Singapore has introduced new regulations targeting major data centres critical to the nation’s digital infrastructure, aiming to strengthen security, operational resilience, and energy efficiency. The Digital Infrastructure Bill, passed by Parliament on October 7, imposes licensing requirements on large data centres and sets stricter standards for cybersecurity and business continuity.

Under the legislation, data centres exceeding certain thresholds—specifically, those with at least 10 megawatts (MW) of electrical capacity or generating average annual revenues of over S$100 million from Singapore users over three years—will be required to obtain a foundational digital infrastructure (FDI) licence. Additionally, data centres consuming at least 3 MW of power must acquire a data centre (DC) licence, subjecting them to energy efficiency standards. These thresholds encompass approximately two-thirds of Singapore’s 70 data centres, including major operators such as Amazon Web Services, Microsoft Azure, and Google Cloud Platform.

The Bill seeks to address multiple risks, requiring licensees to implement measures for physical security, cybersecurity, disaster recovery, and business continuity to safeguard against incidents such as fire, flooding, power outages, or system misconfiguration. Licensees will also have to report significant cybersecurity incidents to the Infocomm Media Development Authority (IMDA), which coordinates with the Cyber Security Agency of Singapore. Future regulations may require direct notifications to users during service disruptions.

In terms of sustainability, DC licensees must meet power usage effectiveness (PUE) standards—a key metric for energy efficiency in data centres. While exact PUE requirements remain under consultation, recent government tenders have specified PUE targets of 1.25 to 1.3, with plans to consider broader resource efficiency metrics, including water use. Authorities acknowledged that meeting these standards may be especially challenging for older facilities and indicated support for operators requiring transition periods.

The Bill also includes provisions allowing IMDA to enforce compliance, with penalties of up to S$1 million or 10% of a company’s annual Singapore turnover for breaches related to cybersecurity and resilience mandates. Additionally, licence conditions may tie economic commitments—such as investments, job creation, and research activities—to the allocation of limited data centre capacity.

During parliamentary debate, MPs highlighted the economic importance of data centres and their role in sustaining Singapore’s digital competitiveness. However, concerns were raised about the impact of tougher regulations on investment attractiveness compared to regional competitors, and about support for upgrading aging facilities. Senior Minister of State for Digital Development and Information Tan Kiat How acknowledged these concerns, emphasizing the need for careful planning to balance growth with Singapore’s constraints on land, power, and water resources. Tan also affirmed that the expansion of data centres would not increase household electricity bills, as these operators purchase power under commercial arrangements.

Tan further pointed to global trends in data centre regulation, noting that countries like Thailand, Spain, and Australia are adopting similar measures in response to rising demand for computing power driven by artificial intelligence and other technologies. Singapore’s framework aims to provide clarity and flexibility for businesses while safeguarding the resilience and sustainability of its digital infrastructure amid evolving technological and environmental challenges.