Singapore Mandates AI-Specific Privacy Notifications But Stops Short of Prescribing How
Source: Techgoondu
Singapore has drawn a new line in the sand for how companies handle personal data in the age of generative AI, but it's a line drawn in pencil, not ink. From July 20, the Personal Data Protection Commission's (PDPC) new advisory guidelines require organisations to explicitly notify consumers when their...

Singapore has drawn a new line in the sand for how companies handle personal data in the age of generative AI, but it's a line drawn in pencil, not ink. From July 20, the Personal Data Protection Commission's (PDPC) new advisory guidelines require organisations to explicitly notify consumers when their personal data is used to train or improve generative AI systems — a first-of-its-kind rule for the city-state that signals a deliberate shift from broad privacy notices to AI-specific transparency. But the guidelines deliberately stop short of mandating how companies must comply, underscoring Singapore's preference for principles-based regulation over prescriptive rules.
The requirement, announced by Minister for Digital Development and Information Josephine Teo at the inaugural Singapore Data Festival on July 20, covers any organisation that uses personal data — including sensitive information such as children's data, health records, and credit information — to develop, adapt, or deploy generative AI tools. The PDPC's concern is specific: once data has been incorporated into a model, it may be difficult to remove or correct. Previously, companies could rely on broad privacy notices covering activities such as product development or service personalisation. Now, they must separately flag when training a GenAI model is one of those activities.
The flexibility in compliance method is the most Singaporean aspect of the guidelines. Companies can use in-app notifications, dedicated webpages, or any channel that effectively communicates the use to consumers — there is no prescribed template or format. This mirrors the approach the city-state has taken with other emerging technology regulations: set the principle, let industry figure out the implementation, and tighten only if gaps emerge. The PDPC's advisory follows a public consultation and reflects feedback from both industry and civil society on the tension between AI innovation and data protection.
Alongside the mandatory notification rule, the government released voluntary transparency guidelines encouraging providers of public-facing AI chatbots to publish a "chatbot information card" — a plain-language summary of what the chatbot can and cannot do, how user data is handled, and how to report problems. Josephine Teo compared the concept to a medicine label: consumers do not need every scientific detail, just the information required to use the product safely. Google, Meta, DBS, OCBC, Singapore Airlines, and public healthcare IT agency Synapxe have all committed to rolling out these cards over the next six to 12 months.
Why it matters for Singapore: Singapore is taking a fundamentally different path from the EU's AI Act, which focuses on obligations for developers and providers. By centring its approach on consumer notification and chatbot transparency, Singapore is betting that trust — not technical compliance — is the bottleneck to AI adoption. The approach aligns with the National AI Strategy's emphasis on building a trusted AI ecosystem, and positions Singapore as a testbed for a lighter-touch model of AI governance that other Asian markets may adopt. The real test will be whether principles-based notices actually change consumer behaviour, or whether they become another layer of fine print that nobody reads.


