Singapore’s PDPC issued final generative AI data guidance on July 20, 2026: when consent is required, generic phrases such as “new product development” are not enough, and organisations must specifically explain the A... Notices should explain the model’s purpose, the categories of personal data used, how the data c...
Research answer

Create a landscape editorial hero image for this Studio Global article: What are Singapore’s proposed Personal Data Protection Commission (PDPC) guidelines for organisations using personal data to train generativ. Article summary: The PDPC’s June 2026 proposal aimed to prevent organisations from hiding GenAI training behind generic “product development” privacy language. It called for a prominent, AI-specific notice, but it left important practica. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Singapore’s proposed rules on personal data and generative AI are no longer only a consultation issue. The Personal Data Protection Commission (PDPC) issued final Advisory Guidelines on the Use of Personal Data in Generative AI on July 20, 2026. The central message remains clear: organisations should not rely on vague privacy language when consent is needed for large-scale model training or fine-tuning.
Where an organisation needs consent to use personal data for developing or improving a generative-AI model, its notice should identify that AI-specific purpose directly. A general statement that data may be used for “new product development” is not sufficient.
The guidance is advisory rather than a standalone ban on AI training. It works within Singapore’s Personal Data Protection Act (PDPA), including exceptions that may allow some uses without consent. One important example is the treatment of certain publicly available personal data used for AI development.
A useful notice should give people enough information to understand both the product and the data pipeline. The proposed approach called for organisations to explain:
The PDPC’s concern is transparency that works at the point of decision—not a buried sentence in a lengthy privacy policy. Suggested formats included a prominent in-product notice or a dedicated webpage.
A company developing text-to-speech functionality could explain that it uses customers’ voice recordings to train the model and that the recordings help the system recognise speech patterns. That is materially clearer than describing the purpose only as product improvement.
The most important compliance distinction is between telling people what will happen and establishing a lawful basis for using their data. Under the PDPA’s general framework, organisations generally need to notify individuals of the purpose and obtain consent unless an exception applies.
The final guidance clarifies the content of the notification when consent is required: the organisation must expressly address the intended AI model-development use. That does not mean every use of personal data for AI training automatically requires affirmative, explicit consent. The answer can depend on the applicable PDPA exception, including rules concerning publicly available information.
For businesses, the practical lesson is to document the legal basis for each training dataset separately. A clear notice cannot replace consent where consent is required, and consent cannot be assumed from language too general to describe the actual AI use.
The consultation-stage proposal attracted attention because several operational questions were not obvious from the initial notice requirement.
The draft did not clearly establish that affirmative, explicit consent would be required in every GenAI-training scenario. It instead prompted questions about when an opt-out approach might be acceptable and when an existing PDPA exception could apply.
The final guidance’s treatment of consent and exceptions makes the legal basis more important, not less. Organisations should avoid presenting an AI-specific notice as a universal substitute for consent.
The draft also left uncertainty about whether the special notification expectation would apply when data were anonymised before training. That question matters because the privacy analysis may differ depending on whether information can still be linked to an identifiable individual and how the organisation performs and documents the anonymisation.
The available reporting does not support treating anonymisation as an automatic answer for every dataset. Companies should assess the data and processing method rather than assuming that labelling a dataset “anonymised” ends the analysis.
Another unresolved issue was whether banks, insurers, platforms, or other providers could withhold or make a service unavailable when an individual refused the use of their data for AI training. This is where formal choice can meet practical pressure: an opt-out may exist on paper but be difficult to exercise if refusing it carries a significant cost.
The notification requirement improves visibility, but it does not by itself answer every question about fairness, service access, or the bargaining power between individuals and providers.
The PDPC’s attention to generative AI sits within a broader concern about products that collect data in ways people may not notice. Reporting around Commissioner Denise Wong’s priorities has highlighted devices and systems such as smart glasses, smartwatches, and palm-scanning payment systems.
These products can involve sensitive information, including facial features, fingerprints, voice data, and palm-vein patterns. The reported risks include covert recording, exposure or misuse of biometric information, and smart glasses being used to capture examination material or other information to facilitate cheating.
Singapore’s Ministry of Digital Development and Information has also addressed questions about visual indicators on smart glasses and the collection of biometric or environmental data from people nearby who are not using the device.
The underlying issue is meaningful awareness. A small recording light or a device policy hidden in documentation may not give bystanders a realistic opportunity to understand what is happening or make a choice.
Teams developing or deploying GenAI systems in Singapore should treat the guidance as a data-governance checklist:
Singapore’s shift is therefore less about banning the use of personal data in generative AI than about making the use visible, specific, and tied to an identifiable legal basis. The final guidance closes some of the gap between traditional privacy notices and modern AI development, while the hardest questions—especially meaningful choice and the treatment of sensitive or indirectly captured data—remain active governance concerns.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Singapore’s PDPC issued final generative AI data guidance on July 20, 2026: when consent is required, generic phrases such as “new product development” are not enough, and organisations must specifically explain the A...
Singapore’s PDPC issued final generative AI data guidance on July 20, 2026: when consent is required, generic phrases such as “new product development” are not enough, and organisations must specifically explain the A... Notices should explain the model’s purpose, the categories of personal data used, how the data contributes to the model, and how people can opt out or withdraw consent.
The draft raised unresolved questions about explicit consent, anonymised data, and whether refusing AI training use could affect access to a service.