facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Businesses and Users

L
Lunyb Security Team
··10 min read

Singapore's Online Safety Act 2026 represents one of the most significant updates to the country's digital regulation framework since the original Online Safety (Miscellaneous Amendments) Act came into force in 2023. Building on the Infocomm Media Development Authority's (IMDA) enforcement experience and lessons learned from the Code of Practice for Online Safety, the 2026 amendments extend obligations to a wider range of service providers, tighten timelines for harmful content removal, and introduce new duties around scams, deepfakes, and child safety.

This complete guide breaks down what the Singapore Online Safety Act 2026 covers, who must comply, what penalties apply, and how both businesses and individual users can prepare. Whether you operate a social media platform, run a Singapore-based e-commerce site, or simply want to understand your rights online, this article gives you the practical detail you need.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 is an updated legislative framework administered by the IMDA that regulates how online communication services, social media services, and app distribution services handle harmful content accessible to Singapore users. It expands and clarifies the earlier 2023 amendments to the Broadcasting Act by adding new categories of regulated harm and introducing sector-specific codes of practice.

The Act's core objective is straightforward: reduce Singapore users' exposure to egregious online harms while preserving legitimate expression and innovation. It applies extraterritorially, meaning overseas platforms serving Singapore users must comply even if they have no physical presence in the country.

Key Changes From the 2023 Framework

  • Expanded scope of regulated harms, including AI-generated deepfakes, non-consensual intimate imagery, and financial scams.
  • Shorter removal timelines for certain content categories (as fast as a few hours for child sexual exploitation material).
  • New duties on app stores to vet and remove non-compliant applications.
  • User empowerment tools, including mandatory reporting channels and appeal mechanisms.
  • Higher financial penalties for systemic non-compliance.

Who Must Comply With the Act?

The Act uses a tiered approach. Not every website or app faces the same obligations — duties scale with the size, risk, and function of the service.

Designated Social Media Services (DSMS)

Large platforms with significant reach in Singapore — such as Facebook, Instagram, TikTok, YouTube, X, and similar services — are designated by IMDA and face the strictest obligations. These include implementing systemic risk assessments, publishing annual transparency reports, and adhering to the Code of Practice for Online Safety.

Online Communication Services

Messaging platforms, forums, and interactive services accessible to Singapore users fall under general obligations to remove egregious content when directed by IMDA.

App Distribution Services

App stores (Apple App Store, Google Play, and equivalents) must implement age assurance measures, content review processes, and rapid takedown procedures for apps flagged by the regulator.

Small and Medium Businesses

SMEs operating websites, e-commerce stores, or community platforms are generally not designated, but they must still respond to lawful directions from IMDA and avoid hosting content that promotes clearly illegal harms.

Categories of Regulated Harmful Content

The 2026 Act consolidates and expands the categories of content that regulated services must proactively manage. Understanding these categories is essential for compliance officers, trust and safety teams, and platform operators.

Category Examples Priority Level
Child Sexual Exploitation Material CSAM, grooming content Highest — immediate removal
Terrorism Content Recruitment, incitement, propaganda Highest — immediate removal
Non-Consensual Intimate Imagery Revenge imagery, deepfake intimate content High — within hours
Financial Scams Phishing sites, investment fraud, impersonation High — within 24 hours
Cyberbullying and Harassment Doxxing, targeted harassment campaigns Medium — within 48 hours
Health Misinformation Dangerous medical claims, vaccine disinformation Medium — contextual review
Content Endangering Public Health or Racial Harmony Incitement, hate speech High — within 24 hours

Compliance Obligations for Businesses

If your service is designated or otherwise in scope, here is a practical checklist to work through with your legal and product teams.

1. Conduct a Systemic Risk Assessment

Document the risks your platform poses across each regulated harm category. This assessment must be updated annually and made available to IMDA on request.

2. Implement User Reporting Tools

Users must be able to report harmful content easily and receive acknowledgement of their report. The Act requires clear reporting flows in Singapore's four official languages where practical.

3. Establish Content Moderation SLAs

Align internal service-level agreements to statutory timelines. Highest-priority categories require near-immediate action; other categories have graduated response windows.

4. Deploy Proactive Detection

Designated services are expected to use hash-matching, AI classifiers, and other proactive tools for high-priority content categories such as CSAM and terrorism material.

5. Publish Transparency Reports

Annual reports must include metrics on content removed, appeal outcomes, and enforcement actions taken against users.

6. Provide Appeal Mechanisms

Users whose content is removed must be able to appeal. Platforms must respond within a reasonable window and provide reasons for decisions.

7. Age Assurance for Certain Services

Services likely to be accessed by minors — particularly those involving user-generated content, gaming, or adult material — must implement age assurance mechanisms proportionate to risk.

Penalties for Non-Compliance

The Act significantly increases the financial and operational consequences for regulated services that fail to meet their obligations.

  • Financial penalties of up to SGD 1 million per breach for designated services, with additional daily penalties for continuing offences.
  • Access blocking directions: IMDA can direct internet access service providers to block non-compliant platforms from Singapore users.
  • App store removal: Non-compliant apps can be ordered removed from Singapore app store fronts.
  • Individual liability for senior officers in cases of wilful non-compliance.
  • Public naming of non-compliant services in IMDA enforcement communications.

How the Act Affects Everyday Singapore Users

For individual users, the Act is largely protective rather than restrictive. You gain stronger reporting tools, faster removal of harmful content, and clearer appeal rights. However, there are a few practical points worth understanding.

Your Reporting Rights

You can report harmful content directly to platforms and, if the platform fails to act, escalate to IMDA. The regulator maintains a public portal for scam and harmful content reports.

Deepfakes and AI-Generated Content

Non-consensual AI-generated intimate imagery is explicitly covered. Victims can request removal from platforms and, in serious cases, pursue civil and criminal remedies alongside the regulatory route.

Protecting Yourself From Scams and Phishing Links

The Act does not remove your personal responsibility to practise safe browsing. Financial scams remain the most common online harm reported in Singapore, and many arrive through shortened or disguised URLs shared on messaging apps and social media.

Before clicking any shortened link, preview the destination. Reputable link management tools such as Lunyb offer link previews, click analytics, and abuse reporting so recipients can verify a link's destination before opening it. For a broader comparison of trustworthy link tools, see our 2026 buyer's guide to URL shorteners.

Cross-Border Implications

Overseas services with Singapore users cannot avoid the Act simply by operating from abroad. The Act uses a "targeting" test: if your service is accessible to and used by Singapore users in a non-trivial way, you are in scope. Practical implications include:

  1. Designating a local representative or point of contact for regulator communications.
  2. Building geo-aware content policies and takedown workflows.
  3. Retaining evidence of compliance actions for potential IMDA audits.
  4. Cooperating with international frameworks — the Act aligns in many respects with the EU Digital Services Act and the UK Online Safety Act, so a well-designed global compliance programme can cover multiple jurisdictions.

How the Act Compares to Regional Frameworks

Jurisdiction Key Law Scope Maximum Penalty
Singapore Online Safety Act 2026 Social media, messaging, app stores SGD 1M+ per breach
Australia Online Safety Act 2021 (updated) Social media, adult content, cyberbullying AUD 782,500+
United Kingdom Online Safety Act 2023 User-to-user services, search Up to 10% global turnover
European Union Digital Services Act Intermediary services, VLOPs Up to 6% global turnover

Practical Preparation Steps for Businesses

If you run a platform, marketplace, or communication service used by Singapore residents, here is a 90-day preparation plan.

Days 1–30: Assessment

  1. Map your user base and confirm Singapore exposure.
  2. Identify which regulated harm categories are relevant to your service.
  3. Audit current moderation policies and takedown timelines.
  4. Engage local Singapore legal counsel if you have material user numbers.

Days 31–60: Design

  1. Redesign reporting flows to meet Act requirements.
  2. Set moderation SLAs aligned to statutory timelines.
  3. Build or license proactive detection tools for the highest-risk categories.
  4. Draft your systemic risk assessment.

Days 61–90: Deploy

  1. Roll out user-facing changes with clear notices.
  2. Train moderation and customer support teams.
  3. Establish an IMDA liaison and escalation procedures.
  4. Publish an initial transparency statement.

Link Safety and the Online Safety Act

A significant proportion of harmful content — particularly scams and phishing attempts — reaches Singapore users through shortened URLs shared over messaging apps and social platforms. Under the Act, platforms have stronger duties to detect and remove links pointing to fraudulent or malicious destinations.

Businesses that use shortened links for marketing should choose a provider with strong abuse-monitoring practices, transparent logging, and rapid takedown capability. Services like Lunyb combine short branded links with click analytics and abuse reporting; for an honest breakdown of how Lunyb approaches trust and safety, read our honest review of Lunyb. If you're comparing enterprise options, our Rebrandly review for 2026 covers pricing and features in detail.

Pros and Cons of the 2026 Framework

Pros

  • Stronger, faster protection for users against scams, deepfakes, and CSAM.
  • Clearer statutory timelines that make compliance planning more predictable.
  • Alignment with international frameworks reduces the burden of parallel compliance programmes.
  • Enhanced transparency through mandatory reporting.
  • Meaningful appeal mechanisms for users whose content is removed.

Cons

  • Higher compliance costs for smaller platforms that fall within scope.
  • Some ambiguity around "targeting" thresholds for overseas services.
  • Age assurance requirements raise privacy concerns if implemented poorly.
  • Risk of over-removal as platforms err on the side of caution to avoid penalties.
  • Enforcement capacity at IMDA will need to scale to match expanded remit.

Frequently Asked Questions

Does the Singapore Online Safety Act 2026 apply to small websites and blogs?

Generally, no. Small websites, personal blogs, and low-traffic community forums are not designated services and face only baseline obligations — chiefly, cooperating with lawful IMDA directions and not knowingly hosting illegal content. Designation is reserved for platforms with meaningful reach or systemic risk profiles.

What should I do if I see harmful content targeting me or others?

Report it first through the platform's in-product reporting tool. If the platform fails to respond within a reasonable time — or if the harm is severe such as CSAM, threats, or non-consensual intimate imagery — escalate through IMDA's public reporting channels or, for criminal matters, contact the Singapore Police Force.

How does the Act handle AI-generated deepfakes?

The 2026 Act explicitly covers AI-generated harmful content, including deepfake intimate imagery and impersonation used in scams. Designated services must have processes to detect and remove such content, and victims can request removal directly with an expected rapid response.

Do overseas platforms really need to comply?

Yes. The Act applies extraterritorially where a service is accessible to and used by Singapore users. Non-compliance can result in access blocking, app store removal, and financial penalties enforceable through international cooperation channels.

How does the Act affect link shorteners and marketing tools?

Link shorteners are not directly designated, but they intersect with the Act because shortened links are frequently used in scams and phishing. Reputable providers implement abuse detection, allow rapid takedowns, and provide transparency to recipients. Businesses using shortened links for legitimate marketing should choose providers with strong trust and safety practices to protect both their brand and their audience.

Conclusion

The Singapore Online Safety Act 2026 tightens the country's approach to online harms while broadly aligning with international best practice. For businesses, the message is clear: build proactive trust and safety programmes now, document your systemic risk work, and treat compliance as an ongoing capability rather than a one-off project. For users, the Act provides stronger tools and clearer rights — but personal vigilance, especially around shortened links, scams, and deepfake content, remains essential.

Whether you're preparing your platform for designation, choosing safer link tools for your marketing, or simply trying to stay safe online, understanding the Act is the first step toward a more secure Singapore internet.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles