The chatbot guidance is different. It is voluntary and applies to external-facing GenAI chatbots that interact with customers, consumers or members of the public. It recommends a single, easy-to-find place where users can understand what a chatbot does, where it may fail, how it is kept safe, how data is handled and how concerns can be raised.
The PDPC guidance addresses personal data across the GenAI lifecycle. That can include web-scraped information, data supplied by users to receive an ordinary service and later reused to develop or improve a model, model deployment, security, retention, and responses to requests for access or correction.
The underlying privacy challenge is purpose change. Information originally provided for a transaction, account, support interaction or other service may later be reused at scale for model training or fine-tuning. That reuse can make it harder for people to understand what happened to their data, control it or exercise their rights after the data has entered a large training process.
The guidance also separates responsibilities across the AI supply chain. Model providers remain responsible for PDPA obligations connected with developing and deploying models. System providers are expected to consider security and communicate relevant safeguards, while deployers must define processing purposes, understand data flows and review controls in the systems they put into operation.
An organisation must obtain consent through an AI-specific notification when it wants to use “User Data” to develop a GenAI model and no applicable PDPA exception to consent applies. The notification must make the GenAI use clear rather than relying on a broad description such as “service enhancement,” “personalisation” or “product improvement.”
This is particularly important when information was supplied directly through an existing product or service for a non-GenAI purpose and is later repurposed for model development. The organisation must assess the original collection context, the new purpose and whether an exception applies before deciding how to proceed.
The PDPA’s publicly available-data exception may allow organisations to collect publicly available personal data without consent for model development. That does not mean every piece of data reachable online automatically qualifies. Information behind a paywall, login, registration requirement or a similar digital barrier requires a careful assessment of whether it is still publicly available for this purpose.
Properly anonymised data is not personal data for PDPA purposes because it cannot identify an individual. PDPC materials encourage organisations to use anonymised data for analytics and research where feasible.
The practical qualification is important: removing a name alone does not necessarily make a dataset anonymous if a person could still be identified using the remaining information or other reasonably available information. Organisations therefore need to assess whether their anonymisation process genuinely removes the ability to identify individuals.
The supplied materials do not establish a separate, categorical exception for call-centre recordings. A recording that identifies, or can reasonably identify, a caller should be treated as personal data for the purpose of assessing GenAI reuse. The organisation would still need an applicable PDPA basis—such as valid consent, notification or another statutory exception—before using it for model development.
The available sources do not provide enough detail to state an additional call-recording-specific rule. The correct implementation therefore depends on the recording’s content, how it was collected, the proposed GenAI use and any applicable PDPA exception.
The notice should give people meaningful, specific information about the proposed use. At a minimum, the supplied guidance identifies these elements:
A generic privacy policy may still contain useful background information, but it should not be the only disclosure if it leaves the GenAI training purpose unclear. The central test is whether a reasonable person can understand that their personal data may be used to develop or improve a generative-AI model.
The supplied materials do not prescribe one mandatory format or a single location for every organisation. A practical approach is to show the information where the relevant data is collected or where the service is used—for example, during onboarding, in a just-in-time product prompt, in account privacy controls or through a clearly linked privacy notice.
That placement advice is an implementation inference rather than an exhaustive list from the PDPC factsheet. Whatever format is chosen, the disclosure should be visible and specific rather than buried in broad, difficult-to-find terms.
People may request access to and correction of their personal data even after it has been used in GenAI development. Organisations are expected to use sensible upstream data practices, assess requests case by case and adopt appropriate technical measures, although tracing information through a large training dataset can be difficult.
Where consent is the legal basis, individuals must be told how to refuse or withdraw it. That does not automatically mean that every person can continue using every part of a service on unchanged terms after opting out. Whether core service access can continue depends on the role of GenAI training, the necessity of that processing and the organisation’s consent design. The supplied sources do not establish a blanket right to retain full service access after every opt-out.
IMDA’s Transparency Guidelines for Generative AI Chatbots take a consumer-facing approach. They apply to deployers of external-facing GenAI chatbots and are intended to help users make more informed decisions, standardise disclosures and make providers more accountable for their stated safety and reliability practices.
The central recommendation is a “Chatbot Info Card,” comparable to a nutrition or medicine label. It can take the form of a dedicated information page or disclosure document, provided it gives users one consolidated and accessible place to find the important information.
The card should follow three principles:
A useful card should cover:
The card is not a guarantee that a chatbot is accurate or safe. Its value is that it gives users a clearer basis for deciding when to rely on the tool, what information to share and where to go when something goes wrong.
IMDA initially focused on public chatbots because they have broad consumer exposure and raise concerns including privacy, child safety and risks affecting mentally vulnerable users. The framework may also become a reference point for other GenAI applications and future sector-specific guidance.
Google, Meta, DBS, OCBC, Singapore Airlines and Synapxe have indicated that they will use the voluntary chatbot guidance as a reference as they improve transparency practices for public-facing chatbots. That signals planned alignment and ongoing improvement—not proof that every organisation has already launched an identical information card.
For banks, the emphasis is likely to be on explaining customer-facing functions, limitations and safeguards alongside existing AI-governance and risk-management processes. DBS pointed to its customer-facing AI initiatives, while OCBC connected the guidance with its established AI governance and risk management.
Singapore Airlines said it would continue reviewing and strengthening AI governance and safeguards as it expands AI-enabled customer experiences. Google and Meta supported clearer, more accessible information about how their AI products work and how users interact with them.
Public agencies are also expected to use the framework as a reference: the National Library Board and Health Promotion Board plan to take it into account for their public-facing chatbots.
Singapore’s approach combines a more specific privacy disclosure for certain GenAI data uses with a voluntary public transparency standard for chatbots. Organisations should therefore treat the two measures as complementary but not interchangeable:
The result is not a universal promise that users can stop every AI-related use of their data. It is a push toward clearer disclosure, more deliberate data governance and more accountable public-facing AI.