Singapore’s OCHA Codes of Practice: A Structural Reckoning for Messaging and Social Media Platforms

The Regulatory Thesis
Singapore’s Online Criminal Harms Act Office has issued a set of binding codes of practice that fundamentally recast the legal obligations of messaging services, social media platforms, and e-commerce operators — and the central argument embedded in this regulatory architecture is unambiguous: platforms that profit from user engagement bear direct institutional responsibility for the criminal activity that engagement enables. This is not a nudge toward self-regulation. It is a structured liability framework, backed by escalating financial penalties, designed to compel systemic behavioural change from some of the world’s most powerful technology companies.
The Singapore Police Force announced the measures on 18 August, framing them under three distinct codes — one for online messaging and conferencing services, one for social media platforms, and an enhanced version of an existing e-commerce code. Taken together, they represent the most comprehensive anti-scam regulatory intervention Singapore has directed at digital platforms to date, and they arrive at a moment when the data on scam prevalence is difficult to dismiss. WhatsApp and Telegram alone accounted for approximately 23 per cent of all scam cases in 2025; Facebook, Instagram, and TikTok collectively accounted for roughly 30 per cent, with Facebook bearing 18 per cent of that share independently.
The Messaging Code: Consent, Context, and Impersonation
Seven platforms have been designated under the messaging code on the basis that they pose the highest scam risk to users in Singapore: WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages, and Google Meet. The selection reflects both market penetration and documented misuse patterns — Google Meet, for instance, has been observed as a vehicle for phishing scams involving the impersonation of police officers, a detail that illustrates how even video-conferencing infrastructure has been absorbed into the scam ecosystem.
The substantive requirements under the messaging code are architecturally significant. Platforms must obtain a user’s explicit consent before that user can be added to a group or channel by an unknown contact — a direct disruption of the mass-recruitment mechanic that investment scam syndicates have exploited systematically. Platforms must also display contextual risk indicators when users receive messages or calls from unknown or suspicious accounts, with disclosures potentially including account creation date and country of origin. This shifts informational asymmetry in the user’s favour, giving individuals the material context they need to make an informed decision before engaging with an unknown interlocutor. Additionally, platforms must provide users with the option to silence, filter, or block communications from numbers not saved in their contact lists.
A separate and more urgent timeline governs the anti-spoofing requirements. Because government official impersonation scams — approximately 18 per cent of which occurred on WhatsApp in 2025 — represent a category of harm with acute public trust implications, the messaging code requires platforms to prevent the spoofing of Singapore Government entities through profile names or images by 30 September 2026. The remaining measures carry a compliance deadline of 31 January 2027, a timeline that is firm rather than aspirational given the penalty framework underpinning it.
The Social Media Code: Advertising Accountability as a Structural Obligation
The social media code introduces a dimension that the messaging code does not: the explicit implication of advertising revenue in the scam economy. The OCHA Office’s framing here is pointed — social media platforms profit from publishing advertisements, and they therefore bear a duty to ensure that this revenue stream is not instrumentalised for criminal purposes. Facebook, Instagram, and TikTok, the three designated platforms, must now implement pre-publication checks to prevent scam advertisements from reaching Singapore users, including detection of URL cloaking — a technique used to obscure a destination website’s true address and a common tool in phishing operations.
Beyond detection, the code mandates prompt removal of suspected scam advertisements accessible to Singapore users, including those flagged through user reports. This introduces a responsive enforcement obligation rather than a purely proactive one, recognising that no algorithmic filter is exhaustive. The most structurally significant requirement, however, concerns advertiser identity verification: platforms must conduct checks against government-issued records before allowing advertisers to publish content targeting Singapore users. Furthermore, any advertisement offering financial services or products must be traceable to an entity licensed by the Monetary Authority of Singapore or another applicable authority — a requirement that directly closes the loophole through which unlicensed investment products have been marketed at scale on these platforms.
E-Commerce and the Enforcement Architecture
The enhanced e-commerce code applies to Carousell, Facebook Marketplace, and Facebook Business Pages, building on seller verification and payment protection requirements introduced in June 2024. The enhancements focus on device-level security — specifically, stronger consent mechanisms before logins from new or unrecognised devices are permitted — and adopt the advertising safeguards from the social media code. Carousell’s public response was notably measured: a spokesperson confirmed that the company was already compliant with the most material requirements and anticipated no difficulty meeting the January 2027 deadline, a statement that reads as institutional readiness rather than mere diplomatic courtesy.
The enforcement architecture deserves careful attention because it is where Singapore’s regulatory intent becomes most legible. Under the current OCHA penalty framework, non-compliance with a rectification notice carries a fine of up to S$1 million, with a further S$100,000 per day for continuing offences. Proposed legislative amendments, introduced to Parliament in August and due for a second reading in September under the Scams (Countermeasures) and Other Matters Bill, would substantially raise these ceilings. Under the proposed framework, the OCHA Office could impose financial penalties of up to S$10 million per instance of non-compliance, with fines of up to S$300,000 per day for continuing offences after conviction. These are not nominal deterrents — they are numbers calibrated to register meaningfully on the balance sheets of global technology companies.
The broader implication of this regulatory moment is that Singapore is operationalising a theory of platform co-responsibility that many jurisdictions have debated but few have codified with this degree of procedural specificity. By rescinding the existing Online Communication Services Code once the new codes take effect, the OCHA Office is not merely adding rules — it is replacing a general framework with targeted, platform-class-specific obligations that leave considerably less interpretive room. Whether global platforms will absorb these requirements as Singapore-specific carve-outs or as templates for broader operational reform remains to be seen. What is clear is that the regulatory cost of inaction has been materially raised.





