Law / Singapore

Singapore

11 of 14 named instruments researched to a stage, across five of the six areas of law we track: 11 in force. As of 22 September 2026.

When they take effect10 of 11 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 2 instruments (2 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 4 instruments (4 in force) 2022: 1 instrument (1 in force) 2023: 1 instrument (1 in force) 2024: 0 instruments 2025: 1 instrument (1 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 5
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law 2
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (170 words)

Singapore has no general AI-transparency, AI-risk-obligation or AI-governance statute; its Model AI Governance Frameworks (including the framework for agentic AI) and an IMDA discussion paper on AI-agent legal responsibility are voluntary guidance rather than binding law, and are not recorded as instruments here.

Singapore does bind an outright prohibition reaching AI-generated content in one place: the Penal Code 1871's intimate-image offence at section 377BE, most recently amended in 2025, extends to an image or recording that has been digitally altered or generated to appear to show a person in an intimate depiction, so a computer-generated or deepfake sexual image of a real person falls within the same distribution and threat-to-distribute offence as an authentic one.

Two further candidates for this topic are not described here: the Elections (Integrity of Online Advertising) (Amendment) Act 2024's reported ban on AI-manipulated election content, whose specific section numbers and commencement are not confirmed in the primary text, and the Penal Code's child abuse material offence at section 377BG, whose provisions are not described here.

AI prohibited practices

Penal Code, Distributing or Threatening to Distribute Intimate Image or Recording

Penal Code 1871, s. 377BE (Distributing or Threatening to Distribute Intimate Image or Recording)official consolidated Act text, Singapore Statutes Online (SSO)

In force. Binds public and private bodies.

What this law does

Section 377BE makes it an offence for any person to intentionally or knowingly distribute, or knowingly threaten to distribute, an intimate image or recording of another person without that person's consent, knowing or having reason to believe the distribution or threat will or is likely to cause humiliation, alarm or distress.

The section was inserted by the Criminal Law Reform Act 2019 (Act 15 of 2019); the specific day section 377BE itself came into operation is not confirmed in the primary text and so is not stated here.

Section 377BE(5)(b), most recently amended with effect from 17 August 2026, defines an intimate image or recording to include an image or recording in any form that has been altered or generated to appear to show a person's intimate depiction, excluding an image so altered or generated that no reasonable person would believe it depicts that person; the section's own illustration is a face copied and pasted onto another body to appear that the person engaged in a sexual act.

A person convicted is liable to imprisonment for up to 5 years, or a fine, or caning, or a combination, rising to a mandatory fine or caning alongside imprisonment where the depicted person is below 14 years of age.

What it requires

Privacy law5 instruments, 5 in force

Research summary (201 words)

Singapore's comprehensive private-sector data-protection law is the Personal Data Protection Act 2012 (No. 26 of 2012, PDPA), as substantially amended by the Personal Data Protection (Amendment) Act 2020 (Act 40 of 2020), with most provisions in force 1 February 2021 and the financial-penalty regime commencing later, 1 October 2022.

PDPA uses a single consent-based framework applied uniformly to all personal data; it has no statutory sensitive-category or biometric-specific provision, a direct full-text search for biometric returning zero hits, so a voiceprint or faceprint is regulated exactly like any other personal data, with no heightened biometric restriction.

Cross-border transfer requires a standard of protection comparable to the Act under s.26, and s.48O arms a private plaintiff for a contravention of the Consent, Access and Correction, Care of Personal Data, Notification of Data Breaches, or Data Portability provisions, alongside PDPC financial penalties of up to 10 percent of Singapore annual turnover.

The exact scope of the Act's publicly-available-data consent exception is an open item: Section 2 defines the term publicly available, which strongly suggests a Schedule exception uses it to excuse consent, but the operative exception provision itself is not read here, so whether a publicly-available-data exemption applies is not stated either way.

Breach notification

Personal Data Protection Act, data breach notification

Personal Data Protection Act 2012, Part 6A, ss.26A-26E, as added by Act 40 of 2020official statute text, Singapore Statutes Online (SSO)

In force since 1 February 2021. Binds private bodies.

What this law does

Part 6A, added by the 2020 amendment, makes a data breach notifiable if it results in, or is likely to result in, significant harm to an affected individual, or is or is likely to be of significant scale; an internal-only breach is deemed not notifiable.

The organisation must notify the PDPC as soon as practicable, and in any case no later than 3 calendar days after assessing the breach is notifiable, and must also notify each affected individual, subject to exceptions where technological measures render significant harm unlikely or a law-enforcement agency or the PDPC directs otherwise.

What it requires

Comprehensive regime

Personal Data Protection Act, comprehensive consent-based regime

Act 26 of 2012 (Singapore), as amended by the Personal Data Protection (Amendment) Act 2020, Act 40 of 2020official statute text, Singapore Statutes Online (SSO)

In force since 1 February 2021. Binds private bodies.

What this law does

PDPA applies a single consent-based framework to all personal data processing by organisations in Singapore: collection, use, or disclosure requires consent or a Part 3 or Schedule exception, and the Act does not distinguish controller from processor by name, instead regulating organisations directly with pass-through duties on data intermediaries.

There is no statutory sensitive-category or biometric-specific tier; every category of personal data, including a faceprint or voiceprint, is regulated under this one uniform standard.

What it requires

Cross border transfer

Personal Data Protection Act, cross-border transfer

Personal Data Protection Act 2012, s.26official statute text, Singapore Statutes Online (SSO)

In force since 2 July 2014. Binds private bodies.

What this law does

Section 26(1) bars an organisation from transferring personal data to a country or territory outside Singapore except in accordance with requirements ensuring a standard of protection comparable to the PDPA; the PDPC may grant exemptions on application under s.26(2) and (3). This is a comparability-based mechanism, not a flat prohibition or a data-localization mandate; the specific instruments accepted as satisfying comparable protection sit in PDPA Regulations not read.

Section 26 sits in the original 2012 Act's Part 6 (Care of Personal Data), which the Act's own consolidated text records as having commenced 2 July 2014 alongside the rest of Parts 3 to 7.

What it requires

Data subject rights

Personal Data Protection Act, data subject rights

Personal Data Protection Act 2012, ss.21-22official statute text, Singapore Statutes Online (SSO)

In force since 2 July 2014. Binds private bodies.

What this law does

Part 5 grants a data subject the statutory rights of access (s.21) and correction (s.22) of their personal data; the Act's own consolidated commencement note records Part 5 as having commenced 2 July 2014 with the rest of Parts 3 to 7.

A data portability right, headed Part 6B and added by the Personal Data Protection (Amendment) Act 2020, does not appear anywhere in the Act's own table of contents on Singapore Statutes Online, which lists every Part from Part 1 through Part 10 and goes directly from Part 6A to Part 7 with no Part 6B heading between them, so no Part 6B data portability right is asserted here as a numbered Part of the Act.

That conflicts with a quotation elsewhere, in the enforcement instrument, which names Part 6B among the Parts whose contravention grounds a private right of action; that quotation is not independently verified against primary text, because Singapore Statutes Online serves only the table of contents at this URL and not the section body, so the conflict is left open rather than resolved either way. No distinct statutory deletion or erasure right was found in the table of contents structure surveyed.

What it requires

Enforcement supervision

Personal Data Protection Act, enforcement and private right of action

Personal Data Protection Act 2012, ss.48J, 48O, as added by Act 40 of 2020official statute text, Singapore Statutes Online (SSO)

In force since 1 October 2022. Binds private bodies.

What this law does

The Personal Data Protection Commission (PDPC) is Singapore's supervisory authority. Financial penalties under s.48J, added by the 2020 amendment and commencing 1 October 2022, reach up to 10 percent of Singapore annual turnover for an organisation with turnover exceeding S$10 million (otherwise up to S$1 million), and up to S$200,000 for an individual, or up to 5 percent of turnover exceeding S$20 million.

Section 48O(1), also added by the 2020 amendment, gives a person who suffers loss or damage directly from a contravention of the Consent Obligation (Part 4), Access and Correction (Part 5), Care of Personal Data (Part 6), Notification of Data Breaches (Part 6A), or Data Portability (Part 6B) provisions a right of action for relief in civil proceedings; its own specific commencement date within the 2020 amendment was not independently isolated.

What it requires

Scraping law2 instruments, 2 in force

Research summary (273 words)

Singapore has no scraping-specific statute, so general law governs each dimension separately. The Computer Misuse Act 1993 criminalises securing access to a computer without authority, defined by section 2(5) as access a person neither controls nor has consent for from someone who does; a page served openly, with no login or technical barrier, carries that consent for ordinary unauthenticated access.

No reported case has tested the broader question of whether public accessibility is a categorical carve-out from the offence, or whether declining to honour a robots.txt directive falls outside the consent an open page gives.

The Copyright Act 2021 adds a dedicated computational data analysis exception at ss.243-244, permitting a person with lawful access to a work to copy it for computational data analysis, including training a computer program, subject to conditions on purpose, supply and lawful access; section 187 makes any contract term that purports to exclude this exception void.

The Personal Data Protection Act 2012 applies to personal data without a general public-data carve-out, so scraping personal data from a public Singapore website remains subject to the Act's consent-based framework (see the privacy topic document for this jurisdiction).

No Singapore statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, a sui generis database right, a robots.txt-specific legal weight, or a mechanism for a rightsholder to opt content out of the computational data analysis exception.

A Singapore High Court decision on browsewrap website terms asks whether the user had actual or constructive notice of them, a fact-sensitive inquiry rather than a fixed rule, so terms posted only behind a link bind a crawler only where it had that notice.

Computer misuse

Computer Misuse Act, Unauthorised Access to Computer Material

Computer Misuse Act 1993 (Cap. 50A), s. 3 (Unauthorised Access to Computer Material)official consolidated Act text, Singapore Statutes Online (SSO)

In force since 30 August 1993. Binds public and private bodies.

What this law does

Section 3(1) makes it an offence for any person to knowingly cause a computer to perform any function for the purpose of securing access without authority to any program or data held in any computer, punishable on a first conviction by a fine not exceeding $5,000 or imprisonment not exceeding 2 years or both, and on a second or subsequent conviction by a fine not exceeding $10,000 or imprisonment not exceeding 3 years or both.

Where the offence causes damage, section 3(2) raises the penalty to a fine not exceeding $50,000 or imprisonment not exceeding 7 years or both. Access is unauthorised under section 2(5) where the person is not entitled to control access of that kind and has no consent from someone who is so entitled; no reported Singapore decision has tested whether reading a public, unauthenticated web page without defeating any access control falls within this offence. The Act commenced on 30 August 1993.

What it requires

Age gating law2 instruments, 2 in force

Research summary (276 words)

Singapore has no adult-content age-verification statute and no age-based restriction on exhibiting or supplying restricted films confirmed in the primary text of the Films Act 1981. It does have two age-appropriate design codes issued by the Info-communications Media Development Authority (IMDA) under section 45L of the Broadcasting Act 1994.

The Code of Practice for Online Safety for Social Media Services, binding on social media services designated under section 45K(1), took effect 18 July 2023 and requires a designated service to give children differentiated, more restrictive default safety settings and tools their parents or guardians can use to manage their exposure to harmful content.

The Code of Practice for Online Safety, App Distribution Services, binding on app distribution services designated under the same power, took effect 31 March 2025 and requires a designated app store to implement age verification or another form of age assurance so that an account holder's age or age range can be established with reasonable accuracy, alongside more restrictive default settings for children's accounts.

The Films Act 1981 establishes a licensing and classification scheme, administered by IMDA, for importing, distributing and publicly exhibiting films, but its own text does not state an age-based restriction on exhibiting or supplying a restricted or R21-rated film to a person under 21; that restriction is set through a film's classification conditions rather than the Act's own provisions.

The Online Safety (Relief and Accountability) Act 2025, passed 25 November 2025 and partly in force from 29 June 2026, creates a redress, direction and tort regime for online harassment, doxxing, non-consensual disclosure and image-based child abuse, but does not impose an age-verification or age-gating duty on an online service.

Age-appropriate design code

Code of Practice for Online Safety, Social Media Services

Code of Practice for Online Safety, Social Media Services, issued under s. 45L of the Broadcasting Act 1994Code text issued by the Info-communications Media Development Authority (IMDA)

In force since 18 July 2023. Binds private bodies.

What this law does

The Code applies to Social Media Services designated or to be designated under section 45K(1) of the Broadcasting Act 1994; six services (Facebook, HardwareZone, Instagram, TikTok, X and YouTube) were designated when it took effect.

It requires a designated service to minimise all end-users' exposure to harmful content (sexual content, violent content, suicide and self-harm content, cyberbullying content, content endangering public health, and content facilitating vice and organised crime) through published community guidelines and content moderation. Beyond that baseline, the Code requires additional measures for children, defined as anyone below 18.

Unless the service restricts child access entirely, a child's account must have age-appropriate default settings that are more restrictive than a general account, tools for the child or a parent or guardian to manage exposure and limit the visibility of and interaction with the account, and a clear warning before the child or parent opts out of those protective defaults.

A designated service must also use technology to proactively detect and swiftly remove child sexual exploitation and abuse material.

Note and primary source

App store age verification (AV)

Code of Practice for Online Safety, App Distribution Services

Code of Practice for Online Safety, App Distribution Services, issued under s. 45L of the Broadcasting Act 1994Code text issued by the Info-communications Media Development Authority (IMDA)

In force since 31 March 2025. Binds private bodies.

What this law does

The Code applies to App Distribution Services designated or to be designated under section 45K(1) of the Broadcasting Act 1994. It requires the provider of a designated service to minimise all users' exposure to harmful content (sexual content, violent content, suicide and self-harm content, cyberbullying content, content endangering public health, and content facilitating vice and organised crime) through content guidelines and content moderation of the apps it distributes.

For children, defined as anyone below 18, the provider must have systems and processes, including age verification or another means of age assurance, so that a user's age or age range can be established with reasonable accuracy. Unless the service restricts children's access entirely, a child's account must have differentiated, more restrictive default settings.

Age assurance must be implemented consistently with the Personal Data Protection Act 2012's data-protection provisions and the Personal Data Protection Commission's guidelines on children's personal data, including data minimisation. A provider that has not yet implemented age assurance must submit an implementation plan and timeline to IMDA for its agreement. The provider must also use technology to proactively detect and swiftly remove child sexual exploitation and abuse material.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (158 words)

Singapore has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright Act 2021's open-ended fair use test at ss.190-191, rather than any aggregator-specific carve-out, is the provision an aggregator's reproduction of headlines and snippets would rest on.

The Act contains no separate quotation or news-reporting exception distinct from this fair use test, and no reported Singapore decision applies it to a systematic news aggregator as opposed to an individual use. No statute or case law addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law has been identified.

The Act's computational data analysis exception at ss.243-244 (see the scraping topic's Singapore summary) is a machine-readable text-and-data-mining permission that indexing and training activity can invoke, but it is not itself a publisher-facing opt-out mechanism of the kind the European Union's Digital Single Market (DSM) Directive Article 15 creates.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.