KEEP IN TOUCH
Subscribe to our mailing list to get free tips on Data Protection and Cybersecurity updates weekly!




2027: Why NRIC Authentication Is Now a Data Protection Risk Singapore’s data protection regime is entering a decisive phase. With enforcement action against the misuse of NRIC numbers for authentication set to begin on 1 January 2027, organisations are being given a finite window to modernise their authentication practices. This shift is not merely technical.
4 PDPC Decisions Signal a Hard Line on Protection Obligation Singapore’s data protection enforcement landscape entered 2026 with unusual clarity. In January, the Personal Data Protection Commission released four separate enforcement decisions, all involving breaches of the protection obligation under the Personal Data Protection Act. Taken together, these decisions offer a sharp and consistent message
The breach of the protection obligation is the most common breach of the PDPA by the organisations in Singapore.
What every organization should know about the Protection Obligation Organizations should implement the necessary security measures to safeguard the personal data in their possession or under their control, as well as the storage media or devices on which such data is stored. This is done to prevent any unauthorized access, collection, use, or disclosure of