Major data centres to meet stricter security, resilience rules with the passing of new Bill随着新法案的通过,大型数据中心将需要满足更严格的安全性和弹性规则。
The Bill helps account for a range of risks in data centres, from physical and operational continuity to cyber security. Read more at straitstimes.com.
Facade of Keppel Data Centre Campus at 82 Genting Lane.
Published Oct 07, 2026, 02:25 PM
Updated Oct 07, 2026, 02:27 PM
- Singapore passed the Digital Infrastructure Bill to make major data centres stronger on security, resilience and energy efficiency.
- About two-thirds of Singapore’s 70 data centres will need foundational digital infrastructure licences.
- IMDA can fine firms up to $1 million or 10 per cent of Singapore turnover, and operators may face action if they miss economic promises.
SINGAPORE - Large data centres that underpin critical digital services in Singapore will need to account for a range of risks from physical and operational continuity to cyber security with the passing of a new Bill and amendments to an existing law.
The Digital Infrastructure Bill, passed in Parliament on Oct 7, seeks to ensure energy efficiency and operational resilience - including physical security and recovery from system misconfiguration, fire, flood and power supply cuts - through licensing.
Amendments to the existing Cybersecurity Act will also subject most major data centres to similar cyber-incident reporting requirements currently enforced on critical information infrastructure operators here.
Speaking during the debate on the Bill, supported by all MPs, Senior Minister of State for Digital Development and Information Tan Kiat How said: “Many different digital services often rely on the same data centre or cloud service provider. When it is disrupted, the impact is not confined to one digital service. Many services can be affected at once, and the impact can quickly ripple across our economy and society.”
About two-thirds of the 70 data centres here cross specific revenue or electrical capacity thresholds under the new Bill. These thresholds are: an average annual revenue from users in Singapore over three years of at least $100 million, or operations requiring at least 10 megawatts (MW) of electrical capacity.
The authorities did not name the firms, but those operating in Singapore matching this scale include Amazon Web Services, Microsoft Azure and Google Cloud Platform.
Many of these major data centres will also be caught under the amended Cybersecurity Act.
During the five-hour debate on the new Bill spanning Oct 6 and 7, a total of 19 MPs spoke about data centres’ economic value and their impact on Singapore’s competitiveness and jobs here, as well as plans for older facilities, sustainability, security and resilience.
MPs like Sharael Taha (Pasir Ris-Changi GRC) and Saktiandi Supaat (Bishan-Toa Payoh GRC) asked whether the new requirements could weaken Singapore’s competitiveness and drive investments to regional rivals.
Nominated MP Neo Kok Beng and Shawn Loh (Jalan Besar GRC) asked if support would be provided to upgrade older data centres, while Lee Hui Ying (Nee Soon GRC) asked how Singaporeans would be upskilled to meet the sector’s growing needs.
Tan said that a sharp rise in demand for computing power to support artificial intelligence (AI) applications has made data centre development a contested and politicised issue in many countries.
Some countries have had to formulate responses after rapid data centre growth exerted pressures on electricity, water, and land. In 2026, Thailand froze approvals for new data centre projects to develop national standards, while Spain and Australia are working on legislation for data centres.
Similarly, Singapore needs to plan ahead with its limited land, power and water.
“We plan ahead...so that we can create as much room as possible for our digital economy and society, as well as AI ambitions while staying within our resource and environmental constraints,” said Tan.
Singapore currently has over 1.6 gigawatts of existing data centre capacity, across about 70 data centres. The figure includes 200MW of new capacity awarded to four operators in Aug 2026.
Tan pointed out that the Bill provides businesses certainty by setting out the regulatory clearly, while also giving the Government the flexibility to calibrate detailed security, resilience and sustainability requirements as circumstances evolve.
The Bill will introduce two licences: foundational digital infrastructure (FDI) and data centre (DC) licences.
Data centres that require 10MW of electrical power to operate essential computing equipment like servers, storage drives and networking hardware will need an FDI licence. Cloud service providers that generate more than an average annual revenue of $100 million from Singapore users over three years will also need to apply for an FDI licence.
FDI licencees will have to implement process to ensure the physical and cyber security of their services, put in place business continuity and disaster recovery plans to ensure essential operations can keep going during disruptions, and notify Infocomm Media Development Authority (IMDA) of prescribed cybersecurity incidents or service disruptions.
Details, which are still being worked out, will be introduced in subsidiary regulations and Codes of Practices.
Where reporting requirements for cyber security incidents are similar, IMDA will be the main port of call, and it will share information with the Cyber Security Agency of Singapore.
A data centre will need a DC licence if it uses at least 3MW of electricity to power essential computing equipment like servers, storage drives and networking hardware. DC licensees will need to meet power usage effectiveness (PUE) requirements that have yet to be determined.
PUE measures how efficiently a data centre uses energy, with a perfect score of 1. Data centre contracts awarded to operators in July 2023 had a PUE requirement of 1.3. Proposals selected in August 2026 had a requirement of 1.25.
“PUE is a useful starting point, but it does not capture every dimension of sustainability. Efficiency tells us how well a facility uses resources; we must also keep an eye on the sector’s overall use of electricity and water,” said Tan, adding that equipment-level energy efficiency and plant-level water efficiency may be considered in future.
He acknowledged that these requirements will be more challenging to meet for older data centres. Noting that some operators may need transition time, he committed to work with them.
Additionally, data centre operators that fail to deliver on economic commitments made to secure scarce capacity in Singapore could face enforcement action. These promises, such as investments, job creation and research, can be made conditions of their licences, he said.
IMDA will work with the Economic Development Board to resolve any alleged lapses.
Tan said that this reflects Singapore’s approach to maximise value from Singapore’s limited computing capacity.
“We are not seeking to attract every megawatt of data centre capacity we can... Scarce capacity should not simply be allocated; it should be put to productive use and deliver the value that was promised,” said Tan.
The Bill empowers IMDA to impose a fine of up to $1 million, or up to 10 per cent of a firm’s annual turnover in Singapore, whichever is higher, for failing to meet cybersecurity and business continuity requirements.
AI/artificial intelligence
Artificial Intelligence
吉宝数据中心园区外观,地址:云顶巷82号。
发布于 2026 年 10 月 7 日下午 2:25
更新于2026年10月7日下午2:27
- 新加坡通过了《数字基础设施法案》,旨在加强大型数据中心在安全性、韧性和能源效率方面的实力。
- 新加坡 70 个数据中心中约有三分之二需要基础数字基础设施许可证。
- 新加坡资讯通信媒体发展局 (IMDA) 可对企业处以最高 100 万美元或新加坡营业额 10% 的罚款,如果企业未能履行经济承诺,则可能面临处罚。
新加坡——随着一项新法案的通过和对现有法律的修订,支撑新加坡关键数字服务的大型数据中心将需要考虑一系列风险,从物理和运营连续性到网络安全。
10 月 7 日在议会通过的《数字基础设施法案》旨在通过许可制度确保能源效率和运营弹性,包括物理安全以及从系统配置错误、火灾、洪水和电力供应中断中恢复。
对现行《网络安全法》的修订还将使大多数主要数据中心受到与目前对关键信息基础设施运营商实施的类似的网络安全事件报告要求的约束。
在全体议员支持的法案辩论中,数码发展及新闻部高级政务部长陈杰豪表示:“许多不同的数字服务通常依赖于同一个数据中心或云服务提供商。一旦这些服务中断,其影响并非局限于单一数字服务。许多服务可能同时受到影响,并且这种影响会迅速波及我们的经济和社会。”
根据新法案,新加坡境内70个数据中心中约有三分之二的营收或电力容量超过了特定门槛。这些门槛包括:过去三年来自新加坡用户的年均营收至少达到1亿美元,或运营所需的电力容量至少达到10兆瓦(MW)。
当局没有透露这些公司的名称,但在新加坡运营且规模达到如此水平的公司包括亚马逊网络服务、微软 Azure 和谷歌云平台。
许多大型数据中心也将受到修订后的《网络安全法》的约束。
在 10 月 6 日至 7 日举行的长达 5 小时的新法案辩论中,共有 19 名国会议员发言,讨论了数据中心的经济价值及其对新加坡竞争力和就业的影响,以及旧设施的规划、可持续性、安全性和韧性。
议员沙拉尔·塔哈(巴西立-樟宜集选区)和萨克蒂安迪·苏帕特(碧山-大巴窑集选区)质疑,新要求是否会削弱新加坡的竞争力,并将投资推向区域竞争对手。
委任议员梁国明和卢晓明(惹兰勿刹集选区)询问是否会提供支持以升级老旧的数据中心,而李慧莹(义顺集选区)则询问如何提升新加坡人的技能以满足该行业不断增长的需求。
谭表示,为支持人工智能 (AI) 应用而对计算能力的需求急剧上升,使得数据中心的发展在许多国家成为一个充满争议和政治化的问题。
数据中心快速增长给电力、水和土地资源带来压力,一些国家不得不制定应对措施。2026年,泰国暂停审批新的数据中心项目,以制定国家标准;西班牙和澳大利亚也在着手制定数据中心相关法律。
同样,新加坡也需要提前规划,以应对其有限的土地、电力和水资源。
“我们提前做好规划……以便在资源和环境限制范围内,尽可能为我们的数字经济和社会以及人工智能雄心创造更多空间,”谭说道。
新加坡目前拥有超过1.6吉瓦的现有数据中心容量,分布在约70个数据中心。该数字包括2026年8月授予四家运营商的200兆瓦新增容量。
谭指出,该法案通过明确规定监管措施,为企业提供了确定性,同时也赋予政府灵活性,可以根据情况的变化调整详细的安全、韧性和可持续性要求。
该法案将引入两种许可证:基础数字基础设施(FDI)许可证和数据中心(DC)许可证。
运行服务器、存储驱动器和网络硬件等关键计算设备需要10兆瓦电力的数据中心需要申请外国直接投资许可证。此外,连续三年从新加坡用户获得年均收入超过1亿美元的云服务提供商也需要申请外国直接投资许可证。
获得外国直接投资许可证的企业必须实施相关流程,以确保其服务的物理和网络安全,制定业务连续性和灾难恢复计划,以确保在中断期间基本运营能够继续进行,并向信息通信媒体发展局 (IMDA) 报告规定的网络安全事件或服务中断。
具体细节仍在制定中,将在附属法规和行为准则中予以说明。
对于网络安全事件的报告要求类似的情况,新加坡资讯通信媒体发展局 (IMDA) 将是主要联系点,它将与新加坡网络安全局共享信息。
如果数据中心使用至少 3 兆瓦的电力来为服务器、存储驱动器和网络硬件等关键计算设备供电,则需要获得数据中心许可证。获得数据中心许可证的机构需要满足尚未确定的电源使用效率 (PUE) 要求。
PUE 衡量数据中心使用能源的效率,满分为 1。2023 年 7 月授予运营商的数据中心合同对 PUE 的要求为 1.3。2026 年 8 月选定的方案对 PUE 的要求为 1.25。
“PUE(电源使用效率)是一个有用的起点,但它并不能涵盖可持续性的所有方面。效率告诉我们一个设施如何有效地利用资源;我们还必须关注整个行业对电力和水的整体使用情况,”谭说道,并补充说,未来可以考虑设备层面的能源效率和工厂层面的用水效率。
他承认,对于老旧的数据中心而言,满足这些要求将更具挑战性。他指出,一些运营商可能需要过渡期,并承诺会与他们合作。
此外,他表示,未能履行为确保新加坡稀缺数据中心容量而作出的经济承诺的数据中心运营商可能面临执法行动。这些承诺,例如投资、创造就业机会和研发,可以作为其许可证的附加条件。
新加坡资讯通信媒体发展局将与经济发展局合作,解决任何被指控的疏漏。
陈先生表示,这体现了新加坡如何最大限度地利用其有限的计算能力。
“我们并非要尽可能吸引每一兆瓦的数据中心容量……稀缺的容量不应该只是被分配;它应该被有效利用,并交付承诺的价值,”谭说道。
该法案授权新加坡资讯通信媒体发展局 (IMDA) 对未能满足网络安全和业务连续性要求的公司处以最高 100 万美元的罚款,或公司在新加坡年营业额的 10%(以较高者为准)。
人工智能
人工智能