Singapore sets out PDPA duties for organisations using personal data in GenAI
Singapore’s PDPC explains how the PDPA applies when organisations collect, reuse and process personal data in GenAI systems.
Singapore’s Personal Data Protection Commission has published guidance explaining how the Personal Data Protection Act applies when organisations use personal data to develop and operate generative artificial intelligence models and systems. Prepared with support from the Infocomm Media Development Authority, the guidelines follow the entire lifecycle of a GenAI system. This journey begins with how data is collected for model development, continues through active deployment, and concludes with handling requests from individuals after their information has been processed. The framework also divides specific responsibilities among model providers, system providers, and the organisations using those systems.
Table Of Content
Public access does not remove every consent requirement
Organisations developing GenAI models may rely on the Publicly Available Exception within the Personal Data Protection Act to collect publicly accessible personal data through web scraping without explicit consent. However, the guidance requires these entities to consider how the information was originally made available. Personal data positioned behind paywalls, registration requirements, or other digital barriers may not qualify as publicly available in the same way as information that anyone can access freely. Consequently, organisations must thoroughly assess whether the exception applies before collecting such data for model development.
The position becomes more specific when organisations want to reuse information that individuals originally provided for another purpose. Where no exception to consent applies, they must obtain clear consent before using that data to develop a GenAI model. To address this, the commission recommends an AI-specific notification that explains why the information will be used, which data is involved, how it will be processed, and how individuals can decline or later withdraw consent. This approach places the emphasis directly on the intended AI use, rather than relying on a notification written for the service or transaction through which the data was first collected.
Responsibility follows the system into deployment
Once a GenAI system is deployed, responsibilities are divided according to the specific role each organisation plays. Model providers must comply with applicable Personal Data Protection Act obligations when processing personal data to develop and deploy GenAI models, with particular attention directed towards data retention. When handling data on behalf of other organisations, they are also encouraged to document their model-level safeguards and share that information with downstream users.
System providers, which supply the wider systems built around those models, must periodically review their security arrangements. The guidelines recommend that they give organisations using their systems enough information to understand the protections in place. Meanwhile, primary responsibility remains with the system deployer. The organisation operating the GenAI system must define clear purposes for processing personal data, protect information flowing through the system, and review its safeguards regularly, especially when agentic AI systems are involved.
This division of duties creates a clear chain of accountability, but it does not transfer compliance entirely to the technology provider. Model and system providers are expected to support downstream organisations with information about their safeguards, while deployers remain responsible for how personal data is used within their own operations.
Individual rights continue after development
The use of personal data in model development does not remove an individual’s right to request access to or correction of that information. The commission acknowledged that responding can be difficult when models have been trained on large volumes of data or when the underlying information is not kept in a conventional repository. The guidelines nevertheless expect organisations to prepare for such requests by improving how data is handled earlier in the process, considering cases individually, and adopting appropriate technical measures.
The final guidance incorporates feedback from a public consultation that closed on 1 July. The commission received responses from 40 organisations and three individuals, including submissions from Google, Meta, WeChat, DBS, Singapore Airlines, Workday, Prudential, HSBC, Epic Systems Corporation, and NUHS. Respondents asked for clearer examples of digital barriers that could affect whether personal data is considered publicly available. They also recommended expanding the types of safeguard information that model and system providers share with organisations deploying their technology.
The new guidelines are intended to be read alongside the existing advisory guidelines on personal data in AI recommendation and decision systems, as well as broader guidance on key concepts under the Personal Data Protection Act.





