1 of 32

Enabling Better Guidance for Data Classifications through an AI-assisted Educational Tool

25th Nov, 2025

Danny Goh

Staff Data Engineer

Data Programme

Anshu Singh

Research Engineer

Data Practice

2 of 32

Agenda

  • The Challenge
  • Deep Diving into our Solution
    • Why an LLM assistant for Data Classification?
    • Design Choices: shaped with agencies and policymakers engagements
    • Evaluation
  • The Impact

2

3 of 32

Enabling Singapore’s Smart Nation Vision With Secure Data Sharing

3

4 of 32

A First Step To Secure Data Sharing:

“Right” Data Classification

  • Sensitivity/Security Assessment potential harm if mis-disclosed
  • Apply anonymization – statistical disclosure control, k-anon, PETs

  • Review in context
  • Check identifiers/sensitive fields
  • Reduce risk, preserve utility

  • Practical tooling for privacy-risk & quality
  • Data- & policy-grounded guidance
  • Auditable and explainable decisions

Policy Expectations

Expectations From Public Officers

What’s Required (the gaps)

5 of 32

Government Officers' Data Sharing Dilemmas

A Hypothetical Scenario

Health Agency (Provider)

Highly sensitive. ⚠️

Share only with safeguards. ⚠️

What could stall data sharing

Right classification

Policy ↔ data translation (whole-of-gov policies + agency policies)

Tooling & guidance

Utility vs risk trade-offs

External sharing needs approvals.

after the data is shared

Education Agency (Requester)

Need student health-visit data

Fields don’t fit our analysis. ⚠️ Need to share with external researchers.

6 of 32

DataSharingAssist (DSA):

Empowering Government Officers With Informed & Confident Data Sharing

Now in prototype after a winning GovTech incubator proof-of-concept

  • “productivity” tool with contextual guidance
  • co-designed with government agencies and policymakers
  • embedded AI assistant grounded in data and policy
  • helps assess data profiling and privacy risk heuristics

6

7 of 32

DataSharingAssist (DSA)

  1. Why an LLM assistant for Data Classification?
  2. Design Choices: shaped with agencies and policymakers engagements
  3. Evaluation

7

8 of 32

Anatomy of DataSharingAssist Tool

Assistant

Sources

Assessment

8

9 of 32

Anatomy of DataSharingAssist Tool

Sources

Upload datasets, metadata and internal policies

9

10 of 32

Assessment

Analyse privacy risk and data quality

Anatomy of DataSharingAssist Tool

10

11 of 32

Assistant

Anatomy of DataSharingAssist Tool

Answer queries related to data classification

11

12 of 32

Decoding Data Classification

“sensitivity” =

potential HARM to an individual or entity

  • Level of detail: raw, aggregated, or hashed
  • Where it lives: public, internal, or restricted
  • How bad the value can be: ordinary vs. highly damaging values
  • Type of identifier: internal IDs vs. strong external IDs (NRIC, FIN, passport)
  • Codified values
  • Context: cultural norms and agency-specific context

Identifying & sensitive information depends on…

granular details + context matters

12

13 of 32

Why an LLM Assistant, not just an API?

We don’t want to replace officers’ judgement

we want to augment it.

“AI should give the final classification” – what we don’t want

Officer + assistant = augmented classifier

13

14 of 32

Design Considerations For the Assistant

14

15 of 32

Data classification policies

(Retrieval

Augmented

Generations)

Meticulous prompt engineering enriched with data assessment signals

16 of 32

accessibility & usability

structured answer + using policy language

Example 1: CPF Wage Contribution Dataset (Synthetic)

17 of 32

Example 2: Offence Dataset (Synthetic)

18 of 32

attribution & trust

inline cited policies

19 of 32

accountability

& traceability

chain of thought

column-level assessments

20 of 32

transparency and verification

Surfaced assumptions about the data and context

21 of 32

22 of 32

Putting it all together:

Design consideration helps reduce

hallucination + encourages insights generations

accountability & traceability

transparency & verification

surfacing assumptions

chain of thought

accessibility & usability

structured output + policy language

attribution & trust

inline cited policies

23 of 32

Evaluation

23

24 of 32

Assumptions:

Requiring human judgements

  • public info?
  • internal IDs?
  • agency-specific context?

Failure Cases

Severity (goes to higher sensitivity)

non-sensitive → sensitive-normal

Classification Accuracy (86%)

tested on 30

agencies’ synthetic datasets

25 of 32

LLM-as-a-judge

for consistency checks

classification

consistency

reasoning

consistency

assumption

consistency

citation

consistency

Claude 4.5 Sonnet

26 of 32

"key_differences": [

"Minor elaboration differences in harm assessment examples (reputational damage vs financial disadvantage)",

"Complementary assumptions about address field characteristics (concatenation vs hashing)"

],

LLM-as-a-judge

for consistency checks

For the same classifications, reasoning reaches an avg score of 9

27 of 32

Key Notes:

Designed for extensibility, trust, and accountability

  • supports metadata and internal policies of agencies
  • insights generation from the datasets
  • making human-ai collaboration faster
  • reduce the policies and question answer fatigue

Andrej Karpathy's keynote on June 17, 2025 at AI Startup School

27

28 of 32

DataSharingAssist (DSA)

The Impact

28

29 of 32

Greatest Impact

Agency Profile

  • Large amounts of sensitive datasets
  • Multiple Non-Government Entities

29

30 of 32

What Our Users Are Saying

“The tool is valuable as it can help in case we miss or do not have enough understanding of the data classification and risk framework.”

“Data chat bot to answer queries that staff in branches have. “

“This tool can serve as a check and balance for data classification that I can easily justify and communicate to my boss.”

Useful,

Intuitive,

High Potential

30

31 of 32

PEOPLE

responsible AI,

human-in-the-loop,

privacy & security global perspectives,

consistent & evidence-based

understand data sharing workflows,

focus on

education

TECHNOLOGY

PROCESS

Building Trustworthy Assistant like DSA 🌱

co-design with policy makers, data stewards through every iteration

Key Takeaways

32 of 32

Let’s Chat:

Community call for feedback!

Thank you.