Singapore Online Safety Act 2026: Complete Guide for Users and Businesses
Singapore has steadily built one of the most comprehensive digital safety frameworks in Asia, and the Online Safety Act 2026 represents its most ambitious step yet. Building on amendments to the Broadcasting Act and the Online Criminal Harms Act, the 2026 framework broadens the scope of what platforms must do to protect Singapore users from illegal, harmful, and manipulative content. This guide breaks down what the Act covers, who must comply, and what it means for everyday users, content creators, and businesses operating in Singapore.
What Is the Singapore Online Safety Act 2026?
The Singapore Online Safety Act 2026 is a consolidated legislative framework administered by the Infocomm Media Development Authority (IMDA) that regulates online communication services, social media platforms, and app distribution services accessible to users in Singapore. It expands earlier online safety codes to cover a wider range of harms, including scams, deepfakes, doxxing, and content that endangers minors.
The Act does not replace existing laws such as the Protection from Online Falsehoods and Manipulation Act (POFMA) or the Personal Data Protection Act (PDPA). Instead, it sits alongside them, focusing specifically on platform responsibility — the duty of online service providers to design, moderate, and operate their systems in ways that reduce harm to Singapore users.
Why Singapore Introduced the 2026 Framework
Three trends drove the update:
- Rise of AI-generated harm: deepfake scams targeting Singaporeans surged sharply in 2024–2025, especially impersonations of political figures and finance personalities.
- Cross-border scam networks: syndicates using messaging apps and short-form video platforms required a coordinated regulatory response.
- Child safety concerns: growing exposure of minors to grooming, self-harm content, and inappropriate advertising.
Key Provisions of the Act
The Online Safety Act 2026 introduces obligations across six main areas. Understanding these categories helps both users and businesses know what to expect from regulated platforms.
1. Duty of Care for Designated Platforms
Platforms designated by IMDA — typically those with significant reach in Singapore — must implement systems to detect, mitigate, and remove specified categories of harmful content. This includes:
- Sexual content involving minors
- Content promoting terrorism or violent extremism
- Content inciting suicide or self-harm
- Cyberbullying and harassment
- Scam and fraud-related material
- Non-consensual intimate imagery
- AI-generated deceptive content (deepfakes)
2. Content Removal Directions
IMDA can issue binding directions requiring platforms to disable access to specified content within Singapore, often within 24 hours. Non-compliance can lead to access-blocking orders directed at internet service providers.
3. App Store Accountability
App distribution services must ensure listed apps meet Singapore's safety standards, including age ratings, transparent data practices, and removal of apps repeatedly used for scams.
4. Deepfake and Synthetic Media Rules
Platforms must label or restrict AI-generated content that depicts real individuals in misleading ways, particularly during election periods or in financial promotions.
5. Child Safety by Design
Services likely to be accessed by minors must implement age-appropriate defaults: restricted messaging from strangers, limits on targeted advertising, and safer content recommendations.
6. Transparency Reporting
Designated platforms must publish annual reports detailing content moderation actions, response times, and effectiveness of safety features for Singapore users.
Who Must Comply?
Compliance obligations scale with platform size and risk profile. The table below summarizes the main categories.
| Category | Examples | Key Obligations |
|---|---|---|
| Designated Social Media Services | Large global social networks, video platforms | Full duty of care, transparency reports, child safety codes |
| Designated Messaging Services | Major messaging apps used in Singapore | Scam mitigation, reporting tools, cooperation with directions |
| App Distribution Services | Mobile app stores | App vetting, age ratings, removal of harmful apps |
| Smaller Platforms | Niche forums, regional apps | Respond to IMDA directions, remove illegal content |
| Individual Users | Singapore residents | Refrain from posting illegal content; may report harms |
Penalties and Enforcement
The Act gives IMDA a graduated set of enforcement tools, ranging from advisory notices to substantial financial penalties.
Financial Penalties
- Up to SGD 1 million per breach for designated platforms failing to comply with codes of practice.
- Daily penalties for ongoing non-compliance with removal directions.
- Access-blocking orders as a last resort against non-cooperative services.
Criminal Liability
Individuals who create or distribute certain categories of content — such as non-consensual intimate imagery or deepfakes used for fraud — may face criminal charges under related statutes, with penalties including imprisonment.
How the Act Affects Everyday Users
For most Singapore residents, the Online Safety Act 2026 should translate into a safer everyday online experience without significantly changing how they use platforms.
New Rights and Tools
- Easier reporting: platforms must offer clear, in-app pathways to report harmful content, with acknowledgement timelines.
- Faster takedowns: illegal content targeting Singapore users should be removed more quickly.
- Protection from doxxing: victims can request removal of personal information published to harass them.
- Deepfake recourse: individuals impersonated in synthetic media can request labeling or removal.
New Responsibilities
Users should be aware that sharing or amplifying certain categories of content — even without creating it — can carry legal risk. Forwarding scam messages, resharing non-consensual imagery, or spreading known deepfakes may attract enforcement, especially when done deliberately.
Impact on Businesses and Content Creators
Businesses that market, sell, or communicate with Singapore audiences online should treat the Act as a baseline compliance issue, similar to how they treat the PDPA.
Marketing and Advertising
Digital marketers should review creative assets, especially those using AI-generated visuals or endorsements. Misleading synthetic content — for example, a fabricated celebrity endorsement of a financial product — is squarely within scope. Ensure your ad creative is:
- Free of unauthorized likenesses of real people
- Clearly labeled when AI-generated imagery is used in a way that could mislead
- Compliant with age-gating on platforms where minors may be present
- Delivered through reputable, transparent link infrastructure
On the last point, marketers who rely on shortened links for tracking should choose providers that offer transparent redirect behavior, malware scanning, and clear branding. A trusted link management tool such as Lunyb can help teams maintain link hygiene, avoid being flagged as scam-adjacent, and preserve audience trust — a growing concern as platforms tighten scam controls. For a broader comparison of options, see our 2026 URL shortener buyer's guide.
Content Creators and Influencers
Creators producing content for Singapore audiences should:
- Disclose AI-generated segments, especially voice cloning or face swaps
- Avoid parody that could reasonably be mistaken for real statements by public figures
- Implement clear community guidelines and moderate comment sections against harassment
- Keep records of sponsorships and content approvals in case of inquiries
SMEs and E-commerce
Small businesses running e-commerce operations should audit their customer communication channels. Common risk areas include:
- Third-party affiliate links that redirect through suspicious domains
- Unverified user reviews that could constitute manipulation
- Customer service messaging that could be spoofed by scammers impersonating your brand
How the Act Compares to Other Regional Frameworks
Singapore's approach is often compared to the EU Digital Services Act, Australia's Online Safety Act, and the UK Online Safety Act. Each shares the principle of platform duty of care, but the details differ.
| Feature | Singapore OSA 2026 | EU DSA | UK Online Safety Act | Australia OSA |
|---|---|---|---|---|
| Scope | Illegal + specified harms | Illegal + systemic risks | Illegal + harmful to children | Illegal + core harms |
| Regulator | IMDA | European Commission + national | Ofcom | eSafety Commissioner |
| Max Penalty | Up to SGD 1M per breach | Up to 6% global turnover | Up to 10% global turnover | Up to AUD 49.5M |
| Deepfake Rules | Explicit provisions | Covered via transparency | Covered via illegal content | Growing focus |
| Directions Model | Rapid takedown directions | Court/regulator orders | Ofcom notices | Removal notices |
Practical Compliance Checklist for Businesses
Use the following checklist to prepare your organization for the Online Safety Act 2026.
- Map your Singapore footprint: identify which of your services, apps, or communications reach Singapore users.
- Assign accountability: designate a compliance owner responsible for online safety, ideally coordinating with your data protection officer.
- Review content policies: ensure your community guidelines address scams, deepfakes, harassment, and child safety.
- Implement reporting flows: provide simple, accessible reporting tools with defined response timelines.
- Audit AI use: label AI-generated content where it could mislead, and document your synthetic media policies.
- Vet third-party links and ads: check that outbound links, affiliate networks, and ad partners are trustworthy.
- Train staff: run awareness sessions for marketing, product, and customer service teams.
- Prepare a directions-response playbook: know internally how you would respond within 24 hours to an IMDA takedown notice.
Protecting Yourself as a User
While regulation shifts more responsibility onto platforms, individual vigilance remains critical. Consider layered protection:
- Enable two-factor authentication on messaging and social accounts
- Use browsers with strong tracking and phishing protection
- Enable encrypted DNS at the network level to reduce exposure to malicious domains
- Hover over shortened links before clicking, and prefer platforms that show link previews
- Report scams to ScamShield and suspicious content directly through in-app tools
If you frequently share links — whether for work, community groups, or content — using a reputable link platform matters. For a user-perspective look at one option, see our review Is Lunyb Legit? An Honest Review, and if you're evaluating alternatives, our Rebrandly 2026 review covers a well-known enterprise option.
What to Expect Next
IMDA is expected to publish sector-specific codes of practice throughout 2026, including detailed guidance on deepfake labeling, child safety design, and scam disruption. Businesses should monitor consultations and participate where relevant. Enforcement is likely to escalate gradually, with early actions focused on the largest platforms and the most severe harms — particularly financial scams and content targeting minors.
The broader trajectory is clear: Singapore is moving toward a model where trust, transparency, and safety-by-design are not optional add-ons but core requirements for operating online. For users, that should mean fewer scams and faster help when things go wrong. For businesses, it means treating online safety as a first-class operational discipline.
Frequently Asked Questions
Does the Online Safety Act 2026 apply to platforms based outside Singapore?
Yes. The Act applies to any online communication service accessible to end-users in Singapore, regardless of where the provider is headquartered. Designated foreign platforms must comply with codes of practice, respond to directions, and may face access-blocking if they refuse.
Can I be penalized for sharing a scam message with friends?
Casually forwarding a message you didn't realize was a scam is unlikely to trigger enforcement. However, knowingly amplifying scam content, deepfakes, or non-consensual imagery — especially at scale — can attract liability under this Act or related criminal statutes. When in doubt, don't share; report instead.
How is the Act different from POFMA?
POFMA focuses on falsehoods of public interest and allows correction and takedown directions on specific statements. The Online Safety Act 2026 is broader, targeting categories of harmful content (scams, child safety, deepfakes, harassment) and imposing systemic duty-of-care obligations on platforms rather than acting statement-by-statement.
What should small businesses do first to prepare?
Start with three actions: (1) review your website and social channels for content and links that could be misused, (2) tighten customer communication so scammers can't easily impersonate you, and (3) document a simple internal process for responding to takedown requests or complaints within 24 hours.
How do I report harmful content under the Act?
Use the in-app reporting tools on the platform where the content appears — these are required to be accessible and responsive. For serious cases, or when a platform fails to act, you can escalate to IMDA through its online safety reporting channels. Scam-specific content can also be reported to ScamShield and the Singapore Police Force.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.