新加坡個人信息保護新規:機構索取身份證號碼需徵求同意

2025/02/04   •   3244閱
新加坡政府正式回應公眾對身份證號碼(NRIC)泄露的深切擔憂,明確表示絕不會廣泛公開完整NRIC信息。部長強調,NRIC僅限必要場景使用,嚴禁作為密碼或身份認證工具,部分機構誤用後四位數字已成安全漏洞。政府將全面整頓公共部門使用規範,並引導私營企業逐步改革,同時呼籲全民立即更改以NRIC為密碼的高風險習慣。此次政策調整旨在防範身份盜用與網絡詐騙,守護每一位新加坡人的數字隱私安全。

Instead of the full NRIC number, some organisations collect and use a partial NRIC number, usually the last four characters of the NRIC number. They think that this is safe and that revealing only the last four characters still keeps the full NRIC number secret. Among public agencies, even when the agencies had the full NRIC numbers, the use of masked NRIC numbers became more common.

Besides organisations, some individuals also started to use their NRIC numbers as their passwords. They did so under the impression that the full NRIC number is secret.

However, as shown by Dr Tan Wu Meng in his question, there are now algorithms that can be found online, that have made it easier to work out the full NRIC number from the partial or masked NRIC number. The easy availability of such algorithms means that the continued use of partial or masked NRIC numbers gives both organisations and individuals a false sense of security. This does not really keep the full NRIC number secret. This also makes the practice of using NRIC numbers as passwords even more inappropriate.

To the questions by Dr Tan, Mr Liang Eng Hwa and Ms Sylvia Lim, these developments led the Government to take steps to stop the incorrect uses of the NRIC number. This meant two things: one, not using the NRIC number as an authenticator; and two, moving away from the use of masked NRIC numbers, because it creates a false sense of security.

We knew this transition would take time. But it was better to start while the problem is relatively contained and for the Government to take the lead.

To the question by Ms Joan Pereira, we proceeded to ask agencies to stop using the NRIC number as an authenticator or as a password. We also asked agencies not to plan new uses, with a view to discontinuing existing uses of masked NRIC numbers eventually.

The lapse in coordination between agencies led to ACRA's misunderstanding and the disclosure of full NRIC numbers in the People Search function of its new Bizfile portal.

In hindsight, what we should have made clear was that moving away from the use of masked NRIC numbers did not mean automatically using the full NRIC number instead, in every case. At no point was our intention to disclose full NRIC numbers on a wide scale.

In place of masked NRIC numbers, in some instances, there would be no need for the NRIC number at all. In other instances, names alone or some other identifier would be sufficient. But there could also be instances where full NRIC numbers should be used, instead of masked NRIC numbers. Each case would have to be assessed and decided individually.

Members including Mr Leong Mun Wai, Mr Liang Eng Hwa, Mr Xie Yao Quan, Ms Jessica Tan, Mr Dennis Tan and Mr Pritam Singh have asked about the internal processes leading to ACRA's actions. Minister Indranee will say more about it in her Statement later and address Members' questions related to ACRA.

Miss Cheryl Chan asked why the efforts to change did not include the private sector. The Government knew that it would take time for public agencies to make the change. We expected that it would take even longer for the private sector because of long-standing practices and habits. The plan was therefore to change the internal practices of Government before moving to change practices in the private sector and non-profit organisations, which Ms Usha Chandradas asked about. We believed that doing so would allow us to better understand the implementation challenges and, as a result, facilitate a smoother transition in the private sector.

We had also planned to mount a major effort to help Singaporeans be aware of the risks and to support efforts to stop incorrect practices. The Bizfile incident was an unfortunate misstep which now means these plans need to be brought forward.

While we had taken steps to stop the incorrect uses of NRIC numbers in the public sector, we had not started implementation for the private sector. Mr Edward Chia, Mr Liang Eng Hwa, Ms Hazel Poa and Mr Xie Yao Quan have asked specifically what should be done in the private sector.

At this stage, we would advise private sector organisations to do two things: first, private sector organisations that are using NRIC numbers as a factor of authentication or as default passwords should stop this practice as soon as possible; and second, private sector organisations that presently collect partial NRIC numbers to identify people can continue to do so. The guidelines for the private sector have not yet changed and we will only consider how they should be updated after consulting the public.

To questions by Mr Xie Yao Quan, Mr Melvin Yong and Mr Sharael Taha, we aim to start consultations soon and will provide details when ready. Our initial soundings with the private sector suggest there can be different approaches. Some organisations currently using partial NRIC numbers can stop the practice and replace them with alternative means of identification such as mobile numbers or email addresses or drop them entirely. But there are also organisations that need to accurately identify persons and can justify the collection of full NRIC numbers even if they are not required by law. For example, preschool centres will prefer to collect the full NRIC numbers of visitors rather than just the mobile numbers; the parents will certainly feel more secure. In applications for and disbursements of substantial financial aid, persons would also need to be accurately identified.

We will take these considerations on board when updating the guidelines. In any case, I would like to assure Members like Ms Jean See and Mr Ong Hua Han that the Personal Data Protection Commission will support businesses in changing their authentication methods. This will include raising their awareness on why the use of NRIC numbers as a factor of authentication is unsafe and working through the Infocomm Media Development Authority and the Cyber Security Agency's programmes to help businesses review and adjust their practices.

及時獲取本站更新:

設為 Google 偏好來源

2026年申請新加坡公民,這些變化值得關注

2026/06/23   •   1701閱

拿到新加坡PR後,這幾件大事必須馬上辦!

2026/06/22   •   1464閱

新加坡51萬人都在用SRS,但50億新幣仍躺在帳戶里「睡覺」

2026/06/24   •   1143閱

大國威懾失效,世界將陷入混亂?新加坡國防部長發出嚴厲警告:我們正處於危險邊緣!

2026/06/23   •   243閱

騙子借樂齡活動 社媒設局騙長者

2026/06/23   •   170閱

虛假信息已成為全球「地方性流行病」!新加坡總理黃循財:民眾也要提高媒體素養

2026/06/23   •   731閱

新加坡部長辭職,重回外科一線,因公立醫院太缺醫生了?

2026/06/24   •   488閱

新加坡男子私信李顯龍資政,威脅「炸彈襲擊」?原因竟是……

2026/06/24   •   2593閱

剛出獄又犯!新加坡男子幫柬埔寨團伙騙走同胞$65萬

2026/06/24   •   87閱

辦香會如經營樟宜機場?新加坡國防部長以四句「順口溜」闡述對話與合作的重要

2026/06/23   •   575閱

重磅!未來5年,新加坡每年將狂攬2.5萬-3萬新公民+4萬PR!

2026/06/23   •   488閱

獅城續打擊非法跨境載客 7司機落網車輛被扣押

2026/06/24   •   164閱

2026新加坡國慶慶典大變樣!時隔十年重返國家體育場...

2026/06/23   •   329閱

新加坡豪車欲加補貼油,大馬油站員工硬核制止獲贊

2026/06/23   •   648閱

數碼發展及新聞部:願意支持《給阿嬤的情書》潮語版加場

2026/06/24   •   495閱

新加坡競消委7月推快速通道:配合解決調查事宜 罰單可減多達30%

2026/06/23   •   168閱

冒充陸交局發詐騙簡訊 騙子6月以來捲走逾7萬元

2026/06/24   •   81閱