Data centers could be classed as critical infrastructure under new legislation in Singapore
Data centers may face more stringent regulation under proposed changes to the country's cyber security act


Data centers could be classed as critical infrastructure according to a recently published consultation paper in which the Cyber Security Agency of Singapore (CSA) proposed amendments to Singapore’s 2018 cyber security act.
The original act defined critical infrastructure as computer systems necessary for the “continuous delivery of an essential service”, citing examples such as energy, water, healthcare, and transport.
Read more
In the proposed amendments, foundational digital infrastructure, including data center facilities located within Singapore, could be added to the list. This would have the potential to impact big name cloud companies like Google and AWS.
The changes would also see the CSA commissioner take on a bigger role, giving them the final say on which computer systems are designated as critical infrastructure. Data centers would also be required to comply with the CSA commissioners requests.
A global push toward data regulation
Singapore isn’t the only country moving towards a new classification of data as critical infrastructure.
The UK recently announced its own proposal to class data centers as critical infrastructure, with the Department for Science, Innovation, and Technology (DSIT) arguing that existing data regulations don't go far enough.
RELATED RESOURCE
Securely enable cloud applications
DOWNLOAD NOW
Australia also expanded its definition of critical infrastructure in 2022, while Germany has been regulating data centers since 2016.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“Since the Act was enacted, the cyber threat landscape and business environment have been continually changing” said the CSA.
“Singapore is now amongst one (sic) of the most digitally connected countries in the world,” it added. “These developments have accelerated our connectivity, computing and data storage needs. These bring about new considerations for cybersecurity.”
Stakeholders and members of the public can share their views on the proposed changes here, before the end of the consultation period on 15 January 2024.

George Fitzmaurice is a former Staff Writer at ITPro and ChannelPro, with a particular interest in AI regulation, data legislation, and market development. After graduating from the University of Oxford with a degree in English Language and Literature, he undertook an internship at the New Statesman before starting at ITPro. Outside of the office, George is both an aspiring musician and an avid reader.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Fortify your future: How HPE ProLiant Servers deliver top-tier cyber security, management, and performance
Whitepaper Deploy servers with a secure approach
By ITPro Published
-
Fortify your future with HPE ProLiant Servers powered by Intel
Whitepaper Enhance your security and manage your servers more effectively
By ITPro Published
-
Better together: HPE Aruba Networking CX switches and HPE Aruba Networking Central
Whitepaper Explore the power and simplicity of managing HPE Aruba Networking CX Switches with HPE Aruba Networking Central
By ITPro Published