Singapore: PDPC Publishes Advisory Guidelines on Use of Personal Data in Generative AI
August 04, 2026
Singapore: PDPC Publishes Advisory Guidelines on Use of Personal Data in Generative AIAugust 04, 2026 On 20 July 2026, Singapore’s Personal Data Protection Commission (“PDPC”) published its Advisory Guidelines on Use of Personal Data in Generative AI (the “Guidelines”), following a public consultation on the proposed guidelines that closed on 1 July 2026 (see our previous alert: Singapore: PDPC Seeks Public Consultation on Proposed PDPC Guidelines on Personal Data in Generative AI). The Guidelines remain largely consistent with the earlier consultation paper. However, there are some notable revisions and updates – we have summarised these below. Publicly Available ExceptionThe consultation paper previously recommended that organisations notify data controllers before scraping personal data which is behind digital barriers but which would still be considered to be publicly available to the reasonable person. In the Guidelines, the standard has been made more strict – organisations must now document their assessment and reasoning via a Data Protection Impact Assessment or other written record if they wish to rely on the Publicly Available Exception in order to scrape personal data that is behind a digital barrier and which they have assessed would still constitute publicly available data. Additionally, organisations and individuals making personal data available online should implement appropriate digital barriers if they do not intend their data to be web-scraped for the purposes of Gen AI model training. Consent and NotificationWith regard to consent and notification – the PDPC emphasises in the Guidelines that organisations using personal data to train AI models must prepare an AI-specific notification for individuals to review so that the individuals can give meaningful consent to these purposes. Importantly, organisations must not, as a condition of providing a product or service, require consent to the use of an individual’s personal data for AI model training. Data AnonymisationThe PDPC has set alternative expectations for organisations developing Gen AI models. The consultation paper recommended that Gen AI model developers practise data minimisation. The Guidelines now provide organisations with an option to anonymise datasets as much as possible, as an alternative to data minimisation, to minimise unnecessary risks. The Guidelines also introduce stricter obligations for organisations that must use personal data for AI development. These organisations should implement appropriate physical controls for data protection, in addition to the technical, process, and legal controls which the consultation paper previously expected. Broader Inclusion of StakeholdersData protection obligations now extend across the entire AI supply chain. The consultation paper identified three primary generative AI stakeholder categories: “Model Providers”, “System Providers”, and “System Deployers”. The Guidelines now expressly include organisations that specialise in collecting, curating, and supplying datasets for Gen AI development and deployment. This suggests that the PDPC is expecting broader stakeholders across the AI supply chain to comply with the data protection obligations. Incident Response and Data Breach ProceduresThe PDPC has strengthened incident preparedness expectations. The Guidelines now expressly state that Model Providers should document their incident response and data breach procedures as good practice. This applies alongside data access controls and data residency and retention policies. Similarly, System Providers should document and make available their incident response and data breach procedures. Practical ImplicationsThe Guidelines are advisory and not legally binding in nature. However, they provide important clarity on the PDPC’s expectations. In general, the PDPC has adopted a firmer position on documentation and accountability. These changes suggest a more proactive enforcement approach, with the PDPC setting clearer expectations that organisations should be able to demonstrate compliance. Latest Insights
Latest News
Latest Events
legal updates August 05, 2026 Continuation Vehicle Finance: Key Issues for Lenders in UK and Europe legal updates August 04, 2026 Singapore: PDPC Publishes Advisory Guidelines on Use of Personal Data in Ge... legal updates July 31, 2026 Hong Kong: Enacts biggest listing framework reforms to enhance global compe... legal updates July 30, 2026 Technology Law Shorts - July 2026 client news July 30, 2026 Eversheds Sutherland Advises Johnson Matthey on Acquisition of CORMETECH In... client news July 24, 2026 Advising Johnson Matthey on completion of the sale of its Catalyst Technolo... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States |