Singapore’s Guidelines on Personal Data in Generative AI: Key Compliance takeaways for Companies

Singapore’s Guidelines on Personal Data in Generative AI: Key Compliance takeaways for Companies

Companies that train or deploy generative artificial intelligence (AI) models must walk a tightrope between innovation and business efficiency on the one hand and the need to handle personal data in accordance with the applicable personal data protection regimes on the other. Failing to do this might attract regulatory action and significant financial penalties for the company. Across 2025 and 2026 alone, Singapore’s Personal Data Protection Commission (PDPC) imposed financial penalties worth $405,750 across 5 high-profile cases of failures to protect the personal data under the companies’ control[1][2][3][4][5]. This is in addition to stringent compliance directions issued in those and other cases.

To provide greater clarity on how Singapore’s data protection framework applies to the use of personal data across the development, deployment and post-deployment stages of generative AI models and systems, the PDPC issued the Advisory Guidelines on Use of Personal Data in Generative AI on 20 July 2026.

These Guidelines provide a clearer picture of how stakeholders, including model providers, system providers and system deployers, should manage personal data throughout the Generative AI lifecycle.

I. Locked behind a Digital Barrier: When the “Publicly Available Exception” is not enough

Where personal data is generally available to the public with no restrictions, companies using it can rely on the Publicly Available Exception (PAE), subject to whether a reasonable person would consider the use appropriate in the circumstances. However, sometimes data is locked or restricted by digital barriers, such as:

  1. Paywalls/subscriptions;
  2. Registration requirements;
  3. Authentication requirements, such as passwords and one-time codes;
  4. Location/eligibility access controls, such as geo-blockers;
  5. Tools that prevent automated programs from accessing the data.

In such cases, the data does not stop being publicly available. However, companies should consider the following factors before using the data:

  1. The purpose of the digital barrier;
  2. The overall effect of the digital barrier as to the data’s availability to the public;
  3. The steps needed to access the personal data;
  4. Whether the data can be obtained without restrictions from other sources.

Where it is reasonably arguable that the data is not publicly available, but the company still relies on the PAE, it should document its reasoning via a Data Protection Impact Assessment or other written record and produce it if called upon by the PDPC to justify its reliance on the PAE.

Some data, however, is held as publicly available despite being behind paywalls or registration requirements, such as registers administered by public agencies and meant to be publicly available, news or media websites that provide a limited number of articles for free before requiring a subscription and large online forums that do not involve a complex or burdensome registration process. Reliance on the PAE does not override contractual obligations, website terms of use, intellectual property requirements or other applicable laws.

II. When Consent is Required: General Notifications are not enough

To train generative AI models, companies sometimes employ user data, which is data provided to them by their employees or by individuals while using their products or services. Presently, countless companies also notify and obtain consent for utilizing user data through privacy policies and terms of service. Such notifications may take one of two forms:

  1. A General Notification citing the use of the personal data for “new product development” and the like without mentioning generative AI;
  2. An AI-Specific Notification explicitly stating the proposed use of the user data for training generative AI. Some notices may have to be accompanied by a mechanism for individuals to decline or withdraw their consent.

In its Guidelines, the PDPC has expressed the view that General Notifications are an inadequate means of obtaining consent for using personal data for training generative AI, specifically for large-scale model training or fine-tuning. Companies must instead provide AI-Specific Notifications, pursuant to Section 20(1)[6] of the PDPA, which obligates a company to inform individuals of the purpose of the collection, use or disclosure of their personal data.

However, in some cases, companies may rely on an applicable exception to consent or on deemed consent. For example, as explained in paragraphs 4.1 to 6.4 of the PDPC’s 2024 Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems[7], AI developers may cite the Business Improvement Exception when developing a new product or enhancing an existing one or the Research Exception when the company conducts commercial research to advance science and engineering with no product development roadmap, subject in each case to the applicable statutory conditions.

III. Anonymization and Data Minimization: Proactive steps to minimize needless risks

In its Guidelines, the PDPC encourages companies to anonymize their datasets as much as possible and to practice data minimization when developing generative AI models. Should personal data be necessary to develop such models, companies must implement the appropriate physical, technical, process and legal controls for data protection. This minimizes risk and protects the individual from having their personal data leaked and the company from incurring liability. Properly anonymized data falls outside the scope of the PDPA only where there is no serious possibility of reidentification.

For further information regarding this, companies may refer to the abovementioned Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems.

IV. Access and Correction: The Compliance Journey Post Data Collection

The compliance obligations for a stakeholder in the training of generative AI models do not end with the collection of personal data. They continue throughout the AI lifecycle. For instance, pursuant to Section 21, Section 22 and Section 22A of the PDPA, companies are obligated to respond to requests from individuals to access or correct their personal data. This is not limited to the data currently in the company’s possession, either. It includes data transferred to a data intermediary.

Companies may, for example, refuse an access request where the burden or expense would be unreasonable to the company or disproportionate to individual interests and decline a correction request if there are reasonable grounds to believe the data subject to the correction request should not be corrected. The PDPC has also recognized the significant practical challenges of responding to access and correction requests, stemming from the massive amounts of data involved, the nature of the AI model itself or similar technical difficulties. However, where the request is appropriate and reasonable, companies are expected to adhere to the following best practices:

  1. Adopt upstream data handling measures such as verifying data accuracy at the point of collection, implementing data cleaning techniques like de-duplication and outlier detection and maintaining data provenance records;
  2. Review access and correction requests on a case-by-case basis and where appropriate remove personal data including inaccurate data from training datasets for future AI training runs;
  3. Track the maturity and effectiveness of technical measures for addressing the removal of inaccurate personal data from models and systems. In the interim, implement output filters and other appropriate safeguards where direct removal is not technically feasible.

What Companies should do now: A Practical Compliance Checklist

Considering the clarifications provided by the Guidelines, companies should consider taking the following steps to ensure continued compliance:

  1. Identify whether the company is acting as a model provider, system provider, system deployer or in more than one role and map the personal data processed at each stage of the generative AI lifecycle;
  2. Review the legal basis for collecting the relevant personal data;
  3. Assess whether personal data behind digital barriers can still be considered publicly available;
  4. Document and retain the reasoning for relying on the PAE to access personal data behind digital barriers and be prepared to present to the PDPC if so required;Assess whether the collection and use of user data falls under exceptions or whether consent is required;
  5. Where consent to collect and use the user data is required, prepare AI-Specific Notifications, not General Notifications;
  6. Anonymize and minimize personal data wherever possible;
  7. Set up a mechanism to respond to user requests to access and correct their personal data, including appropriate arrangements for accounting for personal data transferred to data intermediaries;
  8. Review vendor contracts and safeguards and establish appropriate controls for personal data contained in prompts, outputs and activity logs;
  9. Document retention and deletion decisions and strengthen controls where agentic AI systems can access files, networks, tools or other systems.  

Conclusion

The Guidelines make it clear that data protection cannot be treated as a one-time exercise. Companies using personal data in generative AI must understand that the compliance journey continues throughout the AI’s lifecycle. The precise obligations depend on the company’s role in the generative AI lifecycle, the personal data involved and the purpose for which it is processed. The Guidelines issued by the PDPC help companies build these considerations into AI governance from the outset. This, in turn, helps companies innovate responsibly while remaining aligned with their obligations under the PDPA.

How Komrisk Can Help

Manually tracking governance obligations, whether internal or regulatory, that are constantly evolving requires significant resources and increases the risk of oversight. Komrisk, a comprehensive compliance management solution, helps companies reduce complex compliance obligations into clear, concise, actionable tasks. Additionally, Komrisk allows companies to assign responsibilities, send alerts and escalations, track tasks and retain evidence, all in one place. This reduces the time spent on manual tracking and allows in-house teams to focus on compliance oversight, governance and risk management.


[1] https://www.pdpc.gov.sg/assets/c8661505-2a12-4929-a8fd-505f41fdc008

[2] https://www.pdpc.gov.sg/assets/f9fdd00e-2e3d-4e69-a017-4da0db04d1ad

[3] https://www.pdpc.gov.sg/organisations/regulations-decisions/enforcement-decisions/breach-of-the-protection-obligation-by-sesami-singapore-pte-ltd-and-abecha-pte-ltd

[4] https://www.pdpc.gov.sg/assets/25ee3edf-acd0-4172-afdc-f3e5bf1071e3

[5] https://www.pdpc.gov.sg/assets/e41fbd73-1183-4a11-bf30-129103f68b12

[6] https://sso.agc.gov.sg/Act/PDPA2012?ProvIds=P14-#pr20-

[7] https://www.pdpc.gov.sg/assets/f97f8ecc-3ced-4406-a36f-4783505d64f7

Author: Chandrayan Gupta

Co-Author by: Swapna Umakanth

Disclaimer

The information provided on this blog is for general informational purposes only and is not a substitute for professional legal advice. We are not a law firm and are not authorized to practice law in your jurisdiction. Laws and regulations are complex and constantly changing, and information that may be true in one jurisdiction may not apply in another. Before acting on any information you read here, you should consult with a qualified lawyer practicing in the relevant jurisdiction for your specific legal issues or concerns. While we strive to provide accurate and up-to-date information, we make no guarantees that the information on this blog is completely current or error-free. We disclaim any liability for any actions taken or not taken based on the information on this blog.


Let's shape the future, together

Partner with Lexplosion and harness the power of innovation, expertise, and global reach. Let’s embark on a journey of growth and unparalleled success.

Find Out How Lexplosion Can Help You
Company

Lexplosion Solutions Pte. Ltd.

1 North Bridge Road, #19-08 High Street Centre, Singapore 179094

Get In Touch

General Queries:
Grievances: Shantanu Das

shantanu.das@lexplosion.in

Subscribe to Our Newsletter

    © Copyright 2025 Lexplosion Solutions Private Limited. All Rights Reserved. Powered By Dreamz Interactive.