Singapore - Personal Data in AI Systems

Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (PDPC)

Singapore

RAI-SG-NA-AGUPDXX-2024
Effective: March 1, 2024
In Force(In Force)
GuidelineData Protection and PrivacyAccountability and DocumentationSafety, Testing, and Evaluation
Export PDF

The Personal Data Protection Commission (PDPC) of Singapore published advisory guidelines on 1 March 2024 clarifying how the Personal Data Protection Act (PDPA) applies to the use of personal data in AI systems that make recommendations, predictions or decisions. The Guidelines explain consent and relevant exceptions (notably the Business Improvement and Research exceptions), outline data protection and procurement best practices for service providers, and encourage transparency and accountability measures for organisations using personal data in AI.

Summary

Issued by Singapore’s Personal Data Protection Commission (PDPC) on 1 March 2024, the "Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems" provide practical, non-binding guidance on how the Personal Data Protection Act (PDPA) applies to the design, development, testing, deployment and procurement of AI systems that process personal data to produce recommendations, predictions or decisions. The Guidelines are structured around three lifecycle stages: (i) development, testing and monitoring; (ii) deployment (business-to-consumer uses); and (iii) procurement (business-to-business engagements with third-party service providers). They reiterate that the PDPA applies broadly to collection, use and disclosure of personal data involving AI systems and that organisations should generally rely on meaningful consent where required, or consider PDPA exceptions such as the Business Improvement Exception and the Research Exception where the statutory criteria are met. Practical criteria and considerations are provided for when those exceptions may apply, including requirements that business improvement purposes cannot reasonably be achieved without identifiable personal data and that research uses demonstrate public benefit or scientific advancement.

The Guidelines emphasise data protection safeguards during AI development, including data minimisation, de-identification/pseudonymisation where feasible, secure handling and retention limits, and the importance of assessing re-identification risk even for anonymised datasets. For deployments that collect or use personal data to deliver recommendations or decisions, the Guidelines detail notification and consent obligations and encourage organisations to craft notifications that are intelligible and proportionate to risk. The Accountability Obligation under the PDPA is highlighted: organisations remain responsible for personal data even when they engage third-party developers; service providers acting as data intermediaries have Protection and Retention obligations and should adopt good practices such as data mapping, provenance records and contractual safeguards.

Additional elements include recommended use of tools and resources such as PDPC materials, data protection impact assessments, and IMDA’s AI Verify toolkit to support trustworthy AI testing and assurance. The Guidelines also provide sample use-cases (e.g., recommendation engines, HR candidate-matching, job-assignment systems) to illustrate how PDPA principles apply in practice. While advisory and not legally binding, the Guidelines clarify PDPA interpretation and signal PDPC’s supervisory expectations regarding transparency, DPIAs, security measures, bias assessment and documentation that organisations should maintain to demonstrate compliance. They are intended to lower uncertainty for businesses innovating with AI while protecting individuals’ data protection rights. The document is available from PDPC’s website and references cross-agency resources and wider Singapore AI governance initiatives.

Full article

Read full text ↗

Overview

The Personal Data Protection Commission (PDPC) published the Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems on 1 March 2024 to clarify how the Personal Data Protection Act 2012 (PDPA) applies to AI systems that process personal data to make recommendations, predictions or decisions. The Guidelines are advisory and do not change statutory law; they set out practical expectations for organisations at three stages of an AI lifecycle (development, deployment and procurement) and stress the primacy of meaningful consent or, where applicable, reliance on PDPA exceptions. The Guidelines also encourage transparency to consumers and stronger vendor management for organisations engaging third-party AI developers. The full text is available from the PDPC website and accompanying PDF. For testing and assurance resources, the Guidelines direct organisations to tools such as IMDA’s AI Verify and PDPC materials like the Guide to Basic Anonymisation and other advisory guidelines.

Definitions

The Guidelines define key terms in the PDPA/AI context: "AI System" refers to systems embedding machine learning models used to assist or make decisions; "AI developer" refers to organisations that build or train models (including in-house teams and third-party service providers); "Service Provider" or "data intermediary" denotes third-party developers who process personal data on behalf of client organisations; and statutory constructs from the PDPA such as the "Business Improvement Exception" and "Research Exception" are explained with application criteria. The Guidelines also clarify concepts like "personal data", "anonymisation", "pseudonymisation", and the PDPA obligations of Protection, Retention and Accountability that continue to apply when personal data is used for AI-related purposes.

Governance and Institutional Framework

The Guidelines situate PDPA obligations within Singapore’s broader AI governance ecosystem. They reinforce organisational accountability obligations under the PDPA and recommend governance controls, role clarity and documentation to manage AI-related risks. Organisations are encouraged to integrate data protection checks into AI governance frameworks, incorporate privacy and security by design, and adopt documented policies on dataset curation, model evaluation and post-deployment monitoring. The PDPC also recommends coordination with the Infocomm Media Development Authority (IMDA) and other national initiatives: the Guidelines reference relevant PDPC advisory outputs and testing frameworks such as IMDA's AI Verify to help operationalise principled testing for transparency, fairness and robustness. Contracts with third-party Service Providers should allocate responsibilities (including Protection and Retention obligations), require records of provenance and mapping, and provide for audits or attestations to demonstrate compliance.

Key Focus Areas

The Guidelines focus on several interlinked areas: first, lawful basis for processing — meaningful consent vs specified statutory exceptions (Business Improvement and Research), with detailed criteria to determine when exceptions legitimately apply; second, data minimisation and de-identification — minimising attributes and volume used, pseudonymisation and anonymisation as preferred practices while noting re-identification risks; third, transparency and notice — providing individuals with clear, risk-proportionate notifications at point of collection and when AI systems materially affect outcomes; fourth, data intermediary management — Service Providers acting as data intermediaries must implement adequate safeguards and are subject to Protection and Retention obligations; fifth, testing, evaluation and bias mitigation — organisations should perform performance validation, bias assessment and monitoring using suitable datasets; and sixth, accountability and documentation — maintain DPIAs, provenance records, model evaluation logs and decisioning rationales sufficient to demonstrate PDPA compliance. These focus areas align with existing Singapore instruments and international AI governance norms and are illustrated via examples (recommendation engines, HR screening, job allocation systems) to help organisations interpret obligations in concrete contexts.

Implementation Framework

Operational guidance in the Guidelines covers lifecycle actions. During development and testing, organisations should evaluate whether consent is necessary or whether the Business Improvement or Research exceptions apply, conduct Data Protection Impact Assessments (DPIAs), apply minimisation and de-identification, and maintain provenance and test records. For deployment, organisations must craft clear notifications, implement mechanisms to obtain or document consent where required, ensure accuracy and perform ongoing monitoring for harms and bias, and maintain retention schedules consistent with PDPA retention obligations. For procurement, the Guidelines advise contractual clauses that allocate PDPA responsibilities, enforce technical and organisational safeguards, require records for audits, and embed model update/change management in supplier agreements. The PDPC recommends use of PDPC tools and IMDA’s AI Verify tests to strengthen assurance and encourage transparency by making non-sensitive aspects of testing outcomes available to affected users where appropriate.

Monitoring and Evaluation

The Guidelines require ongoing monitoring of deployed AI systems with processes to measure accuracy, fairness and safety. Organisations should regularly review model performance and data drift, log monitoring results, and have protocols for remediation where adverse impacts are detected. The PDPC encourages adopting structured evaluation frameworks, including the use of test suites and benchmarks (such as those promoted by IMDA’s AI Verify), and recommends that monitoring outputs be recorded in an auditable manner to meet accountability obligations. Where Service Providers are engaged, agreements should enable the client to verify continued compliance through audit rights, reporting obligations and access to provenance and testing documentation.

Penalties, Liability, and Appeals

While the Guidelines themselves are advisory and non-binding, they clarify how existing PDPA obligations may be enforced. Non-compliance with PDPA obligations (for example, failing to obtain consent where required, inadequate protection of personal data, or failing to notify notifiable data breaches) exposes organisations to PDPA enforcement actions, which may include directions, financial penalties and other corrective measures as provided under the PDPA. The Guidelines therefore emphasise preventive compliance (documentation, DPIAs, contractual protections) to reduce enforcement risk and to prepare organisations for potential supervisory inquiries; they also note Service Providers’ legal obligations when acting as data intermediaries under the PDPA.

Relationship to Other Instruments

The Guidelines expressly instruct readers to consult other PDPC advisory instruments (such as the Advisory Guidelines on Key Concepts, the Guide to Basic Anonymisation, and sector- or topic-specific guidance) and to align AI governance practices with IMDA’s Model AI Governance Framework and AI Verify tools. They complement existing sectoral standards and regulatory regimes (e.g., MAS requirements for financial institutions) rather than supplanting them. The Guidelines also point practitioners to relevant contractual, technical and organisational controls recommended by PDPC and to cross-agency resources that support trustworthy AI deployment in Singapore.

International Alignment

The PDPC Guidelines reference and align with international AI governance principles and testing approaches — for example, transparency, fairness, robustness and accountability — and encourage use of testing frameworks that map to internationally recognised principles (such as those incorporated in AI Verify). By focusing on practical controls (DPIAs, de-identification, provenance records and supplier management) the Guidelines facilitate interoperability with overseas standards and encourage organisations to adopt practices that ease cross-border data protection compliance and multi-jurisdictional assurance efforts.

Implementation Timeline

MilestoneDate
Public consultation period (closed)2023-05-xx to 2023-08-31
Guidelines issued2024-03-01
PDPC web update (last updated)2024-04-01

Sources and References

SourceType
Advisory Guidelines on use of Personal Data in AI Recommendation and Decision Systems (PDPC, 1 Mar 2024)Primary Source
PDPC web page – Advisory Guidelines (PDPC)Primary Source
IMDA – AI VerifyPrimary Source
Singapore Government press release (1 Mar 2024) — announcement of GuidelinesPrimary Source

Requirements for a company

What an organisation has to do under Singapore - Personal Data in AI Systems, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

8
  • Assess and establish a lawful basis for processing personal data in AI systems.Organizations using personal data in AI systems.
  • Minimise personal data used and apply de-identification techniques like pseudonymisation.Organizations using personal data in AI systems.
  • Provide clear, risk-proportionate notifications to individuals about AI system use and effects.Organizations using personal data in AI systems.
  • Implement contractual clauses with service providers to allocate PDPA responsibilities and safeguards.Organizations engaging third-party AI service providers.
  • Maintain data retention schedules consistent with PDPA obligations for personal data used in AI.Organizations deploying AI systems.
  • Conduct Data Protection Impact Assessments (DPIAs) during AI system development and testing.Organizations developing or deploying AI systems.
  • +2 more in the table below

Must not do

0

Nothing in this category.

Should do

2
  • Integrate data protection checks into AI governance frameworks and incorporate privacy by design.Organizations developing or deploying AI systems.
  • Perform performance validation and bias assessment using suitable datasets.Organizations developing or deploying AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Singapore - Personal Data in AI Systems, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Organizations using personal data in AI systems.Assess and establish a lawful basis for processing personal data in AI systems.
stress the primacy of meaningful consent or, where applicable, reliance on PDPA exceptions.
Before processing personal data in AI systemsCritical
2Organizations using personal data in AI systems.Minimise personal data used and apply de-identification techniques like pseudonymisation.
data minimisation and de-identification — minimising attributes and volume used, pseudonymisation and anonymisation as preferred practices
Before processing personal data in AI systemsCritical
3Organizations using personal data in AI systems.Provide clear, risk-proportionate notifications to individuals about AI system use and effects.
transparency and notice — providing individuals with clear, risk-proportionate notifications at point of collection and when AI systems materially affect outcomes
At point of data collection and when AI systems materially affect outcomesCritical
4Organizations engaging third-party AI service providers.Implement contractual clauses with service providers to allocate PDPA responsibilities and safeguards.
Contracts with third-party Service Providers should allocate responsibilities (including Protection and Retention obligations), require records of provenance and mapping, and provide for audits or attestations to demonstrate compliance.
Before engaging third-party AI service providersCritical
5Organizations deploying AI systems.Maintain data retention schedules consistent with PDPA obligations for personal data used in AI.
maintain retention schedules consistent with PDPA retention obligations.
Ongoing, post-deploymentCritical
6Organizations developing or deploying AI systems.Conduct Data Protection Impact Assessments (DPIAs) during AI system development and testing.
conduct Data Protection Impact Assessments (DPIAs)
During development and testingImportant
7Organizations deploying AI systems.Continuously monitor deployed AI systems for accuracy, fairness, safety, and data drift.
The Guidelines require ongoing monitoring of deployed AI systems with processes to measure accuracy, fairness and safety.
Ongoing, post-deploymentImportant
8Organizations using personal data in AI systems.Maintain provenance records, model evaluation logs, and decisioning rationales.
maintain DPIAs, provenance records, model evaluation logs and decisioning rationales sufficient to demonstrate PDPA compliance.
Ongoing, throughout AI lifecycleImportant
9Organizations developing or deploying AI systems.Integrate data protection checks into AI governance frameworks and incorporate privacy by design.
Organisations are encouraged to integrate data protection checks into AI governance frameworks, incorporate privacy and security by design
During AI system design and developmentRecommended
10Organizations developing or deploying AI systems.Perform performance validation and bias assessment using suitable datasets.
organisations should perform performance validation, bias assessment and monitoring using suitable datasets
During development and testingRecommended

© Regulations.AI · updated on 13-Jun-2026