AI safety monitoring deployments go live in approximately 1 hour on existing CCTV infrastructure — no new cameras, no rewiring, ONVIF-compatible cameras the plant already operates. The technical side is not where procurement typically stalls. What stalls procurement is question 14 of the IT security review questionnaire — something about data retention periods or PDPA applicability — going unanswered for three weeks while the budget cycle turns.
The gap between an EHS manager's confidence in a system and an IT security reviewer's confidence in the same system is almost always an information gap, not a risk gap. EHS has seen the pilot. IT has a questionnaire. The questions that stall deployment cluster into four areas: what the system collects and stores, how long it is retained, who has access, and whether it falls under employment-related personal data regulations in Singapore or Malaysia.
Each of these has a specific technical answer. The answers are favorable, but they do not reach the IT review unless someone prepares them in advance. This post provides the architectural facts and the regulatory framing — in plain language — so that the legal and IT review starts with accurate information rather than assumptions about what "AI on CCTV" means.
A note on scope: this is not legal advice. PDPA compliance for your specific deployment requires your own legal counsel. What follows is the technical and architectural framing that governs the compliance questions, so the legal review engages with what the system actually does rather than what IT assumes it does.
What AI safety monitoring actually stores
The single most consequential fact in the data-retention conversation: HyperQ AI Safety is event-driven, not continuous.
A standard industrial DVR records everything — 24 hours a day, 7 days a week, regardless of what is happening on screen. Retention is limited only by storage capacity and loop settings, typically 30 to 90 days before the system overwrites itself. This is the data profile most IT reviewers assume when they see "AI on CCTV."
An AI safety monitoring system monitors continuously but stores selectively. The camera feed is processed at the edge in real time for defined safety event types: falls, PPE non-compliance, zone intrusions, fire and smoke detection, man-down conditions, smartband vital-sign alerts. When a defined event is detected, the system stores a short clip — typically 10 to 30 seconds bracketing the trigger point — and generates metadata: event type, timestamp, zone identifier, device identifier. Outside of detected events, no clip is stored.
The stored data footprint is therefore proportional to event frequency, not to camera count or operating hours. A plant with 20 cameras and a low incident rate may store a handful of event clips per day. That is a materially different data profile from 20 cameras recording continuously at 25 frames per second for 90 days.
This distinction — event-triggered storage versus continuous recording — is the answer to the IT reviewer's question about what the system retains during working hours. It is also the answer to the employee relations question about whether the system records everything workers do.
PDPA Singapore: what applies
Singapore's Personal Data Protection Act (PDPA), administered by the Personal Data Protection Commission (PDPC), applies to the collection, use, and disclosure of personal data by organisations. Workplace CCTV footage that captures identifiable individuals — face, gait, name badge — is personal data under the PDPA. AI safety monitoring falls within scope.
The relevant obligations for a manufacturing deployment:
Purpose specification. The PDPA requires that personal data be collected for a purpose that a reasonable person would consider appropriate in the circumstances. Workplace safety monitoring — fall detection, PPE verification, fire and smoke detection — passes this standard when documented. The purpose must be defined before deployment and stated in the employee notification. It should be specific: "detection of safety events including falls, PPE non-compliance, and unauthorized zone entry" is a purpose definition. "Security monitoring" is not.
Notification. Employees must be informed that their personal data is being collected, the purpose for which it is collected, and how they may access or correct it. Workplace safety monitoring is a recognized category. The minimum notification requirement is signage at camera locations plus an internal communication to all affected staff identifying the purpose, the event types that trigger recording, the retention period, and who has access to clips. Under most PDPC guidance, safety monitoring under an employment relationship operates on the contractual-necessity basis — explicit consent is not required, but notification remains mandatory.
Retention limitation. Personal data should not be retained longer than necessary for the stated purpose. For routine safety event clips (a zone intrusion that resolved without incident), a 30 to 90-day retention window is defensible. Clips tied to a reported incident, an MOM investigation, or an insurance claim should be retained for the duration of the investigation plus the applicable limitation period — 3 years is a conservative baseline for workplace injury claims in Singapore, but your legal counsel should confirm the appropriate window based on the specific incident type.
Access control. Access to event clips should be limited to personnel with a defined need: EHS management, HR for incident investigations, legal for insurance and regulatory matters, and system administrators for maintenance. Access logs should be maintained and available for audit. The PDPC has published guidance stating that access to surveillance footage should be on a need-to-know basis with records of who accessed what and when.
PDPA Malaysia: parallel structure, one additional consideration
Malaysia's Personal Data Protection Act 2010 (as amended) has a parallel structure: purpose limitation, notification, retention, security safeguards. The Malaysian PDPA applies to personal data processed in the course of commercial transactions. Manufacturing operations in Malaysia fall within scope.
The additional consideration for Malaysian deployments: Malaysia's PDPA designates certain categories of data as "sensitive personal data," which includes information about a person's physical or mental health. If the AI safety deployment includes smartband biometric monitoring — heart rate, SpO2, skin temperature — that data stream may be classified as sensitive personal data under the Malaysian PDPA. Sensitive personal data requires explicit written consent from each employee rather than operating on the contractual-necessity basis available for standard camera monitoring.
For camera-only deployments in Malaysia (no wearable component), the analysis closely parallels Singapore's. Purpose documentation, employee notification, defined retention windows, and access control are the four requirements to address.
One operational difference: the DOSH (Department of Occupational Safety and Health) is the relevant regulatory authority for workplace safety in Malaysia. Where event clips are retained as incident evidence for a DOSH investigation, the DOSH process timeline should inform the minimum retention period for those specific clips. Clips relevant to an active investigation should not be deleted on the standard schedule.
Safety monitoring versus productivity surveillance
The distinction between safety monitoring and productivity surveillance matters in two ways: as a regulatory matter and as an employee-relations one. Works councils, union representatives, and employees themselves raise it, and regulators apply different scrutiny to the two categories.
Safety monitoring, as used here: recording triggered by a defined safety event — fall, fire, zone intrusion, PPE non-compliance, man-down. The organizational purpose is to protect workers and document compliance with occupational safety obligations. The organization has both a legal basis (employer duty of care under the WSH Act in Singapore, OSHA in Malaysia) and a recognized legitimate interest.
Productivity surveillance: monitoring directed at measuring individual worker pace, output, rest duration, or task completion. This is the more contested category. It is harder to justify under PDPA purpose-limitation principles and draws works-council objections in many jurisdictions.
A HyperQ AI Safety deployment should be scoped explicitly as safety monitoring through its event-type configuration. The configuration record — which events the system is set to detect, on which zones, approved by which named individuals — is the documented evidence of purpose. If the initial deployment covers falls, PPE, and zone intrusion, that configuration defines the scope. Adding a capability later that monitors individual work behavior requires a separate purpose assessment before the configuration change is made, not after.
The event-type configuration record also answers the "is this surveillance?" question if it is ever raised: it shows what the system detects, what it does not detect, and who authorized the scope. An immutable configuration log makes that answer auditable.
Hardware-agnostic deployment and the smaller compliance surface
HyperQ AI Safety deploys on ONVIF-compatible cameras already installed at the facility — no new camera placements, no expansion of the physical sensing footprint. This has a direct privacy implication.
Many IT reviewers approach AI safety systems as a new data collection layer. Where the existing CCTV is continuous-recording and already within the organization's PDPA scope, adding event-triggered AI monitoring on the same cameras changes the processing activity without expanding the physical sensing. The PDPA-relevant additions are the event metadata, the event clips, and the access and retention policies for those clips. The camera coverage — what physical spaces are monitored — does not change.
That is a materially smaller compliance surface than a deployment requiring new camera installations at additional locations. New cameras mean new data collection at new locations, each of which requires purpose documentation, notification, and access control that was not previously in scope. Hardware-agnostic deployment on existing cameras narrows that surface to the new processing layer only.
Pre-POC compliance checklist
Use the checklist below in a pre-deployment meeting between EHS, IT security, and HR or legal to identify open items before the pilot begins. Items marked "required" should be resolved before go-live; items marked "recommended" reduce ongoing compliance effort.
| # | Item | Owner | Priority |
|---|---|---|---|
| 1 | Purpose statement documented: event types, zones, and safety rationale in writing | EHS | Required |
| 2 | Employee notification prepared: signage plus internal memo covering purpose, event triggers, retention period, and access rights | HR/EHS | Required |
| 3 | Retention policy defined: routine event clips (30-90 days); incident-linked clips (investigation duration plus 3 years, or as advised by legal) | IT/Legal | Required |
| 4 | Access control configured: roles defined, access log enabled, named approvers for clip review requests | IT | Required |
| 5 | Event-type configuration documented and signed off: what the system detects, on which zones, by whom approved | EHS/IT | Required |
| 6 | Data processing agreement with vendor reviewed by legal | Legal | Required |
| 7 | Security review of data storage location, encryption at rest, and access credentials | IT Security | Required |
| 8 | PDPA notification to authority, where required by local regulation | Legal | Required |
| 9 | Wearable biometric component (MY deployments only): if smartband monitoring included, explicit consent framework required for each employee | HR/Legal | Required if wearables included |
| 10 | Works council or union consultation, if applicable to the facility | HR | Required if unionized |
| 11 | Incident clip handling procedure: who may request, who approves, chain of custody, deletion schedule | EHS/Legal | Recommended |
| 12 | Quarterly access-log audit: review who accessed clips, flag anomalies against purpose scope | IT | Recommended |
| 13 | Annual configuration review: verify event-type configuration still matches documented purpose statement | EHS | Recommended |
Items 1 through 8 are the minimum viable compliance set for a camera-only HyperQ AI Safety deployment in Singapore. Item 9 activates for Malaysian deployments that include smartband biometric monitoring. Items 10 onward depend on site-specific factors.
One pattern worth avoiding: completing items 1 and 2 as a formality after the system is already live. Employee notification after deployment — rather than before — has been a source of regulatory findings in Singapore PDPC enforcement decisions. The notification requirement is genuinely pre-deployment.
Frequently asked questions
Does AI safety monitoring require employee consent under Singapore's PDPA? For safety-purpose monitoring under an employment relationship, Singapore's PDPA generally allows the contractual-necessity basis rather than requiring explicit consent. The obligation is notification, not consent: employees must be informed what is being monitored, for what purpose, and how recordings are handled. Signage and a written communication satisfy the notification requirement for most deployments. Confirm with legal counsel that this basis applies to your specific scope.
How long should AI safety event clips be retained? 30 to 90 days is a defensible standard for routine events where no incident occurred. Clips tied to an injury, near-miss investigation, or MOM or DOSH report should be retained for the duration of the investigation plus the applicable limitation period — 3 years is a conservative baseline for workplace injury claims in Singapore and Malaysia. Your legal team should confirm the window for your jurisdiction and incident type.
Does Malaysia's PDPA require consent for smartband biometric data? Malaysia's PDPA classifies health-related data as sensitive personal data, and heart rate, SpO2, and skin temperature from smartband monitoring fall within that classification. Sensitive personal data requires explicit written consent rather than the contractual-necessity basis available for standard camera monitoring. For camera-only deployments in Malaysia with no wearable component, the standard notification approach applies. Confirm current regulatory guidance with Malaysian legal counsel.
What is the difference between safety monitoring and productivity surveillance under PDPA? Purpose definition and event-type configuration determine the classification. Safety monitoring covers defined safety events: falls, PPE non-compliance, zone intrusions, fire and smoke, man-down. Productivity surveillance covers individual work pace, output, rest behavior, or task completion rates. PDPA regulators apply stricter scrutiny to the latter. The clearest protection is a documented and immutable configuration record showing which events the system detects and on which zones — this is the evidence that the deployment remains within the safety-monitoring scope.
Our IT team says any AI system on CCTV is a new data collection activity. Is that correct? It is a new processing activity on data the organization already collects — not a new data collection from new sensors. Where the AI system switches from continuous recording to event-triggered recording, the stored-data footprint decreases. The PDPA-relevant additions are the event metadata and the access and retention policies for event clips. The physical sensing footprint — which cameras cover which areas — does not change on a hardware-agnostic deployment. That distinction is worth establishing early in the IT security review.
Does hardware-agnostic deployment affect PDPA compliance? Yes, favorably. Deploying on existing cameras means no new sensor locations and no expansion of the physical monitoring footprint. The compliance surface is limited to the event-triggered processing layer on cameras already within the organization's PDPA scope. That is smaller than a deployment requiring new camera installations, which would add new data collection points each requiring their own purpose documentation and notification.
