Who Owns Customer Data Risk When Marketing Uses AI?
Key Takeaway
Your business remains responsible for customer information placed in an AI tool.
Before approving an AI vendor, assistant or workflow, know what customer information enters, where it goes, who can access it, and who has authority to respond.
Your business remains responsible for customer information placed in an AI tool. Before approving an AI vendor, assistant or workflow, know what customer information enters, where it goes, who can access it, and who has authority to respond when a question, complaint, incident or regulatory enquiry arises.
Across Singapore, the European Union, the United Kingdom, the United States and Australia, the legal route differs. The operating questions stay practical: purpose, notice, access, retention, deletion, customer rights and named ownership. Singapore's final Generative AI data guidelines provide the starting point for this five-market comparison.
For commercial leaders, the significance sits inside the customer journey. Marketing teams increasingly send transaction histories, messages, voice recordings, images, behavioural data, prompts and internal customer information into AI-enabled tools. Each use creates decisions about purpose, legal basis or permitted use, notice, access, retention, deletion, vendor safeguards and incident response.
The AI tool brings a data decision with it
A marketing team may buy a customer-service assistant, personalisation platform, campaign tool, lead-scoring application or sales agent through an ordinary software procurement. The interface can make the deployment feel routine. The data path is usually more complex.
FCP Customer Data Accountability Test
Full Court Press uses two operating terms to make customer-information responsibility actionable before an AI vendor, assistant or workflow is approved.
Customer Data Path
The documented route customer information follows through an AI-enabled commercial workflow, covering collection or input, processing, storage, sharing, output, retention and deletion.
Customer Data Response Owner
The named role with authority to coordinate and close the organisation's response when a customer, regulator or business partner asks a question, or when an internal incident requires action.
Together they form the FCP Customer Data Accountability Test:
- Can we trace the customer's information through this workflow?
- Who has the authority to respond when questions arise?
One-page approval matrix
| Approval question | Required answer | Required record | Named role | Decision |
|---|---|---|---|---|
| Can we trace the customer's information through this workflow? | Complete Customer Data Path | Data-flow map and vendor details | Workflow owner | Approve / Hold |
| Who has the authority to respond when questions arise? | Named Customer Data Response Owner | Escalation and response procedure | Accountable role | Approve / Hold |
Before approving an AI vendor, assistant or workflow, require documented answers to both questions and assign the response owner by role. These are FCP-defined operating terms developed for commercial governance. Applicable legal duties depend on the organisation, jurisdiction, sector, data type and intended use.
The official launch announcement confirms that on 20 July 2026, the Personal Data Protection Commission issued its final Advisory Guidelines on the Use of Personal Data in Generative AI after consulting industry and the public. The draft had been issued on 2 June 2026 and the public consultation closed on 1 July 2026. The final guidelines are advisory and clarify how the existing PDPA applies to Generative AI. The PDPA and subsidiary legislation prevail if an inconsistency arises.
The final guidelines identify model providers, system providers and system deployers as distinct stakeholders. A provider may process personal data to run inference, host data or improve a model. A system deployer may build in-house or buy through a SaaS or API offering. The deployer bears primary responsibility for ensuring that the chosen system can meet the deployer's PDPA obligations.
The provider's obligations still matter. The guidelines describe providers as organisations when they process personal data for their own model or system development, and as data intermediaries when they process it on behalf of downstream users. That allocation gives procurement teams more to verify, because responsibility and control can sit across several parties at the same time.
A vendor agreement can allocate duties and remedies. The deploying business still needs clear documentation showing that the customer-data journey is understood and controlled.
Singapore: general privacy wording may be too broad for AI training
The guidelines draw a clear line around user data used for large-scale model training or fine-tuning. Unless deemed consent or a relevant statutory exception applies, consent is required and the customer must be told the purpose of the intended use.
They also say broad statements such as "new product development" are insufficient for this type of training. An AI-specific notification should explain the model function, the types of personal data involved, how the data will be used for training or fine-tuning, and how an individual can decline or withdraw consent. The notification should be clearly visible through a route such as an in-product pop-up or dedicated webpage.
The Infocomm Media Development Authority's separate Generative AI Chatbot Transparency Guidelines are voluntary. They encourage a Chatbot Information Card explaining in plain language what the chatbot does, its limitations, how data may be handled and how users can report issues. At the launch, the Minister said DBS, Google, Meta, OCBC and Singapore Airlines would use the guidelines as a point of reference. For Google, this involves consolidating key information about the Gemini app and making it easier for users to find.
This changes the marketing brief. A campaign owner needs to know whether customer data is being used only to deliver the feature, retained in logs, routed to subprocessors, added to retrieval databases, or used to train and improve a model. Those are different data uses with different customer explanations and internal controls.
European Union: GDPR accountability sits beside AI Act transparency
The EU General Data Protection Regulation applies when personal data is processed within its scope. The controller determines the purposes and means of processing and remains responsible for GDPR compliance. A processor acts on the controller's instructions under a contract that covers the required safeguards and assistance.
For an AI-enabled marketing use, the controller needs an appropriate lawful basis, transparent information for individuals, data minimisation, security, rights handling and controls over processors and international transfers. Processing likely to create a high risk to people's rights and freedoms can require a data protection impact assessment before deployment.
The European Data Protection Board's Opinion 28/2024 on AI models explains that anonymity and the use of legitimate interests for developing or deploying AI models require case-specific assessment. The business still has to establish the underlying personal-data position behind a model label or vendor assurance.
The EU AI Act adds obligations based on the AI use and risk category. Its transparency provisions apply from 2 August 2026. They include informing people when they interact with an AI system such as a chatbot and labelling certain AI-generated or manipulated content. The European Commission published final guidelines on the Article 50 transparency obligations on 20 July 2026. Marketing teams operating in Europe therefore need to assess the data-protection position and the AI-specific disclosure duties that apply to the customer experience.
United Kingdom: data protection duties continue as automated-decision rules change
UK organisations work within the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025. The Information Commissioner's Office guidance on AI and data protection applies the familiar requirements of fairness, lawfulness, transparency, accountability and risk management to AI systems processing personal data.
The ICO confirmed that all data-protection provisions in the Data (Use and Access) Act 2025 were in force by 19 June 2026. The Act broadens the lawful bases available for significant decisions made solely through automated processing, while requiring safeguards such as information about the decision, a route for representations and human intervention. Special-category data remains more tightly protected.
The practical question for marketing is whether profiling, lead scoring, personalisation or customer eligibility produces a significant decision. A team needs to document the processing purpose, lawful basis, customer information, impact assessment, human review and vendor role according to the actual use.
United States: the campaign has to account for a federal, state and sectoral patchwork
The United States has a layered privacy framework. A Congressional Research Service review published in August 2025 describes federal law as sectoral and records at least 19 state comprehensive consumer privacy laws. These state regimes commonly provide rights such as access, correction and deletion, with obligations around targeted advertising, sensitive data and certain forms of profiling.
At federal level, the Federal Trade Commission can act against unfair or deceptive practices. Its enforcement guidance on AI and consumer data says businesses can be held accountable for how they obtain, retain and use the data powering algorithms. The FTC has also described orders requiring deletion of data products derived from unlawfully obtained or misused data.
State scope matters. California provides one useful example: CCPA regulations took effect on 1 January 2026. A risk assessment is required before covered processing initiated after that date begins. Covered processing already under way before the effective date has a transition deadline of 31 December 2027. Requirements for automated decision-making technology used in defined significant decisions begin on 1 January 2027 and include consumer access and opt-out rights for covered uses. The definition covers decisions such as lending, housing, education, employment and healthcare; advertising is excluded.
A single "US compliant" label provides too little information for an international campaign. The business needs a state and sector map covering where customers are located, which data is involved, whether targeted advertising or significant profiling occurs, which notices and opt-outs apply and which vendor terms support those duties.
Australia: inputs, outputs and inferred information all matter
The Australian Privacy Act 1988 and Australian Privacy Principles apply to covered organisations handling personal information through AI. The Office of the Australian Information Commissioner's guidance for commercially available AI products says privacy obligations can apply to personal information entered into a tool and to personal information generated or inferred in its outputs.
The OAIC directs organisations to assess whether collection is reasonably necessary, lawful and fair under APP 3. APP 6 can restrict a secondary AI-related use unless it is supported by consent or another permitted basis, including a related use within the individual's reasonable expectations. The regulator also recommends clear privacy policies and notices, visible identification of public-facing AI tools and due diligence on access, human oversight, privacy and security risks.
As a matter of best practice, the OAIC recommends keeping personal information, especially sensitive information, out of publicly available generative AI tools. For marketing teams, that creates a clear procurement distinction between an open consumer tool and an enterprise service with documented contractual and technical controls.
International comparison: what changes and what stays operationally important
| Market | Main regulatory frame | Where business responsibility sits | Customer-facing requirement | Approval focus |
|---|---|---|---|---|
| Singapore | PDPA plus final GenAI advisory guidelines; separate voluntary chatbot-transparency guidelines | The PDPC guidance places primary responsibility on the system deployer; providers may have their own organisation or data-intermediary duties. | Purpose-specific notice and, for covered training or fine-tuning uses, AI-specific information and customer choice; voluntary chatbot information cards. | Provider role, consent or exception, access, residency, retention, deletion, leakage controls and customer-facing chatbot explanations. |
| European Union | GDPR plus the EU AI Act | The controller remains accountable for purposes, means and processor oversight; provider or deployer duties may also arise under the AI Act. | GDPR transparency and rights; AI interaction or content disclosures for covered AI Act uses. | Lawful basis, DPIA, processor contract, transfers, minimisation, rights handling and applicable AI Act category. |
| United Kingdom | UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025 | The controller remains accountable, with processors acting under documented instructions. | Clear privacy information; safeguards around significant solely automated decisions, including human intervention routes. | Lawful basis, impact assessment, profiling significance, special-category data, processor controls and review rights. |
| United States | FTC Act, sectoral federal laws and state privacy laws; California shown as an example | Responsibility depends on the entity, sector, state, data and use; vendor allocation leaves the business responsible for its own unfair or deceptive practices. | State notices, access, deletion, correction, opt-out and sensitive-data requirements where applicable. | State and sector scoping, privacy promises, targeted advertising, profiling, retention, security and vendor restrictions. |
| Australia | Privacy Act 1988 and Australian Privacy Principles | The covered entity remains responsible for its collection, use, disclosure, security and accuracy obligations. | APP notices, privacy-policy transparency and clear identification of customer-facing AI interactions. | Necessity, primary or secondary purpose, consent or reasonable expectations, accuracy, human oversight and vendor access. |
The table is a commercial orientation tool. Coverage, definitions, exemptions, sector rules and enforcement positions vary. Jurisdiction-specific advice should determine the final legal position for each deployment.
Vendor due diligence becomes part of campaign readiness
The final guidelines encourage model and system providers to document safeguards such as access controls, data residency, retention policies, input and output filters, privacy-enhancing measures and data-leakage testing. System deployers are expected to obtain enough information about upstream safeguards to assess the chosen system as a whole.
That moves several questions into the commercial approval process:
- Where are prompts, inputs, outputs and logs stored and processed?
- Does the provider use customer data to train, fine-tune or improve its models?
- Which employees, subprocessors and systems can access the data?
- How long is the data retained, and how is deletion verified?
- What testing covers data leakage, prompt injection, unauthorised access, accuracy and harmful outputs?
- How will the provider support access, correction, deletion, withdrawal, opt-out and incident-response requests?
- Which changes to models, terms, subprocessors or data locations require notice or approval?
A legal or procurement review at the end of the project often arrives too late. By then, the campaign design, workflow, customer promise and vendor dependency may already be fixed. The stronger operating pattern brings marketing, data protection, legal, security, procurement and the commercial owner into the design while choices can still change.
Five checks before an international AI-enabled campaign goes live
The approval decision becomes easier when leadership can answer five linked questions.
What customer outcome requires the data, and which lawful basis, consent route or exception supports the use in each relevant market?
Which personal data appears in prompts, uploads, transaction histories, retrieval sources, outputs, logs and agent activity? Which new personal information can the AI infer or generate?
What will customers be told about the AI use, and how can they exercise access, correction, deletion, withdrawal, opt-out, objection or human-review rights where applicable?
What has the provider documented about storage, residency, transfers, access, subprocessors, retention, deletion, testing and incident handling?
Who approves the use case, monitors live behaviour, manages provider and model changes, handles customer requests and coordinates a regulator or incident response?
Ownership has to travel with the campaign
The five markets use different legal concepts, thresholds and enforcement routes. They still create a common operating demand for international marketing teams: know the purpose, minimise the data, explain the use, verify the provider, support customer rights and name the owner.
A practical global standard can set the strongest workable controls as the internal floor, then add jurisdiction-specific requirements for the market, sector, data and use case. This reduces the risk of rebuilding governance after a campaign has launched and gives commercial leaders a clearer basis for approving the expected return.
If a regulator, customer or board asks tomorrow why this data entered an AI workflow, who can produce the purpose, notice, contract, retention decision and monitoring records?
Important: This article provides general commercial-governance information. Legal advice should be obtained for the jurisdictions, sectors, data and workflows involved.
Photo: Claudio Schwarz on Unsplash
Singapore
Personal Data Protection Commission, public consultation cover note and closing date, 2 June 2026
Channel NewsAsia, Singapore launches 'nutrition label' guidelines for GenAI chatbots, 20 July 2026
European Union
European Union, General Data Protection Regulation, Regulation (EU) 2016/679
European Data Protection Board, Opinion 28/2024 on AI models and personal data
European Commission, AI Act regulatory framework and implementation timeline
European Commission, Code of Practice on Transparency of AI-Generated Content
United Kingdom
Information Commissioner's Office, Guidance on AI and data protection
United States
Congressional Research Service, Preemption and Privacy Law, 29 August 2025
Federal Trade Commission, Hey, Alexa! What are you doing with my data?, 14 June 2023
Australia
Scope: This article provides general commercial interpretation only. Applicable duties vary by organisation, jurisdiction, state, sector, data type and use case. Obtain legal advice for the facts of each deployment.
Check the workflow before customer data enters it.
The Agentic Readiness Diagnostic reviews the goal, inputs, controls, human approval points and operating ownership behind an AI-enabled workflow. It covers workflow readiness; jurisdiction-specific legal review remains a separate requirement.
Run the Diagnostic Review Commercial AI ArchitectureQuestions this article answers
Answers to common commercial questions about customer data, AI vendors and international privacy obligations.
The legal allocation varies by jurisdiction and contractual role. The business deploying the workflow still needs to establish its purpose, legal basis or permitted use, customer information, vendor controls, retention, rights handling and operational ownership. A provider may carry separate duties.
Each market takes a different route. Singapore's final PDPC guidance focuses on deployers and providers under the PDPA, while separate IMDA guidance addresses voluntary chatbot transparency. The EU and UK use controller and processor duties. Australia applies the Privacy Act and APPs. The United States combines federal, state and sector-specific requirements.
For large-scale Generative AI model training or fine-tuning using user data, the guidelines say broad statements such as new product development are insufficient and AI-specific notifications should be provided. Deemed consent and statutory exceptions may still apply in some circumstances.
EU and UK data protection rules require a lawful and transparent basis for processing personal data. In the EU, AI Act transparency provisions applying from 2 August 2026 also require disclosure for covered interactions such as chatbots. In the UK, significant solely automated decisions require appropriate safeguards under the Data (Use and Access) Act framework.
US privacy law combines federal sector rules, FTC enforcement and a growing group of state comprehensive privacy laws. Coverage and customer rights can change with the state, sector, data type, targeted-advertising activity and use of profiling or automated decisions.
Contracts can allocate instructions, safeguards, assistance, liability and remedies. The deploying business still needs to assess whether its own collection, use, disclosure, notice, rights handling and oversight meet the requirements applying to the workflow.
