Singapore requires consent for reuse of user data in GenAI development under new guidance-Xinhua

Singapore requires consent for reuse of user data in GenAI development under new guidance

Source: Xinhua

Editor: huaxia

2026-07-20 14:34:00

SINGAPORE, July 20 (Xinhua) -- Organizations in Singapore will need to obtain users' consent before using data originally provided for non-generative artificial intelligence (GenAI) purposes to develop GenAI models, under new guidance released on Monday.

The guidance on the use of personal data in GenAI models and systems requires organizations to provide users with "AI-Specific Notifications" explaining the purpose of use, the data that will be used, how it will be used, and how individuals can decline or withdraw consent.

Released by Singapore's Personal Data Protection Commission (PDPC), with support from the Infocomm Media Development Authority, the guidance clarifies how the Personal Data Protection Act applies throughout the GenAI lifecycle, including model development, deployment and post-deployment handling of data requests.

Under the act, organizations may collect data without consent when developing GenAI models if it falls under the "publicly available" exception, which covers publicly accessible online sources.

However, data behind digital barriers, such as paywalls or registration requirements, may not qualify as publicly available and should be assessed carefully, the guidance said.

Individuals also retain the right to request access to and correction of their personal data after it has been used in GenAI development.

The PDPC acknowledged that fulfilling such requests could pose challenges, given the vast amounts of data used to train GenAI models and the fact that training data may not be stored in a traditional repository. It encouraged organizations to adopt best practices such as reviewing requests on a case-by-case basis and tracking and adopting appropriate technical measures.

The guidance said model providers, system providers and system deployers each have distinct responsibilities in protecting personal data, with deployers bearing primary responsibility for compliance.

The guidelines incorporate feedback from a public consultation that ended on July 1, which received responses from 40 organizations.