Singapore is moving to make companies tell you when your personal data trains a generative AI system. A vague line about improving services won't be enough.
The real target here is not AI itself. It is the privacy notice you never read, the one that lets a company collect your name, voice recording, transaction history or location data, then later fold it into model training under language broad enough to mean almost anything.
Singapore's Personal Data Protection Commission is now trying to close that gap. As The Business Times reported on July 13, the PDPC's proposed advisory guidelines say organisations using personal data to train generative AI models should give affected users AI-specific notifications instead of relying on broad privacy wording about uses such as "new product development." That's the right fight. If your data is helping build a model, you should be told that directly.
What the notice has to say
The proposed guidelines were put out for public consultation, which closed on July 1. They ask companies to explain what the generative AI model does, what categories of personal data it takes in, how that data is used for training or fine-tuning, and how you can opt out or withdraw consent. Names, e-mail addresses, video and voice recordings, transaction history and location data are all examples PDPC identified in the consultation material.
That is not a small drafting change. It means a bank, an insurer, a retailer, even a social media platform - none of them can hide a generative AI training purpose inside a general privacy clause and call the job done. If a company is building a text-to-speech feature using customers' voice recordings, the notice has to say the recordings are being used to train the model and explain why the model needs them.
Plain enough.
The PDPC is also pointing companies toward notices people might actually see: an in-product pop-up or a dedicated webpage linked clearly at the right moment. That detail matters because disclosure has become a performance in too many digital products. A company can technically disclose something while making sure no ordinary customer ever understands it. Singapore is saying that distinction counts.
Why advisory guidance still bites
These are proposed advisory guidelines, not a new statute passed overnight. You should still treat them seriously. In Singapore, PDPC guidance often sets the practical standard for how the existing Personal Data Protection Act is read in complaints, investigations and compliance reviews. A company that waves it away because the word "advisory" appears in the title is playing a silly game.
The timing also tells you something. Singapore is holding its first Singapore Data Festival from July 20 to July 24 at the Sands Expo and Convention Centre at Marina Bay Sands, with organisers expecting more than 2,000 attendees - from data and AI professionals to policymakers and business leaders. The festival replaces the older Personal Data Protection Week, according to event material from the Data Protection Excellence Network. That rebrand is not subtle. Privacy is no longer being treated as a back-office compliance topic. It is being tied directly to AI adoption and data use.
Josephine Teo, Singapore's Minister for Digital Development and Information, has been pushing that theme for more than a year. At Personal Data Protection Week in 2025, The Straits Times reported that she urged businesses to use privacy-enhancing technologies to unlock more data for AI responsibly. The new generative AI guidance is the harder half of the same argument: if companies want more data, they owe people a clearer explanation of what they are doing with it.
The global comparison is the point
Other regulators are circling the same issue. The EU's AI Act has transparency rules taking effect on August 2, 2026, including duties to tell users when they are interacting with AI systems and to mark AI-generated or manipulated content. Brussels is focused heavily on system transparency and synthetic content. Singapore's proposal is narrower, but in one respect sharper: it goes straight at personal data used to train generative AI.
Frankly, that is where the trust problem lives. People don't only worry that a chatbot exists. They worry that the chatbot learned from their records, their voice, their purchases, their location trail, or some other piece of life they handed over for a completely different reason.
The proposal doesn't ban model training. It doesn't stop companies from building generative AI tools on customer data. It asks them to say what they are doing before they do it, in language attached to the AI use itself. That is a modest demand, but it forces real work: consent flows, product screens, privacy pages and withdrawal processes all have to line up with the actual model development practice.
The PDPC has not said when the guidelines will be finalised after the July 1 consultation close. For now, the message is clear enough for any company operating in Singapore. If your customer data is going into a generative AI model, don't bury that fact. Tell your customer.
Also read: TSMC Doubles Down on Arizona as It Sees Years of AI Chip Demand Ahead • Moonshot Quietly Fixed Real Security Bugs In Kimi K3's Coding Tool • Indian AI startup Emergent hits $1.5 billion valuation a year after launching