NRIC authentication deadline: an HR checklist for 2026
Find NRIC-based payslip passwords, logins and recovery checks. Replace them by 31 December 2026, test employee access and address older files separately.
· 5 min read

Guidance checked 7 October 2026.
A payslip that opens with an employee’s NRIC still needs fixing—even if your HR portal has a new login. Private organisations in Singapore have until 31 December 2026 to phase out full or partial NRIC numbers used for authentication. PDPC will step up enforcement from 1 January 2027. Government announcement
Check document passwords, account activation and recovery—not just the main login. Employees and leavers still need a safe way to obtain their documents after the old method is removed.
The phase-out concerns how people gain access, not a blanket deletion of NRICs from employment records. Existing data-protection duties still apply before the deadline. PDPC’s enforcement announcement
An NRIC identifies a person; it does not prove who is asking
An identifier finds the record; authentication checks who is asking for it. Knowing an employee’s NRIC does not prove that someone is the employee.
Using part of the number, or combining it with a name or birth date, does not turn it into a reliable secret. The government’s guidance expressly covers these combinations, including passwords for emailed documents. Guidance on NRIC passwords
A payroll system may have a legitimate reason to hold an NRIC and still use an unsafe method to unlock the payslip. Assess collection and access separately under the PDPA’s data-protection obligations.
Find the access methods HR actually uses
Ask payroll, benefits, recruitment and IT colleagues to show how people receive documents, activate accounts and recover access. Include outside providers and leaver services.
| Where to look | What to check | Owner to involve |
|---|---|---|
| Payslips and tax documents | Does a full or partial NRIC unlock the file? | Payroll and its supplier |
| Benefits or insurance portals | What proves identity during activation and recovery? | Benefits administrator and provider |
| Candidate accounts and assessments | Can an identifier from a CV or identity document unlock a record? | Recruitment systems owner and supplier |
| HR or helpdesk recovery | Can identifier-based answers trigger a password or contact-number reset? | IT/helpdesk and HR operations |
| Leaver documents and older files | Which files remain accessible using the old password convention? | Records owner and security |
Use one inventory row per access method, not per supplier. A provider may have fixed its portal while leaving emailed PDFs unchanged.
For each row, record the current method, replacement, owner, target date and test result. Set your internal switch-over date early enough to resolve access problems before the official deadline. Close the row only after testing your account—not when the supplier announces a new feature.
Ask the supplier what changes in your account
Send a specific request rather than asking whether the product is “compliant”:
We are reviewing our HR workflows for the NRIC authentication phase-out. Please identify any use of full or partial NRIC numbers in account activation, passwords, document access or recovery for our account. What replaces each method, when will it change, and what must our administrator do? Please include fallback access, historical documents and a way to test the changes with sample data.
Divide the work explicitly: HR confirms who needs access and how to reach them; IT or the supplier changes the system; the security owner assesses the replacement and recovery method. Agree who updates email templates and helpdesk instructions. Do not assume the supplier will enable the change for you.
Choose a replacement that also secures recovery. Strong passwords, security tokens and other appropriately protected methods may be suitable; substituting a passport number or birth date recreates the problem. The government’s authentication guidance gives examples, not a guarantee that any particular configuration is secure.
Test new documents, recovery and fallback access
Use authorised test accounts and sample documents. These checks are a practical acceptance test, not a complete security audit.
New documents: Confirm that the intended employee can obtain a newly issued payslip or other protected document, while another test user cannot. Check that the former NRIC-based password no longer opens it.
Account recovery: Walk through a forgotten password and a changed phone number. Knowing an identifier alone must not be enough to take over the account. Include both automated and staff-assisted recovery.
Fallback access: Try the alternative route and saved email templates. A secure main login achieves little if the fallback still uses the old password formula.
Leaver access: Test the process after the work email account is disabled. A code sent only to that inbox will not help a former employee obtain a final payslip. Agree and test an appropriately verified alternative.
Record the result, tester and date. Give failures an owner and a safe interim response. The helpdesk must not solve a failed login by reverting to an NRIC-based reset or sending an unprotected attachment.
Treat old PDFs as a separate problem
Moving new payslips to a portal does not change a PDF already saved on someone’s device. Separate copies you can still control from those you cannot recall.
With security and the records owner, decide which controlled copies can be withdrawn, replaced or otherwise protected. Document the response for copies that cannot be recalled. Keep that historical-file decision separate from testing the new access method.
Tell employees how to get their documents
Send the message only when the new route and support process work. Describe the task and the help available, not another password formula.
We are changing how you access payroll documents. From [date], new documents will be available through [verified company portal]. Use your existing account and the normal recovery process if you cannot sign in.
HR will not ask you to send your password or a full identity document in reply to this email. For access problems, contact [verified internal channel].
Adapt the message to the actual rollout. Send former employees instructions through an appropriate contact route, and make sure someone answers the support channel.
When is the replacement ready?
For the live workflows and newly protected documents, confirm that the right person can get access, an unrelated person cannot, and the old NRIC-based access and recovery methods no longer work. Staff also need a safe response when access fails.
Keep the test results and the separate historical-file decision with the system owner. These checks address the replacement; they do not certify the whole system’s PDPA compliance.
This guide provides general information, not legal advice or security certification. The checklist and employee message must be adapted to your systems and any sector-specific requirements. Your security and privacy owners should assess the replacement, recovery routes and historical-file risks before deployment.


