PDPA Compliance Checklist for AI in HR
Half the AI-in-HR questions HR leaders bring to FPA are actually PDPA questions in disguise. "Can I paste this into ChatGPT?" is really "Which PDPA obligation applies to this data class, and can I discharge it against a US-hosted LLM?" This checklist gives you a working answer for every day of the week.
The one-page summary
Three PDPA anchors matter for AI in HR:
- Consent Obligation — you need a valid basis (consent or a listed exception) to collect, use, or disclose personal data. Pasting into an LLM is a "use" and, if the LLM provider retains or trains on it, a "disclosure".
- Purpose Limitation Obligation — the AI use must be within the purpose the employee consented to at collection. "For processing your employment" typically covers admin; it does not automatically cover "training a third-party AI model".
- Transfer Limitation Obligation (Section 26) — personal data can only leave Singapore if the receiving organisation is bound to a comparable standard of protection. In practice this means a Data Processing Agreement with the AI vendor.
The data classes checklist
What you can — and cannot — put into a public LLM (ChatGPT free, Claude free, Gemini free) versus an enterprise instance with a signed DPA:
| Data class | Public LLM (free tier) | Enterprise tier w/ DPA | Notes |
|---|---|---|---|
| Fully anonymised policy text (no names, no NRIC) | OK | OK | Verify de-identification is robust. |
| A job description (no candidate data) | OK | OK | Watch for TAFEP bias language. |
| Interview questions (generic) | OK | OK | Standard use. |
| Candidate CV or resume | NO | CONDITIONAL | Requires DPA + purpose consent at application. Redact NRIC. |
| Employee performance data | NO | CONDITIONAL | DPA + explicit HR-processing purpose. Consider pseudonymisation. |
| Salary or compensation data | NO | CONDITIONAL | Sensitive under PDPA norms. Aggregate ranges only where possible. |
| NRIC / FIN / passport numbers | NO | NO | Never. Strip before any AI use. |
| Medical certificates or health data | NO | NO | PDPA-sensitive category. Human-only handling. |
| Grievance / disciplinary narrative | NO | CONDITIONAL | DPA + strict need. Prefer anonymised summary. |
| Whistleblower / investigation content | NO | NO | Confidentiality overrides efficiency. |
The cross-border question — PDPA Section 26
Most enterprise LLMs process data outside Singapore (US, EU, Ireland, sometimes Japan). Section 26 obliges the transferring organisation — you, the employer — to ensure the recipient is bound to a comparable standard. Practical steps:
- Get the vendor's Data Processing Agreement and confirm it names PDPA or an equivalent (GDPR is usually treated as equivalent).
- Confirm the data-residency options — some enterprise tiers offer regional processing.
- Confirm zero training on your submissions (this is standard on enterprise but not on free tiers).
- Log the DPO sign-off before onboarding the tool.
The DPO sign-off template
Every AI-in-HR tool should get a one-page DPO sign-off covering:
- Tool name, vendor, and tier (free / team / enterprise)
- Purpose scope (drafting only? decision support? autonomous?)
- Data classes permitted (referenced against the table above)
- Data classes prohibited
- Cross-border processing location
- Retention and deletion terms
- Human-review requirement (mandatory for hiring / termination decisions)
- Review cadence (quarterly for the first year)
- DPO name, date, signature
FPA hands this template to every workshop participant. The AI for HR Foundations workshop walks a live example.
Retention and deletion
PDPA's retention limit says you must cease retention when the purpose is no longer served. Practical implications for AI:
- Do not use LLM chat history as a de facto HR record — export the decision, then delete the chat.
- Prefer AI vendors that offer zero-retention API modes for regulated workflows.
- If a candidate withdraws or is rejected, ensure any AI-processed record of them is deleted per your candidate-retention policy.
The five most common PDPA mistakes in AI-in-HR
- Pasting a full CV into a personal ChatGPT account to "help write feedback for the hiring manager".
- Using a public LLM to draft a termination or performance letter with the employee's name in the prompt.
- Uploading an entire HR handbook (which contains PII in examples) into a public LLM knowledge base.
- Building a candidate-screening bot on a free-tier LLM and calling it "assistive".
- Not logging any of the above, so when the DPO asks "what AI touched this decision", nobody knows.
Frequently asked PDPA-AI questions
Do I need candidate consent to use AI in screening?
You need a lawful basis. Practically, add an AI-use notice to your candidate privacy statement and application form. The PDPC has signalled that meaningful transparency matters more than a specific "AI consent" checkbox.
Is Microsoft Copilot for M365 PDPA-safe by default?
Microsoft's enterprise terms are strong, but PDPA compliance still rests on how you configure it — which users, which SharePoint scopes, which retention. Do not skip the DPO review because it is Microsoft.
What about Singapore-hosted AI?
Increasingly available — AWS Bedrock, Azure OpenAI, and Google Vertex all have Singapore regions. Data residency is not itself a PDPA requirement, but it simplifies the Section 26 conversation.
Get your HR team PDPA-anchored on AI in one day
FPA's AI for HR Foundations workshop walks this checklist live, drafts your DPO sign-off template with your DPO in the room, and leaves your team with a defensible AI-in-HR policy.
Book a discovery call Read the pillar guide →Related guides: The 2026 AI in HR Singapore Guide · TAFEP-Safe AI in Screening · 10 ChatGPT Prompts for Singapore HR
