MDDI スピーチ · 2026-07-20
ジョセフィン・テオ大臣によるSingapore Data Festivalでの開場スピーチ(Sands Expo and Convention Centre)
要点
- • シンガポールは個人データ保護週間を「Singapore Data Festival」に拡大させ、データとビジネス価値に関するより広い問題に対応しています。これは特にAIの取り組みの支援が重点です。
- • IMDAは「Digital Twin For Enterprises Playbook」を立ち上げています。これは組織がAIとデータを組み合わせ、運用最適化のためのデジタルツインを設計するのを支援する実践的なガイドです。
- • 施設管理会社のExceltecは、70以上のサイトからセンサーデータを活用するデジタルツインシステムを導入しました。問題検出の自動化により、検査チームは毎日約45分の時間を削減しています。
- • PDPCは「生成AIにおける個人データの利用に関する勧告ガイドライン」を発行しています。これにより、組織が個人データを使用してAIモデルを開発または改善する場合、明確で具体的な通知を提供することが求められます。
- • IMDAは「生成AIチャットボット透明性ガイドライン」を立ち上げています。これはチャットボットの目的、制限事項、データ処理、ユーザーの救済方法を明確に開示する任意の情報カード形式を備えています。
全文翻訳
MDDI 英語原文の翻訳 · 翻訳日: 2026-07-28
おはようございます。同僚の皆さん、友人の皆さん。ワールドカップの決勝戦は4時間も前に終わったばかりです。今朝のイベントに早めに来たのは、月曜日の朝の交通渋滞がそれなりにあると思っていたからですが、今日の道路は非常に静かでした。皆さんの応援するチームが勝ったことを願っています。
スコアは実は非常に興味深いものでした。スペインが前回ワールドカップに優勝した時と似たようなスコアだったのです。驚くべきことに、データが示すところによると、ワールドカップ優勝への道のりで、スペインは1点以上失点しませんでした。スペインチームに敬意を表し、ここにおいでいただいた皆さんにも敬意を表します。皆さんは本当にデータが好きなのですね。拍手をお送りします。
本日ご参加いただいた多くの皆さんは、これまで私たちが開催した個人データ保護週間にご参加いただいています。今年は、このイベントをシンガポール・データ・フェスティバルへと拡大いたしました。このことを指摘してくださった方も複数いらっしゃいます。
これはデータ保護がもはや重要ではないからではありません。今なお重要です。
しかし、組織はデータについてより大きな質問を投げかけています。特に、自社のAI取り組みをどのようにサポートするかについてです。
したがって、データ・フェスティバルは、私たちがデータのビジネス価値をより良く認識するために設計されています。同時に、持続的な価値を創造するために、シンガポール及び地域内において信頼できるデータエコシステムを構築するために協力する必要があります。では、ビジネス価値の源泉としてのデータについて、もう少し詳しく語ってみましょう。
ビジネス価値の源泉としてのデータ
ご存知の通り、企業は、そう呼ぶかどうかに関わらず、常にデータを活用してきました。
小売業者は売上データを見て、変わりゆく顧客嗜好を評価し、それに応じて在庫水準を調整しています。
銀行は取引データを調べて詐欺の証拠を探し、どのアカウントと顧客が問題かを判断し、それにどう対処するかを決定しています。
データはかつて企業に何が起きたかを伝えるものでした。すべて過去形だったのです。しかし今、テクノロジーの助けを借りて、企業は展開をほぼリアルタイムで見ることができ、適切に使用されたデータは、企業が後からではなくより早く正しい行動をとるのを支援できます。
さて、私たちは皆、予期しない事態に見舞われるのではなく、より早く行動することができることを望んでいます。AIはこのプロセスを加速させます。AIシステムはそのライフサイクルのあらゆる段階でデータに依存しています。実は、IMDAは一貫してAIの前にデータについて語ってきました。しかし、良質なデータがなければ、最高のシステムでさえ有用な結果を生み出すのに苦労するでしょう。
AI時代においてデータガバナンスがより一層重要となる理由はここにあります。
データは信頼があるときにのみ価値を創造する
根本的に、データガバナンスは信頼に関するものです。
顧客は、組織がデータを適切に保護し、責任をもって使用することを信頼する場合にのみ、データを共有します。
企業は、データが自社の利益を損なうために悪用されないと信頼する場合にのみ、パートナーとデータを共有します。
これが、シンガポールが常にデータ保護を十分に機能するビジネス環境の不可欠な要素と考えてきた理由です。実は、ビジネスイノベーションの鍵なのです。
信頼できるデータ利用のための適切な条件の構築
また、信頼できるデータガバナンスには、適切な能力と明確な説明責任が必要だと考えています。この2つが同時に備わることが必要ですので、私たちがこれらの分野を強化している2つの方法についてご説明させていただきます。
AIおよびデータ能力の開発
第1は、組織がデータとAIをうまく活用するためのノウハウを構築するのを支援することです。
ほとんどの組織は既にAIとデータの可能性を認識しています。
より難しい質問は、私たちがどのようにしてそれを最大限に活用し始めるかです。
デジタルツインは、今日の企業にとって1つの実用的な機会です。
デジタルツインは、物理資産、システム、またはプロセスのリアルタイムの仮想表現です。
企業はそれを使用してシナリオをシミュレートし、業務を最適化し、より良い意思決定を行うことができます。
デジタルツインはそれほど珍しくはありません。どのF1チームに話を聞いても、彼らはデジタルツインを持っています。なぜなら、エンジニアリング改善がクルマとドライバーのパフォーマンスに与える影響をシミュレートする必要があるからです。つまり、これらのデジタルツインは、テクノロジーに精通している企業や、技術の最先端にいる企業によって使用されてきました。しかし、今日ではSMEでさえ潜在的に独自のデジタルツインを構築する可能性があると考えています。
Exceltecを例に挙げてみましょう。シンガポールの施設管理企業です。
同社は、顧客の拠点である70以上のサイトからのセンサーデータに基づくデジタルツインを構築しました。クライアントに代わって施設管理を実施しているため、70のサイトにセンサーを設置し、センサーデータを活用することができます。構築したシステムはこのデータを継続的に分析し、運用上の問題を早期に特定するのに役立ちます。
例えば、建物の空調システムが故障の兆候を示していないでしょうか?
あるいは、明確な理由のない水使用量の増加は、どこかの漏水を示唆していないでしょうか?
手動検査への依存と比較すると、Exceltec のチームは、対応が必要な場合に自動的にアラートを受け取ることができるようになりました。
これにより、各チームは検査ごとに1日約45分の時間を節約することができました。
多くの建物、チーム、日数にわたれば、その効果は蓄積されます。
さらに重要なことに、組織は問題への対応から、より早期の検出と迅速な対応へと移行しています。
Exceltec のような企業がさらに恩恵を受けられるよう支援するために、IMDA は「Digital Twin For Enterprises Playbook」を立ち上げています。これは、組織が AI とデータをより良く組み合わせ、運用上のボトルネックに対処するためのデジタルツインを設計するのに役立つ実践的な法的ガイドです。これは私たちが実現したいことの一つです。
良好な説明責任の在り方を明確にする
より多くの組織が生成 AI ツールを開発、適応、または展開するにつれて、私たちは説明責任という問題に対処する必要があります。
例えば、顧客からの問い合わせにより迅速かつ正確に対応できるよう、通話録音を使用して生成 AI モデルを改善したいと考えているカスタマーサービスチームを考えてみてください。
私たちはすべて、これらの通話の受信者であり、品質チェックと改善のために通話が記録される可能性があることを尋ねられたり伝えられたりしています。しかし、その録音には個人データ(名前、住所、請求詳細など)が含まれている可能性があることも承知しています。
これらのカスタマーサービスチームが、顧客のデータをモデルトレーニングに使用する前に、顧客に対して負う義務は何ですか?
本日、PDPC は「生成 AI での個人データの使用に関するアドバイザリーガイドライン」を発行しています。
業界と一般の方々に相談した上で、私たちは、個人データの所有者から同意を求めるという PDPA の既存の法的要件を、組織がどのように充たすことができるかを明確にしています。生成 AI モデルの開発または改善のために個人データが使用される場合、組織はユーザーが気付かないか理解できないような広い説明に依存するのではなく、それを明確に述べるべきであることを明確にしています。
私が説明した例のカスタマーサービスチームの場合、同意した顧客の通話録音が AI モデルのトレーニングと改善に使用されることを明記するようにプライバシーポリシーを更新できます。
スタッフが同意を求める際に使用するスクリプトも更新することができます。
その後、顧客は目的を理解し、同意を与える前に情報に基づいた判断を行うことができます。
多くの組織は既に今日、このような AI 固有の通知を提供しています。したがって、本ガイドラインはさらに先を行っています。
また、AI バリューチェーン全体の関係者の役割と責任、および公開されているデータに依存する際のデューデリジェンスもカバーしています。
既存の要件が生成 AI にどのように適用されるかについてより明確になることで、企業は適切なセーフガードを備えたより良いプロセスを設計できます。
データレイヤーを超えて、私たちは AI アプリケーションの説明責任もサポートしています。
ほとんどのユーザーにとって、最も頻繁に出会う生成 AI アプリケーションはチャットボットです。
私たちはアプリケーションを使用しますが、その制限事項やデータに何が起こるのかを知らないかもしれません。
通常、その情報は存在しています。しかし、それは利用規約、プライバシー通知、その他の文書に散在しており、多くの場合、通常のユーザーにとって単純すぎるか技術的すぎるかのいずれかです。
このギャップを埋めるために、IMDA は最初のステップとして「生成 AI チャットボット透明性ガイドライン」を立ち上げています。
本ガイドラインは、医薬品のパッケージでよく見かけるラベルのように機能する「チャットボット情報カード」を求めています。
ラベルはすべての科学的詳細を教えてくれるわけではありません。
代わりに、それは本質を教えてくれます:その医薬品が何のためのものか、どのように使用するか、どのくらいの用量が推奨されるか、どのような副作用に気を付けるべきか、いつ使用しないべきか。
情報カードは同じように機能することを目的としています。チャットボットが何のためのものか、何のためのものではないか、データがどのように処理される可能性があるか、およびユーザーがどのように問題を報告できるかを平易な言葉で説明しています。
私たちは自主的なフレームワークから開始し、実務慣行の成熟に伴い業界の意見を取り入れながら改善していきます。
DBS、Google、Meta、OCBC、SIAといった企業からのサポートに心強さを感じています。これらの企業は、チャットボットの透明性慣行をさらに改善する際に、本ガイドラインを参考にしていきます。
Googleの場合、これはGeminiアプリに関する主要な情報を統合し、その情報をユーザーが容易にアクセスできるようにすることで、ユーザーはより自信を持ってGeminiを利用できるようになります。
Metaも、AI搭載ツールおよび製品がどのように機能するか、人々がそれらとどのように相互作用できるかについて、明確でアクセス可能な情報を提供します。
先ほど述べた企業は、データおよびAIガバナンスにおいて指導的役割を示す先駆的企業です。多くの企業がその足跡をたどることを期待しています。
エコシステムの共同構築
信頼されたデータおよびAIエコシステムの構築におけるパートナーシップの重要性について、本日申し上げたい最終的なポイントがあります。
シンガポールであれ他の地域であれ、AI施設を開発する際には、企業、技術提供者、研究者、実務家、標準化機関、および規制当局から構成される強力なコミュニティが必要です。互いに学び、アイデアをテストし、一緒に基準を引き上げていく必要があります。
良い例として、1月に開催された今年のAI Safety Red Teaming Challengeが挙げられます。
80人以上の専門家が参加しました。
ASEAN加盟国全体、および中国、インド、日本、および韓国から参加者がいました。
彼らのタスクは、生成型AI応用が本来漏洩すべきではないデータを漏らす可能性があるかどうかをテストすることでした。
参加者は研究者とサイバーセキュリティ専門家だけではありませんでした。地域の言語、文化、および文脈を理解する言語学者および社会学者も含まれていました。これが実際に大きな違いをもたらしました。
あるチームは、英語では拒否された有害な要求がクメール語で応答されることを発見しました。
他のチームは、形式的な要求は通さないセーフガードをカジュアルな地域表現は通り抜けることができることを発見しました。
言い換えれば、モデルは形式的な要求に対しては適切に応答しましたが、地域的な表現で提示された要求に対しては、モデルのセーフガードが失敗しました。
この脆弱性および特定された多くの他の脆弱性は、技術的なだけでなく、言語的および文化的でもありました。
これが、本日お伝えしたいより広い教訓です。
自国の境界線の中だけに目を向けていては、信頼されたデータエコシステムの構築はできません。
地域から幅広い専門家を集めたときにのみ、モデルリスクのより完全な多様性を見ることができます。
シンガポールが来年ASEAN議長職を担うようになるにつれて、地域全体でデータが信頼を持って使用されるための条件を強化するために、地域パートナーと協力します。これは以下を意味します。
私たちのアプローチをより密接に結びつけること、
ビジネスの不要な摩擦を減らすこと、および
デジタル経済の成長のためにより多くの余地を作ることです。
最終的に、プレイブック、ガイドライン、または技術基準は単独では成功しません。人々および組織がそれらを実践に移し、学んだことを共有し、集合的に基準を引き上げるときにのみ、それらは意味を持つようになります。
だからこそ、このフェスティバルが重要なのです。
本フェスティバルは、データを保護する人、データを活用する人、AIシステムを構築する人、そしてそれらの利用を統治する人々を一堂に集めます。
これは、良いアイデアをより良い実践に変え、シンガポールおよび地域における信頼されたデータ使用のためのより強固な基礎を構築するのに役立ちます。
そして、その点で、フェスティバルで皆様が実り多い日を過ごされることを願っています。本日はここにお越しいただきありがとうございます。
英語原文
MDDI 公式サイト原文 · 取得日: 2026-07-28
Good Morning, colleagues and friends. It was less than four hours ago that the World Cup had its finals. And I was early for this event because I thought the Monday morning traffic would be at a certain level, but today the roads were very quiet. I hope your favourite team won.
The scoreline was actually quite interesting. The last time that Spain won the World Cup, they had a similar scoreline. Quite amazingly, the data shows that on the way to winning the World Cup, they did not drop more than one goal. Kudos to the Spanish team, and kudos to you, for still being here. You must really love data. You deserve a round of applause.
Many of our friends today have joined us on previous occasions when we held the Personal Data Protection Week. This year, we have broadened the event into the Singapore Data Festival. Some of you pointed this out to me.
This is not because data protection is no longer important. It still is.
But organisations are also asking bigger questions about data, especially how to support their AI endeavours.
The Data Festival is therefore designed for us to better recognise the business value of data . At the same time, to create lasting value, we must work together to build a trusted data ecosystem in Singapore, as well as the region. So let’s talk a little more about data as a source of business value.
Data as a source of business value
As you know, businesses have always used data, whether they speak of it as such or not.
Retailers look at sales data to assess changing customer preferences and adjust their stock levels accordingly.
Banks look at transactions data for evidence of fraud, to decide which accounts and parties are problematic, and what to do about them.
Data used to tell businesses what happened. It was all in the past tense. But now, with the help of technology, businesses can see developments as they happen, almost in real time, and data, when used appropriately, can help businesses take the right action sooner rather than later.
Now, we all like to be able to do that, act sooner rather than be caught by surprise. AI accelerates this process. AI systems depend on data at every stage of their lifecycle. In fact, IMDA has consistently talked about data before AI. But without good data, even the best systems will struggle to produce useful outcomes.
That is why data governance matters more, not less, in the age of AI.
Data creates value only when there is trust
At its heart, data governance is about trust.
Customers share data only if they trust the organisation to safeguard it properly and use it responsibly.
Businesses share data with partners only if they trust that the data will not be abused to compromise their own interests.
This is why Singapore has always thought of data protection as essential to a well-functioning business environment. In fact, it is key to business innovation.
Building the right conditions for trusted data use
We also believe that trusted data governance comes with the right capabilities and clear accountability. We need these two to be present at the same time, so let me highlight two ways we are strengthening these areas.
Developing AI and data capabilities
The first is helping organisations build the know-how to use data and AI well.
Most organisations already recognise the potential of AI and data.
The harder question is how do we begin to make the most of it.
Digital twins are one practical opportunity for companies today.
A digital twin is a real-time virtual representation of physical assets, systems, or processes.
Companies can use it to simulate scenarios, optimise operations, and make better decisions.
Digital twins are not so uncommon. If you talk to any F1 team, they do have digital twins, because they need to simulate the engineering improvement impact on the performances of both the vehicle, as well as the driver. So, these digital twins have been used by companies that are tech-savvy and at the frontier of technology. But we see that even SMEs today could potentially build their own digital twins.
You take Exceltec. It is a facilities management company in Singapore.
It built a digital twin that draws on sensor data from more than 70 sites where the company has customer operations. It conducts facilities management on behalf of its clients, so at 70 sites, it has inserted sensors and is able to harness the sensor data. The system that they built analyses this data continuously, and helps identify operational problems early.
For example, is a building’s air-conditioning system showing signs of a breakdown?
Or does water usage appear to have spiked for no apparent reason, suggesting a leakage somewhere?
Compared to the heavy reliance on manual inspections, teams at Exceltec can now be alerted automatically when something needs attention.
This has helped each team save about forty-five minutes a day on each inspection.
Across many buildings, teams, and days, the gains add up.
More importantly, the organisation moves from reacting to problems, to detecting them earlier and acting faster.
To help more companies benefit like Exceltec, IMDA is launching a Digital Twin For Enterprises Playbook. It is a practical legal guide to help organisations better combine AI and data, and design digital twins to address their operational bottlenecks. That’s one of things we would like to do.
Clarifying what good accountability looks like
As more organisations develop, adapt or deploy generative AI tools, we must address the question of accountability.
Take for example, a customer service team that wants to improve a Generative AI model using call recordings, so that they can respond more quickly and accurately to customer queries.
We have all been at the receiving end of these calls, and being asked or told that the call may be recorded for quality checks and improvement. But we also know that the recordings may contain personal data, such as our names, addresses, billing details.
What are the obligations that these customer service teams have to the customers before using their data for model training?
Today, the PDPC is issuing its Advisory Guidelines on the Use of Personal Data in Generative AI.
Having consulted industry and the public, we are making clear how organisations can fulfil an existing legal requirement in the PDPA for consent to be sought from the data owner. We are making it clear that where personal data is used to develop or improve a Generative AI model, organisations should say so plainly, rather than rely on broad descriptions that users may not notice or understand.
For the customer service team in the example that I described, they can update the privacy policy to state that call recordings of consenting customers will be used to train and improve AI models.
They can also update the scripts that staff use when seeking consent.
Customers can then understand the purpose and make an informed choice before giving consent.
Many organisations already provide such AI-specific notices today. Therefore, the Guidelines go further.
They also cover the roles and responsibilities of parties across the AI value chain, and due diligence when relying on publicly available data.
With greater clarity on how existing requirements apply to Generative AI, companies can design better processes with the right safeguards.
Beyond the data layer, we are also supporting accountability for AI applications.
For most users, the Generative AI application they meet most often is the chatbot.
We use the application, but may not know itslimitations , or what happens to our data.
The information usually exists. But it is scattered across the terms of service, privacy notices and other documents, and is often either too simplistic or too technical for ordinary users.
To close this gap, IMDA is launching the Generative AI Chatbot Transparency Guidelines as a first step.
The Guidelines call for a Chatbot Information Card that works like the label we often find on the packaging of medicinal products.
The label does not tell us every scientific detail.
Instead, it tells us the essentials: what the medicine is for, how to take it, how much is recommended, what side effects to watch for, when not to use it.
The Information Card is meant to work the same way. It sets out in plain language what the chatbot is for, what it is not for, how data may be handled, and how users can report issues.
We are starting with a voluntary framework, and will refine it with industry inputs as practices mature.
We are heartened by the support from companies like DBS, Google, Meta, OCBC and SIA, who will be using the Guidelines as a point of reference as they continue improving transparency practices for their chatbots.
In Google’s case, this means consolidating key information about the Gemini app, and making that information easily accessible to users, so that they can use Gemini with greater confidence.
Meta will also provide people with clear and accessible information about how its AI-powered tools and products work and the ways people can interact with them.
The companies I mentioned are early adopters who are demonstrating leadership in data and AI governance. We hope many more will follow their tracks.
Building the ecosystem together
This brings me to a final point I would like to make today about the importance of partnership in building trusted data and AI ecosystems.
In developing our AI hubs, whether Singapore or elsewhere, we need a strong community of businesses, technology providers, researchers, practitioners, standards bodies and regulators. We need to learn from one another, test ideas, and raise standards together.
One good example is this year’s AI Safety Red Teaming Challenge held in January.
More than 80 experts took part.
They came from all ASEAN countries, as well as China, India, Japan, and Korea.
Their task was to test whether Generative AI applications could leak the data they were not supposed to.
The participants were not only researchers and cyber experts. They also included linguists and sociologists who understood local language, culture, and context. That turned out to have made a real difference.
Some teams found that a harmful request refused in English was answered in the Khmer language.
Others found that casual local phrasing could slip through the safeguards that a formal-sounding request could not.
In other words, the model responded to a formal request the way it should, but when the request was put to it with local phrasing, the model safeguards failed.
This vulnerability, and many others that were identified, were not only technical; they were also linguistic and cultural.
That is the wider lesson we would like to share today.
None of us can build a trusted data ecosystem by looking only within our own borders.
We see the fuller variety of model risks only when we bring together a range of experts from the region.
As Singapore assumes the ASEAN Chairmanship next year, we will work with regional partners to strengthen the conditions for data to be used with confidence across our region. This means:
Bringing our approaches closer together,
Reducing unnecessary friction for businesses, and
Creating more room for our digital economies to grow.
Ultimately, no playbook, guideline or technical standard succeeds on its own. They become meaningful only when people and organisations put them into practice, share what they have learnt, and collectively raise standards.
That is why this Festival matters.
It brings together those who protect data, use data, build AI systems, and govern their use.
This will help us turn good ideas into better practice and build a stronger foundation for trusted data use in Singapore and the region.
And so, on that note, I wish you all a very fruitful day ahead at the Festival. Thank you once again for being here.