← All articles

PDPA, ChatGPT and AI Chatbots: SME Checklist

Cortex Lab AI · · Updated

General information on the PDPA as at 5 October 2026, not legal advice. For a decision about your own customers' data, check with a lawyer or the PDPC.

Two questions stop a lot of Singapore chatbot projects before they start. Will this break the PDPA, Singapore's privacy law? Will our customers' messages be used to train someone else's AI? A chatbot can follow the PDPA. Whether an AI company trains on your chats depends on which plan you pay for and how its settings are switched, and you can check both. This guide covers the privacy rules a chatbot has to follow, what happens when staff paste customer details into ChatGPT, where your customers' messages end up when they chat with a WhatsApp bot, and a checklist you can work through this week.

To keep things concrete, we'll follow one made-up business: a beauty salon with two outlets that takes bookings on WhatsApp. It isn't a real client. We build AI chatbots and automations for Singapore SMEs (small and medium-sized businesses), so we'd like you to finish this guide thinking it's doable. Keep that in mind. We explain what we do near the end.

This is general information, not legal advice. For advice on your own business, ask a qualified adviser.

Does the PDPA apply to an AI chatbot?

Yes. The PDPA covers any time a business collects or uses people's personal data, and that includes an AI system once it's live (PDPC Advisory Guidelines on AI, para 2.1). A customer's name, phone number and booking request all count as personal data, wherever they end up.

The PDPC, the agency that enforces the PDPA, published those AI guidelines on 1 March 2024. They were written for AI that makes recommendations, predictions or decisions. A bot that answers "are you open on Sunday?" barely fits. The guidelines aren't law (para 2.2), but they show how the PDPC thinks, and their advice on telling customers what you're doing and writing your rules down suits chatbots well.

Hiring a vendor doesn't make it their problem. Under section 4(3) of the PDPA, if a vendor handles data for you, the law treats it as if you handled it yourself (Advisory Guidelines on Key Concepts, para 6.20). The vendor, which the law calls a "data intermediary", only has to follow three rules directly: keep the data safe, don't keep it longer than needed, and report leaks (para 6.16).

Which PDPA obligations apply to a chatbot?

The PDPA has ten main rules, which it calls obligations. Nine of them come up in a normal chatbot project (Key Concepts, para 10.2). The tenth is about keeping data accurate.

Obligation What it means for a chatbot At the salon
Consent and purpose limitation Only use data for the reason the customer gave it to you Booking details are for bookings. Sending promotions needs a separate yes
Notification Tell people what you collect and why, before or while you collect it The bot's first message says it's a bot and links to the privacy policy
Access and correction If someone asks, show them their data and who you shared it with in the past year Staff search the chat logs as well as the booking system
Protection Keep the data reasonably secure Each staff member has their own login to the chatbot dashboard, removed when they leave
Retention limitation Delete data once you no longer need it for the original reason, the law or the business Chat logs are deleted after a set time the salon writes down
Transfer limitation Data sent overseas must be protected about as well as the PDPA would protect it A contract on file for every overseas vendor, covering how they protect the data
Data breach notification If data leaks, work out how serious it is. If it's serious enough, tell the PDPC within three calendar days One named person decides whether a leak has to be reported
Accountability Write down your data rules and let people see them The privacy policy on the website mentions the chatbot

Can my staff paste customer data into ChatGPT?

Not into a personal account on the default settings. For personal ChatGPT accounts, OpenAI says it "may use your content to train our models" unless you switch off a setting called "Improve the model for everyone" (OpenAI Help Centre). Even with that off, clicking thumbs up or thumbs down on a reply lets OpenAI use the whole conversation.

Paid business plans are different. OpenAI says that by default it doesn't train on what you type or what it replies in ChatGPT Business, Enterprise, Edu or its API (OpenAI business data). Microsoft says that when Copilot Chat is used through a work account, your prompts and its replies aren't used to train the underlying AI models (Microsoft Learn). Google says Workspace doesn't train AI on your company's data without your permission (Google Workspace privacy hub).

Plenty of staff use personal accounts anyway. MIT NANDA found that only 40% of companies had paid for an official AI subscription, while workers at over 90% of the companies it surveyed regularly used their own AI tools for work (The GenAI Divide: State of AI in Business 2025). If an employee breaks the PDPA, the business is mainly the one responsible (Key Concepts, para 6.12). At the salon, the bigger risk might be a receptionist pasting an unhappy customer's messages into their own ChatGPT to help write an apology. Pay for a business plan and set one simple rule: customer names, numbers and messages only go into the company account.

Where does customer data go in a WhatsApp chatbot?

Usually through three to five companies before it reaches your booking system. The exact number depends on how many jobs one vendor does. Here's where one message to the salon goes: "Hi, it's Mei Ling, can I book a facial on Saturday at 3pm?"

Data Where it goes Who can see it What to check
Phone number and WhatsApp name Meta, which owns WhatsApp, then the company that connects your business to WhatsApp (often sold as the "WhatsApp Business API") Meta, that company Which country they store it in, and for how long
Message text That company, then the chatbot software, then the AI model that writes the reply The chatbot company, the AI company Training is switched off, and how long chats are kept
Booking (name, service, time) The chatbot software, then your booking system or customer database (CRM) Your staff, the booking system company Who can log in, and how a record gets deleted
Full chat history The chatbot software, sometimes copied into your CRM The chatbot company, your staff How long it's kept, and that it's included when a customer asks for their data
Anything sensitive the customer sends without being asked Same path as the message Everyone above The bot asks people not to send it, and marks it for deletion

Each stop keeps data for a different length of time. OpenAI's API doesn't train on your data unless you agree to it, but it keeps logs for up to 30 days to check for misuse, unless you're on its zero data retention setup (OpenAI API data controls). OpenAI lets API and ChatGPT Enterprise customers have their data stored in Singapore. ChatGPT Business customers can't.

Is a WhatsApp chatbot PDPA compliant?

It can be, but WhatsApp's own rules make it your job. Meta's WhatsApp Business Messaging Policy, last updated 23 September 2026, says: "You are responsible for and must secure all necessary notices, permissions, and consents to collect, use, and share people's content and information."

The policy also says people must agree before you message them, and a bot must give them a "prompt, clear, and direct" way to reach a real person. You also can't ask for full card numbers or ID numbers. If the salon's bot asked for an NRIC (Singapore identity card) number to "verify" a booking, it would break Meta's rules. It would also be collecting the kind of data that, together with a few other details, means a leak has to be reported (Key Concepts, para 20.15).

Do I need customer consent for an AI chatbot?

Not a separate one, if the bot is only answering a question the customer asked. When someone gives you their details, the law treats them as agreeing to you using those details for the obvious reason (Key Concepts, para 12.20). The PDPC gives the example of someone who calls a taxi company and gives their name and number. They've agreed to be told when their taxi arrives. They haven't agreed to ads for the company's limousine service.

Using chat data for anything else, like promotions or training an AI, needs the customer's agreement or a specific exception in the law. You still have to tell people what you're collecting, and the AI guidelines encourage you to explain what the bot does and what data it uses (paras 9.5 to 9.7). For the salon, one opening message does the job: "You're chatting with our automated booking assistant. We use your name, number and messages to handle your booking. Type STAFF to reach a person. Privacy policy: [link]."

Can customer data be stored overseas?

Yes, as long as whoever receives it has to protect it about as well as the PDPA would. The law accepts a few ways to show that: a contract, company-wide rules the receiver must follow, the laws of their country, or international data protection certifications such as APEC CBPR and PRP (Key Concepts, paras 19.4 to 19.6). Most AI models run on servers outside Singapore. So in practice, read each vendor's data processing terms (the part of their contract about how they handle your data) and keep a copy. The PDPC says to rely on customers' consent for overseas transfers only when you can't get a contract or certification (para 19.7).

What happens when the chatbot gets it wrong?

It will, sometimes. Plan for these four situations before you switch it on.

  • It gives a wrong answer, or isn't sure. The bot passes the chat to a named staff member instead of guessing. Meta's policy requires a way to reach a person anyway.
  • A customer sends an NRIC, card number or medical detail. The bot replies that it can't accept that, and the message is marked for deletion.
  • A vendor leaks data. Vendors handling data for you have to tell you. If the leak is likely to cause significant harm or affects 500 or more people, you must report it to the PDPC within three calendar days of working that out (Key Concepts, paras 20.20 and 20.22).
  • A customer asks what data you have on them. Chat logs count, so someone has to be able to find and export one person's chats.

What are the PDPA fines for SMEs?

Up to S$1 million for most SMEs. If your business makes more than S$10 million a year in Singapore, the maximum is S$1 million or 10% of that yearly revenue, whichever is bigger (Advisory Guidelines on Enforcement, para 27.1). These maximums apply when a breach is deliberate or careless, and the 10% rule has applied since 1 October 2022.

Few SME cases get anywhere near the maximum. The PDPC looks at how much harm was done and how much the business was to blame, and it has cut fines for small firms. It lowered the fine for Advance Home Tutors [2019] SGPDPC 35 so it wouldn't crush a small home business, and for O2 Advertising [2019] SGPDPC 32 because the company was in serious money trouble (Table 1). The PDPC can also order you to stop using, or delete, data you collected against the rules (para 26.1.2). For a chatbot, that could mean switching it off and wiping its chat history.

PDPA AI chatbot checklist

Go through this with your current setup, or with any quote you're looking at.

  • List every company your chatbot's data passes through. The table above helps.
  • Ask each vendor to tell you in writing whether your data trains any AI, and how long they keep it.
  • Move staff onto business AI accounts and write the one-line rule about customer data.
  • Add an opening message that says it's a bot, what it collects and why, how to reach a person, and links to your privacy policy.
  • Only collect what a booking needs, and tell customers not to send ID or card numbers.
  • Decide how long to keep chat logs, and check that old ones actually get deleted.
  • Keep each overseas vendor's data processing terms on file.
  • Pick one person to handle requests to see or fix data, and to decide what to do about leaks.
  • Mention the chatbot in your privacy policy, as the AI guidelines suggest (para 10.4).

Questions to ask any chatbot vendor

  • Is our chat data used to train any AI, yours or your AI provider's? Will you put that in the contract?
  • Which AI company do you use, on what kind of account, and in which country is our data processed?
  • How long do you keep chat logs? Can we change that? Can you delete one customer's data if they ask?
  • How fast will you tell us about a leak?
  • How does the bot pass a chat to our staff?

Where Cortex Lab AI fits

We're a Singapore consultancy, and we follow the same PDPA rules as our clients, including on the WhatsApp chatbots we set up. We build inside tools you already pay for, so your data stays in systems you control, under contracts you already have. We set up every connection so your data isn't used to train AI, and we tell you in writing which company can see what. We aren't lawyers, and we can't change where an AI company processes data overseas. To see where your customer data would go, book a free 30-minute consultation.

Do you need a custom chatbot to stay PDPA compliant?

No. A ready-made chatbot you subscribe to can tick every box above, as long as it's set up properly and the vendor answers your questions in writing. Either way, the legal responsibility stays with you. What an AI chatbot costs in Singapore explains when a ready-made tool is enough, and the grants that replaced PSG covers what government funding you can get.

Some businesses shouldn't hand customer chats to a bot yet. If most of your messages are about health, money or ID details, or need a person to make a judgement call, a bot adds risk and doesn't save much. Keep it to opening hours, prices and bookings, or hold off for now.

Sources, all checked on 30 September 2026, with every paragraph reference re-checked on 5 October 2026: PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (1 March 2024); PDPC Advisory Guidelines on Key Concepts in the PDPA (revised 29 April 2026); PDPC Advisory Guidelines on Enforcement (revised 1 October 2022); OpenAI Help Centre; OpenAI business data; OpenAI API data controls; Microsoft Learn; Google Workspace privacy hub; WhatsApp Business Messaging Policy; MIT NANDA, The GenAI Divide, July 2025 (PDF copy hosted by MLQ.ai).