facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Businesses and Users

L
Lunyb Security Team
··9 min read

Singapore has steadily built one of the most comprehensive online safety frameworks in Asia-Pacific. The Online Safety Act, first introduced through amendments to the Broadcasting Act in 2023 and progressively expanded in 2024 and 2025, enters a mature enforcement phase in 2026 with new codes of practice, expanded scope, and stricter penalties. Whether you run an online business, moderate a community, or simply want to understand your rights as a user in Singapore, this guide breaks down everything you need to know about the Singapore Online Safety Act in 2026.

What Is the Singapore Online Safety Act?

The Singapore Online Safety Act is a regulatory framework administered by the Infocomm Media Development Authority (IMDA) that governs harmful online content and holds digital platforms accountable for user safety. It empowers regulators to issue directions to online communication services, require content removal, and impose financial penalties for non-compliance.

Originally enacted as amendments to the Broadcasting Act (Cap. 28) in February 2023, the framework has since been reinforced by the Online Criminal Harms Act (OCHA) 2023 and updated Codes of Practice. In 2026, these instruments operate together as an integrated online safety regime covering everything from social media platforms to messaging services and content-sharing sites.

Key Objectives of the Act

  • Protect Singapore users, especially children, from harmful online content
  • Compel platforms to implement proactive safety measures
  • Enable rapid takedown of egregious content such as child sexual exploitation material, terrorism content, and cyberbullying
  • Increase transparency around content moderation and user safety practices
  • Combat online scams, phishing, and criminal harms

What's New in 2026?

The 2026 update to the Online Safety Act introduces several significant changes that businesses and platform operators must understand. These changes reflect Singapore's response to emerging threats including AI-generated content, deepfakes, and increasingly sophisticated online scams.

Major 2026 Updates

  1. Expanded scope to mid-sized platforms: Previously focused on "Designated Online Communication Services" (large social media platforms), the 2026 update extends compliance obligations to platforms with as few as 100,000 Singapore users.
  2. Deepfake and synthetic media provisions: New rules require labeling of AI-generated content and rapid removal of non-consensual deepfakes.
  3. Enhanced scam response: Platforms must implement real-time scam detection and cooperate with the Anti-Scam Command within 24 hours of notice.
  4. Age assurance requirements: Services accessible to minors must implement age assurance measures proportionate to risk.
  5. Increased penalties: Maximum fines raised to S$1 million or 10% of annual Singapore turnover, whichever is higher.

Who Must Comply With the Act?

The Act applies broadly to any online service accessible to users in Singapore, but obligations scale with size and risk profile. Understanding which category your service falls into is the first compliance step.

CategoryThresholdKey Obligations
Designated Online Communication Services (DOCS)Large platforms designated by IMDA (typically 1M+ SG users)Full Code of Practice compliance, annual reports, dedicated SG contact
Mid-tier services (new in 2026)100,000+ SG usersBasic safety measures, reporting mechanisms, complaint handling
Small servicesUnder 100,000 SG usersRespond to IMDA directions, remove egregious content on notice
App storesAny operating in SGAge ratings, parental controls, review of hosted apps

Categories of Regulated Harmful Content

The Act defines specific categories of "egregious content" that platforms must be able to detect and remove quickly. In 2026, these categories have been clarified and expanded.

Egregious Content Categories

  • Sexual exploitation of children: Zero tolerance; immediate removal required
  • Terrorism content: Content that incites, promotes, or facilitates terrorism
  • Content endangering public health: Serious health misinformation during emergencies
  • Content inciting racial or religious disharmony: A particularly sensitive area in multicultural Singapore
  • Non-consensual intimate imagery: Including AI-generated deepfakes (expanded in 2026)
  • Cyberbullying and harassment: Especially targeting minors
  • Scam and fraudulent content: Phishing links, fake investment schemes, impersonation
  • Suicide and self-harm promotion: Content encouraging or instructing on self-harm

Code of Practice for Online Safety

The Code of Practice for Online Safety is the operational backbone of the Act. It sets out specific measures that designated services must implement, and in 2026 the Code has been updated with more prescriptive requirements.

Core Code Requirements

  1. User reporting mechanisms: Easy-to-use in-app reporting for all content categories, with acknowledgement within a set time frame.
  2. Content moderation systems: A mix of automated detection and human review, with Singapore-context training for moderators.
  3. Child safety by default: Restrictive default settings for accounts identified as belonging to minors, including disabled direct messaging from strangers.
  4. Transparency reports: Annual reports detailing content actioned, response times, and enforcement statistics broken down for Singapore.
  5. User empowerment tools: Content filters, blocking features, and parental supervision options.
  6. Proactive detection: Use of hash-matching and classifiers for known harmful content, particularly child sexual abuse material (CSAM) and terrorism content.

Powers of the Regulator

IMDA holds significant enforcement powers under the Act, and these have been sharpened in the 2026 update. Understanding these powers helps businesses appreciate the compliance stakes.

IMDA's Enforcement Toolkit

  • Disabling access directions: Orders to remove or restrict access to specific content in Singapore
  • Account restriction directions: Orders to suspend or restrict specific user accounts
  • App removal directions: Orders to app stores to delist non-compliant apps
  • Service restriction orders: In extreme cases, directions to internet access service providers to block a service
  • Financial penalties: Up to S$1 million or 10% of Singapore annual turnover
  • Public censure: Publication of non-compliance findings

Implications for Businesses Operating in Singapore

For businesses, the Act creates both compliance obligations and opportunities. E-commerce operators, community platforms, and even marketing teams using user-generated content must factor safety obligations into their operations.

Practical Compliance Steps

  1. Conduct a scope assessment: Determine whether your service falls under DOCS, mid-tier, or small-service obligations based on Singapore user counts.
  2. Appoint a Singapore contact: Designated services must have a local representative empowered to receive IMDA directions.
  3. Implement reporting mechanisms: Ensure users can flag harmful content easily and receive acknowledgement.
  4. Update terms of service: Reflect Singapore-specific prohibited content and moderation practices.
  5. Train moderation teams: Include Singapore cultural and legal context, particularly around racial and religious content.
  6. Document everything: Maintain records of moderation actions, response times, and reporting metrics to support transparency reports.
  7. Prepare an incident response plan: Establish workflows for responding to IMDA directions within statutory time limits.

Link Sharing, Marketing, and the Act

Marketing teams and content publishers should note that the Act's scam provisions extend to link-based fraud, phishing campaigns, and impersonation. Sharing links, particularly shortened links, requires additional care in 2026 because scammers frequently abuse generic shorteners to disguise malicious destinations.

Using a reputable, transparency-focused link shortener helps demonstrate good faith and reduces the risk of your legitimate marketing links being confused with scam content. Services like Lunyb offer branded short links, click analytics, and safety scanning that make it easier to prove your links point to legitimate destinations. For a broader comparison of options available to Singapore marketers, see our 2026 buyer's guide to URL shorteners or our honest review of Lunyb.

User Rights Under the Act

The Act isn't only about platform obligations. It also strengthens the rights of Singapore users, particularly victims of online harms.

What Users Can Do

  • File complaints with IMDA: If a platform fails to act on reported egregious content, users can escalate to the regulator directly.
  • Request takedown of intimate imagery: Victims of non-consensual imagery, including deepfakes, can seek expedited removal.
  • Access safety tools: Users are entitled to block, mute, and filter features on covered platforms.
  • Receive transparency: Users should be informed about moderation decisions affecting their accounts, with a route to appeal.

Interaction With Other Singapore Laws

The Online Safety Act does not operate in isolation. Businesses need to consider it alongside a growing stack of digital regulations in Singapore.

Related Legislation

LawFocusOverlap With Online Safety Act
Personal Data Protection Act (PDPA)Data privacy and protectionUser data handled during moderation and reporting
Online Criminal Harms Act (OCHA)Criminal content online, especially scamsCoordinated takedown powers
Protection from Online Falsehoods and Manipulation Act (POFMA)MisinformationCorrection and takedown directions
Cybersecurity ActCritical information infrastructureSecurity measures underpinning safety
Foreign Interference (Countermeasures) ActForeign influence operationsCoordinated inauthentic behavior removal

Penalties and Enforcement Trends

In 2026, enforcement is expected to intensify. IMDA has signalled that it will move from a primarily educational stance to more active penalty imposition, particularly for repeat offenders and platforms that ignore statutory time limits.

Penalty Structure

  • Failure to comply with a direction: Up to S$1 million per offence, plus S$100,000 per day of continuing non-compliance
  • Failure to implement the Code of Practice: Up to 10% of annual Singapore turnover
  • Providing false information to IMDA: Up to S$500,000 and/or imprisonment for responsible officers
  • Obstruction of investigation: Criminal liability for individuals

Best Practices for 2026 Compliance

Beyond the letter of the law, forward-looking businesses can adopt best practices that reduce risk and build user trust.

Recommended Actions

  1. Perform an annual online safety audit against the latest Code of Practice
  2. Integrate safety-by-design principles into product development cycles
  3. Invest in Singapore-context training for content moderators and trust-and-safety teams
  4. Publish a clear Singapore transparency report even if not strictly required
  5. Establish direct communication channels with IMDA and law enforcement
  6. Educate users about reporting tools and safety features through onboarding flows
  7. Monitor emerging threats such as AI-generated scams and update controls accordingly

Frequently Asked Questions

1. Does the Singapore Online Safety Act apply to overseas platforms?

Yes. The Act has extraterritorial reach. Any online service accessible to Singapore users can be issued directions by IMDA, regardless of where the platform is headquartered. Designated services must appoint a local representative in Singapore.

2. What is the difference between the Online Safety Act and OCHA?

The Online Safety Act focuses on harmful content in general (egregious categories, cyberbullying, child safety) and imposes systemic obligations on platforms. The Online Criminal Harms Act (OCHA) specifically targets criminal content such as scams and provides law enforcement with expedited takedown powers. They complement each other and can apply simultaneously.

3. Do small businesses and community forums need to comply?

Small services below the 100,000 Singapore user threshold have limited proactive obligations but must still respond to lawful IMDA directions and remove egregious content when notified. Even a small community forum should have a reporting mechanism and a takedown process to demonstrate good faith.

4. How quickly must platforms respond to takedown directions?

Timeframes depend on the type of direction. For egregious content such as CSAM or terrorism content, action is expected within hours. For other categories, IMDA typically specifies deadlines in the direction itself, often between 24 and 72 hours. Failure to meet these deadlines triggers daily penalties.

5. Are private messaging services covered?

Yes, in specific circumstances. The Act covers online communication services that enable communication among end-users, including messaging apps. However, obligations focus on features like public groups, discovery mechanisms, and reporting tools rather than the content of private end-to-end encrypted conversations.

Conclusion

The Singapore Online Safety Act in 2026 represents a mature, layered approach to online harms that balances user protection with practical compliance pathways for platforms of different sizes. For businesses, the message is clear: safety is now a baseline expectation, not a differentiator. Investing in robust reporting mechanisms, transparent moderation, and Singapore-aware safety practices is essential not only to avoid penalties but to build lasting trust with users. As enforcement intensifies through 2026 and beyond, businesses that treat online safety as a core function, rather than a legal afterthought, will be best positioned to thrive in Singapore's digital economy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles