Key takeaways
- From 20 July 2026, Singapore’s PDPC requires businesses to give customers an AI-specific notice whenever personal data is used to train a generative AI model.
- This applies well beyond chatbots — it covers personalised email, ad targeting, lead-scoring and any marketing tool that trains or fine-tunes an AI model on your customer data.
- An opt-out mechanism is not legally required, and anonymised data is exempt, but the notice itself is mandatory.
- You’re responsible for disclosure even when the AI training happens inside a third-party platform like your ad network or CRM.
If you run marketing for a Singapore business, there’s a new compliance item that probably isn’t on your radar yet — and it sits squarely in marketing’s lap rather than legal’s. On 20 July 2026, Singapore’s Personal Data Protection Commission (PDPC) finalised advisory guidelines requiring organisations to tell customers, in an AI-specific way, when their personal data is being used to train generative AI models. Announced by Minister for Digital Development and Information Josephine Teo at the Singapore Data Festival, the rule closes a gap that a lot of marketing teams have been quietly operating in for the past two years.
Why this lands on marketing’s desk, not just legal’s
Data protection notices used to be something legal drafted once and marketing never thought about again. That doesn’t work anymore, because the AI training PDPC is worried about is often happening inside the marketing stack itself, not in some back-end data science project. Consider what a typical Singapore SME’s marketing setup is already doing with customer data:
- Predictive send-time and subject-line tools in email platforms that learn from your subscriber list’s open and click history.
- Lookalike and Advantage+/Performance Max style audiences on Meta and Google, which train on your customer and conversion data to find similar prospects.
- AI chat widgets or lead-qualification bots that store and learn from visitor conversations.
- Generative ad-copy or creative tools plugged into your CRM that use past customer interactions to generate new content.
Under the old approach, a generic line buried in a privacy policy about data being used for “new product development” or “service improvement” was treated as good enough. PDPC’s new guidelines say that’s no longer sufficient when generative AI training is involved — you need a notice that specifically calls out the AI use.
What actually has to change
The good news is that the bar is lower than most teams expect. PDPC has deliberately avoided being prescriptive about format. A compliant notice could be:
| Format | When it fits |
|---|---|
| In-app or on-site pop-up | Point of data collection, e.g. a signup or booking form feeding a personalisation engine |
| Dedicated “How we use AI” page | Linked from your footer and referenced from marketing emails and ads |
| Updated privacy policy clause | General coverage for CRM, ad platform and analytics use |
| Updated call script or IVR message | If call centre recordings are used to train an AI assistant, a script or policy update is enough — no separate pop-up needed |
What matters is specificity: telling a customer their photo, voice recording, purchase history or browsing behaviour will be used to train or run an AI feature, and roughly what that feature does for them.
The two things you don’t have to do (yet)
Two provisions from the earlier draft consultation were softened in the final guidelines, and they’re worth knowing because a lot of early commentary still assumes the stricter version:
- No mandatory opt-out. You don’t have to build an unsubscribe-from-AI-training flow, though offering one is good practice for trust-sensitive segments.
- No service refusal. Banks, insurers, retailers and social platforms cannot decline to serve a customer purely because they’ve indicated they don’t want their data used for AI training.
Anonymised or aggregated data is also exempt entirely — if your dataset genuinely can’t be traced back to an individual, this rule doesn’t apply to it.
A quick audit for your marketing stack
Before writing new notice copy, it’s worth mapping where AI training is actually happening in your funnel. Ask your team and vendors:
- Which ad platforms are using our uploaded customer/conversion lists to train targeting or lookalike models?
- Does our email or marketing automation tool use subscriber behaviour to train predictive features?
- Does our website chatbot or lead form feed a model that’s being trained or fine-tuned, rather than just running a fixed script?
- Are any of our CRM or loyalty datasets being used to build or license a separate AI product?
That last point matters more than it looks — PDPC’s guidance treats repurposing customer data to build a new, separately licensable AI product as a fresh purpose requiring its own notice, even if you already disclosed the original use.
Frequently asked questions
Do all businesses in Singapore need to issue an AI-specific notice now?
Yes. As of 20 July 2026, any organisation using personal data to train a generative AI model needs to give an AI-specific notice, per PDPC’s finalised advisory guidelines.
What exactly counts as an AI-specific notification?
A clear, specific statement of what data is used for AI training or operation and why — a pop-up, dedicated page, or privacy policy clause can all qualify, as long as it’s not generic boilerplate.
Do I need to let customers opt out of AI training?
No, an opt-out mechanism isn’t mandatory under the finalised rules, though it can support customer trust. You also can’t refuse someone service just because they decline.
Does this apply to anonymised marketing data?
No. Anonymised or aggregated data that can’t be tied to an individual is exempt from the AI-specific notice requirement.
What if my ad or CRM platform trains its own AI on my customer data?
You’re still responsible for telling your customers. It’s worth reviewing vendor contracts and reflecting that use in your own privacy notice, even when the training happens on a third-party platform.
Not sure what your martech stack is already doing with customer data?
Digitalix works with Singapore SMEs to map exactly where AI training happens across your email, ads and CRM tools, and to put plain-language, compliant disclosures in the right places — without slowing your campaigns down.







