The NRIC fiasco is not just a simple “lapse of coordination” between government agencies.
This is not a game of cards… as the late Lee Kuan Yew would have put it.
It is a huge data leak with potentially dangerous consequences for Singaporeans.
By a government that stated in parliament in 2019 that it is exempted from the PDPA because it holds itself to a “higher standard” of data protection than corporations.
The minister who made that arrogant statement is current convict Mr S Iswaran, who headed the Ministry for Communications and Information (now MDDI).
ACRA has just offered identity thieves a big lelong freebie.
From the leaked NRIC numbers, they can easily track individuals’ addresses and even health records.
Singaporeans lost $650 million to scams in 2023. On average, victims here lost the most money in the world to scams.
A data leak like this, and the snail’s pace that the government took to address the problem, has given scammers a bigger window of opportunity to piece together profiles of vulnerable citizens and target them with more convincing lies.
Especially, scammers who pose as government officials and prey on the elderly who happen to put a lot of trust in the government.
Especially, when NRIC numbers are still widely used as a verification tool by banks, telcos and even SingPass.
Just before this data leak, a Singaporean couple was traumatised when an acquaintance maliciously cancelled their credit cards across 3 banks using their personal details, including NRIC number.
It’s too late to shut the barn door after the horse has ran off to some ulu part of Tengah.
Just like how the government now appears to be covering its backside by pointing the finger of blame at companies for using NRIC as a verification tool.
Companies been doing this for years. What has the government been doing all these years if it believed the practice was wrong?
There are real-world consequences to this data leak by the government.
MDDI Minister Josephine Teo is also the Second Minister for Home Affairs, and Minister-in-charge of the Cyber Security Agency.
So, a simple apology for causing “anxiety” just will not cut it.
Since more government agencies such as the Health Ministry are demanding more of citizens personal data for the sake of “efficiency” and centralisation.
Interestingly, hackers stole 1.5 million health records from the Health Ministry’s database not too long ago.
There are pressing questions that the government needs to answer.
(1) What are the processes in place to protect citizens’ data, and track malicious actors who access and extricate such data?
(2) How is our personal data handled, so that staff and vendors appointed by the government (IT development may be offshored to India or China for all we know) do not gain unauthorised access so they can abuse this data?
(3) How many citizens’ profile have been access in this latest ACRA data leak by persons who would otherwise be deemed unauthorised to access such data?
(4) What recourse do citizens have with regards to repercussions of data leaks by the government, since government agencies are exempted from the PDPA?
Singaporeans deserve accountability from the government and not just hollow lip service, since the government supposedly holds itself to a “higher standard” of care.
Desmond Lim
Chairman
Singapore Democratic Alliance