In this article

Kooky
Builder of Shaka, the payment router that pays every agent their commission on closing date.
About Kooky and Shaka →A property agency holds a great deal of information about people: who is selling, who is looking, what they can afford, which numbers they answer. An AI tool that drafts a listing, ranks enquiries or suggests homes to a buyer works on exactly that material. In Singapore the question of what an agency or a salesperson may do with it is not answered in one place, and none of the documents read for this guide was written for estate agency work alone.
This guide follows four of them: the advisory guidelines the Personal Data Protection Commission (PDPC) issued on personal data in AI systems, the Model AI Governance Framework, the Do Not Call rules as the Council for Estate Agencies (CEA) explains them to salespersons, and CEA's Practice Guidelines on Ethical Advertising. It describes what each asks in general terms. How they apply to one tool and one set of client records depends on the facts, and the points the documents leave open are named at the end.
PDPC advisory guidelines issued 1 March 2024; CEA article on the Do Not Call Registry, accurate as at 28 December 2020.
Four documents, none written for property alone
The base is the Personal Data Protection Act 2012, read here on Singapore Statutes Online in its 2020 Revised Edition, which the site shows as in operation from 31 December 2021. Section 2(1) defines personal data as data, whether true or not, about an individual who can be identified from that data, or from that data together with other information the organisation has or is likely to have access to. A seller's name beside a unit, a tenant's telephone number and a buyer's budget noted against an enquiry all sit comfortably inside that wording when the person can be identified.
Related readUS housing algorithms: what HUD said on AI and what still appliesOn top of the Act sit the PDPC's Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, issued on 1 March 2024. Their own introduction sets two aims: certainty for organisations about when personal data may be used to develop and deploy AI systems, and assurance for consumers about how their data is used. They describe an AI system as one that embeds machine learning models. The PDPC's page for the guidelines adds that they are to be read with two older texts, the Advisory Guidelines on Key Concepts and the Advisory Guidelines on the Act for Selected Topics.
The third document is the Model AI Governance Framework, which the PDPC released in a first edition on 23 January 2019 and a second on 21 January 2020. The fourth layer is CEA's own: the Practice Guidelines on Ethical Advertising, numbered PG 2/2011, and an article CEA published for the industry on the Do Not Call Registry.
The AI guidelines are advisory, and the Act prevails
Paragraph 2.2 of the PDPC guidelines says they are not legally binding on the Commission or on any other party and are not legal advice. Where they and the Personal Data Protection Act or its subsidiary legislation differ, the legislation prevails.
That status matters for reading everything below. The guidelines explain how the PDPC reads the Act when an AI system is involved and add practices it encourages. The duties themselves are the Act's, and paragraph 2.1 of the guidelines states that the Act applies to all collection and use of personal data, including to develop, test and monitor AI systems or as part of deploying them.
Who answers for the data
Three passages of the Act, as shown on Singapore Statutes Online, settle who carries the duties before any AI question arises.
First, section 4 lists who is outside the main data protection parts of the Act, Parts 3 to 6B. The list includes individuals acting in a personal or domestic capacity, employees acting in the course of their employment, and public agencies. The duties in those parts therefore rest on the organisation. How that maps onto a salesperson working under an agency depends on the working arrangement, and the pages read for this guide do not settle it.
Related readUS real estate AI this week: an MLS assistant, new data, title rulesSecondly, section 2(1) defines a data intermediary as an organisation that processes personal data on behalf of another organisation, not counting that other organisation's own employees. A vendor that runs client records through a model for an agency fits the description of the role.
Thirdly, section 4(3) makes an organisation responsible for personal data that its data intermediary processes on its behalf. Passing records to a tool supplier does not pass the responsibility with them. The AI guidelines repeat the point in their last paragraph on procurement: organisations keep primary responsibility for ensuring that the AI system they choose complies with the Act.
Three stages of an AI system
The guidelines are organised by what is being done with the data. Paragraph 3.2 divides them into three parts, and an agency may find itself in one, two or all three depending on whether it builds, buys or simply uses a tool.
| Stage | Part | What it covers | Main route to using data |
|---|---|---|---|
| Development, testing and monitoring | III | Training, testing and checking a model with personal data. | Consent, or the business improvement or research exception. |
| Deployment | IV | A system that gives recommendations, predictions or decisions to consumers. | Consent with notification, unless deemed consent or an exception applies. |
| Procurement | V | A service provider building a bespoke system for a business customer. | The provider acts as a data intermediary for the customer. |
The first stage is where an agency tunes a model on its own transaction history or enquiry records. The second is where a system in use produces something about a person: a shortlist of homes, a prediction of who is likely to sell, a decision on which enquiry is answered first. The third concerns the supplier relationship, and it is narrower than the word procurement suggests, as a later section shows.
Training a tool on client records without consent
Paragraph 1.3 of the guidelines says organisations can generally rely on meaningful consent, or on exceptions in the Act such as business improvement and research. The two exceptions are the heart of Part III, because they describe when existing client data may be used to build or improve a model without going back to each client.
Related readAustralia: what privacy law asks of an agency using AI tools| Point | Business improvement | Research |
|---|---|---|
| Where it sits in the Act | Part 5 of the First Schedule; Division 2 of Part 2 of the Second Schedule. | Division 3 of Part 2 of the Second Schedule. |
| What it is for | Four listed purposes tied to the organisation's goods, services and processes. | Commercial research that advances science and engineering with no product roadmap. |
| Conditions | Two: identifiable data is needed, and a reasonable person would find the use appropriate. | Four: need, clear public benefit, no decision about the individual, no identification in published results. |
| Sharing | Within a group of companies and between departments. | Between unrelated companies for jointly conducted research. |
The business improvement exception is the one closer to ordinary agency work. Paragraph 5.1 lists its purposes: improving or enhancing existing goods and services or developing new ones; improving methods or processes for business operations related to them; learning or understanding the behaviour and preferences of individuals, including segmented groups; and identifying goods and services that may suit individuals, or personalising them. The fourth purpose reads like a description of a recommendation engine, and paragraph 5.4 of the guidelines gives recommendation engines in social media services as an example.
The purposes come with two conditions in paragraph 5.2. The purpose cannot reasonably be achieved without using the data in individually identifiable form, and the use is one a reasonable person would consider appropriate in the circumstances. Paragraph 5.3 lists what the PDPC would weigh: whether using personal data improves the effectiveness or quality of the AI system, whether alternatives without personal data are technically possible and cost-effective, what is common industry practice, and whether the use contributes to better product features. The guidelines add that the exception can extend to testing a system and to assessing it for bias, and note that industry best practice is generally to use personal data to debias training datasets.
Where data moves between related companies under this exception, a footnote to the guidelines says they should be bound by a contract, an agreement or binding corporate rules that require appropriate safeguards. An agency group with several entities is the kind of structure that sentence addresses.
Related readAustralia: PropertyMe links agencies' own AI assistants to live dataThe research exception is tighter. Paragraph 6.2 sets four conditions: the research cannot reasonably be accomplished without data in individually identifiable form; there is a clear public benefit; the results will not be used to make any decision that affects the individual; and any published results do not identify individuals. The third condition is what separates research from product work. A model trained under this exception and then used to decide which owner receives a call would be making exactly the kind of decision the condition excludes. Disclosing data to another company for joint research requires the same four conditions and, under paragraph 6.3, an assessment that seeking consent would be impracticable.
Less data, pseudonyms and anonymisation
Whichever route is used, Part III asks how much personal data the work really needs. Paragraph 7.1 describes data minimisation in three moves: use only the attributes required, limit the volume, and restrict the set by relevant time periods and other filters. For an agency, that is the difference between feeding a model every field of every client file and feeding it the fields and years the task depends on.
Paragraph 7.2 encourages pseudonymisation as a basic control wherever possible. Where it is not possible and raw personal data is used, paragraph 7.3 points to the Protection Obligation in section 24 of the Act and encourages a data protection impact assessment. The guidelines also warn, in paragraph 7.6, that a trained model can itself be exposed to privacy attacks such as model inversion, and recommend designing privacy in from the start.
Related readCalifornia's law on digitally altered listing photos, explainedAnonymisation goes a step further. The guidelines note that anonymised data falls outside the Act, while still carrying a risk of re-identification. The standard they describe is that there should be no serious possibility of re-identification, judged on factors that include whether the technique can be reversed, how widely the data is disclosed and what controls surround it. They accept that an organisation may choose personal data over anonymised data for reasons such as accuracy, and ask that the choice be documented and made at a senior level. Paragraph 7.7 ties this to the Accountability Obligation: an organisation should have policies on when anonymised and when identifiable data is used.
When the tool faces a client: notices and policies
Part IV applies once a system is in front of people. Paragraph 9.1 states the starting point: unless deemed consent or an exception applies, consent is required to collect and use personal data for recommendations, predictions or decisions. Paragraph 9.2 adds the Notification Obligation in section 20(1) of the Act: individuals are told the purposes on or before collection, or before any new use or disclosure.
The guidelines insist that consent be meaningful, and they are specific about what makes a notice useful. Paragraph 9.5 encourages organisations to explain four things:
- the function of the product that needs personal data;
- the general types of personal data collected and processed;
- how that data is relevant to the feature;
- the specific features of the data that are most likely to influence the outcome.
Applied to a buyer-matching feature, purely as an illustration, the four items would be the matching function itself, categories such as budget and search history, the fact that they are used to rank homes, and which of them weigh most in the ranking. The guidelines' own examples are recommendations of books, songs and films; the property reading is this guide's, not the PDPC's.
Related readColorado's automated decision law and housing: what applies from 2027Paragraph 9.4 says the notice should be proportionate to the risk, taking account of the potential harm to the individual and how autonomous the system is, and should not be overly technical. Paragraphs 9.6 and 9.7 suggest pop-ups or published policies as the vehicle, with layered information and model or system cards for those who want more. Paragraph 9.8 allows commercially sensitive or security-related detail to be held back, on condition that the decision is justified and documented internally.
One exception is given separate treatment. Legitimate interests, with specific examples listed in paragraphs 2 to 10 of Part 3 of the First Schedule, may support using personal data without consent when the organisation has assessed that the interests outweigh any adverse effect on the individual. The guidelines' example is an AI system that detects or prevents illegal activities. An organisation relying on this exception must make that reliance known to individuals, under paragraph 9.11.
Consent and notices face outward. The Accountability Obligation, in sections 11 and 12 of the Act, faces inward: section 12 requires an organisation to develop policies and practices to meet its obligations. Paragraph 10.3 of the guidelines says an organisation using AI systems should include the relevant practices and safeguards in its written policies, in a way that is proportionate to the risk.
Paragraphs 10.5 to 10.8 list what such policies can cover: measures for fairness and against bias, data protection safeguards, human oversight, and the robustness of the system. On the quality of data, they mention how representative the training data is, whether it was pseudonymised, why any bias assessment needed personal data, how secure the development environment is, and how data was minimised.
Related readWhat UAE data protection law asks of a Dubai brokerage using AI toolsTwo procedural points follow. Under section 12(d), as the guidelines cite it, information about policies is made available on request, and paragraph 10.4 suggests considering publication in advance in a short and clear form. And paragraphs 10.11 and 10.12 ask organisations to review notices and policies regularly and to consider impact assessments, in particular data protection impact assessments.
Buying a tool from a supplier
Part V is addressed to service providers, and paragraph 11.1 draws its borders carefully. It applies to providers such as systems integrators that build bespoke or fully customisable AI systems for a customer. It does not apply to in-house development, and it does not apply to commercial off-the-shelf products. An agency that subscribes to a standard product is therefore not in the situation Part V describes, though Parts III and IV still describe its own use of personal data.
Where Part V does apply, the provider that processes personal data for its customer is a data intermediary. The guidelines list what follows from the Act: the Protection Obligation in section 24, the Retention Obligation in section 25, and the duty in section 26C to report a data breach to the organisation on whose behalf the data is processed. They add two good practices for the build itself: mapping and labelling the training data at the pre-processing stage, and keeping a provenance record that tracks where data came from and how it was transformed. Paragraph 11.3 explains the purpose: these records help detect unauthorised access or modification, support the assessment of a breach, and help identify sensitive personal data.
Related readHow the Dubai Land Department uses artificial intelligence, by serviceParagraph 11.4 encourages providers to help their customers meet the Notification, Consent and Accountability Obligations, and says they may be asked for technical clarification on the customer's policy documents. The agency remains the party that gives the notice, and under paragraph 11.8 it remains the party primarily responsible.
The Model AI Governance Framework
The guidelines recommend two further resources in paragraphs 10.9 and 10.10: the Model AI Governance Framework and AI Verify. The framework is not about personal data alone. The PDPC's page describes the second edition as sector-agnostic and technology-agnostic, able to complement sector-specific requirements, and says the PDPC encourages organisations to use it. It is built around four areas.
| Area | What the PDPC's page says it covers |
|---|---|
| Internal governance structures and measures | Clear roles and responsibilities, standard operating procedures to monitor and manage risks, staff training. |
| Level of human involvement | An appropriate degree of human involvement in AI-augmented decisions, and minimising the risk of harm to individuals. |
| Operations management | Minimising bias in data and models; a risk-based approach to explainability, robustness and regular tuning. |
| Stakeholder interaction and communication | Making AI policies known to users, allowing feedback where possible, keeping communication easy to understand. |
The second edition added considerations on robustness and reproducibility. Two companions come with it: an Implementation and Self Assessment Guide for Organisations, developed with the World Economic Forum's Centre for the Fourth Industrial Revolution and more than 60 contributing organisations, and a Compendium of Use Cases in two volumes.
Generative tools, the kind that write text or produce images, have a separate text. According to an Infocomm Media Development Authority factsheet, the Model AI Governance Framework for Generative AI was proposed in January 2024 and finalised on 30 May 2024 by the authority with the AI Verify Foundation. The factsheet describes the 2019 framework, updated in 2020, as addressing what it calls Traditional AI, and says the generative framework comprises nine dimensions. It does not list them on the page read for this guide.
AI-drafted outreach and the Do Not Call Registry
A tool that writes a marketing message does not change the rules on sending it. CEA's article for salespersons on the Do Not Call Registry, marked accurate as at 28 December 2020, describes the duty by the message and the number it goes to. The article says nothing about how the message was composed, and the Do Not Call provisions it summarises generally prohibit organisations and data intermediaries from sending marketing messages to registered Singapore numbers.
Related readNew South Wales rental ads and renter data: the 2026 Act explainedThe Registry has three registers, for voice calls, text messages and faxes, and covers mobile, fixed-line, residential and business numbers. CEA's article states that messages sent through apps that use a telephone number as the identifier, and it names WhatsApp, are covered when addressed to a Singapore number.
- Submit the listThrough a Registry account, the sender submits the numbers. The Registry shows which are in any register.
- Send to the restMessages go only to numbers not listed, with clear sender details and no concealed calling number.
- Resubmit after 30 daysA result may be relied on for up to 30 days. A later send needs a new check.
A worked example, with assumed figures. An agency drafts a message with a generative tool and plans to send it to 200 numbers. It submits the list on 20 August 2026 and the Registry returns 60 of them as registered for text messages. The message may go to the remaining 140. If a follow-up is planned for 5 October 2026, more than 30 days after the check, the list is submitted again first.
CEA's article gives two routes around the check. One is clear and unambiguous consent, in writing or another accessible form, from the user or subscriber of the number. The other is the Personal Data Protection (Exemption from Section 43) Order 2013, whose conditions the article names without describing. It also reminds salespersons that the data protection provisions apply alongside: consent and notification of purposes for the personal data used, unless an exception applies. An organisation can open sub-accounts under its main Registry account so that more than one user can run checks.
The advertising guidelines add rules of their own that an automated sending tool would have to respect. Paragraph 4.2 of PG 2/2011 bars telephone calls and text messages to the public between 10.00pm and 9.00am and requires contact to cease immediately when a recipient objects. Paragraph 4.3 prohibits email to addresses obtained through a dictionary attack or address-harvesting software, citing section 9 of the Spam Control Act.
Related readSingapore agency AI tools: what ERA and PropNex have announcedAI-made images and text in a property advert
CEA's Practice Guidelines on Ethical Advertising were issued on 29 June 2011 and took effect on 1 August 2011; the version read for this guide is version 2.0, dated 10 December 2020. It does not contain the words artificial intelligence, and it has no provision on virtually staged or AI-generated images. What it contains is a set of rules about results, which apply whatever produced the advert.
A photograph may not be altered to misrepresent the property
The guidelines say photographs must not be altered or enhanced in any way that would misrepresent actual aspects of the property. Interior photographs show the actual interior, and photographs of another property are not allowed.
Three more passages bear on generated content. Where a photograph is used for illustration, paragraph 3.2 requires appropriate qualifiers next to it. Paragraph 3.1 states that advertisements shall not be inaccurate, false or misleading, and paragraph 3.2 that materials must accurately describe the property; a description written by a language model is held to the same sentence as one written by hand. And paragraph 7 says the rules apply equally to the Internet, with paragraph 7.1 requiring that the information and photographs in online listings be actual and not misleading.
Responsibility is placed with people. The preamble requires estate agents, the licensed agencies, to vet their salespersons' publicity and advertising materials before publication, and paragraph 5 requires key executive officers to approve all advertisements or to have a structured process in place before they are issued. The guidelines state that non-compliance may result in disciplinary action, and recall that paragraph 4(2)(a) of the Code of Ethics requires agents to be fully conversant with, and to comply with, the Act, its regulations and CEA's guidelines.
CEA has written about AI in agency work in another register. A feature it published on 24 May 2023 reported that ERA Realty Network had announced in March 2023 that it was integrating GPT-3 and ChatGPT into its agents' app to draft listings, a task of 30 minutes to an hour that ERA estimated would take a few minutes, and that VIP Realtors had used a chatbot since mid-2021 to process invoices and organise documents. The feature sets no rule; it describes adoption.
What the documents leave open
Several points could not be settled from the pages read on 10 October 2026, and each is a matter for the source itself.
- A CEA rule on AI imagery. Neither the advertising guidelines nor the two CEA articles read here addresses virtual staging or generated images by name. Whether a later CEA circular, or a version of the guidelines newer than the one read, does was not established.
- Penalties. The penalty provisions of the Personal Data Protection Act and its Do Not Call parts were not read in the Act's text for this guide, so no amount is given.
- Current Do Not Call periods. The 30-day figure comes from CEA's article of 28 December 2020. The PDPC's own Do Not Call pages are where the current figure stands.
- Off-the-shelf tools. Part V of the AI guidelines excludes commercial off-the-shelf products. What a supplier of such a product owes an agency is a matter of the Act and the contract, which the guidelines do not develop.
- The nine dimensions. The generative AI framework's nine dimensions are not named on the factsheet page read.