facebook-pixel

Singapore Online Safety Act 2026: Complete Guide for Businesses and Users

L
Lunyb Security Team
··9 min read

Singapore has steadily tightened its digital regulatory framework over the past decade, and the Online Safety Act 2026 represents the next major milestone in that journey. Building on amendments to the Broadcasting Act and the Online Criminal Harms Act, the 2026 framework consolidates and expands obligations on online platforms, advertisers, and intermediaries operating in or targeting Singapore. This guide breaks down what the Act covers, who it applies to, what the penalties are, and the practical steps businesses and users should take to stay compliant.

What Is the Singapore Online Safety Act 2026?

The Singapore Online Safety Act 2026 is a consolidated piece of legislation administered primarily by the Infocomm Media Development Authority (IMDA) that governs how online services must prevent, detect, and respond to harmful content accessible to users in Singapore. It merges and extends obligations previously spread across the Broadcasting (Amendment) Act 2023, the Online Criminal Harms Act (OCHA), and various codes of practice into a single, more enforceable regime.

The Act focuses on three core pillars: user safety (particularly for minors), platform accountability, and rapid response to egregious harms. Unlike earlier instruments, the 2026 Act gives regulators clearer authority to issue binding directions, impose financial penalties, and require independent audits of safety systems.

Why the Act Was Introduced

Singapore's existing framework was reactive and fragmented. The 2026 Act was introduced in response to:

  1. The rising prevalence of scams, with Singaporeans losing over SGD 1.1 billion to online fraud in recent years.
  2. Growing exposure of minors to harmful content on social media and messaging platforms.
  3. Deepfake-driven misinformation and non-consensual intimate imagery.
  4. The need to align Singapore's rules with international standards such as the EU Digital Services Act and the UK Online Safety Act.

Who Does the Act Apply To?

The Act applies broadly to any online service accessible to end users in Singapore, regardless of where the provider is incorporated. This extraterritorial reach is one of the Act's defining features.

Regulated Entities

  • Designated Online Services (DOS): Large social media services, video-sharing platforms, and messaging apps formally designated by IMDA.
  • App stores: Required to enforce age ratings and remove non-compliant apps.
  • Search engines and content aggregators.
  • Online marketplaces and classifieds that facilitate user-generated listings.
  • Advertising intermediaries that serve ads to Singapore users.
  • URL shorteners, link aggregators, and redirection services are indirectly captured where links lead to prohibited content.

Thresholds for Designation

Not every website is subject to the full set of obligations. IMDA uses thresholds such as monthly active users in Singapore, risk profile, and the service's prominence to decide whether to formally designate it. Smaller services face lighter, principle-based duties, while designated services must comply with detailed codes of practice.

Categories of Harmful Content Covered

The 2026 Act classifies harmful content into tiers, each with distinct response timelines and obligations.

TierContent TypeRequired Response Time
Tier 1 — EgregiousChild sexual exploitation material, terrorism content, incitement to violenceImmediate removal upon notice (within hours)
Tier 2 — SeriousScams, non-consensual intimate imagery, deepfakes, illegal drug promotionWithin 24 hours of a direction
Tier 3 — HarmfulCyberbullying, self-harm promotion, hate speech, dangerous challengesWithin 72 hours or per code of practice
Tier 4 — Age-InappropriateAdult content accessible to minors, gambling promotionsAccess controls and age assurance required

Key Obligations for Platforms

Designated platforms face a comprehensive set of duties under the Act. These are typically operationalized through codes of practice issued by IMDA.

1. Risk Assessment and Safety by Design

Platforms must conduct and document annual risk assessments covering content risks, user demographics (especially minors), and recommendation algorithms. Products must be designed with safety features enabled by default for younger users.

2. Content Moderation Systems

Services must deploy a combination of automated detection and human review, with transparent escalation paths. Moderators handling Singapore content must have appropriate language and cultural capabilities, including coverage of English, Mandarin, Malay, and Tamil.

3. User Reporting and Appeals

Platforms must provide easy, in-product reporting mechanisms and respond within defined timeframes. Users whose content is removed must have access to an appeal process.

4. Age Assurance

Services likely to be accessed by minors must implement proportionate age assurance measures. This can range from self-declaration with behavioural signals to document-based verification for higher-risk services.

5. Transparency Reporting

Designated services must publish semi-annual transparency reports covering takedowns, response times, algorithmic recommendations, and advertising policies.

6. Cooperation with Directions

Platforms must comply with four main types of directions issued by IMDA or the Police:

  • Disabling directions — block access to specific content for Singapore users.
  • Account restriction directions — suspend or restrict offending accounts.
  • App removal directions — require app stores to delist non-compliant apps.
  • Service restriction directions — in extreme cases, require ISPs to block the service entirely.

Penalties and Enforcement

The 2026 Act significantly raises the stakes for non-compliance compared with earlier regimes.

ViolationMaximum Penalty
Failure to comply with a disabling directionUp to SGD 1 million per offence, plus SGD 100,000/day for continuing offences
Breach of code of practiceUp to 10% of annual turnover attributable to Singapore
Failure to implement age assuranceUp to SGD 500,000
Obstructing an investigationFine and/or imprisonment up to 12 months
Senior executive liability (knowing consent)Personal fines and potential imprisonment

Enforcement is tiered. IMDA typically engages first through informal queries, then issues formal directions, and finally pursues financial penalties or service blocking as a last resort.

Impact on Different Stakeholders

For Social Media and Messaging Platforms

Large platforms face the heaviest compliance burden. They must localize safety teams, maintain Singapore-specific transparency reports, and respond to directions within hours. Many have appointed dedicated local representatives, as required by the Act.

For E-commerce and Marketplaces

Scam listings and counterfeit goods fall squarely within the Act's scope. Marketplaces must verify high-risk sellers, enforce know-your-business (KYB) checks, and provide refund pathways for buyers affected by fraud.

For SMEs and Content Publishers

Smaller businesses are not formally designated but must still avoid hosting prohibited content and respond to directions. Many SMEs rely on third-party platforms, which shifts most compliance work upstream, but publishers running comment sections or forums should implement basic moderation.

For URL Shorteners and Link Services

Services that redirect users to third-party pages must have mechanisms to detect and disable links leading to scam, phishing, or egregious content. Reputable providers already scan destinations and honour takedown requests. If you're evaluating link management tools, our 2026 buyer's guide to URL shorteners compares providers on exactly these safety features. Platforms like Lunyb incorporate automated malicious-link detection and rapid takedown workflows, which aligns well with the Act's expectations.

For Everyday Users

Users gain clearer rights: easier reporting, faster takedowns of intimate imagery and scams, and appeal mechanisms when their content is removed. Parents benefit from mandatory safety-by-default settings on services popular with minors.

Compliance Checklist for Businesses

If your organization operates an online service accessible from Singapore, use the following checklist as a starting point.

  1. Map your exposure. Identify which parts of your service involve user-generated content, advertising, or links to third-party sites.
  2. Appoint a local point of contact. Designated services must have a Singapore-based representative authorized to receive directions.
  3. Document a risk assessment. Cover content risks, minor exposure, and algorithmic amplification.
  4. Build a takedown workflow. Define SLAs that meet or beat the tiered response times in the Act.
  5. Deploy age assurance where relevant. Choose proportionate measures based on your risk profile.
  6. Implement transparent reporting. Prepare templates for semi-annual transparency reports.
  7. Train moderators. Ensure linguistic and cultural coverage for Singapore's main languages.
  8. Audit third-party vendors. Shorteners, CDNs, ad networks, and comment plugins should all have aligned safety practices.
  9. Monitor regulatory updates. Codes of practice are updated regularly; subscribe to IMDA notices.

How the Act Compares Internationally

Singapore's approach draws inspiration from several jurisdictions but has its own flavour.

FrameworkPrimary FocusMax PenaltyExtraterritorial?
Singapore Online Safety Act 2026Content harms, scams, child safety10% of SG turnoverYes
EU Digital Services ActSystemic risks, transparency6% of global turnoverYes
UK Online Safety ActIllegal content, child safetyGBP 18m or 10% global turnoverYes
Australia Online Safety ActCyberbullying, image abuseCivil penalties, variesYes

The Singapore regime stands out for its speed of enforcement — directions can take effect within hours — and its tight integration with criminal harms legislation such as OCHA.

Practical Tips for Singapore Users

Even though the heavy lifting falls on platforms, users play an important role in making the Act work.

  • Report harmful content through in-platform tools; most now route directly to safety teams with Singapore SLAs.
  • Verify links before clicking. Hover over shortened URLs or use preview features offered by reputable shorteners.
  • Enable safety settings on social and messaging apps, especially for younger family members.
  • Use encrypted DNS and up-to-date browsers to reduce exposure to phishing and malicious redirects.
  • Keep evidence (screenshots, URLs, timestamps) when reporting scams; this helps investigations.

What's Next After 2026?

IMDA has signalled several areas for future rulemaking, including generative AI-specific duties, stronger provenance requirements for synthetic media, and expanded obligations on advertising intermediaries. Businesses that build robust safety programs now will be well-positioned to adapt. If you manage branded links or short URLs as part of your marketing stack, revisit vendor choices periodically — our Rebrandly 2026 review and comparison pieces are useful starting points for evaluating safety and compliance posture.

Frequently Asked Questions

Does the Singapore Online Safety Act 2026 apply to overseas companies?

Yes. The Act applies to any online service accessible to users in Singapore, regardless of where the company is based. Designated services must appoint a local representative who can receive and act on regulatory directions.

What happens if a platform ignores a disabling direction?

IMDA can impose financial penalties of up to SGD 1 million per offence, with additional daily fines for continuing non-compliance. In serious cases, IMDA can require ISPs to block the entire service for Singapore users and, for app-based services, require app stores to delist them.

How does the Act affect small businesses with a basic website or online store?

Small businesses are generally not formally designated and face lighter, principle-based obligations. You should still avoid hosting illegal content, respond to any directions you receive, and implement basic moderation on user-generated areas like reviews or comments. Using reputable third-party platforms shifts most heavy compliance duties upstream.

Are URL shorteners covered by the Act?

Shorteners are not called out by name but can be captured where their links lead to prohibited content. Responsible providers detect and disable malicious destinations, honour takedown requests promptly, and provide transparency on abuse handling — all of which align with the Act's expectations.

How can users report harmful content under the new regime?

The quickest route is still the in-platform reporting tool, which designated services must now offer with transparent response timelines. Users can also report to the Singapore Police Force for criminal content (such as scams or threats) or to IMDA for broader online safety concerns. Keeping screenshots and URLs helps investigators act faster.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles