You will check three real or planned AI uses at your workplace against a short PDPA checklist.
Daniel's manager has asked a simple question at the weekly meeting: which of the ways we're using AI are fine, and which ones should we stop? Three people have started using assistants for different jobs, and nobody has checked any of them. Daniel volunteers to find out, and he gives himself thirty minutes.
This exercise is that thirty minutes. You'll take three AI uses from your own workplace and put each one through four questions drawn from module 2. A lawyer would go much further. What you're doing is a quick first pass that sorts the easy cases from the ones that need someone with more authority, and each use ends with a one-line recommendation.
Question one: does it involve personal data, and whose? Use the definition from lesson 2.1, PDPA basics every employee should know, and the list from lesson 2.2. Write down whose data it is: customers, patients, job applicants, staff, members of the public. Note anything especially sensitive, such as health details, financial information or NRIC numbers.
Question two: is the tool approved by the organisation, and where is the data processed? Check your company's list of approved tools from lesson 1.2. If the tool is approved, find out where it processes data if you can, since that brings in the transfer limitation obligation. If it isn't approved, say so plainly.
Question three: were people told about this purpose, and did they agree, or does another basis under the Act apply? Look at what people were told when their data was collected, usually in a privacy notice or a form. If this use isn't covered, the answer may be that the company needs fresh consent, or that an exception applies. Deciding whether an exception applies isn't your call alone, so mark it for the data protection officer.
Question four: can identifiers be removed, and who signs off if they can't? Use the method from lesson 2.2. If the task works without personal data, the other three questions mostly fall away. If it can't, name the person who should approve it.
Each use ends with one of three lines. Go ahead means no personal data, or an approved tool used for a purpose people were told about. Change it means the task is fine in principle but something must change first, usually removing identifiers or moving to the approved tool. Ask the data protection officer means the use involves personal data and the answer to question three is unclear, or the data is sensitive, or you simply aren't sure.
When in doubt, choose the third. Asking costs a short email. Guessing wrong can cost the company far more.
Here's how Daniel's check came out. The clinic and its uses are examples.
Use one: Siti at reception pastes patient feedback forms, with names and phone numbers, into her personal assistant to find common complaints. Question one: yes, patients' names, contact details and treatment comments, which include health information. Question two: no, she uses her personal account, which the clinic never approved. Question three: patients gave feedback to help the clinic improve, but weren't told it would go to an outside AI provider. Question four: yes, names and numbers can be removed and physio names replaced with labels. Recommendation: change it. Remove identifiers and use the clinic's approved tool, or skip AI for this task.
Use two: Marcus, a physiotherapist, uses the approved assistant to draft a newsletter article about desk posture, from his own knowledge. He uses no personal data, the tool is approved, and the last two questions don't apply. Recommendation: go ahead.
Use three: the clinic manager wants to try an AI app that records treatment sessions and writes the clinical notes automatically. Question one: yes, patients' voices, health conditions and treatment, which is sensitive. Question two: not yet approved, and the vendor's servers are overseas. Question three: patients haven't been told sessions would be recorded or processed this way. Question four: no, the whole point is to capture the session. Recommendation: ask the data protection officer before any trial, and use the vendor questions from lesson 2.3, What the PDPC has said about AI systems.
Notice how quickly the easy one went. Most of Daniel's thirty minutes went on use three, which is exactly where the time should go.
Pick three uses you know about: your own, a colleague's, or one your team is planning. Try to include at least one that you suspect is fine and one that makes you a little uneasy, so the check has something to sort.
Write each answer in a sentence or two. Short answers are fine. Vague ones aren't: "some customer info" should become "customers' names and order histories".
If your check lands on "ask the data protection officer", count that as a good result. You've turned an unspoken risk into a specific question with a named person to answer it. Start with the use you're least sure about.
Complete the checklist for three AI uses at work and write a one-line recommendation for each: go ahead, change it, or ask the data protection officer.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).