Assemblists
Book a Consultation
—

Insights

Data protection

AI and the PDPA: what to get right

The PDPA did not change because of AI. What changed is how easily personal data now leaves your building — usually pasted into a chat window by someone trying to be helpful.

The problem is rarely the model

Most PDPA exposure in AI projects has nothing to do with the clever part. It comes from staff pasting customer lists, CVs, medical details or contracts into a consumer chatbot to save twenty minutes, on a free tier whose terms allow the provider to train on what they receive.

That is a disclosure. It happens quietly, it happens daily in most organisations that have not addressed it, and it is invisible until it is not.

The four questions worth asking

Before any AI system touches personal data, four things need an answer. What personal data does it see? Where does that data physically go? How long is it kept, and by whom? And who reviews a decision before it affects a person?

A system that cannot answer those is not ready, regardless of how well it performs. A system that can is usually straightforward to defend.

Consent and purpose

Data collected for one purpose does not automatically become available for another. Customer records gathered to fulfil orders were not gathered to train a model or to feed a recommendation engine, and using them that way needs to be thought through rather than assumed.

The pragmatic route is usually to avoid the question: strip or mask identifiers before anything reaches a model, so what leaves is a shape rather than a person.

Where the data actually sits

Overseas transfer has conditions, and “the API is in the US” is a transfer. This is answerable at design time: regional hosting, a private cloud deployment, or a model running on hardware you control.

We run image generation and other workloads on our own GPU precisely so that some material never leaves the building. That is not the right answer for every project, but it should be a live option rather than an afterthought.

Human review is a design decision

If a system makes or shapes a decision about a person — a shortlist, a credit call, a claim — someone should be able to see why and overrule it. Build that in at the start and it is a checkpoint in a workflow. Add it later and it is a rewrite.

This is not legal advice

We build systems; we are not your lawyers, and the PDPC is the authority on what the PDPA requires. What we can tell you is that permissions, retention, transfer and human review are all architecture decisions, and they are far cheaper to get right before the thing is built.

Worried about where your data goes?

We will map what leaves your building today and what it would take to keep the sensitive parts in.