By DPEX Editorial Team
Over 3,000 data and AI leaders gathered at Sands Expo & Convention Centre from 20 to 24 July for the inaugural Singapore Data Festival, the event that has expanded on what used to be Personal Data Protection (PDP) Week. DPEX Network sat down with Ms Denise Wong, who was appointed Commissioner of the Personal Data Protection Commission (PDPC) on 1 Apr 2026, on the sidelines of the festival to talk through what changes with the new title, and what doesn't — from agentic AI liability to AI wearables in the workplace.
Missed our last interview with her? Read it here.
Q: Congratulations on your appointment as Commissioner in April. As Deputy Commissioner, you shaped much of the PDPC's data and AI governance. What does stepping into the role of Commissioner change, and what do you hope will define your tenure?
I was proud and honoured to be asked to be the Commissioner. The PDPC plays a very critical role in Singapore because we help protect citizens’ personal data and enforce the PDPA, while enabling businesses to use data responsibly and flourish. As Commissioner, I am very much seeing my role to further that mission.
I hope to continue the good work in understanding emerging technology (e.g. privacy enhancing technologies (PETs), AI and biometrics) and how we can interpret the PDPA in the face of changing technology. New technology like AI (including agentic and wearables) and biometrics will bring up new data protection issues that as a community, we have to look into.
I'll continue to look at children's privacy — there is a much broader conversation about children and online safety and how we create positive online experiences for children. PDPC will support that by looking at how we can keep children's data safe and how to give them a positive online experience while keeping them from harm. As these are our next generation digital natives, we need to understand their point of view, their concerns, and work with companies that provide services for them to do that well.
The third thing is building community — this community is our “tribe”. They understand what we do, they work with us, they push and challenge us to have meaningful conversations about all the topics I just mentioned. The community is both local — DPOs operating in Singapore — and regional; there are companies, law firms, compliance outfits, and regulators from many countries that form our tribe. The idea of [the Singapore Data Festival] being the convener, bringing people together to have conversations across data privacy, governance, cybersecurity, online safety aspects — all of that merging into different themes and communities, is a key part of what I want to continue to build over the next few years.
Q: You've said throughout the week that trust is becoming a competitive advantage — that organisations that protect data well, use it responsibly, and govern AI confidently are better positioned to grow locally and expand globally. What separates organisations that treat trust as strategy from those that simply treat it as compliance?
At the end of the day, whether an organisation is big or small, they should see trust as the foundation of what they do. I think that allows them to pursue their commercial interests with more confidence. Users nowadays want performance and capability, but they also want to know that products they use are safe. And that's very much the case for digital products and services.
We think that companies that incorporate trust by design into their business processes, strategy, workflows, and products from the start, enjoy a competitive advantage compared to other businesses. It also makes them more resilient to changes in regulatory frameworks, because you are also building for it by design. It also allows companies to move faster. I have been using the seatbelt analogy all week — if you design your systems with the passenger in mind, then everything else can move at speed.
We very much see that as an advantage for companies, and that applies to both big companies and small companies. We acknowledge that the resources and abilities to think about these issues will be different, which is why when we talk to companies and write guidance, we are mindful to give them enough space, not be too prescriptive, and allow them to tailor some of these outcomes and ideas to what they can manage at that time.
Q: Last year you described DPOs evolving from compliance into broader data governance. Today over 190,000 organisations have registered DPOs with the PDPC, and the IAPP partnership aims to train AI governance professionals. How do you see this profession evolving in the next few years, and what's your advice for DPOs who need to start that transition now?
There are a wide range of organisations, many different functions, and each organisation has to decide how to organise and structure their compliance, privacy, and AI governance functions. There will be differences — I don't think there is one single correct approach. However, I think it is important that the DPO of that function must start to understand that language and how adjacent areas – AI governance, cybersecurity, intellectual property, and online safety — all come together. Where there is another department doing it, have active conversations, don't be bogged down by institutional silos.
That's why our partnership with the International Association of Privacy Professionals (IAPP) has been very important to us. They are a leading professional organisation in this space, and have a strong suite of programmes, conferences, and certifications that help the DPO community and trust community build skill sets. They held an AI Governance Professional (AIGP) training recently that has been well attended. We are also building up our tools and resources to help the DPO community — we have updated our website with resources that are easier to access. Coming up, we will launch new e-learning materials for training staff on the PDPA, and a new web-based tool that provides easy-to-follow action plans for organisations.
Q: Moving to agentic AI — last year you told us PDPC is always trying to figure out what the next bound is. Since then, IMDA released the updated Model AI Governance Framework for Agentic AI and a discussion paper on legal responsibilities for AI agents. What makes agentic AI harder to govern than generative AI, and what are the biggest challenges for regulators?
It is an interesting topic — I think agentic AI brings a lot of benefits. Generative AI chatbots we were used to before agentic systems are primarily question-and-answer interactions. With agentic AI, there will be many more modes of interaction. It will bring a lot of benefits in terms of automating tasks and being able to act and make decisions for you, interact in ways that save you time. There will be great productivity and accessibility gains through this. We are very excited by the technology.
But there are also a range of questions that need to be answered, and concerns about how we assess the risks, how we bound the risks and understand them, and how those are explained to the people who use these systems. That is why we put out the Model AI Governance Framework for Agentic AI in January. There are four main pillars: assessing and bounding risks upfront; ensuring meaningful human accountability; putting in technical controls; and enabling end-user responsibility.
What we were trying to do in that piece was really figure out, at its core, what the different aspects of accountability are in an agentic AI workflow. The next bound is to deep dive into more aspects of this. We were looking into agent liability, and we gathered legal experts to think about whether current private law legal frameworks are sufficient or insufficient to deal with liability when it comes to agentic systems. We issued an initial discussion paper and raised a lot of questions — there are some answers that need to be figured out including data protection questions, and we are very excited to be embarking on this work.
Q: Singapore takes over the ASEAN chairmanship in 2027. A principles-based approach — sandboxes, interoperable mapping — might work well for Singapore, but ASEAN members sit at very different levels of data protection maturity. When Singapore holds the chair, do you expect to push these approaches onto other ASEAN members?
We do not enact approaches for ASEAN. ASEAN has been an important community and conversation for us. In fact, the ASEAN member states, the data protection authorities and governments involved in data protection have been having a data conversation for a number of years. We already have a number of frameworks out there — the ASEAN Data Management Framework and Model Contractual Clauses. That has provided a very good foundation of agreement and convergence among the ASEAN member states.
Certainly in our chairmanship, we want to build on privacy enhancing technologies. There has been broad support; we have discussed it among the ASEAN DPAs who are here for the festival, and some of the government representatives as well. We welcome that dialogue to share our perspective on some of these newer and emerging technologies, and learn from them too, because some of them are actually very familiar and have their own perspectives. Synthetic data, for example, and anonymisation are fairly well known right now, and there are use cases across the ASEAN region employing some of these technologies.
Q: Last year, one observation on the PET market was that it's becoming more productised and lower cost. This year brings a federated learning guide and new sandbox use cases, local and international. What will it take for PETs to cross from flagship pilots and sandboxes into mainstream adoption, particularly for SMEs without well-stacked data science teams?
There is a misconception that PETs are only for big and well-resourced companies. PETs are a range of technologies — certainly there are very sophisticated ones which are appropriate for some use cases, but for other use cases, there are PETs that such as anonymisation and synthetic data that could be more suitable and easily adopted. PDPC has put up an anonymisation tool on the PDPC website that is free to use, and we encourage SMEs to try and see if it works for them. We also put out a PETs Adoption Guide recently, meant to help companies understand their use case, and which privacy enhancing technology is relevant and if it makes sense for them.
I am quite encouraged that a number of these PETs have made it to mainstream, productised use. There is now a thriving ecosystem of PETs solution providers and system integrators — people who are working with companies to implement these solutions. The sentiment is very positive across the different regulators and jurisdictions here. I think there is more we can do, we are still hoping to grow the use and adoption of this. But it is very encouraging, and understanding the use case and what problems it can solve from a data sharing perspective, then identifying the correct solution, is going to be critical for each business.
Q: You mentioned privacy and safety concerns around AI wearables being on the horizon — how will you determine where legitimate enterprise use ends and employee surveillance begins, and what should organisations expect from PDPC guidance before deploying these?
The starting point is the Personal Data Protection Act (PDPA). We and companies know what the principles are: consent, reasonable use, purpose limitation, data retention, legal basis for collection, use and disclosure. All of that is universal and relevant. The question for a company wishing to create and deploy these new technologies is how those existing principles apply. This is both a regulatory question and a societal one.
There are a lot of potential and exciting uses and benefits to this technology. We will just have to, as with all new technology, make sure that the seatbelts are on well, properly — that some of these privacy concerns and data protection concerns are well addressed, and that data is well protected. It is really about clarity in rules bringing about confidence in use. That is what we will be working with industry and different stakeholders to do across the next year or two.