aiweb.sg lucky cat logoaiweb.sg
21 July 2026 · 8 min read

Singapore's New PDPC Rules on Generative AI & Personal Data (2026)

The PDPC just published Singapore's first proper rulebook for generative AI and personal data. If your business uses ChatGPT, Gemini, or an AI chatbot, these rules apply to you — here is a plain-English breakdown.

Singapore's New PDPC Rules on Generative AI & Personal Data (2026)

On 20 July 2026, Singapore's Personal Data Protection Commission (PDPC) issued its final Advisory Guidelines on Use of Personal Data in Generative AI — closing a public consultation that ran from June and formally answering a question SME owners have been asking for two years: "What can we legally do with customer data when we use ChatGPT, Gemini, Claude or our own AI chatbot?"

If your Singapore business feeds customer names, emails, WhatsApp messages, resumes, medical notes or purchase history into any generative AI tool — whether a public chatbot, a fine-tuned model or an AI website assistant — these guidelines apply to you. Here's what changed, what stayed the same, and the five things you should do this week.

What the new guidelines actually cover

The Advisory Guidelines sit alongside the existing Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems (issued March 2024). Together they now cover the full spectrum of AI under the Personal Data Protection Act (PDPA).

The new generative-AI guidelines focus on three areas:

  1. How personal data may be collected and used to develop generative AI models — including training, fine-tuning and evaluation.
  2. How data-protection responsibilities are split between model developers, deployers (the SaaS vendors) and organisations that use the model (that's most SMEs).
  3. How to handle individual requests — access, correction, withdrawal of consent — when personal data has been processed by a generative AI system.

Crucially, PDPC has confirmed that the PDPA's existing obligations — Consent, Notification, Purpose Limitation, Accuracy, Protection, Retention, Transfer Limitation and Accountability — all continue to apply. There is no separate "AI carve-out". Generative AI is not a licence to do things you couldn't do before.

Who is responsible for what

For most Singapore SMEs, the important question is: "Am I the deployer or the developer?" In 95% of cases, you are the deployer — you use ChatGPT, Claude, Gemini, Copilot, or a chatbot bolted onto your website. That means:

  • The model developer (OpenAI, Google, Anthropic, etc.) is responsible for what went into training the base model.
  • You are responsible for what you put in as prompts, what you get out, and how you use it.

If you paste a customer's PDPA-protected data into a public AI tool, the PDPA sees that as you disclosing it — the AI vendor is your data intermediary at best, and often not even that.

The five things every Singapore SME should do this week

1. Write a one-page "AI Data Notice"

Update your website's Privacy Policy (or add a short AI Notice) that tells visitors:

  • Which AI tools you use (e.g. "we use an AI chatbot for enquiries").
  • What data goes into them.
  • Whether that data is used to train external models (for most consumer-tier tools, the answer is yes unless you explicitly opt out).
  • How they can opt out or request deletion.

This satisfies PDPA's Notification Obligation, which the guidelines flag as one of the areas SMEs most commonly miss.

2. Turn off training on your business AI accounts

For the tools your team actually uses — ChatGPT, Gemini, Claude, Copilot, Perplexity — switch on the "do not train" setting and use business/enterprise tiers where possible. On free consumer tiers, prompts are often used for future training by default, which almost always breaches your Purpose Limitation duty when customer data is involved.

3. Ban PDPA data from public prompts

Give your team a short, written rule: no NRIC, no FIN, no full names + phone numbers, no medical or financial details, no minor's data may be pasted into a public AI tool. If you need AI to process such data, use a business plan with a signed Data Processing Agreement (DPA), or a locally-hosted model.

4. Fix your AI chatbot's data flow

Many SG SME websites now run an AI chat widget (Intercom, Tidio, Chatbase, ManyChat, a custom OpenAI wrapper). Check:

  • Is there a visible notice at the start of the chat that the conversation is processed by AI?
  • Are you storing transcripts? For how long? (Retention Obligation)
  • Do you have a process to delete a user's chat history if they ask? (Withdrawal + Access/Correction)
  • Is the vendor's data-processing region acceptable under the Transfer Limitation Obligation? (US-hosted vendors need contractual safeguards.)

5. Log your AI use cases

The Accountability Obligation now clearly extends to AI. Keep a simple internal register: what AI tool, what data, what purpose, who approved it, opt-out method. A Google Sheet is enough for a 5–20 person business. If the PDPC ever asks — or a customer complains — you can answer in a day rather than a week.

What individuals can now ask you for

The guidelines confirm that individuals retain their PDPA rights even when their data has been processed by a generative AI model. Practically, that means a customer can ask you to:

  • Access — what personal data of theirs you fed into an AI tool, and roughly what came out.
  • Correction — fix errors in AI-generated content about them.
  • Withdrawal of consent — stop using their data in your AI workflows.
  • Deletion — remove their data from your AI vendor's systems (which you must in turn request from the vendor).

You have 30 days to respond substantively. "The AI did it" is not a defence.

What this means for AI-built websites

At aiweb.sg we build AI-generated websites for Singapore SMEs every day, so we've been watching this closely. Two takeaways for site owners:

  • Contact forms and lead capture are unchanged. As long as your form has clear consent language and you're not silently feeding submissions into a public chatbot for training, you're fine.
  • AI chatbots on your site now need a visible AI notice. If you have (or want) a chat widget powered by GPT, Gemini, or similar, add a one-line disclosure at the start of the conversation: "This chat is powered by AI. Please don't share NRIC, financial or medical details." All our client sites that use AI chat now ship with this by default.

FAQ

Q: Do these guidelines have the force of law? A: They are advisory, but they are how the PDPC will interpret the PDPA in enforcement. Financial penalties under the PDPA can reach S$1 million or 10% of Singapore turnover, whichever is higher — so treat them as binding.

Q: We only use ChatGPT internally for drafting emails. Do we need to do anything? A: Yes, at minimum: switch off training in ChatGPT settings, and tell your team not to paste customer PDPA data into it. That covers 90% of your risk.

Q: Does this apply to AI-generated marketing copy on our website? A: Only if the input contained personal data. AI writing "5 reasons to visit our clinic" is fine. AI writing "Case study: how we treated Ms Tan, 42, from Bukit Timah" using a real patient's details is not.

Sources

Want this kind of site for your Singapore business?

Free 1-page trial on aiweb.sg subdomain. Paid plans from S$89/month, live in 3–5 days.