Key takeaways
- PDPC has set a firm deadline: all private organisations, including F&B outlets, must stop using NRIC numbers for authentication by 31 December 2026, with enforcement stepping up from 1 January 2027, per PDPC’s 2 February 2026 advisory.
- “Authentication” covers common F&B practices — using a customer’s full or partial NRIC (e.g. the last 4 characters) as a login, password, or verification code for loyalty accounts, reservations, or lucky draws.
- Every organisation that handles personal data must appoint a Data Protection Officer (DPO) and publish their contact details — there is no small-business exemption under the PDPA.
- A data breach affecting 500 or more individuals (or causing significant harm) must be reported to PDPC within three calendar days of determining it’s notifiable, under rules in force since 1 February 2021.
- Penalties are real and can be steep: the maximum fine is the higher of S$1 million or 10% of an organisation’s annual turnover in Singapore — Marina Bay Sands was fined S$315,000 in October 2025 after a breach exposed 665,495 patrons’ data to a threat actor.
If your outlet asks customers for their NRIC when they sign up for a loyalty programme, make a reservation, or enter a lucky draw, Singapore’s data protection regulator wants you to stop — at least for verification purposes. On 2 February 2026, the Personal Data Protection Commission (PDPC) announced that all private organisations must cease using NRIC numbers for authentication by 31 December 2026, with active enforcement beginning 1 January 2027. For F&B businesses running POS, loyalty, or table-reservation systems that quietly built NRIC into their sign-up or verification flow over the years, this is a real deadline with real teeth — here’s what it actually requires.
What did PDPC just change about NRIC numbers, and does it affect my F&B business?
PDPC’s original Advisory Guidelines on NRIC and other National Identification Numbers have restricted collecting, using, or disclosing NRIC numbers since 1 September 2019, unless required by law or necessary to verify identity to a high degree of accuracy. Many businesses, including F&B operators, kept using NRIC anyway as a default customer identifier — for membership sign-ups, visitor logs, and reservation lookups. PDPC’s 2 February 2026 announcement closes that gap: it sets a firm, dated deadline and signals a move from guidance to active enforcement. If your business collects NRIC numbers from customers or staff in any capacity, this applies to you — company size is not a factor.
Can we still collect a customer’s NRIC for loyalty sign-ups, reservations, or lucky draws?
The restriction targets using NRIC to authenticate someone — not every possible collection of the number. You can generally still record an NRIC where it’s genuinely necessary (for example, verifying age for alcohol sales where required), but you should not be using it as the credential that logs a customer into their loyalty account, confirms a reservation, or verifies entry into a promotion. If your current membership or reservation system asks for an NRIC (or its last 4 characters) purely as a way to “prove it’s you,” that’s the exact practice PDPC is telling organisations to redesign before 31 December 2026.
What exactly counts as “using NRIC for authentication”?
Based on PDPC’s guidance, authentication use includes:
- Using a full or partial NRIC (e.g. the last 4 characters) as a login credential, password, or verification code.
- Combining a partial NRIC with date of birth to verify a customer’s identity.
- Requiring an NRIC to confirm a reservation, collect a lucky-draw prize, or retrieve loyalty points at the counter.
- Using NRIC as the default unique identifier for a customer record in a CRM, POS, or membership system.
PDPC’s joint advisory with the Cyber Security Agency of Singapore, issued 26 June 2025, had already flagged that relying on NRIC numbers for authentication creates a heightened risk of unauthorised access, since the number itself isn’t secret — it appears on physical ID cards, in booking confirmations, and across countless other records. The fix is to move to a proper credential (a PIN, an app-based login, an OTP, or a membership number the business itself issues) that isn’t also a piece of identity data.
Do small F&B outlets really need a Data Protection Officer?
Yes. Under the PDPA, every organisation that collects, uses, or discloses personal data must appoint at least one Data Protection Officer and make their business contact details publicly available — there is no exemption based on headcount or revenue. For a single hawker stall taking cash only, this may be largely moot; but the moment your outlet runs a POS system, a loyalty app, online reservations, or even a customer WhatsApp broadcast list, you’re handling personal data and the DPO requirement applies. The role doesn’t need to be a dedicated hire — an existing manager or owner can hold it alongside their other duties, provided they understand the business’s obligations well enough to handle inquiries and respond if PDPC investigates.
What must we do if our POS or loyalty database is breached?
Since 1 February 2021, the PDPA has required organisations to notify PDPC of a data breach if it affects, or is likely to affect, 500 or more individuals, or is likely to cause significant harm (financial loss, identity theft, or similar). Notification must happen “as soon as practicable,” and in any event no later than three (3) calendar days of concluding the breach is notifiable — that clock starts from the determination, not from the moment the breach itself occurred. For an F&B chain running a loyalty programme or online ordering platform across multiple outlets, a single compromised customer database can easily cross the 500-person threshold, so it’s worth knowing your notification obligations before an incident happens, not during one.
What’s the actual cost of getting this wrong?
Since 1 October 2022, the maximum financial penalty under the PDPA is the higher of S$1 million or 10% of an organisation’s annual turnover in Singapore (for organisations with local turnover above S$10 million). This isn’t theoretical: in October 2025, PDPC fined Marina Bay Sands S$315,000 after a system-migration configuration error went undetected for roughly six months, during which the personal data of 665,495 patrons was exfiltrated by a threat actor and later found for sale on the dark web. The lesson for smaller F&B operators isn’t the dollar figure — it’s that a single configuration mistake, sitting undetected, is enough to trigger an investigation and a public enforcement decision.
Not sure whether your POS, loyalty, or reservation set-up still leans on NRIC somewhere in the flow? Get in touch with the Warely team — we help Singapore F&B operators review exactly this kind of customer-data plumbing.
Frequently asked questions
When exactly does the NRIC authentication ban take effect?
PDPC announced the deadline on 2 February 2026: organisations must stop using NRIC numbers for authentication by 31 December 2026. Active enforcement, including directions and financial penalties, begins from 1 January 2027 for organisations that haven’t transitioned away by then.
Does the PDPA apply to small F&B businesses and hawker stalls?
Yes — the PDPA applies to any organisation handling personal data, regardless of size. A cash-only hawker stall with no digital records has minimal exposure, but any outlet running a POS system, loyalty app, or online reservations is collecting personal data and must meet the same core obligations as larger operators, including appointing a DPO.
What’s the maximum fine under the PDPA?
Since 1 October 2022, the maximum financial penalty is the higher of S$1 million or 10% of the organisation’s annual turnover in Singapore, for organisations whose local turnover exceeds S$10 million. Annual turnover is assessed from the most recent audited accounts at the time the penalty is imposed.
How quickly must a data breach be reported to PDPC?
Organisations must notify PDPC as soon as practicable, and in any case no later than three calendar days after concluding a breach is notifiable — not within “72 hours” as often paraphrased elsewhere. Notification is required if the breach affects 500 or more individuals or is likely to cause significant harm.
Is CCTV footage of customers or staff considered personal data under the PDPA?
PDPC does not require CCTV use to be separately registered or pre-approved, but footage that can identify an individual is personal data under the PDPA. That means standard obligations — purpose limitation, protection, and retention limits — apply to how F&B businesses store and use their CCTV recordings.
What’s a practical alternative to using NRIC for loyalty or reservation verification?
Move to a credential your business controls and can reset independently of a customer’s identity documents — a mobile number plus OTP, a membership number issued at sign-up, or an app-based login. None of these double as identity data the way an NRIC number does, which is the core risk PDPC is asking organisations to remove.



