Categories: PDPA

by Koh Teng Teng

Share

PDPAFebruary 2nd, 2026

Share

From 1 January 2027, organisations in Singapore are expected to stop using NRIC numbers as a means of authentication. The change matters to almost every business, because the practice it targets is so common that most companies do not realise they are doing it: asking a caller for the last three digits of their NRIC, setting an NRIC number as the password on a payslip, or using it as a customer login ID.

The underlying point is simple, and it is worth stating plainly. An NRIC number is an identifier, not a secret. It appears on forms, contracts, delivery labels, insurance documents and school records. Treating something that widely known as proof of identity is what creates the risk — and it is that practice, rather than the collection of NRIC numbers itself, that the Personal Data Protection Act (PDPA) framework is moving against.

This article sets out what is changing, what your business can still lawfully do, where NRIC numbers tend to hide in day-to-day operations, and the practical steps to take before the deadline.

Chat with us here to see how we can help.

What Exactly Is Changing for NRIC Use in Singapore?

The shift follows sustained public and regulatory attention on how freely NRIC numbers circulate. The position now being reinforced is threefold:

  • NRIC numbers must not be used as authenticators. They cannot serve as passwords, PINs, verification questions or standalone proof that a person is who they claim to be.
  • Masking is not a control. Partially hiding an NRIC number does not turn it into a secret. Because the format is predictable and the unmasked portion is widely circulated, masking provides reassurance rather than security.
  • Collection rules are unchanged in principle. Where the law requires you to collect an NRIC number, or where you genuinely need it to verify identity to a high degree of fidelity, you may still collect it. What you may not do is repurpose it as a credential.

For most businesses, then, this is not a data deletion exercise. It is an authentication redesign — and the two are frequently confused, which is why remediation projects often start in the wrong place.

Identifier or Authenticator — Why Does the Distinction Matter?

This single distinction determines whether a given practice in your business is acceptable or needs to change.

An identifier answers “who is this?”

Using an NRIC number to match a person to the correct medical record, tax file or client account is an identifier use. It distinguishes one person from another. This remains permissible where you have a lawful basis to collect the number.

An authenticator answers “are you really this person?”

Accepting an NRIC number as evidence that the person on the phone, on the form or at the counter is the account holder is an authenticator use. Because the number is not confidential, anyone who has seen it can impersonate the individual. This is the practice being phased out.

The test to apply to any process in your business is: if someone else knew this number, could they gain access to something? If the answer is yes, you have an authentication problem to fix.

What Is the Legal Basis for Stricter Enforcement?

The Personal Data Protection Act is the legal framework the Personal Data Protection Commission (PDPC) enforces, supported by its Advisory Guidelines on NRIC and other national identification numbers. Several PDPA obligations bear directly on NRIC handling:

  • Purpose Limitation: personal data may only be collected, used or disclosed for purposes a reasonable person would consider appropriate in the circumstances. Convenience is not a purpose.
  • Notification and Consent: individuals must be told what you are collecting and why, before or at the point of collection.
  • Protection Obligation: you must make reasonable security arrangements to protect personal data in your possession or control — which is precisely where NRIC-as-password fails.
  • Retention Limitation: you must cease retention once the purpose is served and there is no legal or business need to keep it. Legacy NRIC fields sitting in an old CRM fail this test.
  • Accountability: organisations must appoint a data protection officer, make that person’s business contact details available, and put policies and practices in place to meet PDPA obligations.

The goal of stricter enforcement is not administrative tidiness. It is to reduce the impersonation and identity-fraud risk created when a widely circulated number is treated as a credential.

When Can Your Business Still Collect and Use NRIC Numbers?

Businesses in Singapore must adhere to the PDPA when dealing with NRIC numbers, and legitimate purposes for NRIC collection are strictly defined.

Which Scenarios Are Legitimate?

Collection is generally acceptable in two situations: where it is required or authorised under written law, and where it is necessary to accurately establish or verify identity to a high degree of fidelity. In practice this covers:

  • Regulated financial services — customer due diligence performed by banks, fund managers, insurers, payment institutions and other MAS-regulated entities
  • Employment — hiring, payroll, CPF, tax filing and work pass administration
  • Healthcare — patient identification, where a mismatch carries serious consequences
  • Property, tenancy and legal transactions — where statutory or contractual identification is required
  • Sector-specific obligations — for example, telecommunications subscriber registration

Which Uses Are Prohibited?

NRIC numbers should not be collected or used for unauthorised authentication, nor retained without a valid reason. Common practices that do not survive scrutiny include:

  • Lucky draws, contests, webinar sign-ups and event registration lists
  • Loyalty programmes, membership cards and mailing list subscriptions
  • Visitor management — recording NRIC numbers in a logbook or retaining physical NRIC cards at reception
  • Using an NRIC number as a customer account number, login ID or employee ID
  • Setting an NRIC number, or part of it, as the password on statements, payslips or reports
  • Telephone verification that relies on the caller reciting NRIC digits
  • Retaining full photocopies or scans of NRIC cards where only limited details were needed

Does Masking the NRIC Solve the Problem?

No — and relying on it is one of the more common errors. A masked NRIC is still personal data, and the masked format does not prevent an unauthorised person from using the visible portion to impersonate someone. Masking may still have a role in limiting unnecessary display on screens and documents, but it should be understood as data minimisation, not as authentication. Any process where masked digits are the thing being checked still needs to change.

Where Do NRIC Numbers Hide in Your Business?

Most organisations underestimate the footprint. Before you can fix anything, you need to know where the numbers are. Work through these locations systematically:

  • Customer-facing forms — online sign-up, paper forms, PDFs, third-party landing pages
  • Call centre and front-desk scripts — verification questions and escalation procedures
  • Document security — password-protected statements, payslips, policy documents and invoices
  • Core systems — CRM, HR and payroll platforms, ticketing systems and databases, including fields used as primary keys
  • Legacy and shadow data — spreadsheets on shared drives, exported reports, archived email attachments, old backups
  • Physical records — visitor books, filing cabinets, photocopies of identity documents
  • Third parties — vendors, outsourced service providers, marketing agencies and IT contractors holding data on your behalf
  • Communications — NRIC numbers appearing in email subject lines, chat logs or message templates

This inventory is the deliverable that makes everything downstream possible. Without it, remediation becomes guesswork, and you will not be able to demonstrate to the PDPC that you assessed your exposure.

What Should You Use Instead of NRIC Numbers?

The replacement depends on whether you are fixing an identifier or an authenticator.

To replace an identifier

Use a system-generated account or member number, a user-created username, a registered email address, or a mobile number. These can be reissued if compromised — which is the entire point, and something an NRIC number can never offer.

To replace an authenticator

Use something the individual knows, holds or is: a password or PIN they set themselves, a one-time passcode sent to a registered channel, multi-factor authentication, Singpass-based verification for higher-risk transactions, or biometric verification where proportionate. For call centres, replace NRIC recitation with a combination of account-specific information and a callback or OTP to the registered number.

How Does This Affect MAS-Regulated Firms That Must Collect NRIC for KYC?

This is the question we field most often from financial institutions, and the answer is reassuring on collection but not on usage.

If you are a bank, licensed fund management company, capital markets services licensee, insurer or payment institution, your AML/CFT obligations require you to identify and verify customers — which necessarily involves NRIC numbers. That collection sits squarely within the legal-requirement exception, and nothing about the NRIC changes removes it.

What does change is everything downstream:

  • You cannot use the NRIC number as the client’s portal login or the password on their statements
  • Telephone verification of a client cannot rest on NRIC digits alone
  • Access to full NRIC numbers within your CRM should be restricted to staff with a genuine need, not available to every user by default
  • Retention of NRIC data must follow both your PDPA retention schedule and the record-keeping periods imposed by MAS — where they conflict, the regulatory retention requirement generally prevails, and the rationale should be documented

Firms that already operate a mature regulatory compliance framework will find this straightforward to absorb. For a broader view of how data protection sits alongside licensing and conduct obligations, see our guide on building a compliance framework that survives regulatory inspection.

What Are the Penalties for Getting This Wrong?

Non-compliance with PDPA obligations can lead to significant consequences. Following investigation, the PDPC may issue directions to stop a practice, require remediation, and impose a financial penalty — with the maximum for larger organisations calculated by reference to a percentage of annual turnover in Singapore, subject to a statutory floor. Directions and decisions are frequently published, which carries its own commercial cost.

There is a second exposure that businesses often overlook. Where weak authentication leads to unauthorised access to personal data, you may face a data breach notification obligation: assess the incident promptly, notify the PDPC within the prescribed period where the breach is notifiable, and notify affected individuals where the breach is likely to result in significant harm. An NRIC-as-password practice is precisely the kind of control weakness that turns a minor incident into a notifiable breach. If your incident response process has not been tested recently, read our practical walkthrough on handling a personal data breach in Singapore.

What Should You Do Before the Deadline?

A workable sequence for most organisations:

  1. Map it. Build the NRIC inventory across systems, forms, documents, vendors and physical records.
  2. Classify each use. For every instance, decide: is this an identifier, an authenticator, or a use with no lawful basis at all?
  3. Stop the authenticator uses first. These carry the highest fraud and enforcement risk and are usually the quickest to fix.
  4. Remove collections you cannot justify. Amend forms, remove fields, and stop the practice at source before cleaning up historical data.
  5. Migrate identifiers. Introduce system-generated references and plan the data migration, including legacy records and integrations.
  6. Tighten access and retention. Restrict who can view full NRIC numbers, apply a documented retention schedule, and dispose of what you no longer need.
  7. Update documentation. Refresh your data protection policy, privacy notice, consent wording, and vendor data protection agreements.
  8. Train the people who touch it. Front desk, call centre, HR and sales are where old habits persist longest.
  9. Record your decisions. Keep the assessment, the rationale and the remediation log. If the PDPC asks, a documented decision trail is your strongest position.

How Does Alder Compliance Support Your Business as an Outsourced DPO?

Alder Compliance grasps the intricacies of PDPA and NRIC regulations. We help businesses in Singapore establish strong data protection measures, so that compliance is demonstrable rather than assumed.

Appointing a data protection officer is mandatory under the PDPA, but few organisations need a full-time one. Our outsourced DPO service gives you a named, contactable DPO with the experience to run the work that matters: NRIC and personal data mapping, gap assessment against the PDPA obligations, policy and notice drafting, vendor due diligence, staff training, and incident response when something goes wrong.

We also provide compliance policy outsourcing, allowing businesses to concentrate on their main activities while adhering to regulations. With our knowledge, companies can confidently handle the changing regulatory environment in Singapore.

Frequently Asked Questions

Can we still ask customers for their NRIC number?

Yes, where the law requires it or where you genuinely need it to verify identity to a high degree of fidelity. What you cannot do is collect it out of habit or convenience, or use it as a credential once collected.

Is using only the last four digits of the NRIC acceptable?

Not as an authenticator. Partial NRIC numbers remain personal data and provide no meaningful security, because the visible digits are widely circulated on forms and documents. Replace the verification step rather than shortening the number.

Do we need to delete every NRIC number we hold?

No. You need to stop retaining NRIC numbers you have no lawful basis or business need to keep, and stop using them as authenticators. NRIC data held under a statutory or regulatory requirement should be retained for the required period, with access controlled and the basis documented.

Does this apply to employee data as well as customer data?

Yes. HR is one of the most common places NRIC numbers are misused — as employee IDs, as payslip passwords, and in spreadsheets shared across the business. Employment-related collection is generally permitted, but the authenticator and retention rules apply equally.

What if our vendor’s system uses NRIC as a key field?

You remain accountable for personal data processed on your behalf. Raise it with the vendor, confirm their remediation timeline in writing, and reflect the obligation in your data protection agreement. Where the vendor cannot change the field, compensating controls such as restricted access and encryption should be documented.

Is an outsourced DPO acceptable under the PDPA?

Yes. The PDPA requires you to appoint at least one individual as DPO and make their business contact information available; the role may be filled by an external provider. Accountability for compliance stays with the organisation, so the arrangement should be documented and the DPO given real access to systems, people and management.

This article is provided for general information and does not constitute legal advice. Regulatory requirements and timelines change — confirm the current position with the PDPC or seek advice specific to your circumstances.

About the Author: Koh Teng Teng

Teng Teng is the Compliance Director at Alder. She holds a Bachelor of Arts from the National University of Singapore and is an Associate of The Chartered Governance Institute (CGI) and the Chartered Secretaries Institute of Singapore (CSIS). With over 7 years of experience in compliance and regulatory advisory, she leads Alder’s outsourced compliance service delivery, helping clients strengthen governance and meet Singapore regulatory requirements.

Related Posts