SINGAPORE, July 20 — Singapore consumers will soon get more information about how companies use their personal data to train generative artificial intelligence (AI) systems, but they may not always have the option to stop it.
From today, organisations in the republic using personal data to develop or improve generative AI models must inform users through AI-specific notifications under new guidelines issued by the Personal Data Protection Commission (PDPC), Singapore-based news outlet The Straits Times reported today.
According to the newspaper, the move aims to make companies more transparent about how they handle information such as names, contact details, photographs, voice recordings, biometric information, and financial or transaction records.
“As more organisations develop, adapt or deploy generative AI tool, we must address the question of accountability,” Minister for Digital Development and Information Josephine Teo was quoted as saying at the Singapore Data Festival.
The new notifications could appear as in-app pop-ups, webpages or other disclosure documents explaining the types of personal data used and how it is handled.
However, companies are not required to provide a standard format for these notices, and the guidelines do not make it mandatory for them to offer consumers a way to opt out or withdraw consent.
This means consumers may be informed that their data is being used for AI training, but may not always be able to stop it.
However, organisations such as banks, insurers and social media platforms cannot refuse to provide services simply because consumers do not agree to their data being used to train AI systems.
Companies also do not need to issue notifications when they use anonymised data that cannot be linked back to individuals.
Beyond data use, Singapore has also introduced voluntary guidelines encouraging AI chatbot providers to give users clearer information about their systems.
These include details on what chatbots can do, their limitations, reliability and safety measures.
The guidelines recommend companies provide a “chatbot information card” – similar to a medicine label – explaining what the AI tool is for, what it is not suitable for, how user data may be handled and how problems can be reported.
Teo said many users currently do not know what happens to information they enter into AI chatbots because details are often buried in privacy notices and terms of service.
Companies including Google, Meta, DBS, OCBC, Singapore Airlines and Synapxe are expected to roll out their own chatbot information cards over the next 12 months.
For consumers, the advice is simple: check what information an AI service collects before sharing personal details, especially when using chatbots for personal, financial or sensitive matters.