The Personal Data Protection Act 2012 (PDPA), administered by the Personal Data Protection Commission (PDPC), as amended by the Personal Data Protection (Amendment) Act 2020 (in force 1 February 2021), imposes eleven data-protection obligations plus the Do Not Call regime. (Source: PDPC / Singapore Statutes Online; retrieved 20 Aug 2026. Verified)
Legal-status distinction, maintained throughout this report: the PDPA and its Regulations are binding law; PDPC Advisory Guidelines and IMDA’s Model AI Governance Framework are regulator recommendation / interpretation, not binding (though guidelines are the best evidence of how PDPC will enforce); other items are good practice.
A1. Obligations mapped to the seven workflows
- Consent, Purpose Limitation, Notification (ss.13–20): The SME must have a lawful basis to collect, use or disclose personal data and must have notified individuals of purposes. Putting a customer’s data into Claude is a use (and, to Anthropic, a disclosure). For workflows 1–5 and 7 the purpose must be one a reasonable person would consider appropriate and one the individual was informed of. Uploading a client’s data to Claude to draft a reply is a new purpose that most SMEs have not notified. (Inferred from ss.18, 20; Verified statute.)
- Accuracy (s.23): Especially engaged where Claude output feeds a decision about an individual (workflow 7). Hallucination risk means output must be verified.
- Protection (s.24): Requires reasonable security arrangements — the obligation most directly engaged by every workflow (endpoint security, access control, connector scoping).
- Retention Limitation (s.25): Personal data must not be retained once purpose and legal/business need ends. Collides with vendor-side retention (chats, memory, cached files) — see A8.
- Transfer Limitation (s.26): Anthropic processes outside Singapore. See A4 — central.
- Data Breach Notification (ss.26A–26E): See A6.
- Accountability (ss.11–12): Policies, a designated DPO, demonstrable compliance. Applies regardless of firm size.
- Access & Correction (ss.21–22): The SME must be able to retrieve and correct data that may sit in Claude chats, memory and projects.
- Do Not Call (Part 9): Engaged if Claude generates or sends outbound marketing to Singapore numbers — check the DNC registers.
A2. Data intermediary analysis — the pivotal question
Under the PDPA a data intermediary processes personal data on behalf of another organisation pursuant to a written contract; it is subject only to the Protection and Retention obligations, while the principal remains liable for all obligations. (Source: PDPC Advisory Guidelines on Key Concepts; PDPA s.4(2)–(3). Verified)
- On commercial tiers: Anthropic’s DPA (incorporated into the Commercial Terms) establishes a processor relationship. Anthropic states it “act[s] as a Data Processor” for commercial products. (Source: privacy.claude.com, “Does Anthropic Act as a Data Processor or Controller?” Verified) This lets the SME treat Anthropic as its data intermediary.
- On consumer tiers (Free/Pro/Max): there is no DPA. Consumer Terms govern, and there is no written contract establishing processing “on behalf of” the SME. The SME therefore cannot establish the data-intermediary relationship at all, and every unit of personal data placed into Claude is a disclosure to Anthropic acting for its own purposes (including training). (Sources: privacy.claude.com DPA article; anthropic.com/news, updates to consumer terms, 28 Aug 2025. Verified) This is the single fact that makes consumer tiers Red for third-party personal data.
- What remains with the SME regardless: consent, notification, purpose limitation, accuracy, transfer, breach notification, accountability, access/correction. The intermediary relationship offloads none of these.
- Required contractual terms: the DPA must restrict Anthropic’s use to the SME’s instructions, mandate comparable security, and address retention and deletion — the Anthropic DPA does this and includes SCCs.
A3. Legal basis for putting customer data into Claude
- Consent (s.13): Cleanest but rarely obtained specifically for “we will process your data using a US AI vendor.” Realistically available only prospectively via updated notices.
- Deemed consent by contractual necessity (s.15): Available where processing is reasonably necessary to perform a contract with the individual (e.g., using Claude to draft a deliverable the client engaged the firm to produce). Narrow.
- Deemed consent by notification (s.15A): Requires (i) a documented assessment of adverse effect, (ii) notification of the purpose, (iii) a reasonable opt-out period. Documentation-heavy but workable.
- Legitimate Interests exception (First Schedule, Part 3): Requires a documented Legitimate Interests Assessment balancing benefit against adverse effect, plus disclosure of reliance. Realistically the most useful basis for internal efficiency uses — but must be documented.
Rule of thumb: for client or customer data, rely on contractual necessity or an LIA, and update the privacy notice to disclose AI processing and cross-border transfer. Do not assume “consent is implied.”
A4. Cross-border transfer — s.26 PDPA and Regulation 10, PDP Regulations 2021
Section 26 prohibits transferring personal data outside Singapore unless the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA. (Source: PDPA s.26; PDP Regulations 2021 Reg 10; PDPC Key Concepts Guidelines. Verified) “Comparable” does not mean identical. Recognised mechanisms: (a) a contract imposing comparable obligations (satisfied by Anthropic’s DPA/SCCs); (b) Binding Corporate Rules; (c) a specified certification (APEC/Global CBPR, or PRP for intermediaries); (d) the individual’s consent to the transfer.
- On commercial tiers: the Anthropic DPA with SCCs provides the contractual mechanism. The SME must still (i) identify the transfer basis in its records, (ii) satisfy itself the terms are enforceable, and (iii) disclose the transfer.
- On consumer tiers: no DPA, so no s.26 mechanism exists — the transfer is non-compliant unless individual consent to the specific transfer is obtained (impractical).
- Data residency changes the analysis materially: deploying via AWS Bedrock or Google Vertex AI in
ap-southeast-1 (Singapore) keeps inference and (configurably) storage in-region. On those platforms the cloud provider is the data processor and Anthropic does not access the inference environment. This can reduce — though not eliminate, since the contracting and vendor chain still involves overseas entities — the cross-border exposure. (Sources: claude.com/regional-compliance; docs.aws.amazon.com Claude data residency; AWS ML blog on Global CRIS incl. Singapore. Verified that the Singapore region exists and the cloud provider is processor; Partially documented on the exact contract chain.)
A5. Higher-risk data categories
- NRIC/FIN numbers: PDPC’s Advisory Guidelines for NRIC and Other National Identification Numbers (31 Aug 2018, effective 1 Sep 2019) generally prohibit collection, use or disclosure of NRIC numbers or copies except where required by law or necessary to verify identity to a high degree of fidelity. (Source: pdpc.gov.sg NRIC Advisory Guidelines. Verified) Pasting a customer’s NRIC into Claude, or letting an agent ingest an NRIC scan, is a use that will rarely fall within an exception — redact before upload. FIN, birth-certificate, work-permit and passport numbers are treated the same.
- Financial account data, incidental health data, minors’ data, biometric and identity-document images: all attract heightened Protection-obligation expectations; incidental health disclosures in a monitored mailbox (workflow 3) are especially hard to control.
- Employment/HR data: governed by the PDPA (with the Employment chapter of the Selected Topics guidelines) — see A10.
A6. Data breach notification in an agentic context
A breach is notifiable if it (a) is likely to result in significant harm, or (b) is of significant scale — 500 or more individuals (the 500-individual threshold applies regardless of whether the data is sensitive). The SME must assess expeditiously, then notify PDPC as soon as practicable and in any case no later than 3 calendar days after completing its assessment that the breach is notifiable; affected individuals must be notified where significant harm is likely. (Source: PDPA s.26B; Personal Data Protection (Notification of Data Breaches) Regulations 2021; PDPC Guide on Managing and Notifying Data Breaches (15 Mar 2021), pdpc.gov.sg/report-data-breach. Verified)
Agentic scenarios that can be notifiable: an agent auto-sending a message containing one client’s data to another recipient; an over-permissioned connector exposing a shared drive; a prompt-injection-driven exfiltration; a staff member pasting a client list into a personal Claude account. Mechanics: contain, assess, notify via the PDPC breach form, notify individuals, document every step.
A7. Anonymisation and redaction
PDPC’s Guide to Basic Anonymisation sets the standard: data is outside the PDPA only if individuals cannot be re-identified, accounting for other data reasonably available. (Source: PDPC anonymisation guidance / Selected Topics Ch.3. Verified) “Redact before you upload” is a real control only if technically enforced and complete. At SME scale, manual redaction of free-text emails and scanned documents is error-prone; treat redaction as risk-reduction, not as taking data outside the PDPA, unless de-identification is robust.
A8. Retention
Section 25 requires deletion once purpose and legal need end. Reconcile with statutory retention duties: IRAS/Income Tax Act record-keeping (generally 5 years), Companies Act accounting records (5 years), employment records. Vendor-side retention complicates this: consumer chats persist until deleted then are purged within ~30 days (or up to 5 years if training is on); commercial/API inputs default to deletion within 30 days; Enterprise admins can set custom retention (minimum 30 days); and safety-flagged content can be retained up to 2 years and classifier scores up to 7 years regardless of settings. (Sources: privacy.claude.com retention articles; platform.claude.com API and data retention. Verified) Map the firm’s retention schedule onto these vendor windows; deletion is neither instantaneous nor complete.
A9. AI-specific guidance
- PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (2024): clarifies consent, notification, accountability and the Business Improvement/Research exceptions for AI. Advisory, not binding. (Source: pdpc.gov.sg. Verified)
- IMDA / AI Verify Foundation Model AI Governance Framework for Generative AI (30 May 2024): nine dimensions (accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment R&D, AI for public good). Recommendation / good practice, not binding. (Source: aiverifyfoundation.sg. Verified)
A10. Employee and candidate data
Almost every SME will run HR material through Claude (appraisals, CV summaries, disciplinary notes). This is personal data; the Employment chapter of the Selected Topics guidelines applies. Employment consent exceptions do not extend to disclosing employee data to a third-party processor without a lawful basis and (on commercial tiers) a DPA. Candidate data used for shortlisting can also engage the AI decision-systems guidelines and the Accuracy obligation.