Implementation Framework
Implementation Framework
[MARCH, 2020]
VERSION 2.2
NIGERIA DATA PROTECTION REGULATION 2019:
IMPLEMENTATION FRAMEWORK
1. Background
2. Summary of the NDPR
3. Compliance Approach
4. Compliance Framework
4.1 Forms of Compliance
4.2 Compliance Checklist for Data Controllers
5. Enforcement Framework
5.1 Forms of Enforcement
6. Enforcement Process
7. How Personal Data is to be Handled
7.1 Further Processing
8. Digital Consent
8.1 Types of Consent
8.2 Consent Requirement Under NDPR
8.3 Valid Consent Guide
8.4 Consent to Cookies
9. Data Protection Audit
9.1 Audit Periods
9.2 Audit Filing Fees
9.3 Content of the Audit Report
9.4 Audit Verification Statement by DPCO
10. Transfer of Data Abroad
11. Retention of Records
12. Report of Data Privacy Breach
13. Establishment of Administrative Redress Panel
14. Third Party Processing
15. Data Protection in MDAs
16. Relationship with Attorney-General of the Federation
1|Page
17. Continuous Public Awareness and Capacity Building
Annexure A- Audit Template for NDPR Compliance
Annexure B- Sample Privacy Policy Template for Public Institutions
Annexure C- Countries with Adequate Data Protection Laws
2|Page
NIGERIA DATA PROTECTION REGULATION 2019: IMPLEMENTATION
FRAMEWORK
1. BACKGROUND INFORMATION
The NDPR was issued on 25th January 2019 pursuant to Section 6 (a) and (c) of
the NITDA Act, 2007. The NDPR was made in recognition of the fact that many
public and private bodies have migrated their respective businesses and other
information systems online. These information systems have thus become
critical information infrastructure which must be safeguarded, regulated and
protected against personal data breaches. The Government further takes
cognizance of emerging data protection laws and regulations within the
international community geared towards protecting privacy, identity, lives and
property as well as fostering the integrity of commerce and industry in the data
and digital economy.
3|Page
2. SUMMARY OF THE NDPR
c) stored only for the period within which it is reasonably needed; and
5|Page
i. the right to be informed of the actual or intended Processing
activities;
ii. the right to have the Personal Data rectified;
iii. the right to object to certain Processing activities;
iv. the right to have the Personal Data deleted;
v. the right to request the restriction of the Processing; and
vi. the right to portability of the Personal Data.
6|Page
d) to ensure that Nigerian businesses remain competitive in international trade
through the safe guards afforded by a just and equitable legal regulatory
framework on data protection and which is in tune with best practice.
The NDPR applies to every Data Controller and Data Processor. A data
controller is defined by the Regulation as a person who either alone, jointly with
other persons or in common with other persons or a statutory body determines
the purposes for and the manner in which Personal Data is processed or is to
be processed. A data processor (Referred to data administrator in the
Regulation) is a person or an organization that processes data on behalf of the
data controller.
7|Page
The approach adopted by the NDPR considers the Nigerian context and seeks
to be implemented in a non-obstructive, compliance promoting approach. The
NDPR uses a triangular compliance model.
In this model, NITDA would register DPCOs which will provide auditing and
compliance services for Data Controllers. The criteria for licensing DPCOs
would be publicly accessible and such licensed DPCOs would be listed on
NITDA website. Data Controllers who process personal data of more than 2000
Data Subjects are required to submit a summary of their data protection audit
to NITDA on an annual basis.
8|Page
a) data science
b) data protection and privacy
c) information privacy
d) information audit
e) data management
f) information security
g) data protection legal services
h) information technology due diligence
i) EU implementation of and compliance with GDPR
j) cyber security/cyber security law
k) data analytics
l) data governance
DPCOs are licensed to provide one or more of these services:
9|Page
A Data Controller is required to appoint a dedicated DPO where one or
more of the following conditions are present:
a) The entity is a Government Organ, Ministry, Department, Institution
or Agency;
b) The core activities of the organization relate to usual processing of
large sets of data subjects per annum;
c) The organization processes sensitive personal data in the regular
course of its business; and
d) The organization processes critical national databases consisting of
personal data.
3.3 DPO in Multinational Company
A DPO appointed for the purpose of compliance with the NDPR must
be based in Nigeria and be given full access to the management in
Nigeria. Such Nigerian DPO may give reports to a global DPO where
such exists.
4. COMPLIANCE FRAMEWORK
10 | P a g e
iv. Monitoring and Analytics. The compliance framework will ensure the
proactive monitoring and evaluation of data provided by concerned
entities by utilizing analytic tools to identify patterns that reflect non-
compliance.
The Data Controller is the focal point in the data protection value chain. Most
responsibilities for compliance lie with the Data Controller. However, the Data
Processors have a duty to provide all information and take all the relevant
measures allowing the Data Controller to comply with its regulatory obligations,
including, but not limited to providing processing information that is not available
to the Data Controller (such as the categories of data processed, the Data
retention periods, the identity and exact locations of the sub-Processors, the
details of the security measures implemented by the Data Processor etc.).
i. conduct of Information audit: Article 3.1(7) of the NDPR provides what the
audit report should contain.
ii. lawful bases for processing
iii. Clear information on the data processing activities: The Regulation
provides for information, publicity and clear privacy policy. It states that
the information must be provided to the Data Subject in “a concise,
transparent, intelligible and easily accessible form, using clear and plain
language, in writing, or by other means, including, where appropriate, by
electronic means, orally, when requested by the data subject, provided
that the identity of the data subject is proven by other means, free of
charge except, where requests from a data subject are manifestly
unfounded or excessive, in particular because of their repetitive
character. The Regulation further provides that “any medium through
11 | P a g e
which personal data is being collected or processed shall display a simple
and conspicuous privacy policy that the class of data subject being
targeted can understand.” The business process of each data controller
would determine the medium and mode of publicising the privacy policy.
For example, an entity that does its business substantially through digital
platforms is expected to have a privacy policy on its website and send
messages to inform data subjects of certain new developments requiring
new or different consent. Publicity of privacy policy may be fulfilled
through any one or combination of the following:
➢ website
➢ digital media
➢ posted at conspicuous parts of business premises
➢ by reading to the affected data subjects; or
➢ publication in any public media
Whichever mode or medium adopted shall provide a means of exercising
verifiable consent of the data subject.
iv. Data protection-by-design: Data Controllers must show that the systems
they use directly or indirectly via the Data Processors are built in
accordance with the Data Protection regulatory requirements. This
applies to Data retention periods, data security measures, such as
encryption, or the insertion of consent and withdrawal of consent
functionalities in data subject-facing applications with regard to security.
Data Controllers are expected to ensure continuous improvement of their
information security architecture to prevent possible data breaches.
v. Awareness creation on data protection: continuous capacity building for
staff, contractors, processors and relevant third parties is a core duty of
the Data Controller.
12 | P a g e
vi. Develop and circulate an internal data privacy strategy or policy to help
staff and vendors to understand the data controller’s direction in respect
of managing personal data.
vii. Conduct Data Protection Impact Assessment (DPIA): Where the
organization intends on embarking on a project that is likely to result in
significant risks to the rights and freedoms of a Data Subject. A DPIA
should be conducted to identify possible areas where breaches may
occur and device means of addressing such risks. Organisations are also
required to conduct DPIAs on their processes, services and technology
periodically to ensure continuous compliance.
viii. Data breach notification. Every data controller must stipulate a process
for notifying NITDA on identified data breaches within seventy-two hours
of the breach. The Data Controller is now required to inform the Data
subject of breach of his or her Personal Data within seven working days
after discovering the breach.
ix. Appoint a DPO or assign an appropriate person who has responsibility to
the top-most hierarchy of the Organisation in respect of data protection.
x. Update agreement with third party processors to ensure compliance with
the NDPR.
xi. Design system and processes to make data request and access easy for
Data Subjects
xii. Design systems and processes to enable data subjects easily correct or
update information about themselves.
xiii. Design system and processes to enable data subjects easily transfer
(port) data to another platform at minimal costs.
xiv. Process for objection to processing of personal data is clearly
communicated to Data Subjects
xv. Procedure for informing and protecting rights of Data Subject where
automated decision is being made on personal data
13 | P a g e
5. HOW PERSONAL DATA IS TO BE HANDLED
Where a Data Controller wishes to further process data initially collected for a
defined, limited purpose, the Data Controller shall consider the following:
a) Whether there exists a connection between the original purpose and the
proposed purpose;
b) The context in which the data was originally collected;
c) Possible impact of the new processing on the data subject; and
d) Existence of requisite safeguards for the data subject.
The above information shall be provided to the Data Subject before the further
processing is done. The further processing may be done if the Data Subject
gives consent based on the new information or the processing is required in
compliance with a legal obligation.
c. Systematic monitoring;
6. DIGITAL CONSENT
‘Consent’ of the Data Subject means any freely given, specific, informed and
unambiguous indication of the Data Subject's wishes by which he or she,
through a statement or a clear affirmative action, signifies agreement to the
processing of Personal Data relating to him or her (Article 1.3iii). Consent may
be made through a statement- written, sign or an affirmative action signifying
agreement to the processing of personal data.
15 | P a g e
d) Access to data. The data subject has a right to request and receive the
data he/she gave, to know how such data is being used, where it is being
transferred and who has access to it.
c) where Personal Data is used for purposes other than those initially
specified to the Data Subject;
Exceptions to the above may be cases of: health emergency, national security
and crime prevention.
16 | P a g e
a) Explicit Consent: Subject gives clear, documentable consent eg.
Tick a box, sign a form, send an email or sign a paper
If the box is left unticked, you will not receive the XXX newsletter
NITDA may, on its own, carry out scheduled audits, or may require report of
audits as carried out by DPCOs and may schedule “spot check” or “Special
Audits” to ascertain compliance or to identify breaches. Usually these audits or
investigations are unscheduled and may be at a “tipoff “or random to ensure
compliance with the NDPR and related laws.
The NDPR provides two types of audits: (i) the initial Data Audit and (ii) the
annual data audit. The Initial data audit is provided in Article 4.1(5) while the
Annual data audit is an audit showing the continuing state of data processing in
the organization.
18 | P a g e
✓ to assess the level of compliance with the NDPR
✓ to evaluate compliance with the organisation's own data protection policy
✓ to identify potential gaps and weaknesses in organisation’s processes
✓ to give requisite advice and/or remedial actions for identified gaps
Article 4.1(7) of the Regulation addresses the period when audit report is to be
filed by Data Controllers. The Article provides as follows:
Each Controller is expected to file the audit report through a DPCO and pay the
following amount as applicable:
The data protection audit shall contain information as specified in Article 4.1(5)
of the Regulation. For clarity, the report shall contain the following:
19 | P a g e
a) the identity and the contact details of the Controller;
c) the purpose(s) of the processing for which the Personal Data are
intended as well as the legal basis for the processing;
g) the period for which the Personal Data will be stored, or if that is not
possible, the criteria used to determine that period;
h) the existence of the right to request from the Controller access to and
rectification or erasure of Personal Data or restriction of processing
concerning the Data Subject or to object to processing as well as the right
to Data Portability;
20 | P a g e
well as the significance and the envisaged consequences of such
processing for the Data Subject;
m) Where the Controller intends to further process the Personal Data for
a purpose other than that for which the Personal Data were collected, the
controller shall provide the Data Subject prior to that further processing
with information on that other purpose, and with any relevant further
information; and
The DPCO in the implementation of the NDPR has critical roles to play to ensure
the objectives of the Regulation are met. In the performance of data audits,
DPCOs are responsible for:
7.7.1 Terms
Every DPCO shall ensure all its staff are well aware of the ethical considerations
in the performance of Audit under the NDPR. NITDA shall ensure DPCOs
become registered with professional associations that regulate ethical conducts
of their members and to ensure standardized delivery of services. The following
are basic ethical expectations required of DPCOs in the conduct of their
business.
a) Confidentiality:
DPCOs shall handle the information and data of their client in the most
confidential manner. A binding non-disclosure agreement shall be signed
before embarking on the audit and implementation process.
b) Conflict of Interest:
DPCOs shall not audit a client where the doing of such would lead to
manifest conflict of interest. For example, a DPCO that designed and
implemented the data protection system should not conduct the data
audit
A DPCO that is engaged to provide financial or systems audit may also
perform data audit, however, such must not have been retained as the
outsourced DPO or be responsible for the implementation of the data
protection compliance.
c) Honesty:
23 | P a g e
DPCOs must state verifiable facts and not conjectures, half-truths or
concealed facts. The essence of the audit is not to sanction organisations,
but to have an idea of where the country’s cyber and information
management practices can be improved.
Any established falsehood found in a report or communication to NITDA
by the DPCO is a ground for immediate withdrawal of license
d) Professionalism
Auditors must perform the service with the highest level of
professionalism. Continuous capacity building of staff is a prerequisite for
relicensing by NITDA. DPCOs must not undertake any work for which
they lack the requisite skills, manpower and capacity.
iii. The privacy policy of the Data Controller, compliant with the provisions of
the NDPR.
v. Any other detail that assures the privacy of personal data is adequately
protected in the target country.
NITDA shall coordinate transfer requests with the office of the Attorney-General
of the Federation. A ‘white-list’ of jurisdictions shall be compiled and published
on official media of communication. Where transfer to a jurisdiction outside the
24 | P a g e
White list is being sought, the Data Controller shall ensure there is a verifiable
documentation of consent to one or more of the exceptions stated in Article 2.12
of the NDPR.
9. RETENTION OF RECORDS
The Regulation does not explicitly provide for a time period because that detail
in certain scenarios may be subject to existing laws or contractual agreements.
However, where the time frame for storage of the personal data is not specified,
the length of storage of data shall be determined by:
25 | P a g e
Every data Controller shall specify the duration of storage clearly in its Terms of
Service or other binding document. NITDA would consider the above and other
circumstances to determine if the data was stored appropriately and for a
reasonable length of time.
Personal Data that is no longer in use and after requisite statutorily required
storage period shall be destroyed in line with global best practices for such
operations. Evidence of destruction of data shall be a valid defense against
future allegation of breach by a Data Subject.
In line with Article 4.1(8) and other relevant provisions, Data Subjects, civil
society or professional organisations or any government Agency may report a
breach of this Regulation to NITDA through an advertised channel. Upon receipt
of this report, the Director General/CEO may direct action to be taken which
may include the following steps:
26 | P a g e
i. A description of the circumstances of the loss or unauthorized access or
disclosure
ii. The date or time period during which the loss or unauthorized access or
disclosure occurred
iii. A description of the personal information involved in the loss or
unauthorized access or disclosure
iv. An assessment of the risk of harm to individuals as a result of the loss or
unauthorized access or disclosure
v. An estimate of the number of individuals to whom there is a real risk of
significant harm as a result of the loss or unauthorized access or
disclosure
vi. A description of any steps the organization has taken to reduce the risk
of harm to individuals
vii. A description of any steps the organization has taken to notify individuals
of the loss or unauthorized access or disclosure, and
viii. The name and contact information for a person who can answer, on
behalf of the organization, the Agency’s questions about the loss of
unauthorized access or disclosure
11. ENFORCEMENT FRAMEWORK
Any person who believes a party is not complying with any of the provisions of
the Regulation may file a complaint with NITDA. Such complaints must meet the
following requirements:
11.1.3 Investigations
28 | P a g e
written communication with the concerned entity, NITDA will indicate the basis
of the audit.
iii. Issue public notice to warn the public to desist from patronizing
or doing business with the affected party;
Where NITDA has determined that a party is in breach of the NDPR, especially
where such breach affects national security, sovereignty and cohesion, it may
seek to prosecute officers of the organization as provided for in Section 17(1,3)
29 | P a g e
NITDA Act 2007. NITDA shall seek a fiat of the Honorable Attorney General of
the Federation (HAGF) or may file a petition with any authority in Nigeria, this
may include; the Economic and Financial Crimes Commission (EFCC), the
Department of State Security (DSS), the Nigerian Police Force (NPF), the
Independent Corrupt Practices (and other related offences) Commission (ICPC)
or the Office of National Security Adviser (ONSA).
30 | P a g e
violator or any other party who may be in a
position to provide clarity on facts of the
allegation of breach.
31 | P a g e
Request of A. Where a violator does not take steps to address breach or
Prosecution consult with NITDA as to what steps to be taken to remedy
breach after the period stated in the "Notice for
Enforcement"; or
In line with Article 4.2 of the Regulation, NITDA shall establish Administrative
Redress Panels (ARP). The ARP shall be composed of accomplished IT
professionals, public administrators and lawyers who shall work with the Agency
for the purpose of resolving issues related to the Regulation.
The rules of procedure of the ARP shall be drawn up by a Panel of experts. The
ARP Procedure shall however be designed with the following in mind:
32 | P a g e
b) Arguments and case presentations shall be done in writing. The
procedure shall limit oral presentation to the barest minimum
c) The ARP shall in reaching its decision, clearly state the proof of violation,
identify some or all the data subjects affected by the breach (in an
anonymized, pseudonymized or summarized format), the provision of the
Regulation violated and any acts of omission or commission which
exacerbated the breach.
d) In reaching its decision, the Panel may consider whether the indicted
entity has a reputation for data or other criminal or corporate breaches in
the past; the number of employees in its establishment; the impact of the
fine on its overall contribution to the economy. Nothing in this provision
shall however limit the powers of the ARP to discharge its duties as
expected of a typical quasi-judicial panel
Third Party processors may include data processors and other statutory or non-
statutory data recipients whom the Controller sends data to for the purpose of
delivering service to the Subject.
Data Controllers are required to publish a list of third parties with whom the Data
Subject’s data may be shared. This publication which must also be included in
the audit filing report include:
• Informing and advising the MDA on compliance with NDPR and other
applicable data protection laws and policies
• monitoring compliance with the Regulation and with the internal policies
of the organization including assigning responsibilities, awareness raising
and training staff
• facilitating the cooperation with relevant stakeholders and acting as point
of contact with NITDA.
Every FPI shall incorporate a Privacy Policy with its website and digital media
platform to assure the privacy of the Data Subjects interacting with the FPI. A
34 | P a g e
sample Privacy Policy for government Agencies and institutions is available in
Annexure A for guidance.
In accordance with Article 2.12 of the NDPR, where a Data Controller seeks to
transfer data to a foreign country, NITDA shall examine if such country has
adequate data protection law or regulation that can guarantee minimum privacy
for Nigerian citizens’ data. Where there is need for further legal cooperation
from a target country, NITDA may approach the office of Attorney-General for
that purpose. In such circumstance, such data transfer and storage processes
shall be done under the supervision of the Attorney-General.
NITDA shall generate a list of countries with acceptable data protection laws,
this list shall be validated by the Attorney-General. Where a Data Controller
seeks to transfer to any country other than the ones listed, then such shall be
subject to further processes to ascertain the protection of Nigerian citizens’ data
17. CONTINUOUS PUBLIC AWARENESS AND CAPACITY BUILDING
35 | P a g e
Where the NDPR and this Framework do not provide for specific details on the
implementation of Data Protection, the European Union General Data Protection
Regulation (EU GDPR) and its judicial interpretations shall of persuasive effect
in Nigeria.
White list of countries: These are countries that have provided a basic data
protection law upon which the rights of Data Subjects can be enforced in such
country or in the international courts.
36 | P a g e
ANNEXURE A
1.8 Art. 2.1 Do you have a Data Protection compliance and review
mechanism?
37 | P a g e
Have you developed a capacity building plan for
1.9 Art. 2.6
compliance with data protection for all staff?
1.13 Art. 4.1(2) Who is responsible for your compliance with data
protection laws and processes
1.14 Art. 1.3 Have you assessed whether you are a Data Controller or
Data Processor?
Have you reviewed your Human Resources policy to
1.15 Art 4.1(5) ensure personal data of employees are handled in
compliance with the NDPR?
Have appropriate technical and organisational measures
been implemented to show you have considered and
1.16 Art. 2.5(d)
integrated data protection into your processing
activities?
Do you have a policy for conducting Data Protection
1.17 Art. 4.5 Impact Assessment (DPIA) on existing or potential
projects?
Does your DPIA Policy address issues such as:
a) A description of the envisaged processing operations
b) The purposes of the processing
c) The legitimate interest pursued by the controller
1.18 Art. 4.5 d) An assessment of the necessity and proportionality of
the processing operations in relation to the purposes
e) An assessment of the risks to the rights and freedoms
of Data Subject f) Risk mitigation measures being
proposed to address the risk
38 | P a g e
2 DATA PROTECTION OFFICER/DATA PROTECTION COMPLIANCE ORGANISATION
Have you appointed a Data Protection Compliance
Art. 4.1(4)
Organisation (DPCO)?
Which kind of service has a DPCO provided for you till
Art. 4.1(4) date? Hint- Audit, Data Protection Impact Assessment,
Data Breach Remediation etc.
Art. 4.1(2) Does your DPCO also perform the role of your DPO?
Has a Data Protection Officer (DPO) been appointed and
given responsibility for NDPR compliance and the
2.1 Art. 4.1(2)
management of organisational procedures in line with
the requirements of NDPR?
Art. 4.1(4) Do you utilise the same DPCO for Data Protection
compliance implementation and audit?
2.2 Art. 4.1(3) Have you trained your Data Protection Officer in the last
one year?
Does the Data Protection Officer (DPO) have sufficient
Art. 4.1(2)
access, support and the budget to perform the role?
If the DPO has other job functions, have you evaluated
Art. 4.1(2)
whether there is no conflict of interest?
Does the DPO have verifiable professional expertise and
knowledge of data protection to do the following:
a) To inform and advice the business, management,
employees and third parties who carry out processing, of
their obligations under the NDPR b) To monitor
compliance with the NDPR and with the organisation's
own data protection objectives
Art. 4.1(2) c) Assignment of responsibilities, awareness-raising and
training of staff involved in processing operations
d) To provide advice where requested as regards the
data protection impact assessment and monitor its
performance e) To
cooperate with NITDA as the Supervisory Authority
f) To act as the contact point for NITDA on issues relating
to data processing
39 | P a g e
Is there a clearly available mechanism (e.g. webpage,
2.3 Art. 2.5 etc.) for data subjects that explains how to contact your
organisation to pursue issues relating to personal data?
3 DOCUMENTATION TO DEMONSTRATE COMPLIANCE
3.5 Art. 1.3 Do you have a register of data breaches and security
incidents?
4 PROCESSING ACTIVITIES
Have you carried out a comprehensive review of the
4.1 Art. 2.2
various types of processing your organisation perform?
40 | P a g e
If your organisation offers services directly to children,
4.3 Art. 2.4 have you communicated privacy information in a clear,
plain way that a child will understand?
Do you adopt data pseudonymisation, anonymisation
Art. 2.6 and encryption methods to reduce exposure of personal
data?
Have you identified all the points at which personal data
is collected: websites, application forms (employment
4.4 and other), emails, in-bound and out-bound telephone
Art. 1.3(xix)
calls, CCTV, exchanges of business cards and,
attendance at events etc?
Do you have procedures for regularly reviewing the
4.5 Art. 3.1 (8)
accuracy of personal data?
Do you have a system for Data Subjects to erase or
Art. 3.1(8)
amend their personal data in your custody?
Have you identified all the ways in which personal data is
4.6 Art. 2.5(d)
stored, including backups?
4.7 Art. 2.2 data, for determining and authorising internal or external
access and all disclosures of data?
41 | P a g e
Has your organisation implemented appropriate
4.12 Art. 4.1(5) procedures to ensure personal data breaches are
detected, reported and investigated effectively?
Do you have mechanisms in place to notify affected
4.13 Art. 4.1(5) individuals where the breach is likely to result in a high
risk to their rights and freedoms?
Have you trained all staff who deal with personal data
4.14 Art. 2.6 about their responsibilities and data protection
procedures?
Are these responsibilities written into job descriptions?
4.15 Art. 2.6
4.16 Art. 2.7 Have you contracted with any third-party data
processors?
If so, are such contracts compliant with the requirements
4.17 Art. 2.7
of the NDPR?
Have you agreed a schedule to review current contracts
4.18 Art. 2.7
for compliance with NDPR?
42 | P a g e
ANNEXURE B
This Privacy Policy describes your privacy rights regarding our collection, use, storage,
sharing and protection of your personal information. It applies to the NITDA website
and all database applications, services, tools and physical contact with us regardless
of how you access or use them.
If you have created a username, identification code, password or any other piece of
information as part of our access security measures, you must treat such information
as confidential, and you must not disclose it to any third party. We reserve the right to
disable any user identification code or password, whether chosen by you or allocated
by us, at any time, if in our opinion you have failed to comply with any of the provisions
of these Conditions. If you know or suspect that anyone other than you know your
security details, you must promptly notify us at info@[Link]
2.0 Consent
You accept this Privacy Policy when you give consent upon access to our platforms,
or use our services, content, features, technologies or functions offered on our
website, digital platforms or visit any of our offices for official or non-official purposes
(collectively “NITDA services”). This Policy governs the use of NITDA services and
43 | P a g e
intervention projects by our users and stakeholders unless otherwise agreed through
written contract. We may amend this Privacy Policy at any time by posting a revised
version on our website, or placing such notice at conspicuous points at our office
facilities. The revised version will be effective 7-days after publication.
When you use NITDA Services, we collect information sent to us by your computer,
mobile phone or other electronic access device. The automatically collected
information includes but not limited to- data about the pages you access, computer IP
address, device ID or unique identifier, device type, geo-location information,
computer and connection information, mobile network information, statistics on page
views, traffic to and from the sites, referral URL, ad data, standard web log data, still
and moving images.
We may also collect information you provide us including but not limited to- information
on web form, survey responses account update information, email, phone number,
organization you represent, official position, correspondence with NITDA support
services and telecommunication with NITDA. We may also collect information about
your transactions, enquiries and your activities on our platform or premises.
We may also use information provided by third parties like social media sites.
Information about you provided by other sites are not controlled by NITDA and we are
therefore not liable for how they use it.
The purpose of our collecting your personal information is to give you efficient,
enjoyable and secure service. We may use your information to:
Process applications and send notices about your transactions to requisite parties;
44 | P a g e
Manage risk, or to detect, prevent, and/or remediate fraud or other potentially
prohibited or illegal activities;
Measure the performance of the NITDA Services and improve content, technology and
layout;
Contact you at any time through your provided telephone number, email address or
other contact details;
5.0 Cookies
Cookies are small files placed on your computer’s hard drive that enables the website
to identify your computer as you view different pages. Cookies allow websites and
applications to store your preferences in order to present contents, options or
functions that are specific to you. Like most interactive websites, our website uses
cookies to enable the tracking of your activity for the duration of a session. Our website
uses only encrypted session cookies which are erased either after a predefined
timeout period or once the user logs out of the platform and closes the browser.
Session cookies do not collect information from the user’s computer. They will typically
store information in the form of a session identification that does not personally identify
the user.
We store and process your personal information on our computers in Nigeria. Where
we need to transfer your data to another country, such country must have an adequate
data protection law. We will seek your consent where we need to send your data to a
country without an adequate data protection law. We protect your information using
physical, technical, and administrative security measures to reduce the risks of loss,
misuse, unauthorized access, disclosure and alteration. Some of the safeguards we
45 | P a g e
use are firewalls and data encryption, physical access controls to our data centers,
and information access authorization controls.
7.0 How We Share your information within NITDA and other users
During your interaction with our website or premises, we may provide other Ministries,
Departments, Agencies (MDA), other organs of government, private sector operators
performing government functions, with information such as your name, contact details,
or other details you provide us for the purpose of performing our statutory mandate to
you or third parties.
We work with third parties, especially government agencies to perform NITDA services
and implement its mandate. In doing so, a third party may share information about you
with us, such as your email address or mobile phone number.
You accept that your pictures and testimonials on all social media platforms about
NITDA can be used for limited promotional purposes by us. This does not include your
trademark or copyrighted materials.
From time to time we may send you relevant information such as news items,
enforcement notice, statutorily mandated notices and essential information to aid the
implementation of our mandate. We may also share your personal information in
compliance with National or international laws; crime prevention and risk management
agencies and service providers.
8.0 Security
We will always hold your information securely. To prevent unauthorized access to your
information, we have implemented strong controls and security safeguards at the
technical and operational levels. This site uses Secure Sockets Layer/Transport Layer
Security (SSL/TLS) to ensure secure transmission of your personal data. You should
see the padlock symbol in your URL address bar once you are successfully logged
into the platform. The URL address will also start with https:// depicting a secure
webpage. SSL applies encryption between two points such as your PC and the
connecting server. Any data transmitted during the session will be encrypted before
transmission and decrypted at the receiving end. This is to ensure that data cannot be
read during transmission.
46 | P a g e
NITDA has also taken measures to comply with global Information Security
Management Systems (ISMS) we therefore have put in place digital and physical
security measures to limit or eliminate possibilities of data privacy breach incidents.
Your information is regarded as confidential and will not be divulged to any third party
except under legal and/or regulatory conditions. You have the right to request sight of,
and copies of any and all information we keep on you, if such requests are made in
compliance with the Freedom of Information Act and other relevant enactments. While
NITDA is responsible for safeguarding the information entrusted to us, your role in
fulfilling confidentiality duties includes, but is not limited to, adopting and enforcing
appropriate security measures such as non-sharing of passwords and other platform
login details, adherence with physical security protocols on our premises, dealing with
only authorized officers of the Agency.
47 | P a g e
This Privacy Policy is made pursuant to the Nigeria Data Protection Regulation (2019)
and other relevant Nigerian laws, regulations or international conventions applicable
to Nigeria. Where any provision of this Policy is deemed inconsistent with a law,
regulation or convention, such provision shall be subject to the overriding law,
regulation or convention.
48 | P a g e
49 | P a g e
SN COUNTRY DATA PROTECTION LAW COMMENT
1 Austria, Belgium, Bulgaria, Croatia, Cyprus,
Czech Republic, Denmark, Estonia, Finland,
France, Germany, Greece, Hungary, Iceland,
Ireland, Italy
All EU and
Latvia, Lithuania, Luxembourg, Malta,
European
EU- General Data Protection Regulation Netherlands Norway, Poland, Portugal,
Economic Area
Romania, Serbia
Countries
Slovakia, Slovenia, Spain, Sweden
United Kingdom.
Every Country has a Supervisory Authority for
the implementation of the GDPR in its domain.
2 2018 Algerian law on the Protection of Individuals Autorité National de Protection des Données à
Algeria
in the Processing of Personal Data Caractère Personnel
3 Personal Data Protection Law 2000 (Law No.
Agency for Access to Public Information
Argentina 25,326) applies to any person or entity in the
established pursuant to Decree 746 of 2017
country that deals with personal data.
4 General Data Protection Law 2018 (LGPD) very
similar to GDPR. Brazil also has snippets of The Amended LGPD created the National Data
Brazil privacy laws from the Constitution and other Protection Authority (ANPD). The law would
statutes such as Consumer Protection Code take effect in August 2020
1990; Internet Act 2014 etc.
5 Mauritius THE DATA PROTECTION ACT 2017 Mauritius Data Protection Office
6 The Protection of Personal Information, Act 4 of
South Africa The Information Regulator (DPA)
2013
7 Togo Protection of Personal data Togolese Data Protection Authority
8 The Organic Law no. 2004-63 on Personal Data The National Authority for Protection of
Tunisia
Protection (Tunisian Law) Personal Data (DPA)
9 Private sector is governed by Personal
Information Protection and Electronic Documents
Act (PIPEDA) 2000 amended in 2008 to include PIPEDA creates the Office of the Privacy
Canada
mandatory data breach notification and record- Commissioner of Canada
keeping laws. the public sector is governed by the
Privacy Act of 1983.
10 Data Protection Law (Law 133/V/2001 (as The National data protection authority in Cape
Cape Verde amended by Law 41/VIII/2013) and Law Verde is the Comissão Nacional de Proteção de
132/V/2001, of 22 January 2001. Dados Pessoais ('Data Protection Authority').
11 Information Technology – Personal Information
Cyberspace Administration of China (CAC) is
China Security Specification is the latest law on privacy
the data protection authority
in China. It came into effect in May 2018
12
The Protection of Natural Persons With Regard
Cyprus to the Processing of Personal Data and for the Commission for personal data protection
Free Movement of Such Data of 2018.
50 | P a g e
22 Implementation of the General Data Protection
Croatia Croatian Personal Data Protection Agency
Regulation
23 Faeroe Islands Data Protection Act Faroese Data Protection Agency
24
DATA PROTECTION ACT 2018
Data Protection (Application of GDPR) Order
2018 (SD2018/0143) (GDPR Order)
Isle of Man Data Protection (Application of LED) Order 2018 Office of the Data Protection Supervisor
(SD2018/0144) (LED Order)
GDPR and LED Implementing Regulations 2018
(SD2018/0145) (Implementing Regulations)
51 | P a g e
proclaimed through Proclamation No. 3 of 2018,
effective January 15, 2018. The Act repeals and
replaces the Data Protection Act 2004, so as to
align with the European Union General Data
Protection Regulation 2016/679 (GDPR).
37 Qatar The Qatar Financial Centre (QFC) implemented
QFC Regulation No. 6 of 2005 on QFC Data
Protection Regulations (DPL).
38 Singapore Singapore enacted the Personal Data Protection
Act of 2012 (No. 26 of 2012) (the Act) on October
15, 2012. The Act took effect in three phases:
39 South Korea Personal Information Protection Act, 'PIPA') was
enacted and became effective as of 30
September 2011
40 Taiwan The former Computer Processed Personal Data
Protection Law (CPPL) was renamed as the
Personal Data Protection Law (PDPL) and
amended on May 26, 2010. The PDPL became
effective on October 1, 2012, except that the
provisions relating to sensitive personal data and
the notification obligation for personal data
indirectly collected before the effectiveness of
the PDPL remained ineffective. The government
later proposed further amendment to these and
other provisions, which passed legislative
procedure and became effective on March 15,
2016.
41 Turkey The main piece of legislation covering data
protection in Turkey is the Law on the Protection
of Personal Data No. 6698 dated April 7, 2016
(LPPD). The LPPD is primarily based on EU
Directive 95/46/EC.
42 United Arab The Dubai International Financial Centre (DIFC)
Emirates implemented DIFC Law No. 1 of 2007 Data
Protection Law in 2007 which was subsequently
amended by DIFC Law No. 5 of 2012 Data
Protection Law Amendment Law (DPL).
43 India On August 24, 2017, a Constitutional Bench of
nine judges of the Supreme Court of India in
Justice [Link] (Retd.) v. Union of India
[Writ Petition No. 494/ 2012] upheld that privacy
is a fundamental right, which is entrenched in
Article 21 [Right to Life & Liberty] of the
Constitution. This led to the formulation of a
comprehensive Personal Data Protection Bill
2018.[1] However, presently the Information
Technology Act, 2000 (the Act) contains specific
provisions intended to protect electronic
data(including non-electronic records or
information that have been, are currently or are
intended to be processed electronically).
52 | P a g e
44 Data Protection Act Law No. 18.331 (August 11,
Unidad Reguladora y de Control de Datos
Uruguay 2008); Decree No. 414/009 (August 31, 2009)
Personales (URCDP)
(the Act).
REFERENCES
[Link]
53 | P a g e