When may an organisation collect, use, or disclose a full NRIC number under Singapore PDPA guidance?
For private-sector use, PDPC's NRIC guidelines say organisations should collect, use, or disclose NRIC numbers or copies of NRIC only where the collection, use, or disclosure is required under the law or an exception under the PDPA applies, or where it is necessary to accurately establish or verify an individual's identity to a with notification and consent.
Treat this as a narrow justification test, not a default account-creation field. Before a form, workflow, vendor handoff, or support script asks for a full NRIC, record the written-law or PDPA-exception basis, or the concrete high-fidelity identity-verification reason and how notification and consent are obtained. If neither basis exists, redesign the process around another identifier.
- Allowed trigger: a written law requires the collection, use, or disclosure, or an exception under the PDPA applies.
- Allowed trigger: the service genuinely needs high-fidelity identity establishment or verification and satisfies the notification and consent requirements.
- Not enough: convenience, legacy database design, duplicate-account prevention, loyalty programme membership, or using NRIC as a username.
Supports the two permitted bases for collecting, using, or disclosing full NRIC numbers or NRIC copies.
Identifies the PDPC guidance as covering collection, use, disclosure, and physical NRIC retention.