You will be able to tell when an AI task at work involves personal data and what changes if it does.
It's Friday afternoon and Daniel has 60 patient feedback forms to summarise for the clinic's monthly meeting. He exports them to a spreadsheet: name, phone number, treatment, physiotherapist, rating, comment. An assistant could sort the comments into themes in two minutes. All he has to do is paste the sheet in.
That one paste is the subject of this lesson. Lesson 2.1, PDPA basics every employee should know, set out the obligations. Here you'll learn to spot when an AI task brings them into play, and the simple change that often takes them back out.
Personal data turns up in more of your work than you might think. The obvious items are names, phone numbers, email addresses, home addresses and NRIC numbers. Less obvious ones include photos and video of people, voice recordings, and case notes or comments that describe a person's situation, health, complaint or performance.
NRIC numbers deserve a special mention. The PDPC has issued separate advisory guidelines that limit when organisations may collect, use or disclose NRIC numbers, because they're permanent and tied to so much else. An NRIC number should almost never need to go into an AI tool.
In Daniel's spreadsheet, the names and phone numbers are personal data. So is the treatment column, which is also health information about identifiable patients. Even the comments may be, since "my back has been worse since the session with Raj on 3 March" can be matched to a patient through the booking system.
When you paste personal data into an AI tool, it goes to the provider's servers, as lesson 1.1 described. In PDPA terms, the organisation has disclosed that data to a third party. If the servers are outside Singapore, the transfer limitation obligation from lesson 2.1 applies as well.
That doesn't make it automatically unlawful. Organisations disclose data to service providers all the time: payroll companies, cloud storage, the clinic's booking software. What makes those disclosures acceptable is that the organisation chose the provider, has a contract covering how the data is handled, has looked at where it's stored, and has told patients in its privacy notice that data may be shared with service providers for these purposes.
This is where lesson 1.2, Personal, business and enterprise accounts are not the same, becomes a legal point.
If Daniel's clinic has an approved AI tool on a business plan, with a contract that says the provider won't train on clinic data and sets out where it's processed, then the company has done the work that makes that disclosure defensible. Using that tool for that task may well be fine, depending on what the clinic's policy says.
If Daniel uses his personal account instead, none of that applies. The clinic has no contract with that provider, didn't assess it, and doesn't know the data has gone there. The data has left the clinic's control through a channel it never approved, and the clinic is still accountable for it.
So the first question for any work task is not "is AI allowed?" but "is this tool, on this account, approved for this kind of data?"
Here's the part that saves the most trouble. Very often you can do the task with no personal data at all.
Daniel doesn't need names or phone numbers to find themes in feedback. He deletes those columns. He replaces the physiotherapists' names with Physio A, B and C and keeps the key on his own computer. He removes dates from the comments and scans them for anything else that points to a person, such as "my daughter who works at the clinic". What's left is a list of ratings and comments that nobody outside the clinic could link to a patient. He gets his themes, and the clinic hasn't disclosed anyone's data.
This is often called removing identifiers, and it isn't magic. Some data stays identifiable however much you strip out, especially rare cases or very small groups, and combining datasets can re-identify people. For high-stakes data, ask your data protection officer whether your method is good enough. For a lot of everyday tasks, though, deleting a few columns and replacing names with labels is enough to change the answer.
Other tasks can be reframed entirely. Instead of pasting a customer's angry email to get a reply, describe the situation in general terms: "A customer is upset that a refund took three weeks. Draft a polite reply that apologises and explains the new process." The assistant writes the same reply without ever seeing the customer.
Daniel's sheet took about ten minutes to clean. Most of your own tasks will be like that: the hard part is noticing the personal data in the first place, and once you've seen it, removing it is usually quick.
Take three AI tasks you have done or might do at work and mark whether each involved personal data and how it could be avoided.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).