Singapore launches AI training data guidelines, expands PETs resources

Singapore's digital regulators rolled out a range of fresh AI and data protection resources, with officials outlining the rollouts at the IAPP Asia Forum 2026.

Contributors:
Lexie White
Staff Writer
IAPP
Singapore's Personal Data Protection Commission released its Advisory Guidelines on the Use of Personal Data in Generative AI, detailing transparency and risk management obligations associated with artificial intelligence system development.
The PDPC's guidance covered key data protection questions while clarifying best practices for an organization's use of personal data throughout the "generative AI lifecycle." It launched alongside a compendium of new resources, including PDPC's Federated Learning Guide and Singapore's Infocomm Media Development Authority's new use cases for its Privacy-Enhancing Technologies Sandbox.
The rollouts highlight Singapore's efforts to promote responsible AI innovation and bolster data protection compliance with the Personal Data Protection Act.
Additionally, the IAPP and IMDA announced a memorandum of intent 22 July to strengthen its partnership on AI, data protection and digital responsibility while advancing professional development opportunities.
During a keynote speech at the IAPP Asia Forum 2026, PDPC Commissioner Denise Wong said the authority's guidance looks to improve accountability and security, noting, "regulators do not have all the answers. But we believe regulating well means providing clarity. This enables society to adopt technology with confidence."
PDPC AI initiatives
The advisory guidelines are broken down into how companies should treat training data in the development, deployment and post-deployment stages of building AI. In the deployment stage, the guide outlines the specific requirements left to model providers, system providers and system deployers, respectively.
While noting companies must ensure they are compliant with the PDPA, Wong said there must also be focus on organizational standards to operationalize compliance and developing internal best practices.
"Even as you embrace new technology to grow your business, and please do, you should also apply that innovation mindset to governance and trust," Wong said.
The PDPA's Publicly Available Exception allows organizations to process accessible personal data without consent when using web-scraping processes to train AI models. The guidance states for data to be considered publicly accessible under the exception, there must be no restrictions or "digital barriers" during collection.
The PDPC held a public consultation to support the guide, receiving feedback from 40 organizations. The organizations raised concerns about the practical challenges with the guideline's web-scraping exception, noting "organizations could use the opportunity of being notified to impose additional restrictions on data access, which would undermine reliance on the Publicly Available Exception."
The PDPC's response to feedback stated it would require companies using the exception to clarify the purpose of collecting publicly available data and its steps to mitigate the potential risks.
Under the guidelines, companies must receive consent from consumers when collecting and processing personal data that is not considered accessible.
The PDPC clarified that companies must also obtain additional consent from consumers if they are processing personal data for a different purpose than originally intended, even if they previously received consent.
Wong indicated consumer trust and transparency is a key priority within Singapore's digital economy strategy.
"Change is all around us. But to the public, it can create uncertainty and anxiety," she said. "So, in today's context, trust is no longer optional. Society will reject innovation it doesn't trust. If innovation is the building, then trust is the foundation, and all of us here are architects."
Singapore Minister for Digital Development and Information Josephine Teo said the authority remains focused on "harnessing AI for public good, while ensuring it is developed and deployed responsibly."
In light of AI's increasing societal threats, the Singapore Cyber Security Agency also contributed to the AI rollouts with revisions to its Cybersecurity Code of Practice for Critical Information Infrastructure that address developments stemming from advanced persistent threats and AI-enabled harms.
Each release plays into Singapore's National AI Strategy and broader efforts to become a hub for AI innovation and data protection.
"Ultimately, no playbook or guideline succeeds on its own — it takes governments and enterprises working together to uphold trust through strong data protection," Teo said. "As Singapore assumes the Association of Southeast Asian Nations Chairmanship next year, we will work with regional partners to align our approaches, build trusted data flows, and grow our digital economies together."
Wong said as the digital economy accelerates, the PDPC's job "hasn’t gotten smaller," noting instead, the data ecosystem "just gets bigger."
"Technology is developing at a pace that stretches our laws, our institutions — even our imagination," she added.
IMDA's PET sandbox
The PDPC's new Federated Learning Guide details how the decentralized technique can enable AI development without requiring organizations to share sensitive data.
"By keeping input data local and sharing only model updates, (federated learning) allows organisations to collaborate securely, unlock the value of diverse datasets, and produce better AI models," the guide states.
The IMDA simultaneously added new use cases for its ongoing PET sandbox. The sandbox allows organizations in a variety of sectors to test and implement PETs. The IMDA announced its new use cases focus on protecting sensitive health data, as well as payment processing systems and financial data.
“As AI systems become more autonomous and increasingly connected to sensitive data, internal systems and critical business processes, the risks are heightened," IMDA CEO Ng Cher Pong said during the Singapore Data Festival 2026. "In this environment, the role of Privacy Enhancing Technologies, or PETs, will become increasingly important. They are not simply a niche set of technologies but are becoming essential infrastructure for trusted and responsible data use."

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Lexie White
Staff Writer
IAPP
Tags:


