STA - PDPA and AI

PDPA and AI

What Changes When Your Systems Learn From Personal Data ?

The PDPA does not have a separate “AI law,” and that is precisely the point

Singapore has not enacted a standalone AI statute analogous to the EU AI Act. Instead, the Personal Data Protection Commission (PDPC) has confirmed that the existing Personal Data Protection Act 2012 (PDPA) already governs the collection and use of personal data wherever it occurs, including inside AI systems, and has issued guidance clarifying how existing obligations apply in that context. The PDPC’s Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, issued 1 March 2024, state this directly: the PDPA is broad-based legislation that applies to an organisation’s collection and use of personal data to develop, test, monitor, and deploy AI systems (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). For a CIO or general counsel, the practical consequence is that adopting AI does not create a new compliance regime to learn from scratch; it requires re-applying familiar PDPA obligations, consent, notification, accountability, and protection, to a technology that processes data differently from the systems those obligations were originally written for.
The Guidelines define “AI Systems” as systems embedding machine learning models that are typically used to make autonomous decisions or to assist a human decision-maker through recommendations and predictions (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). They are advisory rather than legally binding, and expressly do not modify the PDPA itself; the statute and subsidiary legislation prevail wherever there is any inconsistency (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). That does not make them optional reading; they are the clearest signal of how the PDPC will interpret existing obligations when it examines an AI deployment.

Three stages, three different data problems

The Guidelines usefully break down AI system implementation into three stages, each raising distinct PDPA questions (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems):

  • Development, testing, and monitoring: training and testing the model, and monitoring its performance post-deployment. Here the relevant topics are consent, the Business Improvement and Research exceptions to consent, data protection measures, and anonymisation.
  • Deployment: collecting and using personal data within a deployed AI system in business-to-consumer contexts. Here notification, consent, and accountability dominate.
  • Procurement: where a service provider develops a bespoke AI system using personal data already in an organisation’s possession, in a business-to-business context. The same notification, consent, and accountability questions apply, but responsibility must be clearly allocated between the organisation and the vendor.
    This staged framing matters because many organisations treat “AI governance” as a single deployment-time checklist. A compliance gap opened during training, for instance fine-tuning a model on customer data without an appropriate consent basis, cannot be closed retroactively just because the deployed product later provides good notices to end users.

Consent, exceptions, and the practical alternative to blanket opt-in

Organisations generally need consent to collect and use personal data in an AI system that produces recommendations, predictions, or decisions, unless deemed consent applies or a recognised exception is available (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). Two exceptions do much of the practical work here: the Business Improvement Exception and the Research Exception, both of which can support using existing personal data to develop or refine an AI system without seeking fresh consent for every use, subject to the exception’s specific conditions (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). Organisations may also rely on the Legitimate Interests Exception under section 13 of the PDPA in some circumstances, but the Guidelines specify that organisations relying on it must inform individuals that they are doing so (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). The practical governance lesson is that “we have a privacy policy” is not the same as having mapped, for each AI use case, which specific legal basis under the PDPA supports it, and whether that basis was actually satisfied at the point the data was collected rather than assumed after the fact.

Notification: proportionate, not exhaustive

The Notification Obligation under section 20 of the PDPA requires organisations to notify individuals of the purposes for which personal data will be collected, used, and disclosed, on or before collection, or before any new purpose not previously notified (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). Importantly, the Guidelines explicitly reject the idea that AI transparency requires exhaustive technical disclosure. Notifications “need not be overly technical or detailed” and should be proportionate to the risk of the use case, factoring in potential harm to the individual and the degree of autonomy the AI system exercises in producing an outcome (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). Organisations are encouraged, where practicable, to explain the product function requiring the data, the general types of data used, how that data relates to the feature, and which data attributes are most influential to the outcome (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). The Guidelines also expressly sanction layered disclosure, for example a short notice pointing to a fuller privacy policy, and mention model cards or system cards as an acceptable supporting mechanism where an organisation already uses them (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). Organisations may also withhold commercially sensitive details, provided the decision to do so is justified and documented internally rather than left as an undocumented judgement call (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems).

Accountability: the obligation that turns policy into audit evidence

The Accountability Obligation requires organisations to take responsibility for personal data under their control, and sections 11 and 12 of the PDPA require them to develop and document policies and practices that give effect to their PDPA obligations (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). For AI systems specifically, this means an organisation should be able to produce documentation showing internal governance and supervision over how personal data is used across the development, deployment, and procurement stages described above, not merely assert that governance exists (PDPC Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems). This is where PDPA compliance and AI management system evidence, of the kind expected under ISO/IEC 42001, begin to overlap in practice: an auditor asking for accountability evidence under the PDPA and an AIMS auditor asking for AI risk treatment evidence are often looking for the same underlying document trail.

No standalone right against automated decision-making, but consent still matters

One point that generates frequent confusion is worth stating precisely: unlike some other jurisdictions’ data protection regimes, the PDPA does not grant individuals a standalone right to object to solely automated decision-making or profiling (ICLG Data Protection Laws and Regulations 2026, Singapore chapter). However, individuals retain the ability to withdraw consent where they oppose automated decision-making or profiling being conducted on their data, which in practice constrains how organisations can rely on AI-driven personalisation once a user withdraws consent for the underlying data use (ICLG Data Protection Laws and Regulations 2026, Singapore chapter). Boards should not read the absence of an EU-style automated-decision-making right as an absence of obligation; the consent, notification, and accountability requirements described above still apply in full force to any AI system processing personal data, and a withdrawal of consent still has to be operationally honoured.

What this means for governance practice ?

Organisations deploying AI systems that touch personal data should treat the PDPC’s 2024 Guidelines as a practical audit checklist rather than background reading. At minimum, that means documenting the legal basis relied upon at each of the three implementation stages, drafting notification language that is proportionate to risk rather than either silent or overengineered, and keeping accountability records current enough that governance claims can be substantiated on request rather than reconstructed under pressure during a PDPC inquiry or an internal audit.

Leave a Comment

Your email address will not be published. Required fields are marked *