For years, a director’s or shareholder’s NRIC number has quietly done double duty in Singapore corporate services. It identifies the individual on ACRA filings, and it has also often been used, informally, as a verification factor: confirming a caller is who they say they are, resetting a portal password, or authenticating a client during onboarding. From 31 December 2026, the second use becomes off-limits. The Personal Data Protection Commission (PDPC) has set that date as the deadline for private sector organisations to stop using NRIC numbers, in full or in part, as an authentication factor, with enforcement action to follow from 1 January 2027.

For company secretaries and corporate service providers, whose entire onboarding and know-your-customer (KYC) process has traditionally leaned heavily on NRIC details, this is not a minor administrative footnote. It requires a genuine review of how client identity is verified, both at onboarding and during ongoing due diligence.

What the PDPC Change Actually Prohibits

The change does not stop organisations from collecting or recording NRIC numbers where there is a genuine legal or operational need to do so, such as for statutory ACRA filings identifying a director or shareholder. What it prohibits is using the NRIC number, whole or partial, as a credential that proves someone’s identity: as a password or default login, as a “security question” answer, or combined with other easily obtained personal details such as a name or date of birth to form a verification check. The PDPC’s reasoning is straightforward: NRIC numbers are not secret. They appear on countless documents, are often visible to third parties, and have already been the subject of numerous data breaches, so using them as if they were a secret credential creates real identity fraud risk.

Why This Matters Specifically for Corporate Secretarial Work

Corporate service providers regularly verify a director’s or shareholder’s identity in two related but distinct contexts: statutory record-keeping, where the NRIC number is simply a required data field, and client authentication, where the firm needs to be confident that the person instructing a change of director, a share transfer, or a bank signatory update is genuinely who they claim to be. It is this second use that must change. A firm that has historically confirmed a client’s identity over the phone by asking them to state their NRIC number, or that uses the last four digits of an NRIC as a client portal password reset check, will need a new process in place well before the end of 2026.

This sits alongside, but is distinct from, the broader identity verification obligations corporate service providers already carry under the Corporate Service Providers Act 2024 framework, which governs client due diligence for anti-money laundering purposes. The PDPC’s NRIC authentication rule is a separate, PDPA-driven requirement about how identity is confirmed operationally, not what due diligence records must be kept.

What to Use Instead

The PDPC has pointed organisations toward several accepted alternatives, including Singpass-based login and verification for individuals, one-time passwords sent to a verified email or mobile number, organisation-issued unique client reference numbers instead of NRIC digits, multi-factor authentication for portal access, and biometric verification where appropriate. For a corporate secretarial firm, the most practical starting points are usually replacing any client portal or document-signing workflow that currently relies on NRIC-based login or password resets, and updating phone-based verification scripts so that staff no longer ask clients to “confirm” their identity by reciting an NRIC number.

Practical Steps Before 31 December 2026

Firms should audit every point in their client journey where an NRIC number is currently used as a check, rather than simply recorded. This includes onboarding forms, phone verification scripts, portal login and password reset flows, and any automated system that flags a “match” against an NRIC field as proof of identity. Each of these touchpoints needs either a genuine authentication alternative, such as Singpass or OTP verification, or a redesign so that the NRIC field is used purely as a record, with a separate credential doing the actual authentication work.

Staff training matters as much as the systems change. Many NRIC-as-authentication practices are informal habits built up over years of client service, rather than documented policy, which means they can be easy to miss during a systems-only review. A short staff briefing confirming exactly which practices must stop, alongside the replacement script or process, is worth building into the transition plan now rather than close to the deadline.

How This Interacts With Existing ACRA and CSP Obligations

Corporate secretaries should be careful not to over-correct. ACRA filings, the Register of Registrable Controllers, and statutory registers of directors and members will continue to require full NRIC numbers to be collected and recorded exactly as before; nothing about the PDPC change removes that obligation. The distinction is narrow but important: collecting and recording an NRIC number for a statutory purpose is unaffected, while treating that same number as a secret credential that proves someone’s identity is what must stop. Firms that also handle Register of Registrable Controllers filings should review that process specifically, since RORC updates are often triggered by a phone or email instruction that has historically been verified using exactly the kind of NRIC-based check the PDPC is now phasing out.

Timeline at a Glance

Date Milestone
Now Organisations should begin auditing onboarding, portal login and phone verification processes for NRIC-based authentication
31 December 2026 Deadline for private sector organisations to stop using NRIC numbers as an authentication factor
From 1 January 2027 PDPC enforcement action, including directions and financial penalties, may apply to organisations still relying on NRIC-based authentication

Conclusion

The 31 December 2026 deadline gives corporate service providers a reasonable runway, but the change touches enough everyday onboarding and verification habits that it is worth starting the review now rather than in the final quarter of the year. Distinguishing clearly between recording an NRIC number for statutory purposes, which remains necessary, and using it as a security check, which will soon be prohibited, is the core of the compliance task ahead.

If your firm needs legal advice on updating client authentication practices under the PDPA, we can point you in the right direction. For the latest Singapore business news and regulatory updates, there are useful resources for compliance teams tracking this transition.

The team at Raffles Corporate Services can help you review your client onboarding and verification processes ahead of the PDPC deadline.

To speak with the team at Raffles Corporate Services, you can email [email protected] or call, SMS, or WhatsApp +65 8501 7133. We are happy to assist with any queries.

The Editorial Team, Raffles Corporate Services