Singapore Guidance Guidance Non-binding

PDPC AI advisory guidelines: requirements, deadlines and compliance actions

PDPC Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems

What is the PDPC AI advisory guidelines?

These advisory guidelines explain how the Personal Data Protection Act applies when organisations use personal data to develop, test and deploy AI systems that make recommendations, predictions or decisions. They clarify the consent obligation and relevant exceptions (business improvement and research), what to include in notifications to individuals, accountability practices such as documenting data provenance and model development, and expectations for service providers building bespoke AI systems.

Who does it apply to?

Organisations subject to the PDPA that use personal data in AI recommendation and decision systems, and service providers developing such systems for them. Advisory; not legally binding, but reflects how the PDPC interprets binding PDPA obligations.

PDPA-regulated organisations and their AI service providers.

When do the requirements apply?

Issued 1 March 2024 following a 2023 public consultation.

What must organisations do?

Identify the legal basis for using personal data in AI (consent or an exception), provide notification about the AI's use of personal data, and document data-protection and governance practices across the AI lifecycle.

Legal requirement Identify consent or an applicable PDPA exception before using personal data in AI Advisory guidelines, sections on consent, business improvement and research exceptions

Personal data used to train or operate AI systems requires consent unless an exception applies, such as the business improvement exception for improving products and services or the research exception for developing models, each subject to conditions.

Practical action: Map AI data uses to consent or a specific exception and record the conditions met.

Evidence examples: Legal basis assessment for AI personal data

Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on data for AI systems

Obligation page Source-linked

Legal requirement Notify individuals about the use of personal data in AI recommendations and decisions Advisory guidelines, section on notification obligation

Organisations should inform individuals that AI systems use their personal data, the purposes, the relevant features and how they influence decisions, proportionate to the impact on the individual.

Practical action: Add AI-specific disclosures to privacy notices and in-product notifications.

Evidence examples: AI notification wording

Framework mapping (original, editorial): NIST AI RMF 1.0 GOVERN 4.x

Obligation page Source-linked

Penalties

Underlying PDPA breaches can attract financial penalties up to 10 % of annual turnover in Singapore or SGD 1 million, whichever is higher.

Official sources

  1. Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems
    Personal Data Protection Commission Singapore · 1 Mar 2024 · Tier 2 source

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.