新加坡个人信息保护新规:机构索取身份证号码需征求同意

2025/02/04   •   3244阅
新加坡政府正式回应公众对身份证号码(NRIC)泄露的深切担忧,明确表示绝不会广泛公开完整NRIC信息。部长强调,NRIC仅限必要场景使用,严禁作为密码或身份认证工具,部分机构误用后四位数字已成安全漏洞。政府将全面整顿公共部门使用规范,并引导私营企业逐步改革,同时呼吁全民立即更改以NRIC为密码的高风险习惯。此次政策调整旨在防范身份盗用与网络诈骗,守护每一位新加坡人的数字隐私安全。

To questions by Ms Tin Pei Ling, Mr Zhulkarnain Abdul Rahim and Assoc Prof Jamus Lim, I should emphasise that NRIC numbers are personal data. This means that organisations collecting and using NRIC numbers must continue to exercise a duty of care. Subject to applicable law, they must notify and seek consent on use, and also ensure the data is sufficiently protected. Certainly, they should not disclose the NRIC numbers unless there is good reason to do so.

Members may also ask, if the NRIC number is not suitable as an authenticator, what about the physical NRIC card, our pink identity card? If we look at our physical NRIC card, we will see that it contains other identifying information, such as our photo and fingerprint. It allows others to check that the information on the card matches me, the person holding the card. In addition, the physical NRIC card is not easily faked. The physical NRIC card is, therefore, suitable as an authenticator, or proof of who I claim to be. But someone providing my NRIC number and claiming to be me, does not have these additional factors of proof.

Organisations must know that the physical NRIC card and NRIC number are different. The physical NRIC card can be an authenticator, but the NRIC number should not be used as an authenticator. Organisations should, therefore, not accept my NRIC number alone as proof that the person citing it is indeed me.

Besides organisations, individuals, too, have questions about what they should do. There are also two things. The first is to clarify their understanding of the NRIC number. Members like Ms Sylvia Lim asked about this.

We have said that our NRIC number is like our name. Even if it is not widely disclosed, it is not secret. In our daily lives, if someone we do not recognise calls out our name and starts to behave as though they know us well, we would be slightly suspicious. We might be polite but not too friendly. Certainly, we should not fully trust this person, just because they know our name.

This should also be how we treat anyone who tells us our NRIC number. We should not automatically assume that they know us well or are figures of authority or can be trusted. We should be cautious about revealing more about ourselves, or saying yes to their requests or following their instructions without checking further.

The second thing we can do as individuals is to review our passwords. If we have used our NRIC number as a password to access any information or service, we have mistakenly used it as an authenticator and should change the password immediately. Doing so will give us better protection against people who use our NRIC number to get access to information or services. It will also complement efforts by organisations to stop using the NRIC number as a factor of authentication.

To Ms Hany Soh's question, NRIC-related scams are not new. Most NRIC-related scams involve victims who think they are speaking to figures of authority and end up taking actions that harmed themselves, such as transferring money without further checks. Very few cases have involved scammers directly using NRIC numbers to unlock access to valuables.

Several Members have also asked how to mitigate the risks when NRIC numbers are disclosed. They include Mr Zhulkarnain Abdul Rahim, Mr Edward Chia, Mr Christopher de Souza, Mr Ong Hua Han, Mr Liang Eng Hwa, Ms Jessica Tan, Mr Louis Chua, Miss Cheryl Chan, Mr Sharael Taha and Mr Yip Hon Weng.

As I have explained, the risks arise from the incorrect use of the NRIC numbers. If individuals stop using NRIC numbers as passwords and organisations stop using NRIC numbers as authenticators, this will go a long way to preventing harms from scams and identity theft. They will give us all better peace of mind to use the NRIC number whenever it is necessary, such as to get medical treatment or apply for jobs.

Sir, the Government appreciates that the incorrect uses of the NRIC number may not be well understood. Our public education efforts will raise awareness among organisations and individuals, and to guide them on what they should do. In doing so, we will focus on the points I highlighted above.

Mr Gerald Giam asked about alternatives to the current NRIC number system. In fact, the risks do not arise directly from the structure of the NRIC number. Rather, the risks arise when the NRIC number, which is meant to be a unique identifier, is incorrectly used as an authenticator or a password. Even if we were to create an alternative identifier, we would still have a problem if organisations used it as an authenticator and individuals used it as a password.

Sir, let me turn now to questions about ACRA's exemption from Personal Data Protection Act (PDPA) requirements and the Government's data protection measures. These were raised by Ms Tin Pei Ling, Ms Sylvia Lim, Mr Saktiandi Supaat and Mr Patrick Tay.

The Government has always taken seriously its responsibility to protect the data entrusted to the public sector. The Government's personal data protection standards are set collectively by the Public Sector (Governance) Act, or PSGA, and our own internal rules.

The PSGA is aligned with the PDPA and adapted to the Public Service context. Our internal rules are comprehensive and take reference from international and industry standards. We also continually strengthen our data governance practices.

ACRA is expected to comply with these rules and the PSGA, which are no less stringent than PDPA requirements. Regular, mandatory audits are conducted to ensure that public agencies, including ACRA, comply with the standards for data protection and the security of information and communications technology systems. The number of data incidents and their severity is published annually.

In the most recent whole-of-Government audit exercise on information technology-related data security controls, there were very few significant findings and all of them had been remediated by the agencies concerned. There has also been a reduction in data incidents of medium severity and above. Where necessary, we have also taken public servants to task, for example, in serious cases involving unauthorised disclosure or improper use of information.

Members can be reassured that we take these rules and controls very seriously. We will continue to regularly review the safeguards to ensure that they remain relevant.

及时获取本站更新:

设为 Google 偏好来源

紧急提醒!ICA冒充骗局翻倍爆发,新加坡留学家庭务必警惕

2026/06/24   •   0阅

2026年申请新加坡公民,这些变化值得关注

2026/06/23   •   1863阅

新加坡51万人都在用SRS,但50亿新币仍躺在账户里“睡觉”

2026/06/24   •   1548阅

大国威慑失效,世界将陷入混乱?新加坡国防部长发出严厉警告:我们正处于危险边缘!

2026/06/23   •   243阅

骗子借乐龄活动 社媒设局骗长者

2026/06/23   •   170阅

虚假信息已成为全球“地方性流行病”!新加坡总理黄循财:民众也要提高媒体素养

2026/06/23   •   731阅

新加坡部长辞职,重回外科一线,因公立医院太缺医生了?

2026/06/24   •   731阅

新加坡男子私信李显龙资政,威胁“炸弹袭击”?原因竟是……

2026/06/24   •   3484阅

刚出狱又犯!新加坡男子帮柬埔寨团伙骗走同胞$65万

2026/06/24   •   87阅

办香会如经营樟宜机场?新加坡国防部长以四句“顺口溜”阐述对话与合作的重要

2026/06/23   •   575阅

重磅!未来5年,新加坡每年将狂揽2.5万-3万新公民+4万PR!

2026/06/23   •   488阅

狮城续打击非法跨境载客 7司机落网车辆被扣押

2026/06/24   •   164阅

太贪心!新加坡幼儿园园长涉嫌造假骗取1.4万新币补贴,面临最高10年监禁!

2026/06/24   •   324阅

2026新加坡国庆庆典大变样!时隔十年重返国家体育场...

2026/06/23   •   329阅

新加坡豪车欲加补贴油,大马油站员工硬核制止获赞

2026/06/23   •   648阅

数码发展及新闻部:愿意支持《给阿嬷的情书》潮语版加场

2026/06/24   •   495阅

新加坡竞消委7月推快速通道:配合解决调查事宜 罚单可减多达30%

2026/06/23   •   168阅

冒充陆交局发诈骗简讯 骗子6月以来卷走逾7万元

2026/06/24   •   81阅