On 20 July 2026, the Personal Data Protection Commission of Singapore (PDPC) published its Advisory Guidelines on Use of Personal Data in Generative AI. The guidelines are issued under the Personal Data Protection Act 2012 (Act 26 of 2012) (PDPA) and set out how existing PDPA obligations apply to organisations that use generative AI systems to collect, use, or disclose personal data in Singapore. They follow a public consultation launched 2 June 2026.
The guidelines address PDPA obligations across three stages of generative AI use. At the training stage, organisations collecting or using personal data to train or fine-tune models must identify a valid purpose and, where required, obtain consent under the PDPA's consent obligation in Part 3. At the inference stage, organisations must comply with purpose limitation, consent, and data accuracy obligations when feeding personal data as model inputs. At the output stage, organisations must assess the risk that AI-generated content contains or reconstructs personal data, including data not directly input to the model.
Technology companies, financial institutions, healthcare providers, and professional services firms deploying generative AI tools in Singapore that process personal data must review their AI workflows against the guidelines. Vendor contracts for third-party AI tools must be assessed for PDPA-compliant data processing terms. Firms that send personal data to offshore inference or training infrastructure must assess compliance with the PDPA's transfer limitation obligation under Part 9.
The guidelines sit alongside the PDPC's Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (published February 2024), together covering the main AI use categories under the PDPA. They complement Singapore's National AI Strategy 2.0 and the Model AI Governance Framework published by the Infocomm Media Development Authority, bringing personal data protection obligations into a broader national AI governance programme. The PDPC indicated it may issue further sector-specific guidance in subsequent phases.
Licentium advises organisations on data protection compliance for AI systems across Asia-Pacific jurisdictions, including Singapore PDPA readiness assessments. Contact us to discuss your obligations under the new guidelines. Work we undertake includes PDPA gap assessments for generative AI deployments, training data audit and consent framework design, AI vendor contract review, cross-border data transfer structuring under PDPA transfer limitation provisions, and AI governance policy drafting.
Source: PDPC, Advisory Guidelines on Use of Personal Data in Generative AI, 20 July 2026