A marketing email should connect a business with its customers. In the Bee Cheng Hiang case, it also exposed customers’ email addresses to other recipients.
According to CNA’s reporting of the Personal Data Protection Commission’s (PDPC) findings, 95,364 customers were affected after an employee used an AI tool to generate a script for distributing marketing emails. PDPC described it as the first AI-related data breach reported to the Commission in Singapore. [1]
For PrivacyTrust, the lesson is practical: organisations should build privacy checks into the way work gets done. Technology adoption needs clear responsibilities, risk assessment and safeguards that protect the people whose information a business holds.
What Happened in the Bee Cheng Hiang Case?
The employee’s prompt requested bulk email distribution without specifying that recipients’ addresses should remain hidden. Testing checked activity logs without inspecting the actual test email, allowing the disclosure to go unnoticed.
PDPC attributed the incident to human error in developing the code, rather than an AI malfunction. It also clarified that the affected addresses were not processed by AI and that there was no evidence of further misuse.
This distinction matters when reviewing the case: the disclosure occurred through the email distribution process.
The Privacy Governance Lessons for Businesses
The recommendations below are PrivacyTrust-oriented practical takeaways from the case.
1. Define Privacy Requirements Before Building an Automation
Start with the outcome that must be protected. For customer emails, specify that recipients must not see anyone else’s address. Document how the system should behave, who can access the mailing list and who approves the final send.
A more detailed prompt can support that process, but the organisation should still verify the resulting code and behaviour.
2. Test What the Recipient Actually Receives
A successful delivery log does not show whether the message protects recipients’ privacy.
Use dummy accounts to inspect the recipient fields, message content, attachments and links before a live send. Ask someone other than the developer to check the results. Define the conditions that would stop deployment.
3. Give Staff Clear Responsibilities
Before introducing an AI-assisted workflow, decide who owns it, who reviews technical changes and when the DPO or privacy lead should be consulted.
Build those responsibilities into a short, usable approval process. Employees should know how to escalate concerns without having to decide alone whether a privacy risk is acceptable.
How Bee Cheng Hiang Responded
The company stopped the bulk email distribution, corrected the script and notified affected customers. It also introduced verification by at least two employees for bulk communications. PDPC accepted a voluntary undertaking to improve its data protection practices. [1]
The PDPC record states that the undertaking was executed on 2 September 2026. [2]
PrivacyTrust’s published approach connects privacy protection with building trust, identifying risks and supporting organisations through compliance measures, technology and employee training. [3]
Applied to this case, that means bringing privacy into operational decisions before an automation reaches customers. A policy should help a marketing employee decide how to send a campaign safely. A review process should help a manager identify what needs checking. Training should give staff the confidence to recognise and raise a concern.
The aim is to make responsible data handling part of everyday work.
What Businesses Should Review Now
Organisations using AI-assisted tools or automated communications can begin with these questions:
• Which workflows can send, export or disclose personal data?
• Have privacy requirements been documented for each workflow?
• Does testing inspect the actual output using dummy data?
• Who independently reviews and approves changes?
• Do staff know whom to contact if something goes wrong?
• Are safeguards reviewed when the workflow changes?
Use the answers to identify gaps and assign owners for corrective action. Prioritise workflows that can distribute information to many people at once.
Strengthen Everyday Data Protection with PrivacyTrust
PrivacyTrust offers DPO-as-a-Service, data protection training and Data Protection Impact Assessment services. Its DPO-as-a-Service includes assessing organisational needs and working with teams to implement policies, procedures and controls. [4]
For businesses reviewing AI-assisted workflows, these services provide a starting point for discussing privacy risks, staff responsibilities and operational safeguards.
Speak with PrivacyTrust about strengthening your organisation’s data protection practices:
Sources
[1] CNA: Nearly 100,000 Bee Cheng Hiang customers’ email addresses exposed in first AI-related data breach in Singapore
https://www.channelnewsasia.com/singapore/bee-cheng-hiang-data-breach-ai-pdpc-emails-6421711
[2] PDPC: Voluntary Undertaking by Bee Cheng Hiang Marketing Pte Ltd
https://www.pdpc.gov.sg/organisations/regulations-decisions/enforcement-decisions/voluntary-undertaking-by-bee-cheng-hiang-marketing-pte-ltd
[3] PrivacyTrust: Our Approach
[4] PrivacyTrust: DPO-as-a-Service