Singapore’s Personal Data Protection Commission (PDPC) has issued guidance explaining how organisations should handle personal data throughout the development and deployment of generative AI systems.
Published jointly with the Infocomm Media Development Authority (IMDA), the guidance explains how organisations should comply with the Personal Data Protection Act (PDPA) during the development, deployment and post-deployment use of generative AI.
Developers may rely on the PDPA’s exception for publicly available information when collecting personal data from openly accessible websites. However, information behind paywalls, registration requirements or other digital barriers may not qualify, meaning organisations may need consent or another legal basis for processing.
Where personal data is used to develop AI models, organisations should also provide AI-specific privacy notices explaining why the information is collected, how it will be processed and how individuals can withdraw consent.
The guidance assigns responsibilities across the AI supply chain. Model providers must comply with data retention and protection obligations, while system providers should review security arrangements and communicate safeguards to downstream users.
Organisations deploying AI systems retain primary responsibility for compliance, including defining lawful processing purposes, protecting personal data throughout deployment and regularly reviewing safeguards, particularly for agentic AI applications.
Individuals retain the right to request access to or correction of their personal data after it has been used in AI development. Organisations are expected to establish practical processes for handling such requests, even where training datasets are large or stored differently from conventional databases.
The final guidance reflects feedback from a public consultation involving technology companies, banks, airlines, healthcare organisations and other stakeholders.
Why does it matter?
The guidance clarifies that responsibility for protecting personal data does not disappear as information moves through increasingly complex AI supply chains. By defining the obligations of developers, providers and deployers, Singapore is reinforcing the principle that accountability must accompany every stage of the AI lifecycle.
The document also illustrates how privacy regulation is adapting to generative AI without creating a separate legal regime. Instead, it applies established data protection principles—such as consent, transparency, security and individual rights—to emerging AI technologies, providing organisations with clearer expectations for responsible deployment.
Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!
