What the PDPC has said about AI systems

You will be able to describe in general terms the PDPC's guidance on personal data in AI recommendation and decision systems.

Daniel's clinic group is talking to a software company about a new booking app. The sales deck says the app uses AI to suggest the best physiotherapist and session plan for each patient, based on their history. The owners like the idea. Then one of them asks Daniel a question he can't answer: what does the PDPA say about this?

It's a fair question, and Singapore's data protection regulator has written about it. This lesson describes that guidance in general terms, so you know it exists, roughly what it covers and when to go and read it properly.

The guidelines and what they're for

The Personal Data Protection Commission, the PDPC, has issued Advisory Guidelines on the use of personal data in AI recommendation and decision systems. You'll find them on the PDPC website alongside its other advisory guidelines.

They don't create a separate AI law. Advisory guidelines explain how the PDPC interprets the existing Act, so the obligations are the same ones you met in lesson 2.1, PDPA basics every employee should know. What the guidelines add is an explanation of how those obligations apply when an organisation builds or uses a system that makes recommendations or decisions about people. A booking app that suggests a treatment plan from a patient's records is a clear example. So are product recommendations in an online shop, or a tool that ranks job applicants.

The guidelines look at different stages of a system's life. Here's the shape of them, described broadly.

When a system is being built

Building or improving an AI system usually means using existing data to develop, test and tune it. The guidelines discuss how organisations can do that within the Act. They point to exceptions in the PDPA that may let an organisation use personal data without fresh consent for certain purposes, such as improving its own products or doing research, provided the conditions in the Act are met.

They also encourage organisations to use less personal data where they can: removing identifiers, using anonymised data where it does the job, and protecting what they do keep. That's the same instinct as lesson 2.2, When pasting a customer list becomes a disclosure, applied at the scale of a whole system.

When a system is used on people

Once a system is making recommendations or decisions about customers, the familiar obligations come back to the front. People should be told that their data is being used this way and for what purpose, and consent is needed unless an exception applies.

The guidelines also discuss accountability. Organisations are encouraged to be open about how they use personal data in these systems, for example by explaining in their written policies what data the system uses and what the organisation does to make its recommendations fair and reasonable. For Daniel's clinic, that might mean telling patients that the app uses their treatment history to suggest a plan, and being able to explain what that history includes.

When someone else builds it for you

Most organisations won't build their own AI. They'll buy it, as Daniel's clinic is about to. The guidelines also address service providers that develop or deploy AI systems for organisations.

The broad idea is that the provider should help its client meet the client's own obligations. If the clinic needs to tell patients how their data is used, the provider should be able to explain what the system actually does with it. Practices such as keeping records of where training data came from and how it was prepared make that possible. And the clinic, as the organisation that collected the data, remains accountable for it, whoever writes the code.

That gives Daniel his first useful move. Before the clinic signs, he can ask the software company what patient data the system uses, where it's processed, whether it's used to train models for other customers, and what the company will provide to help the clinic explain the system to patients.

Read the source, not the summary

Everything above is a general description, and it's deliberately loose. The guidelines have specific wording, examples and conditions that matter in a real decision, and the PDPC can update them. Exceptions such as the ones for business improvement and research come with conditions you need to check against your actual situation. So before your team relies on any of this, read the current version on the PDPC website, and bring your data protection officer in when customer data is involved.

That might sound like a lot of reading for a busy person. It isn't, if you go in with questions. Daniel didn't read the guidelines cover to cover. He looked for the parts that answered what his owners wanted to know: can we use patient records for this, what do we have to tell patients, and what should we ask the vendor.

Your team will have its own version of those questions. When you open the guidelines for the activity, look for the sections that match the stage your team is at, whether you're building, using or buying.

Find the guidelines on the PDPC website and list three questions your team should be able to answer before using AI on customer data.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).