Skip to content

Glossary

PDPApersonal data protection act

Singapore's data-protection law, which sets baseline rules on agreement, notification and security for handling personal data of people there.

In plain terms

Singapore's baseline rules for handling people's information: say what you are collecting it for, get agreement where agreement is needed, look after it, and do not use it for something else later. The word baseline is doing real work, because it sets a floor rather than describing everything a careful organisation would do.

01

Why it matters

Because Singapore is where a great many businesses put their regional operations, so the law reaches organisations whose main presence is somewhere else entirely. The tools those teams adopt then process material the regime covers, and the obligations stay with the organisation rather than moving to the vendor supplying the tool.

02

How it works

Consent and notification sit at the centre of it, which shapes what an organisation has to be able to say. Being able to describe what is collected and why is a prerequisite rather than an afterthought, and an AI tool that quietly becomes a new destination for existing material is a change to that description.

Responsibility does not transfer with the data. Engaging somebody else to process material on your behalf leaves the obligations where they were, which is why a vendor's assurances are useful to a buyer and are not a substitute for the buyer's own position.

There is a named national commission, and it publishes guidance. For a buyer that means the standard being applied is documented somewhere public rather than inferred, so a vendor's account of what is required can be checked rather than accepted.

It sets a floor rather than a ceiling, which is the part organisations forget when they treat compliance as the goal. Meeting it says a baseline has been met and says nothing about whether a particular arrangement is sensible for material that happens to be commercially sensitive rather than personal.

Regional operations make it one regime among several. A Singapore team frequently handles material belonging to people across the region, so the practical exercise is finding an arrangement that satisfies more than one set of rules at once rather than optimising for this one.

What moves to the vendor, and what does not

What moves to the vendor, and what does notThis division is worth being clear about because vendor material is written to be reassuring and is accurate about the left-hand column only. A page describing certifications, controls and regional processing is telling you true things about how the vendor operates, and none of it addresses why your organisation decided to collect the material, whether the people it concerns were told, or whether the new destination is consistent with what they were told. Those questions are answerable only from inside the organisation. The practical consequence for an AI adoption is a small piece of work that is easy to skip: when a tool becomes a new place that existing material goes, the organisation's own description of what happens to that material has changed, and somebody has to notice. Nothing about the adoption prompts that. The tool is bought for a capability, the material flows because the capability requires it, and the description everybody relies on quietly stops matching the arrangement it describes.The vendor takes onOperating the service securely.Whatever their contract commitsto.Their own regulatory position.Stays with youDeciding to collect it at all.Describing what happens to it.Answering for the wholearrangement.Engaging a vendor moves work anddoes not move responsibility.The right-hand column is where aregulator's questions land, andnone of it is answerable bypointing at a supplier.
This division is worth being clear about because vendor material is written to be reassuring and is accurate about the left-hand column only. A page describing certifications, controls and regional processing is telling you true things about how the vendor operates, and none of it addresses why your organisation decided to collect the material, whether the people it concerns were told, or whether the new destination is consistent with what they were told. Those questions are answerable only from inside the organisation. The practical consequence for an AI adoption is a small piece of work that is easy to skip: when a tool becomes a new place that existing material goes, the organisation's own description of what happens to that material has changed, and somebody has to notice. Nothing about the adoption prompts that. The tool is bought for a capability, the material flows because the capability requires it, and the description everybody relies on quietly stops matching the arrangement it describes.
03

Seen in the wild

  • A regional team adopting an assistant and finding the obligations stayed with them rather than the vendor.

    ChatGPT
  • Checking what a search deployment makes reachable before it becomes a new destination for existing material.

    Glean
  • An automation quietly becoming a route that moves personal data somewhere nobody described.

    Make
04

Common misconceptions

People assume

Using a compliant vendor makes us compliant.

In fact

Obligations stay with the organisation that decided to collect and use the material. A vendor's own position is useful evidence and does not transfer the duty, so the buyer still has to be able to describe what is happening and why.

People assume

Meeting it means the arrangement is sound.

In fact

It sets a baseline. An arrangement can satisfy the regime and still be a poor idea for material that is commercially sensitive rather than personal, because the law is not the thing protecting that.

05

Questions

Does this apply to us if our head office is elsewhere?
Ordinarily yes, where a Singapore operation is handling personal data of people there. The location of head office is not the deciding fact, which is why organisations with a regional team frequently meet the regime without having thought of themselves as being covered by it.
What changes when we adopt an AI tool?
The tool becomes a new destination for material that was already being handled, and the description of what happens to that material changes with it. The obligation to be able to give that description accurately is what the adoption actually touches.
Is a vendor's compliance statement enough?
It is evidence about the vendor rather than about you. Responsibility for deciding to collect and use the material stays where it was, so a statement of theirs helps you make your own case and does not make that case for you, however thorough it happens to be.
06

Key takeaways

  • Obligations stay with the organisation, not the vendor processing on its behalf.
  • A new tool is a new destination, and the description has to keep up.
  • It is a floor: meeting it is not the same as the arrangement being sensible.
  • Regional teams usually meet several regimes at once, not this one alone.
08

Tools that use this

  • ChatGPT

    Obligations staying with the team rather than the vendor.

  • Glean

    A deployment becoming a new destination for existing material.

  • Make

    An automation moving personal data somewhere nobody described.

Last checked August 2026

All glossary terms