Public Consultation on the Digital Infrastructure Bill
8 September 2026
Consultation Outcome
Background
The Ministry of Digital Development and Information (MDDI) and the Infocomm Media Development Authority (IMDA) conducted a public consultation from 1 July to 22 July 2026 on the draft Digital Infrastructure Bill (Bill).
Digital infrastructure is foundational to Singapore’s economy and society, underpinning the essential services that Singaporeans and businesses rely on daily to work, transact and connect – from banking and healthcare to transport, government services, and communications. As digital infrastructure becomes increasingly critical, there is a need to ensure its secure and reliable functioning to reduce the risks and mitigate the impact of disruptions. There is also a need to support the sustainable growth of Data Centres (DCs) in Singapore given Singapore’s scarce natural resources. MDDI and IMDA are therefore introducing the Bill to uplift security, resilience, and sustainability standards across the digital infrastructure sector.
The Bill will establish two licensing regimes to ensure (i) the security and resilience of major DCs and Cloud Service Providers (CSPs); and (ii) the environmental sustainability of DC operations. Licensees under the respective licensing regimes will be required to implement specific security and resilience, and sustainability requirements to be set out in subsequent instruments.
Summary of Responses
At the close of the public consultation, MDDI and IMDA received responses from 25 respondents.
Overall, respondents were supportive of the Bill’s overarching policy objectives of uplifting the security and resilience of major foundational digital infrastructure (FDI) services and the environmental sustainability of DC operations in Singapore. They recognised it was important to do so given the foundational role of digital infrastructure in supporting a growing range of digital activities, and the need to grow the DC sector sustainably such that Singapore’s scarce natural resources are managed responsibly as compute demand grows.
Most of the feedback were on the licensing regimes for major FDI service providers and DC operators, and how the eventual Digital Infrastructure Act (DIA) would be operationalised (such as the security, resilience, and sustainability requirements on licensees; and harmonisation with the Cybersecurity (CS) Act). Respondents also commented on other matters in the Bill such as the notification requirements for ownership changes, enforcement powers, and transitional provisions.
MDDI and IMDA thank the respondents for their constructive feedback and have made adjustments to the Bill where appropriate. We recognise the need to implement the DIA in a manner that is proportionate and pragmatic, and the feedback received will help inform how the regulatory framework should be implemented. We will continue our engagements with CSPs and DC operators on the final requirements, transition arrangements, and streamlining of regulatory and administrative processes, among other matters.
More details of the feedback received and our responses are reflected in the rest of this closing note.
Key Feedback on Licensing Regimes and Operationalisation of the DIA
(A) Licensing Regimes for Major FDI Service Providers and DC Operators
Respondents noted that CSPs may operate their own DCs (Cloud DCs) solely to support the provision of their own Cloud Services, as compared to Co-Location DCs which offer DC hosting services to third-party customers; as Cloud DCs are functionally different from Co-Location DCs, the two types of DCs may have different regulatory requirements and should be regulated separately. Therefore, respondents suggested for this distinction between Cloud DCs vs. Co-Location DCs to be clarified. MDDI and IMDA acknowledge this feedback and have made this distinction in the definition of ‘data centre facility service’ in the Bill. We also intend to have separate Codes of Practice for the security and resilience of Cloud DCs versus Co-Location DCs, subject to further consultations with the industry. The Bill also provides for such differentiation in the Codes of Practice to be issued.
Respondents sought clarifications on the thresholds for determining whether an operator will be covered under the DIA, for example how revenue should be calculated (e.g., gross vs net revenue; attribution of revenue from users in Singapore) for a cloud computing service, and how critical IT load will be determined for DCs. Ahead of the commencement of the licensing regimes, MDDI and IMDA will provide information on these implementation details, in consultation with affected service providers and operators. We will also consider publishing these as part of licence application guidelines.
Respondents also asked whether the licensing regimes could be streamlined, including for application, reporting, audit, and renewal processes. It is MDDI and IMDA’s intent to minimise regulatory burden for service providers and operators. We are exploring the streamlining of processes such as a single application form and documentation for all DCs and FDI Services covered under the DIA, and will be working with the industry to ensure that these are practical for licensees.
(B) Requirements to Uplift Security and Resilience
Several respondents emphasised the importance of recognising existing international standards and certifications when demonstrating compliance with the security and resilience requirements, to minimise regulatory and administrative burden. Respondents also called for clear materiality thresholds to determine reportable security and resilience incidents, and practical incident reporting timelines.
As MDDI and IMDA develop the security and resilience requirements, we will draw on international standards and industry best practices, while incorporating measures suited for our local context. Where possible, we will leverage existing industry-recognised audits and certifications for demonstration of compliance, to minimise reporting and compliance burden for the industry. We will continue consultations with industry before finalising these requirements.
Respondents suggested that regulatory obligations should consider the respective parties' ownership, operational control and ability to manage the relevant risks, including in relation to customer-owned systems and third-party dependencies. More broadly, some respondents highlighted the importance of shared responsibility between service providers, customers, and other parties in safeguarding systems and user data. This is aligned with MDDI and IMDA’s intent. For example, requirements for DCs are intended to apply to areas within the DC operator’s direct control, e.g. for Co-Location DCs, customer-owned equipment beyond the DC operator’s control will not be covered.
(C) Requirements to Uplift Sustainability
Respondents noted potential challenges that existing DCs may face in meeting facility-level energy-efficiency requirements, specifically power usage effectiveness (PUE) requirements. They emphasised the need for sufficient transition time to meet the PUE requirements, to mitigate the risks of resource constraints and manage continuity of workloads. MDDI and IMDA recognise DCs’ concerns. It is our priority to ensure a smooth transition and continued availability of secure and resilient DC facility services. IMDA will continue to work with DC operators and other affected stakeholders on the details, including implementation and transition timelines, before the requirements are finalised in subsequent regulations or Codes of Practice.
Respondents also raised concerns on potential requirements relating to IT equipment energy efficiency (IT EE). They noted that DC operators may not own or manage their customers’ servers and other IT equipment, and thus, have limited visibility over equipment-refresh decisions. MDDI and IMDA recognise this and will not impose mandatory IT EE requirements at the outset. As a first step, we encourage DC operators to work with their customers to understand the latter’s IT equipment efficiency levels and equipment-refresh plans. We will consult the industry prior to implementing any IT EE requirements, with sufficient transition time to meet these requirements.
A similar approach will be taken prior to setting any water efficiency requirements. We note that DCs already observe PUB’s water efficiency guidelines and best practices today. MDDI and IMDA will coordinate with relevant government agencies and consult the industry to ensure any standards imposed under the DIA are practical, before finalising them in subsequent regulations or Codes of Practice. Meanwhile, we encourage DC operators to optimise the use of water resources where possible, balanced against energy efficiency and operational needs.
Some respondents sought clarification on how licence conditions on clean energy and economic commitments would be applied to DC operators. In general, these are not applicable to existing DCs. Such licence conditions are applicable to DC operators which make commitments as part of their licence applications, in alignment with commitments made when securing DC capacity.
(D) Harmonisation with the Cybersecurity Act
Several respondents emphasised the importance of providing clarity on the practical interaction between overlapping requirements and obligations under the DIA and the Cybersecurity Act, particularly as some major FDI service providers may be subject to both regimes. For example, they commented on whether existing compliance evidence could be shared across regulators and how regulated entities would engage with IMDA and CSA where both regimes apply (e.g., for incident reporting).
MDDI, CSA, and IMDA will streamline the requirements, compliance and operational processes under both regimes to minimise additional regulatory burden on entities that are subject to both regimes. Where reporting requirements for cybersecurity incidents are similar across both the Cybersecurity Act and the DIA, licensees will only need to report to IMDA, with the understanding that relevant information covered under the Cybersecurity Act will be shared with CSA.
Feedback on Other Matters
(E) Notification Requirements for Ownership Changes
Several respondents suggested that for the notification requirement for change in ownership, the 5% threshold may not necessarily result in substantial change in control or influence over the licensee, and hence suggested adopting a higher material threshold. Respondents also raised that some types of ownership changes may not result in a material change in control and influence of the day-to-day operation of the licensed entity – for example, passive institutional investors and diversified funds may not necessarily exercise material control over the operations of the licensee.
MDDI and IMDA recognise the growing significance of DCs in supporting our digital economy and activities. Therefore, it is important to have greater visibility over DCs, including on significant ownership changes. The 5% threshold is a common benchmark across regulatory regimes of similar important infrastructure and sectors, e.g., financial services, telecommunications, electricity and gas sectors. Nonetheless, we will streamline the operational reporting process for transactions that do not affect the material control of regulated entities (e.g., pro-forma transactions).
(F) Transitional Provisions
Respondents welcomed the inclusion of transitional provisions in the Bill, and asked for sufficient time for operators to continue providing services while transitioning into the new licensing regime. Some respondents suggested that the proposed six-month transition period may not provide enough time for entities to determine whether they are required to be licensed, and to apply for the licence and/or make necessary contractual or operational arrangements to comply with the substantive requirements.
MDDI and IMDA note that the six-month period is for the licence application process after the Act comes into effect, and would be extended until the licence application process concludes (either when the license is granted or when the application is refused or withdrawn) should service providers and DC operators apply for a licence within the six-month period. Prior to this, we will engage industry players to clarify if they are required to be licensed. On complying with the substantive requirements, we will continue to consult with industry stakeholders on the development of subsequent regulations or Codes of Practices. As mentioned above, we will endeavour to ensure a smooth transition for regulated entities under the DIA, and we will work with industry to address the challenges involved.
Conclusion
MDDI and IMDA thank all stakeholders and members of the public for participating in this consultation.
Detailed Description
Part I: Introduction
The Ministry of Digital Development and Information (MDDI) and the Infocomm Media Development Authority (IMDA) invite members of the public to provide feedback on the draft Digital Infrastructure Bill (Bill), which seeks to uplift the security and resilience of digital infrastructure services, and the environmental sustainability of data centre (DC) operations in Singapore. The draft Bill is attached as Annex A [PDF, 600.39 KB] ↗(opens in new tab) (opens in new tab).
Digital infrastructure services are a foundational part of our growing digital economy. They underpin Singapore’s digital connectivity, enabling the digital services that are used by businesses and consumers, from digital banking to ride-hailing to e-commerce. Digital infrastructure services like DC Facility Services and Cloud Computing Services, among others, have become more essential, in addition to traditional mobile and broadband connectivity services. Globally, there is likewise increasing recognition of the role of digital infrastructure services.
Given the importance of DC Facility Services and Cloud Computing Services, we must ensure that providers take measures to ensure the security and resilience of such services. While the Cybersecurity Act amendments in 2024 established requirements to address the cybersecurity risks faced by major foundational digital infrastructure (FDI) services, there is no statutory framework to ensure their broader operational resilience. The Bill thus complements the Cybersecurity Act amendments in requiring regulated providers to take measures to ensure the security and resilience of major DC Facility Services and Cloud Computing Services.
At the same time, DCs operations must be environmentally sustainable and energy efficient because of their environmental footprint and intensive use of resources. Recognising this, we have launched the Green DC Roadmap to chart a sustainable pathway for DC growth and also worked with industry to launch several standards to drive the energy efficiency of DCs. We will continue to grow our DC industry in a sustainable manner by ensuring that our new DCs are best-in-class, through capacity allocation exercises such as the Data Centre – Call For Application (DC-CFA). While our efforts have catalysed voluntary DC energy efficiency improvements, voluntary measures alone cannot ensure consistent sustainability outcomes across the sector. The Bill will require all regulated DC operators to ensure that the operation of their DCs meets baseline environmental sustainability requirements.
Through the Bill, MDDI and IMDA seek to achieve the following policy objectives:
Ensure that providers of major DC Facility Services and Cloud Computing Services take measures to maintain an adequate level of security and resilience, so as to reduce the risks and mitigate the impact of disruptions;
Enhance regulatory visibility of cybersecurity incidents and service delivery disruptions affecting major DC Facility Services and Cloud Computing Services; and
Impose and uplift baseline environmental sustainability standards across the DC sector.
In developing the draft Bill, MDDI and IMDA have studied overseas developments, referenced domestic legislation (e.g., the Cybersecurity Act), and conducted extensive engagements with companies and professionals from the digital infrastructure sector.
Part II: Key Features of the Bill
New Licensing Regime for Major FDI Service Providers to Enhance Security and Resilience
The Bill will establish a new licensing regime and regulatory framework for major FDI services provided to users in Singapore. A major FDI service is a digital infrastructure service – (1) for which the loss or impairment of the provision of the service is likely to lead to or cause widespread disruption or deterioration of the operations of businesses or organisations in Singapore, and (2) which is specified in the Schedule as a major FDI service. The Schedule will specify the following as major FDI services:
A DC Facility Service provided in a DC which has a critical IT load1 (CIL) of ≥ 10 megawatts (MW), which is used to serve other parties unrelated to the operator of the DC (i.e., Cloud and Co-Location DCs); and
A Cloud Computing Service that has generated revenue from users in Singapore of ≥ S$100 million per year on average over the 3 preceding years, and falls within the categories of Infrastructure-as-a-Service (IaaS) or Platform-as-a-Service (PaaS) but not Software-as-a-Service (SaaS).
Providers of these major DC Facility Services and Cloud Computing Services will have to apply to IMDA for a major FDI licence. Licensees must take measures to ensure the security and resilience of their major FDI services. They will be required to:
Implement processes and measures to ensure the security, including the physical security and cybersecurity, of their services;
Implement business continuity and disaster recovery plans to ensure timely resumption of their services from interruptions to their business activities and processes; and
Notify IMDA of the occurrence of cybersecurity incidents or service delivery disruptions.
Detailed requirements and practices for major FDI service providers will be set out in relevant instruments (e.g., regulations and codes of practice). They will take reference from the published Advisory Guidelines for Resilience and Security of Cloud Services and DCs.
New Licensing Regime for DC Operators to Enhance Sustainability
Operators of DCs (i.e. with a CIL of ≥ 3 MW) will have to apply to IMDA for a DC licence. The requirements applicable to holders of a DC licence primarily aim to impose and uplift baseline sustainability standards across the DC sector. An operator of a DC that also provides a DC Facility Service described in paragraph 7(a) will be required to hold both a major FDI licence and a DC licence. Operationally, IMDA will streamline the application process for applicants applying for both licences.
When assessing an application for a DC licence, in addition to the applicant’s experience and capability in operating a DC, IMDA will also consider the energy efficiency and water efficiency of the DC. IMDA may also consider other matters, including but not limited to the characteristics of the DC’s energy sources (e.g. the renewability of its energy sources, and the extent of greenhouse gas emissions from the generation of electricity used), and the extent to which the applicant’s current and proposed business operations are or will be of economic or strategic importance to Singapore’s economy.
Licensed DC operators will be required to meet facility-level energy efficiency requirements, specifically, power usage effectiveness (PUE) requirements. The Bill also enables IMDA to provide for requirements and practices relating to information technology equipment energy efficiency and facility-level water efficiency requirements in the future. Similar to ongoing consultations on PUE requirements, IMDA will consult DC operators before finalising such requirements and practices which will be set out in relevant instruments (i.e., regulations and codes of practice). IMDA will continue our engagements with DC operators on the specific requirements and practices which will be finalised after the passage of the Bill.
Administering and Enforcing the Act
IMDA will be given the function of administering the Act (if passed) and the following key powers:
Licensing powers. IMDA may grant, renew, suspend or revoke major FDI licences and DC licences, and impose or modify the conditions of such licences, in appropriate cases.
Codes of practice and directions. IMDA may issue codes of practice and directions to licensees, including directions to require compliance with any code of practice applicable to the licensee.
Financial penalties. IMDA may impose financial penalties for non-compliance in appropriate cases.
Enforcement and investigation. IMDA enforcement officers will be empowered to carry out enforcement and investigation actions.
Related Amendments to the Cybersecurity Act 2018 and Cybersecurity (Amendment) Act 2024
For consistency between regulatory frameworks for major FDI services, the Bill also makes related amendments to the Cybersecurity Act 2018 and Cybersecurity (Amendment) Act 2024, to align the definitions of “foundational digital infrastructure service” and “data centre facility service”.
Part III: Invitation for Feedback
MDDI and IMDA are seeking views from members of the public on the draft Bill. Please note that the information in this document and the draft Bill are being released only for the purpose of consultation and does not represent the final legislation.
All submissions should reach MDDI and IMDA within 3 weeks, no later than 22 July 2026, 10am. Respondents are to adhere to this timeline, and MDDI and IMDA reserve the right to reject late submissions. Submissions are to be in softcopy only (in Microsoft Word or PDF format). Please submit your soft copies, with the email subject “Public Consultation on the Draft Digital Infrastructure Bill [name of individual or organisation making the submission]”, to: DigitalInfrastructure@mddi.gov.sg (opens in new tab) ↗(opens in new tab) (opens in new tab).
MDDI and IMDA reserve the right to make public all or parts of any written submission, and/or to disclose the identity of individuals and organisations that have made submissions. Respondents may request confidential treatment for any part of the submission. Any such information should be clearly marked and placed in a separate annex. Respondents are also required to substantiate with reasons any request for confidential treatment. If MDDI and IMDA grant confidential treatment, it will consider, but will not publicly disclose, the information. If MDDI and IMDA reject the request for confidential treatment, it will return the information to the respondent that submitted it and will not consider this information as part of its review. As far as possible, respondents should limit any request for confidential treatment of information submitted. MDDI and IMDA will not accept any submission that requests confidential treatment of all, or a substantial part of, the submission.
1 Defined as the maximum electrical power capacity for which the DC is designed to supply electrical power to the information technology and network telecommunications equipment (including computer servers) which provide storage, processing and transport of data, that are housed within the DC.
