新加坡个人信息保护新规:机构索取身份证号码需征求同意

2025/02/04   •   3244阅
新加坡政府正式回应公众对身份证号码(NRIC)泄露的深切担忧,明确表示绝不会广泛公开完整NRIC信息。部长强调,NRIC仅限必要场景使用,严禁作为密码或身份认证工具,部分机构误用后四位数字已成安全漏洞。政府将全面整顿公共部门使用规范,并引导私营企业逐步改革,同时呼吁全民立即更改以NRIC为密码的高风险习惯。此次政策调整旨在防范身份盗用与网络诈骗,守护每一位新加坡人的数字隐私安全。

Instead of the full NRIC number, some organisations collect and use a partial NRIC number, usually the last four characters of the NRIC number. They think that this is safe and that revealing only the last four characters still keeps the full NRIC number secret. Among public agencies, even when the agencies had the full NRIC numbers, the use of masked NRIC numbers became more common.

Besides organisations, some individuals also started to use their NRIC numbers as their passwords. They did so under the impression that the full NRIC number is secret.

However, as shown by Dr Tan Wu Meng in his question, there are now algorithms that can be found online, that have made it easier to work out the full NRIC number from the partial or masked NRIC number. The easy availability of such algorithms means that the continued use of partial or masked NRIC numbers gives both organisations and individuals a false sense of security. This does not really keep the full NRIC number secret. This also makes the practice of using NRIC numbers as passwords even more inappropriate.

To the questions by Dr Tan, Mr Liang Eng Hwa and Ms Sylvia Lim, these developments led the Government to take steps to stop the incorrect uses of the NRIC number. This meant two things: one, not using the NRIC number as an authenticator; and two, moving away from the use of masked NRIC numbers, because it creates a false sense of security.

We knew this transition would take time. But it was better to start while the problem is relatively contained and for the Government to take the lead.

To the question by Ms Joan Pereira, we proceeded to ask agencies to stop using the NRIC number as an authenticator or as a password. We also asked agencies not to plan new uses, with a view to discontinuing existing uses of masked NRIC numbers eventually.

The lapse in coordination between agencies led to ACRA's misunderstanding and the disclosure of full NRIC numbers in the People Search function of its new Bizfile portal.

In hindsight, what we should have made clear was that moving away from the use of masked NRIC numbers did not mean automatically using the full NRIC number instead, in every case. At no point was our intention to disclose full NRIC numbers on a wide scale.

In place of masked NRIC numbers, in some instances, there would be no need for the NRIC number at all. In other instances, names alone or some other identifier would be sufficient. But there could also be instances where full NRIC numbers should be used, instead of masked NRIC numbers. Each case would have to be assessed and decided individually.

Members including Mr Leong Mun Wai, Mr Liang Eng Hwa, Mr Xie Yao Quan, Ms Jessica Tan, Mr Dennis Tan and Mr Pritam Singh have asked about the internal processes leading to ACRA's actions. Minister Indranee will say more about it in her Statement later and address Members' questions related to ACRA.

Miss Cheryl Chan asked why the efforts to change did not include the private sector. The Government knew that it would take time for public agencies to make the change. We expected that it would take even longer for the private sector because of long-standing practices and habits. The plan was therefore to change the internal practices of Government before moving to change practices in the private sector and non-profit organisations, which Ms Usha Chandradas asked about. We believed that doing so would allow us to better understand the implementation challenges and, as a result, facilitate a smoother transition in the private sector.

We had also planned to mount a major effort to help Singaporeans be aware of the risks and to support efforts to stop incorrect practices. The Bizfile incident was an unfortunate misstep which now means these plans need to be brought forward.

While we had taken steps to stop the incorrect uses of NRIC numbers in the public sector, we had not started implementation for the private sector. Mr Edward Chia, Mr Liang Eng Hwa, Ms Hazel Poa and Mr Xie Yao Quan have asked specifically what should be done in the private sector.

At this stage, we would advise private sector organisations to do two things: first, private sector organisations that are using NRIC numbers as a factor of authentication or as default passwords should stop this practice as soon as possible; and second, private sector organisations that presently collect partial NRIC numbers to identify people can continue to do so. The guidelines for the private sector have not yet changed and we will only consider how they should be updated after consulting the public.

To questions by Mr Xie Yao Quan, Mr Melvin Yong and Mr Sharael Taha, we aim to start consultations soon and will provide details when ready. Our initial soundings with the private sector suggest there can be different approaches. Some organisations currently using partial NRIC numbers can stop the practice and replace them with alternative means of identification such as mobile numbers or email addresses or drop them entirely. But there are also organisations that need to accurately identify persons and can justify the collection of full NRIC numbers even if they are not required by law. For example, preschool centres will prefer to collect the full NRIC numbers of visitors rather than just the mobile numbers; the parents will certainly feel more secure. In applications for and disbursements of substantial financial aid, persons would also need to be accurately identified.

We will take these considerations on board when updating the guidelines. In any case, I would like to assure Members like Ms Jean See and Mr Ong Hua Han that the Personal Data Protection Commission will support businesses in changing their authentication methods. This will include raising their awareness on why the use of NRIC numbers as a factor of authentication is unsafe and working through the Infocomm Media Development Authority and the Cyber Security Agency's programmes to help businesses review and adjust their practices.

及时获取本站更新:

设为 Google 偏好来源

2026年申请新加坡公民,这些变化值得关注

2026/06/23   •   1863阅

拿到新加坡PR后,这几件大事必须马上办!

2026/06/22   •   1464阅

新加坡51万人都在用SRS,但50亿新币仍躺在账户里“睡觉”

2026/06/24   •   1224阅

大国威慑失效,世界将陷入混乱?新加坡国防部长发出严厉警告:我们正处于危险边缘!

2026/06/23   •   243阅

骗子借乐龄活动 社媒设局骗长者

2026/06/23   •   170阅

虚假信息已成为全球“地方性流行病”!新加坡总理黄循财:民众也要提高媒体素养

2026/06/23   •   731阅

新加坡部长辞职,重回外科一线,因公立医院太缺医生了?

2026/06/24   •   569阅

新加坡男子私信李显龙资政,威胁“炸弹袭击”?原因竟是……

2026/06/24   •   2755阅

刚出狱又犯!新加坡男子帮柬埔寨团伙骗走同胞$65万

2026/06/24   •   87阅

办香会如经营樟宜机场?新加坡国防部长以四句“顺口溜”阐述对话与合作的重要

2026/06/23   •   575阅

重磅!未来5年,新加坡每年将狂揽2.5万-3万新公民+4万PR!

2026/06/23   •   488阅

狮城续打击非法跨境载客 7司机落网车辆被扣押

2026/06/24   •   164阅

2026新加坡国庆庆典大变样!时隔十年重返国家体育场...

2026/06/23   •   329阅

新加坡豪车欲加补贴油,大马油站员工硬核制止获赞

2026/06/23   •   648阅

数码发展及新闻部:愿意支持《给阿嬷的情书》潮语版加场

2026/06/24   •   495阅

新加坡竞消委7月推快速通道:配合解决调查事宜 罚单可减多达30%

2026/06/23   •   168阅

冒充陆交局发诈骗简讯 骗子6月以来卷走逾7万元

2026/06/24   •   81阅