KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!
NRIC numbers are among the most familiar identifiers in Singapore, but familiarity can make organisations underestimate their data protection significance. An NRIC number is permanent, closely associated with an individual’s identity and capable of being linked with other information about that person. For that reason, organisations should not treat the collection of NRIC numbers as a routine administrative step simply because forms and processes have historically asked for them.
The PDPC’s Advisory Guidelines on the PDPA for NRIC and other National Identification Numbers clarify when organisations may collect, use or disclose NRIC numbers and when physical identification documents may be retained. The broader message is straightforward: organisations should be able to explain why they need NRIC numbers, rather than collecting them by default.
NRIC numbers differ from information that can easily be replaced. A compromised email address or password can be changed. A national identification number generally remains associated with an individual for life. That permanence increases the potential consequences if the information is unnecessarily collected, poorly secured or exposed.
This is why the question should not simply be whether collecting NRIC numbers is convenient. Organisations should first consider whether the information is genuinely necessary for the transaction or service involved.
The distinction matters because legacy processes can become difficult to challenge. A registration form may request an NRIC number simply because an earlier version did. Over time, unnecessary collection becomes normalised even though the business purpose could be achieved with less sensitive information.
The guidelines establish a useful starting point. Organisations are generally not allowed to collect, use or disclose NRIC numbers, or copies of NRICs, unless one of two circumstances applies.
The first is where the collection, use or disclosure is required under law, or an applicable exception under the PDPA applies. Certain regulated activities, for example, may require organisations to establish identity using prescribed information.
The second is where using the NRIC number is necessary to accurately establish or verify an individual’s identity to a high degree of fidelity. This is a higher threshold than ordinary identification. The potential consequences of identifying the wrong person should be sufficiently serious to justify using such a strong identifier.
This creates an important compliance test. Organisations should be able to articulate which basis applies and why a less intrusive identifier would not adequately serve the same purpose.
Another important distinction is between identifying someone and authenticating them. NRIC numbers may help distinguish one person from another in appropriate circumstances, but knowing somebody’s NRIC number does not prove that the person presenting it is genuinely that individual.
This distinction matters increasingly in digital systems. Information such as names, dates of birth and identification numbers can become exposed through data breaches, phishing or other sources. If possession of that information is treated as proof of identity, an attacker who obtains it may be able to impersonate the individual.
Organisations should therefore design authentication around stronger credentials and verification mechanisms rather than assuming that knowledge of personal information establishes legitimacy. NRIC information should be treated as an identifier that needs protection, not as a secret password.
Collecting information from an NRIC and physically holding the card are also different activities. Retaining somebody’s physical NRIC creates additional consequences because the person temporarily loses possession of an important identification document.
The guidelines therefore apply a particularly restrictive approach to physical retention. Organisations should not retain physical NRICs merely as collateral, security or an administrative convenience unless retention is required under law.
This is particularly relevant for traditional practices such as leaving an identity card at a counter in exchange for equipment, building access or visitor privileges. Organisations should consider alternatives that achieve the operational purpose without requiring them to hold the physical document.
One of the strongest practical lessons from the guidance is that organisations should challenge unnecessary collection before worrying about how to secure the information afterwards. If an organisation does not need NRIC numbers, not collecting them removes an entire category of risk.
Data minimisation also reduces the impact of a future breach. A customer database containing names and general contact information creates one level of exposure. Adding permanent national identifiers increases the sensitivity and potential downstream consequences considerably.
This makes NRIC governance relevant to cybersecurity as well as privacy. Security teams can protect databases with access controls, encryption and monitoring, but the safest unnecessary NRIC record is the one the organisation never collected.
Compliance problems are often embedded in operational processes rather than deliberate policy decisions. Marketing forms, visitor registration systems, membership applications, event registrations and legacy customer databases may continue requesting NRIC numbers long after the original reason has disappeared.
Organisations should periodically review these workflows and ask three practical questions: what purpose does the NRIC number serve, what allows the organisation to collect it, and could another identifier achieve the same outcome?
The same review should extend beyond forms. Copies of identification documents can exist in shared drives, email attachments or archived onboarding records. Understanding where this information resides is essential to applying appropriate access, retention and disposal controls.
A Data Protection Officer does not need to personally approve every instance involving an NRIC. The DPO’s value is providing a consistent point of oversight so that the organisation has appropriate policies and practices for handling personal data.
For NRIC numbers, this can include reviewing whether organisational practices align with the PDPA, advising teams when questions arise and helping ensure that unnecessary legacy collection does not quietly continue.
The objective is consistency. Different departments should not reach completely different conclusions about the same type of information simply because there is no established data protection framework.
Privacy Ninja’s DPO-as-a-Service helps organisations maintain practical PDPA compliance without requiring a dedicated full-time internal DPO. Our team supports the organisation with its core data protection policies and practices and provides ongoing advisory assistance when questions about personal data arise.
This is particularly useful when businesses are reviewing how they collect NRIC numbers. Existing forms and processes may have been created years ago, and operational teams may not know whether continued collection is necessary. An outsourced DPO provides a structured point of reference for assessing those practices and recommending appropriate adjustments.
Where technical assurance is required, Privacy Ninja’s cybersecurity services can complement data protection governance by helping organisations identify weaknesses in systems that store or process personal information.
The PDPC’s guidance on NRIC numbers is ultimately about necessity and proportionality. Organisations should not collect a powerful permanent identifier simply because doing so is convenient, familiar or historically part of a form.
The better approach is to start with purpose. If NRIC information is required under law or genuinely necessary to establish identity to a high degree of fidelity, organisations should collect only what they need and protect it appropriately. Where that threshold is not met, a less sensitive alternative should be considered.
Good NRIC governance therefore begins before information enters a database. By questioning unnecessary collection, separating identification from authentication and reviewing legacy practices, organisations can reduce both their compliance burden and the consequences of future data exposure.
Organisations should generally collect NRIC numbers only when required by law or when the number is necessary to establish or verify an individual’s identity to a high degree of fidelity.
No. Convenience alone is not a sufficient reason. Organisations should be able to explain why NRIC numbers are necessary and whether a less sensitive identifier could serve the same purpose.
No. An NRIC number is an identifier, not a secret credential. Organisations should not treat knowledge of an NRIC number as proof that the person presenting it is genuinely the individual concerned.
Physical NRICs should generally not be retained simply as collateral or for administrative convenience. Organisations should consider less intrusive alternatives unless retention is required by law.
They should review whether the collection is still necessary and legally justified. If the purpose can be achieved without NRIC numbers, the form or workflow should be updated and unnecessary stored copies should be reviewed for appropriate retention or disposal.