Service Providers as Data Intermediaries
Is this legally binding?
Guidance. Voluntary guidance. Best practice, not obligation, until a contract or a regulator cites it.
GUIDANCE interpreting binding s 4(2): third-party developers of bespoke or fully customisable AI Systems processing personal data for customers are data intermediaries, directly subject to the Protection and Retention Obligations (ss 24-25) and the s 26C breach-reporting duty.
From the source
“they take on the role of data intermediaries and have to comply with applicable obligations under the PDPA”
paras 1.4, 11.2
What this connects to
4 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Part of3
- Concept'Data Intermediary' (s 2(1); s 4(2))Binding
Guideline interprets binding PDPA provision; guideline itself is not legally binding
- ObligationProtection Obligation (s 24)Binding
Guideline interprets binding PDPA provision; guideline itself is not legally binding
- ObligationRetention Limitation Obligation (s 25)Binding
Guideline interprets binding PDPA provision; guideline itself is not legally binding
Cited by1
- SectionPart V, Procurement of AI Systems (B2B Service Providers)Guidance
Structural decomposition of the source instrument
Learn this properly
This page tells you what Service Providers as Data Intermediaries is and whether it binds you. The AI Governance program teaches the whole discipline, with dedicated coverage of the Singapore governance stack and the MAS regime, and every topic is passed by explaining it back in your own words, graded against the source.
See the AI Governance programVerified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.
Readers of this also ask
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.