Navigating the PDPC’s AI Guidelines
Article By
Organisations are increasingly developing and deploying systems that use AI models to analyse personal data, generate content and make recommendations and decisions (“AI Activities”).
The Singapore Personal Data Protection Commission (“PDPC”) has released two advisory guidelines: the Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (“AI Recommendation and Decision Guidelines”) on 1 March 2024 and the Advisory Guidelines on Use of Personal Data in Generative AI (“GenAI Guidelines”) on 20 July 2026 (collectively, “PDPC AI Guidelines”).
This article sets out the key takeaways of both PDPC AI Guidelines for organisations that wish to use personal data for AI Activities. We covered the key takeaways on GenAI Guidelines in our earlier article, but this article will serve as a guidepost to both PDPC AI Guidelines.
While the PDPC AI Guidelines are not legally binding, they are likely to be consistent with the PDPC’s positions if it carries out enforcement of the Personal Data Protection Act (“PDPA”).
1. My organisation is carrying out AI Activities. Which PDPC AI Guidelines should I refer to?
If you are collecting and using personal data for an AI Activity, the relevant guidelines will be dependent on the type of AI Activity you are deploying.
If the AI Activity involves systems that embed a machine-learning model (“AI System”) to generate a recommendation, prediction, or decision, use the AI Recommendation and Decision Guidelines. For example, you are using AI and personal data (such as browsing history) to develop and operate a content-recommendation algorithm.
Where a system uses a generative AI model to generate output (e.g. text, code, images, audio), use the GenAI Guidelines. For example, you are deploying a generative AI feature that uses a user’s profile information, posts and comments to generate personalised captions.
If your use of AI involves both types of AI Activity, you should refer to both guidelines.
It is also important to note that the GenAI Guidelines makes repeated reference to the AI Recommendation and Decision Guidelines. Cross-references to the AI Recommendation and Decision Guidelines may therefore be required.
2. If I am deploying AI, what are the recommended practices by the PDPC that I should adopt to meet my obligations under the PDPA?
The PDPC AI Guidelines provide organisations that are carrying out AI Activities guidance on how they can do so while complying with their PDPA obligations. They also recommend specific practices to help organisations meet those obligations.
Notification
If you are deploying AI Systems, the PDPC encourages organisations to include the following:
- the function of the product that requires the personal data to be collected and processed;
- why it will be processed;
- how it will be used to provide the relevant AI-enabled feature; and
- specific features of personal data that would be more likely to influence the product feature.
If you are deploying generative AI systems, an AI-Specific Notification is needed. Organisations are encouraged to include the following information:
- the function(s) of the generative AI model that require the personal data;
- the types of personal data used to develop the model;
- how personal data will be used to train or tune the model; and
- how individuals can decline or withdraw consent to the use of personal data for AI training.
PDPC clarified that a notification generally referring to “new product development” without specifying AI or generative AI model development in the privacy policy or terms of service is insufficient.
Data Protection – Collection, Use and Security
Organisations should:
- only use the personal data and volume necessary for the AI Activities’ intended purpose;
- practice data minimisation and pseudonymisation as much as possible;
- have appropriate technical, procedural and legal safeguards;
- take a privacy-by-design approach;
- conduct a Data Protection Impact Assessment (“DPIA”) where appropriate; and
- apply safeguards proportionate to the data’s sensitivity, volume, and the risk of disclosure or theft.
The guidelines re-emphasise that the PDPA will not be applicable if anonymised data is being used for the AI Activities. Organisations are reminded that data will only qualify as anonymised data if there is no serious possibility of reidentification.
Accountability
Generally, clear written policies and documented processes are encouraged. The policies should address relevant safeguards for personal data processed through prompts, inputs and outputs, and be made publicly available where appropriate (e.g. on a website).
In AI Systems, technical tools like AI Verify may assist organisations to assess selected aspects of an AI system. Results can be included in notifications or policies.
Access and correction
The GenAI Guidelines acknowledge the practical difficulty of complying with access and correction obligations for large AI models,but confirm that these obligations continue to apply to the extent compliance is reasonable. Organisations should ensure that their deployment of AI systems is supported by upstream data handling techniques, the maintenance of data provenance records, the removal of inaccurate data, and the implementation of output‑filtering measures.
3. Are there situations where I can collect and use personal data for AI Activities without the individual’s consent?
Yes, there are situations where organisations may rely on certain exceptions to consent instead. The PDPC sets out its position on three non‑exhaustive exceptions.
a) Business Improvement Exception: Where the use is directed towards improving, enhancing, or developing new or existing goods or services, improving business processes, understanding individuals’ behaviours and preferences, or personalising goods or services. This exception is limited to personal data used within a company or shared between related companies.
The organisation must also be satisfied that the business improvement purpose cannot reasonably be achieved without using personal data in an individually identifiable form, and that a reasonable person would consider the use appropriate in the circumstances.
Situations in which the exception could apply include:
- recommendation engines in social media services that offer users content more aligned to their browsing history;
- job assignment systems that automatically assign jobs to platform workers;
- use of AI Systems to provide new product features and functionalities to improve competitiveness of products and services.
b) Research Exception: Where the research purposes cannot be accomplished unless personal data is in an individually identifiable form, there is clear public benefit, the results will not be used to make any decision that affects the individual, and published research results cannot identify the individual.
c) Publicly Available Exception: Where the personal data is generally available to the public, including personal data that may reasonably be observed at a location or event open to the public.
The PDPC considers the following publicly available data although the data is behind digital barriers:
- registers administered by public agencies that are generally available, including those accessible upon payment of a fee;
- news or media websites that impose paywalls as monetisation mechanisms rather than substantive access barriers; and
- large online forums open to all users, even if registration details are required, provided such requirements are not unduly complex or burdensome.
Where it is reasonably arguable that the data is not publicly available, organisations should conduct a DPIA or otherwise document their assessment before using the data.
4. What are the best practices for data intermediaries across the AI value chain?
Data intermediaries operate in different commercial roles across the AI value chain under the PDPC AI Guidelines. For AI Systems, this includes service providers who may process an organisation’s personal data to develop bespoke systems. For generative AI, it includes Model Providers (i.e. those who develop and make available generative AI models for distribution and use) and System Providers (i.e. those who develop and make available bespoke, customisable, and/or retail generative AI systems).
Under the PDPA, data intermediaries must comply with the Protection, Retention Limitation and Data Breach Assessment and Notification obligations found at Parts 1, 2, 9, 9A, 9B, 9C, 9D, 10 and Sections 24, 25, 26C(3)(a) and 26E of the PDPA.
Data intermediaries are not required to comply with other provisions of the PDPA (e.g. Consent, Notification, and Accountability obligations). However, they may wish to adopt certain best practices to support client organisations. Client organisations, in turn, should contractually bind their data intermediaries to adopt the following practices where appropriate.
Best practices for service providers of AI Systems include:
- understanding the information that client organisations need to meet their Consent, Notification, and Accountability Obligations and the impact the AI System will have on individuals/users;
- designing a system that enables service providers to easily extract information relevant to meeting the client organisation’s PDPA obligations; and
- data mapping, labelling training sets, and maintaining a provenance record that tracks the source of personal data and its transformed state.
Best practices for generative AI System Providers include the sharing of information on system-level safeguards, such as:
- data security and protection measures around the development environment (e.g. access controls, residency and retention policies, input and output filters, privacy-enhancing technologies);
- testing and performance metrics (e.g. likelihood of data leakage); and
- incident response and data breach procedures (e.g. notification timelines).
Where applicable, generative AI Model Providers should implement documented data access controls, data location and retention, incident response, and data breach procedures appropriate to their role and the data processed. This helps client organisations and System Providers meet their respective PDPA obligations.
If you would like any further information or assistance, please reach out to your existing contact at the firm or email us at contact@ghowsllc.com.