Singapore PDPC accepts an undertaking after an AI-written e-mail script exposed 95,364 members' addresses
EditorialBy TrustList Editorial
Singapore's data protection regulator published a voluntary undertaking by retailer Bee Cheng Hiang after a bulk e-mail sent with a script written using a generative AI tool showed 95,364 members' addresses to every recipient.
- Singapore
- Data Security
- Email Marketing Software
- Artificial Intelligence Software
About Singapore PDPC accepts an undertaking after an AI-written e-mail script exposed 95,364 members' addresses
Singapore PDPC accepts an undertaking after an AI-written e-mail script exposed 95,364 members' addresses
21 September 2026 — Singapore's Personal Data Protection Commission (PDPC) has published a voluntary undertaking by Bee Cheng Hiang Marketing, the company behind the bakkwa retail chain, after a marketing e-mail exposed members' e-mail addresses. The undertaking was published on 21 September 2026 and drew wider coverage in early October, with some outlets calling it Singapore's first AI-related data breach.
Not yet independently verified. The regulator's page confirms the undertaking and its publication date; the incident details (the AI-written script, the visible addresses and the number affected) are taken from press reports of the undertaking, whose full text we could not read on the regulator's page. We will update this when it can be confirmed, and remove this note.
What happened
According to reports of the undertaking, a staff member used a generative AI tool to write a script for sending a bulk marketing e-mail through an e-mail delivery service. The prompt did not ask for recipients to be placed in the blind-copy field, so when the e-mail was sent in April 2026 each recipient in a batch could see the other addresses in the To field. About 95,364 members were affected; only e-mail addresses were exposed. The company notified the PDPC two days later and has since fixed the script and introduced a pre-send check by at least two staff. Taiwan's iThome stressed that the cause was a flawed prompt and unreviewed code, not the AI tool itself.
Who is affected
Any organisation whose staff use AI assistants to write scripts or code that handle customer data, especially marketing teams sending bulk e-mail outside a proper campaign tool, and the e-mail and marketing platforms they use.
What to do
- Treat AI-generated code that touches personal data as code: review it, test it on a small internal list, and keep a record.
- Use a campaign tool with built-in safeguards for mass e-mail rather than ad hoc scripts.
- Require two-person sign-off for sends to large lists.
- Include AI-assisted scripting in your data protection training and acceptable-use policy.
- Have a breach response plan ready: prompt notification was a factor in the regulator accepting an undertaking.
Why it matters for buyers
The mistake was ordinary, but the scale came from automation. As non-developers use AI to write code, regulators will judge the controls around it. A voluntary undertaking, rather than a fine, shows that quick notification and fixes count.
Sources
Categories & features
- Singapore
- Data Security
- Email Marketing Software
- Artificial Intelligence Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More SingaporeThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.