Singapore issues regulatory guidance: Use of personal data in generative AI 

Singapore issues regulatory guidance: Use of personal data in generative AI 
Samuel Yuen

Samuel Yuen

Managing Partner

sam@yuenlaw.com.sg

Market context 

Enterprise adoption of generative AI (GenAI) has taken off, with deployments across Singapore’s financial services, tech, healthcare and professional services sectors, and surging volumes of personal data flowing through model training, retrieval systems, and end-user prompts. 

Presently, Singapore has no AI-specific data protection legislation. Instead, regulatory guidance is issued pursuant to the Personal Data Protection Act 2012 (PDPA). 

On 20 July 2026, the Personal Data Protection Commission (PDPC) issued the Advisory Guidelines on Use of Personal Data in Generative AI, clarifying the PDPA’s application to GenAI, and building on the 2024 Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems. 

Key developments 

The Guidelines cover the development, deployment, and post-development stages of GenAI, addressing personal data collection and use for model developments, allocation of data protection obligations across the lifecycle, and handling user requests concerning personal data processing.  

Development: publicly available exception 

Under Part 2 of the First Schedule to the PDPA, organisations may rely on the “publicly available” exception to collect personal data without consent by web scraping (subject to the reasonableness requirement under s 18 of the PDPA). 

Digital barriers such as a paywall, registration, authentication mechanism, or bot blocker do not imply that data is not publicly available. To assess this, organisations should consider the barrier’s purpose and effect, the number and complexity of steps for data access, and whether the data is freely available elsewhere.  

Consent must not be a condition of service 

The PDPC reiterates that organisations must not require users to consent to the use of their data for AI model development as a condition of providing a product or service, unless reasonably necessary.

AI-specific notifications 

Where no publicly available exception applies, s 13 requires organisations to obtain consent before using personal data, while s 20(1) requires them to notify users why their data is collected, used, and disclosed. Where personal data is used for extensive AI model training or fine-tuning, generic notifications with broad purposes (e.g. new product development) do not suffice. Organisations should provide AI-specific notifications explaining the types of data used, how it trains or fine-tunes models, and how users may decline or withdraw consent. 

Deployment: stakeholders’ distinct obligations

The Guidelines distinguish PDPA obligations of three stakeholders:

  • Model providers developing or making available GenAI models must comply with all PDPA obligations, including retention limitation. Those processing personal data for downstream stakeholders act as data intermediaries subject to the protection obligation under s 24, and the PDPC encourages them to document and share model-level safeguards. 
  • System providers developing or making available GenAI systems must periodically review system-level security arrangements and ideally share them with downstream deployers. 
  • System deployers using or enabling the use of GenAI systems are primarily responsible for PDPA compliance. They must define processing purposes, safeguard data processed via their systems, and regularly review those safeguards.  

Organisations performing multiple roles should implement policies to meet corresponding obligations. 

Post-development: access and correction 

Access and correction obligations under ss 21, 22 and 22A apply to personal data processed for AI model and system development. The PDPC recognises compliance challenges driven by data volumes and technical constraints. As best practice responses, PDPC points to upstream data provenance records, case-by-case request reviews, and adoption of emerging technical measures to remove inaccurate data. 

Practical implications  

The guidelines stress documenting the legal basis for relying on datasets upon collection, instead of justifying it retrospectively. The PDPC prefers contemporaneous records explaining why the “publicly available exception” applies, or why a specific notification is adequate. Organisations using user data for extensive model training or fine-tuning should include AI-specific disclosures in their privacy notices, and deployers procuring third-party AI systems should obtain information on upstream safeguards to assess compliance obligations. 

Agentic AI systems highlight deployers’ obligations under the Purpose Limitation, Protection and Accountability provisions. As autonomous agents generate new data flows, prompts, outputs, and activity logs, safeguards should match the level of autonomy. Internal policies should address agents operating beyond their scope, and contracts across the AI value chain addressing responsibility for agent behaviour.

Interested in becoming a member of XLNC?

If you are a professional services firm with an international client base and are regarded as one of the leading industry practices in your country, working to the highest standards and providing excellent client service, you meet the basic requirements for XLNC membership.

Become a member