Research

Where Singapore SMEs can and cannot use Claude

An advisory reference for Singapore SMEs — where the PDPA, sector rules and Claude’s own product facts permit, restrict or prohibit business use.

As of 20 August 2026

This is general guidance, not legal advice. IMCI AI Software does not provide legal services. Nothing on this page creates a solicitor–client or advisory relationship. Singapore’s data protection requirements depend on your specific circumstances, sector and contracts — always consult a Singapore-qualified lawyer before acting on anything here. Product and regulatory facts were verified as at 20 August 2026 and change frequently. Re-verify before relying on them.

Aerial view of Marina Bay Sands and the Singapore Flyer at night
Photo by Keming Tan on Unsplash

Key findings

Red

On consumer plans (Free/Pro/Max), a Singapore SME should not put any customer, employee, client-confidential or NRIC/FIN data into Claude at all. Those tiers carry no Data Processing Addendum (DPA), train on inputs by default (per Anthropic’s 28 August 2025 consumer-terms update), and retain data up to five years — so the SME cannot lawfully establish Anthropic as its data intermediary under the PDPA. This single fact makes most business workflows Red on consumer tiers, and is the most actionable finding in this report.

Green

The workflows become permissible (Green/Amber) only on Team or Enterprise plans, or via API/AWS Bedrock/Google Vertex — where the Commercial Terms and DPA apply, training is off by default, and, on Bedrock/Vertex in the Singapore ap-southeast-1 region, data can be processed in-region. Even then, the SME remains fully liable as the controller and must document consent or legitimate interests, a cross-border transfer basis, and vendor due diligence.

Red

The highest-risk configuration — an agent reading untrusted inbound email while holding write access and an outbound send capability (the “lethal trifecta”) — should be Red for every SME regardless of plan, unless read is separated from write and every outbound action passes human review. Sector rules (law, accounting, real estate, MAS) override the general position and push several workflows to Red.

Executive summary

This report answers one question: where, when and how can a Singapore SME lawfully and safely use Claude? The answer turns on three variables, in order of decisiveness:

  1. Plan tier (consumer vs commercial). This changes the legal answer, not just features. Consumer tiers (Free/Pro/Max) are governed by Anthropic’s Consumer Terms, train on inputs by default since 28 August 2025, and retain data up to five years for users who allow model-improvement use. Commercial tiers (Team/Enterprise/API/Bedrock/Vertex) are governed by the Commercial Terms, incorporate a DPA with Standard Contractual Clauses, and do not train on inputs by default. Only a commercial arrangement lets the SME establish Anthropic as a data intermediary under the PDPA. Verdict: consumer tiers are Red for any third-party personal or confidential data.
  2. Workflow architecture. Chat drafting with redacted inputs is low-risk. Agentic workflows that combine untrusted input, private-data access and an exfiltration channel are the highest-risk. Verdict: separate read from write; human-in-the-loop on all outbound and deletion actions.
  3. Sector overlay. Professional confidentiality (law, accounting), legal privilege, AML/CFT tipping-off rules, MAS outsourcing expectations and CEA rules sit on top of the PDPA and frequently push a workflow to Red even where the PDPA would permit it. Contract (NDAs) often binds more tightly than statute.

The bottom line for the consultant: advise clients to (a) stop all firm-data use on personal/consumer accounts immediately; (b) move to Team or Enterprise (or Bedrock/Vertex ap-southeast-1) with a signed DPA before any customer data touches Claude; (c) redact NRIC/FIN and use least-privilege connectors; (d) keep a human in the loop on every client-facing or regulator-facing output; and (e) refer to a Singapore-qualified lawyer on cross-border transfer, privilege and sector licensing.

The numbers that set the clock

3 daysto notify PDPC after assessing a breach as notifiable
500individuals — the “significant scale” breach threshold
5 yearsconsumer-tier retention when model training is allowed
30 daysdefault deletion window on commercial API tiers
2 yearssafety-flagged content retained, regardless of settings
1 hourMAS incident notification for regulated firms

Part A — The PDPA baseline

The Personal Data Protection Act 2012 (PDPA), administered by the Personal Data Protection Commission (PDPC), as amended by the Personal Data Protection (Amendment) Act 2020 (in force 1 February 2021), imposes eleven data-protection obligations plus the Do Not Call regime. (Source: PDPC / Singapore Statutes Online; retrieved 20 Aug 2026. Verified)

Legal-status distinction, maintained throughout this report: the PDPA and its Regulations are binding law; PDPC Advisory Guidelines and IMDA’s Model AI Governance Framework are regulator recommendation / interpretation, not binding (though guidelines are the best evidence of how PDPC will enforce); other items are good practice.

A1. Obligations mapped to the seven workflows

  • Consent, Purpose Limitation, Notification (ss.13–20): The SME must have a lawful basis to collect, use or disclose personal data and must have notified individuals of purposes. Putting a customer’s data into Claude is a use (and, to Anthropic, a disclosure). For workflows 1–5 and 7 the purpose must be one a reasonable person would consider appropriate and one the individual was informed of. Uploading a client’s data to Claude to draft a reply is a new purpose that most SMEs have not notified. (Inferred from ss.18, 20; Verified statute.)
  • Accuracy (s.23): Especially engaged where Claude output feeds a decision about an individual (workflow 7). Hallucination risk means output must be verified.
  • Protection (s.24): Requires reasonable security arrangements — the obligation most directly engaged by every workflow (endpoint security, access control, connector scoping).
  • Retention Limitation (s.25): Personal data must not be retained once purpose and legal/business need ends. Collides with vendor-side retention (chats, memory, cached files) — see A8.
  • Transfer Limitation (s.26): Anthropic processes outside Singapore. See A4 — central.
  • Data Breach Notification (ss.26A–26E): See A6.
  • Accountability (ss.11–12): Policies, a designated DPO, demonstrable compliance. Applies regardless of firm size.
  • Access & Correction (ss.21–22): The SME must be able to retrieve and correct data that may sit in Claude chats, memory and projects.
  • Do Not Call (Part 9): Engaged if Claude generates or sends outbound marketing to Singapore numbers — check the DNC registers.

A2. Data intermediary analysis — the pivotal question

Under the PDPA a data intermediary processes personal data on behalf of another organisation pursuant to a written contract; it is subject only to the Protection and Retention obligations, while the principal remains liable for all obligations. (Source: PDPC Advisory Guidelines on Key Concepts; PDPA s.4(2)–(3). Verified)

  • On commercial tiers: Anthropic’s DPA (incorporated into the Commercial Terms) establishes a processor relationship. Anthropic states it “act[s] as a Data Processor” for commercial products. (Source: privacy.claude.com, “Does Anthropic Act as a Data Processor or Controller?” Verified) This lets the SME treat Anthropic as its data intermediary.
  • On consumer tiers (Free/Pro/Max): there is no DPA. Consumer Terms govern, and there is no written contract establishing processing “on behalf of” the SME. The SME therefore cannot establish the data-intermediary relationship at all, and every unit of personal data placed into Claude is a disclosure to Anthropic acting for its own purposes (including training). (Sources: privacy.claude.com DPA article; anthropic.com/news, updates to consumer terms, 28 Aug 2025. Verified) This is the single fact that makes consumer tiers Red for third-party personal data.
  • What remains with the SME regardless: consent, notification, purpose limitation, accuracy, transfer, breach notification, accountability, access/correction. The intermediary relationship offloads none of these.
  • Required contractual terms: the DPA must restrict Anthropic’s use to the SME’s instructions, mandate comparable security, and address retention and deletion — the Anthropic DPA does this and includes SCCs.

A3. Legal basis for putting customer data into Claude

  • Consent (s.13): Cleanest but rarely obtained specifically for “we will process your data using a US AI vendor.” Realistically available only prospectively via updated notices.
  • Deemed consent by contractual necessity (s.15): Available where processing is reasonably necessary to perform a contract with the individual (e.g., using Claude to draft a deliverable the client engaged the firm to produce). Narrow.
  • Deemed consent by notification (s.15A): Requires (i) a documented assessment of adverse effect, (ii) notification of the purpose, (iii) a reasonable opt-out period. Documentation-heavy but workable.
  • Legitimate Interests exception (First Schedule, Part 3): Requires a documented Legitimate Interests Assessment balancing benefit against adverse effect, plus disclosure of reliance. Realistically the most useful basis for internal efficiency uses — but must be documented.

Rule of thumb: for client or customer data, rely on contractual necessity or an LIA, and update the privacy notice to disclose AI processing and cross-border transfer. Do not assume “consent is implied.”

A4. Cross-border transfer — s.26 PDPA and Regulation 10, PDP Regulations 2021

Section 26 prohibits transferring personal data outside Singapore unless the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA. (Source: PDPA s.26; PDP Regulations 2021 Reg 10; PDPC Key Concepts Guidelines. Verified) “Comparable” does not mean identical. Recognised mechanisms: (a) a contract imposing comparable obligations (satisfied by Anthropic’s DPA/SCCs); (b) Binding Corporate Rules; (c) a specified certification (APEC/Global CBPR, or PRP for intermediaries); (d) the individual’s consent to the transfer.

  • On commercial tiers: the Anthropic DPA with SCCs provides the contractual mechanism. The SME must still (i) identify the transfer basis in its records, (ii) satisfy itself the terms are enforceable, and (iii) disclose the transfer.
  • On consumer tiers: no DPA, so no s.26 mechanism exists — the transfer is non-compliant unless individual consent to the specific transfer is obtained (impractical).
  • Data residency changes the analysis materially: deploying via AWS Bedrock or Google Vertex AI in ap-southeast-1 (Singapore) keeps inference and (configurably) storage in-region. On those platforms the cloud provider is the data processor and Anthropic does not access the inference environment. This can reduce — though not eliminate, since the contracting and vendor chain still involves overseas entities — the cross-border exposure. (Sources: claude.com/regional-compliance; docs.aws.amazon.com Claude data residency; AWS ML blog on Global CRIS incl. Singapore. Verified that the Singapore region exists and the cloud provider is processor; Partially documented on the exact contract chain.)

A5. Higher-risk data categories

  • NRIC/FIN numbers: PDPC’s Advisory Guidelines for NRIC and Other National Identification Numbers (31 Aug 2018, effective 1 Sep 2019) generally prohibit collection, use or disclosure of NRIC numbers or copies except where required by law or necessary to verify identity to a high degree of fidelity. (Source: pdpc.gov.sg NRIC Advisory Guidelines. Verified) Pasting a customer’s NRIC into Claude, or letting an agent ingest an NRIC scan, is a use that will rarely fall within an exception — redact before upload. FIN, birth-certificate, work-permit and passport numbers are treated the same.
  • Financial account data, incidental health data, minors’ data, biometric and identity-document images: all attract heightened Protection-obligation expectations; incidental health disclosures in a monitored mailbox (workflow 3) are especially hard to control.
  • Employment/HR data: governed by the PDPA (with the Employment chapter of the Selected Topics guidelines) — see A10.

A6. Data breach notification in an agentic context

A breach is notifiable if it (a) is likely to result in significant harm, or (b) is of significant scale — 500 or more individuals (the 500-individual threshold applies regardless of whether the data is sensitive). The SME must assess expeditiously, then notify PDPC as soon as practicable and in any case no later than 3 calendar days after completing its assessment that the breach is notifiable; affected individuals must be notified where significant harm is likely. (Source: PDPA s.26B; Personal Data Protection (Notification of Data Breaches) Regulations 2021; PDPC Guide on Managing and Notifying Data Breaches (15 Mar 2021), pdpc.gov.sg/report-data-breach. Verified)

Agentic scenarios that can be notifiable: an agent auto-sending a message containing one client’s data to another recipient; an over-permissioned connector exposing a shared drive; a prompt-injection-driven exfiltration; a staff member pasting a client list into a personal Claude account. Mechanics: contain, assess, notify via the PDPC breach form, notify individuals, document every step.

A7. Anonymisation and redaction

PDPC’s Guide to Basic Anonymisation sets the standard: data is outside the PDPA only if individuals cannot be re-identified, accounting for other data reasonably available. (Source: PDPC anonymisation guidance / Selected Topics Ch.3. Verified) “Redact before you upload” is a real control only if technically enforced and complete. At SME scale, manual redaction of free-text emails and scanned documents is error-prone; treat redaction as risk-reduction, not as taking data outside the PDPA, unless de-identification is robust.

A8. Retention

Section 25 requires deletion once purpose and legal need end. Reconcile with statutory retention duties: IRAS/Income Tax Act record-keeping (generally 5 years), Companies Act accounting records (5 years), employment records. Vendor-side retention complicates this: consumer chats persist until deleted then are purged within ~30 days (or up to 5 years if training is on); commercial/API inputs default to deletion within 30 days; Enterprise admins can set custom retention (minimum 30 days); and safety-flagged content can be retained up to 2 years and classifier scores up to 7 years regardless of settings. (Sources: privacy.claude.com retention articles; platform.claude.com API and data retention. Verified) Map the firm’s retention schedule onto these vendor windows; deletion is neither instantaneous nor complete.

A9. AI-specific guidance

  • PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (2024): clarifies consent, notification, accountability and the Business Improvement/Research exceptions for AI. Advisory, not binding. (Source: pdpc.gov.sg. Verified)
  • IMDA / AI Verify Foundation Model AI Governance Framework for Generative AI (30 May 2024): nine dimensions (accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment R&D, AI for public good). Recommendation / good practice, not binding. (Source: aiverifyfoundation.sg. Verified)

A10. Employee and candidate data

Almost every SME will run HR material through Claude (appraisals, CV summaries, disciplinary notes). This is personal data; the Employment chapter of the Selected Topics guidelines applies. Employment consent exceptions do not extend to disclosing employee data to a third-party processor without a lawful basis and (on commercial tiers) a DPA. Candidate data used for shortlisting can also engage the AI decision-systems guidelines and the Accuracy obligation.

Part B — Sector overlays

Accounting and bookkeeping firms

On top of the PDPA: professional confidentiality under the ISCA/ACRA code (client information not disclosed to third parties without authority); ACRA and audit-related obligations; IRAS record-keeping; AML/CFT customer due diligence and, critically, the confidentiality of Suspicious Transaction Reports (STRs) — “tipping-off” is an offence under the CDSA. Engagement letters typically restrict disclosure to third-party processors. Effect: client financial data and working papers should never go into consumer Claude; on commercial tiers, disclosure must be consistent with the engagement letter and professional confidentiality; STR-related material must never be processed by an agent or connector. (Sources: ISCA Code; ACRA; CDSA. Verified on duties; Inferred on application.)

Law firms

  • Legal professional privilege and waiver: disclosing privileged material to a third-party processor risks waiver arguments; s.4(6) PDPA preserves privilege. A confidential commercial-tier tool with a DPA and training off reduces but does not eliminate the risk.
  • Client confidentiality under the Legal Profession (Professional Conduct) Rules remains the lawyer’s non-delegable duty.
  • MinLaw Guide for Using Generative AI in the Legal Sector (6 March 2026): three principles — professional ethics, confidentiality, transparency — with sample client-disclosure clauses; non-binding but authoritative. (Source: mlaw.gov.sg. Verified)
  • Law Society Advisory on the Use of Publicly Available AI Tools: members must ensure a tool’s terms of use are consistent with confidentiality duties and understand their legal effect. (Source: lawsociety.org.sg. Verified)
  • Courts: Supreme Court / State Courts / Family Justice Courts Registrar’s Circular No. 1 of 2024, Guide on the Use of Generative AI Tools by Court Users (effective 1 October 2024): users bear full responsibility for AI output; AI citations must be human-verified; confidential and personal information should not be disclosed to public GenAI tools; GenAI must not fabricate or tamper with evidence. (Source: judiciary.gov.sg. Verified)
  • Conflicts and information barriers: one AI workspace touching multiple clients raises a conflicts issue — see the edge cases in Part D5.

Real estate agencies

CEA framework plus AML/CFT under the Estate Agents (PMLPFTF) Regulations 2021 (customer due diligence, unrepresented-counterparty due diligence, five-year record retention, STR filing under the CDSA, compliance officer). Handling of identity documents and financial information is routine and sensitive. Marketing must comply with DNC. Effect: identity-document images and CDD files must not go into consumer Claude; STR and tipping-off constraints apply as for accountants. (Sources: cea.gov.sg; Estate Agents (PMLPFTF) Regulations 2021, sso.agc.gov.sg. Verified)

Media, marketing and creative agencies

  • Copyright and ownership of AI output (Copyright Act 2021): Singapore requires a human author for copyright to subsist (affirmed in Asia Pacific Publishing v Pioneers & Leaders [2011] SGCA 37); there is no UK-style computer-generated-works provision. Purely AI-generated output may attract no copyright, so agencies cannot reliably assign ownership of it to clients. (Sources: Copyright Act 2021, sso.agc.gov.sg; SGCA case. Verified)
  • Client IP and embargoed material: must not be disclosed to a third-party processor without consent.
  • Defamation, advertising standards (ASAS codes) and IMDA content codes apply to deliverables.
  • Disclosure to clients of AI use in deliverables is recommended good practice.

General SME / professional services

Contract, not statute, is often the binding constraint. NDAs and customer contracts frequently prohibit disclosure to any third-party processor without prior written consent — regardless of what the PDPA permits. Check the client’s own customer contracts before greenlighting any workflow that sends customer data to Claude. A PDPA-compliant transfer can still breach contract.

MAS-regulated firms

Even a small licensed firm (e.g., an RFMC) is expected to apply, proportionately: MAS Guidelines on Outsourcing Risk Management (cloud is outsourcing; classify material outsourcing; maintain an outsourcing register; due diligence to the standard expected of the institution; audit and access rights; sub-outsourcing and exit/portability) and the MAS Technology Risk Management Guidelines (concentration-risk assessment). Under the MAS TRM Notices (e.g., Notice 644/655), an FI must notify MAS within 1 hour upon discovery of a system malfunction or IT-security incident with severe and widespread impact on operations or material customer impact, followed by a root-cause and impact report within 14 days. MAS expectations frequently exceed the PDPA. Guidelines are not legally binding but MAS expects adherence; binding notices (e.g., Banking Act s.47) sit alongside. (Sources: mas.gov.sg Guidelines on Outsourcing; TRM Guidelines and TRM FAQ. Verified) Effect: an MAS-regulated SME needs documented vendor due diligence, audit rights and an exit plan before deploying Claude on customer data — realistically an Enterprise arrangement.

Singapore central business district office towers in panoramic view
Photo by Reuben Chew on Unsplash

Part C — Technical facts about the Claude desktop app and features

All Anthropic facts retrieved 20 August 2026. Product facts change frequently — re-verify before reliance. Confidence markers — Verified, Partially documented, Not publicly documented — are reproduced from the source research and are part of the finding.

Data flow and locality

  1. Local file attachment: For the developer Files API, the full file is uploaded to Anthropic storage and returns a file_id; content is processed server-side. Critically, Files API uploads are accessible to the entire workspace, not scoped to a user or session — a real cross-user leak risk. (Source: platform.claude.com/docs, Files. Verified) For consumer/desktop chat attachments, content is sent to Anthropic servers under the org or consumer retention policy; the exact form (full file vs extracted text vs chunks vs embeddings) is not publicly documented. (Not publicly documented — added to the vendor questions in Part H.)
  2. Agent pointed at a directory (Cowork / Desktop local access): Users attach workspace folders; the agent reads, creates and modifies files inside them and runs code in a sandbox VM. Admins can restrict paths (allowedWorkspaceFolders), set read-only (mode: ro), or block filesystem access ([]); the allowlist is enforced on the resolved path (symlink and .. traversal blocked). (Source: claude.com/docs, claude-desktop/local-access. Verified) Whether Cowork builds a persisted local index is not publicly documented. A Desktop setting “Run new tasks in the cloud” routes tasks to Anthropic’s servers even with a local folder attached. (Source: support.claude.com, Cowork. Verified)
  3. What the desktop app / Claude Code writes to disk: Claude Code stores session transcripts locally in plaintext JSONL under ~/.claude/projects/ for 30 days by default (cleanupPeriodDays). (Source: code.claude.com, data-usage and sessions. Verified) Credentials: macOS Keychain; Linux ~/.claude/.credentials.json (permissions 600). (Source: code.claude.com, authentication. Verified) Plaintext transcripts persist after sign-out until cleanup or manual deletion; protection relies on OS and disk encryption — no app-level encryption layer. (Partially documented / third-party corroborated.) The Cowork local session path on Windows (…\Claude\local-agent-mode-sessions) is third-party-reported. (Partially documented) Note a two-regime subtlety: Claude Code’s local transcript cleanup defaults to 30 days, but the Compliance API capture of those same local sessions is retained 6 years by default (or the org’s custom retention) — do not conflate them.
  4. Cloud sandbox / code execution: The code-execution tool runs Python and bash in server-side sandbox containers; container data (artifacts, uploaded files, outputs) is retained up to 30 days. Code execution is not ZDR-eligible and not HIPAA-eligible. (Source: platform.claude.com, code-execution-tool; api-and-data-retention. Verified)
  5. Processing locations / residency: Direct first-party API and Claude.ai default to US processing. AWS Bedrock and Google Vertex offer regional endpoints including Singapore ap-southeast-1; on those platforms the cloud provider is the data processor. (Sources: claude.com/regional-compliance; docs.aws.amazon.com; AWS ML blog. Verified) Enterprise offers a US-only inference setting (not APAC residency by itself). Connector-reached third-party services process data on their own infrastructure regardless of inference-region settings.

Retention, training and deletion

  1. Default retention: Consumer — chats retained until deleted, then purged within ~30 days; up to 5 years if “Help improve Claude” (training) is on. Commercial API — inputs and outputs deleted within 30 days by default (API log retention reduced to 7 days from 15 Sep 2025 per third-party reporting). Enterprise — admin-set custom retention, minimum 30 days. Safety-flagged content retained up to 2 years; classifier scores up to 7 years — regardless of tier or ZDR. (Sources: privacy.claude.com; platform.claude.com. Verified; the 7-day API figure Partially documented.)
  2. Training by default: Consumer (Free/Pro/Max): trains on new or resumed chats by default since 28 Aug 2025 unless the user opts out — Anthropic’s announcement states “we are also extending data retention to five years, if you allow us to use your data for model training… [this] will only apply to new or resumed chats and coding sessions”; existing users had until 8 Oct 2025 to choose. Commercial (Team/Enterprise/API/Bedrock/Vertex): does not train on inputs by default — the consumer changes “do not apply to services under our Commercial Terms, including Claude for Work (Team and Enterprise plans)” and the API. (Source: anthropic.com/news/updates-to-our-consumer-terms; Privacy Policy effective 28 Sep 2025. Verified) This is the most important consumer-vs-commercial difference.
  3. Zero Data Retention (ZDR): Available per-organisation via Anthropic sales (not self-serve) for eligible API features and Claude Code via Enterprise; covers the Messages and Token-counting APIs. Does not cover: consumer products, Team and standard Enterprise interfaces, Files API, batch, code execution, MCP connector, Claude for Excel — and does not override the up-to-2-year safety-flag retention. (Source: platform.claude.com, api-and-data-retention; code.claude.com, zero-data-retention. Verified)
  4. Deletion mechanics: A user delete removes a conversation from history immediately and from the backend within ~30 days; deleted chats are excluded from training. Enterprise admins can set org retention and use data exports. Deletion does not reach data already incorporated into a trained model, nor safety-flagged retained copies. Uploaded file content lives in separate storage requiring separate deletion. For a PDPA access, correction or erasure request, account for chats, memory, projects, uploaded files and connector-synced copies. (Sources: privacy.claude.com. Verified)

Memory, projects and persistence

  1. Memory / projects: Memory launched for Team and Enterprise (opt-in); Enterprise admins can disable memory org-wide. Memories are project-scoped and isolated (“project boundaries… keep sensitive conversations contained”). Standard-chat and project memory are separate spaces. Standard org data-retention applies. (Source: anthropic.com/news, memory. Verified; some mechanics Partially documented.) Cross-contamination risk: for law and accounting firms, one workspace holding adverse clients’ matters is a conflicts and confidentiality issue, not just privacy — project isolation helps but must be configured and verified.
  2. Artifacts: Published artifacts can use persistent storage that is personal or shared; shared storage exposes data to other users of that artifact (with a confirmation dialog). Team/Enterprise artifacts cannot be published publicly unless an Owner enables external sharing (off by default). Unpublishing permanently deletes associated storage. (Source: support.claude.com / code.claude.com, artifacts. Verified)

Connectors and MCP (items 12–16)

Connector architecture: Remote MCP connectors are brokered through Anthropic’s cloud — “the connection to your MCP server originates from Anthropic’s servers, not from your machine,” even in Cowork/Desktop. Local MCP servers (via claude_desktop_config.json) use the local network but aren’t available in Cowork or claude.ai. Connected third-party services process data on their own infrastructure under their own terms, which may be outside the US and outside Anthropic’s DPA entirely — changing the transfer analysis. On Team/Enterprise, only Owners can add connectors org-wide; users then connect individually, and access is limited to what the user can already see. Enterprise-managed auth allows org-wide authorisation. Custom connectors connect to services “not verified by Anthropic” — supply-chain risk; review scopes carefully. (Sources: support.claude.com, custom connectors / use connectors / MCP connectors. Verified)

Enterprise controls and assurance

  1. Admin controls: Enterprise offers SSO (SAML 2.0/OIDC), domain capture, SCIM and JIT provisioning, RBAC, audit logs (Owners can export; largely metadata — chat titles and content are not in audit-log exports), a Compliance API (Activity Feed retained 6 years; 150+ event types; captures file uploads, SSO/SCIM, project and conversation lifecycle, and local Cowork/Claude Code session transcripts for 6 years unless ZDR/HIPAA), custom retention, CMEK, US-only inference, IP allowlisting. (Sources: anthropic.com/product/enterprise; support.claude.com, Compliance API; platform.claude.com. Verified, some detail Partially documented.)
  2. Certifications: Anthropic holds SOC 2 Type I & II, ISO 27001:2022, ISO/IEC 42001:2023; participates in the EU-US Data Privacy Framework; offers a HIPAA BAA (Enterprise/API only). SOC 2/SOC 3 via trust.anthropic.com (detailed SOC 2 under NDA). These evidence Anthropic’s controls — they do not certify the SME’s own configuration, nor the correctness of Claude’s output. (Sources: trust.anthropic.com; third-party compliance summaries. Verified)
  3. Contractual instruments: Commercial Terms + DPA (with SCCs) + subprocessor list — available on Team/Enterprise/API; not on consumer tiers. BAA and custom retention are Enterprise/API. (Sources: anthropic.com/legal; privacy.claude.com. Verified)
  4. Encryption and isolation: AES-256 at rest, TLS 1.2+ in transit; tenant isolation by workspace and organisation; internal access controls (staff cannot view conversations by default). (Sources: code.claude.com, data-usage; third-party. Verified/Partially documented)

Part D — The permitted-use framework

This is the report’s primary deliverable: verdicts per workflow, per plan tier and per sector. A conditional verdict is only as good as its condition — where an Amber depends on a safeguard (“read-only, no outbound send, human review”), the safeguard is part of the verdict, not a footnote.

Legend: Red do not do this Amber permitted only with the stated conditions Green permitted with routine care Every verdict is encoded three ways — colour, shape (● / ◐ / ○) and word — so it survives greyscale, colour-blindness and screen readers.

D1. Master matrix — general SME baseline, Singapore-resident data subjects

Seven workflows: data, obligations, cross-border position, verdict, and the conditions a verdict depends on
Workflow Data categories Obligations triggered Cross-border Verdict Conditions to reach Green Residual risk
1 · General drafting / knowledge work Whatever staff paste (often personal or confidential) Consent, Purpose, Protection, Transfer Yes (US) unless Bedrock/Vertex SG AmberGreen if no personal data / redacted Commercial tier + DPA; redaction; AUP; training off Staff over-share; hallucination
2 · “Second brain” / memory / projects Accumulated internal + client data All, esp. Retention, Access, Protection Yes Amber Enterprise; memory scoped/isolated or disabled; retention set; no cross-client mixing Cross-matter contamination; retention creep
3 · Agentic inbox access (untrusted inbound) NRIC/FIN, contracts, complaints, sensitive disclosures, privileged All + Breach + (sector) privilege / tipping-off Yes RedAmber only if read-only triage, no outbound send/write, human reviews all drafts, scoped mailbox See verdict — the Amber conditions are the ceiling Lethal trifecta; prompt injection; wrong-recipient breach
4 · Local filesystem / project-folder work Client records, financials, payroll, bank statements Protection, Retention, Purpose, Transfer Yes (local read; cloud if run-in-cloud) Red AmberRed on consumer; Amber on commercial Commercial tier; read-only + scoped folders; “safe-for-AI” structure; disk encryption Over-broad scope; local plaintext cache
5 · Connectors / integrations Email, calendar, cloud storage, CRM, accounting DBs All + Transfer (third-party infra) Yes (Anthropic-brokered + third-party infra) Amber Least-privilege scopes; Owner-approved allowlist; read-only default; audit Over-permissioned tokens; third-party outside DPA
6 · Other desktop surfaces (Claude Code, browser control, artifacts, code execution, mobile) Varies; code, files, browsed content Protection, Transfer, Retention Yes (US sandbox; 30-day container) AmberBrowser control Red for untrusted sites No sensitive data in code execution or shared-storage artifacts; browser control off for untrusted content Sandbox retention; public artifact exposure; browser prompt injection
7 · Client-facing / regulator- or court-filed output Deliverables, filings Accuracy + professional/court duties Yes Amber Mandatory human verification; disclose AI use where required; verify all citations Hallucinated authority; certification breach

D2. Plan-tier overlay — the same seven workflows across four plan tiers

How each workflow’s verdict changes with the plan tier. Conditional verdicts keep their conditions.
Workflow Free/Pro/Max (Consumer) Team Enterprise API / Bedrock–Vertex (SG)
1 Drafting (with personal data) RedNo DPA, trains by default Amber Green GreenIn-region, ZDR available
2 Memory / projects Red Amber Green N/A (API)
3 Agentic inbox Red Red AmberRead-only + human-in-the-loop AmberCustom build, human-in-the-loop
4 Local folders Red Amber Amber / Green Green
5 Connectors Red Amber Amber / Green GreenSelf-built scopes
6 Desktop surfaces Red Amber Amber Amber
7 Client / regulator output Red Amber Amber Amber

The single most actionable pattern: almost everything is Red on consumer tiers and becomes Amber/Green only with a commercial tier + DPA.

D3. Sector overlay — shift vs the general baseline

Where sector duties tighten or override the general verdict
Workflow Law firm Accounting firm Real estate Media / marketing
1 Drafting AmberStricter (privilege) AmberStricter (confidentiality) Amber Amber+ copyright caveat
2 Memory / projects RedUnless strict per-matter isolation (conflicts) RedUnless isolation Amber Amber
3 Agentic inbox RedPrivilege, tipping-off RedSTR tipping-off RedSTR Amber
4 Local folders AmberPrivileged files excluded AmberSTR files excluded AmberCDD / ID docs excluded Amber
7 Output AmberCourt disclosure + citation verification mandatory AmberAudit / independence rules Amber AmberOwnership / defamation

D4. The Red list — do not do these

Eight configurations that stay Red whatever the plan, sector or intention.

  1. Upload client, customer or employee personal data to Claude under consumer terms (Free/Pro/Max). Reason: no DPA, no s.26 transfer basis, trains by default. (PDPA ss.26, 24; Anthropic Consumer Terms.)
  2. Give an agent both untrusted-input access (a monitored inbox or website) and an outbound send or file-write capability without human review. Reason: lethal trifecta / prompt injection → exfiltration or wrong-recipient breach. (Anthropic browser-use guidance; security research.)
  3. Connect an agent to a shared drive or full mailbox with unscoped access. Reason: over-permissioned confused-deputy risk; Files API workspace-wide access. (Anthropic connector docs.)
  4. Process data the firm is contractually barred from disclosing to third parties (NDAs), even if the PDPA would permit it. Reason: contract overrides.
  5. File AI-generated work product with a court or regulator without human verification and required disclosure. Reason: Registrar’s Circular No. 1 of 2024; professional-conduct duties.
  6. Use Claude output as the basis for a decision about an individual without human review. Reason: Accuracy obligation; PDPC AI decision-systems guidelines.
  7. Put NRIC/FIN numbers or identity-document scans into Claude unredacted. Reason: PDPC NRIC Advisory Guidelines.
  8. Run STR / tipping-off-sensitive material through any agent or connector. Reason: CDSA tipping-off offence.

D5. Worked edge cases

Agent auto-drafts a reply containing a different client’s data: if sent, an unauthorised disclosure and likely a notifiable breach. Mitigation: never auto-send; human review; per-matter isolation.

Red if auto-send is enabled

Customer emails an unsolicited NRIC scan into a monitored mailbox: the agent processing it is a use of NRIC data, likely outside exceptions. Mitigation: auto-quarantine attachments, redact, restrict read scope.

Amber with redaction; Red if the agent auto-processes

Financial statements analysed under a personal Pro account: no DPA, trains by default, cross-border non-compliant, likely breaches engagement-letter confidentiality.

Red

Staff member’s personal Claude account used on firm data (shadow AI): unauthorised disclosure by the firm; consumer terms; potential breach.

Red — detect and remediate

Third-party MCP server granted broad filesystem scope: supply-chain + confused-deputy risk; data may leave the DPA.

Red unless vetted, scoped, read-only

Law firm Projects workspace holding two adverse clients’ matters: conflicts and confidentiality risk if context bleeds.

Red unless strict per-matter project isolation is configured and verified

D6. One-page client-facing summary

Do this

  • Use Claude on a Team or Enterprise plan (or via AWS Bedrock / Google Vertex in Singapore) — never a personal Free/Pro/Max account — for anything involving customer, client or staff information.
  • Redact NRICs, FINs and ID scans before uploading.
  • Keep a human reviewing every email, document or filing before it goes out.
  • Give connectors the least access needed (one folder, read-only).
  • Tell your customers, in your privacy notice, that you use an overseas AI tool.

Don’t do this

  • Don’t paste client data into a personal or free Claude account.
  • Don’t let Claude send emails or change files by itself.
  • Don’t connect Claude to your whole inbox or entire shared drive.
  • Don’t put in anything a contract or NDA says you must keep confidential.
  • Don’t file AI-written work with a court or regulator without checking every fact and citation.

Ask us first

  • Before connecting Claude to accounting or CRM systems.
  • Before any “agent” that reads incoming mail.
  • If you are MAS-regulated, a law or accounting firm, or handle payment-card data.

Part E — Security and privacy beyond legal minimums

The lethal trifecta Three overlapping circles labelled private data access, untrusted content, and exfiltration channel. Where all three overlap is the danger zone: an agent holding all three capabilities at once can be manipulated into leaking data. Private data access Untrusted content Exfiltration channel Danger zone
The “lethal trifecta”: an agent that can read private data and ingest untrusted content and send anything outbound holds all three ingredients of a prompt-injection exfiltration. Remove any one circle and the attack collapses.
  1. Prompt injection / confused deputy (the highest risk here). An agent reading untrusted inbound email while holding write access and outbound send is the “lethal trifecta”: private-data access + untrusted content + exfiltration channel. Documented against many production systems; Anthropic itself acknowledges the trifecta for browser use and reports materially improved but non-zero robustness — its published browser/agent indirect-prompt-injection benchmark figures for recent models are on the order of ~1% or below with safeguards enabled, but the raw attack-success rate on the browser surface without safeguards has been reported around 30–50% for recent models (figures vary by benchmark and model and should be reconciled against Anthropic’s current system card and Transparency Hub before quoting). The key point stands: the residual rate is low but non-zero, and it compounds over repeated actions. (Sources: Anthropic system card / Transparency Hub / browser-use guidance; Simon Willison, “lethal trifecta”; MDPI review. Verified that the risk exists and is acknowledged; specific percentages Partially documented and version-dependent.) Mitigations: separate read from write; human-in-the-loop on all outbound actions and deletions; never combine untrusted input with an exfiltration channel in one session; egress controls; treat all tool-returned content as data, not instructions; sandbox with least privilege.
  2. Least privilege for connectors: dedicated service accounts; scoped folders and labels, not full-mailbox; read-only by default; short-lived tokens; periodic scope review; Owner-controlled allowlist.
  3. Data minimisation at the boundary: pre-upload redaction; a segregated “safe-for-AI” folder structure; policy-only controls fail without technical enforcement (path allowlists, read-only modes).
  4. Endpoint security at SME budget: full-disk encryption (mitigates plaintext ~/.claude transcripts), MDM, screen lock, local-cache handling, offboarding. CSA Cyber Essentials is the attainable baseline (five control areas — Assets, Secure/Protect, Update, Backup, Respond; SME co-funding available until 6 Feb 2028; now covers cloud, AI and OT security). (Source: csa.gov.sg. Verified)
  5. Shadow AI: staff using personal accounts on firm data — detect (network/DNS, expense claims), prevent (provide sanctioned Team/Enterprise access; acceptable-use policy), remediate (offboard, breach-assess).
  6. Monitoring and audit: use Enterprise audit logs + the Compliance API; log connector usage; retain enough to reconstruct an incident.
  7. Output accuracy / human review: hallucination risk in financial, legal and regulatory output; automated decisions about individuals attract Accuracy-obligation and AI-guidelines scrutiny.
  8. Vendor concentration / exit: portability, continuity, and the fact that terms, subprocessors and retention change frequently — monitor and re-paper.

Part F — Governance pack for SMEs

Sized for a firm without in-house counsel:

  • AI acceptable-use policy (which plan, what data is allowed, redaction rules, no shadow AI). (The MinLaw guide’s Annex C provides a sample GenAI governance policy for law firms.)
  • Proportionate DPIA in the form PDPC expects (PDPC provides SME templates via the Data Protection Essentials programme and the Guide to DPIAs).
  • Record of processing (data, purpose, basis, transfer mechanism, retention).
  • Privacy-notice language covering AI processing and cross-border transfer.
  • Vendor due-diligence record (Anthropic DPA, SOC 2 / ISO certificates, subprocessor list).
  • Connector approval and review process (Owner allowlist, scope review).
  • Staff training; an incident runbook covering AI-specific incidents (prompt injection, wrong-recipient send, shadow-AI leak) mapped to the 3-day PDPC clock.
  • Review cadence tied to Anthropic terms and subprocessor changes.

PDPC’s Data Protection Essentials and Guide to Managing Data Intermediaries already provide much of this scaffolding for SMEs. (Source: pdpc.gov.sg. Verified)

Quiet glass-walled meeting room with an empty table and chairs
Photo by Hammer Group on Unsplash

Part G — The consultant’s position

  • Where consulting shades into legal advice: interpreting whether a specific transfer satisfies s.26, whether privilege is waived, whether an engagement letter permits disclosure, or whether a firm meets sector-licensing conditions — these are legal questions; we advise generally and refer to a Singapore-qualified lawyer for a formal opinion.
  • Disclaimers: recommendations are technical and operational, not legal advice, and vendor facts were verified as at 20 Aug 2026 and change.
  • Engagement letter: scope, reliance limits, the client’s responsibility to obtain legal sign-off on cross-border, privilege and sector matters, and that the client must implement and maintain controls.
  • Professional indemnity: recommending a configuration that later causes a breach is a real exposure — carry PI insurance, document the basis of each recommendation, and record the client’s decisions.

Part H — Vendor question list

For Anthropic (send verbatim):

  1. For a Singapore-incorporated customer on Team/Enterprise, is the DPA at anthropic.com/legal/data-processing-addendum the operative contract, and do its SCCs satisfy a PDPA s.26 “comparable protection” transfer?
  2. When a user attaches a local file in Claude Desktop / Claude.ai, what exactly is transmitted — full file, extracted text, chunks, or embeddings — and is any part processed on-device?
  3. Does Cowork/Desktop build and persist a local index of an attached directory? Where is it stored, and is it encrypted at rest?
  4. What does the desktop app write to disk per OS (caches, logs, transcripts, tokens, connector config), with what at-rest protection, and what survives sign-out and uninstall?
  5. Confirm default and configurable retention for chats, uploaded files, memory, and projects per tier — and the exact backend-purge timeline after deletion.
  6. Confirm which products and features are ZDR-eligible, and confirm the up-to-2-year safety-flag retention applies even under ZDR.
  7. For memory and projects on Team/Enterprise: is data per-user or org-wide, can admins view, export and purge it, and how is per-project isolation enforced and audited?
  8. For remote MCP connectors: where are OAuth tokens stored, does Anthropic ever hold third-party credentials, and does connector data traverse Anthropic infrastructure?
  9. Which connector and third-party data flows fall outside the Anthropic DPA, and what governs them?
  10. Is Singapore ap-southeast-1 data residency available for storage as well as inference via Bedrock/Vertex, and who is the data processor and controller in that configuration?
  11. Audit-log and Compliance API: event coverage, retention, and exportability; can we evidence connector usage and outbound actions?
  12. Subprocessor list and change-notification period; security-incident notification commitment and timeline; audit rights; liability posture — per tier.

For third-party MCP providers:

  1. Where is data processed and stored (region), and under what terms and DPA?
  2. What OAuth scopes are requested; is read-only available; are tokens short-lived?
  3. What certifications (SOC 2 / ISO 27001) do you hold, and will you sign a PDPA-compliant processing agreement?

Part I — Sources and further reading

I1. Full source list (by tier; all retrieved 20 August 2026)

Singapore government / regulators

  • Personal Data Protection Act 2012 (as amended) — Singapore Statutes Online.
  • Personal Data Protection Regulations 2021; Personal Data Protection (Notification of Data Breaches) Regulations 2021 — sso.agc.gov.sg.
  • PDPC, Advisory Guidelines on Key Concepts in the PDPApdpc.gov.sg.
  • PDPC, Advisory Guidelines on the PDPA for Selected Topics (Employment, Anonymisation, Cloud) — pdpc.gov.sg.
  • PDPC, Advisory Guidelines for NRIC and Other National Identification Numbers (31 Aug 2018) — pdpc.gov.sg.
  • PDPC, Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (2024) — pdpc.gov.sg.
  • PDPC, Guide on Managing and Notifying Data Breaches (15 Mar 2021) — pdpc.gov.sg.
  • PDPC, Guide to Managing Data Intermediaries; Guide to Basic Anonymisation; Data Protection Essentials — pdpc.gov.sg.
  • IMDA / AI Verify Foundation, Model AI Governance Framework for Generative AI (30 May 2024) — aiverifyfoundation.sg / imda.gov.sg.
  • CSA, Cyber Essentials and Cyber Trust marks — csa.gov.sg.
  • MAS, Guidelines on Outsourcing Risk Management; Technology Risk Management Guidelines and TRM Notices — mas.gov.sg.
  • CEA, AML/CFT framework; Estate Agents (PMLPFTF) Regulations 2021 — cea.gov.sg / sso.agc.gov.sg.
  • MinLaw, Guide for Using Generative AI in the Legal Sector (6 Mar 2026) — mlaw.gov.sg.
  • Supreme Court / State Courts / FJC, Registrar’s Circular No. 1 of 2024 — Guide on the Use of Generative AI Tools by Court Usersjudiciary.gov.sg.
  • Copyright Act 2021 — sso.agc.gov.sg.

Anthropic official

Professional bodies / legal commentary

  • Law Society of Singapore, Advisory on the Use of Publicly Available AI Toolslawsociety.org.sg.
  • ISCA Code of Professional Conduct and Ethics — isca.org.sg.
  • Allen & Gledhill; Rajah & Tann; Drew & Napier; Baker McKenzie Wong & Leow; Herbert Smith Freehills — cited for interpretation, traced to primary instruments.
  • Asia Pacific Publishing Pte Ltd v Pioneers & Leaders (Publishers) Pte Ltd [2011] SGCA 37.

I2. Annotated further reading (with review cadence)

  • PDPA + Key Concepts Guidelines — the backbone; defines data intermediary, consent, transfer. Review annually and on amendment.
  • PDPC NRIC Advisory Guidelines — decides most redaction rules. Review on update.
  • PDPC Data Breach guide — your incident-runbook source (3-day clock). Review annually.
  • IMDA MGF for GenAI — governance scaffolding; recommendation, not law. Review on new edition.
  • MinLaw GenAI legal-sector guide + Registrar’s Circular 1/2024 — mandatory reading for law-firm and litigation-facing clients. Monitor for new circulars.
  • MAS Outsourcing + TRM Guidelines — for MAS-regulated clients; expectations exceed the PDPA. Review on revision.
  • Anthropic legal + trust pages + subprocessor list — product facts change frequently. Review quarterly and on any Anthropic terms email.
  • CSA Cyber Essentials — attainable security baseline and procurement signal. Review at re-certification (2-yearly).

Sources to monitor for change (suggested cadence): PDPC enforcement decisions and guidance (quarterly); IMDA guidance (semi-annual); Anthropic terms, retention, ZDR and subprocessor pages (quarterly and on notice); court practice directions and registrar’s circulars (on issue).

Limitations

This is research and analysis, not legal advice. A Singapore-qualified lawyer should review before any client relies on it — particularly on: (1) whether Anthropic’s DPA/SCCs satisfy s.26 for a given data set; (2) legal professional privilege and waiver risk; (3) sector licensing conditions (MAS, CEA, ISCA/ACRA) and AML tipping-off; and (4) contractual and NDA constraints that override the statutory position. Product facts about Claude were verified against Anthropic documentation as at 20 August 2026 and are the findings most likely to go stale — re-verify retention windows, ZDR scope, connector behaviour, residency options, subprocessors and the browser/agent prompt-injection benchmark figures before implementation. Several Part C items are marked Not publicly documented and require direct answers from Anthropic (Part H).

This is general guidance, not legal advice. IMCI AI Software does not provide legal services. Nothing on this page creates a solicitor–client or advisory relationship. Singapore’s data protection requirements depend on your specific circumstances, sector and contracts — always consult a Singapore-qualified lawyer before acting on anything here. Product and regulatory facts were verified as at 20 August 2026 and change frequently. Re-verify before relying on them.