facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Users and Businesses

L
Lunyb Security Team
··10 min read

Singapore has spent the last decade tightening its digital rulebook, and the Online Safety Act 2026 represents the country's most ambitious attempt yet to make the internet safer for its 5.9 million residents. Building on the 2022 amendments to the Broadcasting Act and the Online Criminal Harms Act of 2023, the 2026 update expands regulator powers, introduces new duties for platforms, and adds fresh obligations around scam prevention, child protection, and algorithmic transparency.

This guide breaks down everything you need to know about the Singapore Online Safety Act 2026: what it does, who it applies to, how enforcement works, and what individual users and Singapore-based businesses should do to stay compliant.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 is a consolidated piece of legislation that strengthens the Infocomm Media Development Authority's (IMDA) ability to regulate online platforms operating in or accessible from Singapore. It expands earlier online safety frameworks by adding scam-content duties, deepfake provisions, and stricter obligations for large social media services.

At its core, the Act pursues four goals:

  1. Reduce exposure to egregious content (child sexual abuse material, terrorism content, self-harm content).
  2. Curb online scams, phishing, and impersonation, which cost Singaporeans over S$650 million in 2024 alone.
  3. Increase transparency around recommendation algorithms and content moderation.
  4. Give the government fast-acting takedown and access-blocking powers.

Key Changes From Previous Legislation

The 2026 Act does not replace the Broadcasting Act or the Online Criminal Harms Act (OCHA). Instead, it harmonises them and introduces new categories of regulated conduct. Below is a summary of the major changes.

Expanded Scope of Regulated Services

Previously, the strictest duties applied to "Designated Online Communication Services" (DOCS) — essentially large social media platforms. The 2026 update extends similar obligations to:

  • App stores distributing apps to Singapore users
  • Messaging services with public group features
  • Search engines with more than 1 million monthly Singapore users
  • Livestreaming and short-form video platforms
  • Generative AI services that produce or host user-shared content

New Duties Around Scams and Impersonation

Platforms must now implement "reasonably practicable" measures to detect and remove scam content, including impersonation of Singapore government agencies, banks (DBS, OCBC, UOB), and public figures. This includes proactive scanning of shortened or masked links used in phishing campaigns.

Child Safety Codes of Practice

A dedicated Code of Practice for Child Safety requires platforms accessible to minors to apply default privacy settings, restrict direct messaging from strangers, and provide age-appropriate content filters. Non-compliance carries fines of up to S$1 million per breach.

Who Must Comply With the Act?

The Act uses a tiered approach. Not every website faces the same obligations — duties scale with size, risk, and audience.

TierWho It CoversKey Obligations
Tier 1 – Designated ServicesPlatforms with 1M+ Singapore users (Facebook, Instagram, TikTok, X, YouTube, Telegram)Full Codes of Practice, annual reports, local point of contact, algorithmic transparency
Tier 2 – Regulated ServicesMid-sized platforms, app stores, search engines, AI servicesTakedown compliance, scam prevention, user reporting tools
Tier 3 – General Online ServicesWebsites, blogs, small forums, e-commerce sitesCompliance with takedown orders and access-blocking directions
IndividualsSingapore residents and usersProhibited from creating or sharing designated harmful content

Types of Content Regulated

The Act defines several categories of "harmful online content" that platforms must act on when notified — and in some cases, proactively detect.

Egregious Content

This is the highest-priority category and includes child sexual exploitation material, terrorism content, content advocating suicide or self-harm, and content inciting violence based on race or religion. Platforms must remove this within 24 hours of an IMDA directive.

Scam and Malicious Cyber Content

New in 2026, this covers phishing pages, fake investment schemes, romance scam profiles, and impersonation content. It also targets malicious short links and cloaked URLs used to disguise phishing destinations — a growing enforcement priority.

Non-Consensual Intimate Imagery and Deepfakes

The Act criminalises the creation and distribution of non-consensual intimate imagery, including AI-generated deepfakes. Victims can request expedited removal, typically within 6 hours of a verified complaint.

Content Harmful to Children

Platforms accessible to under-18s must restrict content depicting sexual activity, extreme violence, cyberbullying, and content encouraging dangerous challenges or eating disorders.

Enforcement Powers and Penalties

The IMDA and the newly established Online Safety Commission share enforcement authority. Their toolkit is broad.

Directions the Regulator Can Issue

  1. Removal directions — content must be taken down within a set timeframe.
  2. Disabling directions — specific accounts, groups, or channels must be disabled for Singapore users.
  3. Access-blocking directions — ISPs like Singtel, StarHub, and M1 must block domains at the network level.
  4. App removal directions — app stores must delist offending apps from the Singapore storefront.
  5. Service restriction orders — payment providers and ad networks may be ordered to cut ties with non-compliant services.

Financial Penalties

Fines have increased significantly under the 2026 update. Designated services can be fined up to 10% of annual local turnover or S$1 million, whichever is higher, per breach. Individuals sharing prohibited content face fines up to S$50,000 and jail terms up to 5 years for the most serious categories.

What This Means for Singapore Businesses

Even if you don't run a social media platform, the Act likely touches your business in some way. E-commerce operators, digital marketers, and SaaS providers all have new considerations.

Marketing and Link Management

Digital marketers using shortened URLs need to be aware that platforms are now required to scan short links for malicious redirects. Using a reputable, transparent link management service — one that offers click analytics, custom domains, and does not cloak destinations — reduces the risk of your legitimate campaigns being flagged. Tools like Lunyb and other established shorteners publish transparency reports and cooperate with takedown requests, which helps keep marketing links out of automated block lists. For a broader comparison, see our 2026 buyer's guide to URL shorteners.

User-Generated Content on Your Website

If your site allows comments, reviews, or uploads, you are considered a General Online Service under Tier 3. You must comply with any takedown direction issued by IMDA within the stated timeframe (usually 24–72 hours) and maintain a working abuse-reporting channel.

Data Handling and Cross-Border Transfers

The Act works alongside the Personal Data Protection Act (PDPA). Businesses handling reports of harmful content must still respect PDPA obligations when processing personal data of complainants, alleged offenders, and victims.

What Individual Users Should Know

The Act is not only about platforms — it also creates new rights and responsibilities for everyday users in Singapore.

Your New Rights

  • Expedited takedown for intimate images, deepfakes, and doxxing content targeting you.
  • Right to appeal content moderation decisions on designated platforms via a formal user complaint channel.
  • Transparency about why content was recommended to you, including the ability to reset your recommendation profile.
  • Access to Singapore-based support from designated services within reasonable business hours.

Your New Responsibilities

  • Do not create, share, or forward content in the prohibited categories, even in private chats or closed groups.
  • Verify suspicious links before clicking or forwarding — especially anything appearing to come from a bank or government agency.
  • Report harmful content through platform tools or directly to the ScamShield or Online Safety Commission portals.

Practical Compliance Checklist for Businesses

If you operate a Singapore-facing digital service, use this checklist as a starting point.

  1. Map your obligations — determine your tier based on user numbers and service type.
  2. Appoint a local contact — Tier 1 and Tier 2 services need a Singapore-based representative.
  3. Publish clear community guidelines — align them with the Codes of Practice.
  4. Implement user reporting tools — with acknowledgement and resolution timelines.
  5. Set up an internal takedown workflow — with logged decisions and appeal handling.
  6. Vet third-party links and ads — including short links, affiliate URLs, and programmatic ad inventory.
  7. Train staff — especially community managers and customer support teams.
  8. Prepare annual transparency reports — if you are a Tier 1 service.
  9. Review data protection impact assessments — where content moderation intersects with the PDPA.
  10. Document everything — regulators expect an audit trail.

Comparing Singapore's Approach to Other Jurisdictions

Singapore's model sits between the EU's Digital Services Act (DSA) and the UK's Online Safety Act, with a stronger emphasis on rapid executive action.

FeatureSingapore OSA 2026UK Online Safety ActEU DSA
Primary regulatorIMDA + Online Safety CommissionOfcomEuropean Commission + national DSCs
Max fine10% turnover or S$1M10% turnover or £18M6% global turnover
Access blockingYes, directly orderedYes, via courtLimited, court-based
Deepfake provisionsExplicitPartialCovered under AI Act
Scam content dutyExplicit and proactiveExplicitGeneral due-diligence

Protecting Yourself Online in Singapore

Regulation alone will not stop every scam or harmful post. Personal cyber hygiene matters just as much. A few practical steps for Singapore users in 2026:

  • Enable Singpass two-factor authentication and biometric login.
  • Use encrypted DNS (such as 1.1.1.1 or Quad9) on mobile devices to reduce exposure to malicious domains.
  • Prefer privacy-respecting browsers with built-in tracker and phishing protection.
  • Preview shortened links before clicking — many reputable link services, including those covered in our shortener guide, offer link previews.
  • Register for the ScamShield app to block known scam numbers and SMS.
  • Keep devices patched and enable automatic updates.

Frequently Asked Questions

When does the Singapore Online Safety Act 2026 come into force?

The Act's core provisions took effect in phases starting in Q1 2026, with the full Codes of Practice for designated services becoming enforceable by mid-2026. Some transitional periods apply for smaller platforms adjusting their reporting tools and moderation workflows.

Does the Act apply to overseas platforms?

Yes. The Act applies to any online service accessible to users in Singapore, regardless of where the operator is based. Overseas designated services must appoint a local point of contact and comply with directions issued by the IMDA or the Online Safety Commission.

Can I be fined for forwarding a scam message?

Forwarding a scam or phishing message once, without knowledge that it was fraudulent, is unlikely to trigger enforcement. However, repeatedly sharing content you know or should reasonably know to be scam material — or profiting from it — can lead to fines and, in serious cases, criminal charges under both the Online Safety Act and the Online Criminal Harms Act.

How do I report harmful content?

Use the reporting tools built into the platform where you saw the content first. If the platform does not act, you can escalate to the Online Safety Commission's complaint portal. For scams specifically, use the ScamShield helpline (1799) or the anti-scam hotline. Non-consensual intimate imagery and doxxing cases can be reported directly for expedited handling.

What happens if a platform refuses to comply?

Non-compliant platforms face escalating penalties: fines, ISP-level access blocking so Singapore users cannot reach the service, removal from local app stores, and orders to payment providers and ad networks to sever commercial relationships. In extreme cases, senior executives can face personal liability.

Final Thoughts

The Singapore Online Safety Act 2026 is one of the most comprehensive online safety frameworks in Asia. For users, it means faster help against scams, deepfakes, and harmful content. For businesses, it means new duties around content moderation, link hygiene, and transparency — but also clearer rules of the road.

Whether you're running a small e-commerce store, managing a marketing team, or simply using WhatsApp and TikTok every day, understanding the Act helps you stay safe and stay compliant. Combine that understanding with strong personal cyber hygiene and reputable digital tools, and you'll be well-prepared for Singapore's evolving online landscape.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles