Regulation / Jul 20, 2026 / 4 min
Your Call May Train the Model Now
On July 20, Singapore's PDPC made AI-specific training notifications mandatory under its Personal Data Protection Act and IMDA launched voluntary chatbot "nutrition labels" — a transparency push that tells users when their data trains models but does not require a standard opt-out.
Singapore just drew a line through "product development" as cover for AI training — and mailed chatbots a prescription pad. On July 20, the Personal Data Protection Commission released advisory guidelines clarifying that organisations must issue AI-specific notifications when personal data trains generative models, while IMDA launched voluntary chatbot "nutrition labels" — transparency that informs users without always giving them a veto.
What's new:
- PDPC released advisory guidelines on personal data in GenAI systems at the inaugural Singapore Data Festival, effective July 20.
- Organisations must flag GenAI training use explicitly — broad privacy language like "personalisation" or "product development" no longer suffices, IMDA said.
- IMDA published voluntary Transparency Guidelines for GenAI Chatbots recommending "chatbot information cards" in plain language.
- A one-month public consultation closed July 1 with responses from 40 organisations, including Google, Meta, WeChat, DBS, Singapore Airlines, Workday, Prudential, HSBC, and Epic Systems.
The call-center test:
- Minister Josephine Teo used a customer-service example: call recordings already collected for "quality checks" contain names, addresses, and billing details.
- Before that audio trains a GenAI model, the company must tell customers plainly — not bury the purpose in a generic privacy policy.
- Staff consent scripts and privacy policies need updating, Teo said.
What the label covers:
- IMDA's infocards should answer what a chatbot can and cannot do, how reliable and safe it is, how data is handled, and how to report problems.
- Teo compared the format to a medicine label: "What the 'medicine' is for, how to take it, what side effects to watch out for, when not to use it."
- IMDA called infocards "like a nutrition label or medicine label" — a single consolidated disclosure page.
- Teo said the framework starts voluntary: "We are starting with a voluntary framework and will refine it with industry inputs as practices mature."
Who's signing on:
- Public-sector agencies including the National Library Board and Health Promotion Board plan to adopt infocards.
- DBS, Google, Meta, OCBC, Singapore Airlines, and Synapxe committed to referencing the guidelines over the next six to 12 months.
- Teo said Google will consolidate key Gemini information; Meta will clarify disclosures for AI-powered products.
The gap enterprises should price:
- AI-specific notifications are mandatory, but PDPC did not prescribe notice format or placement — pop-ups, webpages, or disclosure documents all qualify.
- The guidelines do not make opt-out or consent-withdrawal channels mandatory, The Straits Times and Malay Mail reported — though PDPC recommends explaining how users can decline.
- Consumers may learn their data trains a model without a guaranteed way to stop it.
- Organisations cannot refuse service solely because a user declines AI training use, per guidelines cited by Malay Mail.
- Anonymised data beyond re-identification requires no notification.
Scraping and the value chain:
- Organisations may still scrape publicly accessible personal data under the PDPA's "publicly available" exception — but must assess whether paywalls or registration gates disqualify the data.
- Model providers must document safeguards and share them downstream; system deployers bear primary PDPA liability, especially for agentic applications.
- Individuals retain access and correction rights after data enters a training set — PDPC acknowledges this is difficult at GenAI scale and recommends upstream tracking and case-by-case review.
Why it matters beyond Singapore:
- The EU AI Act reaches full applicability August 2, 2026; Brussels is building evaluation capacity, not chatbot nutrition labels.
- Beijing's July 15 companion-AI law deleted virtual personas overnight — a different axis (emotional dependency, not training transparency).
- Washington's Gold Eagle clearinghouse gates frontier model access by partner list. Singapore is building disclosure without export-control theater.
- APAC enterprises already routing to Chinese open-weight models will face a second compliance layer: not whether the model is allowed, but whether customer data that trained it was disclosed.
Convina's view: Singapore chose readable rules over rigid forms — smart politics for a hub that wants AI investment without EU-style friction. The weakness is deliberate: mandatory training notices without mandatory opt-out channels give compliance teams a checkbox and users a pop-up they will not read. The medicine-label frame is the part that travels — expect DBS and Singapore Airlines to set the template multinationals copy across ASEAN before Brussels finishes its omnibus. If your privacy policy still says "product development," rewrite it before a regulator does it for you.