Singapore Bill Puts Data Centres Under $1m Or 10% Turnover Penalty
Asian Business Review reported that Singapore's Digital Infrastructure bill would license major data centre and cloud infrastructure providers after a 2023 cooling failure disrupted more than 2.5 million payment and ATM transactions.

Singapore's proposed Digital Infrastructure bill would put major data centre and cloud infrastructure providers under licensing rules after a 2023 facility outage hit more than 2.5 million payment and ATM transactions, Asian Business Review reported.
The bill would give the Infocomm Media Development Authority direct enforcement powers over covered providers.
Financial penalties could reach $1 million or 10% of annual turnover for the licensee, whichever amount is higher, and noncompliance could lead to a licence suspension or revocation.
Cooling Outage Shapes The Licensing Plan
The Ministry of Digital Development and Information and IMDA sought public feedback on the bill in July.
The measure would complement Singapore's Cybersecurity Act by covering disruptions tied to physical facilities, power and other non-cyber failures, not only malicious digital threats.
Jeremy Tan of Bird & Bird ATMD LLP said in an emailed reply that covered data centre and cloud infrastructure providers would face direct resilience obligations, including business continuity and disaster recovery measures.
Jean Nie Ho at Dentons Rodyk & Davidson LLP tied the scope to facility and power controls, with energy conservation included alongside physical security.
That wider coverage sits outside the narrower cybersecurity framework.
Two Licences Split Resilience And Efficiency
The proposed regime creates two licensing tracks.
A major foundational digital infrastructure licence would apply to providers whose disruption could cause widespread operational problems for dependent businesses and organisations, while a data centre licence would govern energy and water efficiency at covered facilities.
A May report from the International Data Center Authority put data-centre demand at one-fifth of Singapore's national grid this year.
The bill would therefore place resilience and resource use inside the same regulatory programme rather than treating facility efficiency as a separate operating issue.
Keeper Security's Takanori Nishiyama framed the penalty design as a move beyond older fixed-fine models because a turnover-based sanction can scale with hyperscale cloud providers.
Operators Face Board-Level Compliance Work
Detailed requirements will depend on later implementing rules and licence terms.
The public bill still changes the relationship between covered providers and IMDA by making resilience failures a direct regulatory matter rather than only a contractual issue with customers.
Companies that may fall within scope need to determine which licence applies, review power-supply exposure, examine cleaner-energy and carbon-credit options, and set up electricity and water-use tracking where those systems are not already in place.
Those measures would become the baseline for resource-efficiency assessments once Singapore issues the detailed licence conditions.




















