Singapore's CSA issues updated cybersecurity code of practice for critical information infrastructure

Singapore's Personal Data Protection Commission has published final advisory guidelines on how the Personal Data Protection Act applies to the use of personal data in training and deploying Generative AI models, launched at the Singapore Data Festival on 20 July 2026. The guidance covers the full AI lifecycle: what counts as "publicly available" data organisations can scrape without consent (including where paywalls or registration barriers apply), when fresh, AI-specific consent is required for model training, and the differing PDPA responsibilities of model providers, system providers and system deployers once a model is in use.
The guidelines also address the post-deployment phase, setting out best practices for handling individuals' access and correction requests despite the technical challenges of locating personal data within trained models, from upstream data governance to output filters that limit inaccurate personal data appearing in results. Authored by Stephenson Harwood/Virtus Law, the piece frames Singapore as among the first jurisdictions globally to offer this kind of practical regulatory guidance on AI and personal data, ahead of the UK and EU.