facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Users and Businesses

L
Lunyb Security Team
··9 min read

Singapore has long taken a proactive stance on digital regulation, and the Online Safety Act 2026 represents its most ambitious effort yet to make the internet safer for residents, businesses, and children. Building on the foundations of the 2022 Online Safety (Miscellaneous Amendments) Act and the Code of Practice for Online Safety, the 2026 update expands scope, tightens obligations, and introduces new enforcement powers that affect nearly every platform accessible from Singapore.

Whether you run a small e-commerce store, manage a social media presence, or simply share links online, understanding this legislation is essential. This complete guide breaks down what the Act means, who it applies to, what compliance looks like, and how you can protect yourself and your users in 2026.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 is a comprehensive law administered by the Infocomm Media Development Authority (IMDA) that regulates how online services handle harmful content, protect minors, and respond to government directives. It builds on earlier online safety amendments to the Broadcasting Act and consolidates rules into a single, modernised framework.

At its core, the Act aims to achieve four outcomes:

  1. Reduce exposure to egregious content such as child sexual exploitation material, terrorism content, and incitement of violence.
  2. Protect children and young users from age-inappropriate material and predatory behaviour.
  3. Give users clear tools to report harm and receive timely responses.
  4. Hold platforms accountable through transparency reporting and enforceable directions.

Key Differences from the 2022 Framework

The 2026 iteration expands coverage from designated "Online Communication Services" (mainly social media) to include app stores, private messaging providers, generative AI services, and link-sharing tools. It also introduces mandatory age assurance for services likely to be accessed by minors and stronger duties around scam prevention — a growing concern in Singapore.

Who Must Comply with the Act?

The Act uses a tiered approach based on service type, user base in Singapore, and risk profile. Understanding which tier you fall into determines your specific obligations.

CategoryExamplesCore Obligations
Designated Online Communication ServicesLarge social networks, video platforms with significant SG reachFull Code of Practice compliance, annual transparency reports, dedicated SG contact
App Distribution ServicesMobile app storesAge ratings enforcement, removal of non-compliant apps, developer verification
Generative AI ServicesChatbots, image generators available to SG usersContent provenance labelling, harmful-output safeguards, minor protection
Small & Medium PlatformsNiche forums, SME websites, link toolsNotice-and-action mechanisms, cooperation with IMDA directions
End UsersIndividuals sharing content or linksDo not distribute prohibited content; comply with removal orders

Extraterritorial Reach

Like the earlier framework, the 2026 Act applies to any service accessible from Singapore, regardless of where the provider is headquartered. If your platform has meaningful Singapore users, you are within scope — even without a local office.

Categories of Harmful Content Under the Act

The Act defines several categories of "harmful content," and the required response speed depends on severity. The most serious categories must be addressed within hours of notification.

Egregious Content (Immediate Action Required)

  • Child sexual exploitation and abuse material
  • Terrorism content, including recruitment and propaganda
  • Content inciting violence against individuals or groups
  • Content endangering public health or public security
  • Non-consensual intimate imagery

Content Harmful to Children

  • Sexual content and nudity
  • Graphic violence
  • Content promoting self-harm, suicide, or eating disorders
  • Cyberbullying material targeting minors
  • Content promoting dangerous challenges

Scam and Malicious Cyber Activity Content

A major addition in 2026 is the explicit inclusion of scam content — phishing pages, fake investment schemes, impersonation of government agencies, and malicious links. Platforms must have systems to detect and disable such content promptly, and link-sharing services must implement anti-abuse controls.

New Enforcement Powers in 2026

The IMDA has been given a stronger toolkit under the 2026 Act. These powers can be used against both platforms and individuals who repeatedly distribute prohibited content.

  1. Disabling Directions: Order a service to block specific content from being accessed in Singapore.
  2. Access Blocking Directions: Instruct internet access service providers to block entire non-compliant services.
  3. App Removal Directions: Require app stores to delist non-compliant apps for Singapore users.
  4. Account Restriction Directions: Require suspension of accounts responsible for repeated violations.
  5. Information Requests: Compel platforms to hand over information necessary for investigations.

Penalties for Non-Compliance

Financial penalties have been significantly increased. Designated services can face fines of up to SGD 1 million per breach, with additional daily penalties for ongoing non-compliance. Directors and senior officers can be personally liable in cases of wilful disregard, and criminal penalties apply for the most serious offences.

Age Assurance and Child Safety Requirements

One of the most discussed elements of the 2026 Act is mandatory age assurance for services "likely to be accessed by children." This does not mean every website needs strict age verification, but risk-based measures are required.

Acceptable Age Assurance Methods

  • Self-declaration combined with behavioural signals (low-risk services)
  • Age estimation using AI-based facial analysis (medium-risk)
  • Government-issued ID verification or Singpass integration (high-risk services such as adult content or gambling)
  • Parental consent flows for users identified as under 13

Default Safety Settings for Minors

Where a user is identified as a minor, platforms must apply protective defaults: private accounts, restricted direct messaging from strangers, disabled targeted advertising, and limited exposure to algorithmically recommended content from unknown sources.

Implications for Businesses in Singapore

Even if your business is not a social media giant, the Act likely affects you. E-commerce sites with review sections, community forums, marketing platforms, and any service that hosts user-generated content or shares links must reassess their processes.

Compliance Checklist for SMEs

  1. Map your content flows. Identify where user-generated content or shared links appear on your service.
  2. Publish clear community guidelines. Users must know what is and isn't allowed.
  3. Implement a reporting mechanism. Provide an easy way for users to flag harmful content, with acknowledgement and status updates.
  4. Set response timeframes. Egregious content should be actioned within hours; other harmful content within 24–72 hours.
  5. Keep logs. Maintain records of reports, actions taken, and IMDA correspondence for at least 12 months.
  6. Appoint a responsible officer. A named contact for online safety matters is expected, even in smaller organisations.
  7. Review vendor contracts. Ensure your hosting, CDN, and link-sharing providers have their own safeguards.

What the Act Means for Link Sharing and URL Shorteners

Shortened links have historically been abused to disguise phishing pages and scam destinations. The 2026 Act makes clear that link-sharing services with Singapore users must implement anti-abuse safeguards, including malware scanning, phishing detection, and mechanisms to disable links reported as harmful.

For businesses that rely on branded short links, this reinforces the importance of using a reputable provider that takes safety seriously. Platforms like Lunyb incorporate link scanning, abuse reporting, and analytics that help you monitor whether your links are being flagged or misused. If you are evaluating options, our 2026 buyer's guide to URL shorteners compares the main providers on safety, features, and pricing, and our honest review of Lunyb explains how the service handles trust and safety.

Best Practices for Safe Link Sharing

  • Use branded short domains so recipients can recognise legitimate senders.
  • Enable link previews wherever your platform supports them.
  • Avoid stacking multiple redirects, which obscures the final destination.
  • Rotate or disable old campaign links once they are no longer needed.
  • Monitor click analytics for unusual traffic patterns that may indicate abuse.

What the Act Means for Individual Users

For everyday users in Singapore, the Act provides new rights but also reinforces personal responsibility. You have stronger tools to report harmful content, request removal of intimate imagery, and appeal moderation decisions. At the same time, distributing prohibited content — even by sharing a link — can attract enforcement action.

How to Report Harmful Content

  1. Use the platform's in-app reporting tools first; these are now mandated to be visible and easy to find.
  2. Capture screenshots and URLs before content is removed, in case escalation is needed.
  3. If a platform fails to respond appropriately, escalate to the IMDA via their online safety portal.
  4. For urgent threats to life or safety, contact the Singapore Police Force directly.

Privacy Considerations Under the Act

Stronger safety measures can create tension with privacy. Age assurance, content scanning, and information requests all involve processing personal data. The Act works alongside the Personal Data Protection Act (PDPA), meaning platforms must implement safety measures in a way that is proportionate and minimises unnecessary data collection.

User Protections

  • Age estimation data should not be retained longer than necessary.
  • Content scanning should focus on illegal material, not general surveillance.
  • Users have the right to appeal automated moderation decisions.
  • Transparency reports must disclose the volume and nature of government requests.

Preparing Your Organisation: A 90-Day Roadmap

If you are starting compliance work now, a structured plan helps prioritise the most important actions first.

Days 1–30: Assessment

  • Determine which tier of the Act applies to your service.
  • Audit existing policies, reporting tools, and moderation processes.
  • Identify gaps against the Code of Practice.

Days 31–60: Implementation

  • Update terms of service and community guidelines.
  • Deploy or upgrade reporting mechanisms.
  • Train moderation staff on the new categories and timelines.
  • Integrate age assurance where required.

Days 61–90: Testing and Documentation

  • Run simulated content-reporting drills.
  • Document policies, decision logs, and escalation paths.
  • Prepare a transparency report template.
  • Establish a communication channel with IMDA.

Frequently Asked Questions

Does the Singapore Online Safety Act 2026 apply to overseas businesses?

Yes. The Act applies to any online service accessible from Singapore that has Singapore users, regardless of where the business is registered. Overseas providers with significant local reach may be formally designated and face the full Code of Practice obligations.

What happens if my small business receives an IMDA disabling direction?

You must act within the timeframe specified in the direction — typically 24 hours for serious content, shorter for egregious material. Ignoring a direction can result in fines and, for repeat non-compliance, access blocking of your service in Singapore. Seek legal advice if the scope of the direction is unclear.

Do I need age verification on my website?

Only if your service is likely to be accessed by children and hosts content that could harm them. Low-risk business websites usually do not need formal verification, but services with adult content, gambling, or high-risk features must implement robust age assurance such as Singpass or ID verification.

How does the Act affect URL shorteners and link-sharing?

Link-sharing services must implement safeguards against abuse, including malware and phishing detection, and be able to disable harmful links promptly. Users and businesses should choose providers that publish clear abuse policies and offer analytics to monitor link performance and integrity.

Where can I find the official Code of Practice?

The Code of Practice for Online Safety is published by the IMDA on their official website. Designated services receive additional guidance directly, and consultations are typically opened before significant amendments so stakeholders can provide input.

Final Thoughts

The Singapore Online Safety Act 2026 is not just a compliance burden — it reflects a broader shift toward accountable, user-centric digital services. Businesses that treat online safety as a core product concern rather than a checkbox will find compliance easier and build stronger trust with Singaporean users. Whether you operate a global platform or a local SME, now is the time to review your policies, upgrade your tools, and choose partners who take safety as seriously as you do.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles