K Kept
← Insights

guides

Legal AI client confidentiality Singapore: data in-house

Legal AI client confidentiality Singapore explained: what MinLaw's guide and PDPA actually require, and what keeping data in-house means.

4 August 2026

A managing partner reviewing an AI vendor’s proposal this month will hear three different answers to the same question. The vendor says the data stays secure. The IT consultant says it has to stay in Singapore. The associate who tried the free version at home says it is probably fine for anything that is not too sensitive. None of those three is a legal citation, and only one of them is close to right.

Legal AI client confidentiality Singapore searches turn up plenty of vendor blogs and few citations, and the topic is not a matter of instinct. It runs on two documents: Section 26 of the Personal Data Protection Act, and the confidentiality principle in MinLaw’s Guide for Using Generative AI in the Legal Sector, published 6 March 2026. Neither says the data has to sit on a server inside Singapore. Both say the firm has to know, in writing, what the vendor does with client input before that input goes anywhere near the tool. This piece works through what “keeping data in-house” actually requires, the checklist a firm can run before signing with any AI vendor, and where the confusion about data residency comes from.

Rule 6 of the Legal Profession (Professional Conduct) Rules 2015 puts the duty of confidentiality on the lawyer, not the tool. MinLaw’s guide interprets that duty for GenAI use through one principle: match the level of protection to the sensitivity of the data, verified on mlaw.gov.sg, 6 March 2026. The guide ranks tool options from least to most protected: free public tools, enterprise commercial deployments, and in-house or own-tenant systems. Confidential client matter belongs at the top of that ladder, not the bottom. Separately, the Personal Data Protection Commission’s Transfer Limitation Obligation under PDPA Section 26 requires an overseas recipient of personal data to provide protection comparable to the PDPA. It does not require the data to physically stay within Singapore’s borders, a distinction the PDPC’s own advisory guidelines spell out and that most vendor pitches skip past.

Where Singapore’s AI data-residency confusion comes from

Ask three AI vendors where a Singapore law firm’s data has to live and at least one will say “in Singapore, by law.” It is a useful sentence for selling an on-premise box, and it is not what the statute says. PDPA Section 26 asks for comparable protection from the receiving country, not a Singapore address for the server. A vendor with SG data centres, a signed data processing agreement, and a contractual bar on training satisfies the obligation as cleanly as a physical server in a firm’s own server room, and costs a fraction as much to run.

That does not make data residency irrelevant. A client can still ask for it, and some matters, cross-border deals with a counterparty’s own residency terms, regulatory filings with a specific jurisdiction clause, genuinely need it. The point is that residency is a client preference or a contract term to negotiate, not a blanket legal floor every AI deployment must clear. Conflating the two pushes firms toward expensive on-premise builds when a properly configured cloud tenant would satisfy both the guide and the statute at a fraction of the cost.

4

due-diligence categories MinLaw's guide expects a firm to check before using an AI vendor with client data: security and confidentiality, technical capability, model performance, and vendor credentials

MinLaw, Guide for Using Generative AI in the Legal Sector, 6 March 2026, Annex E

The checklist before any AI vendor touches client data

A firm can run this without hiring anyone. It mirrors the vendor due-diligence checklist in the MinLaw guide’s Annex E, narrowed to the confidentiality questions that matter most.

  • Get the training-use terms in writing. Ask directly: does the vendor train its models on our inputs, and can we opt out contractually, not just in a settings toggle that could revert. Confirmed and documented, not assumed.
  • Check the retention window. How long does the vendor keep a document or a prompt after the session ends, and does deleting it from the firm’s interface actually delete it from the vendor’s storage.
  • Confirm who can see what. Access controls should restrict a matter’s documents to the lawyers working that matter, with an audit log the firm can pull if a client asks who touched their file.
  • Ask where the data is processed and whether that location, or the vendor’s certifications, gives protection the firm would call comparable to the PDPA, the actual Section 26 test.
  • Get the no-training and confidentiality terms into the master services agreement, not left as a marketing claim on the vendor’s website.
  • Decide the disclosure. If AI is used substantially in the work product, changes what the client is billed, or the tool’s data handling could conflict with a client’s own preferences, the guide points toward telling the client, with an opt-out, in the engagement letter.

A firm that can answer all six in writing has done the confidentiality work the guide asks for, whatever the underlying architecture turns out to be.

What “in-house” should mean in practice

“Keep the data in-house” gets used loosely enough that it is worth being precise about the three tiers a firm is actually choosing between.

A public consumer account, the free tier of a general-purpose chatbot, is the tier the Law Society’s Advisory on the Use of Publicly Available AI Tools, 2 April 2026, tells members to keep away from confidential client work entirely. No contract, no confirmed training terms, the same exposure as pasting a client’s facts into a public forum.

An enterprise commercial deployment sits above that: a paid business tier with a signed agreement, usually with training disabled by default and some retention controls, but still running on infrastructure the vendor operates and the firm does not fully control.

An own-tenant or in-house system is the top tier: the AI system runs inside the firm’s own cloud environment or a dedicated instance, the provider is contractually barred from training on anything that passes through it, and the firm sets its own access and retention rules rather than accepting a vendor’s default. This is the tier that satisfies the guide’s confidentiality principle for genuinely sensitive matter work, and it is also the architecture recommendation Kept’s own diagnostic step produces, aligned to the guide’s tool-evaluation step. Our explainer on the MinLaw guide walks through how that step fits the full five-step framework, and our MinLaw compliance checklist turns all five steps into a working list.

None of the three tiers requires physical hardware in the firm’s office. Own-tenant almost always means a private, isolated slice of a cloud provider’s infrastructure, configured so the vendor cannot see or train on the firm’s documents, not a server in a cupboard. That distinction alone changes a project’s cost by an order of magnitude, and it is where a lot of vendor proposals quietly overbuild.

Where confidentiality shows up in an actual workflow

The tier question matters most where a firm is already putting real client documents through a tool: first-pass document review and due diligence, the workflow where the volume of confidential material is highest and the value of getting the architecture right is largest. Our pieces on AI document review for Singapore law firms and AI due diligence for Singapore law firms cover what a properly built system changes in a live data room, on the same own-tenant architecture this piece describes.

The grant path for the build

Most Singapore law firms clear the SME test the Enterprise Development Grant applies: Singapore-registered, at least 30% local equity, group turnover of S$100 million or less, or group headcount of 200 or fewer. EDG covers up to 50% of a qualifying project’s consultancy and software cost, subject to EnterpriseSG approval, verified July 2026 on enterprisesg.gov.sg. An own-tenant AI system, with the vendor due diligence and access controls this piece describes, sits inside a qualifying project scope. The process, the consultant certification rule, and a worked example are in our EDG grant guide for law firms.

Common questions

Does Singapore law require law firms to keep AI data physically in Singapore?

No. The PDPA's Transfer Limitation Obligation, Section 26, requires an overseas recipient to give personal data protection comparable to the PDPA, not physical storage inside Singapore. There is no data-localisation rule. What matters for client confidentiality is the contract with the AI vendor: no training on the firm's inputs, defined retention, and access controls the firm can audit, verified against the PDPC's advisory guidelines.

Can a Singapore law firm use ChatGPT or a public AI tool for client work?

Not for anything confidential, on a free personal account. The Law Society's Advisory on the Use of Publicly Available AI Tools, 2 April 2026, tells members plainly not to submit confidential client information to a public AI tool, because a personal account carries no contractual assurance against training or retention. An enterprise or in-house deployment with a signed no-training term is the safer tier.

What does 'keeping data in-house' actually mean for an AI system?

It means the AI system runs on the firm's own cloud tenant, or a private instance the firm controls, with the provider contractually barred from training on the firm's documents and with access logged and restricted to the matter team. It does not require on-premise servers in the firm's office. MinLaw's guide ranks tool options in that order: free public tools carry the least protection, enterprise deployments more, in-house or own-tenant the most.

What happens if a firm's AI vendor is found to be storing or training on confidential client data?

The firm carries the exposure, not just the vendor. Rule 6 of the Legal Profession (Professional Conduct) Rules 2015 puts the duty of confidentiality on the lawyer regardless of which tool was used, and a PDPA Section 24 failure to arrange reasonable security sits alongside it. That is why the due-diligence step, confirming the vendor's training and retention terms in writing before a document goes near the tool, has to happen before deployment, not after.

Start here

A 30-minute discovery call. A written assessment within 24 hours.

You bring the problem. We bring the analysis. You leave with a document, not a pitch: no slide deck, no follow-up sequence unless you ask for one.

Book a discovery call hello@keptsg.com