The 2027 NRIC deadline: what Singapore employers should check before enforcement begins

Written by
Hannah

Singapore employers have until 31 December 2026 to stop using full or partial NRIC numbers for authentication. The change does not prevent legitimate collection or use of NRIC information. It targets practices where NRIC details are treated as passwords, credentials or other proof that somebody is entitled to access personal information. For HR teams, the priority is to find these practices across recruitment, background screening and onboarding before enforcement increases on 1 January 2027.

The deadline applies to authentication

The distinction between identification and authentication is central to the Personal Data Protection Commission’s (PDPC) position.

Identification establishes who somebody is. Authentication proves that the person requesting access to information or a service is entitled to that access.

An NRIC number can serve an identification purpose in legitimate circumstances. The problem arises when organisations rely on that number as information that only the individual should know.

For example, a company might send a candidate a confidential document protected by a password based on their NRIC number. A portal could ask for part of an NRIC number before revealing personal information. A system might use the number as a default credential when an account is created.

The PDPC has specifically identified practices such as using full or partial NRIC numbers as default passwords, including where they are combined with readily obtainable information such as a name or date of birth. Private organisations have until 31 December 2026 to phase out such authentication practices. Enforcement will increase from 1 January 2027.

For employers, this makes the remaining months of 2026 a practical deadline for reviewing how candidate identity data is used.

Why HR processes need particular attention

Recruitment creates several points at which sensitive personal information changes hands.

A candidate may provide identity information when completing an application, undergoing screening, submitting supporting documents or completing onboarding. Some of this information may pass between the employer and external providers.

The issue can therefore sit outside the organisation’s main HR system.

Consider a screening report sent as a password-protected file. The report itself might be securely transferred, yet the password could be derived from the candidate’s NRIC number. An onboarding portal could have inherited an old authentication convention that nobody has reconsidered for years.

These processes are easy to overlook precisely because they may have become routine.

Employers reviewing their controls should follow the candidate’s information through the entire process, from initial collection to storage, reporting and eventual deletion. RMI’s overview of how employers check candidate backgrounds in Singapore explains the range of verification activities that can form part of this process.

An identifier makes a poor password

The security problem is straightforward. An NRIC number identifies an individual, so organisations should not assume it is secret.

PDPC technical guidance notes that an NRIC number is personal data and can potentially be connected to considerable information about an individual. It has advised organisations to avoid using NRIC numbers as usernames or unique identifiers in public-facing systems and advises against their use for authentication.

That creates an obvious weakness when the same information is used to control access to confidential candidate records.

Once somebody obtains the NRIC information, the authentication mechanism loses much of its value. Combining an NRIC number with another readily obtainable fact does not necessarily solve the problem.

The regulatory consequences also warrant attention. The PDPC has stated that organisations using NRIC numbers to authenticate access to personal data may breach the Personal Data Protection Act (PDPA) where they fail to make reasonable security arrangements. Enforcement can include directions and financial penalties.

For organisations with annual turnover in Singapore exceeding S$10 million, the statutory maximum financial penalty for relevant breaches can reach 10% of annual turnover in Singapore, under the applicable enforcement framework. The actual penalty depends on the circumstances and seriousness of the breach.

Start by finding where NRIC information goes

A useful review should begin with an inventory.

Identify every stage of recruitment and onboarding where a full or partial NRIC number is collected, stored, transmitted or requested. Then establish why it is there.

The purpose matters.

If the information is required for a legitimate identification or verification process, the question is whether its collection and use are appropriate for that purpose. If the information grants access to a report, account, document or system, the authentication method requires closer examination.

Employers should also review older systems. A current recruitment platform may use appropriate security controls while a legacy document process still relies on NRIC-derived passwords.

RMI’s background screening services show the range of checks that can involve candidate information, including identification verification, employment verification, qualification verification, financial health screening and reputational checks. Looking across the whole screening process reduces the chance of concentrating on one system while missing another route through which personal data is accessed.

Include suppliers in the review

Third-party processes belong in the same audit.

Recruitment agencies, screening companies, onboarding providers and technology vendors may receive or process candidate data on an employer’s behalf. Their authentication practices can therefore affect the security of the wider recruitment process.

Employers should ask suppliers specific questions.

Does any candidate-facing account use an NRIC number or part of one as a credential? Are reports protected using NRIC-derived passwords? Does a user ever have to enter NRIC information before gaining access to personal data? Do older workflows operate differently from the supplier’s current platform?

Precise questions are more useful than asking a provider whether it is simply “PDPA compliant”.

This supplier review also fits within a broader assessment of how screening is managed. RMI’s article on in-house and outsourced background screening discusses the compliance considerations employers should examine when deciding how screening work is handled.

Do not confuse the change with a ban on identity verification

Employers should avoid drawing the wrong conclusion from the deadline.

Identity verification remains an important part of many background checks. Employers need to establish that the records, qualifications and employment history being examined belong to the right person.

The NRIC deadline concerns authentication practices. It does not remove the underlying need to verify candidate information where doing so is appropriate.

That distinction is especially relevant as recruitment fraud becomes more sophisticated. Employers increasingly need to establish that the individual participating in recruitment is the same person represented by the documents and credentials supplied. RMI discusses this issue further in its guide to building an AI-resistant hiring process in Singapore.

The sensible response is therefore to examine how identity information is being used, rather than removing useful verification controls without considering their purpose.

What employers should complete before the end of 2026

The remaining work is practical.

Map where NRIC information enters the recruitment process and where it travels. Identify every instance where full or partial numbers are used to grant access to information. Review document passwords, candidate portals, HR systems and older onboarding processes.

Where NRIC information is being used for authentication, replace it with an appropriate security method. Recent PDPC enforcement material has repeatedly highlighted controls such as multi-factor authentication, access management, security reviews and stronger password policies when addressing weaknesses in organisations’ protection of personal data.

Then obtain equivalent assurance from suppliers handling candidate information.

Keep a record of the review. Document which systems and processes were checked, what problems were identified, who owns the remediation and when each change was completed.

The 31 December 2026 deadline is close enough that this work should already be under way.

If your organisation is reviewing how employee or candidate checks are carried out, RMI can help. We provide employee background screening services for employers in Singapore and internationally, including identity, employment, qualification and other pre-employment checks. Contact RMI to discuss the checks you need and how they can fit into your hiring process.

From 1 January 2027, the PDPC has said it will step up enforcement against private organisations using full or partial NRIC numbers for authentication.

For HR teams, the question to answer before then is specific: does any part of our recruitment, screening or onboarding process still treat an NRIC number as a secret?

If the answer is yes, that process has an expiry date.