Singapore Generative AI Data Guidelines

Advisory Guidelines on Use of Personal Data in Generative AI

Singapore

RAI-SG-NA-GENERAT-2026
Effective: July 20, 2026
In Force(In Force)
GuidelineData Protection and PrivacyGovernance and OversightRisk Management
Export PDF

Singapore's PDPC issued advisory guidelines on July 20, 2026, clarifying how the Personal Data Protection Act applies to personal data use in Generative AI systems.

Overview

The Advisory Guidelines on Use of Personal Data in Generative AI, issued by the Personal Data Protection Commission (PDPC) of Singapore on 20 July 2026, provide crucial guidance for organisations navigating the complexities of personal data handling within Generative Artificial Intelligence (AI) models and systems. These guidelines serve to clarify how the Personal Data Protection Act 2012 (PDPA) applies across the entire lifecycle of Generative AI, from the initial development and training phases to testing, deployment, and ongoing operation. Recognising the transformative potential of Generative AI, the PDPC aims to foster innovation while upholding robust data protection standards, ensuring that personal data is handled responsibly and in compliance with existing legal frameworks.

This document is not a standalone regulation but rather builds upon and should be read in conjunction with other foundational guidance from the PDPC, specifically the Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (issued March 2024) and the Advisory Guidelines on Key Concepts in the PDPA. This integrated approach ensures a comprehensive understanding of data protection obligations in the evolving AI landscape. The guidelines address critical areas such as the lawful basis for processing personal data, consent requirements, data minimisation, accuracy, security, and accountability, providing practical considerations for organisations developing or deploying Generative AI solutions.

Definitions

The Advisory Guidelines establish a clear set of definitions to ensure a common understanding of key terms within the context of Generative AI and personal data protection. Central to the guidelines is the definition of 'Generative AI,' referring to artificial intelligence systems capable of producing novel content, such as text, images, audio, or code, by learning patterns from extensive datasets. This distinguishes them from discriminative AI systems, which are primarily used for classification or prediction. The guidelines meticulously outline what constitutes 'Personal Data' under the Personal Data Protection Act (PDPA), encompassing any data that can identify an individual, either directly or indirectly, a fundamental concept underpinning all data protection obligations.

Furthermore, the guidelines define 'Organisation' broadly to include any entity, corporate or unincorporated, that collects, uses, or discloses personal data, thereby extending the scope of compliance to a wide array of actors in the Generative AI ecosystem. Terms such as 'Anonymisation' and 'Pseudonymisation' are also clarified, detailing methods for de-identifying data to mitigate privacy risks, with specific guidance on their application in AI training and development. The document also implicitly relies on definitions from the overarching PDPA, such as 'Consent,' 'Purpose Limitation,' and 'Retention Limitation,' which are essential for understanding the legal bases and boundaries for processing personal data in Generative AI contexts. These precise definitions are critical for organisations to accurately assess their obligations and implement appropriate data protection measures.

Governance and Institutional Framework

The governance framework for the use of personal data in Generative AI in Singapore is primarily anchored by the Personal Data Protection Act 2012 (PDPA) and overseen by the Personal Data Protection Commission (PDPC). These Advisory Guidelines, while non-binding in the strictest sense of legislation, represent the PDPC’s authoritative interpretation of how the PDPA’s principles apply to the unique challenges posed by Generative AI. The PDPC acts as the primary regulatory body, responsible for administering and enforcing the PDPA, as well as providing guidance and education to organisations and individuals. Its role extends to investigating complaints, imposing penalties for non-compliance, and promoting best practices in data protection.

Organisations are expected to integrate these guidelines into their existing data governance structures, ensuring that their Data Protection Officer (DPO) and relevant internal teams are well-versed in the specific considerations for Generative AI. The guidelines reinforce the accountability principle of the PDPA, placing the onus on organisations to demonstrate compliance and implement appropriate safeguards. This includes establishing clear internal policies, conducting regular risk assessments, and maintaining robust records of data processing activities related to Generative AI. The PDPC’s framework encourages a proactive approach to data protection, where organisations embed privacy-by-design principles throughout the entire lifecycle of their Generative AI systems, from conception to deployment and decommissioning.

Key Focus Areas

The Advisory Guidelines on Use of Personal Data in Generative AI pinpoint several critical areas for organisations to address to ensure PDPA compliance. A primary focus is on the lawful basis for collecting and using personal data for Generative AI training and development. This includes stringent requirements for obtaining valid consent, where applicable, or relying on legitimate interests or other exceptions under the PDPA, with a strong emphasis on transparency regarding data sources and intended uses. The guidelines also delve into the challenges of data minimisation and accuracy, urging organisations to collect only necessary data and to implement measures to ensure the quality and relevance of training datasets, thereby mitigating risks of biased or inaccurate AI outputs.

Another significant area is the implementation of robust data security measures throughout the Generative AI lifecycle. Organisations are advised to protect personal data from unauthorised access, collection, use, disclosure, copying, modification, disposal, or similar risks, particularly during data ingestion, model training, and inference. The guidelines also highlight the importance of accountability and transparency, requiring organisations to conduct Data Protection Impact Assessments (DPIAs) to identify and mitigate privacy risks, and to provide clear explanations to individuals about how their data is used by Generative AI systems. Furthermore, the document addresses the unique challenges of managing outputs from Generative AI, especially concerning the potential for models to inadvertently generate or reproduce personal data, necessitating careful monitoring and mitigation strategies.

Implementation Framework

The implementation framework outlined in the Advisory Guidelines necessitates a comprehensive and integrated approach by organisations. It emphasizes the need for organisations to embed data protection principles directly into the design and operation of their Generative AI systems, adhering to a 'privacy by design' methodology. This involves conducting thorough Data Protection Impact Assessments (DPIAs) at the early stages of AI development to identify, assess, and mitigate potential privacy risks associated with the collection, use, and disclosure of personal data. DPIAs should be ongoing, reviewed periodically, and updated as the Generative AI system evolves or its use cases expand.

Organisations are also expected to establish clear internal policies and procedures that reflect the guidelines' recommendations, ensuring that all personnel involved in Generative AI development and deployment are adequately trained and aware of their data protection responsibilities. This includes protocols for data anonymisation or pseudonymisation where feasible, robust data security measures, and mechanisms for handling data subject requests, such as access or correction. Furthermore, the guidelines encourage organisations to adopt a proactive stance on accountability, maintaining detailed records of their data processing activities and demonstrating their compliance efforts to the PDPC upon request. This framework aims to foster a culture of responsible AI innovation that prioritises individual privacy and data security.

Monitoring and Evaluation

While the Advisory Guidelines themselves do not prescribe a specific monitoring and evaluation framework for organisations, they implicitly mandate a continuous process of oversight and review to ensure ongoing compliance with the PDPA. The Personal Data Protection Commission (PDPC), as the regulatory authority, is responsible for monitoring the overall adherence to data protection principles in Singapore, including those articulated in these guidelines. The PDPC achieves this through various mechanisms, such as conducting audits, investigating complaints, and issuing enforcement actions when breaches of the PDPA occur. Organisations are therefore expected to establish internal monitoring systems to continuously evaluate their Generative AI systems and data processing practices against the guidelines.

This internal monitoring should include regular reviews of data protection impact assessments, audits of data security controls, and evaluations of the effectiveness of anonymisation or pseudonymisation techniques. Organisations must also monitor the outputs of their Generative AI models to identify and address any instances where personal data might be inadvertently generated or disclosed. Furthermore, the guidelines encourage organisations to stay abreast of technological advancements and evolving best practices in AI and data protection, adapting their compliance strategies accordingly. The PDPC may also periodically review and update these guidelines to reflect new developments in Generative AI technology and regulatory landscapes, necessitating ongoing vigilance and adaptation by organisations.

Penalties, Liability, and Appeals

As advisory guidelines, this document does not introduce new penalties or liability regimes but rather clarifies how existing provisions of the Personal Data Protection Act 2012 (PDPA) apply to the use of personal data in Generative AI. Non-compliance with the principles and recommendations set forth in these guidelines could indicate a breach of the underlying PDPA obligations, leading to potential enforcement actions by the Personal Data Protection Commission (PDPC). The PDPA empowers the PDPC to issue directions, impose financial penalties, and require organisations to take remedial actions to address data protection contraventions. Financial penalties under the PDPA can be substantial, reflecting the seriousness of data breaches and the impact on individuals.

Organisations found to be in breach of the PDPA, particularly where such breaches stem from inadequate adherence to these Generative AI guidelines, may face investigations, public reprimands, and orders to cease specific data processing activities. Individuals affected by such breaches also have rights to seek redress and compensation. The appeals process for any enforcement decisions made by the PDPC typically involves an initial review by the Commission itself, followed by the possibility of appealing to the Singapore High Court. Therefore, while the guidelines are advisory, their recommendations are critical for mitigating legal and reputational risks, as they articulate the expected standard of care and diligence for handling personal data in Generative AI environments under Singaporean law.

Relationship to Other Instruments

The Advisory Guidelines on Use of Personal Data in Generative AI are explicitly designed to complement and be read in conjunction with other key regulatory and advisory instruments within Singapore's data protection landscape. Foremost among these is the overarching Personal Data Protection Act 2012 (PDPA), which serves as the foundational legal framework governing the collection, use, and disclosure of personal data in Singapore. These guidelines provide specific interpretations and practical applications of the PDPA's principles in the context of Generative AI, addressing the unique challenges and opportunities presented by this rapidly evolving technology.

Furthermore, the guidelines build upon and should be understood in light of the Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, issued in March 2024. While that document primarily focused on discriminative AI, the Generative AI guidelines extend and adapt those principles to the generative paradigm, ensuring consistency across different types of AI systems. They also reference the Advisory Guidelines on Key Concepts in the PDPA, which provide fundamental definitions and interpretations of core data protection principles. This interconnected web of guidance ensures that organisations have a comprehensive and coherent understanding of their data protection obligations when engaging with AI technologies.

International Alignment

Singapore's approach to data protection in Generative AI, as reflected in these Advisory Guidelines, demonstrates a commitment to aligning with international best practices and fostering cross-border interoperability in the digital economy. The principles articulated within the guidelines, such as consent, purpose limitation, data minimisation, accuracy, security, and accountability, resonate strongly with globally recognised data protection frameworks like the GDPR and various OECD recommendations on AI. By providing clear guidance on how existing data protection laws apply to Generative AI, Singapore aims to build trust in AI technologies and facilitate responsible innovation that can thrive in a global context.

The PDPC actively participates in international forums and collaborations related to data protection and AI governance, contributing to the development of harmonised standards and approaches. These guidelines, by addressing specific challenges like the use of personal data in training large language models and the potential for AI outputs to generate personal data, contribute to a global discourse on responsible AI development. This alignment helps Singaporean organisations operating internationally, as well as foreign entities operating in Singapore, navigate complex regulatory landscapes with greater clarity, fostering a consistent baseline for data protection and ethical AI deployment across jurisdictions.

Implementation Timeline

MilestoneDateNotes
Issued by the Personal Data Protection Commission2026-07-20The Advisory Guidelines on Use of Personal Data in Generative AI were officially issued by the PDPC.

Compliance Checklist

CheckRequired Action
Data Protection Impact Assessment (DPIA)Conduct a comprehensive DPIA before developing or deploying Generative AI systems that process personal data, and update it regularly.
Lawful Basis for ProcessingEnsure a clear and valid lawful basis (e.g., consent, legitimate interest) for collecting and using personal data for Generative AI activities, including training.
Transparency and NotificationInform individuals clearly about the collection, use, and disclosure of their personal data for Generative AI purposes, including the types of data used and the nature of AI outputs.
Data MinimisationCollect and use only the personal data that is necessary and proportionate for the intended Generative AI purpose.
Data Accuracy and QualityImplement measures to ensure the accuracy, completeness, and relevance of personal data used for training Generative AI models.
Data SecurityEstablish robust technical and organisational security measures to protect personal data throughout the entire Generative AI lifecycle, from collection to deletion.
Anonymisation/PseudonymisationWhere feasible and appropriate, anonymise or pseudonymise personal data used in Generative AI systems to reduce privacy risks.
Output Monitoring and MitigationImplement mechanisms to monitor Generative AI outputs for inadvertent generation or disclosure of personal data and establish processes for prompt mitigation.
Accountability FrameworkMaintain records of data processing activities related to Generative AI, demonstrate compliance with PDPA principles, and assign clear responsibilities for data protection.
Data Subject RightsEnsure mechanisms are in place to facilitate individuals' exercise of their rights (e.g., access, correction, withdrawal of consent) concerning personal data processed by Generative AI.
Regular ReviewPeriodically review and update internal policies, procedures, and Generative AI systems to ensure ongoing compliance with the PDPA and these Advisory Guidelines.

Sources and References

SourceType
Advisory Guidelines on Use of Personal Data in Generative AI (PDF)official
PDPC | Advisory Guidelines on Use of Personal Data in Generative AIgovernment
PDPC | Public Consultation on the Proposed Advisory Guidelines on Use of Personal Data in Generative AIgovernment

© Regulations.AI — created on 26-Aug-2026 using Gemini 2.5 Flash