Singapore Now Requires Companies to Notify Users When Personal Data Is Used for AI Training
Source: The Straits Times
Singapore's approach to AI governance has largely been built on voluntary guidelines and industry collaboration — but that shifted this morning. Starting July 20, companies in Singapore are legally required to inform consumers when their personal data is being used to train generative AI models.

Singapore's approach to AI governance has largely been built on voluntary guidelines and industry collaboration — but that shifted this morning. Starting July 20, companies in Singapore are legally required to inform consumers when their personal data is being used to train generative AI models. It's a concrete regulatory step that brings the city-state closer to the enforceable AI frameworks taking shape across Europe and North America.
The new rule, announced by Minister for Digital Development and Information Josephine Teo at the Singapore Data Festival, is set out in advisory guidelines released by the Personal Data Protection Commission (PDPC) following a month-long public consultation that ran from June 2 to July 1. Organisations can no longer rely on broad privacy notices that mention "new product development" or "personalisation of services" — they must now issue AI-specific notifications when training models on user data.
The guidelines don't prescribe exactly what those notices should say or where they should appear, but the PDPC recommends companies explain the types of data used through in-app pop-ups or dedicated webpages. Importantly, organisations including banks, insurers and social media platforms are not allowed to deny services to consumers who opt out of AI training. The rule does not apply when anonymised data is used.
Alongside the mandatory notifications, the PDPC released voluntary guidelines urging AI chatbot providers to disclose information through what Teo described as "chatbot information cards" — akin to a medicinal product label that tells users what the chatbot is for, what it is not for, how data may be handled, and how to report issues. Big tech companies like Google and Meta, alongside local giants DBS, OCBC, Singapore Airlines and Synapxe, have committed to rolling out their own versions over the next 12 months. Public sector agencies including the National Library Board and Health Promotion Board will also adopt the guidelines.
Why it matters for Singapore: This is the clearest signal yet that Singapore is moving from light-touch AI principles toward enforceable rules. The AI-specific notification requirement — even as a guideline with advisory rather than prescriptive force — sets a compliance baseline that every company developing or deploying generative AI in Singapore will need to operationalise. For a market that has positioned itself as a trusted hub for AI development, this creates both a regulatory moat and a reputational asset: companies operating here now have a clear transparency standard that many regional peers lack. The chatbot information card framework, meanwhile, addresses a gap that consumers have felt for years — not knowing what happens to the data they type into a chatbot, or whether the answers they get are reliable. The next 12 months will show whether voluntary adoption by early movers like DBS, Google and Meta creates enough momentum to make the cards an industry norm.


