Singapore is consulting on a proposed Digital Infrastructure Bill that would introduce resilience, security and sustainability duties for defined large cloud and data-centre operators. The proposal is not enacted law.

The consultation says a data-centre operator with at least 3 MW of contracted load would need a data-centre licence. A separate major data-centre licence would apply to operators above 10 MW that provide critical information infrastructure services to non-related parties. Singapore REACH: public consultation on the Digital Infrastructure Bill Computer Weekly: Singapore’s digital infrastructure bill and cross-border data

What the proposal would cover

For qualifying cloud services, the proposal describes requirements around physical and cyber security, business continuity and disaster recovery, as well as reporting of incidents and service disruptions. The detailed scope, thresholds and final obligations remain subject to the consultation and legislative process.

What buyers should ask now

For enterprise buyers, the useful question is whether a provider’s operating model can evidence recovery arrangements, incident procedures and the scope of the service covered. A consultation paper does not itself prove a provider is compliant, nor does it establish a final compliance date.

The regional implication is practical rather than speculative: Singapore’s policy direction places operational resilience alongside the growth of cloud and data-centre capacity. Businesses using Singapore as a regional technology hub should watch the final bill, implementing regulations and any published transition arrangements.

Source note

The official consultation is the source of the proposed licensing thresholds and operating obligations. Independent reporting supplies current policy context. SEA Connect’s buyer questions are analysis; the bill is a proposal and should not be read as enacted regulation.