Check before you share
Media Literacy Guide

What Never to Post Online: IDs, Boarding Passes, School Uniforms, and Why

The specific items you should never post online—NRIC, boarding passes, school uniforms—and the exact harm each one can enable, with removal steps.

The One Post That Costs You Your Identity

Delete any post showing your NRIC number or a full photo of the card now. That image is a master key, and the moment it is public, someone can open a mobile line in your name, take a loan, or file a fraudulent tax return. Every day in Singapore, people post a photo of their NRIC card to celebrate a new job, a boarding pass to show they are travelling, or a child's first day of school photo with the uniform's name badge visible. Each of those posts is a gift to a criminal. A single barcode on a boarding pass can reveal your full name, your frequent flyer number, and your booking reference. A school uniform with a name tag tells a stranger exactly where your child spends eight hours a day.

The Personal Data Protection Act (PDPA) treats NRIC numbers as personal data, but the law applies to how organisations collect and use it, not to how you post it. Your only defence is to never put it online in the first place.

Why Your NRIC Photo Is a Master Key

The NRIC number is the closest thing Singapore has to a national identity key. It verifies identity for government services, banking, and some retail transactions. When you post a clear photo of your NRIC, you hand over the one piece of information a fraudster needs to impersonate you to a call centre agent, a telco, or a bank's phone line. The harm vector is not that the number is secret. It is that a photo of the card provides the card's other details: your full legal name, your date of birth, your address, all in one neat package. A scammer can combine these to answer security questions or to create a fake Singpass account using your details.

What the Law Covers and What It Does Not

Singapore's Personal Data Protection Commission (PDPC) has been explicit about this. Its advisory on NRIC numbers, effective 1 September 2019, states that organisations should not collect, use, or disclose NRIC numbers unless required by law or necessary to accurately establish identity. But that advisory applies to companies, not to you. The law cannot stop you from posting your own card. What the Protection from Harassment Act (POHA) does cover is the doxxing of others: publishing someone else's NRIC with intent to cause harassment, alarm, or distress. If you post your own, you have no legal recourse. The exact phrase to remember: your NRIC photo is a master key, and you have just posted the lock's blueprint.

When Someone Else Posts Your NRIC

Under POHA's doxxing provisions, which took effect on 1 January 2020, the victim can apply for a Protection Order from the Protection from Harassment Court. The court can order the poster to remove the content and stop further publication. But this only works after the damage is done. The prevention is simple: never photograph your card, never post a photo of it, and if a friend tags you in a photo of your card, ask them to take it down immediately.

Boarding Pass Barcode Information Leak

That boarding pass selfie at Changi Airport's viewing gallery, or the photo of your seat number on a Scoot flight, contains a barcode that encodes far more than your seat. The PDF417 barcode on a typical boarding pass holds your full name, your frequent flyer number, your booking reference, and sometimes your passport number. A determined person can decode that barcode using a free online reader and extract the data in seconds. This is a boarding pass barcode information leak that most travellers do not see coming.

The harm is not theoretical. With your booking reference and name, a fraudster can call the airline, impersonate you, and ask to change your flight or access your account. Some airlines only require the booking reference and the passenger's name over the phone. Your entire trip can be hijacked. Worse, if your frequent flyer number is in the barcode, the attacker can link it to your profile, see your travel history, and use your miles to book tickets or buy upgrades. The Singapore Police Force has issued advisories about this exact vector. The barcode does not expire when the flight lands, and the data inside remains valid for account access.

How to Post Travel Photos Safely

If you must post a travel photo, crop out any barcode or wait until after the trip is completely over and you have checked in for the return leg. Use your phone's editing tool to blur or cover the barcode with your finger before posting. When you dispose of a paper boarding pass after landing, tear it into at least four pieces or shred it. At the airport, use the self-service kiosk to print a new pass if you suspect someone saw your screen. Never share your booking reference on a public forum asking for help with your seat.

School Uniform Child Safety Online

A photo of a child in school uniform, posted by a proud parent on the first day of school, is one of the most dangerous images imaginable. The uniform itself tells a stranger which school the child attends. Add a name tag or a bag with the child's name, and you have given a predator the two pieces of information needed for a targeted approach: a location and a name. The risk is not about the child being tracked in real time. It is about the accumulation of data over time.

A stranger can use the school name and the child's full name to find out the family's address through public records or a simple Google search. A birthdate often appears in a sibling's post or on a family photo with a birthday cake. With name, school, and birthdate, an attacker can craft a phishing message that appears to come from the school, using the young person's name in the subject line. The Singapore Police Force's annual scam briefings list identity theft and impersonation scams as top threats, and children's data is a growing entry point. A minor's digital footprint is built before they can consent to it.

The Long-Term Risk to Your Child

When the child is older, old photos resurface. An employer or a university admissions officer can reverse image search the name and find embarrassing or incriminating photos posted years earlier. The child cannot consent to the removal if the photos are indexed and archived. The only defence is to not post them at all. If you must share a photo of a child in uniform, post it in a private group with strict privacy settings, never include the school's name in the caption, and crop out any name tag. Do not tag the school. Many Singapore international schools now ban any classroom photos on social media. Follow that rule.

  • NRIC photo risk: Full identity theft; NRIC, DOB, address combined
  • Boarding pass barcode: Encodes name, booking ref, frequent flyer number
  • School uniform photo: Reveals child's school and name; enables targeting
  • Home address in post: Enables doxxing, stalking, break-in
  • Signature image: Used to forge documents; not just a scribble
  • Full name + birthdate: Credentials for many security questions

Why Your Home Address and Phone Number Are a Two-Way Door

A post that shows your new condo's keycard, a delivery parcel with your address visible, or a photo taken at home with the street number in the background is a direct invitation. The harm is not that a random stranger might walk past your block. Your digital shadow grows each time you post. A home address in a post is the foundation for doxxing: publishing your home address with intent to cause harassment is an offence under POHA. Even without intent, the address alone enables a stalker to show up, a thief to case the building, or a scammer to call you pretending to be from the Singapore Police Force, citing your address as proof they are legitimate.

The Phone Number Is Worse

Posting your number in a public comment or in a bio invites SMS phishing, which the SPF calls smishing. The scammer sends a message claiming to be from DBS, SingPost, or the IRAS, with a link to a fake login page. The number also gets harvested by data brokers, who sell it to marketing firms. The result is a permanent increase in spam calls. The more specific risk is impersonation. With your phone number and your name, a scammer can attempt to port your number to a new SIM card, a technique called SIM swapping, and then intercept your OTPs for banking. The telco may ask security questions, but those questions are often answerable with information already in your digital footprint.

Treat your phone number like your NRIC. Do not post it anywhere public. If you sell something on Carousell or Facebook Marketplace, use the platform's in-app messaging until the deal is done, and only give your number to a verified buyer after meeting in person. For online forms that require a number, use a secondary number or a VoIP service. If you must post a photo of a delivery, cover the label with your thumb. The post is not worth the risk.

Signature, Children's Full Names, and the Birthdate Trap

A signature is a legal mark. Posting a photo of your signed tenancy agreement, a signed credit card receipt, or a signed document celebrating a new job gives away the one thing banks and government agencies use for verification. The signature on the back of your credit card is there to prevent forgery, but a clear photo of it removes that safeguard. A fraudster can practice your signature, sign a document, and dispute charges, claiming you signed it. The harm is not immediate. It is the quiet, slow burn of a forged document that surfaces months later.

A young person's full name, when combined with a birthdate, is a credential for many online security questions. A mother's maiden name, a pet's name, a first school: these are common security answers derived from publicly available information. Posting a child's full name and birthdate in a birthday post, or in a school announcement, gives a scammer the answer to the question, 'What is your date of birth?' That same full name is also the entry point for opening a bank account or a telco line in their name, a growing form of identity fraud targeting minors. The child's credit record is empty, so the fraud can go undetected for years.

Never post a child's full name and birthdate together. Use a nickname, blur the birthdate, or post the photo a day later with a caption that does not include the date. If you have a family blog or a private Instagram, set it to private and vet followers. Even in a private group, assume someone has a screenshot. The only safe amount of a child's data is none.

What the Law Actually Does: POHA, PDPA, and the Enforcement Gap

Singapore's legal framework has caught up with the era of oversharing, but the law is reactive, not preventive. The Protection from Harassment Act (POHA), specifically its doxxing provisions effective 1 January 2020, makes it an offence to publish a person's personal information, including NRIC numbers, phone numbers, and addresses, with the intent to cause harassment, alarm, or distress. The penalty can be a fine, imprisonment, or both. The law only kicks in after you have been doxxed. It does nothing to stop the original post.

How the PDPA Applies to You

The Personal Data Protection Act (PDPA) is the other tool, but it is aimed at organisations. The PDPC has published enforcement decisions since 2016, and several of them involve mishandling of NRIC data. The PDPA does not apply to an individual posting their own data. The only way the Act touches you is if you post someone else's data without their consent. That is the contract: you have no legal protection for your own oversharing, only for the harm done by others.

The practical takeaway is that the law is a backstop, not a shield. The PDPC's advisory on NRIC collection encourages organisations to stop collecting NRIC numbers unless necessary. When you are at a hotel or a clinic and they ask for your NRIC, you can ask why they need it and whether you can provide a different form of identification. That is your right under the PDPA, and it is a small action that reduces your digital footprint. The moment you post the photo, you have lost control. The data is out there, archived, screenshotted, and indexed. No law can put that genie back in the bottle.

Your Digital Footprint Is Forever: The Archive Problem

Here is the uncomfortable truth about the internet: nothing is ever truly deleted. When you post a photo of your NRIC or a boarding pass, the image is immediately captured by the platform's servers, then by search engine caches, and potentially by the Internet Archive's Wayback Machine. A friend can screenshot it. A stranger can copy it. A data broker can index it. This is the permanence of your digital footprint, and it is a property of the medium, not a bug that can be fixed. The term 'digital shadow' describes the data collected about you without your active participation, like a listing on a people-search site that compiles your location and phone number from publicly visible posts.

The harm of the archive problem is that a post you made when you were young and careless can resurface years later, at the worst possible moment. A university application, a job interview, a visa application, or a custody battle can all be derailed by a photo you thought you deleted. The delete button is an illusion because the copies exist elsewhere. Reverse image search tools like Google Images or TinEye can find where a photo has been reposted, but they cannot stop the distribution.

What to Do If You Have Already Posted Something

Delete the post from the original platform first. Then use a reverse image search to find any copies. Contact each platform and request removal under its terms of service. This process is slow, uncertain, and often futile. The only reliable method is prevention. Before you post anything, ask yourself: would I be comfortable with this appearing on a billboard in Toa Payoh with my name on it? If the answer is no, do not post it.

The Consent Obligation Nobody Reads

Under the PDPA, the first obligation is consent: you must have an individual's consent before collecting, using, or disclosing their personal data. This obligation applies to you, too, when you post a photo of a friend, a family member, or a stranger. That group photo at a hawker centre where the background person's face is clearly visible is a disclosure of their data. If you post it publicly and they are identifiable, you have disclosed their personal data without consent, breaching the PDPA's consent obligation.

The consent obligation also covers incidental data. A photo of your coffee with your laptop open in the background contains your colleague's confidential spreadsheet. A photo of your wedding registry contains your aunt's full name and address. The law is an accountability framework: you are responsible for the data you disclose, even accidentally. The PDPC's enforcement decisions have penalised organisations for unintended disclosures. Individuals are less commonly prosecuted because the Act's reach is limited. The principle holds.

Before you post, do a data sweep of every image. Check for reflections in windows, mirrors, and phone screens. Check for documents on desks and whiteboards. Check for faces of minors who cannot consent. Ask yourself if the post needs to be public. The habit of asking 'why does this need to be public?' before each post is the single most effective privacy preservation technique available. It is free, it is immediate, and it is the only way to control your digital shadow.

What to Do When the Damage Is Done: Reporting and Removal

If you have already posted something you should not have, the clock is ticking. Do not assume deletion is enough. Take a screenshot of the post and its URL as evidence. Then delete the post from the original platform. Next, do a reverse image search using Google Images or TinEye to find copies on other sites. For each copy, use the platform's report function and select 'privacy violation' or 'harassment'.

Filing a Report Under POHA

If the post was maliciously shared by someone else with intent to cause you harassment, alarm, or distress, that is doxxing under POHA. File a police report at any Neighbourhood Police Centre or online at the SPF e-Services portal. The police will investigate, and the court can issue a Protection Order that requires the poster to take down the content and stop publishing. The Protection from Harassment Court is the venue. You do not need a lawyer to apply, though it helps. The court can also award damages and impose a fine.

For content that involves your NRIC or financial data, also report to the Personal Data Protection Commission at pdpc.gov.sg. The PDPC can investigate the organisation that disclosed your data, but only if it was a company, not an individual. If the post was a scam, like a phishing link that you clicked and it shared your data, report to the SPF's Scam Alert at 1800-722-6688, and to the bank or service provider involved. The sooner you act, the more likely you are to limit the damage. The process is slow. The only true cure is prevention.

Travelling With a Personal Data Plan

For the traveller who wants to post a real-time diary of their trip to Bali, the temptation is to share the boarding pass, the villa's address, and the photo of the passport at immigration. This is the fastest way to turn a holiday into a nightmare. A passport photo posted online is the equivalent of a golden ticket for a fraudster. The passport number, combined with your name and date of birth, is enough to apply for a replacement in some countries, or to open a bank account in your name. Post everything after the trip, or blur every document that includes a number.

If you must post in real time, use a private story or a close friends list. The screenshot risk remains. A better approach: post a photo of a souvenir, a landscape, or a meal. None of these contain personal data. Save the boarding pass for a story, but crop out the barcode. Save the villa's pool for the final day, and never post a photo taken inside the villa that shows the key fob or the address on a document.

For the traveller who carries a work phone, the risk is the corporate data on the device. A photo of the laptop screen with a confidential email in the background is a data breach. Check the background of every photo before posting. Enable two-factor authentication on every account. Ask yourself one question before you hit post: is this image more important than my identity?

The Digital Privacy Hub Is the "home" of This Subject

The wider hub this page sits inside covers digital privacy in Singapore, and it dedicates whole sections to the tools and laws that protect you. The hub explains what a digital footprint is, how doxxing works under POHA, and what the PDPC does. This page goes deeper into the specific items you should never post, because the failure of most advice is that it is too generic. Saying 'be careful what you share' is useless. Saying 'your boarding pass barcode contains your booking reference' is actionable.

The hub also explains the difference between a digital footprint and a digital shadow. A footprint is what you leave: the posts, the uploads, the comments. A shadow is what others collect: your browsing history, your location, your purchases. When you post a photo of your NRIC, you are actively expanding your footprint and inviting the shadow to grow. The two concepts are linked. The only way to shrink the shadow is to shrink the footprint.

If you are a parent, the hub's section on children's data is the one to read next. It covers how to talk to kids about not posting their school uniforms, and how to model good behaviour. The core message is the same: the internet does not forget. The hub gives you the questions to ask yourself, and this page gives you the specific items to avoid. The combination is the difference between a holiday that ends with a stolen identity and one that ends with a suitcase full of souvenirs.

Who This Subject Serves and Who It Does Not

This subject suits the deliberate traveller who shares photos of their trip with genuine enjoyment, not for validation. It suits the parent who posts a monthly update of their child's growth, and who can learn to crop out a school name. It suits the professional who knows that a careless post can cost a job offer, and the person who has already been phished and never wants to be phished again. It suits anyone who has ever googled themselves and felt uneasy about what they found.

It does not suit the influencer whose entire identity is built on sharing every detail of their life. That person is the target, not the audience. It does not suit the person who believes privacy is dead and there is no point fighting it. That person is statistically more likely to be a victim of identity theft. It does not suit the traveller who posts a photo of their passport because everyone does it. That is exactly the mistake this page is designed to prevent.

If you are the kind of person who reads terms and conditions, who covers the laptop camera, and who uses a password manager, this page is a reminder. If you reuse the same password and post holiday photos from the airport, this page is a warning. Either way, the knowledge is the same: the cost of a single careless post is measured in the months of paperwork it takes to prove you are not a fraud.