PDPC Steps Up NRIC Misuse Enforcement and Issues New Advisory
Summary
The Singapore Personal Data Protection Commission (PDPC) is stepping up enforcement against private organizations misusing NRIC numbers for authentication starting January 1, 2027. New advisories are also being issued to guide organizations on data protection lapses and recommend more secure authentication methods.
What changed
The Personal Data Protection Commission (PDPC) of Singapore has announced enhanced enforcement actions against private organizations that continue to use NRIC numbers for authentication purposes, effective January 1, 2027. This initiative follows a joint advisory from the PDPC and the Cyber Security Agency of Singapore (CSA) in June 2025, highlighting the risks associated with NRIC misuse and urging a transition to more secure authentication methods. Organizations found in breach of PDPA obligations for failing to implement reasonable security arrangements may face penalties.
Organizations are advised to review their current authentication processes and migrate to more secure alternatives before the December 31, 2026, deadline. The PDPC has also released a new advisory detailing common data protection lapses and providing recommended measures to help organizations manage personal data, including NRIC numbers, more effectively. Compliance with these directives is crucial to avoid potential breaches of data protection obligations.
What to do next
- Review current authentication methods and transition away from using NRIC numbers.
- Implement more secure authentication alternatives as outlined in PDPC and CSA advisories.
- Consult the new PDPC advisory on common data protection lapses and recommended measures.
Source document (simplified)
The Personal Data Protection Commission (PDPC) has issued a media release on stepping up enforcement action from 1 January 2027 against private organisations that use NRIC numbers for authentication purposes.
Organisations should review their authentication methods and transit to more secure alternatives, as outlined in the Joint Advisory by the PDPC and Cyber Security Agency of Singapore (CSA) in June 2025. Using NRIC numbers for authentication increases the risk of unauthorised access, and organisations that continue such practices may be found in breach of their PDPA obligations for failing to implement reasonable security arrangements to protect personal data.
To support organisations that manage personal data including NRIC numbers, PDPC has also published an advisory on common data protection lapses with recommended measures.
Read more:
- Media Release: Organisations To Cease the Use of NRIC Numbers for Authentication by 31 December 2026
- Advisory on Common Data Protection Lapses and Recommended Measures
- FAQs for Organisations
FAQs for Individuals
Tags:
- ### Joint Advisory against using NRIC Numbers for Authentication by the Personal Data Protection Commission (PDPC) and Cyber Security Agency of Singapore (CSA)
- ### Organisations to cease the use of NRIC numbers for authentication by 31 December 2026
- ### Advisory on Common Data Protection Lapses and Recommended Measures
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Protection alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when PDPC Announcements (Singapore) publishes new changes.