by Dean
Share
Share

On 20 July 2026, Singapore’s Personal Data Protection Commission (PDPC) published its final Advisory Guidelines on the Use of Personal Data in Generative AI at the Singapore Data Festival. The Guidelines follow a public consultation launched on 2 June 2026 and closed on 1 July 2026. They mark the clearest statement yet of how the Personal Data Protection Act (PDPA) applies to organisations that build, fine-tune, or deploy generative AI (GenAI) systems.
For financial institutions, fund managers, and corporate service providers increasingly experimenting with GenAI for research, document review, client communications, or internal compliance monitoring, the Guidelines are not optional reading.
They set out the PDPC’s expectations for how personal data should be handled at every stage of the AI lifecycle — from training data sourcing through to production use.
📌
Key Takeaways for Singapore Businesses
- Full Supply Chain Accountability: Liabilities cannot be contracted away when using third-party GenAI vendors or models.
- Legal Basis Mandate: Clear legal grounds under the PDPA are required for training, fine-tuning, or prompting models.
- Active Risk Mitigation: Operational controls must target AI hallucinations and training data bias.
- Transparent Disclosure: Privacy notices must explicitly inform individuals about AI-assisted personal data processing.
Background — From Draft to Final Guidelines
The PDPC first issued proposed Advisory Guidelines on Use of Personal Data in Generative AI on 2 June 2026, opening a month-long public consultation that closed on 1 July 2026. After considering industry feedback, the PDPC published the finalised Guidelines on 20 July 2026. The core structure of the draft has carried through to the final version, with refinements to reflect feedback on practical implementation, particularly around vendor accountability and risk assessment documentation.
Regulatory Roadmap & Key Milestones
PDPC issued proposed draft Advisory Guidelines and launched a public consultation.
Public consultation period closed following industry feedback.
Final Advisory Guidelines officially published at the Singapore Data Festival.
What the Final Guidelines Cover
The Guidelines are organised around four themes that organisations should treat as a compliance checklist:
📌
Accountability Across the AI Supply Chain
Where an organisation uses a third-party GenAI vendor or foundation model provider, it remains accountable under the PDPA for how personal data is handled — accountability cannot be contracted away simply because the model itself was built by someone else.
📌
Appropriate Legal Bases for Training & Use
Organisations must be able to point to a valid legal basis under the PDPA — such as consent, or a permitted exception — for using personal data to train, fine-tune, or otherwise feed into a GenAI model.
⚠️
Risk Mitigation for GenAI Outputs
The Guidelines address risks that are specific to generative systems, including hallucinated personal data (where a model fabricates plausible-sounding but false information about an individual) and outputs that reflect bias embedded in training data.
💡
Transparency Towards Individuals
Where personal data is used in connection with GenAI — whether as training input or in generating output that concerns an individual — organisations should be transparent with affected individuals about that use, consistent with existing PDPA notification obligations.
Practical Implications for Financial Institutions and Fund Managers
Singapore’s financial services sector has been an early adopter of GenAI tools for tasks such as drafting client correspondence, summarising research, screening documents during onboarding, and supporting compliance monitoring. Each of these use cases can involve personal data — client names, identification details, transaction histories, or KYC documentation — flowing into a GenAI system, whether hosted internally or through a third-party vendor.
Under the finalised Guidelines, firms using GenAI in these contexts should be able to demonstrate:
4 Compliance Pillars Firms Must Demonstrate
✅
✅
✅
✅
Steps to Take Now
Organisations already using or piloting GenAI tools should treat the finalised Guidelines as a prompt to review their current practices rather than wait for enforcement activity. Practical first steps include:
✅
Action Plan: Immediate Step-by-Step Implementation
- 1. Data Inflow Mapping: Map every point where personal data enters a GenAI workflow — including third-party tools staff may already be using informally.
- 2. Legal Groundwork: Confirm the PDPA legal basis for each identified data flow, and document it.
- 3. Vendor Contract Audits: Review vendor contracts for GenAI tools to confirm data handling, security, and sub-processing terms.
- 4. Pre-Deployment Risk Assessments: Build a lightweight risk assessment process for new GenAI use cases before they go live, covering hallucination and bias risk.
- 5. Policy Updates: Update your PDPA data protection policy and privacy notices to reflect GenAI use where relevant.
How This Fits with the Broader PDPA Framework
The Guidelines do not create a new legal regime — they sit within the existing PDPA framework and clarify how established obligations (consent, purpose limitation, protection, and notification) apply specifically to generative AI. Organisations that already maintain a mature PDPA compliance programme, including an appointed Data Protection Officer and a data inventory, are well placed to extend that framework to cover AI use cases rather than build a separate one from scratch.
💡
Conclusion
With the Advisory Guidelines on Generative AI now finalised, Singapore businesses have clear, if principles-based, expectations to work against. For financial institutions in particular, where personal data volumes are high and regulatory scrutiny is already elevated, aligning GenAI use with these Guidelines should be treated as part of the core PDPA compliance programme, not a side project.
Alder helps Singapore-regulated financial institutions and corporate entities build and maintain PDPA-compliant data protection frameworks, including governance for AI and GenAI use cases.
Need Assistance with AI Governance & PDPA Compliance?
Ensure your organisation aligns with the PDPC’s finalised generative AI guidelines. Alder assists financial institutions and corporate entities in reviewing AI risk posture, updating policies, and executing vendor assessments.
This article is for general information only and does not constitute legal or regulatory advice. Contact Alder for advice specific to your circumstances.
If your organisation’s current data incident response plan was drafted more than a couple of years ago, you are likely exposing your business to severe regulatory penalties. Operating under the outdated assumption that a data breach will not impact your firm is an immediate risk to your corporate continuity under current enforcement rules. Under the
Alder Corporate Services can help your Singapore business comply with PDPA regulations. Our outsourced DPO services ensure proper NRIC authentication procedures before 2027 enforcement.
Most MCSTs assume data protection issues only arise when there is a complaint. In reality, many breaches happen quietly. Weak passwords, unsecured systems, or unclear responsibilities between managing agents and vendors. By the time something goes wrong, it is often too late.
When a resident asks for CCTV footage, it rarely comes with a manual. Do you check with the managing agent? Security? The council? PDPA expectations are clear, but day-to-day handling often isn’t.





