting a template letter, work just as well with names and identifiers removed.
- Check the purpose. Was the data collected for a purpose that covers this use? Using customer enquiries to answer that customer is likely covered. Using them to profile customers for marketing may not be.
- Consider the exceptions carefully. The PDPA includes a business improvement exception and a research exception that may allow certain uses without fresh consent. The PDPC's AI guidelines describe when these can apply to developing AI systems. Document your reasoning if you rely on them.
- Update notices if the use is new. If customers would be surprised to learn their data is being processed by an AI system, your privacy notice probably needs updating.
While the system is in use
- Keep a human in the loop for decisions that matter. Do not let an AI system make decisions with significant effects on individuals without review, such as rejecting a job applicant or a loan.
- Check outputs for accuracy. If AI outputs feed into records about individuals, put a review step in place. Wrong information about a person is a PDPA issue as well as a quality issue.
- Restrict access. Treat AI tools like any system holding personal data: role-based access, strong authentication, and offboarding when staff leave.
- Set retention rules for prompts and outputs. Chat histories accumulate quickly. Decide how long they are kept and turn on automatic deletion where the tool allows it.
- Include AI in your breach response plan. If personal data is exposed through an AI tool, the usual data breach notification obligations apply, including assessing whether the PDPC and affected individuals must be notified.
Data staff should never paste into an AI tool
Your policy should name categories explicitly. People follow lists better than principles. A typical list:
- NRIC, FIN and passport numbers
- Bank account and payment card details
- Medical information and medical certificates
- Salary and performance information about named employees
- Passwords, API keys and system credentials
- Client information covered by a confidentiality agreement
What "good" looks like for an SME
For a company of 20 to 200 staff, reasonable PDPA-aligned AI practice usually means: one or two approved AI tools on business plans, a two-page usage policy, a short register of AI use cases with the data each one touches, and a review step for any new use involving customer data. It is achievable in a few weeks. If you need a template to start from, see our guide to writing an AI usage policy.
Frequently asked questions
Does the PDPA ban using ChatGPT or Copilot with customer data?
No. The PDPA does not ban specific tools. It requires that you handle personal data according to its obligations, whatever system you use. In practice, this means choosing tools with suitable data-protection terms and controlling what data goes in.
Who is responsible if the AI provider leaks our data?
Your organisation remains responsible for personal data in its possession or under its control, including data processed on your behalf by a provider. That is why vendor due diligence and contractual protections matter.
What are the penalties for breaching the PDPA?
The PDPC can impose financial penalties of up to 10% of an organisation's annual turnover in Singapore for organisations with turnover above S$10 million, or up to S$1 million otherwise, as well as directions to remedy the breach.
Need help applying this in your business? TENONTECH works with Singapore SMEs on AI strategy, implementation and governance. Book a consultation.