Singapore Online Safety Act 2026: Complete Guide
Singapore has steadily built one of the most comprehensive digital safety frameworks in the Asia-Pacific region, and the Online Safety Act 2026 represents its most ambitious step yet. Building on amendments to the Broadcasting Act, the Online Criminal Harms Act, and the Protection from Online Falsehoods and Manipulation Act (POFMA), the 2026 updates introduce stricter obligations for platforms, clearer rights for users, and expanded enforcement powers for the Infocomm Media Development Authority (IMDA).
This complete guide explains what the Singapore Online Safety Act 2026 covers, who it applies to, the key compliance requirements, and practical steps individuals and businesses should take now.
What Is the Singapore Online Safety Act 2026?
The Singapore Online Safety Act 2026 is a consolidated legislative framework that governs how online communication services, social media platforms, and digital intermediaries must prevent, detect, and remove harmful content accessible to users in Singapore. It expands the original Online Safety (Miscellaneous Amendments) Act 2023 by introducing new categories of regulated harms, mandatory reporting duties, and a dedicated statutory body for user complaints.
In short, the Act moves Singapore from a reactive takedown model to a proactive duty-of-care model, similar in philosophy to the UK's Online Safety Act and the EU's Digital Services Act, but tailored to Singapore's multi-racial, multi-religious context and its emphasis on social cohesion.
Why the Act Was Updated in 2026
Three main drivers prompted the 2026 revisions:
- Generative AI harms — deepfakes, synthetic intimate imagery, and AI-generated scams have grown sharply since 2024.
- Cross-border scam networks — Singapore residents lost over SGD 1 billion to online scams in 2024, prompting tougher platform accountability.
- Youth mental health — rising concern about algorithmic amplification of self-harm, eating disorder, and bullying content targeting minors.
Who Must Comply With the Act?
The Act applies to a broad range of service providers, not just large social networks. Any service that enables users in Singapore to communicate, share, or discover user-generated content may be in scope.
Regulated Entities
- Designated Online Communication Services (DOCS) — large social media platforms formally designated by IMDA (e.g., Meta, TikTok, X, YouTube).
- Online intermediaries — messaging apps, forums, marketplaces, dating apps, and gaming platforms with Singapore users.
- App stores — now subject to age-assurance and app-vetting duties.
- Search services — obligations to deindex specified unlawful content on request.
- Hosting and cloud providers — limited duties around egregious content and lawful orders.
Extraterritorial Reach
The Act applies to overseas providers if their service is accessible in Singapore and has a material user base there. IMDA can issue directions regardless of where the company is headquartered, and non-compliance can result in access-blocking orders imposed on local internet service providers.
Categories of Regulated Harmful Content
The 2026 Act expands the list of regulated harms into seven clearly defined categories. Each category carries specific removal timelines and reporting duties.
| Category | Examples | Removal Timeline |
|---|---|---|
| Child sexual exploitation material | CSAM, grooming content | Immediate (within hours) |
| Terrorism and violent extremism | Attack glorification, recruitment | Within 24 hours |
| Non-consensual intimate imagery | Revenge porn, AI-generated deepfakes | Within 24 hours |
| Cyberbullying and harassment | Doxxing, pile-ons targeting individuals | Within 48 hours of valid report |
| Scams and fraud | Investment scams, phishing, fake e-commerce | Within 24 hours |
| Content incitement | Racial, religious, or communal hatred | Within 24 hours |
| Harmful content for minors | Self-harm promotion, eating disorder content | Within 48 hours; algorithmic suppression required |
Key Obligations for Platforms
Platforms designated under the Act must adopt a layered compliance programme. The following obligations represent the core of what IMDA will audit.
1. Systems and Processes Duty
Platforms must implement proportionate systems to minimise user exposure to harmful content. This includes content moderation policies, trusted flagger programmes, and user controls such as muting, blocking, and sensitivity filters.
2. Risk Assessments
Annual risk assessments are mandatory for DOCS. These must identify foreseeable harms, assess the role of algorithms and recommender systems, and document mitigation measures. Reports must be submitted to IMDA and summarised publicly.
3. Age Assurance for Minors
Services likely to be accessed by children under 18 must deploy age-assurance measures. Pornography sites face stricter age-verification duties (not merely self-declaration), while social platforms must implement default privacy settings and reduced algorithmic exposure for underage accounts.
4. User Reporting and Appeals
Platforms must provide clear, accessible reporting tools and give users the right to appeal moderation decisions. A new Online Safety Commission will act as an independent reviewer where users and platforms disagree.
5. Transparency Reporting
Biannual transparency reports must include takedown volumes, response times, automated versus human moderation ratios, and the use of AI classifiers.
6. Scam-Specific Duties
Reflecting Singapore's scam crisis, platforms must proactively detect impersonation of local banks, government agencies, and public figures, and must share threat intelligence with the Anti-Scam Centre.
Enforcement Powers and Penalties
IMDA's enforcement toolkit has been significantly strengthened under the 2026 Act.
Directions IMDA Can Issue
- Disabling directions — remove or restrict access to specific content.
- Account restriction directions — suspend accounts repeatedly linked to harm.
- Service restriction directions — require ISPs to block services that persistently fail to comply.
- App removal directions — order app stores to delist non-compliant apps.
- Code of practice directions — compel adoption of specific technical measures.
Financial Penalties
Maximum fines have increased to the higher of SGD 1 million per contravention or 10% of annual Singapore turnover for the most serious systemic failures. Individual officers of a company can also face fines or imprisonment where there is wilful non-compliance with a lawful direction.
User Rights Under the Act
While much of the Act focuses on platform duties, individual users gain meaningful new rights.
Right to Rapid Takedown of Intimate Imagery
Victims of non-consensual intimate imagery — including AI deepfakes — can request urgent removal through a streamlined IMDA portal. Platforms must act within hours, not days.
Right to Appeal Moderation Decisions
Users whose content or accounts are removed can appeal first to the platform and then to the new Online Safety Commission for independent review.
Right to Information
Platforms must explain why content was removed, which policy was breached, and how to appeal. Automated decisions must disclose that AI was involved.
Right to Child-Safe Defaults
Parents and guardians can expect default protections for minors, including restrictions on direct messages from strangers, no targeted advertising based on sensitive categories, and reduced algorithmic amplification.
Impact on Businesses, Marketers, and Creators
The Act does not only affect global tech giants. Local SMEs, marketing agencies, and content creators also need to adapt their practices.
For E-commerce and Marketplaces
Operators must verify seller identities more rigorously, remove scam listings promptly, and participate in information-sharing with the Anti-Scam Centre. Failure to act on repeated fraud reports can trigger service restriction directions.
For Digital Marketers
Marketers running campaigns targeting Singapore audiences must ensure that creatives do not impersonate officials, do not use deceptive endorsements, and that any shortened or redirect links lead to legitimate destinations. Using a reputable link management tool such as Lunyb helps marketers maintain transparent, traceable URLs and avoid being flagged as suspicious — a growing concern as platforms tighten scam detection. For a broader look at link tools, see our 2026 buyer's guide to URL shorteners.
For Content Creators and Influencers
Creators monetising Singapore audiences should familiarise themselves with the harms list, particularly around minors, harassment, and misleading health or financial claims. Platforms are expected to demote or demonetise content that borders on regulated harms, even where it is not strictly illegal.
How the Act Compares With Other Jurisdictions
Singapore's approach shares DNA with other major online safety regimes but differs in important ways.
| Feature | Singapore OSA 2026 | UK Online Safety Act | EU Digital Services Act |
|---|---|---|---|
| Primary regulator | IMDA | Ofcom | European Commission + national coordinators |
| Max fine | SGD 1M or 10% turnover | £18M or 10% turnover | 6% global turnover |
| Age verification | Required for adult content; age assurance elsewhere | Required for pornography | Risk-based |
| Scam-specific duties | Strong, with Anti-Scam Centre integration | Moderate | Moderate |
| Communal harmony focus | Strong (racial/religious incitement) | Limited | Limited |
| Service blocking | Yes, via ISPs | Yes, via court order | Rare, last resort |
Practical Compliance Checklist for 2026
Whether you run a global platform or a Singapore-focused service, the following checklist captures the most urgent compliance steps.
- Map your user base — determine whether you have material Singapore users triggering the Act.
- Appoint a local point of contact — IMDA expects a designated representative for communications and directions.
- Publish accessible community guidelines — align with the seven harm categories.
- Deploy reporting tools — in-product reporting with category selection and status tracking.
- Document moderation workflows — including SLAs matching statutory removal timelines.
- Implement age-assurance where relevant — plus child-safe defaults.
- Run an annual risk assessment — document algorithmic risks and mitigations.
- Prepare transparency reports — collect metrics from day one.
- Train staff — moderators, trust and safety teams, and senior officers.
- Review vendor contracts — ensure moderation vendors, link tools, and ad networks meet your obligations.
What Individuals in Singapore Should Do
Everyday users also benefit from being proactive about their own online safety. A few habits go a long way:
- Enable two-factor authentication on all critical accounts.
- Use encrypted DNS and a privacy-respecting browser to reduce tracking.
- Verify shortened links before clicking — tools like Lunyb provide link previews and safe-browsing checks.
- Report scams to ScamShield and harmful content directly through platform tools.
- Talk to children about healthy platform use and the new child-safety defaults.
Frequently Asked Questions
When does the Singapore Online Safety Act 2026 take effect?
The core provisions take effect in phases through 2026, with the most demanding duties — such as mandatory risk assessments and expanded scam-detection obligations — becoming fully enforceable by the end of the year. Designated services receive formal notices from IMDA with specific compliance deadlines.
Does the Act apply to small businesses and local SMEs?
Yes, if a service enables user-to-user communication or user-generated content and is accessible to Singapore users, it falls within scope. However, obligations are proportionate: smaller services face lighter duties than Designated Online Communication Services, focusing mainly on reporting tools, takedown of illegal content, and cooperation with lawful IMDA directions.
How is the Act different from POFMA?
POFMA targets specific false statements of fact that affect the public interest and allows the government to issue correction directions. The Online Safety Act 2026 is broader and systemic — it regulates how platforms design their services to prevent a wide range of harms, rather than focusing on individual pieces of misinformation.
What happens if an overseas platform ignores IMDA directions?
IMDA can escalate from fines to access-blocking orders, requiring Singapore internet service providers to restrict the service, and can direct app stores to delist the app. In serious cases, individual officers may also face personal liability.
How can victims of deepfake intimate imagery get help?
Victims can submit urgent removal requests through IMDA's dedicated portal, report directly to the platform, and seek support from SG Her Empowerment (SHE) and the police. Platforms are required to act within hours and to prevent re-uploads using hash-matching technology.
Conclusion
The Singapore Online Safety Act 2026 is a significant step in global online safety regulation. It balances strong platform accountability with practical user rights, and it reflects Singapore's distinctive emphasis on social cohesion, scam prevention, and child protection. For businesses, early compliance is far cheaper than reactive remediation. For individuals, the Act delivers meaningful new protections — but personal digital hygiene remains essential.
Treat 2026 as the year to professionalise your trust and safety posture, audit your tools and vendors, and build habits that keep both your users and your business on the right side of the law.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
GDPR gives everyone in Ireland powerful rights over their personal data, from access and erasure to portability and objection. This guide explains each right in plain English, how to enforce it through the Data Protection Commission, and practical steps to protect your privacy online.
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 reshapes how online platforms, advertisers, and intermediaries handle harmful content. This complete guide covers scope, obligations, penalties, and practical compliance steps for businesses and users in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to data privacy for Canadian businesses — covering PIPEDA, Quebec Law 25, consent, breach response, vendor management, and CPPA preparation. Learn exactly what to implement to stay compliant and build customer trust.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Canadian privacy law has changed dramatically with Bill C-27, Quebec's Law 25, and expanded provincial rules. This 2026 guide explains your rights, business obligations, and practical steps to protect personal information in the digital age.