Data Protection · Singapore

PDPA & Generative AI Guide

A practical starting point for Singapore businesses assessing how personal data moves through AI tools and workflows.

General information onlyThis guide is not legal advice. The applicable position depends on your circumstances; consult your DPO or a qualified Singapore lawyer where needed.

Before an AI pilot uses personal data

The Singapore Personal Data Protection Act 2012 provides a baseline standard for protecting personal data. AI does not remove an organisation’s existing responsibilities. It can introduce additional questions because information may pass through prompts, connected systems, model providers and generated outputs.

1. Define the purpose and owner

Document what the AI workflow does, why personal data is needed, who is accountable and which employees or vendors can access it. Avoid collecting data simply because it may become useful later.

2. Identify the personal data involved

Map the prompts, uploaded documents, connected systems, retrieved knowledge and generated outputs. Consider whether the data can be removed, redacted, aggregated, pseudonymised or replaced with non-personal test data.

3. Confirm the applicable basis and notification

Determine whether consent is required or an exception may apply, and whether individuals have been clearly notified of the relevant purposes. Do not rely on vague wording without assessing the actual workflow.

4. Review the AI provider

Examine how the provider uses prompts and files, where data is processed, how long it is retained, whether it trains models with your data, which subprocessors are involved and what enterprise controls are available.

5. Protect transfers and access

Where personal data may be transferred outside Singapore, assess the PDPA transfer requirements and contractual safeguards. Apply role-based access, authentication, logging and secure offboarding.

6. Keep people accountable

Define which outputs require verification, who approves customer-facing or high-impact decisions and how employees should respond when the model is uncertain, inaccurate or inappropriate.

7. Plan for lifecycle and incidents

Set retention and deletion rules, monitor changes to vendors and models, maintain an incident path and review whether a data breach is notifiable under applicable requirements.

Use current official guidance

The PDPC’s 2024 advisory guidelines address AI recommendation and decision systems. In June 2026, the PDPC also published proposed generative AI guidelines for consultation; proposed guidance should not be presented as final law.

Apply the guide

Review governance before scaling AI access.

Open governance checklistSpeak with a consultant