facebook-pixel

Singapore Online Safety Act 2026: Complete Guide

L
Lunyb Security Team
··10 min read

Singapore has steadily built one of the most comprehensive digital safety frameworks in the Asia-Pacific region, and the Online Safety Act 2026 represents its most ambitious step yet. Building on amendments to the Broadcasting Act, the Online Criminal Harms Act, and the Protection from Online Falsehoods and Manipulation Act (POFMA), the 2026 updates introduce stricter obligations for platforms, clearer rights for users, and expanded enforcement powers for the Infocomm Media Development Authority (IMDA).

This complete guide explains what the Singapore Online Safety Act 2026 covers, who it applies to, the key compliance requirements, and practical steps individuals and businesses should take now.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 is a consolidated legislative framework that governs how online communication services, social media platforms, and digital intermediaries must prevent, detect, and remove harmful content accessible to users in Singapore. It expands the original Online Safety (Miscellaneous Amendments) Act 2023 by introducing new categories of regulated harms, mandatory reporting duties, and a dedicated statutory body for user complaints.

In short, the Act moves Singapore from a reactive takedown model to a proactive duty-of-care model, similar in philosophy to the UK's Online Safety Act and the EU's Digital Services Act, but tailored to Singapore's multi-racial, multi-religious context and its emphasis on social cohesion.

Why the Act Was Updated in 2026

Three main drivers prompted the 2026 revisions:

  1. Generative AI harms — deepfakes, synthetic intimate imagery, and AI-generated scams have grown sharply since 2024.
  2. Cross-border scam networks — Singapore residents lost over SGD 1 billion to online scams in 2024, prompting tougher platform accountability.
  3. Youth mental health — rising concern about algorithmic amplification of self-harm, eating disorder, and bullying content targeting minors.

Who Must Comply With the Act?

The Act applies to a broad range of service providers, not just large social networks. Any service that enables users in Singapore to communicate, share, or discover user-generated content may be in scope.

Regulated Entities

  • Designated Online Communication Services (DOCS) — large social media platforms formally designated by IMDA (e.g., Meta, TikTok, X, YouTube).
  • Online intermediaries — messaging apps, forums, marketplaces, dating apps, and gaming platforms with Singapore users.
  • App stores — now subject to age-assurance and app-vetting duties.
  • Search services — obligations to deindex specified unlawful content on request.
  • Hosting and cloud providers — limited duties around egregious content and lawful orders.

Extraterritorial Reach

The Act applies to overseas providers if their service is accessible in Singapore and has a material user base there. IMDA can issue directions regardless of where the company is headquartered, and non-compliance can result in access-blocking orders imposed on local internet service providers.

Categories of Regulated Harmful Content

The 2026 Act expands the list of regulated harms into seven clearly defined categories. Each category carries specific removal timelines and reporting duties.

CategoryExamplesRemoval Timeline
Child sexual exploitation materialCSAM, grooming contentImmediate (within hours)
Terrorism and violent extremismAttack glorification, recruitmentWithin 24 hours
Non-consensual intimate imageryRevenge porn, AI-generated deepfakesWithin 24 hours
Cyberbullying and harassmentDoxxing, pile-ons targeting individualsWithin 48 hours of valid report
Scams and fraudInvestment scams, phishing, fake e-commerceWithin 24 hours
Content incitementRacial, religious, or communal hatredWithin 24 hours
Harmful content for minorsSelf-harm promotion, eating disorder contentWithin 48 hours; algorithmic suppression required

Key Obligations for Platforms

Platforms designated under the Act must adopt a layered compliance programme. The following obligations represent the core of what IMDA will audit.

1. Systems and Processes Duty

Platforms must implement proportionate systems to minimise user exposure to harmful content. This includes content moderation policies, trusted flagger programmes, and user controls such as muting, blocking, and sensitivity filters.

2. Risk Assessments

Annual risk assessments are mandatory for DOCS. These must identify foreseeable harms, assess the role of algorithms and recommender systems, and document mitigation measures. Reports must be submitted to IMDA and summarised publicly.

3. Age Assurance for Minors

Services likely to be accessed by children under 18 must deploy age-assurance measures. Pornography sites face stricter age-verification duties (not merely self-declaration), while social platforms must implement default privacy settings and reduced algorithmic exposure for underage accounts.

4. User Reporting and Appeals

Platforms must provide clear, accessible reporting tools and give users the right to appeal moderation decisions. A new Online Safety Commission will act as an independent reviewer where users and platforms disagree.

5. Transparency Reporting

Biannual transparency reports must include takedown volumes, response times, automated versus human moderation ratios, and the use of AI classifiers.

6. Scam-Specific Duties

Reflecting Singapore's scam crisis, platforms must proactively detect impersonation of local banks, government agencies, and public figures, and must share threat intelligence with the Anti-Scam Centre.

Enforcement Powers and Penalties

IMDA's enforcement toolkit has been significantly strengthened under the 2026 Act.

Directions IMDA Can Issue

  • Disabling directions — remove or restrict access to specific content.
  • Account restriction directions — suspend accounts repeatedly linked to harm.
  • Service restriction directions — require ISPs to block services that persistently fail to comply.
  • App removal directions — order app stores to delist non-compliant apps.
  • Code of practice directions — compel adoption of specific technical measures.

Financial Penalties

Maximum fines have increased to the higher of SGD 1 million per contravention or 10% of annual Singapore turnover for the most serious systemic failures. Individual officers of a company can also face fines or imprisonment where there is wilful non-compliance with a lawful direction.

User Rights Under the Act

While much of the Act focuses on platform duties, individual users gain meaningful new rights.

Right to Rapid Takedown of Intimate Imagery

Victims of non-consensual intimate imagery — including AI deepfakes — can request urgent removal through a streamlined IMDA portal. Platforms must act within hours, not days.

Right to Appeal Moderation Decisions

Users whose content or accounts are removed can appeal first to the platform and then to the new Online Safety Commission for independent review.

Right to Information

Platforms must explain why content was removed, which policy was breached, and how to appeal. Automated decisions must disclose that AI was involved.

Right to Child-Safe Defaults

Parents and guardians can expect default protections for minors, including restrictions on direct messages from strangers, no targeted advertising based on sensitive categories, and reduced algorithmic amplification.

Impact on Businesses, Marketers, and Creators

The Act does not only affect global tech giants. Local SMEs, marketing agencies, and content creators also need to adapt their practices.

For E-commerce and Marketplaces

Operators must verify seller identities more rigorously, remove scam listings promptly, and participate in information-sharing with the Anti-Scam Centre. Failure to act on repeated fraud reports can trigger service restriction directions.

For Digital Marketers

Marketers running campaigns targeting Singapore audiences must ensure that creatives do not impersonate officials, do not use deceptive endorsements, and that any shortened or redirect links lead to legitimate destinations. Using a reputable link management tool such as Lunyb helps marketers maintain transparent, traceable URLs and avoid being flagged as suspicious — a growing concern as platforms tighten scam detection. For a broader look at link tools, see our 2026 buyer's guide to URL shorteners.

For Content Creators and Influencers

Creators monetising Singapore audiences should familiarise themselves with the harms list, particularly around minors, harassment, and misleading health or financial claims. Platforms are expected to demote or demonetise content that borders on regulated harms, even where it is not strictly illegal.

How the Act Compares With Other Jurisdictions

Singapore's approach shares DNA with other major online safety regimes but differs in important ways.

FeatureSingapore OSA 2026UK Online Safety ActEU Digital Services Act
Primary regulatorIMDAOfcomEuropean Commission + national coordinators
Max fineSGD 1M or 10% turnover£18M or 10% turnover6% global turnover
Age verificationRequired for adult content; age assurance elsewhereRequired for pornographyRisk-based
Scam-specific dutiesStrong, with Anti-Scam Centre integrationModerateModerate
Communal harmony focusStrong (racial/religious incitement)LimitedLimited
Service blockingYes, via ISPsYes, via court orderRare, last resort

Practical Compliance Checklist for 2026

Whether you run a global platform or a Singapore-focused service, the following checklist captures the most urgent compliance steps.

  1. Map your user base — determine whether you have material Singapore users triggering the Act.
  2. Appoint a local point of contact — IMDA expects a designated representative for communications and directions.
  3. Publish accessible community guidelines — align with the seven harm categories.
  4. Deploy reporting tools — in-product reporting with category selection and status tracking.
  5. Document moderation workflows — including SLAs matching statutory removal timelines.
  6. Implement age-assurance where relevant — plus child-safe defaults.
  7. Run an annual risk assessment — document algorithmic risks and mitigations.
  8. Prepare transparency reports — collect metrics from day one.
  9. Train staff — moderators, trust and safety teams, and senior officers.
  10. Review vendor contracts — ensure moderation vendors, link tools, and ad networks meet your obligations.

What Individuals in Singapore Should Do

Everyday users also benefit from being proactive about their own online safety. A few habits go a long way:

  • Enable two-factor authentication on all critical accounts.
  • Use encrypted DNS and a privacy-respecting browser to reduce tracking.
  • Verify shortened links before clicking — tools like Lunyb provide link previews and safe-browsing checks.
  • Report scams to ScamShield and harmful content directly through platform tools.
  • Talk to children about healthy platform use and the new child-safety defaults.

Frequently Asked Questions

When does the Singapore Online Safety Act 2026 take effect?

The core provisions take effect in phases through 2026, with the most demanding duties — such as mandatory risk assessments and expanded scam-detection obligations — becoming fully enforceable by the end of the year. Designated services receive formal notices from IMDA with specific compliance deadlines.

Does the Act apply to small businesses and local SMEs?

Yes, if a service enables user-to-user communication or user-generated content and is accessible to Singapore users, it falls within scope. However, obligations are proportionate: smaller services face lighter duties than Designated Online Communication Services, focusing mainly on reporting tools, takedown of illegal content, and cooperation with lawful IMDA directions.

How is the Act different from POFMA?

POFMA targets specific false statements of fact that affect the public interest and allows the government to issue correction directions. The Online Safety Act 2026 is broader and systemic — it regulates how platforms design their services to prevent a wide range of harms, rather than focusing on individual pieces of misinformation.

What happens if an overseas platform ignores IMDA directions?

IMDA can escalate from fines to access-blocking orders, requiring Singapore internet service providers to restrict the service, and can direct app stores to delist the app. In serious cases, individual officers may also face personal liability.

How can victims of deepfake intimate imagery get help?

Victims can submit urgent removal requests through IMDA's dedicated portal, report directly to the platform, and seek support from SG Her Empowerment (SHE) and the police. Platforms are required to act within hours and to prevent re-uploads using hash-matching technology.

Conclusion

The Singapore Online Safety Act 2026 is a significant step in global online safety regulation. It balances strong platform accountability with practical user rights, and it reflects Singapore's distinctive emphasis on social cohesion, scam prevention, and child protection. For businesses, early compliance is far cheaper than reactive remediation. For individuals, the Act delivers meaningful new protections — but personal digital hygiene remains essential.

Treat 2026 as the year to professionalise your trust and safety posture, audit your tools and vendors, and build habits that keep both your users and your business on the right side of the law.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles