Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore has established itself as one of the most proactive jurisdictions in Asia when it comes to digital regulation. The Singapore Online Safety Act 2026 represents the next major evolution in the country's approach to protecting internet users from harmful online content, scams, and digital abuse. Whether you operate an online platform, run a business with a digital presence, or simply want to understand your rights as a user, this comprehensive guide explains what the Act does, who it affects, and how to comply.
What Is the Singapore Online Safety Act 2026?
The Singapore Online Safety Act 2026 is a legislative framework enacted to strengthen online safety by requiring digital platforms to prevent, detect, and remove harmful content accessible to Singapore users. It builds on earlier amendments to the Broadcasting Act (introduced through the Online Safety (Miscellaneous Amendments) Act 2022) and expands the Infocomm Media Development Authority's (IMDA) enforcement powers.
The Act applies principally to social media services, online communication services, and app distribution platforms that are accessible in Singapore, regardless of whether the operator is based locally or overseas. It focuses on categories of egregious content including child sexual exploitation material, terrorism-related content, content inciting violence, and content that undermines public health or racial and religious harmony.
Why Singapore Introduced a Strengthened Framework
Three main drivers shaped the 2026 update:
- Rising online scams — Singapore recorded record scam losses in 2024 and 2025, with phishing links and impersonation dominating cases.
- Cross-border content risks — Harmful content increasingly originates from overseas platforms not previously accountable under Singapore law.
- Generative AI and deepfakes — The rapid spread of synthetic media created gaps in the earlier regime that needed statutory clarity.
Key Provisions of the Online Safety Act 2026
The Act introduces several structural changes to how online safety is governed in Singapore. Below are the most important provisions businesses and users should understand.
1. Designated Online Services (DOS)
The IMDA can designate any online communication service as a "Designated Online Service" if it has significant reach among Singapore users. Once designated, the service must comply with a Code of Practice that includes:
- User reporting and complaint mechanisms
- Proactive detection of egregious content
- Age assurance measures for minors
- Transparency reporting on content moderation actions
- Localized safety information for Singapore users
2. Directions to Disable Access
The IMDA has the authority to issue directions requiring online service providers to disable Singapore users' access to specific content within a stipulated timeframe — typically as short as 24 hours for the most egregious categories. Non-compliance can trigger access-blocking directions issued to internet access service providers, effectively removing the service from the Singapore internet.
3. Content Categories Covered
The Act specifies six primary categories of harmful content:
- Sexual content involving minors
- Content advocating or instructing acts of terrorism
- Content advocating suicide or self-harm
- Content depicting extreme physical or sexual violence
- Content inciting racial or religious disharmony
- Content that endangers public health
4. Scam and Deepfake Provisions
The 2026 update expands enforcement powers over scam-enabling content, including phishing URLs, impersonation profiles, and AI-generated deepfakes used for fraud. Platforms must implement measures to detect and disrupt such content proactively, rather than only responding to complaints.
Who Must Comply With the Act?
Compliance obligations vary based on the nature of the entity. Here is a breakdown of the primary categories.
| Entity Type | Compliance Level | Key Obligations |
|---|---|---|
| Designated Online Services (large platforms) | Highest | Full Code of Practice compliance, transparency reports, proactive detection |
| Non-designated social/communication services | Moderate | Respond to IMDA directions, remove flagged content |
| App distribution services | Moderate | Enforce age ratings, remove non-compliant apps |
| Internet access service providers | Situational | Execute access-blocking directions when issued |
| Local businesses using digital marketing | Indirect | Ensure marketing content and links are lawful and safe |
| Individual users | Minimal | Refrain from posting egregious content; use reporting tools |
Penalties for Non-Compliance
The Act carries significant financial and operational penalties designed to ensure that global platforms take Singapore's rules seriously.
- Fines of up to SGD 1 million per contravention for failure to comply with a direction or Code of Practice.
- Ongoing daily penalties for continuing non-compliance after a direction is issued.
- Access blocking to Singapore users — a commercially severe outcome that effectively removes a platform from the market.
- Criminal liability for senior officers where non-compliance is willful and involves egregious harm.
Importantly, penalties can apply to overseas operators. Singapore uses reciprocal enforcement channels and market-access consequences as leverage where traditional cross-border enforcement is difficult.
How the Act Affects Businesses in Singapore
Even businesses that do not operate large platforms have practical obligations under the wider Online Safety ecosystem. Marketing teams, e-commerce operators, and SMEs should pay particular attention to the following areas.
Marketing Links and URL Hygiene
Shortened URLs, promotional landing pages, and outbound campaign links are increasingly scrutinized because scammers rely on similar tools. Businesses should use reputable link management services that offer analytics, malware scanning, and transparent domains. Providers like Lunyb emphasize link safety and traceability, which helps demonstrate that a business's outbound links are legitimate. For a broader comparison of options, see our 2026 URL shortener buyer's guide.
User-Generated Content Moderation
Any business that hosts reviews, forums, comments, or community features must have clear moderation policies. If your platform grows enough that IMDA designates it, you must be able to demonstrate:
- An accessible reporting flow
- Documented moderation SLAs
- Records of enforcement decisions
- Escalation paths for law enforcement requests
Advertising and Sponsored Content
Advertising networks operating in Singapore should validate advertiser identity and pre-screen creatives for scam indicators. Deepfake endorsements of local public figures — a growing problem — are explicitly targeted by the 2026 amendments.
How the Act Affects Users
For everyday internet users in Singapore, the Act provides stronger protection but also assigns some responsibility.
Your Rights Under the Act
- The right to report harmful content on Designated Online Services and expect a response within a reasonable window.
- The right to appeal moderation decisions through platform mechanisms.
- The right to age-appropriate safety features, particularly for users under 18.
- Access to public transparency reports on how much content is removed and why.
Your Responsibilities
Users should not share, forward, or amplify content that falls within the egregious categories. Reposting terrorist propaganda, deepfake scams, or content inciting communal disharmony can attract both platform action and criminal liability under existing statutes such as the Broadcasting Act and the Protection from Online Falsehoods and Manipulation Act (POFMA).
Step-by-Step Compliance Checklist for Platforms
If your organization operates any service that could fall within the Act's scope, follow this practical checklist:
- Map your Singapore user base. Determine whether your service is reasonably accessible to Singapore users and estimate reach.
- Appoint a local point of contact. Designated services must maintain a responsive channel for the IMDA.
- Publish a Singapore-facing content policy. Reference the six harm categories explicitly.
- Build reporting infrastructure. Ensure Singapore users can report content in one or two clicks.
- Implement proactive detection. Deploy hash-matching for known harmful content and ML classifiers for emerging harms.
- Introduce age assurance for minors. Where your service is likely used by under-18s, adopt reasonable age assurance methods.
- Document moderation actions. Maintain audit trails to support transparency reporting.
- Prepare an incident response plan. Include workflows for 24-hour takedown directions.
- Train staff. Ensure trust and safety teams understand Singapore-specific obligations.
- Publish transparency reports. Annually at minimum, with Singapore-specific breakdowns where required.
Pros and Cons of the Act
Pros
- Stronger protection for children and vulnerable users online
- Faster removal of harmful content, particularly scams and deepfakes
- Clear obligations for large platforms operating in Singapore
- Cross-border reach that closes previous enforcement gaps
- Improved transparency through mandatory reporting
Cons
- Compliance costs may burden smaller platforms and startups
- Broad discretion granted to IMDA could raise concerns about proportionality
- Risk of over-removal (false positives) as platforms err on the side of caution
- Some obligations overlap with POFMA, the Cybersecurity Act, and PDPA, creating complexity
- Definitions around "harmful" content require careful interpretation for edge cases
How the Act Interacts With Other Singapore Laws
The Online Safety Act 2026 does not exist in isolation. It sits alongside several other digital laws, and understanding the interaction is critical for compliance.
| Law | Primary Focus | Overlap with OSA 2026 |
|---|---|---|
| POFMA | Online falsehoods and misinformation | Correction and takedown of false statements |
| Personal Data Protection Act (PDPA) | Personal data handling | Data used in moderation and reporting |
| Cybersecurity Act | Critical information infrastructure | Incident response for platform breaches |
| Broadcasting Act | Broadcasting and internet content | Foundation for many OSA provisions |
| Online Criminal Harms Act | Criminal activity online (scams, malicious cyber activity) | Scam-related takedown powers |
Practical Tips for Safer Online Operations
Whether you are a business owner, marketer, or user, the following practices align well with the spirit and letter of the Act:
- Use encrypted DNS resolvers to reduce exposure to malicious domains.
- Enable multi-factor authentication across business and personal accounts.
- Verify short links before clicking — trusted shorteners offer previews and analytics.
- Report harmful content using in-platform tools; escalate to IMDA where necessary.
- Educate employees and family members about deepfake scams and phishing.
- Audit outbound marketing links regularly to ensure none have been hijacked or repurposed.
For marketers looking to compare enterprise-grade link management options and how they support compliance-friendly workflows, our Rebrandly Review 2026 is a useful reference alongside the Lunyb review linked above.
What Comes Next?
The IMDA is expected to publish updated Codes of Practice, guidance notes, and enforcement statistics in the months following the Act's entry into force. Businesses should monitor:
- Any designation announcements naming new platforms as DOS
- Sector-specific guidance for e-commerce, gaming, and messaging
- Updated deepfake and generative AI rules
- Enforcement case studies illustrating how IMDA interprets "reasonable steps"
The direction of travel is clear: Singapore expects platforms serving its users to invest meaningfully in safety, and it will use both regulatory and market-access tools to achieve compliance.
Frequently Asked Questions
Does the Singapore Online Safety Act 2026 apply to overseas platforms?
Yes. The Act applies to any online service accessible to Singapore users, regardless of where the provider is headquartered. Overseas platforms can be directed to disable access to specific content or, in cases of persistent non-compliance, be blocked from Singapore entirely.
What are the penalties for non-compliance?
Financial penalties can reach SGD 1 million per contravention, with ongoing daily fines for continued non-compliance. In severe cases, IMDA can direct internet access service providers to block the offending service from being reached by Singapore users.
How does the Act treat deepfakes and AI-generated content?
Deepfakes used for scams, impersonation of public figures, or the spread of harmful content fall squarely within the Act's scope. Platforms are expected to deploy detection tools and act on such content quickly, and advertising networks must screen creatives for synthetic media misuse.
Do small businesses and SMEs need to comply?
Small businesses without user-facing platforms have limited direct obligations, but they must still ensure their marketing, customer communications, and any user-generated content features do not host or amplify harmful content. Using reputable link management and hosting providers helps demonstrate good faith compliance.
How can users report harmful content under the Act?
Users should first use the reporting tools on the platform where they encountered the content. If the platform fails to act on egregious content, users can escalate to the IMDA through its official channels. For scams, the ScamShield resources and the Anti-Scam Centre remain the primary reporting routes.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.