PDPC generative AI guidelines: three issues for companies deploying AI
Companies that build on AI models they don't train face three practical PDPA issues. "No training" is a contract term for large customers but only a setting for small ones. Deployers can correct the personal data they hold, but can't fix data inside a third-party model, so disclosure before training matters. And AI agents with memory create new links between personal data that people never expected.
Key takeaways
- A deployer is a company building on a model it doesn't train.
- Below enterprise tiers, "no training" is usually an account setting, not a contractual commitment.
- Deployers can correct their own records and retrieval stores, not the underlying model.
- Tell people before training that data absorbed into a model can't reliably be removed.
- Agent memory creates new associations between personal data. Scope it and put a human check before cross-context links.
Why did I respond to the PDPC consultation?
I made a submission to the Personal Data Protection Commission's public consultation on the guidelines for personal data in generative AI. I filed as a deployer, a company building on a model it doesn't train. These weren't abstract questions to me. They were mine to answer.
1. Does "no training" mean the same thing for everyone?
No. Enterprise terms, and often team subscriptions, need a company of a certain size. Everyone else gets consumer terms, where "no training" is an account setting, not a contractual commitment.
As AI drives the rise of the one-person company, that opens a gap between expectation and reality. A standard that assumes a negotiated contract pushes everyone below it toward the same invisible non-compliance as shadow AI. Better to say what a company on a policy-only tier should do: pick the most protective settings, assess what's left, and document it.
2. Where does the duty to correct personal data stop?
If you build on a model you don't train, you can't reach into it to delete or fix personal data. That sits with the provider. You can correct the data you actually hold: your own records and the retrieval stores your system draws on.
Saying so plainly matters. A correction duty that implies you must fix the model is one no deployer can meet today. The honest complement is disclosure up front. Tell people, before their data is used to train, that once it is absorbed into a model it can't reliably be removed. Then consent sets the limit, instead of a correction request revealing it.
3. Why is agentic memory a new privacy surface?
As AI agents gain memory, carrying notes across matters and linking today's task to last month's, they build connections between pieces of personal data that were never associated before.
That isn't new data collection, so the usual analysis misses it. It is a new association, and it can quietly defeat what a person reasonably expected. Anyone deploying agents should scope memory deliberately: confine it to a defined matter, and put a human check in place before any cross-context link is written.
What is the common thread?
Privacy rules for AI have to be workable for the companies that will actually be subject to them, not only the ones with legal teams and the bargaining power to negotiate their contracts.
Frequently asked questions
What is an AI deployer under data protection rules?
An organisation that uses or builds on an AI model developed and trained by someone else, as opposed to the developer that trains the model.
Can a company correct personal data inside a third-party AI model?
Generally not. A deployer can correct data it holds, such as its records and retrieval stores, but changing what a third-party model has learned sits with the provider.
Why is AI agent memory a privacy issue?
Agents that remember across tasks can link pieces of personal data that were never connected before. That new association can defeat what a person reasonably expected when sharing the data, even though no new data was collected.
This article is general information, not legal advice. It reflects the position as at the date of publication. A plain-text version for AI assistants is at /blog/pdpc-generative-ai-guidelines-deployers.md.