Opening Speech By Minister Josephine Teo at Singapore Data Festival at Sands Expo and Convention Centre
20 July 2026
Good Morning, colleagues and friends. It was less than four hours ago that the World Cup had its finals. And I was early for this event because I thought the Monday morning traffic would be at a certain level, but today the roads were very quiet. I hope your favourite team won.
The scoreline was actually quite interesting. The last time that Spain won the World Cup, they had a similar scoreline. Quite amazingly, the data shows that on the way to winning the World Cup, they did not drop more than one goal. Kudos to the Spanish team, and kudos to you, for still being here. You must really love data. You deserve a round of applause.
Many of our friends today have joined us on previous occasions when we held the Personal Data Protection Week. This year, we have broadened the event into the Singapore Data Festival. Some of you pointed this out to me.
This is not because data protection is no longer important. It still is.
But organisations are also asking bigger questions about data, especially how to support their AI endeavours.
The Data Festival is therefore designed for us to better recognise the business value of data . At the same time, to create lasting value, we must work together to build a trusted data ecosystem in Singapore, as well as the region. So let’s talk a little more about data as a source of business value.
Data as a source of business value
As you know, businesses have always used data, whether they speak of it as such or not.
Retailers look at sales data to assess changing customer preferences and adjust their stock levels accordingly.
Banks look at transactions data for evidence of fraud, to decide which accounts and parties are problematic, and what to do about them.
Data used to tell businesses what happened. It was all in the past tense. But now, with the help of technology, businesses can see developments as they happen, almost in real time, and data, when used appropriately, can help businesses take the right action sooner rather than later.
Now, we all like to be able to do that, act sooner rather than be caught by surprise. AI accelerates this process. AI systems depend on data at every stage of their lifecycle. In fact, IMDA has consistently talked about data before AI. But without good data, even the best systems will struggle to produce useful outcomes.
That is why data governance matters more, not less, in the age of AI.
Data creates value only when there is trust
At its heart, data governance is about trust.
Customers share data only if they trust the organisation to safeguard it properly and use it responsibly.
Businesses share data with partners only if they trust that the data will not be abused to compromise their own interests.
This is why Singapore has always thought of data protection as essential to a well-functioning business environment. In fact, it is key to business innovation.
Building the right conditions for trusted data use
We also believe that trusted data governance comes with the right capabilities and clear accountability. We need these two to be present at the same time, so let me highlight two ways we are strengthening these areas.
Developing AI and data capabilities
The first is helping organisations build the know-how to use data and AI well.
Most organisations already recognise the potential of AI and data.
The harder question is how do we begin to make the most of it.
Digital twins are one practical opportunity for companies today.
A digital twin is a real-time virtual representation of physical assets, systems, or processes.
Companies can use it to simulate scenarios, optimise operations, and make better decisions.
Digital twins are not so uncommon. If you talk to any F1 team, they do have digital twins, because they need to simulate the engineering improvement impact on the performances of both the vehicle, as well as the driver. So, these digital twins have been used by companies that are tech-savvy and at the frontier of technology. But we see that even SMEs today could potentially build their own digital twins.
You take Exceltec. It is a facilities management company in Singapore.
It built a digital twin that draws on sensor data from more than 70 sites where the company has customer operations. It conducts facilities management on behalf of its clients, so at 70 sites, it has inserted sensors and is able to harness the sensor data. The system that they built analyses this data continuously, and helps identify operational problems early.
For example, is a building’s air-conditioning system showing signs of a breakdown?
Or does water usage appear to have spiked for no apparent reason, suggesting a leakage somewhere?
Compared to the heavy reliance on manual inspections, teams at Exceltec can now be alerted automatically when something needs attention.
This has helped each team save about forty-five minutes a day on each inspection.
Across many buildings, teams, and days, the gains add up.
More importantly, the organisation moves from reacting to problems, to detecting them earlier and acting faster.
To help more companies benefit like Exceltec, IMDA is launching a Digital Twin For Enterprises Playbook. It is a practical legal guide to help organisations better combine AI and data, and design digital twins to address their operational bottlenecks. That’s one of things we would like to do.
Clarifying what good accountability looks like
As more organisations develop, adapt or deploy generative AI tools, we must address the question of accountability.
Take for example, a customer service team that wants to improve a Generative AI model using call recordings, so that they can respond more quickly and accurately to customer queries.
We have all been at the receiving end of these calls, and being asked or told that the call may be recorded for quality checks and improvement. But we also know that the recordings may contain personal data, such as our names, addresses, billing details.
What are the obligations that these customer service teams have to the customers before using their data for model training?
Today, the PDPC is issuing its Advisory Guidelines on the Use of Personal Data in Generative AI.
Having consulted industry and the public, we are making clear how organisations can fulfil an existing legal requirement in the PDPA for consent to be sought from the data owner. We are making it clear that where personal data is used to develop or improve a Generative AI model, organisations should say so plainly, rather than rely on broad descriptions that users may not notice or understand.
For the customer service team in the example that I described, they can update the privacy policy to state that call recordings of consenting customers will be used to train and improve AI models.
They can also update the scripts that staff use when seeking consent.
Customers can then understand the purpose and make an informed choice before giving consent.
Many organisations already provide such AI-specific notices today. Therefore, the Guidelines go further.
They also cover the roles and responsibilities of parties across the AI value chain, and due diligence when relying on publicly available data.
With greater clarity on how existing requirements apply to Generative AI, companies can design better processes with the right safeguards.
Beyond the data layer, we are also supporting accountability for AI applications.
For most users, the Generative AI application they meet most often is the chatbot.
We use the application, but may not know itslimitations , or what happens to our data.
The information usually exists. But it is scattered across the terms of service, privacy notices and other documents, and is often either too simplistic or too technical for ordinary users.
To close this gap, IMDA is launching the Generative AI Chatbot Transparency Guidelines as a first step.
The Guidelines call for a Chatbot Information Card that works like the label we often find on the packaging of medicinal products.
The label does not tell us every scientific detail.
Instead, it tells us the essentials: what the medicine is for, how to take it, how much is recommended, what side effects to watch for, when not to use it.
The Information Card is meant to work the same way. It sets out in plain language what the chatbot is for, what it is not for, how data may be handled, and how users can report issues.
We are starting with a voluntary framework, and will refine it with industry inputs as practices mature.
We are heartened by the support from companies like DBS, Google, Meta, OCBC and SIA, who will be using the Guidelines as a point of reference as they continue improving transparency practices for their chatbots.
In Google’s case, this means consolidating key information about the Gemini app, and making that information easily accessible to users, so that they can use Gemini with greater confidence.
Meta will also provide people with clear and accessible information about how its AI-powered tools and products work and the ways people can interact with them.
The companies I mentioned are early adopters who are demonstrating leadership in data and AI governance. We hope many more will follow their tracks.
Building the ecosystem together
This brings me to a final point I would like to make today about the importance of partnership in building trusted data and AI ecosystems.
In developing our AI hubs, whether Singapore or elsewhere, we need a strong community of businesses, technology providers, researchers, practitioners, standards bodies and regulators. We need to learn from one another, test ideas, and raise standards together.
One good example is this year’s AI Safety Red Teaming Challenge held in January.
More than 80 experts took part.
They came from all ASEAN countries, as well as China, India, Japan, and Korea.
Their task was to test whether Generative AI applications could leak the data they were not supposed to.
The participants were not only researchers and cyber experts. They also included linguists and sociologists who understood local language, culture, and context. That turned out to have made a real difference.
Some teams found that a harmful request refused in English was answered in the Khmer language.
Others found that casual local phrasing could slip through the safeguards that a formal-sounding request could not.
In other words, the model responded to a formal request the way it should, but when the request was put to it with local phrasing, the model safeguards failed.
This vulnerability, and many others that were identified, were not only technical; they were also linguistic and cultural.
That is the wider lesson we would like to share today.
None of us can build a trusted data ecosystem by looking only within our own borders.
We see the fuller variety of model risks only when we bring together a range of experts from the region.
As Singapore assumes the ASEAN Chairmanship next year, we will work with regional partners to strengthen the conditions for data to be used with confidence across our region. This means:
Bringing our approaches closer together,
Reducing unnecessary friction for businesses, and
Creating more room for our digital economies to grow.
Ultimately, no playbook, guideline or technical standard succeeds on its own. They become meaningful only when people and organisations put them into practice, share what they have learnt, and collectively raise standards.
That is why this Festival matters.
It brings together those who protect data, use data, build AI systems, and govern their use.
This will help us turn good ideas into better practice and build a stronger foundation for trusted data use in Singapore and the region.
And so, on that note, I wish you all a very fruitful day ahead at the Festival. Thank you once again for being here.
