口头答复 · 2026-04-07 · 第 15 届国会

防范公民数据被外资 AI / 数据分析平台处理或披露的保障措施

防范公民数据被外资 AI / 数据分析平台处理或披露的保障措施

AI 治理与监管AI 与国家安全 争议度 3 · 实质辩论

工人党非选区议员 Low Wu Yang Andre 提出关键质询:(a) 全政府数据架构是否允许外资总部的专有 AI / 数据分析平台处理公民数据;(b) 若允许,有何法律与技术保障防止外国政府依本国法(如美国 CLOUD Act)调取这些数据。MDDI 政务部长 Jasmin Lau 答覆:政府采用 risk-based approach,data access 严格按"最小权限/按需访问"原则,要求 vendor 实施非保留、加密、身份与访问管理;高敏感数据可要求 data residency;通过 governance framework 与合同条款限制使用、储存与披露。Low 的追问直指核心:他点名 Palantir Technologies——过去五年成为全球各国政府首选 AI/数据/安全方案供应商;并明确 CLOUD Act 强制美国公司在其法域内披露数据,**即使 data residency 在新加坡也可被强制**。Jasmin Lau 直接承认了这一点:"legal and contractual agreements aside, the reality is that no matter what legal provisions the contracts may contain, some jurisdictions like the US may have legislation including with extraterritorial reach that empower government agencies to require companies within their jurisdictions to provide certain information... Such legislation can override contractual obligations." 这是政府首次在国会公开承认 contractual data residency 在外国域外管辖法律前可被覆盖。

关键要点

  • 外资 AI / 数据平台被允许处理政府数据(risk-based)
  • 议员点名 Palantir + 美国 CLOUD Act 域外管辖
  • 部长承认合同条款可被外国域外法律覆盖
  • 保障转向技术控制 + governance + 用例分类
政府立场

采用风险分级 + 技术控制 + 治理框架,承认合同条款不能完全防外国法

质询立场

质疑 CLOUD Act 等域外管辖对 Singapore 数据主权的实际威胁

政策信号

数据主权策略:从合同保障转向技术 + 治理 + 用例分类的多层防御

"Some jurisdictions like the US may have legislation including with extraterritorial reach that empower government agencies to require companies within their jurisdictions to provide certain information... Such legislation can override contractual obligations."

参与人员(2)

完整译文(中文)

Hansard 英文原文译文

工人党非选区议员 Low Wu Yang Andre 提出关键质询:(a) 全政府数据架构是否允许外资总部的专有 AI / 数据分析平台处理公民数据;(b) 若允许,有何法律与技术保障防止外国政府依本国法(如美国 CLOUD Act)调取这些数据。

MDDI 政务部长 Jasmin Lau 答覆:政府采用 risk-based approach,data access 严格按"最小权限/按需访问"原则,要求 vendor 实施非保留、加密、身份与访问管理;高敏感数据可要求 data residency;通过 governance framework 与合同条款限制使用、储存与披露。

Low 的追问直指核心:他点名 Palantir Technologies——过去五年成为全球各国政府首选 AI/数据/安全方案供应商;并明确 CLOUD Act 强制美国公司在其法域内披露数据,**即使 data residency 在新加坡也可被强制**。

Jasmin Lau 直接承认了这一点:合同条款无法对抗外国域外管辖立法,因此政府的策略不仅依赖合同,更依赖技术控制、治理框架与用例分类——多层防御。这是政府首次在国会公开承认 contractual data residency 在外国域外管辖法律前可被覆盖。

英文原文

SPRS Hansard 原始记录 · 抓取日期:2026-05-03

82 Mr Low Wu Yang Andre asked the Minister for Digital Development and Information (a) whether the whole-of-Government data architecture permits proprietary artificial intelligence (AI) or data analytics platforms from foreign-headquartered vendors to process citizen data; and (b) if so, what legal and technical safeguards ensure that such data cannot be compelled for disclosure by a foreign government under that government's domestic laws. The Minister of State for Digital Development and Information (Ms Jasmin Lau) (for the Minister for Digital Development and Information) : Mr Speaker, the Government uses best-in-class technology solutions, including those from international vendors, to deliver effective digital services for citizens and to support our public officers' work. We have established comprehensive safeguards to protect citizen data when working with any vendor. Our risk-based approach ensures that data access is granted strictly on a "needs-basis" following the principle of least privilege. Vendors are expected to implement robust technical safeguards such as non-retention of data, encryption as well as access and identity management.

Data residency may also be required, depending on the sensitivity of the data. This is coupled with proper governance frameworks and contractual agreements on how the data can be accessed, used, stored and retained. These help to prevent vendors from accessing, using or disclosing government data where they are not permitted to do so, including in response to demands from foreign governments. Our approach combines global expertise, technical safeguards, legal protections and ongoing oversight to ensure that citizen data remains secure. We continuously monitor vendor compliance, conduct regular security assessments and update our frameworks to address emerging risks and maintain public trust. Mr Speaker : Mr Low. Mr Low Wu Yang Andre (Non-Constituency Member) : I thank the Minister of State for the response. I would like to share that the primary reason for me to ask this Parliamentary Question was driven by concerns I have over a specific vendor, which is Palantir Technologies, which, over the last five years or so, has become the preeminent supplier to governments around the globe of artificial intelligence, data and security solutions.

I am not sure if the Minister of State is at the liberty to disclose if we do have any ongoing contracts with Palantir, but I think even if the answer is no, the broader concern remains that overseas legislation like the United States' Clarifying Lawful Overseas Use of Data (CLOUD) Act compels these US-based companies to disclose data in their legal system from foreign countries. Even with data residency in mind, the Act still compels them to disclose this data. What assurances can the Minister of State give that we will not be subject to such compulsions? Ms Jasmin Lau : I thank the Member for the question. I understand that the Member may have filed a separate Parliamentary Question on Palantir for the Ministry of Finance (MOF), which I will leave for MOF to answer. I would like to add that he is right. Legal and contractual agreements aside, the reality is that no matter what legal provisions the contracts may contain, some jurisdictions like, as he mentioned, the US, may have legislation or regulations, including with extraterritorial reach, that empower government agencies to require companies or entities within their jurisdictions to provide certain information.

This could include Singapore Government data. Such legislation or regulations can override contractual obligations. This is why the Government's approach is to rely not solely on contractual provisions, but also on other risk mitigation measures, which I have mentioned, such as technical controls and safeguards as well as governance frameworks, which limit what use cases and categories of information may be used with non-government provided tools and platforms.