PDPA Compliance for AI: What Singapore SMEs Must Get Right
Published June 2026 | 9 min read
This article is general information about how the PDPA affects the design of AI systems. It is not legal advice, and we are not lawyers. Where a decision has legal consequences for your business, confirm it with a qualified adviser.
Why this comes up with AI specifically
Singapore’s Personal Data Protection Act has applied to businesses since 2014, so most owners have met it before. What changes with AI is not the law but the volume and the reach: a system that reads every incoming message is touching personal data continuously, often across more services than the process it replaced.
That matters because obligations attach to what you actually do with data, not to what you intended when you bought the tool.
The four questions worth answering before you build
1. What are you collecting, and do you need it?
The PDPA works on purpose. You collect personal data for a stated purpose, and you should not collect beyond it. In practice this is the easiest place to go wrong with AI, because capturing everything is technically simpler than deciding what to keep.
A booking system needs a name, a contact and a date. It does not need the customer’s full message history stored indefinitely because it might be useful later. “Might be useful” is not a purpose.
2. Has the person agreed, and do they know to what?
Consent has to be meaningful. Someone messaging your business expects a reply; that is not the same as agreeing to be added to a marketing list. If the AI captures details during a service conversation and you later want to use them for something else, that is a separate purpose and needs its own basis.
Practically: keep the service conversation and the marketing opt-in separate, and record which one the person actually gave.
3. Where is it processed?
Sending personal data outside Singapore carries obligations under the transfer limitation provisions. Most AI services run somewhere, and that somewhere is frequently not Singapore. This is a design decision: which services see personal data, whether the data can be reduced before it reaches them, and whether a regional option exists.
The answer is not always “keep everything local”. It is that you should know, rather than discover it later.
4. When does it stop existing?
This is the one most often missed. The PDPA requires you to cease retaining personal data once the purpose it was collected for has ended and there is no remaining legal or business need.
Two practical consequences. First, retention needs an actual schedule, not an intention. Second — and this catches people — marking a record as deleted while the name, contact details or identifiers remain in the row is still retention. If the data is still there, you are still holding it.
Where you need to keep the transaction record for legitimate reasons, the usual approach is to strip the identity from it rather than keep the whole thing. You retain what the business or the law requires, and the person is no longer identifiable in it.
What good practice looks like in a small business
- Write down what you collect and why. One page is enough. If a field has no purpose next to it, question whether it should exist.
- Separate what needs identity from what does not. Statistics about how many enquiries arrive at 9pm need no names attached.
- Give retention a date and enforce it automatically. A schedule nobody runs is a policy, not compliance.
- Know which third parties are involved and what each one receives.
- Appoint someone responsible. The PDPA requires organisations to designate a data protection officer and make the contact details available. For a small business this is usually an existing person, not a hire.
Where AI projects typically slip
Everything gets logged “for debugging”. Conversation logs are useful for improving a system, and they are also personal data. They need the same purpose, retention and access decisions as anything else.
Data is copied into a second system and forgotten. An export into a spreadsheet to check something is a new copy with no retention rule attached to it.
Consent is treated as a one-off. Purposes change as a business grows. The basis you collected under still governs what you can do.
Nobody can answer “where is this person’s data?” If a customer asks what you hold about them, you need to be able to answer.
The practical position
None of this makes AI unusable for a small business. It shapes the design: collect less, keep it for a defined period, know where it goes, and be able to explain it. Those decisions are cheap to make at the start and expensive to retrofit.
When we build something that touches personal data, we work through these questions with you and tell you plainly which ones you should put to your own adviser. We would rather raise it early than have you discover it after the system is live.
Ensure Your AI is PDPA-Compliant
Get Your Compliance AssessmentRelated Resources
PDPC Official Site | AI Agents for Business