The word Data on glass, representing customer information moving through AI-enabled marketing workflows
Commercial AI Governance July 2026 10 min read

Who Owns Customer Data Risk When Marketing Uses AI?

Key Takeaway

The business deploying the workflow owns the customer-facing response, while providers may carry separate duties.

Before approving an AI vendor, assistant or workflow, know what customer information enters, where it goes, who can access it, and who has authority to respond.

Commercial ownership

This article sits inside Full Court Press's commercial AI and revenue growth work. For workflow readiness, use the Agentic Readiness Diagnostic. For the wider operating model, see Commercial AI Architecture and agentic AI systems for sales and revenue growth.

The business deploying the marketing workflow owns the customer-facing response to data risk. Vendors can carry separate legal duties, and the exact allocation varies by market and contract. The company whose name is on the customer journey still needs to trace the information, explain its use and name who has authority to act.

A customer enters her budget, timing and business problem into a chat window on your website. The assistant recommends a package, logs the exchange and passes a summary to a salesperson. Weeks later, she asks where her information went, what happened to it and who can correct the outcome.

Singapore's July 2026 PDPC guidance makes that management problem concrete. It identifies model providers, system providers and system deployers as distinct stakeholders, and says the deployer bears primary responsibility for ensuring its chosen system can meet the deployer's PDPA obligations. The guidance is advisory, the PDPA and subsidiary legislation prevail, and providers may carry duties of their own.

Full Court Press uses two operating terms to turn that responsibility into an inspectable customer journey.

FCP Customer Data Accountability Test

Customer Data Path

The Customer Data Path is the recorded route of one customer's information through every person, system, provider and output involved in an AI-assisted interaction.

It answers: Where did the information go, what happened to it, and where does it remain?

The word one is deliberate. Follow one complaint, sales call, recommendation, image or customer request from first input through processing, sharing, storage, output, retention and deletion. A real interaction gives leaders something they can inspect.

Customer Data Response Owner

The Customer Data Response Owner is the named person who can reconstruct the Customer Data Path, coordinate the teams and providers involved, correct the customer-facing outcome and change the workflow.

It answers: Who can bring the complete answer together and act on it?

This is operating accountability. Legal responsibility depends on the circumstances, contracts and statutory roles.

The FCP Customer Data Accountability Test asks two questions before an AI-assisted customer workflow is approved:

  1. Can we reconstruct the Customer Data Path for one real interaction?
  2. Is there a named Customer Data Response Owner with authority to act?

One-page approval matrix

FCP Customer Data Accountability Test approval matrix
Approval questionRequired answerRequired evidenceNamed personDecision
Where did the information go, what happened to it, and where does it remain?Complete Customer Data Path for one interactionData-flow map, account settings and provider detailsWorkflow ownerApprove / Hold
Who can bring the complete answer together and act on it?Named Customer Data Response OwnerEscalation route and decision authorityAccountable executive or delegateApprove / Hold

A clean answer to both questions gives leadership a documented basis for approval. A missing route or an owner without authority sends the workflow back for correction.

1. The path: follow one customer interaction

A supplier register lists approved tools and contracts. The Customer Data Path follows what actually happened to one customer's information across the people, accounts, settings, integrations and providers involved.

The route might begin in a public chatbot, continue through a CRM summary and lead score, produce a generated service reply, and end as a follow-up task for a salesperson. It might begin when an employee pastes a complaint into a consumer AI account. A white-labelled product can pass the same information through a wrapper, an integration partner and an underlying model provider.

For each step, record:

  • the customer information received or inferred;
  • the person, account, provider or integration that handled it;
  • the purpose and available legal basis or exception;
  • the output created and any customer-facing decision;
  • where the input, output and logs are stored or shared;
  • the retention and deletion position; and
  • the person who can correct the outcome or change the route.

The resulting path should let a leader start with the original interaction and reach every copy, summary, output and action that remains relevant.

2. The breaks in the path

Most gaps appear between the approved product name and the way people use the product in daily work.

Product plan and account settings

The exact product and account matter. OpenAI states that inputs and outputs from its business offerings, including ChatGPT Business, ChatGPT Enterprise and its API platform, are excluded from model training by default. Consumer ChatGPT has separate data controls, including a setting that determines whether conversations help improve models.

Anthropic states that chats and coding sessions from Claude for Work and its API are excluded from training by default, subject to limited routes such as explicit feedback or customer participation in a development programme. Its Free, Pro and Max consumer plans have separate controls and may use chats or coding sessions for model improvement when the user allows it, through explicit feedback or in safety-review cases.

Training is one entry in the path. Leadership also needs the account owner, retention setting, connected services, access permissions, public-sharing controls and the categories of information employees may enter.

Integrations, outputs and retention

A chatbot response can become a CRM note, an email draft, a lead score, an analytics event or a task assigned to another team. Each new output can have a different access list and retention period. The path needs to continue until the business can say where each material copy remains and how deletion or correction reaches it.

Provider documentation should also identify subprocessors, hosting locations, security access, model or product improvement uses, and the changes that require a fresh approval. A contract name alone cannot reconstruct those handoffs.

Public sharing

Anthropic's sharing guidance says consumer chats are private by default and that creating a share link makes a snapshot available to anyone with the link. Team and Enterprise sharing is limited to people in the same organisation.

Search Engine Land reported on 28 July 2026 that some public Claude share URLs appeared in search results. Its headline described "private chats", while the reported mechanism involved public share pages. TechCrunch separately reported public Claude share links and Artifacts appearing in search. No reviewed source established exposure of ordinary unshared chats.

The leadership question is specific: which public snapshots or Artifacts exist, what customer information appears in them, who created them and who can revoke them?

3. The owner: give one person authority to close the response

The Customer Data Response Owner can sit in commercial leadership, operations, product, privacy or another function. The decisive requirement is the authority attached to the named person.

That person must be able to:

  • obtain the complete Customer Data Path from every team and provider involved;
  • coordinate legal, privacy, security, procurement, marketing and customer-service action;
  • explain the outcome to the customer in usable language;
  • correct the customer-facing response or record where appropriate; and
  • pause or change the workflow when the evidence or control is weak.

The role also protects the employee who faces the customer. A comparative field study in the Journal of Management Studies' 2026 volume, first published online in November 2025, examined experts across banking, biotechnology and recruitment who had to present AI-generated decisions they could not easily overrule. A Customer Data Response Owner gives that employee access to an explanation, an escalation route and someone with authority to challenge the workflow.

Naming a committee or shared inbox leaves the central question unanswered. Leadership should be able to identify the person who can bring the complete answer together and decide what changes next.

4. The evidence leadership should expect

The evidence should connect the real customer interaction, the provider controls, the customer explanation and the named decision-maker.

Purpose, notice and customer choice

The final PDPC Advisory Guidelines on the Use of Personal Data in Generative AI were issued on 20 July 2026. They build on the PDPC's March 2024 Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, which cover recommendation, prediction and decision uses such as personalisation and recommendation engines.

The July guidance addresses user data used for large-scale Generative AI model training or fine-tuning. Unless deemed consent or a relevant statutory exception applies, consent is required and the individual must be told the purpose. Paragraph 4.6 encourages organisations, to the extent practicable, to explain the model functions that require personal data, the types of personal data involved, how the data will be used for training or fine-tuning, and how an individual can decline or withdraw consent.

Paragraph 4.8 allows consent to this additional use to be a condition of service only to the extent reasonable for providing that product or service. Paragraph 5.1 confirms that properly anonymised data falls outside the PDPA. The 2024 guidance says the Business Improvement Exception can be relevant to personalisation or recommendation engines when its conditions are met. These positions require a documented, use-case-specific assessment.

The separate Generative AI Chatbot Transparency Guidelines are voluntary. They encourage a Chatbot Information Card explaining in plain language what the chatbot does, its limitations, how data may be handled and how users can report issues. DBS, Google, Meta, OCBC and Singapore Airlines have indicated that they intend to use the guidelines as a reference. CNA reported on 20 July 2026 that organisations intended to refer to the guidance over the next six to twelve months; the source does not establish completed information cards.

An accurate card depends on an accurate Customer Data Path. A usable reporting route depends on a Customer Data Response Owner who can act on what the customer reports.

Provider and workflow evidence

Before approval, leadership should expect five connected records:

1
Purpose and legal position

The customer outcome, the data needed and the applicable lawful basis, consent route or exception.

2
Customer Data Path

The input, inference, output, account, integration, provider, storage, sharing, retention and deletion route for one interaction.

3
Customer explanation and choice

The notice, disclosure, correction, deletion, withdrawal, opt-out, objection or human-review route that applies.

4
Provider controls

Access, subprocessors, residency, retention, deletion, testing, incident handling and change notification.

5
Response authority

The named Customer Data Response Owner, escalation route and decisions that person can make.

These records should be reviewed while the campaign design, provider and customer promise can still change.

Market-specific overlay

The operating test stays consistent across markets. The legal analysis must follow the organisation, jurisdiction, sector, data and intended use.

Market-specific evidence for the Customer Data Accountability Test
MarketMain regulatory frameEvidence leadership should add
SingaporePDPA; 2024 AI recommendation and decision guidance; final 2026 GenAI guidance; separate voluntary chatbot-transparency guidanceProvider and deployer roles, purpose-specific assessment, consent or exception, customer choice, retention, deletion and an accurate public explanation.
European UnionGDPR and the EU AI ActController and processor roles, lawful basis, transparency, minimisation, rights handling, transfers, any required DPIA and the applicable AI Act transparency duty.
United KingdomUK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025Lawful basis, impact assessment, processor controls and safeguards for significant solely automated decisions, including information, representations, human intervention and contest routes.
United StatesFTC Act, sectoral federal laws and state privacy lawsState and sector scope, privacy promises, targeted advertising, profiling, sensitive data, retention, security, consumer rights and vendor restrictions.
AustraliaPrivacy Act 1988 and Australian Privacy PrinciplesNecessity, collection and secondary-use position, consent or reasonable expectations, accuracy, human oversight and controls over information entered, generated or inferred.

The EU GDPR places accountability around controllers and processors. The EU AI Act adds duties based on use and risk, including transparency provisions applying from 2 August 2026. The UK ICO says all data-protection provisions in the Data (Use and Access) Act 2025 were in force by 19 June 2026. A Congressional Research Service review describes the US federal framework as sectoral and records at least 19 state comprehensive consumer privacy laws. The Australian privacy regulator says obligations can apply to personal information entered into an AI product and to information generated or inferred in its outputs.

This table is a commercial orientation. Jurisdiction-specific advice should determine the final legal position for each deployment.

5. Test one live customer journey in the next meeting

Choose one recent complaint, sales call, recommendation, image or customer request. Ask the team to reconstruct it in the room:

  • What information did the customer provide, and what did the workflow infer?
  • Which exact product plan, account and settings were used?
  • Which people, providers, integrations and subprocessors handled the information?
  • Which outputs, summaries, logs or public shares were created?
  • Where does each material copy remain, and how would correction or deletion reach it?
  • What was the customer told about purpose, AI use, sharing and choice?
  • Which market, sector and data-type requirements apply?
  • Who is the Customer Data Response Owner, and can that person correct the outcome, revoke a share, pause the workflow and require a new approval?
  • Which provider, model, purpose or data change sends the workflow back for review?

A generic policy answer should trigger a request for the actual interaction, account settings, provider evidence and named decision-maker.

If the same customer asks tomorrow for a complete explanation and a correction, can one person bring the answer together before the gap becomes a public customer problem?

Important: This article provides general commercial-governance information. Legal advice should be obtained for the jurisdictions, sectors, data and workflows involved.

Sources and references

Photo: Claudio Schwarz on Unsplash

Singapore

Ministry of Digital Development and Information, Opening Speech by Minister Josephine Teo at Singapore Data Festival, confirming issue of the final Advisory Guidelines on the Use of Personal Data in Generative AI, 20 July 2026

Personal Data Protection Commission, Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, 1 March 2024

Personal Data Protection Commission, Advisory Guidelines on the Use of Personal Data in Generative AI, 20 July 2026

Channel NewsAsia, Singapore launches 'nutrition label' guidelines for GenAI chatbots, 20 July 2026

AI products, sharing and employee accountability

OpenAI, Business data privacy, security, and compliance, accessed 29 July 2026

OpenAI, Data Controls FAQ, updated 29 July 2026

Anthropic, How do you use personal data in model training?, 16 March 2026

Anthropic, How do you use personal data in model training? — consumer products, 16 March 2026

Anthropic, Share and unshare chats, 15 June 2026

Search Engine Land, Google indexed Claude Chats because Anthropic did not block your private chats from search engines, 28 July 2026

TechCrunch, PSA: Your Claude shared chats and Artifacts may have ended up on Google, 27 July 2026

Mayer, van den Broek and Karačić, Let Me Explain: A Comparative Field Study on How Experts Enact Authority Over Clients When Facing AI Decisions, first published online 8 November 2025; Journal of Management Studies, 2026 volume

European Union

European Union, General Data Protection Regulation, Regulation (EU) 2016/679

European Data Protection Board, Opinion 28/2024 on AI models and personal data

European Commission, AI Act regulatory framework and implementation timeline

European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, 20 July 2026

European Commission, Code of Practice on Transparency of AI-Generated Content

United Kingdom

Information Commissioner's Office, Guidance on AI and data protection

Information Commissioner's Office, Data (Use and Access) Act 2025: what it means for organisations, updated 19 June 2026

Information Commissioner's Office, Data protection summary of the Data (Use and Access) Act changes

United States

Congressional Research Service, Preemption and Privacy Law, 29 August 2025

Federal Trade Commission, Hey, Alexa! What are you doing with my data?, 13 June 2023

California Privacy Protection Agency, CCPA Updates, Cybersecurity Audits, Risk Assessments and Automated Decisionmaking Technology Regulations, effective 1 January 2026

Australia

Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products, updated 17 January 2025

Office of the Australian Information Commissioner, Guidance on privacy and developing and training generative AI models

Scope: This article provides general commercial interpretation only. Applicable duties vary by organisation, jurisdiction, state, sector, data type and use case. Obtain legal advice for the facts of each deployment.

Commercial AI readiness

Check the workflow before customer data enters it.

The Agentic Readiness Diagnostic reviews the goal, inputs, controls, human approval points and operating ownership behind an AI-enabled workflow. It covers workflow readiness; jurisdiction-specific legal review remains a separate requirement.

Run the Diagnostic Review Commercial AI Architecture
Commercial AI governance

Questions this article answers

Answers to common commercial questions about customer data, AI vendors and international privacy obligations.