On 4 September 2026, Singapore's Security and Intelligence Division (SID) marked its 60th anniversary at a closed-door event. Prime Minister Lawrence Wong, the guest of honour, said that "trade, investment, supply chains and access to technology are increasingly being used as instruments of statecraft," according to the Ministry of Defence release of 5 September. Neither that release nor the accompanying fact sheet mentions oversight or accountability. The fact sheet says only that SID holds itself to "high standards of professional discipline and excellence."
This article does not allege wrongdoing by SID. Its point is narrower. A government that wants more intelligence capacity should also be willing to explain the checks on it.
The strongest case for the government
The case for Singapore's approach is serious. It is a small, trade-dependent city-state with no strategic depth. If the prime minister is right that technology access and supply chains are now levers of coercion, early warning is an economic necessity as well as a security one. Intelligence work also loses value when it is published. A closed-door commemoration and a thin fact sheet are normal for a foreign intelligence service, and no one expects an anniversary press release to carry an audit report.
The government also says it has built accountability elsewhere. When it defended exempting public agencies from the Personal Data Protection Act, it argued that they are bound instead by Government Instruction Manuals and the Public Sector (Governance) Act. It said these give "comparable if not higher standards of data protection," and that officers who misuse data face criminal liability, according to the Ministry's replies to parliamentary questions. Those replies put the penalty at fines up to $5,000 or up to two years' imprisonment.
Where the silence matters
The difficulty is that this framework is internal to the executive. The same replies show the government declined to impose financial penalties on agencies because the costs would simply return to public funds. The independent data regulator, the PDPC, supervises the private sector. It does not supervise public agencies.
The digital-control statutes show the same pattern. The Foreign Interference (Countermeasures) Act (FICA) was passed on 4 October 2021 by 75 votes to 11, with 2 abstentions. It lets authorities compel internet and social media providers to hand over user information, block content and remove applications, according to reporting on the vote. Appeals go to a tribunal chaired by a judge, whose rulings are final. Law professor Eugene Tan noted that the bill did not strengthen "checks and balances, particularly judicial review." Minister K Shanmugam defended it as the "best balance" between risk and safeguards against abuse.
The procedure in practice shows how the safeguards work. The Ministry of Home Affairs' FICA guidance says a recipient of a direction must first ask the Minister to reconsider, within 30 days. Only if the Minister refuses can the recipient appeal to the Reviewing Tribunal, within a further 30 days. The appeal carries a $200 fee. Meanwhile, the MHA's FAQ summary for the Act notes that a direction stays in effect while reconsideration is pending. The official FICA guidance says directions remain in effect despite any application made, until varied or cancelled. The minister who issued the direction is therefore the first reviewer of it, and the direction keeps operating throughout.
That design is defensible for fast-moving hostile information campaigns. But it is a thin substitute for prior independent authorisation or routine reporting on how often the powers are used.
Why this matters for an open internet
The prime minister's own framing raises the stakes. If access to technology is now a security domain, then more of the digital economy becomes a legitimate subject of intelligence interest: cloud providers, platforms, cable operators and the firms that depend on them. Companies and users deciding where to host data and build products price in this kind of discretion, even if it is rarely exercised.
The risk of the current approach is that it becomes a trust deficit that is easy to fix and costly to ignore. The government's own justification for data governance, that public servants are held to "comparable if not higher" standards, is an argument that those standards should be visible. The Health Sciences Authority incident involving more than 800,000 blood donors' records shows that public-sector data handling does fail, and that the public learned of it through disclosure and parliamentary questions, not through a standing independent mechanism.
Proportionate fixes
None of this requires exposing sources or methods. Proportionate transparency would look like this:
- Aggregate reporting. Publish annual counts of FICA directions and data-access orders, and of how many were varied or cancelled on reconsideration.
- Independent first look. For the most intrusive digital directions, add judicial or tribunal authorisation before issue, with the existing post-hoc route kept as a second check.
- Cross-agency data standards. Extend an independent regulator's audit role to public-sector personal data, with findings reported to Parliament.
- A statement of principle. The next SID anniversary should say plainly which body reviews its work and how Parliament is informed.
Singapore has earned credibility for competent, predictable governance. Spelling out the checks on its intelligence and surveillance powers would reinforce that credibility, and would cost little. The 60th anniversary was a missed chance to do so.