Singapore issues guidance on using personal data in generative AI systems

The Personal Data Protection Commission has published guidance explaining how organisations should collect, use, protect and correct personal data used in generative AI development and deployment.

Singapore issues guidance on using personal data in generative AI systems

Singaporean Personal Data Protection Commission (PDPC), with support from the Infocomm Media Development Authority, published new guidance on 20 July 2026 on the use of personal data in generative AI systems.

The guidance explains how the Personal Data Protection Act applies when organisations collect information to develop AI models, use existing customer or user data for new purposes, or process personal data through deployed systems.

Organisations may rely on the law’s exception for publicly available information when collecting personal data from openly accessible websites. However, information behind paywalls, registration requirements or other access restrictions may not qualify as publicly available.

When organisations want to reuse information originally collected for another purpose, they may need to obtain consent. The PDPC recommends notices that clearly explain what information will be used, why it is needed, how it will be processed and how individuals can refuse or withdraw consent.

The guidance assigns different responsibilities to model developers, system providers and organisations using the systems. Organisations deploying the technology remain primarily responsible for defining lawful purposes, protecting information and regularly reviewing security measures.

Individuals may continue to request access to or correction of their personal data after it has been used in system development. The PDPC acknowledges that such requests can be difficult to manage but expects organisations to assess them individually and adopt appropriate technical and administrative measures.

The guidance follows a public consultation that received responses from 40 organisations and three individuals. It should be read alongside the PDPC’s existing guidance on automated recommendation and decision systems and the main concepts under the Personal Data Protection Act.

What does this mean?

The guidance does not create a separate data protection regime for generative AI. Instead, it explains how existing privacy rules apply when personal information is collected from the web, reused for system development or processed after a system has been deployed.

In practice, organisations cannot assume that all information found online is free to collect and reuse. They must consider how the information became available, explain new uses of existing data where consent is required, protect information throughout the process and respond to requests from affected individuals.

Go to Top