facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Businesses and Users

L
Lunyb Security Team
··9 min read

Singapore has quietly become one of the world's most active jurisdictions for online safety legislation. Building on the Online Safety (Miscellaneous Amendments) Act that first took effect in 2023, the framework has expanded significantly heading into 2026, with new codes of practice, broader platform obligations, and stricter enforcement powers granted to the Infocomm Media Development Authority (IMDA). This complete guide explains what the Singapore Online Safety Act 2026 means for businesses, content creators, marketers, and everyday users.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 refers to the current, expanded version of Singapore's online safety regulatory framework, administered primarily by IMDA under amendments to the Broadcasting Act and the newer Online Criminal Harms Act (OCHA). Together, these laws give Singapore authorities the power to require online service providers to remove harmful content, block access to non-compliant platforms, and enforce user safety standards, particularly for children.

The framework is not a single statute but a layered system:

  • Broadcasting Act (as amended) — governs Online Communication Services (OCS) accessible to Singapore users.
  • Online Criminal Harms Act (OCHA) — enables direction orders against criminal content including scams and malicious cyber activity.
  • Code of Practice for Online Safety — binding rules for designated social media services.
  • 2026 expansions — new codes covering app stores, generative AI content, and enhanced child protection duties.

Who Must Comply?

The Act applies to any Online Communication Service that is accessible to end-users in Singapore, regardless of where the service is headquartered. This extraterritorial scope is one of the law's most important features for global platforms.

Designated Services

IMDA designates specific platforms as Regulated Online Communication Services (ROCS) based on user reach and risk. As of 2026, designated services include major social media platforms such as Facebook, Instagram, TikTok, X, YouTube, HardwareZone, and select messaging platforms with public channels. Designated services face the strictest obligations under the Code of Practice.

Non-Designated but In-Scope Services

Even if not formally designated, the following are still subject to takedown and access-blocking orders:

  • Websites and forums accessible in Singapore
  • App stores distributing apps to Singapore users
  • URL shorteners, link-in-bio tools, and redirect services
  • Cloud hosting and content delivery networks
  • Search engines indexing Singapore-accessible content

Categories of Harmful Content

The Act identifies specific categories of "egregious content" that platforms must be able to detect, restrict, and remove upon direction. Understanding these categories is essential for compliance.

The Six Core Categories

  1. Sexual harm content — including child sexual abuse material and non-consensual intimate imagery.
  2. Self-harm and suicide content — that promotes or provides instructions for self-injury.
  3. Cyberbullying and harassment — targeted abuse, doxxing, and coordinated harassment.
  4. Content endangering public health — dangerous medical misinformation with real-world harm potential.
  5. Content inciting racial or religious disharmony — reflecting Singapore's strong stance on communal stability.
  6. Content facilitating criminal harm — scams, phishing, malware distribution, and illegal transactions (covered heavily under OCHA).

2026 Additions

The 2026 refresh introduces explicit obligations around:

  • AI-generated deepfakes, particularly non-consensual intimate deepfakes and election-related manipulation.
  • Algorithmic amplification transparency for designated services.
  • Enhanced duties around scam content, aligning with Singapore's broader anti-scam strategy.

Key Obligations for Platforms in 2026

Designated services must comply with the Code of Practice for Online Safety, which sets out concrete operational requirements. Failure to comply can result in financial penalties of up to SGD 1 million per offence, with additional daily fines for continuing breaches.

1. User Safety Measures

  • Systems to minimise user exposure to harmful content.
  • Community guidelines that clearly prohibit the six harm categories.
  • Content moderation resources adequate for Singapore's user base.

2. User Reporting and Resolution

  • Easy-to-access reporting mechanisms.
  • Timely review and action on reports.
  • Feedback to reporters on outcomes.

3. Child Safety

  • Additional safeguards for users under 18, including default privacy settings.
  • Tools for parents and guardians.
  • Restrictions on targeted advertising to minors.

4. Accountability

  • Annual online safety reports submitted to IMDA.
  • Public transparency reports covering enforcement actions taken.
  • Designated local contact points for regulator communication.

Comparison: Singapore vs Other Regional Online Safety Laws

Singapore's approach shares DNA with several other jurisdictions but differs in scope, penalties, and enforcement style. The table below compares key features as of 2026.

Feature Singapore OSA 2026 UK Online Safety Act Australia Online Safety Act EU Digital Services Act
Primary regulator IMDA Ofcom eSafety Commissioner European Commission + national coordinators
Max financial penalty SGD 1M per offence £18M or 10% global turnover AUD 782,500 per contravention Up to 6% global turnover
Access blocking Yes Yes (as last resort) Yes Limited
Child safety focus High Very high Very high High
Deepfake / AI provisions Yes (2026) Yes Yes Yes (AI Act interplay)
Extraterritorial reach Yes Yes Yes Yes

Enforcement Powers Under the Act

IMDA and the Singapore Police Force (under OCHA) hold a wide array of enforcement tools that go beyond typical content moderation frameworks.

Direction Orders

  1. Disabling directions — require a service to remove or restrict specific content in Singapore.
  2. Stop communication directions — target individual accounts or groups producing harmful content.
  3. Account restriction directions — limit an account's ability to interact with Singapore users.
  4. App removal directions — require app stores to delist non-compliant apps.
  5. Access blocking directions — require ISPs to block non-compliant services entirely.

Response Timelines

Most directions must be complied with within specified windows — often as short as 24 hours for egregious content and up to a few days for less urgent categories. Failure to comply can escalate quickly from fines to full access blocking.

What This Means for Digital Marketers and Businesses

The Online Safety Act 2026 has practical consequences well beyond social media giants. Any business operating a digital presence in Singapore should review its practices.

Link Sharing, URL Shorteners, and Redirects

Shortened URLs are a common vector for scams and phishing content, which puts them squarely in the sights of OCHA enforcement. Businesses using link management tools should ensure they:

  • Choose providers with active abuse detection and takedown workflows.
  • Avoid platforms known to host scam links (which risk being blocked in Singapore).
  • Monitor click analytics for unusual traffic that could indicate abuse.

Reputable link management services such as Lunyb operate with built-in phishing checks and clear abuse policies, which reduces the risk of your branded links being caught up in enforcement actions. If you are still evaluating providers, our 2026 buyer's guide to URL shorteners compares the leading options across safety, analytics, and pricing.

Advertising and Sponsored Content

Advertisers must ensure creatives do not fall foul of the harm categories. Financial promotions in particular are under heavy scrutiny given Singapore's ongoing scam crackdown. Platforms are increasingly required to verify advertiser identity for financial products.

Community Management

Brands running Singapore-facing forums, comment sections, or Discord/Telegram communities should implement clear moderation policies and reporting channels. While smaller communities are unlikely to be designated, they remain subject to direction orders.

Rights and Protections for Users

The Act is not only about restrictions — it also gives Singapore users meaningful new rights.

Right to Report and Escalate

Users can report harmful content directly to designated platforms and, if unsatisfied with the response, escalate to IMDA. This creates a genuine backstop where platform moderation is inadequate.

Protection from Scams and Malicious Content

OCHA's direction powers mean scam sites, phishing pages, and malicious redirects can be blocked at the ISP level, offering network-wide protection without requiring users to install anything.

Privacy and Data Considerations

While the Act focuses on content safety, it operates alongside the Personal Data Protection Act (PDPA). Platforms complying with takedown orders must still handle user data responsibly. Users concerned about privacy can complement these legal protections with practical steps like:

  • Using encrypted DNS resolvers (DNS-over-HTTPS) for safer browsing.
  • Choosing privacy-respecting browsers with anti-tracking features.
  • Enabling two-factor authentication on all key accounts.
  • Verifying shortened links before clicking, especially in unsolicited messages.

Compliance Checklist for Businesses

Whether you run a global platform, a Singapore-based startup, or a marketing team, here is a practical compliance checklist for 2026.

  1. Map your exposure — determine whether your service is accessible to Singapore users and whether you meet designation thresholds.
  2. Publish clear community guidelines — explicitly prohibit the six harm categories.
  3. Implement reporting mechanisms — accessible from every piece of user-generated content.
  4. Set moderation SLAs — with faster response for egregious content.
  5. Prepare an IMDA response playbook — assign an internal owner for direction orders.
  6. Audit third-party tools — including link shorteners, ad networks, and hosting.
  7. Strengthen child safety — default privacy for minors, age-appropriate design.
  8. Document everything — annual reports will require solid evidence of compliance.

Common Misconceptions

"We're not based in Singapore, so this doesn't apply to us."

Incorrect. The Act applies to any service accessible to Singapore users. Global platforms have already been the primary targets of designations.

"Only social media platforms are affected."

Incorrect. Websites, forums, app stores, hosting providers, and link services can all receive direction orders.

"Compliance means censorship."

The framework is narrowly tailored to specific harm categories. Ordinary business content, political commentary within legal bounds, and creative expression are not the focus.

Looking Ahead: What to Expect Beyond 2026

Singapore's regulatory trajectory suggests further tightening in several areas:

  • Deeper AI-specific obligations, particularly around synthetic media labelling.
  • Greater alignment with ASEAN neighbours on cross-border enforcement.
  • Expanded designation of mid-tier platforms as their user bases grow.
  • Continued focus on scam prevention, likely with dedicated new instruments.

Businesses that build compliance capability now — clear policies, responsive moderation, safe tooling — will find each new wave of regulation manageable rather than disruptive.

Frequently Asked Questions

Does the Singapore Online Safety Act apply to foreign websites?

Yes. The Act has extraterritorial reach and applies to any online communication service accessible to end-users in Singapore, regardless of where the operator is based. IMDA can issue directions and, if ignored, order Singapore ISPs to block access.

What are the penalties for non-compliance?

Designated services can face fines of up to SGD 1 million per offence, with additional daily penalties for continuing breaches. Non-compliant services may also be blocked from Singapore entirely, and individual officers can face personal liability under OCHA for certain criminal harms.

How does the Act affect URL shorteners and link management tools?

Shortened links used to distribute scams, phishing, or other harmful content can be subject to takedown or blocking orders. Businesses should choose link management providers with robust abuse detection. Legitimate providers like Lunyb operate with built-in safety checks, and our honest review of Lunyb covers those safety features in more detail.

Do small businesses and creators need to comply?

Small businesses are unlikely to be formally designated, but they remain subject to takedown directions if their content or platforms host harmful material. Practically, following the six harm categories, moderating user comments, and using reputable tools is enough for most SMEs.

How can users report harmful content in Singapore?

Users should first report content through the platform's in-app reporting tools. If the platform fails to act on egregious content, users can escalate to IMDA via its official online safety reporting channel. For scams and criminal content, reports can also go to the Singapore Police Force or ScamShield.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles