The full official text, structured for quick navigation. Copy any provision or jump straight to a section.
Public consultation on the Digital Infrastructure Bill: new licensing framework for data centres and cloud services is Singapore COMMENTARY, cited as COMMENTARY 2026-07-20-public-consultation-on-the-digital-infrastructure-bill-new-licensing-framework-for-data-centres-and-cloud-ser 2026 and first recorded in 2026.
Infrastructure Bill:
New Licensing
Framework for Data
Centres and Cloud
Services
8 July 2026
LEGAL
UPDATE
2
03
INTRODUCTION
03
LICENSING REGIME FOR MAJOR
FDI SERVICE PROVIDERS – MAJOR
FDI LICENCE
04
LICENSING REGIME FOR DATA
CENTRE OPERATORS – DC LICENCE
05
INVESTIGATORY AND
ENFORCEMENT POWERS
06
KEY TAKEAWAYS
In this
Update
On 1 July 2026, the Ministry of
Digital Development and
Information and the Infocomm
Media Development Authority launched a public consultation on the draft Digital Infrastructure
Bill to establish Singapore’s first dedicated regulatory framework for digital infrastructure services.
The draft Digital Infrastructure
Bill seeks to improve the security and resilience of digital infrastructure services and the environmental sustainability of data centre operations in
Singapore.
The draft Digital Infrastructure
Bill introduces new licensing regimes for providers of major foundational digital infrastructure services and for operators of data centres in Singapore.
3
INTRODUCTION
On 1 July 2026, the Ministry of Digital Development and Information
(“MDDI”) and the Infocomm Media Development Authority (“IMDA”)
launched a public consultation on the draft Digital Infrastructure Bill
(“Draft Bill”) to establish Singapore’s first dedicated regulatory framework for digital infrastructure services. The Draft Bill seeks to improve the security and resilience of digital infrastructure services and the environmental sustainability of data centre operations in Singapore.
The Draft Bill introduces new licensing regimes for providers of major foundational digital infrastructure (“FDI”) services and for operators of data centres in Singapore. To this end, it also confers corresponding investigatory and enforcement powers on IMDA.
LICENSING REGIME FOR MAJOR FDI SERVICE
PROVIDERS – MAJOR FDI LICENCE
The Draft Bill introduces a new licensing regime for providers of major
FDI services. Such providers will have to apply for a major FDI licence.
A major FDI service is a digital infrastructure service:
(1)
for which the loss or impairment of the provision of the service is likely to lead to or cause widespread disruption or deterioration of the operations of businesses or organisations in Singapore; and
(2)
is specified in the Schedule as a major FDI service.
The following are specified as major FDI services at the Schedule:
(1)
A data centre facility service provided in a data centre which has a critical IT load of ≥ 10 megawatts (MW), which is used to serve other parties unrelated to the operator of the data centre; and
(2)
A cloud computing service that has generated revenue from users in Singapore of ≥ S$100 million per year on average over the 3
preceding years, and falls within the categories of Infrastructure-as-a-Service (IaaS) or Platform-as-a-Service (PaaS) but not Software-as-a-Service (SaaS).
Major FDI licensees must:
(1)
comply with the conditions of the major FDI licence;
(2)
implement prescribed processes and measures to ensure the security of its services;
4
(3)
implement business continuity and disaster recovery arrangements to ensure the timely resumption of services following interruptions to their operations; and
(4)
notify IMDA of prescribed cybersecurity incidents and service delivery disruptions.
In addition, IMDA may issue written directions where necessary to secure compliance with requirements relating to the security and resilience of a major FDI service. Such directions may require audits, remedial action or compliance with applicable codes of practice. Where there is a significant cybersecurity threat or incident, IMDA may also direct a major FDI licensee to notify Singapore users of the protective or remedial measures that users may take.
Detailed requirements are expected to be prescribed through the relevant regulations and codes of practice in due time.
LICENSING REGIME FOR DATA CENTRE
OPERATORS – DC LICENCE
The Draft Bill also introduces a new licensing regime for data centre operators that carry a critical IT load of ≥ 3MW. Such operators will have to apply for a DC licence.
DC licensees must:
(1)
comply with the conditions of the DC licence (e.g., emission and energy requirements);
(2)
comply with prescribed facility-level energy efficiency requirements;
(3)
ensure that IT equipment installed within the data centre complies with equipment-level energy efficiency requirements;
(4)
comply with facility-level water efficiency requirements on the operation of the data centre;
(5)
submit reports to IMDA on regulatory compliance; and
(6)
report changes of equity and control of voting power to IMDA.
Likewise, detailed requirements are expected to be prescribed through the relevant regulations and codes of practice in due time.
5
INVESTIGATORY AND ENFORCEMENT POWERS
The Draft Bill introduces a broad suite of investigatory and enforcement powers.
I. Investigatory Powers
IMDA may require major FDI and DC licensees to provide information and documents necessary to determine the licensee’s compliance with the appliable statutory provisions, licence conditions and applicable codes of practice.
On a non-exhaustive basis, authorised officers also have powers to enter and inspect premises, equipment, systems and activities, make recordings, inspect and copy records from electronic material, take necessary equipment and materials onto the premises, and operate electronic equipment in the premises.
II. Enforcement Powers
Financial Penalties
For major FDI licensees, IMDA may order financial penalties of up to the higher of S$1 million or 10% of the licensee’s annual turnover in
Singapore, for a failure to take measures to ensure the security and resilience of the major FDI service, comply with licence conditions or directions, or any other provisions regulating major FDI licensees.
For data centre licensees, IMDA may also order financial penalties of up to the higher of S$1 million or 10% of the licensee’s annual turnover in
Singapore for licensees that fail to comply with environmental sustainability obligations, comply with licence conditions or directions, or any other provisions regulating DC licensees.
Licence Revocation or Suspension
IMDA may revoke licences, suspend licences, reduce the duration of licences, modify existing licence conditions, impose new licence conditions, or formally censure a licensee. Additionally, data centre licensees may also be ordered by IMDA to reduce the critical IT load at which the data centre may be operated under the licence. These powers may be exercised where a licensee breaches applicable statutory provisions, licence conditions or written directions from IMDA, among other instances.
6
KEY TAKEAWAYS
The Draft Bill marks a significant development in Singapore’s regulation of digital infrastructure, through introducing a new regulatory framework for major cloud service providers and data centre operators.
Businesses operating cloud computing services or data centres operators in Singapore should consider the potential impact of the new framework on their compliance, governance, cybersecurity, business continuity and sustainability programmes. Businesses contemplating investments involving data centre operators or cloud service providers may also wish to evaluate the implications of the proposed regime.
As many of the detailed compliance requirements are expected to be prescribed in subsidiary legislation, codes of practice and licence conditions, we will continue to monitor developments very closely during the consultation and the subsequent legislative implementation.
The public consultation closes on 22 July 2026, 10am. Please contact us if you would like to discuss how the Draft Bill may affect your business, prepare consultation feedback, or assess potential compliance obligations under the proposed framework.
The content of this article does not constitute legal advice and should not be relied on as such.
Specific advice should be sought about your specific circumstances. Copyright in this publication is owned by Drew & Napier LLC. This publication may not be reproduced or transmitted in any form or by any means, in whole or in part, without prior written approval.
7
Please do not hesitate to contact any members of our Telecommunications, Media & Technology
Practice if you require further information about this legal update or would like to discuss how we can assist you and your organisation on TMT matters.
Lim Chong Kin
Managing Director, Corporate &
Finance
Head, Telecommunications, Media &
Technology
Co-Head, Data Protection, Privacy &
Cybersecurity
Co-Head, Competition Law &
Regulatory Practice
T: +65 6531 4110
E: chongkin.lim@drewnapier.com
David N. Alfred
Director, Corporate & Finance
Co-Head, Data Protection,
Privacy & Cybersecurity
T: +65 6531 2342
E: david.alfred@drewnapier.com
Goh Boon Yeow
Director, Telecommunications, Media &
Technology
T: +65 6531 4146
E: boonyeow.goh@drewnapier.com
Drew & Napier LLC
10 Collyer Quay
#10-01 Ocean Financial Centre
Singapore 049315
www.drewnapier.com
T: +65 6535 0733
T: +65 9726 0573 (After Hours)
E: mail@drewnapier.com
If one provision's text doesn't match the official source, use Suggest a fix beside that provision — it opens an editor next to the source document. For anything else — a missing amendment, a broken link, out-of-date content, or a removal request — report it here.