PDPA and AI Tools: What Singapore SMEs Need to Know Before Deploying

PDPA and AI Tools: What Singapore SMEs Need to Know Before Deploying

Before an SME puts customer data into any AI tool, it needs to understand what the Personal Data Protection Act requires. This is not a minor administrative step — it determines whether you are legally entitled to use that data in the way the AI tool uses it, and whether you have the security controls in place to justify the risk. Most SMEs using AI are compliant on the basics without knowing it. Some are not, and they don’t know that either.

This article is a practical overview, not legal advice. For specific questions about your situation, consult the PDPC’s guidance materials or a qualified professional.


What PDPA Says About AI Data Use — In Plain Terms

Singapore’s Personal Data Protection Act (PDPA) governs how organisations collect, use, and disclose personal data. The relevant obligations for SMEs using AI tools are:

Consent: You generally need a legal basis to collect and use personal data. For most AI tools that process customer information, this basis is typically consent (given at the point of data collection) or legitimate interests. If you are feeding customer names, emails, purchase history, or communication records into an AI system, that is processing personal data and the PDPA applies.

Purpose limitation: Data can only be used for the purpose for which it was collected (or a purpose the individual would reasonably expect). If customers gave their email addresses to receive order confirmations, using those email addresses to train a marketing AI they’ve had no indication of is a different purpose — and may not be permissible without additional consent or disclosure.

Data protection by default: The 2020 amendments added mandatory data breach notification requirements. If an AI vendor suffers a data breach involving your customers’ data, you may have an obligation to notify both the PDPC and affected individuals.

Accountability: Organisations are responsible for the data they transfer to third-party processors, including AI tool vendors. If the vendor misuses the data or suffers a breach, the original data controller (your business) retains accountability to the individuals whose data it is.


The Key Question Before Using Any AI Tool with Customer Data

The single most important question: Does this AI tool train on or retain the data I put into it?

Some AI tools use customer inputs to improve their models. If that’s the case, your customers’ data is being used to train a third-party AI system — which is almost certainly beyond the purpose they originally consented to. Enterprise versions of many AI tools (including enterprise tiers of major LLM platforms) offer data isolation agreements that prevent training on your inputs. Consumer or free tiers often do not.

Read the vendor’s Data Processing Agreement (DPA) and Terms of Service before inputting any personal data. If the vendor cannot provide a DPA, or if it is unclear whether your inputs are used for model training, that is a flag.


Practical Risk Points for Singapore SMEs

Using ChatGPT or similar tools with real customer data: Pasting a customer complaint into a general-purpose AI to draft a response sounds harmless, but the customer’s name, purchase details, and contact information are all personal data. Verify whether the version you’re using has a data privacy opt-out or enterprise-tier protections.

AI customer service bots that store conversation transcripts: These bots collect personal data by definition. Your privacy policy should disclose this, and you should know where those transcripts are stored and for how long.

Marketing AI tools that access your customer database: If an AI marketing tool is connected to your CRM or email list, it is processing your contacts’ personal data. The vendor needs to be a data processor operating under your instructions — not independently using that data.

Employee data: PDPA applies to personal data about employees as well as customers. AI tools used for scheduling, HR, or performance monitoring may process employee personal data, which has its own implications.


What to Put in Place Before Deploying AI

A minimum baseline for PDPA compliance when deploying AI tools:

  1. Update your privacy policy to disclose that AI tools are used in your operations and what types of data they process.
  2. Review the vendor’s DPA and confirm that data is not used for model training without your consent.
  3. Map the data flows — know what personal data the AI tool receives, processes, and stores, and where.
  4. Establish a breach notification process. If a vendor notifies you of a data breach, you need to know what your obligations are and how quickly you need to act.
  5. Do not use personal data beyond its original collection purpose without reviewing whether that use is permissible.

The PDPC’s Position on AI

The PDPC has issued advisory guidelines on AI governance, including the Model AI Governance Framework (updated in 2020, with subsequent guidance on generative AI in 2024). These frameworks are voluntary but signal the direction of regulatory expectation. SMEs are not the primary target of enforcement action, but complaints from customers about misuse of their data are taken seriously, and the reputational risk of a data incident may outweigh any operational benefit from an improperly deployed AI tool.

The PDPC’s website (pdpc.gov.sg) has sector-specific guidance and a self-assessment tool that SMEs can use to check their compliance posture.


Sources: Personal Data Protection Act 2012 (as amended 2020); PDPC Model AI Governance Framework 2020; PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems; PDPC guidance on Generative AI, 2024. This article is informational only and does not constitute legal advice.

If you’re evaluating AI tools for customer service, the AI Customer Service guide covers practical deployment considerations. The PSG Grant article explains which AI solutions come pre-assessed for enterprise standards under IMDA’s pre-approval process.