MDDI スピーチ · 2023-07-18

Josephine Teo 大臣による個人データ保護週間開幕式でのスピーチ

· 講演者 · 個人データ保護ウィーク開会式

要点

  • スピーチ内で引用された調査によると、38%の組織が複数の社内システムからのデータ収集に課題を抱え、34%がデータ品質の問題に直面していることが明らかになりました。これはASEANにおける高品質なAI開発に対する構造的な障壁を浮き彫りにしています。
  • シンガポールは2019年にModel AI Governance Frameworkを導入し、その後、業界がAIシステムに関してより高い透明性を確保することを目的とした、テストフレームワーク兼ソフトウェアツールキットであるAI Verifyをオープンソース化しました。
  • シンガポールのPersonal Data Protection Commissionは、AIの推薦システムおよび意思決定システムにおける個人データの利用に関する諮問ガイドラインを公開コンサルテーションに向けて推進しており、AIモデルのトレーニングおよび消費者の同意取得に関して企業にとってより明確なルールを提供しています。
  • 2022年に開始されたIMDAのPrivacy-Enhancing Technology Sandboxパイロットプログラムは、金融、eコマース、メディア、テクノロジーの各分野から参加者を集めており、Zuellig PharmaはPETsを活用してデータ規制への準拠を維持しながら、アジア全域における医薬品の流通動向に関する分析を導出しています。
  • IMDAとGoogleは共同で「PET x Privacy Sandbox」を立ち上げます。これはプライバシー強化技術の業界における試験と普及を支援するための、Googleがアジアパシフィックにおいて規制当局と締結した初めてのパートナーシップとして説明されています。
  • ASEANは、ASEAN Model Contractual ClausesおよびこれをEUのStandard Contractual Clausesと整合させるJoint Guideを含む越境データ移転メカニズムを確立しており、シンガポールは今後議長国を務めるASEAN Digital Ministers Meetingにおいて、この取り組みを推進することを約束しています。

全文翻訳

MDDI 英語原文の翻訳 · 翻訳日: 2026-06-21

おはようございます。Personal Data Protection Weekの開幕にご一緒できることを嬉しく思います。2013年にこのイベントが開催されて以来、初めて、ASEAN全加盟国の国家データ保護当局の同僚の皆さまにもご参加いただいています。

皆さまのご参加は、個人としても集合としても、我々の地域の成長するデジタル経済におけるデータの重要性を示しています。また、人々とビジネスを支援するデータ政策の策定に対するASEANの関心を物語っています。

それゆえ、本日お時間を割いてご参加いただいたASEANの同僚の皆さまに、特に温かい歓迎の意を表したいと思います。

昨年来、人工知能(AI)はニュースの見出しや多くの会話を席巻するようになりました。その興奮の多くは、AIがいかに人間に近く、賢くなったかに関するもので、複雑な質問に答え、エッセイを作成し、コードを書き、さらには驚くべき音楽、画像、動画を生成する能力を持つに至っています。

同様に、AIが生成するコンテンツに関しては多くの懸念もあります。たとえば、偽情報の拡散や詐欺などの犯罪行為に悪用される可能性などが挙げられます。

また、AIが生成するコンテンツに偏見が含まれていたり、特定のグループを差別したりする可能性があるかどうかも問われています。これは、AIモデルの訓練に使用されたデータセット自体に、そのような偏見や差別的な特徴がすでに含まれている場合に起こりえます。

こうした懸念を受け、AIガバナンスは緊急の優先事項となっており、シンガポールを含む一部の国々はすでにその対処に向けた措置を講じています。

私たちは2019年にModel AI Governance Frameworkを導入しました。さらに最近では、オープンソース化されたテストフレームワークおよびソフトウェアツールキットであるAI Verifyの開発を支援する財団を設立し、産業界がAIについてより透明性を高められるよう取り組んでいます。

AIガバナンスを強化するための措置を講じる一方で、AIモデルがどのように開発されているかにも注意を払う必要があります。

多くの点において、AIモデルが生み出す結果は、開発者が使用する訓練データセットの質に依存しています。

「ゴミを入れればゴミが出る(garbage in, garbage out)」という古いことわざはAIにも当てはまります。これはそもそもデータにアクセスできることを前提としています。しかし、高品質なAI実装に向けた2つの前提条件——データへのアクセスと品質——が常に満たされているわけではないことは、私たち全員が知っています。

ある調査によると、以下のことが明らかになっています。

a. 38%の組織が複数の内部システムからのデータ収集において課題に直面していました。これはASEAN地域にも当てはまります。

b. 34%がデータ品質に問題を抱えていました。

場合によっては、これはいくつかの鍵盤が欠けたピアノ、あるいは一部の楽器を欠いたり正しく調律されていない楽器を抱えたりしたオーケストラのようなものかもしれません。音楽は聞こえるでしょうが、おそらく良い音には聞こえないでしょう。しかし、データの問題が建物の柱が欠けていたり不完全であったりする状態に近い場合、その結果はより深刻なものになりえます。

デジタル経済において高品質なAI実装を実現したいのであれば、地域のビジネスが質の高いデータにアクセスし、それを集約できるよう、より多くの取り組みを行う必要があります。これは、広く普及したAIイノベーションの恩恵を受けることを望むならば、不可欠なことです。

同時に、消費者のデータが適切に保護されるよう確保しなければなりません。適切なデータ保護がなければ、人々はデジタルの発展に十分に参加することへの安心感を持てないでしょう。また、AIやその他のイノベーションのためのデータのより広い活用を支持することもないでしょう。

しかし、保護をどのように改善するかは重要です。私たちの目標は、イノベーションが生まれる余地を確保しながら、時間をかけてこの2つの目標をより効果的に両立させる方法を学ぶことであるべきです。こうした考慮事項が、本日さらに詳しくお話しするシンガポールのデータ規制へのアプローチの基盤をなしています。

AIにおける個人データの利用に関する明確性が企業のイノベーションを促進する

個人データを含め、どのデータを使用できるかについて企業が明確な認識を持てば、質の高いデータセットの構築はより容易になります。また、個人データをAIに対して安全かつ信頼できる方法で適用する方法について産業界が明確な指針を持つことで、消費者も恩恵を受けます。

私は3月に、個人データ保護委員会(PDPC)がAI推薦・意思決定システムにおける個人データの利用に関するAdvisory Guidelinesを発表することを表明しました。これは、AIの開発・展開のための信頼できるエコシステムの基盤を構築するという、より広範な取り組みの一環です。

PDPCは非公開協議において幅広いステークホルダーから有益なフィードバックを受け取りました。Advisory Guidelinesが公開に先立ちオープンコンサルテーションの段階へと進むことをお伝えできることを嬉しく思います。

Advisory Guidelinesは、AIモデルの訓練または開発における個人データの利用について、企業にいっそうの明確性を提供するものです。透明性を促進するため、推薦・決定・予測を行うAIシステムへの利用のために個人データを提供する消費者から同意を求める前に行うべき説明に関するガイダンスが設けられます。

また、ガイドラインはAIソリューションプロバイダーがクライアントのPDPA遵守を支援することを奨励しています。これには、クライアントが説明を提供するために必要な情報を容易に抽出できるようにシステムを設計することなどが含まれます。

このAdvisory Guidelineは、推薦および意思決定に使用される従来型のAIシステムに適用されます。

PDPCは、生成AIにおける個人データの利用から生じる新たな懸念を認識しています。たとえば、大規模モデルの訓練や合成メディア、すなわち「ディープフェイク」の生成を目的とした、公開されている個人データの利用などが挙げられます。PDPCはこれらの問題を調査しており、PDPAの下でさらなるガイダンスを提供すべきかどうかを検討しています。

テクノロジーを活用してAIイノベーションを支える信頼されるデータエコシステムを構築する

企業がデータセットを構築するのを政府が支援するもう一つの方法は、プライバシー強化技術(PETs)の活用です。

PETsは、個人データが保護されることを確保しながら、企業が消費者データセットから価値を引き出すことを可能にします。データ共有を促進することを通じて、企業が有用なデータインサイトやAIシステムを開発するのにも役立ちます。

たとえば、PETsを活用することで、銀行はデータを統合し、より優れた不正検知のための革新的なAIモデルを構築しながら、顧客のアイデンティティと金融情報を保護することができます。

IMDAは、プライバシー強化技術(PETs)の産業導入を積極的に促進しています。昨年のPDP Weekにおいて、私はIMDAのPET Sandboxパイロットの立ち上げを発表しました。このパイロットを通じて、参加企業はPETソリューション・プロバイダーのパネルと、PETソリューション開発のための助成金および規制上の指導を含む包括的な支援スイートにアクセスすることができました。

このSandboxは大きな関心を集めています。金融、電子商取引、メディア、テクノロジーなど多様なセクターにわたる産業界との連携により、さまざまなユースケースが開発されました。

一例として、シンガポールに地域本部を置く大手医薬品流通企業Zuellig Pharmaが挙げられます。PET Sandboxへの参加は、Zuellig Pharmaが地域のデータパートナーと連携してPETsを活用する方法を理解するうえで助けとなりました。パートナーのデータへのアクセスにより、規制上の義務を遵守しながら、アジアにおける医薬品の流通動向に関するより精緻な分析を導き出すことが可能となりました。

IMDAのPET Sandboxの成功により、国内外のパートナーとの協力の新たな方途が開かれました。

本日、IMDAとGoogleが共同で「PET x Privacy Sandbox」を立ち上げることを発表できることを嬉しく思います。これは、GoogleがアジアパシフィックにおいてPETsの試験・導入を支援するために規制当局と結ぶ初めてのパートナーシップです。

PET x Privacy Sandboxは、企業と消費者の双方に恩恵をもたらします。

シンガポールおよび地域の多くの企業は、すでに利用しているプラットフォーム上でPETsを活用したプロジェクトを試験的に実施するための安全な場を得ることができます。サードパーティCookieの廃止に伴い、企業はブラウザを通じた消費者行動の追跡にこれを頼ることができなくなり、代替手段としてPETsが必要となります。

消費者は、個人データが侵害される懸念を抱くことなく、より関連性の高いコンテンツの提供を受ける体験をすることができます。

実際、IMDAがPET Sandboxにおいてテック企業と連携するのは今回が初めてではありません。大企業から中小企業まで、すでに多くの企業がIMDAのPET Sandboxに参加しています。IMDAはこうした連携をさらに積極的に推進しています。実験とテストを通じて、強固なテクノロジー・エコシステムの構築を目指しています。国境を越えたデータの流通を促進し、AIの恩恵を享受するASEANの能力を高める

データアクセスを向上させるもう一つの方法は、国境を越えたデータ共有を促進することです。これにより、企業が活用できるデータのプールが豊かになり、企業全般から歓迎されています。

しかしながら、国境を越えたデータ移転がいつ、どのような形で許容されるかを定める規制については、明確さが求められます。どの国も外国の手に渡ることを望まないデータセットが存在することは確かであり、それらは適切に保護されなければなりません。しかし、このことは、ビジネスイノベーションを支える非機微データの流通を妨げるものであってはなりません。

シンガポールは、許容される国境を越えたデータ流通に関する明確かつ透明性のあるガイドラインが、データローカライゼーション・ルールの一律かつ画一的な適用よりも効果的であると考えています。この点において、インドネシアやタイなどの近隣諸国が国境を越えたデータ移転を可能にする進歩的な法律を制定したことを高く評価します。こうした取り組みを地域レベルでさらに後押しすることができます。

ASEANは国境を越えたデータ流通を戦略的優先事項として認識しており、堅牢かつ実用的なデータ移転メカニズムの開発を通じて整合性の実現に向けて取り組んできました。

いくつかの重要な分野において良好な進展が見られます。例えば、2016年にASEAN Framework on Digital Data Governanceを導入し、地域のデータ移転メカニズムの開発を戦略的優先事項として位置づけました。そのようなデータ移転メカニズムの一つが、ASEAN Model Contractual Clauses(MCCs)であり、データ移転に関する地域の規制要件に準拠した契約の作成を支援するための「すぐに使えるテンプレート」を企業に提供するものです。

地域として、企業のデータへのアクセスを強化するため、ASEANとEUの間の国境を越えたデータ流通の促進にも取り組んできました。

ASEAN MCCsとEU Standard Contractual Clauses(SCCs)に関するJoint Guideは、二つのテンプレート間の共通点を明らかにしています。これにより、共通理解の醸成が促され、ASEANとEUのビジネスパートナー間のデータ移転に関する契約交渉が円滑化されます。

シンガポールは、このプロジェクトの次の段階においてASEANおよびEUのパートナーと引き続き協力してまいります。来年の次期ASEAN Digital Ministers Meeting(ADGMIN)議長国在任中に、これを実現へと導くことを目指しています。

結論

結びに当たり、デジタル経済の発展においてデータの安全かつ責任ある利活用へのご関心とご支援をいただいたすべての皆様に感謝申し上げます。

AIの台頭は、データの価値と重要性を改めて浮き彫りにしています。規制当局として、私たちはデータの適切な保護と倫理的な利活用を確保する責務を負っています。同様に、AIモデルが質の高いデータをもとに構築されることを確保することも重要な関心事です。

AIエコシステムの実現基盤としてのデータの価値を最大化するため、私たちは包括的なアプローチを採用することができますし、そうすべきです。これには、国際的かつマルチステークホルダーによる協力が必要となります。

本日取り上げた分野——AIシステムにおける個人データ利用のガイドライン、PETs、および国境を越えたデータ流通の促進——は、この進化する分野と非常に重要な議論にシンガポールが貢献することを望む方途です。

今後数日間、こうした取り組みについてさらに幅広く意見を交換し、この重要な取り組みをともに前進させることを楽しみにしています。

今後の議論が実り多く、示唆に富むものとなりますよう願っております。

ありがとうございました。

スピーチのPDF版

英語原文

MDDI 公式サイト原文 · 取得日: 2026-06-21

Good morning. I am happy to join you for the launch of the Personal Data Protection Week. For the first time since this event has been organised in 2013, we are joined by our colleagues from the national data protection authorities of all ASEAN Member States.

Your presence, individually and collectively, reflects the importance of data to our region’s growing digital economy. It also says something about ASEAN’s interest in developing data policies that help people and businesses.

Therefore, I would like to extend an especially warm welcome to our ASEAN colleagues, for making time to be here today.

In the past year, Artificial intelligence (AI) has come to dominate the headlines and a lot of conversations. Much of the excitement is around how human-like and clever AI has become, with the ability to answer complex questions, compose essays, write code, or even produce amazing music, images, and videos.

Equally, there are many concerns about AI-generated content, including how it can be misused for disinformation or criminal activities like scams.

Another question is whether AI-generated content contain biases or discriminate against certain groups. This could happen if the datasets used to train the AI models already contain such biases and discriminatory features.

As a result of these concerns, AI Governance is an urgent priority which some countries are already taking steps to address, including Singapore.

We introduced the Model AI Governance Framework in 2019. More recently, we set up a foundation to guide the development of AI Verify, a testing framework and software toolkit that has been open sourced, to help industries be more transparent about their AI.

While we take steps to strengthen AI Governance, we should also pay attention to how AI model are being developed.

In many ways, the AI models produce results that are only as good as the training datasets used by the developers.

The old saying “garbage in, garbage out” applies to AI too. This already presumes that data is accessible in the first place. And yet we all know that the two pre-conditions for high-quality AI implementation – data access and quality – are not always met.

One survey found that:

a. 38% of organisations faced challenges collecting data from multiple internal systems. This applies to the ASEAN region;

b. 34% had problems with data quality.

In some cases, this may be like a piano with a few missing keys, or an orchestra that has left out some instruments or have some of the instruments not properly tuned. You will still hear music, though it will probably not sound very good. However, if the data issues are more like missing or poorly-made pillars of a building, the consequences could be more serious.

If we want to see high quality AI implementation in our digital economy, we will need to do more to help businesses in the region access and collate quality data. This is necessary if we hope to benefit from widespread AI innovations.

At the same time, we must ensure that consumers’ data are properly protected. Without proper data protection, people will not feel safe enough to fully participate in digital developments. Nor will they support the greater use of data for AI and other innovations.

But how we improve protection is important. Our aim should be to do so whilst allowing innovation to take place and learning how to marry these twin objectives more effectively over time. These considerations underpin Singapore’s approach to data regulations, which I will say more about today.

Clarity on use of personal data in AI helps companies innovate

Quality data sets are easier to build once companies are clear on what data they can use, including personal data. Consumers also benefit when industry has clarity on how personal data can be applied to AI in a safe and trusted manner.

I had announced in March that our Personal Data Protection Commission, the PDPC, would be launching Advisory Guidelines on the use of Personal Data in AI Recommendation and Decision Systems. This is part of our wider effort to lay the groundwork for a trusted ecosystem for AI development and deployment.

The PDPC has received useful feedback from a wide range of stakeholders during closed consultations, and I am pleased to share that the Advisory Guidelines will now progress to the stage of open consultation, before being published .

The Advisory Guidelines will provide businesses with more clarity on the use of personal data to train or develop AI models. To promote transparency, there will be guidance on explanations that should be provided before seeking consent from consumers who are providing personal data for use in an AI system to make recommendations, decisions, or predictions.

The Guidelines also encourage AI solution providers to support their clients in their compliance with the PDPA. This can include designing systems such that it is easy to extract information clients need for providing their explanations.

This Advisory Guideline applies to traditional AI systems used for recommendations and decision-making.

The PDPC recognises the new concerns arising from the use of personal data in generative AI. For instance, the use of publicly available personal data to train large models, to produce synthetic media or ‘Deep Fakes’. The PDPC is looking into these issues and considering whether further guidance should be provided under the PDPA.

Harness technology to build up a trusted data ecosystem that supports AI innovation

Another way for governments to help companies build up their datasets is through the use of privacy enhancing technologies, or PETs.

PETs allow businesses to extract value from consumer datasets, while ensuring that personal data is protected. Through facilitating data sharing, they can also help businesses develop useful data insights and AI systems.

For instance, using PETs, banks can pool data and build innovative AI models for better fraud detection, while protecting their customers’ identity and financial information.

IMDA actively encourages industry to adopt PETs. At PDP Week last year, I announced the launch of IMDA’s PET Sandbox pilot. Through this pilot, participating businesses could access a panel of PET solution providers and a comprehensive suite of support, including grants to develop PET solutions and regulatory guidance.

This Sandbox has generated much interest. A range of use cases have been developed in partnership with industry across diverse sectors such as finance, e-commerce, media, and technology.

One example is Zuellig Pharma, a major pharmaceuticals distribution firm with regional headquarters in Singapore. Joining the PET Sandbox helped Zuellig Pharma understand how to use PETs in collaboration with regional data partners. Access to their partners’ data have helped them derive more precise analytics around the movement of pharmaceutical products in Asia, while complying with their regulatory obligations.

The success of IMDA’s PET sandbox has opened new ways for us to work with local and international partners.

I am glad to announce that IMDA and Google are jointly launching the “PET x Privacy Sandbox” today. This is Google’s first partnership in Asia Pacific with a regulator to support industry in testing and adopting PETs.

The PET x Privacy Sandbox will benefit both companies and consumers.

Many companies in Singapore and the region will gain a safe space to pilot projects using PETs on a platform they already operate on. With the deprecation of third-party cookies, businesses can no longer rely on these to track consumers’ behaviour through the browser and will need PETs as an alternative.

Consumers will experience being served more relevant content without fearing that their personal data is compromised.

This is, in fact, not the first collaboration that IMDA has with tech companies in the PET sandbox. We already have many companies, large and small, participating in IMDA’s PET sandbox. IMDA is actively pursuing more of such collaborations. Through experimentation and testing, we strive to build a robust tech ecosystem. Facilitate cross border data flows to boost ASEAN’s ability to gain from the benefits of AI

Another way to improve data access is through facilitating data sharing across borders. This enriches the pool of data companies can draw on and is generally welcome by businesses.

However, there must be clarity on the regulations that determine when and how such cross-border data transfers are acceptable. There are certainly datasets which no country will be comfortable falling into foreign hands, and which must be properly secured. This should however not prevent the movement of non-sensitive data that supports business innovations.

Singapore believes that clear and transparent guidelines on permissible cross-border data flows work better than a blunt application of data localisation rules across the board. On this, we commend our neighbours such as Indonesia and Thailand for enacting progressive legislation to enable data transfers across borders. We can give these efforts a further boost at the regional level.

ASEAN recognises cross-border data flows as a strategic priority, and we have been working towards alignment through the development of robust and practical data transfer mechanisms.

We have made good progress in some key areas. For example, we introduced the ASEAN Framework on Digital Data Governance in 2016, which established developing regional data transfer mechanisms as a strategic priority. One such data transfer mechanism is the ASEAN Model Contractual Clauses (MCCs), which provide a “ready-to-use" template to help businesses develop contracts in compliance with regional regulatory requirements for transferring data.

As a region, we have also worked to facilitate cross-border data flows between ASEAN and EU to enhance companies’ access to data.

The Joint Guide to the ASEAN MCCs and EU Standard Contractual Clauses (SCCs) identifies commonalities between the two sets of templates. This helps foster a common understanding and facilitates contractual negotiations on data transfers between ASEAN and EU business partners.

Singapore will continue to work with our ASEAN and EU partners on the next stage of this project. We hope to steward this to fruition during our upcoming ASEAN Digital Ministers Meeting (ADGMIN) Chairmanship next year.

Conclusion

To conclude, I thank everyone here for your interest and support for the safe and responsible use of data in developing the digital economy.

The rise of AI underscores the value and importance of data. As regulators, we have a duty to ensure their proper protection and ethical use. Equally, we have an interest to ensure AI models are built with quality data.

We can and should adopt a holistic approach to maximise the value of data as an enabler for the AI ecosystem. This will require an international and multi-stakeholder cooperation.

The areas I touched on today – guidelines for the use of personal data in AI systems, PETs, and facilitating cross-border data flows – are ways Singapore hopes to contribute to this evolving field and very important conversation.

In the next few days, we look forward to exchanging ideas on these initiatives and more, so that we can together take this important work forward.

I wish you insightful and fruitful discussions ahead.

Thank you.

PDF version of the speech