AI grants, the PDPA and data security
Two questions come up in almost every first call: is there government support for this, and is our data safe? These answers give the general picture and point you to the official sources. They are not legal or grant advice; always check the current criteria.
8 questions · Updated
Can the PSG grant be used for AI solutions?
Possibly, if the specific AI solution and its vendor are pre-approved under the Productivity Solutions Grant (PSG) and your business meets the eligibility criteria. PSG supports pre-approved IT solutions listed on GoBusiness; it is not general funding for any AI project. Check the current list and apply before you sign or pay.
Read the full answerCan the Enterprise Development Grant (EDG) fund an AI project?
It may. The Enterprise Development Grant (EDG), administered by Enterprise Singapore, supports projects that help eligible companies upgrade their capabilities, innovate or expand overseas, and can cover qualifying costs such as third-party consultancy, software and equipment. Approval depends on the project and the company, so check the criteria and apply before the project starts.
Read the full answerHow does the PDPA apply when a business uses AI tools?
The PDPA applies to personal data whether a person or an AI system handles it. You still need consent or another legal basis, a clear purpose, reasonable security, limits on retention, and care when data is transferred overseas, for example to an AI provider. The PDPC has issued guidance on personal data in AI systems that is worth reading.
Read the full answerCan our staff put customer data into ChatGPT?
Not into personal or free accounts. Customer personal data should only go into AI tools your company has approved, on business plans with terms that exclude your data from training and give you admin control, and only when needed for the task. Even then, remove identifiers where you can. Set this out in a written AI policy.
Read the full answerWhat should a company AI policy include?
A practical AI policy fits on one or two pages and covers: which AI tools are approved, what data must never be entered, when AI output must be checked by a person, who is accountable for AI-assisted work, how to disclose AI use to customers where relevant, and who to ask for help. Train everyone on it and review it regularly.
Read the full answerWhere is our data stored when we use AI tools?
It depends on the provider and plan. Many AI services process data in data centres outside Singapore, such as the US, unless you choose regional processing where it is offered. Check each provider's data-processing terms for location, retention, training use and sub-processors, and prefer setups where your records stay in your own systems.
Read the full answerWhat is Singapore's Model AI Governance Framework?
It is voluntary guidance, first issued by the PDPC and IMDA and later extended to generative AI, that helps organisations use AI responsibly. It covers accountability, human oversight, data quality, transparency with customers, testing and incident handling. It is not a law, but it is a useful checklist for any business deploying AI.
Read the full answerHow do we keep AI systems and automations secure?
Give each AI system only the access it needs, use company accounts with two-factor login, log every action, keep sensitive steps behind human approval, protect API keys, and test for prompt injection, where text in an email or document tricks the AI into doing something it should not. Review access whenever staff or vendors change.
Read the full answer
More topics
Want these answers applied to your business?
In a free 30-minute call we look at how the work is done today and show you exactly what we would take over. No commitment, no sales deck.