0% found this document useful (0 votes)
16 views6 pages

Data Protection SOP for Nigeria Operations

This Standard Operating Procedure (SOP) outlines the data protection protocols for Action Against Hunger (ACF-F) in Nigeria, ensuring compliance with the Nigeria Data Protection Act (NDPA 2023) and international standards. It covers governance, data protection principles, data collection and consent, data subject rights, security measures, retention and disposal practices, data sharing, breach management, training, and monitoring. The SOP emphasizes the importance of safeguarding personal data across all operations and interactions involving ACF-F in Nigeria.

Uploaded by

James Oyowe
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views6 pages

Data Protection SOP for Nigeria Operations

This Standard Operating Procedure (SOP) outlines the data protection protocols for Action Against Hunger (ACF-F) in Nigeria, ensuring compliance with the Nigeria Data Protection Act (NDPA 2023) and international standards. It covers governance, data protection principles, data collection and consent, data subject rights, security measures, retention and disposal practices, data sharing, breach management, training, and monitoring. The SOP emphasizes the importance of safeguarding personal data across all operations and interactions involving ACF-F in Nigeria.

Uploaded by

James Oyowe
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Standard Operating Procedure (SOP) on

Data Protection – Nigeria


(Aligned with NDPA 2023, NDPC Guidance, ISO 27701/27001, GDPR Best Practices, and
Humanitarian Data Responsibility Standards)

1. Purpose and Scope


The purpose of this SOP is to establish clear and practical procedures for protecting personal
data processed by Action Against Hunger (ACF-F) in Nigeria. The SOP ensures that all
personal data collected, stored, transferred, or destroyed within the Nigeria Country Office
complies with the Nigeria Data Protection Act (NDPA 2023), guidance from the Nigeria Data
Protection Commission (NDPC), and international data protection frameworks such as
ISO/IEC 27701, ISO/IEC 27001, GDPR, and humanitarian data responsibility principles
adopted by global actors including OCHA and ICRC.

The scope of this SOP is broad and inclusive. It applies to all individuals and entities that
interact with ACF-F data, including staff members, consultants, volunteers, implementing
partners, suppliers, and any third parties handling personal data on behalf of ACF-F in
Nigeria. It also applies across all forms of personal data, whether digital, physical, structured,
unstructured, audiovisual, or metadata.

In addition, this SOP extends to all systems and platforms where data is processed, including
on-premises servers, cloud platforms, mobile applications, donor reporting portals, and third-
party hosted solutions. This ensures that ACF-F maintains a holistic approach to data
protection, covering not just internal handling but also external interfaces with partners,
donors, and regulators.

2. Governance
A structured governance framework that assigns roles and responsibilities across multiple
levels of the organization guides data protection within ACF-F Nigeria.

At the global level, the ACF-F Data Protection Officer (HQ) provides oversight, technical
guidance, and ensures alignment between country operations and the organization’s global
compliance framework. At the national level, the Country Director (Nigeria) is responsible
for ensuring local compliance with the NDPA, allocating sufficient resources to support
implementation, and backing the work of the Country Data Protection Officer (CDPO).

The CDPO Nigeria serves as the official liaison with the NDPC and HQ. Their key
responsibilities include maintaining the Records of Processing Activities (RoPA), providing
advice and maintaining a Data Protection Impact Assessment (DPIA) Register, handling all
Data Subject Rights Requests (DSRs), coordinating data breach notifications, and ensuring
that all cross-border data transfers are properly logged and safeguarded in line with Nigerian
law.
Heads of Departments are responsible for embedding data protection principles into their
operational areas. This includes ensuring that consent forms are properly collected and stored,
privacy notices are issued to all relevant individuals, and that secure storage arrangements
(both digital and physical) are in place.

All staff members and contractors share responsibility. They must respect the duty of
confidentiality, sign Non-Disclosure Agreements (NDAs), and complete mandatory data
protection training both during onboarding and periodically through refresher sessions.

The Procurement and Partnerships Unit plays a key role by ensuring that all vendors,
suppliers, and partners sign Data Processing Agreements (DPAs) that clearly define
responsibilities, liabilities, and safeguards. An External Data Protection Compliance
Organization (DPCO) will carry out an annual compliance audit and submit a Compliance
Audit Report (CAR) to the NDPC as required under NDPA.

To ensure continuous oversight, a Data Protection Steering Committee is established within


the Nigeria Country Office, chaired by the CDPO, and composed of representatives from IT,
HR, MEAL, Procurement, and Compliance. The committee meets quarterly to monitor
compliance progress and address emerging risks.

3. Data Protection Principles


All personal data processing within ACF-F Nigeria must be guided by the fundamental
principles of data protection, as required by NDPA and international standards. These
principles are not optional but mandatory guidelines that inform daily operations:

1. Lawfulness, Fairness, and Transparency: Data must only be collected and


processed on a lawful basis. Individuals must always be informed, in clear and
accessible language, about how their data will be used.
2. Purpose Limitation: Personal data should only be collected for specified, explicit,
and legitimate purposes and not used for any unrelated purpose.
3. Data Minimization: Only the minimum data necessary to achieve the intended
purpose should be collected.
4. Accuracy: Inaccurate or outdated data must be corrected or erased immediately.
5. Storage Limitation: Data must not be retained longer than necessary and must follow
approved retention schedules.
6. Integrity and Confidentiality: Personal data must always be processed securely and
protected against unauthorized or unlawful access, accidental loss, or damage.
7. Accountability: ACF-F must not only comply but also demonstrate compliance with
these principles through records, reports, and audits.
8. Privacy by Design and Default: All new projects, tools, and processes must integrate
privacy considerations from the start, and systems must be set to the most privacy-
friendly defaults.

4. Data Collection and Consent


Data collection at ACF-F Nigeria will only occur when a valid lawful basis exists, including
consent, contract, legal obligation, public interest, legitimate interest, or vital interest.
Consent, where used, must be freely given, specific, informed, and unambiguous. Withdrawal
of consent must be as simple as its provision and available at any time.

For beneficiaries, privacy notices must be provided in English and relevant local languages.
Where literacy or language barriers exist, oral explanations, pictograms, or audio-visual
methods should be used to ensure informed consent. For children, persons with disabilities, or
other vulnerable groups, additional safeguards are mandatory, such as obtaining guardian
consent and using simplified consent tools.

For special category data (such as health, biometric, ethnic origin, or other sensitive data),
explicit consent is mandatory, and additional security measures must be applied. For
suppliers and vendors, data should be collected solely for legitimate procurement purposes. If
a supplier is not selected, their data must be securely destroyed.

All consent forms, whether paper or digital, must be stored securely and electronic copies
uploaded into a central consent repository managed by the CDPO.

5. Data Subject Rights


ACF-F Nigeria fully upholds the rights of data subjects as provided under NDPA, including:

 The right of access,


 The right to rectification,
 The right to erasure (“right to be forgotten”),
 The right to restrict processing,
 The right to data portability, and
 The right to withdraw consent.

To ensure compliance, all requests from data subjects must be forwarded to the CDPO within
24 hours of receipt. ACF-F must respond within 30 days, extendable by another 30 days in
complex cases. A Data Subject Rights Register will be maintained by the CDPO,
documenting all requests and responses. Before releasing any data, the requester’s identity
must be verified to prevent unauthorized access.

If a request is refused, the CDPO must document the legal basis for refusal, ensuring
transparency and accountability.

6. Data Security
Data security at ACF-F Nigeria relies on a combination of organizational, technical, and
physical measures.
Organizational safeguards include mandatory NDAs, confidentiality clauses in contracts, and
role-based access controls. Staff are obligated to follow clear procedures for secure data
disposal.

Technical safeguards include the use of encryption at rest and in transit, multi-factor
authentication (MFA), audit logging, data loss prevention (DLP) systems, and robust anti-
malware and backup systems. Physical safeguards include restricted office access, locked
cabinets for sensitive files, CCTV with defined retention schedules, and visitor registration
procedures designed to protect privacy.

To manage mobile and remote work risks, the organization applies Mobile Device
Management (MDM), restricts the use of personal devices for organizational data, and
mandates VPN access for remote connectivity. ACF-F applies a Zero Trust Security Model,
granting access based on “least privilege” and requiring continuous authentication.

7. Data Retention and Disposal


ACF-F Nigeria retains data only for as long as necessary, in accordance with donor
requirements, humanitarian needs, and legal obligations. Retention periods for different
categories of data are defined in Annex 1.

When data reaches the end of its retention period, it must be securely disposed of:

 Digital data must be permanently deleted from servers, with deletion logs maintained.
 Physical records must be shredded, with certificates of destruction retained.
 Cloud data must also be deleted, and confirmation obtained from the cloud provider.

The CDPO and Internal Audit will conduct periodic audits to ensure compliance with
disposal practices.

8. Data Sharing and Transfers


Personal data may only be shared when it is strictly necessary and supported by appropriate
agreements. For partners and donors, written data sharing agreements or contractual clauses
must define responsibilities and safeguards. Only the minimum required data should be
shared. For government authorities, data sharing is permitted only when legally required and
must not endanger beneficiaries or staff. A risk assessment must precede any such disclosure.

For cross-border transfers, ACF-F must comply with NDPA requirements. Transfers must be
logged in the Cross-Border Transfer Register and safeguarded with Standard Contractual
Clauses (SCCs) or equivalent mechanisms.
9. Data Breach Management
Any staff member who suspects or becomes aware of a data breach must immediately report
it to their line manager and the CDPO. The CDPO supported by the Incident Response Team
(IRT)—composed of IT, HR, and Legal representatives, will assess the breach, determine
risks, and decide on notification requirements.

If the breach is likely to impact individuals, the NDPC must be notified within 72 hours, and
affected individuals informed without undue delay. The CDPO will maintain a Breach
Register, and every incident will be followed by a Post-Incident Review to capture lessons
learned and implement corrective measures.

10. Training and Awareness


All staff must complete data protection training during onboarding and an annual refresher
thereafter. Specialized training will be provided for high-risk roles, such as HR (employee
data), IT (system security), MEAL (beneficiary data), and Procurement (third-party data).

Awareness will be reinforced through internal campaigns such as posters, email reminders,
FAQs, and practical scenarios. Simulated phishing tests and quizzes will be used to test and
reinforce staff knowledge.

11. Monitoring and Review


The CDPO will conduct internal compliance checks every six months, while Internal
Audit/ARC will conduct spot checks. An annual compliance audit will be carried out by an
external DPCO, culminating in a Compliance Audit Report (CAR) submitted to the NDPC.

Performance will be monitored using Key Performance Indicators (KPIs) such as the
percentage of staff trained, the number of DPIAs conducted, and the number of DSRs
handled.

To encourage reporting, an anonymous whistleblowing mechanism will be available for staff


to raise concerns about potential data protection violations. This SOP will be reviewed
annually or earlier if new NDPC directives or global standards are issued. Updates will
require validation by the CDPO, Country Director, and HQ DPO.

Annex 1 – Retention Duration


Department / Data Retention Period Disposal Method
Secure
CVs & unsuccessful applications 6–12 months
deletion/shredding
Department / Data Retention Period Disposal Method
Employee records (contracts, payroll, Archive then
7 years after exit
evaluations) destruction
Consultant data Contract + 5 years Secure destruction
Payroll records 7 years Secure destruction
Archive then
Vendor contracts 7 years
destruction
Project duration + 5 Archive then
Beneficiary registration data
years destruction
Baseline/evaluation studies 7 years (anonymized) Archive
Archive then
Photos/videos (with consent) Project duration
destruction
Visitor logs 1 year Secure destruction
CCTV recordings 30–90 days Automatic overwrite
Donor requirement + 5
Donor reporting data Secure destruction
years
5 years (unless legal
Email correspondence Secure deletion
hold)
System logs (IT/security) 1–2 years Secure deletion

You might also like