Skip to content
TrustList
News

Singapore PDPC accepts an undertaking after an AI-written e-mail script exposed 95,364 members' addresses

Editorial

By TrustList Editorial

Singapore's data protection regulator published a voluntary undertaking by retailer Bee Cheng Hiang after a bulk e-mail sent with a script written using a generative AI tool showed 95,364 members' addresses to every recipient.

About Singapore PDPC accepts an undertaking after an AI-written e-mail script exposed 95,364 members' addresses

Singapore PDPC accepts an undertaking after an AI-written e-mail script exposed 95,364 members' addresses

21 September 2026 — Singapore's Personal Data Protection Commission (PDPC) has published a voluntary undertaking by Bee Cheng Hiang Marketing, the company behind the bakkwa retail chain, after a marketing e-mail exposed members' e-mail addresses. The undertaking was published on 21 September 2026 and drew wider coverage in early October, with some outlets calling it Singapore's first AI-related data breach.

Not yet independently verified. The regulator's page confirms the undertaking and its publication date; the incident details (the AI-written script, the visible addresses and the number affected) are taken from press reports of the undertaking, whose full text we could not read on the regulator's page. We will update this when it can be confirmed, and remove this note.

What happened

According to reports of the undertaking, a staff member used a generative AI tool to write a script for sending a bulk marketing e-mail through an e-mail delivery service. The prompt did not ask for recipients to be placed in the blind-copy field, so when the e-mail was sent in April 2026 each recipient in a batch could see the other addresses in the To field. About 95,364 members were affected; only e-mail addresses were exposed. The company notified the PDPC two days later and has since fixed the script and introduced a pre-send check by at least two staff. Taiwan's iThome stressed that the cause was a flawed prompt and unreviewed code, not the AI tool itself.

Who is affected

Any organisation whose staff use AI assistants to write scripts or code that handle customer data, especially marketing teams sending bulk e-mail outside a proper campaign tool, and the e-mail and marketing platforms they use.

What to do

  1. Treat AI-generated code that touches personal data as code: review it, test it on a small internal list, and keep a record.
  2. Use a campaign tool with built-in safeguards for mass e-mail rather than ad hoc scripts.
  3. Require two-person sign-off for sends to large lists.
  4. Include AI-assisted scripting in your data protection training and acceptable-use policy.
  5. Have a breach response plan ready: prompt notification was a factor in the regulator accepting an undertaking.

Why it matters for buyers

The mistake was ordinary, but the scale came from automation. As non-developers use AI to write code, regulators will judge the controls around it. A voluntary undertaking, rather than a fine, shows that quick notification and fixes count.

Sources

Categories & features