- Supports the page focus on collection, use, disclosure, and retention of NRIC numbers and links the NRIC advisory materials.
"collection, use and disclosure of NRIC"
Treat full NRIC numbers as restricted identifiers: collect, use, or disclose them only when required under the law or a PDPA exception applies, or when high-fidelity identity verification is necessary and notification and consent are obtained.
Use alternatives for routine accounts and public-facing systems, phase out NRIC-based authentication by 31 December 2026, mask or hash scanned values where appropriate, and keep full NRIC data only while a legal or business purpose remains.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page translates current PDPC NRIC guidance into implementation checks for product, privacy, security, support, and operations teams handling Singapore and comparable national identification numbers. The existing collection, use, disclosure, and physical-retention guidelines remain valid while PDPC updates them. Separately, PDPC says private organisations have until 31 December 2026 to phase out full or partial NRIC numbers for and will step up enforcement from 1 January 2027.
Private-sector organisations should not collect, use, or disclose full or NRIC copies as a default customer identifier. The PDPC guidelines allow the handling when it is required under the law or an exception under the PDPA applies, or when it is necessary to accurately establish or verify an individual's identity to a high degree of fidelity with notification and consent.
Operationally, require the requester to name the exact written law or PDPA exception, or the high-fidelity verification reason and how notification and consent are obtained, before a form, workflow, API, ticket, or vendor process accepts a full NRIC value. If the need is only account lookup, queue management, loyalty membership, event registration, building access, or customer support routing, design the workflow around a less sensitive identifier.
are permanent personal identifiers, not shared secrets. For websites, apps, memberships, kiosks, visitor systems, and other public-facing systems, replace NRIC-based usernames or primary identifiers with an identifier that is unique, memorable where needed, not sensitive, and not easily guessed.
Good replacement options depend on the workflow. User-selected usernames work for account logins; organisation-generated customer IDs work for evidence records; validated email addresses or mobile numbers can work where contact control is part of the customer journey; combinations of non-sensitive data can reduce collisions; and partial NRIC values should only be used with other data where a full NRIC is not permitted.
Do not treat knowledge of a full or partial NRIC number as proof that a person is the genuine user. PDPC and CSA advise organisations against using to authenticate persons because NRIC numbers identify people and should be assumed to have been disclosed to others.
PDPC says private organisations have until 31 December 2026 to phase out NRIC . From 1 January 2027, PDPC will step up enforcement; an organisation using to authenticate access to personal data may be found in breach of the PDPA . Remove NRIC values from passwords, default passwords, file passwords, customer-service challenge questions, and combined secrets such as partial NRIC plus date of birth. Choose authentication controls based on the value and sensitivity of the protected service or information, the threat model, and the accessibility of the method.
Systems that scan NRIC or FIN barcodes can receive the complete number even when the business process does not need to retain it. Convert scanned full NRIC values immediately into the final permitted format and avoid permanent storage of the complete number unless the full value is permitted under the NRIC rule.
For display, show a masked value when the complete NRIC is not strictly required. For matching, use a one-way hash where the system only needs to recognise a returning person or compare against a previous scan. Keep logs, analytics, exports, screenshots, and support transcripts out of scope for full NRIC exposure unless they have the same written-law, PDPA-exception, or high-fidelity verification basis.
Physical NRICs and other identity documents containing national identification numbers should be retained only when required by law. Checking a document to verify particulars is different from keeping the card, image, scan, or copy.
For NRIC values stored in systems, apply the PDPA retention limitation rule: stop retaining documents containing personal data, or remove the means of associating the data with individuals, once the original purpose is no longer served and retention is no longer necessary for legal or business purposes. The PDPA does not give one universal retention period; the record should explain the purpose, legal or business need, and deletion or anonymisation method.
This Singapore PDPA NRIC guide helps review forms, databases, scans, support scripts, authentication flows, and retention rules before collecting or keeping full NRIC values.
Use Assessment Autopilot to turn each NRIC field into a permitted-basis, masking, and retention check.
Use Research Copilot to verify whether a specific NRIC workflow has source support.
Review NRIC alternatives, authentication changes, and evidence records with Sorena.
"collection, use and disclosure of NRIC"
"physical NRIC unless the retention of the physical NRIC is required under the law"
"NRIC numbers should not be used as passwords"
"Personal Data Protection Act 2012"