A customer asks your website chatbot whether a servicing package includes a chemical wash, and gets a confident answer. Did it come from your price list or from the model’s best guess? The customer cannot tell, and in a sales conversation that uncertainty costs trust.

At the Singapore Data Festival in July 2026, IMDA launched Generative AI Chatbot Transparency Guidelines. They call for a Chatbot Information Card that sets out, in plain language, what the chatbot is for, what it is not for, how data may be handled and how users can report issues.

On 20 July, at the same festival, the Personal Data Protection Commission issued Advisory Guidelines on Use of Personal Data in Generative AI. Between them, the two documents bear on questions a small sales team will meet: what should customers be told, and can their conversations be reused to improve the bot?

At a glance

  • What: IMDA’s Generative AI Chatbot Transparency Guidelines, launched in July 2026.
  • Core idea: a Chatbot Information Card covering purpose, limits, data handling and how to report issues.
  • Status: voluntary at the outset, to be refined with industry input as practices mature.
  • Early support: companies including DBS, Google, Meta, OCBC and SIA have committed to use the guidelines as a reference.
  • Related guidance: PDPC’s Advisory Guidelines on Use of Personal Data in Generative AI, issued on 20 July 2026.
  • Next step: draft a card for your own chatbot, then check it against IMDA’s guidelines.

Why is a transparency card a sales tool?

Launching the guidelines, Minister Josephine Teo compared the card to the label on a medicine packet, which tells you what the product is for and when not to use it. She noted that users may not know a chatbot’s limitations or what happens to their data, information that is usually scattered across terms of service and privacy notices.

For a business, the card is also a sales discipline. Writing “what it is not for” forces a decision about where the chatbot must hand over to a person: firm quotes, complaints, refunds and anything else that commits the business. That boundary protects the customer, and the salesperson who would otherwise have to honour whatever the chatbot said.

Worked example: an aircon servicing firm drafts its card

Consider a fictional aircon servicing firm in Woodlands with nine technicians. Its website and messaging chatbot answers questions about servicing packages and collects requests for inspection slots. Using the four elements IMDA describes, its draft reads:

  • What this chatbot is for: explaining our servicing packages, checking whether we cover your area and taking a request for an inspection slot.
  • What it is not for: repair prices, fault diagnosis, warranty decisions or complaints. A member of staff confirms these, usually by phone.
  • How your data may be handled: we keep the conversation and your contact details to arrange the visit, as described in our privacy notice. We do not use conversations to train the chatbot.
  • How to report a problem: type “staff” at any point, or email our service desk. We read every report and reply within two working days.

The firm, its wording and its reply target are invented. Two details make the draft useful: it promises nothing the business cannot keep, and every limit names who takes over.

Before you reuse chat logs or call recordings

The data question usually arrives later, when someone suggests improving the chatbot with past conversations. The Minister’s speech used a similar case: a customer service team that wants to improve a generative AI model with call recordings containing names, addresses and billing details. She said PDPC’s guidelines make clear how organisations can meet the PDPA’s existing consent requirements, and that organisations should say plainly when personal data is used to develop or improve a generative AI model, for example in a privacy policy.

A short decision path before any reuse:

  1. Decide whether you need the conversations at all. Updating the chatbot’s approved answers may fix the problem.
  2. Check what your notices said when the data was collected, and read PDPC’s guidelines on what reuse requires.
  3. Update your privacy notice and the information card before any reuse begins.
  4. Remove names, phone numbers and addresses wherever the task does not need them.
  5. Ask your chatbot provider whether it uses your customers’ conversations to improve its own models, and on what terms.
  6. Record the decision and who approved it, and take legal advice if the position is unclear.

A monthly check for the chatbot’s owner

  • Read a sample of conversations against the card: did the chatbot stay within its stated purpose?
  • Compare any prices or package details it gave with your current price list.
  • Count hand-overs to staff, and how long customers waited for a person.
  • Close every reported issue, and note what changed as a result.
  • Update the card whenever the chatbot’s scope, data use or provider changes.

The habit that makes a useful sales follow-up work applies here too: answer the customer’s real uncertainty, and be clear about what is confirmed. If the chatbot will also book or change appointments on its own, it is acting for the business; see our checklist for AI agents.

Common questions

Are IMDA’s chatbot transparency guidelines mandatory?

IMDA introduced them as voluntary, to be refined with industry input as practices mature. They give a reference point for what to tell users, not a certification.

What goes on a Chatbot Information Card?

In plain language: what the chatbot is for, what it is not for, how data may be handled and how users can report issues.

Can we use customer chats to improve our chatbot?

PDPC’s July 2026 guidelines explain how the PDPA’s consent requirements apply when personal data is used to develop or improve generative AI models. Read them, and check your existing notices, before reusing conversations.

Who should own the card?

Someone who can change the chatbot’s scope and act on reports, usually the person responsible for customer enquiries. A card nobody maintains will drift away from what the chatbot actually does.

Sources

Something changed or worth adding?

Send a correction or suggestion