Singapore’s Digital Infrastructure Bill was first introduced in Parliament on 8 September 2026 and was passed on 7 October 2026. Senior Minister of State for Digital Development and Information Tan Kiat How noted that the upcoming regime reflects Singapore’s need to balance growth in AI and digital services with constraints on land, power and water. Set out below is a summary of the key implications for data centre and cloud businesses arising under the Digital Infrastructure Act (DIA) once it takes effect.
Key implications
New DIA regime dovetails with requirements under the Cybersecurity Act
Businesses should continue to monitor for further updates to sector-specific licensing, security risk management, business continuity, disaster recovery and incident-reporting obligations for major data centres and cloud service providers to be published under the DIA. These will supplement existing requirements under the Cybersecurity Act. Source: CSA
Core thresholds are retained
The major foundational digital infrastructure (FDI) licence will apply to co-location and cloud data centres with at least 10 MW of critical IT load, as well as IaaS or PaaS providers averaging at least SGD100 million in annual Singapore revenue over the preceding three years. For now, SaaS and data centres used solely for an operator’s internal purposes remain outside that regime. The data centre (DC) licence will be required by all operators of data centres with at least 3 MW of critical IT load.
Scope for licensing has broadened
The Digital Infrastructure Bill means that qualifying operators may now require more than one licence; a major foundational digital infrastructure (FDI) licence aimed at strengthening the security and resilience of major cloud services and data centres, and a data centre (DC) licence directed at environmental sustainability. Source: Straits Times
Potential enforceability necessitates strategic consideration
Conditions under the Digital Infrastructure Bill include the enforceability of strategic, economic and green-energy commitments through licence conditions; a requirement for licensees to notify IMDA within seven days of specified changes in control or business ownership; and penalties for serious breaches of up to SGD 1 million or 10% of annual Singapore turnover, whichever is higher.
Specific legal considerations for businesses in the data centre ecosystem
Singapore currently has approximately 70 data centres, and more than 60% will be impacted when this Bill comes into effect. The increased legislative pace and rigour across the broader data centre ecosystem and landscape point to heightened risk for data centre owners and operators, cloud providers, technology and infrastructure partners, investors and lenders.
- Licensed operators should prioritise establishing regulatory readiness. Data centre owners and major IaaS and PaaS providers should confirm applicable thresholds, exemptions and dual-licensing exposure, then align their cybersecurity, incident reporting, resilience and sustainability controls with the Bill and the Cybersecurity Act.
- Technology and infrastructure partners must manage contractual exposure. Managed-service, connectivity, facilities, energy, water, property and engineering providers should review service levels, audit and cooperation rights, outage liability, data transfers, third-party dependencies and the allocation of efficiency and change-in-law costs.
Investors and counterparties should protect continuity and deal value: Cloud-dependent organisations, lenders, insurers, sponsors and investors should assess concentration and continuity risk, test licensing compliance, evaluate the feasibility and cost-implications of implementing facility-level and operational changes to meet the new water and energy efficiency requirements under the data centre (DC) licence regime, and address change-of-control approvals, regulatory costs and liability in due diligence, contracts and financing terms.
- Technology and infrastructure partners must manage contractual exposure. Managed-service, connectivity, facilities, energy, water, property and engineering providers should review service levels, audit and cooperation rights, outage liability, data transfers, third-party dependencies and the allocation of efficiency and change-in-law costs.
Ultimately, businesses can reduce risk and improve long-term certainty by assigning clear responsibility at board and senior management level. Seeking integrated legal advice across transactional, cybersecurity, data, energy and funding silos can future-proof business growth plans. Speak with us today.
Related links:
- IMDA Advisory Guidelines for resilience and security of Cloud Services
- IMDA Advisory Guidelines for resilience and security of Data Centres
- Singapore passes stricter data centre security Bill | The Straits Times
- Singapore’s AI Blueprint: Balancing innovation, risk and regional opportunity
- Artificial Intelligence | Linklaters
- Technology Sector | Linklaters
- Private Capital’s Lean Towards AI
- Hong Kong SAR's AI agenda: key takeaways from the 2026 Policy Address and first Five-Year Plan
- Agentic AI and Data Privacy: Hong Kong SAR’s Regulator Sets Out What Businesses Should Do

/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-07-01-10-05-52-711-6a44e6804d141be5967eb61e.jpg)
/Passle/5c4b4157989b6f1634166cf2/SearchServiceImages/2026-10-07-11-24-32-254-6ac62bf058292ff9138a031f.jpg)
/Passle/5c4b4157989b6f1634166cf2/MediaLibrary/Images/2026-03-16-09-26-04-830-69b7ccac0f5150d9ca0d7301.jpeg)
/Passle/5c4b4157989b6f1634166cf2/SearchServiceImages/2026-09-23-08-15-08-251-6ab38a8c5e1b49f97c2c5ab2.jpg)
