What happened
On July 20, 2026, Singapore’s Personal Data Protection Commission released its finalized Advisory Guidelines on the Use of Personal Data in Generative AI. The guidance clarifies the Publicly Available Exception for web‑scraping and requires AI‑specific notifications when seeking consent to train AI models. It is part of broader APAC regulator efforts to address agentic AI and biometric data challenges.
Why it matters for trust and compliance
- Its status is published. It is enacted but may not be in force yet. Check the effective date before planning around it.
- The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore.
- It relates to EU AI Act. The regulations library explains what that law requires.
Who is affected
technology controller processor
Recommended actions
- Check that privacy notices describe the practices this addresses.
- Review the transfer mechanisms relied on for affected data flows.
- Map the security requirements to existing controls and close gaps.
- Check breach-notification procedures and timelines against the requirement.
- Inventory AI or automated decision systems in scope and their assessments.
- Confirm handling of sensitive data categories meets the stricter rules.