# Who Owns Customer Data Risk When Marketing Uses AI?

Canonical URL: https://www.fcpress.org/fcp-article-who-owns-customer-data-risk-marketing-ai
HTML page: https://www.fcpress.org/fcp-article-who-owns-customer-data-risk-marketing-ai
Markdown alternate: https://www.fcpress.org/fcp-article-who-owns-customer-data-risk-marketing-ai.md
Updated: 2026-07-23
Status: Live production bot-facing Markdown alternate. The HTML page remains canonical.
Hero image: The word Data on glass, representing customer information moving through AI-enabled marketing workflows.
Photo credit: Claudio Schwarz / Unsplash: https://unsplash.com/photos/a-close-up-of-a-window-with-a-building-in-the-background-fyeOxvYvIyY
Rights holder: Full Court Press Pte. Ltd. Singapore UEN: 202306714R.

Your business remains responsible for customer information placed in an AI tool. Before approving an AI vendor, assistant or workflow, know what customer information enters, where it goes, who can access it, and who has authority to respond when a question, complaint, incident or regulatory enquiry arises.

Across Singapore, the European Union, the United Kingdom, the United States and Australia, the legal route differs. The operating questions stay practical: purpose, notice, access, retention, deletion, customer rights and named ownership. Singapore's final Generative AI data guidelines provide the starting point for this five-market comparison.

## Key Takeaways

- Your business remains responsible for customer information placed in an AI tool.
- The FCP Customer Data Accountability Test requires a documented Customer Data Path and a named Customer Data Response Owner before approval.

- Singapore's final guidance says system deployers bear primary responsibility for ensuring their chosen AI systems can meet their PDPA obligations. Separate voluntary chatbot-transparency guidelines encourage a clear information card for users.
- The EU GDPR places accountability around controllers and processors, while the EU AI Act adds AI-specific transparency duties for particular uses.
- The UK applies the UK GDPR, Data Protection Act 2018 and the Data (Use and Access) Act 2025, supported by ICO guidance on fair, lawful, transparent and risk-managed AI use.
- The United States uses a federal, state and sectoral privacy framework. FTC enforcement and state laws such as California's CCPA can affect collection, retention, automated decisions and consumer rights.
- Australia's Privacy Act and Australian Privacy Principles apply to personal information entering an AI product and to personal information generated or inferred in its outputs.
- International marketing teams need one operating view of purpose, data inputs, customer notice, vendor safeguards, rights handling, retention and named ownership before launch.

## The AI tool brings a data decision with it

A marketing team may buy a customer-service assistant, personalisation platform, campaign tool, lead-scoring application or sales agent through an ordinary software procurement. The interface can make the deployment feel routine. The data path is usually more complex.

Transaction histories, chat messages, voice recordings, images, customer profiles, prompts, outputs and activity logs can move through the workflow. Some providers process that data only to deliver the service. Others retain it for security, product improvement or model development. Subprocessors and cross-border hosting can add further parties and locations.

The legal roles and available processing grounds vary by market. The operating questions stay practical: what data enters the tool, why it is needed, what the customer was told, what the provider can do with it, how long it remains available and who can act when a customer exercises a right or an incident occurs.

## FCP Customer Data Accountability Test

Full Court Press uses two operating terms to make customer-information responsibility actionable before an AI vendor, assistant or workflow is approved.

### Customer Data Path

The documented route customer information follows through an AI-enabled commercial workflow, covering collection or input, processing, storage, sharing, output, retention and deletion.

### Customer Data Response Owner

The named role with authority to coordinate and close the organisation's response when a customer, regulator or business partner asks a question, or when an internal incident requires action.

Together they form the **FCP Customer Data Accountability Test**:

1. Can we trace the customer's information through this workflow?
2. Who has the authority to respond when questions arise?

### One-page approval matrix

| Approval question | Required answer | Required record | Named role | Decision |
|---|---|---|---|---|
| Can we trace the customer's information through this workflow? | Complete Customer Data Path | Data-flow map and vendor details | Workflow owner | Approve / Hold |
| Who has the authority to respond when questions arise? | Named Customer Data Response Owner | Escalation and response procedure | Accountable role | Approve / Hold |

Before approving an AI vendor, assistant or workflow, require documented answers to both questions and assign the response owner by role. These are FCP-defined operating terms developed for commercial governance. Applicable legal duties depend on the organisation, jurisdiction, sector, data type and intended use.

## Singapore: final GenAI guidance puts the deployer at the centre

The [official launch announcement](https://www.mddi.gov.sg/newsroom/opening-speech-by-minister-josephine-teo-at-singapore-data-festival-at-sands-expo-and-convention-centre/) confirms that on 20 July 2026, the Personal Data Protection Commission issued its final Advisory Guidelines on the Use of Personal Data in Generative AI after consulting industry and the public. The draft had been issued on 2 June 2026 and the [public consultation closed on 1 July 2026](https://files.app.optical.gov.sg/pdpc/production/assets/6bb79f5a-6f1c-484f-8ed0-91cb64c93abd.pdf). The final guidelines are advisory and clarify how the existing PDPA applies to Generative AI. The PDPA and subsidiary legislation prevail if an inconsistency arises.

The final guidelines identify model providers, system providers and system deployers as distinct stakeholders. The system deployer bears primary responsibility for ensuring the chosen system can meet the deployer's PDPA obligations. Providers may carry responsibilities as organisations when they process personal data for their own purposes, or as data intermediaries when they process it on behalf of downstream organisations.

The guidelines also draw a line around user data used for large-scale model training or fine-tuning. Unless deemed consent or a relevant statutory exception applies, consent is required and the individual must be told the purpose. Broad wording such as "new product development" is insufficient. An AI-specific notification should explain the model function, the personal data involved, the training or fine-tuning use and the route to decline or withdraw consent.

The [Infocomm Media Development Authority's separate Generative AI Chatbot Transparency Guidelines](https://www.channelnewsasia.com/singapore/genai-ai-chatbot-nutrition-label-guidelines-data-6263571) are voluntary. They encourage a Chatbot Information Card explaining in plain language what the chatbot does, its limitations, how data may be handled and how users can report issues. At the launch, the Minister for Digital Development and Information said DBS, Google, Meta, OCBC and Singapore Airlines would use the guidelines as a point of reference. For Google, this involves consolidating key information about the Gemini app and making it easier for users to find.

The commercial consequence is immediate. A campaign owner needs to know whether customer data is used to deliver the feature, retained in logs, routed to subprocessors, added to retrieval sources or used to improve a model. Each purpose needs a defensible customer explanation and control path.

## European Union: GDPR accountability sits beside AI Act transparency

The [EU General Data Protection Regulation](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng) applies when personal data is processed within its scope. The controller determines the purposes and means of processing and remains responsible for GDPR compliance. A processor acts on the controller's instructions under a contract that covers the required safeguards and assistance.

For an AI-enabled marketing use, the controller needs an appropriate lawful basis, transparent information for individuals, data minimisation, security, rights handling and controls over processors and international transfers. Processing likely to create a high risk to people's rights and freedoms can require a data protection impact assessment before deployment.

The [European Data Protection Board's Opinion 28/2024 on AI models](https://www.edpb.europa.eu/news/edpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en) explains that anonymity and the use of legitimate interests for developing or deploying AI models require case-specific assessment. The business still has to establish the underlying personal-data position behind a model label or vendor assurance.

The [EU AI Act](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) adds obligations based on the AI use and risk category. Its transparency provisions apply from 2 August 2026. They include informing people when they interact with an AI system such as a chatbot and labelling certain AI-generated or manipulated content. The European Commission published final [guidelines on the Article 50 transparency obligations](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems) on 20 July 2026. Marketing teams operating in Europe therefore need to assess the data-protection position and the AI-specific disclosure duties that apply to the customer experience.

## United Kingdom: data protection duties continue as automated-decision rules change

UK organisations work within the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025. The [Information Commissioner's Office guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/) applies the familiar requirements of fairness, lawfulness, transparency, accountability and risk management to AI systems processing personal data.

The ICO confirmed that all data-protection provisions in the [Data (Use and Access) Act 2025 were in force by 19 June 2026](https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/). The Act broadens the lawful bases available for significant decisions made solely through automated processing, while requiring safeguards such as information about the decision, a route for representations and human intervention. Special-category data remains more tightly protected.

The practical question for marketing is whether profiling, lead scoring, personalisation or customer eligibility produces a significant decision. A team needs to document the processing purpose, lawful basis, customer information, impact assessment, human review and vendor role according to the actual use.

## United States: the campaign has to account for a federal, state and sectoral patchwork

The United States has a layered privacy framework. A [Congressional Research Service review published in August 2025](https://www.congress.gov/crs-product/R48667) describes federal law as sectoral and records at least 19 state comprehensive consumer privacy laws. These state regimes commonly provide rights such as access, correction and deletion, with obligations around targeted advertising, sensitive data and certain forms of profiling.

At federal level, the Federal Trade Commission can act against unfair or deceptive practices. Its enforcement guidance on AI and consumer data says businesses can be held accountable for how they obtain, retain and use the data powering algorithms. The [FTC has also described orders requiring deletion of data products derived from unlawfully obtained or misused data](https://www.ftc.gov/business-guidance/blog/2023/06/hey-alexa-what-are-you-doing-my-data).

State scope matters. California provides one useful example: [CCPA regulations took effect on 1 January 2026](https://cppa.ca.gov/regulations/ccpa_updates.html). A risk assessment is required before covered processing initiated after that date begins. Covered processing already under way before the effective date has a transition deadline of 31 December 2027. Requirements for automated decision-making technology used in defined significant decisions begin on 1 January 2027 and include consumer access and opt-out rights for covered uses. The definition covers decisions such as lending, housing, education, employment and healthcare; advertising is excluded.

A single "US compliant" label provides too little information for an international campaign. The business needs a state and sector map covering where customers are located, which data is involved, whether targeted advertising or significant profiling occurs, which notices and opt-outs apply and which vendor terms support those duties.

## Australia: inputs, outputs and inferred information all matter

The Australian Privacy Act 1988 and Australian Privacy Principles apply to covered organisations handling personal information through AI. The [Office of the Australian Information Commissioner's guidance for commercially available AI products](https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products) says privacy obligations can apply to personal information entered into a tool and to personal information generated or inferred in its outputs.

The OAIC directs organisations to assess whether collection is reasonably necessary, lawful and fair under APP 3. APP 6 can restrict a secondary AI-related use unless it is supported by consent or another permitted basis, including a related use within the individual's reasonable expectations. The regulator also recommends clear privacy policies and notices, visible identification of public-facing AI tools and due diligence on access, human oversight, privacy and security risks.

As a matter of best practice, the OAIC recommends keeping personal information, especially sensitive information, out of publicly available generative AI tools. For marketing teams, that creates a clear procurement distinction between an open consumer tool and an enterprise service with documented contractual and technical controls.

## International comparison: what changes and what stays operationally important

| Market | Main regulatory frame | Where business responsibility sits | Customer-facing requirement | Approval focus |
|---|---|---|---|---|
| Singapore | PDPA plus final GenAI advisory guidelines; separate voluntary chatbot-transparency guidelines | The PDPC guidance places primary responsibility on the system deployer; providers may have their own organisation or data-intermediary duties | Purpose-specific notice and, for covered training or fine-tuning uses, AI-specific information and customer choice; voluntary chatbot information cards | Provider role, consent or exception, access, residency, retention, deletion, leakage controls and customer-facing chatbot explanations |
| European Union | GDPR plus the EU AI Act | The controller remains accountable for purposes, means and processor oversight; provider or deployer duties may also arise under the AI Act | GDPR transparency and rights; AI interaction or content disclosures for covered AI Act uses | Lawful basis, DPIA, processor contract, transfers, minimisation, rights handling and applicable AI Act category |
| United Kingdom | UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025 | The controller remains accountable, with processors acting under documented instructions | Clear privacy information; safeguards around significant solely automated decisions, including human intervention routes | Lawful basis, impact assessment, profiling significance, special-category data, processor controls and review rights |
| United States | FTC Act, sectoral federal laws and state privacy laws; California shown as an example | Responsibility depends on the entity, sector, state, data and use; vendor allocation leaves the business responsible for its own unfair or deceptive practices | State notices, access, deletion, correction, opt-out and sensitive-data requirements where applicable | State and sector scoping, privacy promises, targeted advertising, profiling, retention, security and vendor restrictions |
| Australia | Privacy Act 1988 and Australian Privacy Principles | The covered entity remains responsible for its collection, use, disclosure, security and accuracy obligations | APP notices, privacy-policy transparency and clear identification of customer-facing AI interactions | Necessity, primary or secondary purpose, consent or reasonable expectations, accuracy, human oversight and vendor access |

The table is a commercial orientation tool. Coverage, definitions, exemptions, sector rules and enforcement positions vary. Jurisdiction-specific advice should determine the final legal position for each deployment.

## Vendor due diligence becomes part of campaign readiness

Across these markets, procurement needs enough information to understand the full customer-data journey. The core questions are:

- Where are prompts, inputs, outputs and logs stored and processed?
- Does the provider use customer data to train, fine-tune or improve its models?
- Which employees, subprocessors and connected services can access the data?
- How long is the data retained, and how is deletion verified?
- What testing covers data leakage, prompt injection, unauthorised access, accuracy and harmful outputs?
- How will the provider support access, correction, deletion, withdrawal, opt-out and incident-response requests?
- Which changes to models, terms, subprocessors or data locations require notice or approval?

A late legal or procurement review can leave the campaign design, customer promise and vendor dependency fixed before the necessary documentation is available. Marketing, privacy, legal, security, procurement and the commercial owner need to review the workflow while choices can still change.

## Five checks before an international AI-enabled campaign goes live

### 1. Purpose and legal basis

What customer outcome requires the data, and which lawful basis, consent route or exception supports the use in each relevant market?

### 2. Customer Data Path

Which personal data appears in prompts, uploads, transaction histories, retrieval sources, outputs, logs and agent activity? Which new personal information can the AI infer or generate?

### 3. Customer notice, disclosure and choice

What will customers be told about the AI use, and how can they exercise access, correction, deletion, withdrawal, opt-out, objection or human-review rights where applicable?

### 4. Vendor checks and transfer controls

What has the provider documented about storage, residency, transfers, access, subprocessors, retention, deletion, testing and incident handling?

### 5. Customer Data Response Owner

Who approves the use case, monitors live behaviour, manages provider and model changes, handles customer requests and coordinates a regulator or incident response?

## Ownership has to travel with the campaign

The five markets use different legal concepts, thresholds and enforcement routes. They still create a common operating demand for international marketing teams: know the purpose, minimise the data, explain the use, verify the provider, support customer rights and name the owner.

A practical global standard can set the strongest workable controls as the internal floor, then add jurisdiction-specific requirements for the market, sector, data and use case. This reduces the risk of rebuilding governance after a campaign has launched and gives commercial leaders a clearer basis for approving the expected return.

If a regulator, customer or board asks tomorrow why this data entered an AI workflow, who can produce the purpose, notice, contract, retention decision and monitoring records?

## Common Questions

### Who owns customer data risk when a marketing team uses third-party generative AI?

The legal allocation varies by jurisdiction and contractual role. The business deploying the workflow still needs to establish its purpose, legal basis or permitted use, customer information, vendor controls, retention, rights handling and operational ownership. A provider may carry separate duties.

### Are customer-data rules for marketing AI the same in Singapore, the EU, the UK, the US and Australia?

Each market takes a different route. Singapore's final PDPC guidance focuses on deployers and providers under the PDPA, while separate IMDA guidance addresses voluntary chatbot transparency. The EU and UK use controller and processor duties. Australia applies the Privacy Act and APPs. The United States combines federal, state and sector-specific requirements.

### Do Singapore's final guidelines require AI-specific notifications?

For large-scale Generative AI model training or fine-tuning using user data, the guidelines say broad statements such as new product development are insufficient and AI-specific notifications should be provided. Deemed consent and statutory exceptions may still apply in some circumstances.

### What changes for customer-facing AI in the European Union and United Kingdom?

EU and UK data protection rules require a lawful and transparent basis for processing personal data. In the EU, AI Act transparency provisions applying from 2 August 2026 also require disclosure for covered interactions such as chatbots. In the UK, significant solely automated decisions require appropriate safeguards under the Data (Use and Access) Act framework.

### Why does the United States require a state and sector review?

US privacy law combines federal sector rules, FTC enforcement and a growing group of state comprehensive privacy laws. Coverage and customer rights can change with the state, sector, data type, targeted-advertising activity and use of profiling or automated decisions.

### Does an AI vendor contract transfer the deploying business's responsibility?

Contracts can allocate instructions, safeguards, assistance, liability and remedies. The deploying business still needs to assess whether its own collection, use, disclosure, notice, rights handling and oversight meet the requirements applying to the workflow.

**Important:** This article provides general commercial-governance information. Legal advice should be obtained for the jurisdictions, sectors, data and workflows involved.

## Sources and References

### Singapore

- Ministry of Digital Development and Information, Opening Speech by Minister Josephine Teo at Singapore Data Festival, confirming issue of the final Advisory Guidelines on the Use of Personal Data in Generative AI, 20 July 2026: https://www.mddi.gov.sg/newsroom/opening-speech-by-minister-josephine-teo-at-singapore-data-festival-at-sands-expo-and-convention-centre/
- Personal Data Protection Commission, Proposed Advisory Guidelines on the Use of Personal Data in Generative AI, 2 June 2026, retained as consultation history: https://files.app.optical.gov.sg/pdpc/production/assets/ceb45ef8-294d-4b45-be35-e884d578fd8d.pdf
- Personal Data Protection Commission, public consultation cover note and closing date, 2 June 2026: https://files.app.optical.gov.sg/pdpc/production/assets/6bb79f5a-6f1c-484f-8ed0-91cb64c93abd.pdf
- Personal Data Protection Commission, Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems: https://www.pdpc.gov.sg/organisations/regulations-decisions/regulatory-guidance/advisory-guidelines-on-use-of-personal-data-in-ai-recommendation-and-decision-systems
- Channel NewsAsia, Singapore launches 'nutrition label' guidelines for GenAI chatbots, 20 July 2026: https://www.channelnewsasia.com/singapore/genai-ai-chatbot-nutrition-label-guidelines-data-6263571

### European Union

- European Union, General Data Protection Regulation, Regulation (EU) 2016/679: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- European Data Protection Board, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models: https://www.edpb.europa.eu/news/edpb-opinion-on-ai-models-gdpr-principles-support-responsible-ai_en
- European Commission, AI Act regulatory framework and implementation timeline: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, 20 July 2026: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
- European Commission, Code of Practice on Transparency of AI-Generated Content: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content

### United Kingdom

- Information Commissioner's Office, Guidance on AI and data protection: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/
- Information Commissioner's Office, Data (Use and Access) Act 2025: what it means for organisations, updated 19 June 2026: https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/

### United States

- Congressional Research Service, Preemption and Privacy Law, 29 August 2025: https://www.congress.gov/crs-product/R48667
- Federal Trade Commission, Hey, Alexa! What are you doing with my data?, 14 June 2023: https://www.ftc.gov/business-guidance/blog/2023/06/hey-alexa-what-are-you-doing-my-data
- California Privacy Protection Agency, CCPA Updates, Cybersecurity Audits, Risk Assessments and Automated Decisionmaking Technology Regulations, effective 1 January 2026: https://cppa.ca.gov/regulations/ccpa_updates.html

### Australia

- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products, updated 17 January 2025: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-the-use-of-commercially-available-ai-products
- Office of the Australian Information Commissioner, Guidance on privacy and developing and training generative AI models: https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/guidance-on-privacy-and-developing-and-training-generative-ai-models

Scope: This article provides general commercial interpretation only. Applicable duties vary by organisation, jurisdiction, state, sector, data type and use case. Obtain legal advice for the facts of each deployment.

## Related Pages

- Agentic Readiness Diagnostic: https://www.fcpress.org/agentic-readiness-diagnostic
- Commercial AI Architecture: https://www.fcpress.org/commercial-ai-architecture
- Agentic AI Systems for Sales and Revenue Growth: https://www.fcpress.org/fcp-article-agentic-growth-systems
- FCP Insights: https://www.fcpress.org/insights

## Rights and Ownership

Copyright 2026 Full Court Press Pte. Ltd. All rights reserved.

Rights holder: Full Court Press Pte. Ltd.

Singapore UEN: 202306714R.
