On a humid afternoon in October 2023, more than 2.5 million payment and ATM transactions ground to a halt across Singapore. Bank customers stared at frozen screens and unresponsive ATMs, the victims of a cooling system failure at a data centre that sent temperatures soaring beyond safe operating limits.
It took until the early hours of the following day for services to fully recover—and the fallout was severe enough to prompt the Monetary Authority of Singapore to bar one of the banks from non-essential IT changes and new acquisitions for six months.
That incident, alongside a fire at a Global Switch data centre in Paris in April 2023 that brought down a hyperscaler's services in Europe for weeks, served as a catalyst. On 1 July 2026, Singapore's Ministry of Digital Development and Information (MDDI) and the Infocomm Media Development Authority (IMDA) unveiled the Digital Infrastructure Bill (Bill), a proposed licensing regime that will hold major data centre and cloud operators to far higher standards of resilience—and punish non-compliance with fines of up to S$1 million or 10% of their annual turnover in Singapore, whichever is higher.
The Bill is not merely a reaction to past failures. It arrives as Singapore's data centre market accelerates rapidly. Valued at approximately US$3.25 billion in 2025, the market is projected to reach US$5.11 billion by 2031, growing at a compound annual growth rate of roughly 7.8%, according to analysis from Research and Markets.
With that growth comes heightened scrutiny. The Bill will require major foundational digital infrastructure (FDI) operators—data centres consuming at least 10 megawatts of power and cloud providers generating more than an average of S$100 million in annual revenue from Singapore users over three years—to secure licences, maintain physical and digital security, implement business continuity and disaster recovery plans, and notify IMDA of cybersecurity incidents or service disruptions.
Navigating a maze of overlapping rules
For operators already grappling with Singapore's 2024 Cybersecurity Act, the new Bill raises an immediate question: how do these obligations interact?

Jeremiah Chew, partner at RPC Premier Law, sees both convergence and divergence. "At first glance, there is some overlap, particularly around incident reporting," he notes. The Bill would require major FDI service providers to report cybersecurity incidents and service disruptions, which could overlap with the incident-reporting obligations under the 2024 Cybersecurity Act for owners of critical information infrastructure (CII).
Yet the regulatory landscape is fragmented. "The obligations sit with different regulators: the Digital Infrastructure Act with the IMDA and the Cybersecurity Act with the Cyber Security Agency of Singapore (CSA)," Chew explains. "A business that is both a CII owner and a major FDI licensee could therefore face reporting obligations to both regulators, and potentially the Personal Data Protection Commission if personal data is involved."
The two regimes also focus on different things. "The Cybersecurity Act is principally concerned with identifying, managing and reporting cybersecurity risks and incidents, whereas the Bill goes further, requiring broader business continuity measures," Chew says. "It's not just about stopping hackers; it's about ensuring your services can recover quickly from any operational outage."
To prevent regulatory gridlock, the Bill contains a safeguard. Under Section 16(2), any code of practice issued under the Digital Infrastructure Act cannot contradict or conflict with codes of practice or performance standards established under the Cybersecurity Act. It is a deliberate attempt to keep the regulatory architecture coherent, even as the net of compliance tightens.
The green line: Sustainability becomes mandatory
If cybersecurity and business continuity dominate the headlines, sustainability may prove to be the most disruptive operational shift of all.
"Operators don't need to wait for the fine print to start preparing," Chew advises. "Existing regulatory frameworks and guidelines already give a good indication of where standards are heading."
He points to IMDA's Advisory Guidelines for Cloud Services and Data Centres, issued in February 2025, as well as the Cybersecurity Act, the Personal Data Protection Act, and where relevant, MAS' Technology Risk Management Guidelines.
But the single biggest change is environmental. "The biggest immediate operational shift is sustainability," Chew states plainly.
Data centres consume significant amounts of energy and water, and the new licensing regime will make energy and water efficiency mandatory criteria for obtaining and maintaining a licence.
Even though detailed requirements have not yet been published, operators should already be examining their resource consumption and considering low-carbon and renewable energy sources as part of their operational planning.
The numbers explain why. Data centres accounted for roughly 5.3% of Singapore's electricity consumption in 2019, a figure that climbed to 7% in 2020 as the pandemic accelerated digitalisation.
After a temporary moratorium on new data centre projects was lifted in 2022, operators have faced progressively stricter sustainability benchmarks, including power usage effectiveness (PUE) targets of 1.3 or lower.
The Bill now codifies that trajectory, paving the way for future energy requirements for IT equipment and water-efficiency standards for facilities.
Globally, the pressure is only intensifying. The International Energy Agency projects that global data centre power consumption could reach 1,050 terawatt-hours by 2026, driven largely by AI workloads and energy-intensive GPUs. In that context, Singapore's insistence on sustainability is less an outlier than a preview of where every major data hub is heading.
When the clock starts: Incident reporting across borders
For operators with footprints spanning multiple jurisdictions, the Bill adds another layer of complexity to an already intricate compliance picture.
"Cross-border operators face juggling competing deadlines, different reporting triggers and varying levels of detail required across jurisdictions," Chew observes.
Under Singapore's Cybersecurity Act, CII owners must notify the regulator within two hours of detecting an incident. Malaysia's Cyber Security Act 2024, by contrast, takes a tiered approach: an immediate initial notification, followed by detailed particulars within six hours and a comprehensive report within 14 days.
The divergence matters. A cloud provider running infrastructure in both Singapore and Malaysia could find itself racing against incompatible clocks, each with its own thresholds for what must be reported and to whom.
"Businesses operating across multiple jurisdictions should therefore begin preparing for these requirements now," Chew recommends. "This means having a multi-jurisdictional incident response playbook with clear notification timelines, pre-drafted reporting templates and access to external support, including legal counsel, forensic cybersecurity consultants and crisis PR firms."
He adds that regular, realistic tabletop exercises are essential "to test whether the response works in practice when a serious incident occurs."
What enterprise customers should demand
For banks, fintechs, and e-commerce platforms that depend on data centre and cloud providers, the Bill raises questions about contractual protection. If a provider's compliance failure cascades into an operational disaster or data leak, where does liability land?
Chew offers a measured perspective. "It's helpful to reframe this slightly: service providers will be directly responsible for complying with the Digital Infrastructure Act as a matter of law, so enterprise customers are not responsible for contractually enforcing those obligations," he says.
Regulatory fines under the Act will apply to service providers as the regulated entities, rather than to their enterprise customers.
But that does not leave customers exposed without recourse. If a provider's failure triggers an operational disaster or data leak, the customer could breach its own regulatory obligations under the PDPA or sector-specific rules.
"From this perspective, enterprise customers should ensure their contracts include provisions requiring providers to comply with all applicable laws, including the Digital Infrastructure Act, together with broad indemnities covering all losses, including regulatory fines and penalties, arising from a provider's failure to comply," Chew advises.
Service agreements will typically include liability caps. Given the potential scale of losses, customers may want to consider a supercap for losses relating to non-compliance with the Act, or even unlimited liability—though Chew acknowledges the latter is likely to be harder to negotiate.
This requires providers to purchase cyber insurance with a specified minimum coverage limit, and asking to be named as an insured party is another pragmatic option.
"These are not particularly novel contractual protections," Chew notes, "and are broadly consistent with provisions we already see in existing contracts."
The countdown begins
The public consultation on the Digital Infrastructure Bill closes on 22 July 2026. For operators and their customers, the message is clear: the era of voluntary best practices is ending. What was advisory in February 2025 is becoming statutory in 2026.
The Bill does not exist in isolation. It sits alongside a global data centre market projected to grow from US$269.79 billion in 2025 to US$699.13 billion by 2034, according to Fortune Business Insights. It reflects a world where AI-driven demand is pushing power consumption to unprecedented levels, where a cooling system failure can paralyse a nation's banking infrastructure, and where regulators from Singapore to Kuala Lumpur to Brussels are racing to impose order on digital infrastructure that has become as essential as electricity itself.
For Singapore's operators, the question is no longer whether to prepare. It is whether they can afford not to.








