Major data centres to meet stricter security, resilience rules with the passing of new Bill

Summarise
    • The Keppel Data Centre Campus at 82 Genting Lane.
    • The Keppel Data Centre Campus at 82 Genting Lane. PHOTO: KEPPEL
    Published Wed, Oct 7, 2026 · 03:14 PM

    [SINGAPORE] Large data centres that underpin critical digital services in Singapore will need to account for a range of risks from physical and operational continuity to cyber security with the passing of a new Bill and amendments to an existing law.

    The Digital Infrastructure Bill, passed in Parliament on Oct 7, seeks to ensure energy efficiency and operational resilience - including physical security and recovery from system misconfiguration, fire, flood and power supply cuts - through licensing.

    Amendments to the existing Cybersecurity Act will also subject most major data centres to similar cyber-incident reporting requirements currently enforced on critical information infrastructure operators here.

    Speaking during the debate on the Bill, supported by all MPs, Senior Minister of State for Digital Development and Information Tan Kiat How said: “Many different digital services often rely on the same data centre or cloud service provider. When it is disrupted, the impact is not confined to one digital service. Many services can be affected at once, and the impact can quickly ripple across our economy and society.”

    About two-thirds of the 70 data centres here cross specific revenue or electrical capacity thresholds under the new Bill. These thresholds are: an average annual revenue from users in Singapore over three years of at least S$100 million, or operations requiring at least 10 megawatts (MW) of electrical capacity.

    The authorities did not name the firms, but those operating in Singapore matching this scale include Amazon Web Services, Microsoft Azure and Google Cloud Platform.

    The Business Times turns 50

    Five decades of milestones and moments that shaped Singapore’s success story - told through our headlines.

    Explore BT50

    Many of these major data centres will also be caught under the amended Cybersecurity Act.

    During the five-hour debate on the new Bill spanning Oct 6 and 7, a total of 19 MPs spoke about data centres’ economic value and their impact on Singapore’s competitiveness and jobs here, as well as plans for older facilities, sustainability, security and resilience.

    MPs like Sharael Taha (Pasir Ris-Changi GRC) and Saktiandi Supaat (Bishan-Toa Payoh GRC) asked whether the new requirements could weaken Singapore’s competitiveness and drive investments to regional rivals.

    Nominated MP Neo Kok Beng and Shawn Loh (Jalan Besar GRC) asked if support would be provided to upgrade older data centres, while Lee Hui Ying (Nee Soon GRC) asked how Singaporeans would be upskilled to meet the sector’s growing needs.

    Tan said that a sharp rise in demand for computing power to support artificial intelligence (AI) applications has made data centre development a contested and politicised issue in many countries.

    Some countries have had to formulate responses after rapid data centre growth exerted pressures on electricity, water, and land. In 2026, Thailand froze approvals for new data centre projects to develop national standards, while Spain and Australia are working on legislation for data centres.

    Similarly, Singapore needs to plan ahead with its limited land, power and water.

    “We plan ahead...so that we can create as much room as possible for our digital economy and society, as well as AI ambitions while staying within our resource and environmental constraints,” said Tan.

    Singapore currently has over 1.6 gigawatts of existing data centre capacity, across about 70 data centres. The figure includes 200MW of new capacity awarded to four operators in August 2026.

    Tan pointed out that the Bill provides businesses certainty by setting out the regulatory clearly, while also giving the Government the flexibility to calibrate detailed security, resilience and sustainability requirements as circumstances evolve.

    The Bill will introduce two licences: foundational digital infrastructure (FDI) and data centre (DC) licences.

    Data centres that require 10MW of electrical power to operate essential computing equipment like servers, storage drives and networking hardware will need an FDI licence. Cloud service providers that generate more than an average annual revenue of S$100 million from Singapore users over three years will also need to apply for an FDI licence.

    FDI licencees will have to implement process to ensure the physical and cyber security of their services, put in place business continuity and disaster recovery plans to ensure essential operations can keep going during disruptions, and notify Infocomm Media Development Authority (IMDA) of prescribed cybersecurity incidents or service disruptions.

    Details, which are still being worked out, will be introduced in subsidiary regulations and Codes of Practices.

    Where reporting requirements for cyber security incidents are similar, IMDA will be the main port of call, and it will share information with the Cyber Security Agency of Singapore.

    A data centre will need a DC licence if it uses at least 3MW of electricity to power essential computing equipment like servers, storage drives and networking hardware. DC licensees will need to meet power usage effectiveness (PUE) requirements that have yet to be determined.

    PUE measures how efficiently a data centre uses energy, with a perfect score of 1. Data centre contracts awarded to operators in July 2023 had a PUE requirement of 1.3. Proposals selected in August 2026 had a requirement of 1.25.

    “PUE is a useful starting point, but it does not capture every dimension of sustainability. Efficiency tells us how well a facility uses resources; we must also keep an eye on the sector’s overall use of electricity and water,” said Tan, adding that equipment-level energy efficiency and plant-level water efficiency may be considered in future.

    He acknowledged that these requirements will be more challenging to meet for older data centres. Noting that some operators may need transition time, he committed to work with them.

    Additionally, data centre operators that fail to deliver on economic commitments made to secure scarce capacity in Singapore could face enforcement action. These promises, such as investments, job creation and research, can be made conditions of their licences, he said.

    IMDA will work with the Economic Development Board to resolve any alleged lapses.

    Tan said that this reflects Singapore’s approach to maximise value from Singapore’s limited computing capacity.

    “We are not seeking to attract every megawatt of data centre capacity we can... Scarce capacity should not simply be allocated; it should be put to productive use and deliver the value that was promised,” said Tan.

    The Bill empowers IMDA to impose a fine of up to S$1 million, or up to 10 per cent of a firm’s annual turnover in Singapore, whichever is higher, for failing to meet cybersecurity and business continuity requirements. THE STRAITS TIMES

    Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.

    Share with us your feedback on BT's products and services