Key takeaways
- From 20 July 2026, Singapore businesses must specifically tell customers if their personal data is used to train or fine-tune an AI system — a general “we may use your data” line is no longer enough.
- For most small businesses, this means adding one clear paragraph to an existing privacy policy — not building new software.
- No opt-out button is required by law, and you can’t refuse service to someone who declines. The rule is about telling people, not gatekeeping them.
- If your data is fully anonymised before any AI feature touches it, you’re exempt.
If you run a small business in Singapore — a salon, a café, a trading company, a home bakery with a proper website — this new rule from the Personal Data Protection Commission (PDPC) probably sounds like something meant for bigger tech companies. It isn’t. If your website has a chatbot, your invoicing software suggests products, or your CRM has an “AI insights” toggle you switched on last year, this rule likely applies to you too. The good news: for most small operations, fixing it costs nothing and takes an afternoon, not a law firm retainer.
What actually changed on 20 July 2026
PDPC finalised advisory guidelines requiring any organisation that uses personal data to train a generative AI model to give customers a specific notice about it — separate from a vague catch-all clause buried in a privacy policy nobody reads. The requirement isn’t new in spirit; PDPA has always required businesses to state their purposes for collecting data. What’s new is that “AI training” now has to be named as its own purpose, not folded into generic wording like “to improve our services.”
Do I actually need to do anything? (2-minute check)
- Does your website, POS, or booking system have a chatbot, product recommendations, or an “AI” feature switched on?
- Does that feature use real customer names, phone numbers, emails, or purchase history — not just anonymous numbers?
- Do you currently have no mention of AI anywhere in your privacy policy?
If you answered yes to all three, keep reading — this applies to you. If your site has no AI features at all, you likely don’t need to change anything yet.
The checklist: what to actually do
Compliance in five steps
- List every tool touching customer data that has any “smart,” “AI,” or “recommendation” feature — website chatbot, WhatsApp bot, POS system, email marketing tool, invoicing software.
- For each one, check (or email the vendor to ask) whether it trains on your customers’ personal data specifically, or just runs fixed rules.
- Write one plain sentence per feature: what data it uses and why. Example: “Our website chatbot uses your name and message history to answer questions and improve future responses.”
- Add those sentences as a clear section in your privacy policy page — most small business sites already have one in the footer.
- Keep a simple record of this review (a dated note or spreadsheet is fine) in case you’re ever asked how you assessed it.
What’s genuinely optional — don’t overbuild this
| You might assume you need… | What’s actually required |
|---|---|
| A pop-up or cookie-style banner | No — a privacy policy update is enough for most small sites |
| An opt-out toggle for customers | No — not legally required under the finalised guidelines |
| A lawyer-drafted standalone AI policy | No — a well-written paragraph, done accurately, is sufficient for typical SME use cases |
| Refusing service to customers who object | Not allowed — you must still serve them |
We say this as a business that builds websites for a living, not as lawyers: the biggest compliance risk for small businesses isn’t under-building, it’s panicking and either doing nothing or overspending on something elaborate you didn’t need. No lawyer required for most cases No new software needed
If you’re already updating your site anyway
A fair number of SGWebbuilder clients are small businesses using the Productivity Solutions Grant (PSG) to fund a new or upgraded website. If that’s you, this is a good moment to fold a proper privacy policy and AI data notice into that same project — it’s a normal part of a compliant, professionally built site rather than an extra line item, and it’s one less thing to revisit later. Our own build process runs on Pay Only When Work Delivered, so you’re not paying upfront for a promise; the same applies whether you’re building fresh or just adding a compliance update to an existing site.
Frequently asked questions
Do small businesses really need to comply?
Yes, if any tool touching customer data uses it to train or fine-tune AI — regardless of your business size. A site with no AI features at all is unlikely to be affected.
What’s the cheapest way to comply?
One clear paragraph added to your existing privacy policy. No pop-up, no new software, no standalone legal document required for typical cases.
Do I need to let customers opt out?
No, it’s not mandatory, and you can’t refuse service to someone who says no anyway. You just need to tell them clearly.
My POS or invoicing software has AI features I didn’t build — am I responsible?
Generally yes, since it’s processing your customers’ data as part of your operations. A quick check with your vendor tells you what to write.
Can I get help paying for a compliant website update?
If you’re using PSG funding for a website or e-commerce project, a privacy policy and AI notice update usually fits naturally into that same scope.
Want this handled as part of your next website update?
SGWebbuilder — a brand of web design built by the team at 8Clicks Pte Ltd — builds and updates affordable, compliant small business websites in Singapore, PSG-friendly and paid only when the work is delivered.