A clipboard on a wooden desk holding a handwritten plan headed with a list of steps, used to illustrate an NRIC data migration checklist
Home » Blog » NRIC Numbers in Singapore Marketing: What Has to Change Before 31 December 2026

NRIC Numbers in Singapore Marketing: What Has to Change Before 31 December 2026

“Can I have the last four digits of your IC?” is probably the most-repeated sentence in Singapore retail. It unlocks a loyalty account at the till, confirms a name on an event guest list, releases a prize at a redemption counter, and opens a password-protected statement in an email attachment.

On 1 January 2027, the last of those becomes an enforcement target. The Personal Data Protection Commission has given private organisations until 31 December 2026 to stop using NRIC numbers for authentication, and has said that from the new year it will step up enforcement — including directions and financial penalties — against those that have not.

That is four months away as this is published, and the systems it touches are almost all marketing-owned: loyalty, events, contests, memberships and customer service. This guide separates the two different NRIC rules that are commonly collapsed into one, works through where each bites in a marketing stack, and gives a sequence for getting off the pattern before the deadline.

It sits alongside our broader guide to the PDPA, marketing and tracking in Singapore, which covers consent and tracking generally and is not repeated here, and our performance marketing guide, which is where the measurement side of your customer data lives.

Two different rules, and why collapsing them causes the mistake

There are two separate NRIC rules in play, made at different times, doing different jobs.

Rule one: the collection rule, in force since 1 September 2019

The PDPC’s Advisory Guidelines on the Personal Data Protection Act for NRIC and Other National Identification Numbers, issued 31 August 2018, set the baseline: organisations are generally not allowed to collect, use or disclose NRIC numbers or copies of the NRIC. The same treatment applies to Birth Certificate numbers, Foreign Identification Numbers and work pass numbers.

There are two exceptions. The first is where collection, use or disclosure “is required under the law”. The second is where the organisation “finds it necessary to accurately establish or verify the identity of the individual to a high degree of fidelity” — in which case it may collect the number with notification and consent.

The guidelines then say when PDPC would generally consider that threshold met: where failure to identify the individual accurately “may pose a significant safety or security risk” (their example is visitor entry to preschools), or where it “may pose a risk of significant impact or harm to an individual and/or the organisation”, such as fraudulent claims. The transactions listed are healthcare, financial and real-estate matters — property transactions, insurance applications and claims, substantial financial aid, credit checks, medical reports.

Almost nothing in a marketing programme reaches that bar. A loyalty sign-up is not a property transaction.

The guidelines also carve out a middle path. Paragraph 5.2 recognises that organisations may want a partial number where alternatives are unsatisfactory, and states that collecting a partial NRIC number up to the last 3 numerical digits and the checksum would not be considered collecting the NRIC number at all. That single sentence is why so many Singapore membership schemes are built on the last three digits and the letter.

Rule two: the authentication rule, deadline 31 December 2026

In June 2025 the PDPC and the Cyber Security Agency of Singapore issued a joint advisory against using NRIC numbers for authentication. On 2 February 2026 the PDPC published its media release setting the deadline. Its wording is worth quoting exactly:

“Private organisations will have until 31 December 2026 to phase out the use of NRIC numbers for authentication. From 1 January 2027, the Personal Data Protection Commission (PDPC) will step up enforcement action against private organisations that use full or partial NRIC numbers for authentication.”

And on the mechanism of liability: “Organisations that use NRIC numbers for authentication to access personal data may be found to have breached the Personal Data Protection Act (PDPA) for failing to make reasonable security arrangements to protect personal data. From 1 January 2027, the PDPC will step up enforcement action against such misuse, including imposing directions or financial penalties for such breaches where appropriate.”

The release gives the pattern it has in mind: “Common examples of misuse include using NRIC numbers (whether in full or part) as default passwords, whether on their own or together with other easily obtainable personal data such as names and birthdates (e.g. ‘567A01Jan80’). Such passwords should not be used to access digital documents or to allow access to an individual’s account.”

It also notes that IMDA, MAS and MOH have issued sector guidance for telecommunications, finance and insurance, and healthcare respectively — so if you market in one of those sectors, there is a second document to read.

The distinction the whole thing turns on

The media release defines the two words in a footnote, and it is the most useful sentence published on this subject:

“Authentication refers to the process of proving that a person is who he claims to be, before granting him access to services or information intended only for him. This differs from identification, where identifiers such as names are used to tell people apart.”

Identification tells people apart. Authentication proves someone is who they say they are, before giving them something. The same string of characters can do either job, and the rules are opposite.

Decision test distinguishing identification from authentication for a partial NRIC number The one test to apply to every field that holds an NRIC Is this string the only thing standing between a stranger and the account? NO — IDENTIFICATION It only tells two customers apart, alongside a separate check. Last 3 digits + checksum is not treated as collecting the NRIC (para 5.2) YES — AUTHENTICATION It proves who they are before they are given something. Full OR partial — must be gone by 31 December 2026 The trap: the same partial NRIC is printed on the card as an identifier and typed at the counter as a password. One use is fine; the other is not.
Identification and authentication can use the identical string. Only one of the two uses survives 31 December 2026.

The trap: the same partial NRIC is blessed and banned at the same time

Read the two rules together and a genuinely awkward result appears — one that most Singapore loyalty programmes are sitting on right now.

The 2018 guidelines’ own worked example describes a retail store creating a unique identifier for each member, and suggests it “consider allowing its members to use identifiers, such as their mobile numbers, email address, user-generated identifier or partial NRIC number”. The same example then has the store run a lucky draw, collecting the full name, partial NRIC number and contact details “for the purpose of contacting the winners of the lucky draw and verifying the identities of the winners”, with verification done “by checking their full names and partial NRIC number against the information on their physical NRIC”.

That is still good guidance, and it is not withdrawn. Note what makes it work: the verification happens in person, against the physical card. The partial number is one factor checked against a document the winner is holding. It is not a secret typed into a box.

The pattern that fails is the one that grew out of it. The membership number printed on the card is the last three digits and the checksum, and the staff member at the counter asks for exactly that string to pull up the account and apply the points. At that moment the identifier has become the password, and the 2 February 2026 media release captures it by name: full or partial NRIC numbers used for authentication.

The test to apply to every field in your stack is a single question: if a stranger knew this string, could they get into the account or collect the thing? If yes, it is authentication, whatever your system calls the field.

Where this bites, system by system

Marketing system What it does with the NRIC today Identification or authentication? What to change before 31 Dec 2026
Loyalty lookup at the till Staff ask for last 4 of IC, pull up account, apply points Authentication Move to a scannable member QR or a phone number plus a one-time code
Event check-in Guest gives IC digits, name is ticked off Authentication where it releases entry or a goodie bag Unique registration reference in the confirmation email; scan it
Prize redemption Winner states IC digits to collect Identification if checked against the physical card in person; authentication if stated over phone or chat Keep the in-person document check; remove the remote version entirely
Guest order lookup on your site Order number plus last 4 of IC Authentication Emailed magic link, or order number plus a code sent to the order’s own contact
Call-centre verification “Can you verify the last 4 of your IC?” Authentication Outbound one-time code to the number on file; verify against that
Password-protected PDF statements PDF password is IC digits, or IC plus date of birth Authentication — named in the PDPC release Portal download behind a real login, or a per-document one-time password
Membership portal login IC number as the username or the password Username is identification; password is authentication Email or mobile as the username, a real password or passwordless login
CRM record key Full NRIC stored as the primary key Identification — but likely collected without a valid basis System-generated ID; assess whether the number should be held at all

Two rows deserve extra attention because they are the ones marketing teams own outright.

Prize redemption. Our guide to lucky draw and contest rules in Singapore sets out the separate obligation to notify each winner within seven days and deliver prizes without delay. That clock creates pressure to verify quickly and remotely, over a phone call or a chat thread — and remote verification against a partial NRIC is precisely the authentication use that has to go. Design the verification method into the mechanic before the campaign launches, not at the redemption counter.

Password-protected statements and documents. The PDPC release names this pattern directly, including the composite form of NRIC plus birthdate. If your email service provider sends anything as a protected attachment keyed on IC digits, that is on the list.

The physical NRIC rule people forget

Separate from both rules above, the 2018 guidelines address retention of the physical card. Given the importance of the NRIC as a national identification document and the consequences if it is lost, stolen or used for illegal activity, organisations should not retain the physical NRIC unless retention is required under the law. The same treatment extends to other identification documents such as a driving licence, passport or work pass.

In marketing terms: no holding an IC at a registration desk, an event counter or a showroom while someone browses. If you need to confirm identity, look and hand it back.

What to replace it with

The PDPC deliberately does not prescribe replacements. Paragraph 5.1 says organisations should assess suitability against their own business and operational needs, and lists alternatives that organisations have adopted: an organisation- or user-generated ID, a tracking number, an organisation-issued QR code, or a monetary deposit. It adds that organisations should consider whether the alternatives are reasonable and avoid collecting excessive data in their place.

For a marketing stack, the practical shortlist is short:

  • Mobile number plus a one-time code. Works at a till, on a phone call and online. You almost certainly hold the number already. Note that if you then market to that number, the Do Not Call Provisions apply — covered in our guide to WhatsApp marketing in Singapore.
  • An organisation-issued QR code or member barcode. The guidelines name it, it scans faster than a spoken number, and it is trivially revocable if compromised.
  • A system-generated member ID that carries no meaning and no personal data.
  • Magic links for order lookup and document access — the link is the credential, it expires, and it lands in an inbox you already verified.
  • Singpass and Myinfo where you genuinely need identity assurance rather than convenience. That is a real integration with real obligations; it is not the answer for a loyalty card.

Whichever you choose, two PDPA provisions sit behind the decision. Section 14(2)(a) says an organisation must not, as a condition of providing a product or service, require an individual to consent to collection, use or disclosure of personal data beyond what is reasonable to provide that product or service. Section 12 requires you to develop and implement policies and practices necessary to meet your obligations, and to make them available on request. “We’ve always asked for it” is not one of them.

Timeline from September 2026 to January 2027 showing the phases of an NRIC migration Working backwards from 31 December 2026 SEPT-OCT Inventory every field and script that touches an IC OCT-NOV Replace the authentication uses; retrain counter staff NOV-DEC Purge numbers with no lawful basis; update the policy 1 JAN 2027 PDPC steps up enforcement The long pole is almost never the code. It is the counter script and the printed card. Start with the human process; the database change is the easy half.
Four months, three phases — and the retraining is the part that takes longest.

A four-month plan

  1. Inventory, honestly. Every form, field, script, email template and third-party tool that asks for, stores or checks an NRIC — including the ones nobody owns, like the spreadsheet the events team uses. Include your agencies and your POS vendor.
  2. Classify each one against the single question above: identification, or authentication?
  3. Replace the authentication uses first. These are the ones with a dated deadline and a named enforcement posture.
  4. Then question the collection uses. For each remaining field holding a full NRIC, ask which of the two exceptions applies. If neither does, you should not be holding it.
  5. Rewrite the counter script and retrain. This is the step that slips. A database migration lands in an afternoon; “can I have the last four of your IC?” is a decade-old reflex across a whole floor of staff.
  6. Update your data protection policy and make it available, per section 12.
  7. Keep the record of what you found, what you changed and when. If you are ever asked, that record is the difference between a remediated gap and a negligent one.

If your customer data lives in several places at once, this is also a natural moment to consolidate — our comparison of CRM options for Singapore SMEs covers what to look for, and our guides to conversion tracking and GA4 setup cover the measurement layer that sits on top of it.

Frequently asked questions

Can I still collect NRIC numbers in Singapore after 31 December 2026?

Sometimes, but the collection rule is unchanged and it is strict. Under the PDPC’s Advisory Guidelines, organisations are generally not allowed to collect, use or disclose NRIC numbers or copies of the NRIC except where required under the law, or where it is necessary to accurately establish or verify identity to a high degree of fidelity — a threshold PDPC illustrates with significant safety or security risks and with healthcare, financial and real-estate transactions. What changes on 1 January 2027 is enforcement against using the number for authentication.

Is the last 4 digits of the IC still allowed?

It depends entirely on the job it is doing. As an identifier, PDPC’s guidelines state that collecting a partial NRIC number up to the last 3 numerical digits and the checksum is not considered collecting the NRIC number. As a credential, the 2 February 2026 media release is explicit that enforcement from 1 January 2027 covers organisations that use “full or partial” NRIC numbers for authentication.

What exactly counts as authentication?

PDPC defines it as “the process of proving that a person is who he claims to be, before granting him access to services or information intended only for him”, and distinguishes it from identification, “where identifiers such as names are used to tell people apart”. The release names default passwords built from the NRIC, alone or combined with easily obtainable data such as names and birthdates, and says such passwords should not be used to access digital documents or an individual’s account.

What happens if we miss the deadline?

PDPC has said organisations using NRIC numbers for authentication to access personal data may be found to have breached the PDPA for failing to make reasonable security arrangements, and that from 1 January 2027 it will step up enforcement including directions or financial penalties where appropriate. Members of the public can report misuse to PDPC directly.

Can we keep a photocopy or scan of the NRIC on file?

Copies of the NRIC are treated the same as the number itself under the guidelines, so the same general prohibition and the same two exceptions apply. Separately, the guidelines advise against retaining the physical NRIC unless retention is required under the law, and extend that to other identification documents such as driving licences, passports and work passes.

Does this apply to Foreign Identification Numbers and work pass numbers too?

Yes. The guidelines state that the treatment of NRIC numbers also applies to Birth Certificate numbers, Foreign Identification Numbers and work pass numbers. If your loyalty programme has a separate flow for non-residents, it is in scope on the same terms.

The summary, if you take one thing

Two rules, one question. The collection rule has been in force since 2019 and says you probably should not be holding the number at all. The authentication rule has a hard date — 31 December 2026 — and says that whatever you do hold, full or partial, cannot be the thing that proves who someone is.

The question that resolves nearly every case is whether a stranger who knew the string could get into the account. Where the answer is yes, you have four months, and the slow part is not the database. It is the sentence your staff have been saying at the counter for ten years.

Our 2027 Singapore digital marketing trends piece places this alongside the other dated changes landing in the same window, and our client case studies show what customer data looks like when it is organised around a real identifier instead of a national one.

Not sure which of your systems are actually doing authentication? Talk to our performance marketing team — the inventory usually takes an afternoon, and it is the step that tells you how big the rest of the job is.


Sources, all read directly: PDPC media release, “Organisations to cease the use of NRIC numbers for authentication by 31 December 2026”, published 2 February 2026; PDPC announcement, “PDPC to Step up Enforcement Action Against Misuse of NRIC numbers and Issues New Advisory on Data Protection”, 2 February 2026; PDPC, Advisory Guidelines on the Personal Data Protection Act for NRIC and Other National Identification Numbers, issued 31 August 2018 (paras 1.4, 3.2, 3.12–3.14, 4.1, 5.1, 5.2 and the retail worked example); Personal Data Protection Act 2012, Singapore Statutes Online (ss 12, 14). Last updated 3 September 2026. Written by Adrian Tan and the SDM team. General information about how these rules are written, not legal advice.



Want to know where you actually rank?

We will run a free visibility check across your target searches and send back an honest read — no obligation.

Picture of Adrian Tan

Adrian Tan

A seasoned digital marketing professional with over 15 years of experience, I have built and executed high-impact digital strategies across SEO, SEM, Social Media Marketing (SMM), Social Media Advertising (SMA), content marketing, performance marketing, and integrated digital campaigns. My expertise extends beyond individual channels, focusing on how every aspect of digital marketing works together to drive measurable business growth. Throughout my career, I have successfully managed and optimized campaigns across a wide range of industries, including technology, finance, healthcare, retail, e-commerce, education, real estate, hospitality, and professional services. This cross-industry experience has enabled me to develop data-driven strategies tailored to unique business objectives, customer behaviors, and competitive landscapes. I have partnered with multinational corporations (MNCs) as well as established enterprises and high-growth businesses, helping them strengthen their digital presence, increase brand visibility, generate qualified leads, improve customer acquisition, and maximize return on marketing investment. From developing comprehensive digital strategies to managing multi-channel campaigns with substantial budgets, I have consistently delivered results through continuous optimization, analytics, and innovation. My expertise includes technical and on-page SEO, enterprise SEO strategies, paid search (Google Ads, Microsoft Ads), paid social campaigns across Meta, LinkedIn, TikTok, and other platforms, marketing automation, conversion rate optimization (CRO), web analytics, audience segmentation, content strategy, and performance reporting. I combine analytical thinking with creative problem-solving to ensure every campaign aligns with broader business goals. What sets me apart is my holistic understanding of the digital marketing ecosystem. Rather than viewing SEO, paid media, social media, and content as isolated disciplines, I develop integrated strategies where every channel supports the customer journey—from awareness and engagement to conversion, retention, and advocacy. This full-funnel approach allows businesses to achieve sustainable growth while adapting to evolving market trends and consumer expectations. Driven by continuous learning and innovation, I stay at the forefront of emerging technologies, AI-powered marketing, automation, and evolving digital platforms. My passion lies in transforming complex marketing challenges into scalable, measurable, and sustainable growth opportunities that deliver long-term business success.

On this page

Share

Get found by customers already looking for you

A free, honest look at where you stand today and what it would take to move.

Not sure where you stand?

Tell us about your business and we will take an honest look at where you are today — and what it would take to get where you want to be.

No obligation · a human replies within one working day