Singapore's Personal Data Protection Commission and the Infocomm Media Development Authority issued guidelines for using personal data in generative AI [1].
These rules establish a framework for businesses to integrate AI while maintaining legal compliance and public trust. As companies increasingly deploy chatbots and large-scale models, the guidelines prevent the unregulated use of private information in training and deployment phases.
The proposed guidelines were released June 2, 2026 [2]. They specifically target the boundaries of how personal data is ingested by generative AI systems to ensure that companies adhere to the Personal Data Protection Act (PDPA) [1].
Under the new framework, businesses must implement strict safeguards and obtain necessary consent before processing personal data through AI models [1]. The measures are designed to help organizations adopt generative AI responsibly while protecting the privacy of individuals [3].
The announcement took place during the Singapore Data Festival [4]. The initiative seeks to balance the rapid pace of technological innovation with the need for rigorous data protection standards [3].
By setting these boundaries, the PDPC and IMDA aim to provide clarity for developers and enterprises. The guidelines serve as a roadmap for maintaining data integrity in an era where AI can synthesize and potentially expose sensitive personal information [1].
“Singapore's PDPC and IMDA issued guidelines for using personal data in generative AI.”
This regulatory move signals Singapore's intent to remain a global AI hub by providing legal certainty rather than restrictive bans. By aligning generative AI use with existing PDPA laws, the government is shifting the burden of risk management onto the corporations, ensuring that innovation does not come at the expense of citizen privacy.



