More disclosure, more opportunity? Singapore's new rules for GenAI and personal data use
At the Singapore Data Festival, the Infocomm Media Development Authority (IMDA) launched guidelines around personal data use for GenAI, as well as resources to support enterprises to leverage data for business value.

The Singapore Data Festival, formerly the Personal Data Protection Week, has broadened its focus to "bigger questions about data, especially how to support AI efforts." Image: IMDA
Organisations in Singapore would now need to tell consumers explicitly when their personal data is used to train or develop generative artificial intelligence (GenAI) models.
Previously, they could rely on general privacy notices in the personal data advisory guidelines for traditional AI. For example, organisations could simply state that the consumer data is used to personalise services and product development.
The new AI-specific notification requirements goes further, encouraging organisations to spell out the type of data used, how it is used, and how consumers can opt out or withdraw consent.
This was one of the key announcements made at the Singapore Data Festival organised by the Infocomm Media Development Authority (IMDA) on July 20.
Digital Minister Josephine Teo noted that the event, formerly the Personal Data Protection Week, has broadened its focus to "bigger questions about data, especially how to support [businesses'] AI efforts."
The announcements were framed around two pillars of Singapore's approach to trusted data governance, which were accountability and capability building, as highlighted by Minister Teo.
This meant clarifying responsibilities and obligations across the data and AI lifecycle, while equipping organisations with the skills and practical tools to harness data and AI.
Organisations need to specify personal data use for GenAI
The Personal Data Protection Commission (PDPC), the authority behind the updated GenAI guidelines, has structured its recommendations around the typical stages of the GenAI lifecycle.
These stages include the development of the GenAI model (e.g. how to notify and obtain meaningful consent from consumers when it comes to using data for model training), deployment of the model (e.g. how to allocate data protection responsibilities across the AI lifecycle), as well as post-deployment (e.g. how to address consumer requests to access or correct personal data).
Currently, the guidelines remain advisory in nature, but organisations are highly encouraged by PDPC to adopt them.
According to the official statement, the guidelines took feedback from 40 global and local organisations in a public consultation which ended on July 1.
These organisations included Google, Meta, DBS, Singapore Airlines, Workday, National University Hospital System (NUHS) and more.
The respondents recommended including more examples of digital barriers to help organisations assess whether data qualifies as publicly available, and expand the categories of information that Model and System Providers can share with downstream stakeholders.
Single chatbot info card for consumers
IMDA also published new voluntary transparency guidelines for GenAI chatbots, describing them as "amongst the first of its kind in the world."
The guidelines aimed to standardise how chatbot information was shared with consumers, addressing a key concern that consumers may not fully understand a chatbot's limitations, and that relevant information was often hard to find or understand.
The main output of these guidelines was a chatbot info card, presented in plain language and clearly positioned for consumers.
Likened by IMDA to a nutrition label or medicine label, the card consolidates the key information in one place.
This information included what the chatbot could do, what it shouldn't be used for, data protection practices, and how consumers could give feedback or report concerns.
Singapore public sector "will also lead by example," said the IMDA, with the National Library Board (NLB), Health Promotion Board (HPB) and Land Transport Authority (LTA) planning to reference the guidelines for their own public-facing chatbots.
Beyond government, major AI deployers such as Google's Gemini app, DBS, OCBC and Singapore Airlines were also looking to the guidelines to strengthen transparency practices for their chatbots.
Privacy enhancing tech to unlock data sharing for AI
The PDPC also launched a new guide on federated learning and updated its guide on synthetic data generation (SDG), aimed at helping organisations understand, adopt and leverage personal data sharing for business value.
The former helps organisations understand, assess needs and kickstart the adoption of federated learning. The latter guide expands new ways for businesses to generate synthetic data, drawing on practical case studies from organisations that have already done so.
Federated learning and SDG both fall under privacy-enhancing technologies (PETs), which allow organisations to make full use of data without compromising privacy.
Federated learning enables organisations to collaboratively train AI models while keeping data stored locally, whereas SDG creates artificial datasets that mirror the statistical properties of real data without containing any personal information.
IMDA highlighted that the technical guides were developed tapping on insights from its PET sandboxes.
To date, 11 organisations from various sectors like healthcare, finance, construction, transport, and advertising tech have implemented PETs within the sandboxes.
For example, Singapore General Hospital (SGH) joined the sandbox to leverage PETs to enable secure processing of sensitive data when shared in the cloud. More information about other cases for PETs within IMDA's sandboxes is available here.
The technical guides would enable more organisations to leverage practical PET tools to test and implement their own use cases within the sandboxes.
Mainstreaming digital twin tech in selected sectors
IMDA has also launched its first digital twin for enterprises playbook, aimed at helping non-ICT enterprises adopt digital twin technology.
Digital twin is a live, data-driven digital replica of a physical asset, system, or process that stays in sync with real-world operations.
By integrating AI and data into a single, dynamic view, organisations could proactively monitor operations and anticipate what could go around.
According to the official statement, the playbook would be particularly useful for the manufacturing, built environment, and logistics and supply chain sectors, where capital investment and disruption risks can be significant.
The playbook is intended as a practical guide to help organisations identify the right use cases, assess their data readiness, and establish safeguards.
IMDA highlighted that while developing the playbook, it engaged early industry adopters to draw from their real-world deployment experiences in the local business context.
At the event, PDPC also established two agreements, respectively with Japan's Personal information Protection Commission (PPC) focusing on trusted cross-border data flows for businesses, as well as with the International Association of Privacy Professionals (IAPP) to co-develop AI governance training programmes.
-1783304403050.jpg)