Singapore · PDPC
Singapore's PDPA and automated decisions
What the Personal Data Protection Act actually requires of an AI system, which is less than the GDPR-shaped assumption suggests, plus the obligation everyone lists that was never brought into force.
Covers: PDPA 2012 (Act 26 of 2012), Amendment Act 40 of 2020, PDPC AI guidelines 2024 and 2026Published September 26, 2026
There is no Article 22 analogue
If you are mapping an AI system against Singapore law with a GDPR checklist in hand, this is the first thing to correct. The PDPA grants individuals the right of access (section 21), the right of correction (section 22), and the right to withdraw consent (section 16). That is the set. There is no right not to be subject to a solely automated decision, no right to an explanation of how a decision was reached, and no right to demand that a human review it.
PDPC’s own advisory guidelines on AI recommendation and decision systems bear this out: they do not use the phrases “automated decision,” “human review,” or “Article 22” at all. Transparency in those guidelines is framed as notification, and they expressly allow an organisation to omit detail in order to protect proprietary information.
Data Portability is still not in force
The Personal Data Protection (Amendment) Act 2020, Act 40 of 2020, drafted a Data Portability Obligation as Part 6B, together with a new Twelfth Schedule. The Act commenced in two phases, on 1 February 2021 and 1 October 2022. The provisions that would have brought Part 6B and the Twelfth Schedule into operation appear in neither phase, and Part 6B is absent from the Act’s in-force contents today.
The reason this error is so widespread is that the scaffolding survives in the live text. Section 48J still refers to “any provision of Part 3, 4, 5, 6, 6A or 6B,” and the First Schedule still cites the Twelfth Schedule. The hooks are there; the Part behind them is not. Any list of eleven PDPA obligations that counts Data Portability as live is describing a law Singapore has not commenced.
The obligations that are actually in force
- Part 3, Accountability (sections 11 and 12).
- Part 4, Consent, Purpose Limitation, and Notification.
- Part 5, Access and Correction.
- Part 6, Accuracy (23), Protection (24), Retention Limitation (25), and Transfer Limitation (26).
- Part 6A, Data Breach Notification (sections 26A to 26E).
The Act is still correctly cited as the Personal Data Protection Act 2012, Act 26 of 2012, even after the 2020 amendments. One small housekeeping note: the chapter-number form “Cap. 26A” is obsolete, since the 2020 Revised Edition took effect on 31 December 2021 and dropped chapter numbers.
Legitimate Interests and Business Improvement
These two exceptions, added in 2020, are the ones an analytics or AI use case most often relies on, and both are commonly mislocated in summaries.
Legitimate Interests sits in the First Schedule, Part 3, not the Second. Paragraph 1 is a general balancing test: conduct an assessment before collecting, using, or disclosing; identify and mitigate any adverse effect on the individual; and provide reasonable access to information about the reliance. Paragraphs 2 to 10 set out named purposes, among them evaluative purposes, investigations, debt recovery, legal services, credit bureau reports, and employment. It cannot be used to send marketing messages.
Business Improvement is split across two Schedules, which is why it is easy to cite incorrectly: the First Schedule Part 5 covers corporations, including collection and disclosure between related corporations subject to a contract or binding corporate rules safeguard, while the Second Schedule covers use by organisations that are not corporations. Both require that the purpose could not reasonably be achieved without data in individually identifiable form, and that a reasonable person would consider the use appropriate.
PDPC's two AI advisory guidelines
There are two, and a page citing only the first is now incomplete.
- Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems, issued 1 March 2024. Expressly not legally binding. It creates no new obligations: it interprets existing ones, chiefly consent and notification at deployment under section 20, and Accountability under sections 11 and 12. Its own worked example is a bank using AI for credit scoring.
- Advisory Guidelines on the Use of Personal Data in Generative AI, issued 20 July 2026. The 2024 guidelines expressly exclude generative AI, and these fill that gap: the Publicly Available Exception as it applies to web-scraped training data, the roles of model provider, system provider, and system deployer, and how access and correction requests work against a model.
What the 2024 guidelines recommend disclosing, where an organisation relies on consent and notification, is the existence of the AI feature, the types of personal data used, why that data is relevant, and which features most influence the output. That is a notification standard, not an explanation right.
Four Singapore AI instruments people conflate
“Singapore AI regulation” is usually four different things from two different issuers, none of them binding law:
- PDPC's two advisory guidelines above: interpretive, expressly not legally binding.
- Model AI Governance Framework, second edition, PDPC with IMDA, January 2020: voluntary.
- Model AI Governance Framework for Generative AI, IMDA with the AI Verify Foundation, May 2024: voluntary.
- AI Verify: a voluntary testing toolkit built by IMDA and now under the AI Verify Foundation, covering eleven principles. It is a toolkit, not a certification, and passing it certifies nothing.
For financial institutions specifically, the sector layer is MAS’s FEAT principles from 2018, which are non-binding. MAS issued a consultation paper on proposed guidelines on AI risk management for financial institutions on 13 November 2025, and the consultation closed on 31 January 2026. Final guidelines have not been issued, so there is nothing final to comply with yet on that track.
Breach notification, and two common errors
A breach is notifiable under section 26B if it results in, or is likely to result in, significant harm to an individual, or if it is of significant scale. Two details get misreported constantly.
- The three-day clock runs from assessment, not discovery. Section 26D(1) requires notification to PDPC no later than three calendar days after the day the organisation makes its assessment. Section 26C separately requires that assessment to be made in a reasonable and expeditious manner, with no fixed day count of its own.
- The 500-individual threshold triggers notification to PDPC, not to individuals. It sits in the Notification of Data Breaches Regulations 2021 rather than in the Act. Individual notification is tied to the significant-harm limb only, so a large breach with no significant-harm element is reportable to the regulator and not to the people affected.
Significant harm is deemed where the data includes an individual's full name, alias, or identification number together with a listed category, and the listed categories are heavily financial: salary, card and bank account numbers, creditworthiness, net worth, deposits, loans, insurance, and capital markets holdings. An account identifier together with its credential also qualifies. Purely internal unauthorised access is deemed not notifiable under section 26B(4).
Penalties after the 2020 amendment
Section 48J(3), in force since 1 October 2022, sets the ceiling on what may be prescribed as a maximum financial penalty: for an organisation whose annual turnover in Singapore exceeds S$10 million, up to 10 per cent of that turnover; in any other case, up to S$1 million. Do-not-call breaches are capped separately at S$200,000 for an individual and S$1 million otherwise.
Two points of precision. The statute is structured as a turnover threshold, not as a “whichever is higher” formula, which is how it is usually paraphrased. And section 48J(3) sets a ceiling on what may be prescribed, so the safest description is a statutory ceiling rather than a flat statement that the fine is ten per cent.
How Nova AIS lines up against it
The PDPA’s demands on an AI system are mostly about provenance and accountability rather than about explaining individual outputs, and provenance is an architectural property. Nova AIS puts a permission model and an immutable audit trail under the systems built on it, so which data was used, on whose authority, and for what purpose is answerable from the record. That is what the Accountability obligation and the Business Improvement conditions actually turn on.
Where a system is deployed for a Singapore-licensed financial institution, expect the sector layer rather than the PDPA to be the binding constraint on decision transparency, and watch the MAS AI risk management guidelines as they move from consultation to final.
Common questions.
- Does Singapore's PDPA give people a right not to be subject to automated decisions?
- No. There is no equivalent of GDPR Article 22 anywhere in the Act. The individual rights the PDPA grants are access (section 21), correction (section 22), and withdrawal of consent (section 16). There is no right against solely automated decision-making, no right to an explanation of a decision, and no right to demand human review. PDPC's own 2024 AI advisory guidelines do not use the phrases “automated decision,” “human review,” or “Article 22” at all.
- Is Data Portability part of the PDPA?
- It was drafted but never brought into force. The Personal Data Protection (Amendment) Act 2020 added Part 6B on data portability, but the provisions that would have commenced it are absent from both commencement lists, and Part 6B does not appear in the Act's in-force contents. Checklists listing eleven obligations with Data Portability among them are wrong. Cross-references to Part 6B and to the Twelfth Schedule do survive elsewhere in the Act, which is why the error is easy to make.
- Which schedule holds the Legitimate Interests exception?
- The First Schedule, Part 3, not the Second Schedule as many summaries state. Paragraph 1 is the general balancing test, which requires an assessment before collection, use, or disclosure, identification and mitigation of any adverse effect, and reasonable access to information about the reliance. Paragraphs 2 to 10 cover named purposes including evaluative purposes, investigations, debt recovery, legal services, credit bureau reports, and employment. It cannot be used to send marketing messages.
- When must a data breach be notified to PDPC?
- No later than three calendar days after the day the organisation makes its assessment, under section 26D(1). The clock runs from the assessment, not from discovery. Section 26C separately requires the assessment itself to be conducted in a reasonable and expeditious manner, with no fixed number of days attached.
- Does a breach affecting 500 or more people have to be reported to the individuals?
- Not on that basis alone. The 500 threshold, which sits in the Notification of Data Breaches Regulations rather than in the Act, triggers notification to PDPC on significant-scale grounds. Notification to affected individuals is required only where the breach is likely to result in significant harm. A large breach with no significant-harm element is reportable to the regulator but not to the individuals.
- What is the maximum financial penalty under the PDPA?
- Since 1 October 2022, section 48J(3) sets the ceiling on what may be prescribed: for an organisation whose annual turnover in Singapore exceeds S$10 million, up to 10 per cent of that turnover; in any other case, up to S$1 million. Note the structure is a turnover threshold rather than a “whichever is higher” formula, which is how it is often paraphrased. The older flat S$1 million figure is out of date for larger organisations.