Singapore expands Gen AI data rules and enterprise guidance
Singapore expands its Gen AI data guidance alongside measures covering chatbots, digital twins and cross-border transfers.
Singapore has introduced new guidance on the use of personal data in generative AI, alongside measures covering chatbot transparency, digital twins, privacy-enhancing technologies, and cross-border data transfers.
Table Of Content
Announced at the inaugural Singapore Data Festival on 20 July, the package addresses two distinct aspects of enterprise data adoption. While organisations receive clearer responsibilities for protecting personal information, new playbooks, workshops, and funding support aim to help them deploy data effectively in operational projects.
Personal data rules extend into AI workflows
The Personal Data Protection Commission’s (PDPC) Advisory Guidelines on use of Personal Data in Gen AI clarify how personal data can be collected and utilised to develop generative AI models.
This guidance delineates data protection responsibilities across the AI lifecycle and addresses emerging information sources created via AI services, such as user-entered prompts. It also outlines how organisations should respond to individual requests regarding their personal data.
In certain cases, specific consent may be required before personal information can be used to train a Gen AI model. This extends existing data protection obligations into a development process where data frequently passes between model builders, deployers, and the organisations operating the final service.
Consumer-facing transparency is addressed through separate guidelines from the Infocomm Media Development Authority (IMDA). These encourage chatbot operators to provide Chatbot Info Cards detailing the system’s capabilities and limitations, safety and reliability practices, data usage and protection policies, and available reporting channels.
These cards aim to better inform users before they decide what information to share with a chatbot. Concurrently, the PDPC has updated its Guide to Data Protection Practices for Information and Communications Technology Systems, incorporating current practices based on recent data breaches and cybersecurity measures, alongside specific guidance for companies integrating AI into their workflows.
Guidance moves from data protection to deployment
Beyond protection, the broader programme addresses how companies can effectively utilise data once the necessary safeguards are established.
The IMDA’s Digital Twin for Enterprises Playbook is designed to help Singaporean businesses assess and implement digital twin projects. A digital twin serves as a live, data-driven representation of a physical asset, system, or process, maintaining a continuous connection to real-world operations.
These systems allow organisations to monitor performance, identify potential issues, and simulate changes in a virtual environment before applying them to physical operations. The IMDA highlights significant potential in sectors such as manufacturing, buildings, and logistics, particularly where equipment failures, defects, or supply chain disruptions incur high costs.
Developed in consultation with early adopters, technology providers, and industry leaders in Singapore, the playbook covers use-case selection, data readiness, safeguards, and implementation. The IMDA will support this initiative through Tech Discovery Workshops, partnering with technology providers to help companies identify suitable applications and guide projects through to full deployment.
This emphasis on controlled data use extends to privacy-enhancing technologies. The PDPC has released a Guide on Federated Learning, developed with input from industry experts including NVIDIA, to help organisations assess whether the approach suits their requirements and how to implement it responsibly.
Additionally, its Guide on Synthetic Data Generation has been updated to reflect recent use cases, practices, and adoption trends.
Businesses exploring these technologies can access support through the IMDA’s Privacy Enhancing Technologies Sandbox, which offers grants to offset the cost of proof-of-concept projects. The programme will also introduce demonstrations of various tools, allowing organisations to evaluate their functions and potential applications before committing to a trial.
Furthermore, new sandbox use cases featuring the Singapore General Hospital and Ant International have been published.
Japan agreement addresses cross-border transfers
Complementing the domestic guidance is a new data protection agreement between Singapore and Japan.
Singapore’s PDPC has signed a Memorandum of Cooperation with Japan’s Personal Information Protection Commission (PPC), focusing on the Global Cross-Border Privacy Rules and the development of model contractual clauses.
These frameworks aim to lower compliance costs for companies transferring data between the two nations, while ensuring robust protection under their respective privacy regulations.
The agreement was signed by Denise Wong, Singapore’s Commissioner for Personal Data Protection, and Tezuka Satoru, Chairman of Japan’s PPC. The signing was witnessed by Hiroshi Ishikawa, Japan’s Ambassador to Singapore, and Ng Cher Pong, Chief Executive of the IMDA.
The Singapore Data Festival takes place from 20 to 24 July at the Sands Expo & Convention Centre.





