facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Businesses and Users

L
Lunyb Security Team
··9 min read

Singapore has quietly built one of the most rigorous online safety frameworks in Asia. The Singapore Online Safety Act 2026 extends and refines the earlier Online Safety (Miscellaneous Amendments) Act 2022, sharpening obligations on social media services, expanding coverage to emerging platforms, and giving the Infocomm Media Development Authority (IMDA) stronger tools to act against harmful online content. Whether you run a business, moderate a community, or simply want to stay safe online, this guide breaks down what the Act means in 2026.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 is the updated statutory framework regulating harmful online content accessible to users in Singapore. It amends the Broadcasting Act and layers additional obligations on designated online services, particularly large social media platforms, requiring them to prevent and remove egregious content and protect Singapore users, especially children.

The Act sits alongside the Online Criminal Harms Act (OCHA) and the Personal Data Protection Act (PDPA), forming a three-pillar approach to online governance in Singapore: content safety, criminal misuse, and personal data.

Legislative Timeline

  1. 2022: Online Safety (Miscellaneous Amendments) Act passed, amending the Broadcasting Act.
  2. 2023: Code of Practice for Online Safety takes effect for designated social media services.
  3. 2024: Online Criminal Harms Act operationalized, targeting scams and malicious cyber activity.
  4. 2025–2026: Expanded provisions for app stores, generative AI outputs, and deepfake election content.

Who Does the Act Apply To?

The Act applies broadly to any online communication service accessible to end-users in Singapore, but the heaviest obligations fall on Designated Online Services (DOS)—typically large social media platforms with significant Singapore reach.

Categories of Regulated Entities

  • Designated Social Media Services: Platforms like Facebook, Instagram, TikTok, X, YouTube, and HardwareZone forums that meet IMDA's user reach or risk threshold.
  • App Distribution Services: Apple App Store, Google Play, and other stores serving Singapore users.
  • General Online Communication Services: Any service that allows communication with end-users in Singapore, including messaging apps, forums, and dating platforms.
  • Businesses and Content Publishers: Companies operating websites, running ad campaigns, or distributing links to Singapore audiences.

Categories of Harmful Content Covered

The Act defines several categories of "egregious content" that must be blocked or removed swiftly once IMDA issues a direction. Understanding these categories is essential for compliance officers, community managers, and marketing teams.

Content CategoryDescriptionRemoval Timeframe
Sexual harm contentChild sexual exploitation material, non-consensual intimate imagesImmediate (hours)
Terrorism contentContent advocating or facilitating terrorismImmediate (hours)
Self-harm contentMaterial promoting suicide or self-injuryWithin 24 hours
Public health contentDangerous health misinformation during declared emergenciesAs directed
Public security contentContent inciting violence, race or religious hostilityAs directed
Deepfakes of candidatesDigitally manipulated election content (during election periods)Immediate

Key Obligations for Designated Platforms

Designated services under the Code of Practice must implement systemic safeguards—not just react to takedown orders. The 2026 refresh strengthens these obligations, particularly around child safety and algorithmic transparency.

1. User Safety Systems

Platforms must maintain community standards, provide easy in-app reporting, and act on reports within reasonable timeframes. They must also publish annual online safety reports detailing actions taken.

2. Child Safety by Default

Accounts belonging to minors must have stricter default privacy settings, restricted messaging from unknown adults, and reduced exposure to sensitive content. Age assurance mechanisms are increasingly expected.

3. Proactive Detection

Designated platforms must use technology—including hash-matching and classifiers—to detect known child sexual abuse material and terrorism content proactively, not only after reports.

4. Response to IMDA Directions

When IMDA issues a direction, the platform must:

  1. Disable access for Singapore end-users to the specified content.
  2. Do so within the timeframe stated in the direction (often hours for egregious material).
  3. Comply with any implementation directions on systemic issues.
  4. Report back to IMDA on actions taken.

Penalties for Non-Compliance

The Act carries substantial financial and access-related penalties. Non-compliant services face fines and, in serious cases, orders that require internet access service providers to block the platform in Singapore.

  • Financial penalties: Up to SGD 1 million per offence for designated services failing to comply with directions or the Code of Practice.
  • Continuing offences: Additional daily fines for ongoing non-compliance.
  • Access blocking: IMDA can direct ISPs to block non-compliant services entirely from Singapore users.
  • Criminal liability: Individual officers may face charges for willful obstruction under related legislation.

What This Means for Singapore Businesses

Even if you don't run a social media platform, the Act reshapes how businesses handle online content, links, and community interactions. Marketing teams, SaaS providers, e-commerce operators, and publishers all have exposure.

Marketing and Link Sharing

Businesses that distribute links through email, SMS, or paid campaigns must ensure destination pages don't host or redirect to prohibited content. Using a reputable link management platform such as Lunyb helps because you can update, disable, or audit redirects centrally if a direction is received or if a partner page becomes problematic. For a deeper look at trusted shorteners, see our 2026 buyer's guide to URL shorteners.

User-Generated Content

If your website hosts comments, reviews, forums, or uploaded media, you should:

  1. Publish clear community guidelines aligned with the Act's content categories.
  2. Provide an accessible reporting mechanism.
  3. Log moderation actions with timestamps for auditability.
  4. Nominate a Singapore contact person for statutory correspondence.

Advertising and Sponsored Content

Advertisers should ensure creatives don't fall within egregious categories—especially health-related claims, scam-adjacent offers, or manipulated political imagery. During election periods, deepfake candidate content is prohibited outright.

Interaction with the Online Criminal Harms Act

The Online Safety Act focuses on content categories that harm the public, while OCHA targets specifically criminal content—scams, malware distribution, and cyber-enabled fraud. Together they give Singapore authorities a fast-track mechanism to disable scam websites, phishing pages, and fraudulent apps.

Direction Types Under OCHA

  • Stop communication directions – remove specific criminal content.
  • Disabling directions – disable access to accounts or URLs.
  • Account restriction directions – limit specific accounts' interactions.
  • Access blocking directions – block entire domains at the ISP level.
  • App removal directions – require app stores to delist malicious apps.

How Users in Singapore Are Protected

For everyday users, the Act translates into more usable in-app safety tools, faster removal of harmful content, and stronger recourse when things go wrong.

User Rights and Tools

  1. In-app reporting: Every designated platform must offer clear reporting flows for the content categories above.
  2. Feedback on outcomes: Users should be informed of the outcome of their report.
  3. Child-safe defaults: Accounts identified as belonging to minors receive stricter settings automatically.
  4. Appeal mechanisms: Users whose content is wrongly removed can appeal via the platform's process.

Practical Safety Tips for Singapore Users

  • Enable two-factor authentication on all social and banking accounts using an authenticator app.
  • Use encrypted DNS (such as DNS-over-HTTPS) in your browser to reduce exposure to malicious lookalike domains.
  • Verify shortened links before clicking—many modern shorteners, including Lunyb, offer link previews. See our honest Lunyb review for how link previews work in practice.
  • Report scam messages via the ScamShield app so that the National Crime Prevention Council can help authorities issue OCHA directions faster.
  • Keep browsers, operating systems, and messaging apps updated to receive the latest phishing protections.

Compliance Checklist for Businesses

Use this checklist as a starting point. Larger organizations, especially those approaching designated-service thresholds, should conduct a formal legal review.

AreaActionPriority
GovernanceAssign an accountable executive for online safety complianceHigh
Content moderationDocument moderation policies mapped to Act categoriesHigh
Reporting toolsDeploy accessible in-product reportingHigh
Link hygieneAudit outbound links, use branded managed shortenersMedium
Child safetyImplement age-appropriate defaults if minors may use serviceHigh if applicable
Incident response24/7 contact for IMDA directions; escalation SLAHigh
TransparencyPrepare annual safety reporting templateMedium
Vendor reviewAssess third-party tools for compliance implicationsMedium

Emerging Areas: AI, Deepfakes, and Election Integrity

The 2026 legislative landscape places heavy weight on synthetic media. The Elections (Integrity of Online Advertising) Act complements the Online Safety Act by prohibiting digitally generated or manipulated content that realistically depicts a candidate saying or doing something they did not. Platforms must remove such content within stringent windows during election periods.

Generative AI operators are also being brought into the ambit through evolving codes of practice, particularly where their outputs could be surfaced on designated services. Expect further guidance from IMDA in the second half of 2026.

How Singapore Compares Regionally

Singapore's approach is more prescriptive than Malaysia's Content Code but less broad than Australia's Online Safety Act, which includes an eSafety Commissioner with sweeping powers. Compared with Indonesia's MR5 rules, Singapore focuses more on systemic obligations than blanket registration requirements. For multinational operators, aligning global trust and safety policies with Singapore's Code of Practice usually satisfies most ASEAN neighbours, with jurisdiction-specific tweaks.

Preparing for the Next Wave

IMDA has signalled several priorities beyond 2026: stronger age assurance, watermarking of AI-generated content, and clearer duties on private messaging services regarding illegal content. Businesses should build compliance programmes that are principles-based rather than merely checkbox-driven so they can absorb these changes with minimal disruption.

If you manage marketing links, publisher partnerships, or affiliate networks, adopting a controlled link infrastructure now—one where you can rapidly disable, audit, and rewrite destinations—will pay dividends when directions are issued or when a partner site is compromised.

Frequently Asked Questions

Does the Singapore Online Safety Act apply to overseas platforms?

Yes. The Act has extraterritorial reach. Any online communication service accessible to end-users in Singapore can be subject to directions, and designated services must comply regardless of where they are headquartered. Non-compliance can result in access blocking by Singapore ISPs.

What is the difference between the Online Safety Act and the Online Criminal Harms Act?

The Online Safety Act focuses on categories of harmful content (sexual, terrorism, self-harm, public health, public security) and systemic platform obligations. The Online Criminal Harms Act targets content used to commit crimes such as scams, malware, and impersonation, giving authorities faster tools to disable criminal infrastructure.

Do small businesses and bloggers need to comply?

Small businesses and bloggers are not "designated services" but must still ensure their websites and communications don't host or distribute prohibited content. They should respond to any IMDA directions promptly, publish sensible community guidelines if they allow user comments, and audit outbound links regularly.

How quickly must harmful content be removed?

Timeframes depend on the category and the direction. Child sexual exploitation material and terrorism content typically require removal within hours. Other categories may allow 24 hours or the timeframe specified in the direction. Designated platforms are expected to have systems capable of very rapid response.

Can users appeal if their content is removed unfairly?

Yes. Designated platforms must offer internal appeal mechanisms. In addition, decisions by IMDA can be challenged through statutory review pathways. Users who believe their content was wrongly removed should document the content, capture any notice they received, and use the platform's appeal flow first.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles