Inicio / Blog / Data Protection

2026 has been an eventful year for data protection in Singapore. The Personal Data Protection Commission (PDPC) has set a firm deadline for ending the use of NRIC numbers as passwords, published its first dedicated guidance on personal data in generative AI, and continued to issue financial penalties for avoidable security failures. This update summarises what has changed, what the latest enforcement decisions tell us, and what your organisation should do before the end of the year.

Key Dates at a Glance

  • 26 June 2025: PDPC and the Cyber Security Agency of Singapore (CSA) issue a joint advisory against using NRIC numbers for authentication
  • 2 February 2026: PDPC announces that organisations must stop using NRIC numbers for authentication by 31 December 2026
  • 20 July 2026: PDPC publishes the Advisory Guidelines on Use of Personal Data in Generative AI
  • 31 December 2026: Deadline to cease NRIC-based authentication
  • From 1 January 2027: PDPC will step up enforcement against organisations that still use NRIC numbers for authentication

1. Stop Using NRIC Numbers for Authentication by 31 December 2026

On 2 February 2026 the PDPC announced that organisations must cease using NRIC numbers for authentication by 31 December 2026. This builds on the joint advisory issued by the PDPC and CSA in June 2025, which asked organisations to stop the practice as soon as possible. From 1 January 2027, the PDPC has said it will step up enforcement action against organisations that have not complied.

Identification Is Not Authentication

The advisory draws a clear line between two uses of the NRIC number:

  • Identification — using the NRIC number to establish who someone claims to be, for example to locate a customer record during a phone call. This remains possible where the existing rules on collecting NRIC numbers allow it.
  • Authentication — using the NRIC number to prove that a person is who they claim to be before granting access to an account, a document or a service. This is what must stop.

The reasoning is simple: an NRIC number is issued to identify a person and must be assumed to be known to many others. It is not a secret, so it cannot work as a password.

Practices That Must End

  • Using full or partial NRIC numbers as default passwords for customer portals, employee accounts or HR systems
  • Password-protecting PDF statements, payslips or reports with the NRIC number (or the last digits plus date of birth)
  • Verifying callers or customers only by asking for their NRIC number together with easily obtainable details such as name or date of birth

Recommended Alternatives

The advisory points to robust passwords, security tokens and biometric identifiers, and recommends multi-factor authentication where feasible. Sector regulators are issuing their own guidance as well — the Ministry of Health, for example, has published a circular for healthcare institutions on ceasing NRIC-based authentication.

What to Do Now

  1. Inventory every system, document workflow and call-centre script that uses NRIC numbers, including those operated by vendors on your behalf
  2. Classify each use as identification or authentication
  3. Replace authentication uses with proper credentials or MFA, and plan the customer communication for the change
  4. Update your access control and password policies and document the decision trail
  5. Confirm that your vendors and outsourced service providers have made the same changes

2. New Advisory Guidelines on Personal Data in Generative AI

On 20 July 2026, following a public consultation in June, the PDPC published its Advisory Guidelines on Use of Personal Data in Generative AI. The guidelines explain how the PDPA applies across the whole GenAI lifecycle — development, deployment and post-deployment — and cover three main areas:

  • Collecting and using personal data to develop GenAI models, including web scraping and the re-use of data originally collected for other purposes
  • Allocating data protection responsibilities between model providers, system providers and the organisations that deploy GenAI systems
  • Handling individuals' requests, such as access and correction requests, after a model has been deployed

Points of Note for Organisations

  • Deployers carry primary responsibility: If your organisation deploys a GenAI tool, you are responsible for ensuring PDPA compliance and safeguarding the personal data the system processes — even if a vendor built the model.
  • Publicly available data has limits: Data behind logins, paywalls or other digital barriers needs a documented assessment before it is used.
  • Consent for re-use: Where no exception applies, using existing customer data for GenAI development requires consent based on a clear, AI-specific notification of the purpose, the data categories and how the data will be used.
  • Individual rights still apply: Access and correction requests must be handled after deployment. Keep records of data provenance and consider output filters while technical solutions for removing data from models mature.

Although advisory guidelines are not legally binding, they reflect how the PDPC interprets the PDPA. Organisations using GenAI should review their AI use cases, vendor contracts and privacy notices against them. Our article on the Singapore AI governance framework provides further background.

3. Latest PDPC Enforcement Decisions and Penalties

Recent decisions show the PDPC continuing to penalise basic security failures, with ransomware and compromised accounts the most common root causes. The following decisions were published between October 2025 and March 2026.

Marina Bay Sands — S$315,000 (28 October 2025)

The PDPC imposed a financial penalty of S$315,000 on Marina Bay Sands Pte Ltd for breaching the Protection Obligation. A configuration error introduced during a software migration exposed personal data of around 665,000 patrons. It is one of the largest penalties issued under the PDPA in recent years and shows that change management and review controls are part of "reasonable security arrangements".

Air Sino-Euro Associates Travel — S$47,000 (31 October 2025)

A cyberattack on the travel agency exposed personal data of 336,759 individuals. The PDPC found breaches of both the Accountability and Protection Obligations: no data protection officer had been appointed before the incident, internal data protection policies were missing, operating systems were outdated, vendor security was not reviewed and multi-factor authentication was not in place.

People Central — S$17,500 (8 January 2026)

A threat actor deleted databases and exfiltrated personal data of around 95,000 employees of client organisations, plus data of their emergency contacts and children. The HR software provider lacked two-factor authentication and had not carried out regular vulnerability assessments or penetration tests.

SESAMi (Singapore) and Abecha — S$8,750 plus Directions (26 February 2026)

A 2024 ransomware attack encrypted files containing personal data, including bank and credit card details, of approximately 39,000 individuals. SESAMi was fined and its subsidiary Abecha received directions. The PDPC pointed to unpatched security software, weak password rotation and access control, no MFA for administrator accounts and missing file-level encryption. It also stressed that group-level policies must be adapted to each subsidiary, with clear roles and responsibilities.

Voluntary Undertakings for Ransomware Incidents (2026)

The PDPC also accepted voluntary undertakings from Cycle & Carriage Industries, Lian Beng Group and St Francis Methodist School (International) following separate ransomware and system compromises. Instead of a financial penalty, these organisations committed to remediation such as updating systems, rotating credentials, strengthening encryption, conducting regular security assessments and training staff.

What the Decisions Have in Common

  • Missing multi-factor authentication, especially for administrator and remote access accounts
  • Unpatched and outdated systems exposed to the internet
  • No regular security testing — vulnerability scans and penetration tests were absent or infrequent
  • Weak governance — no DPO, no documented policies and unclear responsibilities within corporate groups
  • Insufficient vendor oversight of systems and service providers that process personal data

As a reminder, the PDPC can impose financial penalties of up to 10% of an organisation's annual turnover in Singapore (for organisations with turnover above S$10 million) or S$1 million, whichever is higher. Our analysis of PDPC enforcement trends covers the aggravating and mitigating factors in more detail.

Your Year-End PDPA Checklist

  1. Remove NRIC-based authentication from all systems, documents and processes before 31 December 2026
  2. Enforce MFA for administrator, remote access and customer-facing accounts
  3. Test your defences: schedule vulnerability scans and a penetration test of internet-facing systems
  4. Review your GenAI use against the new PDPC guidelines and update privacy notices and vendor contracts
  5. Check your governance: confirm your DPO appointment, policies and responsibilities across group companies — an outsourced DPO can close gaps quickly
  6. Rehearse your breach response so you can meet the three-day notification deadline — see our breach notification guide
  7. Document everything in a central data protection management platform so you can demonstrate accountability if the PDPC comes asking

How ResGuard Can Help

ResGuard supports Singapore organisations with a compliance platform and expert services covering the full PDPA lifecycle — from DPO support, policies and awareness training to vulnerability scanning and penetration testing. Contact us to review your NRIC, GenAI and security readiness before the year-end deadline.

This article provides general information as of 9 October 2026 and does not constitute legal advice. Sources: PDPC announcements and Commission's decisions, and published summaries of these decisions.

Seguir Leyendo

Artículos Relacionados

Manténgase Informado

Explore Nuestras Soluciones de Cumplimiento

Explore todos nuestros recursos de cibercumplimiento o descubra cómo nuestra plataforma y servicios expertos pueden ayudar a su organización a alcanzar y mantener el cumplimiento.

Todos los Artículos Contactar
Formulario de contacto