The one line that summarises it: "Your data may be processed by AI" in the master privacy policy is not enough. A specific, prominent AI-purpose notification is required.
What happened on 20 July 2026
The PDPC published its final Advisory Guidelines on the Use of Personal Data in Generative AI Systems at the inaugural Singapore Data Festival. Minister for Digital Development and Information Josephine Teo announced them. Consultation on the draft ran from 2 June to 1 July 2026. The final guidance took effect on the publication date — 20 July 2026 — with no transitional period.
The AI-Specific Notification requirement
The PDPC\'s position is that where personal data is used for AI model training or fine-tuning, the individual must be told specifically. That means:
- A general "we may use your data to improve our services" line does not cover AI training.
- The notification should be given at the point of collection where practicable, or via a clearly-signposted separate notice where not.
- Notification should identify AI/GenAI as the purpose, not hide behind generic language.
Notification is distinct from consent. Consent may or may not be required depending on the legal basis relied on; notification is required regardless.
The publicly-available exception — and its limit
The PDPA\'s publicly-available exception permits processing of personal data made publicly available. The final Guidelines confirm this exception can be relied on for training AI models on web-scraped content. But the Guidelines are also clear that:
- Data behind a paywall is not "publicly available" even if superficially accessible.
- Data behind registration or authentication is not "publicly available".
- Data on social platforms may or may not be — depends on the specific access model.
The deployer — the Singapore organisation using the AI system — bears the primary responsibility for verifying the classification. "Our vendor said it was public" is not a defence.
Which Singapore businesses this hits hardest
Three profiles carry the highest exposure:
- SaaS and CRM operators processing customer records through GenAI features. Every AI feature that touches customer data needs its notification path checked.
- Marketing agencies and lead-generation businesses. Enquiry forms feeding AI enrichment or classification — the notification belongs on the form, not in the master policy.
- Clinics, financial advisors and any professional service running an AI intake or chatbot. Personal data flows into AI as part of the service; the disclosure has to be prominent.
What to do this week
- Inventory every AI use over personal data. One row per system.
- Add an AI-Specific Notification at the collection point. One sentence per system. Plain language.
- Audit training-vs-inference distinction with each vendor. Data used purely at inference (never retained, never trained on) has a lighter notification profile than data ingested into training.
- Document your scraping / public-data classification. If you rely on the publicly-available exception, write down why the data qualifies.
What did not change
The PDPA framework itself. The Do Not Call registry rules (see DNC + PDPA for Singapore lead follow-up) are unchanged. The general purpose-limitation and consent regime is unchanged. The Guidelines sit alongside the PDPA, not on top of it.
Related reading
- The voluntary chatbot information card — released alongside the Guidelines
- shakalakaa Singapore — regional practice
References
- PDPC, Advisory Guidelines on the Use of Personal Data in Generative AI Systems (final), 20 July 2026 — pdpc.gov.sg
- Stephenson Harwood, client alert on the final PDPC Guidelines, July 2026
- Latham & Watkins, Global Privacy & Cyber Blog on Singapore Advisory Guidelines, July 2026
- Techgoondu, coverage of Singapore Data Festival AI announcements, 22 July 2026