The last stage is the one most agencies miss. When enquiries are tracked by topic, the patterns tell policy and programme teams where guidance is unclear, long before a formal review would.
Which data protection rules apply to public bodies?
The answer differs by market, and it is not always the law that applies to private companies.
- Singapore. The government states that the Personal Data Protection Act “applies to the private sector”. Public agencies are governed instead by the Public Sector (Governance) Act and government instruction manuals and policies on data protection and security (Singapore government).
- Malaysia. Section 3 of the Personal Data Protection Act 2010 states that it “shall not apply to the Federal Government and State Governments” (PDPA 2010). Statutory bodies, contractors and each agency's internal policies need their own legal review.
- Philippines. The Data Privacy Act of 2012 applies to the processing of personal information broadly, and Section 22 requires heads of government agencies to secure sensitive personal information to the most appropriate standard, with the National Privacy Commission monitoring compliance (National Privacy Commission).
An exemption from a private sector law is not a licence to be careless. Agencies hold some of the most sensitive data there is, and public trust depends on handling it well. We design to the agency's own data classification, collect only what each case needs and keep identity documents in the systems built for them.
What about data residency?
HubSpot hosts customer data in data centres in the European Union, Canada, Australia and the United States, and says it does not currently have immediate plans for additional data centres (HubSpot). For an agency, that makes residency a question to settle at the start. Some agencies may only place certain classes of data in a given environment, or only after approval. Confirm the classification of the data the CRM will hold, and whether the agency's cloud policy permits it, before design begins.
How does procurement shape the project?
Public procurement is formal for good reason, and the project plan should follow it rather than work around it. In Singapore, GeBIZ is “the Singapore Government's one-stop e-procurement portal” (GeBIZ). In the Philippines, the New Government Procurement Act, Republic Act 12009, was signed on 20 July 2024; the Procurement Service of the Department of Budget and Management says it modernises PhilGEPS and introduces new award criteria and procurement methods (PS-DBM).
In practice, scope licences and services separately and clearly, define deliverables that can be evaluated, and plan the timeline around the procurement calendar. A well-written requirement, focused on outcomes such as response time and case visibility rather than features, makes evaluation fairer and the project easier to run.
Where can AI agents help, and where must they stop?
Agents can help with the large volume of general questions agencies receive: opening hours, eligibility criteria that are already published, how to apply, where to find a form, the status of a programme. They should answer only from published, approved content, and say so.
They should not make or imply decisions on individual applications, interpret law for a specific case, or handle anything involving personal circumstances. Those go to an officer, with the conversation on the record. Every agent needs an owner, a reviewed knowledge base and a clear path to a person. HubSpot's Customer Agent supports default and custom handoff triggers, live or asynchronous (HubSpot Knowledge Base).
What should an agency measure?
- Response time to new enquiries, by channel.
- Case age, and cases open beyond the service standard.
- Time to resolve, by topic.
- Satisfaction after each case.
- Repeat enquiries on the same topic, as a signal for clearer guidance.
How do you govern the platform once it is live?
Public bodies are accountable for how they use technology long after a project closes. Governance should be designed in from the start, not added after an audit question.
- Ownership. Name a business owner for the platform, not only an IT administrator, and an owner for each programme that uses it.
- Access. Give officers access only to the cases and records their role needs, and review access when people move.
- Retention. Agree how long each type of record is kept, and how it is deleted or archived at the end of that period.
- Content. Review the knowledge an agent answers from on a fixed schedule, with a named owner for each topic.
- Audit. Keep a record of configuration changes, and report case volumes and service standards to leadership regularly.
Agencies that plan for these from the first workshop find that audit and security reviews become routine rather than disruptive. They also find it easier to extend the platform to the next programme.
Where to start
Settle the rules first: data classification, residency, applicable law and procurement route. Then pick one programme or one stakeholder group, bring its enquiries into one place and track them as cases. Add outreach and feedback, and only then an agent for published information. Our data protection answer covers the private sector laws in more detail.