17 Sep
For many businesses, data protection still sits somewhere between compliance paperwork and IT. A privacy policy is placed on the website, consent is obtained through customer forms, and perhaps a data protection audit has been conducted. Once those boxes have been ticked, it can be tempting to consider the issue dealt with.
The Nigeria Data Protection Act 2023 goes considerably further. The NDPA regulates how businesses collect, process, store, disclose and protect personal data. Data protection therefore extends into everyday business decisions and operations, rather than remaining within the documents kept in a compliance folder.
Consider customer data. A business collecting names, contact details, identification documents, financial information or other personal data should be able to explain why the information is being collected, the legal basis for processing it, who has access to it, whether it is shared with third parties, how long it will be retained and what happens when it is no longer required.
The principle of data minimisation is particularly important in this context. Businesses should collect personal data that is adequate, relevant and limited to what is necessary for the purpose for which it is being processed. Keeping information indefinitely simply because it might become useful in the future can create unnecessary exposure for the organisation.
Third-party relationships present another area that requires greater attention. Many businesses rely on payment platforms, cloud providers, customer relationship management systems, marketing tools, HR platforms and other vendors that process personal data on their behalf. These arrangements should be properly structured, with appropriate contractual provisions and safeguards governing how personal data is handled.
Data subject rights also demonstrate why having a privacy policy is different from having an effective compliance framework. Where a customer requests access to their personal data, seeks correction of inaccurate information or exercises another applicable right under the NDPA, the business needs a practical process for receiving, assessing, responding to and documenting the request. A policy may explain the rights available to data subjects, but the organisation still needs the internal systems and people capable of giving effect to those rights.
Incident response is another area where the administrative approach can quickly become inadequate. A data breach cannot simply be treated as an IT problem because the legal consequences may extend across the organisation.
Section 40 of the NDPA requires a data controller to notify the Nigeria Data Protection Commission within 72 hours of becoming aware of a personal data breach where the breach is likely to result in a risk to the rights and freedoms of individuals. Where the breach is likely to result in a high risk to the rights and freedoms of a data subject, the controller is also required to communicate the breach to the affected data subject in accordance with the Act.
This makes preparedness particularly important. When an incident occurs, the organisation should already understand how the incident will be identified and escalated, who will assess the affected data, how the risks to data subjects will be determined, who is responsible for regulatory communication and what steps will be taken to contain the incident and prevent further harm.
Those questions should not be considered for the first time after customer information has already been compromised.
The same principle applies to higher-risk processing. Businesses introducing new technologies, extensive customer profiling, automated processing or other activities that may present significant risks to individuals should consider those risks before the processing begins. Data protection should be incorporated into the design and implementation of the business activity rather than reviewed only after the system or product has been deployed.
The broader issue is that data protection is often viewed as a compliance function when it is actually connected to several parts of the business. Customer acquisition, marketing, technology, procurement, human resources, vendor management and incident response can all involve the processing of personal data.
The real question, therefore, is not simply whether a business has a privacy policy or has completed a compliance exercise. The more important question is whether the way the business actually operates reflects its obligations under the NDPA.
A privacy policy cannot control who has access to a database. A compliance certificate cannot respond to a data breach. A consent form cannot determine whether customer information is being retained for longer than necessary.
Meaningful data protection compliance requires the legal framework to be supported by appropriate processes, accountability, safeguards and operational controls.
For businesses operating in an increasingly data-driven environment, treating data protection as an administrative exercise can leave important risks sitting outside the compliance framework.
The issue is no longer simply whether the documents are in place. It is whether the business is prepared to act on its data protection obligations when they matter.
No Comments