Search

Singapore Tables Digital Infrastructure Bill Introducing Licensing for Major Cloud Providers and Data Centers

By: IDCNOVARegion: Southeast Asia
Singapore has tabled a sweeping new law that would impose licensing requirements on the city-state's largest cloud service providers and data center operators, marking one of the most comprehensive regulatory frameworks for digital infrastructure anywhere in the world. The Digital Infrastructure Bill, introduced in Parliament for First Reading, establishes two distinct licensing regimes aimed at strengthening the security and resilience of critical cloud and data center infrastructure while ensuring the environmental sustainability of data center operations.

The proposed legislation, to be administered by the Infocomm Media Development Authority (IMDA), would require licensing for major co-location and cloud data centers with a critical IT load of at least 10 megawatts, as well as major Cloud Service Providers whose Infrastructure-as-a-Service and Platform-as-a-Service offerings generate at least S$100 million (US$79 million) in average annual revenue from users in Singapore over the three preceding years. The move reflects growing government concern that the digital infrastructure underpinning Singapore's economy must meet rigorous standards as reliance on cloud computing and data center capacity continues to accelerate across the region.

The Bill covers a broad range of operational resilience risks, including technical failures, power or cooling issues, fires, and other physical or operational incidents. Licensees would be required to implement security risk management measures, business continuity and disaster recovery plans, and to report specified incidents and disruptions to IMDA. The legislation complements the Cybersecurity Act, which sets out narrower cybersecurity requirements for major digital infrastructure, and at the implementation stage, the requirements under both the Bill and the Cybersecurity Act will be streamlined to avoid duplication.

A second licensing regime would require all data center operators, both new and existing, with a critical IT load of at least 3 megawatts to be licensed. These operators would need to meet facility-level energy-efficiency requirements, including Power Usage Effectiveness standards, and later, IT equipment and water efficiency requirements where necessary, following consultation with industry. The Bill also provides a basis for strategic, economic, and green energy commitments made in exchange for being awarded new data center capacity through exercises such as the Data Centre Call for Application to be enforced as license conditions, ensuring that material commitments made in securing scarce capacity are accountable.

In a statement accompanying the Bill, authorities emphasized that the legislation would give businesses, organizations, and citizens assurance that the infrastructure they depend on is secure and resilient, while providing the clarity and predictability needed for long-term investment in Singapore's digital infrastructure. The statement also noted that the Bill would ensure the data center sector continues to grow sustainably and makes the best use of Singapore's scarce national resources.

The Bill has been developed in collaboration with industry stakeholders, including major data center operators, Cloud Service Providers, industry associations, and enterprise users. It will be tabled for a Second Reading at the next available Parliament sitting. Singapore, which now has more than 1.6 gigawatts of data center capacity, has previously implemented several data center-related guidelines, including Advisory Guidelines for Resilience and Security of Cloud Services and Data Centers, the Green Data Center Roadmap, the refreshed BCA-IMDA Green Mark certification for data centers, and standards covering IT energy efficiency, liquid cooling, and tropical data centers.