Review account access, document passwords and customer-support verification together. Replacing a weak login while retaining a weak recovery process leaves an avoidable gap.
The development
Regulatory phase-out deadline: 31 December 2026
PDPC’s 2 February 2026 announcement directs private organisations to phase out full or partial NRIC numbers for authentication by 31 December 2026. It says enforcement against this misuse will step up from 1 January 2027. This addresses proof of identity for access, not a blanket prohibition on lawful identification.
Find the less obvious uses
Do not limit the review to the website login screen. Ask the teams that send customer documents, administer employee portals and answer telephone enquiries how access is granted. A process may depend on an NRIC-derived value even if the person using it calls it a reference code rather than a password.
Actions to consider
- Inventory login, password-reset, document-opening and telephone verification processes.
- Ask software providers to identify NRIC-derived default passwords and recovery rules.
- Agree a replacement authentication method with security support, including a usable recovery route.
- Test both successful access and attempted access with publicly obtainable information.
- Remove outdated staff scripts and customer instructions when the replacement goes live.
Scope and timing
Do not wait for the enforcement date to address a security weakness. Check the joint advisory and any sector-specific requirements when selecting the replacement. Authentication changes should not be treated as permission to collect additional identity data without assessment.
What to prepare
An authentication inventory, an owner for each replacement and evidence that the old route no longer grants access.
Official sources
General information, not a determination of your organisation’s legal obligations. The actions are Averisdata’s practical suggestions; check the cited rules against your circumstances.