← Back to list

Before You Paste That Contract into ChatGPT: What Singapore’s New PDPC Guidelines Mean for You

Why the way you extract data from contracts, invoices and HR documents with AI chatbots is about to come under closer scrutiny, and what to…

Ian Loe · 2026-07-28 02:53 · 0 claps · 4.9 min read
#ai-law #singapore #privacy
Open on Medium ↗
Wiki topics: LLM · Large Language Models AI · AI · General 🔒 · Cybersecurity ⚖️ · Law & Justice

Before You Paste That Contract into ChatGPT: What Singapore’s New PDPC Guidelines Mean for You

Why the way you extract data from contracts, invoices and HR documents with AI chatbots is about to come under closer scrutiny, and what to do about it.

There is a habit that has quietly become part of daily work for a lot of professionals in Singapore (especially for SME). A contract lands in the inbox, an invoice needs reconciling, an HR letter needs summarising, and instead of reading line by line, we paste the whole document into an AI chatbot and ask it to extract the key terms. It is fast, it is convenient, and until recently, almost nobody stopped to ask what happens to the personal data sitting inside that document once it leaves our screen.

On 2 June 2026, Singapore’s Personal Data Protection Commission (PDPC) issued its Proposed Advisory Guidelines on Use of Personal Data in Generative AI, opening a public consultation on how the Personal Data Protection Act 2012 (PDPA) applies across the generative AI lifecycle. The consultation has since closed, and the guidelines are not yet final or legally binding. But they signal clearly where the regulator’s thinking is heading, and for anyone whose daily workflow includes feeding contracts, invoices, payslips or HR correspondence into an AI chatbot, that direction matters now, not just once the final version is gazetted.

What the guidelines actually cover

The Proposed Guidelines are organised around the generative AI lifecycle: development, deployment and post-deployment. They address three things in particular:

  • How personal data may be collected and used to develop generative AI models in the first place
  • How data protection responsibility is allocated across model providers, system providers and system deployers
  • How organisations should handle individuals’ access and correction requests when their personal data has passed through a generative AI system

That middle point is the one most relevant to the everyday user extracting information from documents. A contract typically contains counterparty names, signatories, addresses and sometimes NRIC or passport numbers. An invoice contains billing names, contact details and sometimes bank account information. The moment you paste that into a chatbot, you are not just using a tool, you are engaging in an act of personal data processing under the PDPA, and the guidelines make clear that the party doing the deploying carries real obligations for that.

Why this matters even if you are “just extracting information”

There is a common assumption that extraction is a lower-risk activity than generation. You are not asking the AI to invent anything, you are asking it to summarise what is already there. The Proposed Guidelines push back on that assumption in a few ways worth understanding.

First, purpose limitation still applies. If your organisation deploys a generative AI system for contract review, that system should be scoped and configured for that specific purpose, with only the personal data necessary for it. A general-purpose consumer chatbot, used informally by an individual employee to speed through a stack of invoices, was very likely never notified to anyone as a channel for processing their personal data, and that is precisely the gap the guidelines are trying to close.

Second, the guidelines are explicit that vague notifications will not suffice going forward. Referring to data use for “new product development” or “service improvement” without specifying generative AI is treated as insufficient to discharge notification obligations. Extend that logic to the workplace, and a blanket “we use software to process your documents” line in an HR policy is unlikely to hold up if the tool doing the processing is a generative AI chatbot ingesting personal data at scale.

Third, retention and where that data goes next becomes a live question. Many consumer-grade AI tools retain conversation history, use inputs to improve their models unless you have opted out, or process data outside Singapore entirely. Under the guidelines’ allocation of responsibility across the AI lifecycle, the organisation deploying the tool, not just the AI vendor, carries accountability for understanding and controlling that.

The practical impact, by role

If you are an individual employee who has developed the habit of pasting contracts or payslips into a chatbot to save time, the guidelines do not target you personally, but they will very likely reshape what your employer allows. Expect tighter policies on which AI tools may be used for documents containing personal data, and possibly enterprise-approved tools replacing ad hoc consumer chatbot use.

If you are in a role that procures or deploys AI tools for teams, such as legal, HR, finance or IT, the guidelines put a spotlight on documentation. Good practice going forward includes recording what data access controls, data residency arrangements and retention policies apply to any generative AI system used on documents containing personal data, and making sure notifications to affected individuals actually name generative AI as a purpose, not just imply it.

If you sit in a governance or compliance function, this is a useful moment to map where generative AI touches document workflows across the organisation. Contract review, invoice processing, HR correspondence, customer onboarding documents. All of these routinely contain personal data, and under the proposed allocation of responsibility, “we didn’t know staff were doing this” is not going to be a comfortable position to defend.

Where this sits against frameworks like ISO 42001

This is one of the reasons I keep coming back to the value of lightweight, practical governance frameworks as a starting point rather than jumping straight to something as heavyweight as ISO 42001. Most organisations are not yet at the stage of a full management system for AI governance. What they need right now is something closer to what these PDPC guidelines are asking for directly: clear notification language, defined purposes, documented data flows, and sensible controls on which tools staff are allowed to use for what. That is squarely the kind of groundwork frameworks like FRAME and AAEF are built to help organisations put in place before they attempt certification-grade governance.

What to do this week, not after the guidelines are finalised

You do not need to wait for the final version to act sensibly. A few things worth doing now:

  • Check whether your organisation has an approved list of AI tools for handling documents that contain personal data, and if there is not one, ask who owns that decision
  • Avoid pasting contracts, invoices or HR documents containing personal data into consumer-grade chatbots unless you know the data handling terms and retention settings
  • If you manage a team, put a simple written note in place clarifying what tools are approved for document extraction work and why
  • Revisit your notification language to staff and customers, and check whether it actually names generative AI as a purpose of processing, not just a vague reference to “improving our services”

The PDPC’s proposed guidelines are, at their core, an attempt to catch up regulation with a habit that has already become routine. The convenience of dropping a contract into a chatbot and getting a clean summary back is real, and it is not going away. What is changing is the expectation that someone in the organisation has actually thought through where that data goes, who else can see it, and whether the person named in that contract ever agreed to it being processed that way. That is not a reason to stop using AI for this kind of work. It is a reason to start doing it with your eyes open.


메타데이터
post_id
140cde0773b1
slug
before-you-paste-that-contract-into-chatgpt-what-singapores-new-pdpc-guidelines-mean-for-you-140cde0773b1
url
https://medium.com/@ianloe/before-you-paste-that-contract-into-chatgpt-what-singapores-new-pdpc-guidelines-mean-for-you-140cde0773b1
canonical_url
https://medium.com/@ianloe/before-you-paste-that-contract-into-chatgpt-what-singapores-new-pdpc-guidelines-mean-for-you-140cde0773b1
author_url
https://medium.com/@ianloe
status
ok
fetched_at
2026-08-05 19:46:00