A bank using customer data to develop or improve an AI assistant must provide an AI-specific notice if it relies on consent. The notice should distinguish model development from the ordinary delivery of banking or customer-service functions.
A bank may be able to rely on a PDPA consent exception, such as the business-improvement exception, but only if the statutory conditions and scope of that exception are satisfied. If a valid exception applies, consent—and therefore a consent-based opt-out—may not be required.
An insurer faces the same basic notification question: if consent is required for using medical or claims data to develop a generative-AI model, the notice must specifically describe that AI use. A broad prior statement about service improvement should not automatically be treated as sufficient for model training.
The insurer would need to establish that a relevant PDPA exception applies or obtain valid consent through an AI-specific notice. The available sources do not establish a blanket rule that all medical or claims data are automatically exempt.
Using purchase histories or browsing activity to develop a separate commercial generative-AI product is a clear example of repurposing data beyond the immediate shopping experience. Where consent is required, the platform should explain the AI purpose directly rather than rely on a generic product-development clause.
The business-improvement exception may be relevant in some circumstances, but it is not a general licence for every new commercial use. The organisation must still meet the exception’s legal requirements and remain within its scope.
A social-media platform using profiles, photos, videos, posts or interactions to improve generative-AI content-creation tools must give an AI-specific notification where consent is its legal basis.
Publicly available personal data may fall under the PDPA’s publicly available-data exception, meaning consent may not be required. But visibility is critical: material that is genuinely public is different from content shared only with selected users or protected by access controls.
If data are genuinely anonymised so that they are no longer personal data, the PDPA’s personal-data notification and consent obligations do not apply. Pseudonymised or masked data should not automatically be treated as anonymous; the relevant question is whether individuals can still be identified.
An organisation may not need consent where it can properly rely on a statutory exception, including the publicly available-data exception or, where the conditions are met, the business-improvement exception. Because the AI-specific notification requirement is tied to situations in which consent is required, it does not create a universal right to opt out of every lawful AI-training use.
PDPC guidance describes an opt-out route as involving notice, a reasonable period and a reasonable way for the individual to decline where that route is used. That does not mean every AI-related processing activity must include an opt-out—particularly where the organisation is relying on a consent exception rather than consent.
Consumers may still have withdrawal rights where consent was given or deemed to have been given under the PDPA, subject to the framework that applies to the processing.
Generally, an organisation should not deny a product or service merely because a consumer refuses consent for AI training when that training is not reasonably necessary to provide the requested product or service. This means consent for developing a general-purpose AI assistant or an unrelated commercial model should not ordinarily be bundled into access to a standard bank account, shopping service or social platform.
The key qualification is necessity. Consent may be required as a condition where the collection, use or disclosure is reasonably necessary for the service or transaction the consumer has requested. Whether that threshold is met depends on the specific service, data use and circumstances; the guidance does not establish a blanket answer for every organisation or AI system.
Consumers should look for four details in an AI notice:
Organisations should first determine whether the information remains personal data, whether an exception applies and whether the proposed AI use is reasonably necessary for the requested service. Only then can they determine whether an AI-specific consent notice—and an opt-out mechanism—is required. This distinction is the central limit of Singapore’s July 2026 framework: greater transparency for consent-based AI training, but no automatic opt-out from every lawful use of data.